Click here to close now.

Welcome!

Security Authors: Tim Hinds, Elizabeth White, Esmeralda Swartz, Liz McMillan, Adam Vincent

Related Topics: Security, XML, Web 2.0, Open Web

Security: Article

Victim-nomics: Estimating the “Costs” of Compromise

Should you pay now or pay later?

Since launching ThreatConnect.com, Cyber Squared's Intelligence Support Team has become more effective in managing, analyzing and sharing our Threat Intelligence. While understanding the threat remains one of our core requirements, we have also begun to fill a key gap that, we feel, many within the industry are failing to address.

Providing effective Threat Intelligence requires more than just characterizing the threat from a technical perspective.  Instead, you must strike a balance between providing technical context as well as non-technical relevancy to the victim.  Industry report authors will often admire the cyber espionage problem all the while promoting their technical talents.  Unfortunately, these overly technical threat details are not easily interpreted or acted upon by today's non-technical business leaders.  So, ultimately, this shortcoming often overwhelms and distances the customer from the reality of the issue. It also reduces their ability to fully appreciate and understand how an investment toward Threat Intelligence can protect their business operations and enhance their overall corporate risk mitigation strategy.

Caveats
In the following scenario, we have masked the possible victim companies in an effort to protect their identities and have addressed the threat and its infrastructure in very general terms to acknowledge operational equities without contextually identifying the possible victim companies. We have used the data obtained in our recent discovery to walk through several hypothetical scenarios while making assumptions that give the reader a better understanding of the potential financial impact of dealing with a targeted attack.  Finally, we have notified the appropriate authorities and possible victim companies, so that they are aware of the threat and the tailored infrastructure which we believe may be directed against them or their customers.

The Facts
While recently researching a known threat group within ThreatConnect.com, we identified several interesting observables associated with targets of a single Chinese-based Advanced Persistent Threat (APT) group.  Over the course of seven days, we watched the adversary tailor their command and control infrastructure toward the specific target companies and industries.  Ten suspected targets were readily identified; they consisted of U.S. based, publicly and privately held companies across the following industries:

  • Mining & Metals
  • Aerospace & Defense
  • Manufacturing & Fabrication
  • Construction & Engineering

We researched the collective group of target organizations and found that the sum of the companies' annual revenues was approximately $54 Billion dollars.  The relative size of each company and specific industries give us insights into what the intelligence collections requirements of the attackers may have been at the time of compromise.

Company

Rounded Revenue

U.S. Company 1

$26,000,000,000

U.S. Company 2

$11,000,000,000

U.S. Company 3

$6,000,000,000

U.S. Company 4

$5,000,000,000

U.S. Company 5

$4,000,000,000

U.S. Company 6

$1,500,000,000

U.S. Company 7

$600,000,000

U.S. Company 8

$20,000,000

U.S. Company 9

$20,000,000

U.S. Company 10

$2,500,000

Total:

$54,142,500,000

In this use case, we made some assumptions based on the information available to us.  Our first assumption was that the victim companies were likely committed to making a short to mid-term investment in mitigating the immediate risk and eradicating the threat from their network.  Unfortunately, we did not have any data available to us that revealed the severity of the compromise nor did we have access to the actual budgets or investments toward a response and future threat mitigation efforts in which these respective companies may choose to make.

The cost of getting "RSA'ed":
When making assumptions, it is important that we compare apples to apples.  We can assess with a high level of confidence that the threat we are monitoring in this case is an APT of Chinese origin.  We can confidently assess that the threat is most likely persisting within the respective enterprises with the intent of conducting long term data exfiltration of proprietary information from the respective organizations.

One example that helped us put the scenario in perspective is from the 2011 RSA breach.  Between April and June 2011, RSA spent $66 million dollars in the aftermath of a March 2011 APT breach, which also resulted in the compromise of information associated with RSA's SecurID two-factor authentication technology.   It is important to note that the $66 million cleanup figure did not include the post breach expenses from the first quarter of 2011 when EMC began investigating the breach, nor does it account for any of the long-term associated costs.  EMC's 2011 earnings statement cited a consolidated revenue of $20 billion dollars.  The $66 million cleanup figure would account for 0.33% of EMC's overall $20 billion dollar revenue.  However, if we apply the same $66 million cleanup costs for RSA's total revenue of $828.2 million for 2011, we find that the intrusion had a direct impact of 7.96% of RSA's 2011 revenue.

What if?
All of the target organizations are not the same.  Their roles, sizes and revenues within their respective industries all differ.  Furthermore, many of these companies do not have a parent company the size of EMC which could absorb the cost of a $66 million dollar incident. However, each organization could respond and invest in a similar manner as RSA.  If we theorize that each company identified were to invest 7.96%, of their annual revenues to mitigate the effects of this persistent APT, the effect would be:

Company

Rounded Revenues

Cost of getting "RSA'ed"

U.S. Company 1

$26,000,000,000

$2,069,600,000

U.S. Company 2

$11,000,000,000

$875,600,000

U.S. Company 3

$6,000,000,000

$477,600,000

U.S. Company 4

$5,000,000,000

$398,000,000

U.S. Company 5

$4,000,000,000

$318,400,000

U.S. Company 6

$1,500,000,000

$119,400,000

U.S. Company 7

$600,000,000

$47,760,000

U.S. Company 8

$20,000,000

$1,592,000

U.S. Company 9

$20,000,000

$1,592,000

U.S. Company 10

$2,500,000

$199,000

Total:

$54,142,500,000

$4,309,743,000

Irrespective of size, could these companies really all afford a 7.96% hit in response to a major enterprise breach? Considering that many of the victims are either publicly traded or provide direct support to U.S. Government funded programs, most would be compelled to notify various stakeholders, such as investors, the U.S. Security Exchange Commission, and their primary customers or government contract managers.

Based on our long term understanding of this threat group, we are almost certain that a resourced Chinese state sanctioned or sponsored threat group is responsible for establishing and using the observed command and control infrastructure we have detected within ThreatConnect.com.  We also conclude that the threat group is likely conducting economic espionage on behalf of an unknown Chinese benefactor who may be in an advantageous position to operationalize and monetize the information.  What we do not know is who, when or how the information may be employed.

The targeted and persistent nature of the threat suggests that the threat actor knows what type of information they want to acquire and are concentrating their collection by targeting multiple victims within overlapping industries.  Left unchecked, enterprise compromises could facilitate access to corporate intellectual property such as research and development, confidential corporate insights, and operational plans.  Access to confidential information regarding the mining and metals industry, as well as U.S. defense aerospace, engineering and fabrication could allow the attacker to enable the manipulation of markets, conduct restricted defense related technology transfers and or obtain unfair advantages within international business or trade negotiations.

Conclusion
Until more companies come forward with details of Chinese corporate espionage, little data will be available to us regarding the associated short and long term costs. In 2011 the U.S. International Trade Commission issued a report titled "China: Effects of Intellectual Property Infringement and Indigenous Innovation Policies on the U.S. Economy".  The report details estimates of Chinese Intellectual Property Rights (IPR) infringement had cost the U.S. economy approximately $48 billion in 2009 alone, caveating the $48 billion figure that many companies were unable to quantify their losses.  The ITC report also highlighted that if China improved their current international obligations to protect and enforce IPR, 2.1 million jobs could have been created in the U.S.

Although there are numerous variables that cannot be accounted for with the data available to us, we can apply a simple model based on the RSA data that supports our hypothetical scenario and begin to see what the financial and economic effects would be across ten companies of various industries and revenues.  It is important to understand the scenario outlined above is associated with a real threat that has tailored their infrastructure and is likely exploiting the U.S. companies. Any associated enterprise exploitation would have an obvious direct and indirect effect to each company's respective annual revenues.   All of the threat data obtained is based on real-world data collected and analyzed within ThreatConnect.com.

More Stories By Rich Barger

Rich is the Chief Intelligence Officer for Cyber Squared and the ThreatConnect Intelligence Research Team (TCIRT) Director. Rich has over 17 years of experience supporting the commercial sector, defense industry, and intelligence community with threat intelligence and computer network operations. Rich is a passionate and creative thought leader that has led talented teams of researchers in producing quality analysis and actionable intelligence. After his commitment to the United States Army, Rich has supported the U.S. Army Command and Control Support Agency, the U.S. Army 1st Information Operations Command, the Joint Task Force Global Network Operations, and the NSA/CSS Threat Operations Center. Rich possesses a variety of industry certifications and a BS in Information Systems Security with Honors from American Military University.

@ThingsExpo Stories
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
SYS-CON Events announced today that CommVault has been named “Bronze Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY, and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. A singular vision – a belief in a better way to address current and future data management needs – guides CommVault in the development of Singular Information Management® solutions for high-performance data protection, universal availability and sim...
Cloud is not a commodity. And no matter what you call it, computing doesn’t come out of the sky. It comes from physical hardware inside brick and mortar facilities connected by hundreds of miles of networking cable. And no two clouds are built the same way. SoftLayer gives you the highest performing cloud infrastructure available. One platform that takes data centers around the world that are full of the widest range of cloud computing options, and then integrates and automates everything. Join SoftLayer on June 9 at 16th Cloud Expo to learn about IBM Cloud's SoftLayer platform, explore se...
The list of ‘new paradigm’ technologies that now surrounds us appears to be at an all time high. From cloud computing and Big Data analytics to Bring Your Own Device (BYOD) and the Internet of Things (IoT), today we have to deal with what the industry likes to call ‘paradigm shifts’ at every level of IT. This is disruption; of course, we understand that – change is almost always disruptive.
SYS-CON Media announced today that 9 out of 10 " most read" DevOps articles are published by @DevOpsSummit Blog. Launched in October 2014, @DevOpsSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce softw...
Wearable technology was dominant at this year’s International Consumer Electronics Show (CES) , and MWC was no exception to this trend. New versions of favorites, such as the Samsung Gear (three new products were released: the Gear 2, the Gear 2 Neo and the Gear Fit), shared the limelight with new wearables like Pebble Time Steel (the new premium version of the company’s previously released smartwatch) and the LG Watch Urbane. The most dramatic difference at MWC was an emphasis on presenting wearables as fashion accessories and moving away from the original clunky technology associated with t...
The world's leading Cloud event, Cloud Expo has launched Microservices Journal on the SYS-CON.com portal, featuring over 19,000 original articles, news stories, features, and blog entries. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. Microservices Journal offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. Follow new article posts on Twitter at @MicroservicesE
SYS-CON Events announced today that Site24x7, the cloud infrastructure monitoring service, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Site24x7 is a cloud infrastructure monitoring service that helps monitor the uptime and performance of websites, online applications, servers, mobile websites and custom APIs. The monitoring is done from 50+ locations across the world and from various wireless carriers, thus providing a global perspective of the end-user experience. Site24x7 supports monitoring H...
After making a doctor’s appointment via your mobile device, you receive a calendar invite. The day of your appointment, you get a reminder with the doctor’s location and contact information. As you enter the doctor’s exam room, the medical team is equipped with the latest tablet containing your medical history – he or she makes real time updates to your medical file. At the end of your visit, you receive an electronic prescription to your preferred pharmacy and can schedule your next appointment.
The WebRTC Summit 2014 New York, to be held June 9-11, 2015, at the Javits Center in New York, NY, announces that its Call for Papers is open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 16th International Cloud Expo, @ThingsExpo, Big Data Expo, and DevOps Summit.
SYS-CON Events announced today that SafeLogic has been named “Bag Sponsor” of SYS-CON's 16th International Cloud Expo® New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. SafeLogic provides security products for applications in mobile and server/appliance environments. SafeLogic’s flagship product CryptoComply is a FIPS 140-2 validated cryptographic engine designed to secure data on servers, workstations, appliances, mobile devices, and in the Cloud.
@ThingsExpo has been named the Top 5 Most Influential M2M Brand by Onalytica in the ‘Machine to Machine: Top 100 Influencers and Brands.' Onalytica analyzed the online debate on M2M by looking at over 85,000 tweets to provide the most influential individuals and brands that drive the discussion. According to Onalytica the "analysis showed a very engaged community with a lot of interactive tweets. The M2M discussion seems to be more fragmented and driven by some of the major brands present in the M2M space. This really allows some room for influential individuals to create more high value inter...
SYS-CON Events announced today the IoT Bootcamp – Jumpstart Your IoT Strategy, being held June 9–10, 2015, in conjunction with 16th Cloud Expo and Internet of @ThingsExpo at the Javits Center in New York City. This is your chance to jumpstart your IoT strategy. Combined with real-world scenarios and use cases, the IoT Bootcamp is not just based on presentations but includes hands-on demos and walkthroughs. We will introduce you to a variety of Do-It-Yourself IoT platforms including Arduino, Raspberry Pi, BeagleBone, Spark and Intel Edison. You will also get an overview of cloud technologies s...
Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 16th Cloud Expo at the Javits Center in New York June 9-11 will find fresh new content in a new track called PaaS | Containers & Microservices Containers are not being considered for the first time by the cloud community, but a current era of re-consideration has pushed them to the top of the cloud agenda. With the launch of Docker's initial release in March of 2013, interest was revved up several notches. Then late last...
SOA Software has changed its name to Akana. With roots in Web Services and SOA Governance, Akana has established itself as a leader in API Management and is expanding into cloud integration as an alternative to the traditional heavyweight enterprise service bus (ESB). The company recently announced that it achieved more than 90% year-over-year growth. As Akana, the company now addresses the evolution and diversification of SOA, unifying security, management, and DevOps across SOA, APIs, microservices, and more.
The Open Compute Project is a collective effort by Facebook and a number of players in the datacenter industry to bring lessons learned from the social media giant's giant IT deployment to the rest of the world. Datacenters account for 3% of global electricity consumption – about the same as all of Switzerland or the Czech Republic -- according to people I met at the recent Open Compute Summit in San Jose. With increasing mobility at the edge of the cloud and vast new dataflows being predicted with the growth of the Internet of Things (and The Coming Age of Many Zettabytes) in the near...
GENBAND has announced that SageNet is leveraging the Nuvia platform to deliver Unified Communications as a Service (UCaaS) to its large base of retail and enterprise customers. Nuvia’s cloud-based solution provides SageNet’s customers with a full suite of business communications and collaboration tools. Two large national SageNet retail customers have recently signed up to deploy the Nuvia platform and the company will continue to sell the service to new and existing customers. Nuvia’s capabilities include HD voice, video, multimedia messaging, mobility, conferencing, Web collaboration, deskt...
SYS-CON Events announced today that Cisco, the worldwide leader in IT that transforms how people connect, communicate and collaborate, has been named “Gold Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Cisco makes amazing things happen by connecting the unconnected. Cisco has shaped the future of the Internet by becoming the worldwide leader in transforming how people connect, communicate and collaborate. Cisco and our partners are building the platform for the Internet of Everything by connecting the...
15th Cloud Expo, which took place Nov. 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA, expanded the conference content of @ThingsExpo, Big Data Expo, and DevOps Summit to include two developer events. IBM held a Bluemix Developer Playground on November 5 and ElasticBox held a Hackathon on November 6. Both events took place on the expo floor. The Bluemix Developer Playground, for developers of all levels, highlighted the ease of use of Bluemix, its services and functionality and provide short-term introductory projects that developers can complete between sessions.
Temasys has announced senior management additions to its team. Joining are David Holloway as Vice President of Commercial and Nadine Yap as Vice President of Product. Over the past 12 months Temasys has doubled in size as it adds new customers and expands the development of its Skylink platform. Skylink leads the charge to move WebRTC, traditionally seen as a desktop, browser based technology, to become a ubiquitous web communications technology on web and mobile, as well as Internet of Things compatible devices.