Posts

Showing posts with the label attribution

Attribution: OPM vs Sony

Image
I read  Top U.S. spy skeptical about U.S.-China cyber agreement based on today's Senate Armed Services Committee hearing titled  United States Cybersecurity Policy and Threats . It contained this statement: U.S. officials have linked the OPM breach to China, but have not said whether they believe its government was responsible. [Director of National Intelligence] Clapper said no definite statement had been made about the origin of the OPM hack since officials were not fully confident about the three types of evidence that were needed to link an attack to a given country: the geographic point of origin, the identity of the "actual perpetrator doing the keystrokes," and who was responsible for directing the act. I thought this was interesting for several reasons. First, does DNI Clapper mean that the US government has not made an official statement regarding attribution for China and OPM because all "three types of evidence" are missing, or do we have one...

An Irrelevant Thesis

Image
This week The Diplomat published an article by Dr Greg Austin titled  What the US Gets Wrong About Chinese Cyberespionage . The subtitle teases the thesis: "Is it government policy in China to pass on commercial secrets obtained via cyberespionage to civil sector firms?" As you might expect (because it prompted me to write this post), the author's answer is "no." The following contains the argument: "Chinese actors may be particularly adept in certain stages of economic espionage, but it is almost certainly not Chinese government policy to allow the transfer of trade secrets collected by highly classified intelligence sources to its civil sector firms for non-military technologies on a wide-spread basis . A U.S. influencing strategy toward China premised on the claim that this is China’s policy would appear to be ill-advised based on the evidence introduced so far by the United States in the public domain." (emphasis added) I find it interest...

Elevating the Discussion on Security Incidents

Image
I am not a fan of the way many media sources cite "statistics" on digital security incidents. I've noted before that any "statistic" using the terms "millions" or "billions" to describe "attacks" is probably worthless. This week, two articles on security incidents caught my attention. First, I'd like to discuss the story at left, published 17 February in The Japan Times, titled  Cyberattacks detected in Japan doubled to 25.7 billion in 2014 . It included the following: The number of computer attacks on government and other organizations detected in Japan doubled in 2014 from the previous year to a record 25.66 billion , a government agency said Tuesday. The National Institute of Information and Communications Technology used around 240,000 sensors to detect cyberattacks... Among countries to which perpetrators’ Internet Protocol addresses were traced, China accounted for the largest share at 40 percent, while South K...

Focus on the Threat: Bank Heists

Image
Thief Retrieves Cash, from Bloomberg Businessweek The February 2nd issue of Bloomberg Businessweek featured a story titled Boom: Inside a British Bank-Bombing Spree . The article describes how "five men, dressed all in black" used "crowbars, power tools, coils of flexible tubing, and two large tanks of explosive gas" to blow apart ATMs in the UK, then retrieve cash inside. The story opens by describing a raid that netted "almost £250,000, or about $375,000" and was the group’s biggest score in a single night yet. Their MO, using cheap, common, and legal gas, was nearly impossible to trace, and they left precious little forensic evidence for the police. To stop the rampage, there was little Britain’s banks could do. What is the history of this sort of attack? The article states: Bank security experts think the first ATM gas attack may have been in Italy in 2001. Early statistics are shaky, but by 2005 there were almost 200 across the continent...

A Word of Caution on Fraudulent Routing

Image
If you've read TaoSecurity Blog for a while, you remember me being a fan of companies like Renesys (now part of Dyn Research ) and BGPmon . These organizations monitor Internet-wide routing by scrutinizing BGP announcements, plus other techniques. (I first posted on the topic almost 12 years ago.) I am well aware that an organization, from its own Internet viewpoint , cannot be absolutely sure that the other end of a conversation truly represents the IP address that it seems to be. The counterparty may be suffering a BPG hijack. An attacker may have temporarily positioned itself in BGP routing tables such that the legitimate IP address owner is not the preferred route. There have been many examples of this, and on Thursday Dyn Research posted a great new blog titled The Vast World of Fraudulent Routing that describes six recent examples. A Tweet by Space Rogue about Dyn's post caught my attention. He said: You really want to tell me that an IP Address is enough fo...

