Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

10/30/2013
07:32 PM
50%
50%

Naming And Shaming Unlikely To Work For Cyberespionage

Why a whistleblower's evidence of widespread surveillance by the NSA has caused the U.S. government to react, but Mandiant's revelations about Chinese espionage fail to curb that nation's efforts

In February, incident response firm Mandiant released its much-publicized report outlining the activities of a Chinese espionage group, dubbed APT1, and its connections to the Chinese government. The report linked the group to more than 140 attacks over seven years and postulated that the well-funded actors were likely part of an intelligence unit within the People's Liberation Army.

Initially, the conclusions caused a stir among computer security professionals and policy makers alike. Yet, despite shining the spotlight on the China's connection to the attacks and some uncertain pressure by the U.S. government, the People's Republic of China continued to deny involvement, and the espionage attacks continued to compromise systems.

If companies hoped that shedding light on nation-state attackers would curb their espionage activities, they were disappointed. While the report did a lot to spotlight the issue of nation-state attacks and what companies could do to investigate them, it also showed that plausible deniability is a workable strategy, says Adam Meyers, vice president of intelligence for security services firm CrowdStrike.

"I think we are going to see proliferation in cyberoperations -- that's my biggest concern," he says. "When nation-state actors have calculable successes, other nations are going to jump in."

While the APT1 report has largely failed to impact China's espionage activities, the revelation of another nation's cyberoperations has had quite a dramatic impact on its policies. Whistleblower Edward Snowden's leak of documents outlining the extent to which the National Security Agency collected data and communications on foreign and American citizens has resulted in multiple congressional hearings, an investigation by the Obama administration, and pressure from allies, many of whom were the target of the agency's information gathering efforts.

[Leaked operations manual reveals NSA attack techniques that are not significantly better than common cybercrime capabilities, despite their high cost to government. See NSA Hack Attacks: Good Value For Money?.]

The results of the two cases are different for a variety of reasons, but a significant factor is the type of evidence presented in each, says Michael Sutton, vice president of security research for cloud security provider Zscaler.

"In the Mandiant report, the activity is never tied directly to the Chinese government; they are in a position where they can claim plausible deniability," he says. "Compare that to the Snowden revelations: There is no plausible deniability for the U.S. government. It is very clear that this is business as usual for them. When you are looking at the PowerPoint decks, it is hard to deny that that is your program."

In addition, the United States and China have different cultures, and the NSA's ability to collect and sift through data on U.S. citizens does not sit well with people's expectation of privacy and freedom in the United States, Sutton says.

For companies suffering from probable nation-state attacks, the comparison between outing Chinese espionage and the Snowden revelations leaves little hope that naming and shaming will ease the pressure on their defenses. It's unlikely that a hacker embedded in an espionage group will come forward with documents describing their activities.

Yet attackers do react to being spotlighted by investigations into their activities, according to Mandiant.

Following the report, the incident response firm detected some changes in the behavior of APT1, but almost all of the activity has been aimed at evading future detection, according to the company's intelligence group. APT1 issued commands to their infrastructure to communicate through different servers and, in some case, replaced the malware.

"While Mandiant’s APT1 report appears to have affected [its] operations, APT1 is still active using a well-defined attack methodology with a discernible post-report shift towards tools not included in the ... report," says the intelligence group in a statement sent to Dark Reading. "Mandiant has also observed an overall decrease in APT1 operations volume; however, it is possible [the group] shifted operations into areas we currently lack visibility."

Perhaps the most significant impact of the Mandiant report, however, is that it allowed companies to see what they were up against and to have indicators of compromise that could be used to block the activity, says CrowdStrike's Meyers.

"Only by going public will companies get the resources they need to deal with these issues," he says. "That is far better than sitting passively by and letting them attack over and over again."

Until nations take stronger actions against known espionage activity -- and can claim the moral high ground by eliminating their own espionage activities -- companies and individuals will have to rely on the sharing of such information to help them combat such attacks, he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bryan Yurcan
50%
50%
Bryan Yurcan,
User Rank: Apprentice
11/4/2013 | 1:37:21 AM
re: Naming And Shaming Unlikely To Work For Cyberespionage
I agree, information sharing among companies is key to preventing cyber attacks. So called"Naming and shaming," doesn't do much, everyone knows which countries are behind the majority of cyber attacks against the Western world, but as Sutton says it's so convoluted they can claim plausible deniability.
Aviation Faces Increasing Cybersecurity Scrutiny
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/22/2019
Microsoft Tops Phishers' Favorite Brands as Facebook Spikes
Kelly Sheridan, Staff Editor, Dark Reading,  8/22/2019
MoviePass Leaves Credit Card Numbers, Personal Data Exposed Online
Kelly Sheridan, Staff Editor, Dark Reading,  8/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-6154
PUBLISHED: 2019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
CVE-2019-5594
PUBLISHED: 2019-08-23
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
CVE-2019-6695
PUBLISHED: 2019-08-23
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6.2.1 may allow an attacker to implant third-party programs by recreating the image through specific methods.
CVE-2019-12400
PUBLISHED: 2019-08-23
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this im...
CVE-2019-15092
PUBLISHED: 2019-08-23
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.