Showing posts with label Chinese hackers. Show all posts
Showing posts with label Chinese hackers. Show all posts
Wednesday, February 10, 2016
The Institute for Critical Infrastructure Technology (ICIT) Releases the Encyclopedia of the Most Prominent Hacktivists, Nation State, and Mercenary Hackers
The Institute for Critical Infrastructure Technology, a leading cybersecurity think tank, has published its most recent research report entitled Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups. The report is an encyclopedia of bad actors stemming from the nation state, mercenary, and hacktivist arenas and details the characteristics and intricacies of the world’s most prolific threat groups.
Authors James Scott (ICIT Co-Founder and Senior Fellow) and Drew Spaniel (Visiting Scholar) cover threat groups not by use of a particular ranking system, rather by the dominant players categorized by geography, including China, Russia, Iran, and North Korea. Zero days, malware, tool kits, exploit techniques, digital foot prints and targets are covered in-depth. The report covers 40 bad actors including: Blue Termite, the Elderwood Platform, Deep Panda APT 30, APT 2, Tarh Andishan, Ajax, Dark Hotel, Bureau 121, Energetic Bear, Uroburos, Sofacy Group, the “Duke” family, Carbanak, SEA, Animal Farm, Hellsing. and Shrouded.
Monday, June 8, 2015
Who Knows More about You – The US, or China?
While I suspect China lags the US in knowing about its citizens, China might be catching up quickly.
In light of last week's 4 million strong data breach, described as one of the largest thefts of government data ever seen, TK Keanini, CTO at Lancope, offers the following.
"Last Thursday night, U.S. officials said that the Office of Personnel Management (OPM) had suffered a breach. Data from four million current and former federal employees, across numerous government agencies, may have been stolen by Chinese hackers. It does not take a security expert to see a pattern taking place here. Most of the attacks allegedly from China over the past few years have gone after the personal information of US citizens, and there is no sign that this trend will diminish. It is fair to assume at this point in the game, China may have more accurate information on US citizens than the US itself.
"The OPM manages security clearances for various government organisations. During that process, employees must provide extreme detail to every aspect of their life – which is in turn stored and kept in the same systems that were breached.
"Organizational confidence takes a long-time to build, but can (and is) eroded much more quickly. Governmental breaches put these trusted government organizations in the same light as all the recent private company breaches (like Target, Home Depot). Much like your personal medial history, the big difference here is the government has much more sensitive data about their victims, and the victims have no choice in sharing that data.
"This attack once again exemplifies the need for more security resourcing in the federal government and the need for a different more comprehensive approach to incident detection and response. The current methodologies have lead to this breach – not avoided them. Attacks are being detected much too late in the attack continuum. Effective security these days means detecting these threat actors as they operate and before they exfiltrate data. You can't win all the battles but all of these headlines suggest that we are still on the losing side.
"In particular, organizations need to categorize and isolate what they need to protect, place additional controls around that information, and meticulously log & monitor access to that encrypted data.
For example, some past advanced attacks have targeted Windows administrative accounts. Smart organizations have realized this, and created a separate isolated set-up for domain admin accounts, with additional security controls around them (like dual factor authentication, jump boxes that are the only place domain admin activity can occur and logging and monitoring of that separate set-up). This isn’t fast, easy or cheap, but organizations have been pushed into adding these controls by ongoing attacks.
"In addition, organizations need to leverage telemetry, and leave hackers no place to hide. If there is a blind spot on your network, someone will be hiding there. Find them and remove them in a way that they can't get back in. These types of incident detection and response approaches have been vastly under-funded in the past, but as these hacks increase, we will see a shift in focus. Until organizations get better at doing this, we can guarantee that the Chinese will continue to have better data on US citizens than anyone in this country does and this information superiority is what scares me the most."
In light of last week's 4 million strong data breach, described as one of the largest thefts of government data ever seen, TK Keanini, CTO at Lancope, offers the following.
"Last Thursday night, U.S. officials said that the Office of Personnel Management (OPM) had suffered a breach. Data from four million current and former federal employees, across numerous government agencies, may have been stolen by Chinese hackers. It does not take a security expert to see a pattern taking place here. Most of the attacks allegedly from China over the past few years have gone after the personal information of US citizens, and there is no sign that this trend will diminish. It is fair to assume at this point in the game, China may have more accurate information on US citizens than the US itself.
"The OPM manages security clearances for various government organisations. During that process, employees must provide extreme detail to every aspect of their life – which is in turn stored and kept in the same systems that were breached.