How to Answer the CEO and Board Attribution Question

Image
Elements of the Q Model of Attribution, by Thomas Rid and Ben Buchanan Earlier today I Tweeted the following: If you think CEOs & boards don't care about #attribution, you aren't talking to them or working w/them. The 1st question they ask is "who?" I wrote this to convey the reality of incident response at the highest level of an organization. Those who run breached organizations want to know who is responsible for an intrusion. As I wrote in Five Reasons Attribution Matters , your perspective on attribution changes depending on your role in the organization. The question in the title of this blog post is, however, how does one answer the board? It's likely that the board and CEO will be asking the CIO or CISO "who." What should be the response? My recommendation is to respond "how badly do you want to know?" Generally speaking, answering the attribution question is a function of the resources applied to the problem. For e...

Notes on Stewart Baker Podcast with David Sanger

Image
Yesterday Steptoe and Johnson LLP released the 50th edition of their podcast series, titled  Steptoe Cyberlaw Podcast - Interview with David Sanger . Stewart Baker's discussion with New York Times reporter David Sanger (pictured at left) begins at the 20:15 mark. The interview was prompted by the NYT story NSA Breached North Korean Networks Before Sony Attack, Officials Say . I took the following notes for those of you who would like some highlights. Sanger has reported on the national security scene for decades. When he saw President Obama's definitive statement on December 19, 2014 -- " We can confirm that North Korea engaged in this attack [on Sony Pictures Entertainment]. " -- Sanger knew the President must have had solid attribution . He wanted to determine what evidence had convinced the President that the DPRK was responsible for the Sony intrusion. Sanger knew from his reporting on the Obama presidency, including his book Confront and Conceal: Obama'...

Cass Sunstein on Red Teaming

Image
On January 7, 2015, FBI Director James Comey spoke to the International Conference on Cyber Security at Fordham University. Part of his remarks addressed controversy over the US government's attribution of North Korea as being responsible for the digital attack on Sony Pictures Entertainment. Near the end of his talk he noted the following: We brought in a red team from all across the intelligence community and said, “Let’s hack at this. What else could be explaining this? What other explanations might there be? What might we be missing? What competing hypothesis might there be? Evaluate possible alternatives. What might we be missing?” And we end up in the same place. I noticed some people in the technical security community expressing confusion about this statement. Isn't a red team a bunch of hackers who exploit vulnerabilities to demonstrate defensive flaws? In this case, "red team" refers to a group performing the actions Director Comey outlined abov...

Daniel Ellsberg on Secrets

Image
Daniel Miessler just wrote a post about his attitude toward attribution. I'm not going to comment about it, but I wanted to provide the source of the story he mentioned, along with the specific excerpt. It's from Secrets by Daniel Ellsberg. Kevin Drum posted the same excerpt  in 2010, but I'm going to print it here for my reference. As an intro, Ellsberg was working for RAND, and approached Henry Kissinger at a party in 1968. Ellsberg begins:     "Henry, there's something I would like to tell you, for what it's worth, something I wish I had been told years ago. You've been a consultant for a long time, and you've dealt a great deal with top secret information. But you're about to receive a whole slew of special clearances, maybe fifteen or twenty of them, that are higher than top secret.     "I've had a number of these myself, and I've known other people who have just acquired them, and I have a pretty good sense of what the...

Attribution and Declassifying Current Satellite Imagery

Image
I listened to a great Webinar by Rick Holland today about digital threat intelligence. During the talk he mentioned the precedent of declassifying satellite imagery as an example of an action the government could take with respect to "proving" DPRK attribution. Rick is a former military intelligence analyst like me, and I've had similar thoughts this week. They were heightened by this speech excerpt from FBI Director James Comey yesterday: [F]olks have suggested that we have it wrong. I would suggest—not suggesting, I’m saying—that they don’t have the facts that I have—don’t see what I see—but there are a couple things I have urged the intelligence community to declassify that I will tell you right now. I decided to look online for events where the US government declassified satellite imagery in order to support a policy decision. I am excluding cases where the government declassified imagery well after the event. I'm including a few cases where satellites ...

Incentives for Breaking Operational Security?

