Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

10/30/2013
07:32 PM
50%
50%

Naming And Shaming Unlikely To Work For Cyberespionage

Why a whistleblower's evidence of widespread surveillance by the NSA has caused the U.S. government to react, but Mandiant's revelations about Chinese espionage fail to curb that nation's efforts

In February, incident response firm Mandiant released its much-publicized report outlining the activities of a Chinese espionage group, dubbed APT1, and its connections to the Chinese government. The report linked the group to more than 140 attacks over seven years and postulated that the well-funded actors were likely part of an intelligence unit within the People's Liberation Army.

Initially, the conclusions caused a stir among computer security professionals and policy makers alike. Yet, despite shining the spotlight on the China's connection to the attacks and some uncertain pressure by the U.S. government, the People's Republic of China continued to deny involvement, and the espionage attacks continued to compromise systems.

If companies hoped that shedding light on nation-state attackers would curb their espionage activities, they were disappointed. While the report did a lot to spotlight the issue of nation-state attacks and what companies could do to investigate them, it also showed that plausible deniability is a workable strategy, says Adam Meyers, vice president of intelligence for security services firm CrowdStrike.

"I think we are going to see proliferation in cyberoperations -- that's my biggest concern," he says. "When nation-state actors have calculable successes, other nations are going to jump in."

While the APT1 report has largely failed to impact China's espionage activities, the revelation of another nation's cyberoperations has had quite a dramatic impact on its policies. Whistleblower Edward Snowden's leak of documents outlining the extent to which the National Security Agency collected data and communications on foreign and American citizens has resulted in multiple congressional hearings, an investigation by the Obama administration, and pressure from allies, many of whom were the target of the agency's information gathering efforts.

[Leaked operations manual reveals NSA attack techniques that are not significantly better than common cybercrime capabilities, despite their high cost to government. See NSA Hack Attacks: Good Value For Money?.]

The results of the two cases are different for a variety of reasons, but a significant factor is the type of evidence presented in each, says Michael Sutton, vice president of security research for cloud security provider Zscaler.

"In the Mandiant report, the activity is never tied directly to the Chinese government; they are in a position where they can claim plausible deniability," he says. "Compare that to the Snowden revelations: There is no plausible deniability for the U.S. government. It is very clear that this is business as usual for them. When you are looking at the PowerPoint decks, it is hard to deny that that is your program."

In addition, the United States and China have different cultures, and the NSA's ability to collect and sift through data on U.S. citizens does not sit well with people's expectation of privacy and freedom in the United States, Sutton says.

For companies suffering from probable nation-state attacks, the comparison between outing Chinese espionage and the Snowden revelations leaves little hope that naming and shaming will ease the pressure on their defenses. It's unlikely that a hacker embedded in an espionage group will come forward with documents describing their activities.

Yet attackers do react to being spotlighted by investigations into their activities, according to Mandiant.

Following the report, the incident response firm detected some changes in the behavior of APT1, but almost all of the activity has been aimed at evading future detection, according to the company's intelligence group. APT1 issued commands to their infrastructure to communicate through different servers and, in some case, replaced the malware.

"While Mandiant’s APT1 report appears to have affected [its] operations, APT1 is still active using a well-defined attack methodology with a discernible post-report shift towards tools not included in the ... report," says the intelligence group in a statement sent to Dark Reading. "Mandiant has also observed an overall decrease in APT1 operations volume; however, it is possible [the group] shifted operations into areas we currently lack visibility."

Perhaps the most significant impact of the Mandiant report, however, is that it allowed companies to see what they were up against and to have indicators of compromise that could be used to block the activity, says CrowdStrike's Meyers.

"Only by going public will companies get the resources they need to deal with these issues," he says. "That is far better than sitting passively by and letting them attack over and over again."

Until nations take stronger actions against known espionage activity -- and can claim the moral high ground by eliminating their own espionage activities -- companies and individuals will have to rely on the sharing of such information to help them combat such attacks, he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bryan Yurcan
50%
50%
Bryan Yurcan,
User Rank: Apprentice
11/4/2013 | 1:37:21 AM
re: Naming And Shaming Unlikely To Work For Cyberespionage
I agree, information sharing among companies is key to preventing cyber attacks. So called"Naming and shaming," doesn't do much, everyone knows which countries are behind the majority of cyber attacks against the Western world, but as Sutton says it's so convoluted they can claim plausible deniability.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
4 Security Tips as the July 15 Tax-Day Extension Draws Near
Shane Buckley, President & Chief Operating Officer, Gigamon,  7/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...