"Organizational confidence takes a long-time to build, but can (and is) eroded much more quickly. Governmental breaches put these trusted government organizations in the same light as all the recent private company breaches (like Target, Home Depot). Much like your personal medial history, the big difference here is the government has much more sensitive data about their victims, and the victims have no choice in sharing that data.
"This attack once again exemplifies the need for more security resourcing in the federal government and the need for a different more comprehensive approach to incident detection and response. The current methodologies have lead to this breach – not avoided them. Attacks are being detected much too late in the attack continuum. Effective security these days means detecting these threat actors as they operate and before they exfiltrate data. You can't win all the battles but all of these headlines suggest that we are still on the losing side.
"In particular, organizations need to categorize and isolate what they need to protect, place additional controls around that information, and meticulously log & monitor access to that encrypted data.
For example, some past advanced attacks have targeted Windows administrative accounts. Smart organizations have realized this, and created a separate isolated set-up for domain admin accounts, with additional security controls around them (like dual factor authentication, jump boxes that are the only place domain admin activity can occur and logging and monitoring of that separate set-up). This isn’t fast, easy or cheap, but organizations have been pushed into adding these controls by ongoing attacks.
"In addition, organizations need to leverage telemetry, and leave hackers no place to hide. If there is a blind spot on your network, someone will be hiding there. Find them and remove them in a way that they can't get back in. These types of incident detection and response approaches have been vastly under-funded in the past, but as these hacks increase, we will see a shift in focus. Until organizations get better at doing this, we can guarantee that the Chinese will continue to have better data on US citizens than anyone in this country does and this information superiority is what scares me the most."
Labels:
China,
Chinese hackers,
data loss,
data theft,
PII,
privacy
Tuesday, October 14, 2014
Russian Hackers Spying on NATO: Business as Usual
Following the news of the new Russian 'Sandworm' hack that is exploiting a bug in Microsoft Windows to spy on NATO, EU, Ukraine and others, Tim Erlin, director of IT security and risk strategy for Tripwire explains why this is no surprise:
"It's a short path from shoe phones to zero days. It's simply not surprising that this kind of activity has been going on. Russia, the United States, Britain and others have long histories of very strong and effective spy organizations. There should be little surprise that these groups have continued their missions through the boom of technology.
"Defending against such a targeted attack is extremely difficult. When the attacker is willing to spend significant resources to compromise you specifically, the playing field can be very uneven. As an industry, we tend to focus on the many broad threats that exist, but these kinds of targeted and sophisticated campaigns may actually do more damage."
Conflict and Cooperation in Cyberspace: The Challenge to National Security, edited by Panayotis Yannakogeorgos and Adam Lowther of the Air Force Research Institute, brings together some of the world’s most distinguished military leaders, scholars, cyber operators, and policymakers in a discussion of current and future challenges that cyberspace poses to the United States and the world. Maintaining a focus on policy-relevant solutions, it offers a well-reasoned study of how to prepare for war, while attempting to keep the peace in the cyberspace domain.
Monday, September 8, 2014
Manufacturers Losing Intellectual Property to Security Breaches
While this isn't new, spies have been stealing IP since there's been IP to steal, the techniques have changed. And while the PRC seems to be villain #1, our so-called allies, such as Israel and France, are just as active.
So, what's a person to do? You can start with Trade Secret Theft, Industrial Espionage, and the China Threat.
This book provides an overview of economic espionage as practiced by a range of nations from around the world—focusing on the mass scale in which information is being taken for China's growth and development. It supplies an understanding of how the economy of a nation can prosper or suffer, depending on whether that nation is protecting its intellectual property, or whether it is stealing such property for its own use. The text concludes by outlining specific measures that corporations and their employees can practice to protect information and assets, both at home and abroad.
Wednesday, May 21, 2014
Russia, China urge to develop and introduce rules for information security
First, I don't believe this for a minute. It's like Cold War propaganda. But wait, we're now in a new Cold War.
But you'd think they'd have better translators for this stuff.
I just finished the latest novel from Tom Clancy, Inc., Command Authority. What's interesting about this, aside from Tom, like L. Ron Hubbard, writing books from the grave, is how closely the book comes to recent events in the Ukraine. Of course, the Putin-liked Russian leader controls all media and is given to long diatribes against enemies, internal and external, real and imaginary.
So, I decided to read the last year or so of the Russian English-language press to see how they covered the lead to the Russian invasion of the Urkaine.
What I found, and this applies to the Chinese English-language press, were barely literate articles, many penned by "Americans." What this amounted to was illiterate propaganda. The outrageous claims were funny enough (and I know our politicians are wont to make outrageous claims that can't be substantiated), but the writing was abysmal. (One editorial printed the lyrics to "Feel Like I'm Fixin' to Die Rag" verbatim. I'm willing to bet they didn't get permission to do that.)
Anyway, how effective can propaganda be when its laughable on so many levels?
Thursday, February 6, 2014
Huawei Faces Indian Inquiry over Hacking Claim
Huawei faces Indian inquiry over hacking claim.
Poor Huawei. They can't catch a break. While this doesn't seem to be a supply chain issue, something that fascinates me, it still reflects negatively on the PRC and its quasi-owned companies.
I suspect there are some national security issues at play here, too. China is nothing if not aggressive in pushing the fear buttons on its neighbors.
Poor Huawei. They can't catch a break. While this doesn't seem to be a supply chain issue, something that fascinates me, it still reflects negatively on the PRC and its quasi-owned companies.
I suspect there are some national security issues at play here, too. China is nothing if not aggressive in pushing the fear buttons on its neighbors.
Monday, July 1, 2013
Hong Kong university warns students and staff about US hackers
The India Times reports that following the Snowden leaks, the Chinese University in Hong Kong warned students and staff about basic computer security to ward off an onslaught of US hackers. Is this calling the pot calling the kettle black, or another skirmish in the new Cold War?
Wednesday, May 29, 2013
Confidential report lists U.S. weapons system designs compromised by Chinese cyberspies
Surprise! PLA hackers have stolen weapons plans from the military.
Why does every system have to be Internet facing? I can see commerical enterprises wanting to save money but using public networks, but government and the military? For them, money is merely a way to keep score. It's not real.
Just as two can keep a secret if one of them is dead, if you want a secure system, segregate it; take it offline. While I'm pained to think of the lost information, it's even more painful to know that it could have been prevented.
Why does every system have to be Internet facing? I can see commerical enterprises wanting to save money but using public networks, but government and the military? For them, money is merely a way to keep score. It's not real.
Just as two can keep a secret if one of them is dead, if you want a secure system, segregate it; take it offline. While I'm pained to think of the lost information, it's even more painful to know that it could have been prevented.
Monday, April 29, 2013
China’s Hackers Shifting Focus
According to the Taipei Times, Taiwan's National Security Bureau (NSB) estimates that the PLA’s cyberarmy now numbers more than 100,000, has a budget of more than US$2.71 million and targets telecoms and think tanks. It also believes that the Chinese military has shifted the emphasis of cyberattacks on Taiwan from government institutions to civilian think tanks, telecommunications service providers, Internet node facilities and traffic signal control systems.
This doesn't seem to agree with US evaluations. PRC has long engaged in espionage with the other APT: humans. It's only recently, it seems, that attention has been directed to government, critical infrastructur, and military targets.
This doesn't seem to agree with US evaluations. PRC has long engaged in espionage with the other APT: humans. It's only recently, it seems, that attention has been directed to government, critical infrastructur, and military targets.
Wednesday, April 10, 2013
O-TTPS and Huawei
The Open Group Releases Global Technology Supply Chain Security Standard
From the press release, "Specifically intended to prevent maliciously tainted and counterfeit products from entering the supply chain, this first release of the O-TTPS codifies best practices across the entire COTS ICT product lifecycle, including the design, sourcing, build, fulfilment, distribution, sustainment, and disposal phases."
Meanwhile, the head of Huawei admits "challenges and problems" in America.
So, even though the new O-TTPS is supposed to create trust within the supply chain for COTS, could Huawei, even if it were a software company, ever use it? I doubt any type of certification will overcome the deep mistrust of enterprises owned by either the PRC or the PLA.
From the press release, "Specifically intended to prevent maliciously tainted and counterfeit products from entering the supply chain, this first release of the O-TTPS codifies best practices across the entire COTS ICT product lifecycle, including the design, sourcing, build, fulfilment, distribution, sustainment, and disposal phases."
Meanwhile, the head of Huawei admits "challenges and problems" in America.
So, even though the new O-TTPS is supposed to create trust within the supply chain for COTS, could Huawei, even if it were a software company, ever use it? I doubt any type of certification will overcome the deep mistrust of enterprises owned by either the PRC or the PLA.
Friday, June 29, 2012
GAO: Cyber Threats Facilitate Ability to Commit Economic Espionage
Another day, another warning, another restatement of the obvious. In the summary, it's noted that in past reports the GAO has made hundreds of recommendations to better protect federal systems, critical infrastructures, and intellectual property. The implication is that prior warnings have gone unheeded, and little's been done about these threats and vulnerabilities from both technology and personnel.
Tuesday, March 27, 2012
National Security-Related Agencies Have No ITC Supply Chain Risks?
Last week, the GAO said that defense-related departments have a security problem because of software, hardware, and components sourced or manufactured overseas, especially China. The departments in question don't track these items, and maintain that no threat exists, or the cost of monitoring exceeds the cost of the risk. This is disingenuous at best.
Now, today, the GAO reports that suspect counterfeit electronic parts can be found on DOD supply chain Internet purchasing platforms.
I recall Whitfield Diffie addressing a RSA conference state that one of his greatest security fears is components calling home (to China). This type of threat has movie written all over it, but this doesn't make it any less real.
Australia has no such qualms, however. It's blocked Huawei from bidding on gear for its National Broadband Network. It seems that foreign governments, especially in Asia, are much more aware of these threats. At least the US Congress has blocked sale of some US high-tech companies to Chinese enterprises controlled by the PLA.
There are other IT security lessons that Australia can teach us.
Now, today, the GAO reports that suspect counterfeit electronic parts can be found on DOD supply chain Internet purchasing platforms.
I recall Whitfield Diffie addressing a RSA conference state that one of his greatest security fears is components calling home (to China). This type of threat has movie written all over it, but this doesn't make it any less real.
Australia has no such qualms, however. It's blocked Huawei from bidding on gear for its National Broadband Network. It seems that foreign governments, especially in Asia, are much more aware of these threats. At least the US Congress has blocked sale of some US high-tech companies to Chinese enterprises controlled by the PLA.
There are other IT security lessons that Australia can teach us.
Thursday, March 22, 2012
If we didn't have Google to kick around, I'd have to create it
Well, Google's back in the news, although this is more about the Puzzle Palace (NSA pressed to reveal details on Google deal following Chinese attack).
At this point, Google is still battling Amazon for the top slot on my list of companies I love to hate. Remember when the world hated Microsoft because of its dominance in desktop computing and LANs? They look absolutly altruistic when compared to the undisguised rapacious behavior of Google and Amazon. For a long time I hated Barnes & Noble for putting independent, especially technical, bookstores out of business in the 1990s. Now, I'm praying for its survival under the offensive launched by Amazon on the entire book publishing industry. I still hate Walmart for its business and labor practices, and pioneering the decline of American manufacturing. Channeling this disgust at the "be evil" company and Amazon is cathartic, though, even though I'm spinning my wheels.
What's this go to do with information security? Not much. But it was cathartic.
At this point, Google is still battling Amazon for the top slot on my list of companies I love to hate. Remember when the world hated Microsoft because of its dominance in desktop computing and LANs? They look absolutly altruistic when compared to the undisguised rapacious behavior of Google and Amazon. For a long time I hated Barnes & Noble for putting independent, especially technical, bookstores out of business in the 1990s. Now, I'm praying for its survival under the offensive launched by Amazon on the entire book publishing industry. I still hate Walmart for its business and labor practices, and pioneering the decline of American manufacturing. Channeling this disgust at the "be evil" company and Amazon is cathartic, though, even though I'm spinning my wheels.
What's this go to do with information security? Not much. But it was cathartic.
Friday, March 9, 2012
IT security neglect helps Anonymous: a deliberately contentious statement?
"IT security neglect helps Anonymous." Is this a deliberately contentious statement? Trashing people tasked with the thankless job of administering and securing a network and data isn't helpful. Thanks to the asymetric nature of the threats, it's relatively easier for someone with nothing better to do than attack a network than it is for someone for whom securing a network is just one of many, sometimes onerous, tasks. It's not like infosec people want to make it easy. If anything, the fault lies with whomever makes the decision to make every app Internet-facing. So, it's probably more accurate to state that it's managment neglect that abets hackers.
Thursday, December 22, 2011
China Hackers Hit U.S. Chamber of Commerce
According to this WSJ report, the attacks breached computer systems and stole email. And the story gets better.
"The Chamber continues to see suspicious activity, they say. A thermostat at a town house the Chamber owns on Capitol Hill at one point was communicating with an Internet address in China, they say, and, in March, a printer used by Chamber executives spontaneously started printing pages with Chinese characters."
A thermostat communicating with an IP address in China?! The interconnected, M2M, IoT world--what's not to love?
"The Chamber continues to see suspicious activity, they say. A thermostat at a town house the Chamber owns on Capitol Hill at one point was communicating with an Internet address in China, they say, and, in March, a printer used by Chamber executives spontaneously started printing pages with Chinese characters."
A thermostat communicating with an IP address in China?! The interconnected, M2M, IoT world--what's not to love?
Subscribe to:
Posts (Atom)