Image
Thanks Adam Segal for posting a link to a fascinating Wall Street Journal piece titled  Sony Hackers May Have Left Deliberate Clues, Expert Says . From the story by Jeyup S. Kwaak: Apparent slip-ups by the hackers of Sony Pictures that have helped convince U.S. investigators the hackers are North Koreans have a precedent, and may even have been deliberate to win domestic kudos , according to a top cybersecurity expert and former senior North Korean official. The head of a group of hacking experts that have analyzed previous suspected North Korean cyberattacks on South Korea said a record of a North Korean Internet address was also left in a 2013 attack on Seoul because a detour through Chinese servers was briefly suspended, exposing the origin of the incursion... Choi Sang-myung, who is also an adviser to Seoul’s cyberwarfare command, said... [w]hile it was impossible to prove whether the hackers left evidence by mistake or on purpose, that they didn’t fully cover their ...

Five Reasons Attribution Matters

Image
Attribution is the hottest word in digital security. The term refers to identifying responsibility for an incident. What does it matter, though? Here are five reasons, derived from the five levels of strategic thought. I've covered those before, namely in  The Limits of Tool- and Tactics-Centric Thinking . Note that the reasons I outline here are not the same as performing attribution based on these characteristics. Rather, I'm explaining how attribution can assist responsible actors, from defenders through policymakers . 1. Starting from the bottom, at the Tools level, attribution matters because identifying an adversary may tell defenders what software they can expect to encounter during an intrusion or campaign. It's helpful to know if the adversary uses simple tools that traditional defenses can counter, or if they can write custom code and exploits to evade most any programmatic countermeasures. Vendors and software engineers tend to focus on this level beca...

What Does "Responsibility" Mean for Attribution?

Image
I've written a few posts here about attribution . I'd like to take a look at the word "responsibility," as used in the FBI Update on Sony Investigation posted on 19 December: As a result of our investigation, and in close collaboration with other U.S. government departments and agencies, the FBI now has enough information to conclude that the North Korean government is responsible for these actions. While the need to protect sensitive sources and methods precludes us from sharing all of this information, our conclusion is based, in part, on the following... (emphasis added) I'm not in a position to comment on the FBI's basis for its conclusion, which was confirmed by the President in his year-end news conference. I want to comment on the word "responsibility," which was the topic of a February 2012 paper by Jason Healey for The Atlantic Council , titled  Beyond Attribution: Seeking National Responsibility in Cyberspace . In the paper, Jason ...

Spectrum of State Responsibility

Image
"Attribution" for digital attacks and incidents is a hot topic right now. I wanted to point readers to this great paper by Jason Healey at the Atlantic Council titled Beyond Attribution: Seeking National Responsibility in Cyberspace . ACUS published the report in February, but I'm not hearing anyone using the terms described therein. Probably my favorite aspect of the paper is the chart pictured at left. It offers a taxonomy for describing state involvement in digital attacks, ranging from "state-prohibited" to "state-integrated." I recommend using the chart and ideas in the paper as a starting point the next time you have a debate over digital attribution. Tweet

Attribution Using 20 Characteristics

Image
My post Attribution Is Not Just Malware Analysis raised some questions that I will try to address here. I'd like to cite Mike Cloppert as inspiration for some of this post. Attribution means identifying the threat, meaning the party perpetrating the attack. Attribution is not just malware analysis. There are multiple factors that can be evaluated to try to attribute an attack. Timing. What is the timing of the attack, i.e., fast, slow, in groups, isolated, etc.? Victims or targets. Who is being attacked? Attack source. What is the technical source of the attack, i.e., source IP addresses, etc.? Delivery mechanism. How is the attack delivered? Vulnerability or exposure. What service, application, or other aspect of business is attacked? Exploit or payload. What exploit is used to attack the vulnerability or exposure? Weaponization technique. How was the exploit created? Post-exploitation activity. What does the intruder do next? Command and control method. How does th...

Attribution Is Not Just Malware Analysis

Image
In a recent Tweet I recommended reading Joe Stewart's insightful analysis of malware involved in Google v China . Joe's work is stellar as always, but I am reading more and more commentary that shows many people don't have the right frame of reference to understand this problem. In brief, too many people are focusing on the malware alone. This is probably due to the fact that the people making these comments have little to no experience with the broader problems caused by advanced persistent threat. It's enough for them to look at the malware and then move to the next sample, or devise their next exploit, and so on. Those of us responsible for defending an enterprise can't just look at the problem from a malware, or even a technical, perspective. I was reminded of this imperative when I read Waziristan: The Last Frontier in a recent Economist magazine. [I]t is tempting to think Waziristan has hardly changed since those colonial days... Mostly, [the Pakista...