Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

10/30/2013
07:32 PM
50%
50%

Naming And Shaming Unlikely To Work For Cyberespionage

Why a whistleblower's evidence of widespread surveillance by the NSA has caused the U.S. government to react, but Mandiant's revelations about Chinese espionage fail to curb that nation's efforts

In February, incident response firm Mandiant released its much-publicized report outlining the activities of a Chinese espionage group, dubbed APT1, and its connections to the Chinese government. The report linked the group to more than 140 attacks over seven years and postulated that the well-funded actors were likely part of an intelligence unit within the People's Liberation Army.

Initially, the conclusions caused a stir among computer security professionals and policy makers alike. Yet, despite shining the spotlight on the China's connection to the attacks and some uncertain pressure by the U.S. government, the People's Republic of China continued to deny involvement, and the espionage attacks continued to compromise systems.

If companies hoped that shedding light on nation-state attackers would curb their espionage activities, they were disappointed. While the report did a lot to spotlight the issue of nation-state attacks and what companies could do to investigate them, it also showed that plausible deniability is a workable strategy, says Adam Meyers, vice president of intelligence for security services firm CrowdStrike.

"I think we are going to see proliferation in cyberoperations -- that's my biggest concern," he says. "When nation-state actors have calculable successes, other nations are going to jump in."

While the APT1 report has largely failed to impact China's espionage activities, the revelation of another nation's cyberoperations has had quite a dramatic impact on its policies. Whistleblower Edward Snowden's leak of documents outlining the extent to which the National Security Agency collected data and communications on foreign and American citizens has resulted in multiple congressional hearings, an investigation by the Obama administration, and pressure from allies, many of whom were the target of the agency's information gathering efforts.

[Leaked operations manual reveals NSA attack techniques that are not significantly better than common cybercrime capabilities, despite their high cost to government. See NSA Hack Attacks: Good Value For Money?.]

The results of the two cases are different for a variety of reasons, but a significant factor is the type of evidence presented in each, says Michael Sutton, vice president of security research for cloud security provider Zscaler.

"In the Mandiant report, the activity is never tied directly to the Chinese government; they are in a position where they can claim plausible deniability," he says. "Compare that to the Snowden revelations: There is no plausible deniability for the U.S. government. It is very clear that this is business as usual for them. When you are looking at the PowerPoint decks, it is hard to deny that that is your program."

In addition, the United States and China have different cultures, and the NSA's ability to collect and sift through data on U.S. citizens does not sit well with people's expectation of privacy and freedom in the United States, Sutton says.

For companies suffering from probable nation-state attacks, the comparison between outing Chinese espionage and the Snowden revelations leaves little hope that naming and shaming will ease the pressure on their defenses. It's unlikely that a hacker embedded in an espionage group will come forward with documents describing their activities.

Yet attackers do react to being spotlighted by investigations into their activities, according to Mandiant.

Following the report, the incident response firm detected some changes in the behavior of APT1, but almost all of the activity has been aimed at evading future detection, according to the company's intelligence group. APT1 issued commands to their infrastructure to communicate through different servers and, in some case, replaced the malware.

"While Mandiant’s APT1 report appears to have affected [its] operations, APT1 is still active using a well-defined attack methodology with a discernible post-report shift towards tools not included in the ... report," says the intelligence group in a statement sent to Dark Reading. "Mandiant has also observed an overall decrease in APT1 operations volume; however, it is possible [the group] shifted operations into areas we currently lack visibility."

Perhaps the most significant impact of the Mandiant report, however, is that it allowed companies to see what they were up against and to have indicators of compromise that could be used to block the activity, says CrowdStrike's Meyers.

"Only by going public will companies get the resources they need to deal with these issues," he says. "That is far better than sitting passively by and letting them attack over and over again."

Until nations take stronger actions against known espionage activity -- and can claim the moral high ground by eliminating their own espionage activities -- companies and individuals will have to rely on the sharing of such information to help them combat such attacks, he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bryan Yurcan
50%
50%
Bryan Yurcan,
User Rank: Apprentice
11/4/2013 | 1:37:21 AM
re: Naming And Shaming Unlikely To Work For Cyberespionage
I agree, information sharing among companies is key to preventing cyber attacks. So called"Naming and shaming," doesn't do much, everyone knows which countries are behind the majority of cyber attacks against the Western world, but as Sutton says it's so convoluted they can claim plausible deniability.
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-3154
PUBLISHED: 2020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
CVE-2019-17190
PUBLISHED: 2020-01-27
A Local Privilege Escalation issue was discovered in Avast Secure Browser 76.0.1659.101. The vulnerability is due to an insecure ACL set by the AvastBrowserUpdate.exe (which is running as NT AUTHORITY\SYSTEM) when AvastSecureBrowser.exe checks for new updates. When the update check is triggered, the...
CVE-2014-8161
PUBLISHED: 2020-01-27
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2014-9481
PUBLISHED: 2020-01-27
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
CVE-2015-0241
PUBLISHED: 2020-01-27
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric ...