Welcome!

Cloud Security Authors: Rishi Bhargava, Elizabeth White, Liz McMillan, Kevin Jackson, Harry Trott

Related Topics: Cloud Security, Government Cloud

Cloud Security: Blog Post

Burning Down the House for Fun and Profit

The Pros and Cons of Naming and Shaming

In October of 1962, during the buildup to the Cuban Missile Crisis, a debate between Adlai Stevenson and Valerian Alexandrovich Zorin at the United Nations Security Council, revealed how far the U.S. was willing to go to produce evidence that the Soviet Union was indeed stockpiling tactical nuclear weapons and ballistic missiles in North America. The Soviets, reluctance to be truthful "in the court of world opinion", forced the hand of the U.S. to produce the very intelligence that the Soviets' claimed the U.S. did not have. Once the overhead photos of the missiles were shared publicly, the Soviets immediately countered that the imagery was fake. We knew the truth then and we know it today, the Soviets had been caught in their lie.

What we saw this week was very similar to what we saw in 1962.  What is most interesting in this case is that the bombshell was not dropped in a stuffy chamber full of wrinkly policy makers, nor was it used by the administration to draw a hard line under Executive Order 13636 that President Obama signed last week. No, the story was brought to light by a single, private sector entity using unclassified information that was publicly available for anyone to put together. By doing so, a precedent has been set. Finally, the veil has been lifted. Now, the public was able take a glimpse at an unseen threat that many within the security industry have been following closely for nearly a decade.  A complex, intangible idea has a face, or rather a building, attached to it.

So what does this mean? Is this good, bad or somewhere in the middle?

Operational Caveat:
Since 13 February, Cyber Squared's ThreatConnect.com has detected an unknown security research group, (believed to be Mandiant) sink-holing known "Comment Group" command and control infrastructure to a variety of named Virtual Private Servers (VPS) ahead of their 19 February report release. All "Comment Group" infrastructure has been freely available to vetted ThreatConnect users since November 2012.

The Pros:
Unfortunately, there are no lanes in the road that point out clear-cut standards by which organizations can measure if they are responsibly or irresponsibly disclosing cyber threat information. While not everyone supports public disclosures of this nature, we can look at both sides of what has occurred and find the benefits and cost of this massive disclosure.

PRO1: Finally an organization has developed a public attribution picture, publicly naming and shaming China for behavior that many have observed internationally for over a decade.

PRO2: A precedent has now been set for the entire security community; there are many others who have chosen to hold off on disclosing details of attacks or operationalizing infrastructure take downs out of concerns with tipping the threat actors and forcing them to change their TTPs and operational security. Now a green-light has been given to disclose similar details and to unilaterally act to take down large chunks of malicious infrastructure associated with APT's.

PRO3: The United States Government (USG) appears to have handed over the issue of Chinese cyber espionage to commercial industry. Some may argue that this level of disclosure should only be part of an official USG response. However, allowing industries to self-regulate and establish norms of internet behavior may serve as a more efficient way to manage threats of this nature.

PRO4: This now gives the security industry something to measure against.  Not only can the industry observe and measure how "Comment Group" will respond to the disclosure, but also their reactions to sweeping sinkhole operations in addition to target reacquisition efforts.  The industry can also pay attention to general responses from other Chinese APT groups.

PRO5: A disclosure at this level raises the issue of nation state sponsored or sanctioned cyber espionage to a larger audience, keeping the issue in the spotlight and increasing overall global awareness of the threat posed by Chinese cyber espionage.

The Cons:
On the flipside, despite the new opportunities that this may present the industry, there are untold numbers of secondary effects that could come to light because of this disclosure.

CON1: The USG appears to be sidestepping a strategic national policy issue by allowing a commercial entity to assume all of the risk by acting as the mouthpiece that may influence U.S.-China relations. If the USG is to send a message, it needs to send it unequivocally with no appearance of a puppet.

CON2: This may increase the precedent for foreign governments or non-U.S. companies that wish to embarrass the U.S. or western allies by attributing details of other sophisticated threats to western powers.

CON3: "Comment Group", while quite effective, could be considered "low hanging fruit".  There were many "eyes on" from across the global security community which were actively monitoring the threat. Many organizations that had adequate visibility of "Comment Group" infrastructure, capabilities and operations now find themselves exposed to the unknown.  Assuming a Chinese military intelligence unit isn't just going to give up and go home, everyone is now equally vulnerable to whatever they use next.

CON4: A single Chinese APT group out of an average of approximately 20 APT groups would only address 5% of the overall problem. By disclosing details of just one threat group, the effect to Chinese cyber espionage operations would be minimal.

CON5: A detailed disclosure at this level reveals a laundry list of specific items that the Chinese can now use as lessons learned to improve upon overall tradecraft. This increases the probability of Chinese counter intelligence operations, operations security, oversight and an overall process improvement which will diminish the security industries ability to effectively combat the threat of Chinese APT's in the future.

Conclusion
Only time will tell if the gains outweigh any losses associated with the disclosure.  Despite growing evidence that this is the work of the Chinese, the official response has been no different than what we have seen before.  A poor embassy spokesperson, followed by spokespeople for the Ministry of Foreign Affairs and Defense, are forced to respond with the standard canned and reflexive denial stating that accusing China without evidence is "irresponsible" and "unprofessional" or that China is ultimately the victim and would never do such a thing. What this spokespersons probably doesn't understand, through the layers of party bureaucracy, is how "irresponsible" and "unprofessional" the Chinese Computer Network Exploitation (CNE) machine actually is. If this is the case, it highlights how intentionally deceptive the PRC is or that the left hand has no idea what the right hand is doing in the shadows.

Ultimately, what is truly "irresponsible" and "unprofessional" is targeting the same individual four times a day through emails written in broken English with an attached implant embedded in a self extracting archive. For those who bear the scars of APT attacks or organizations who specialize in protecting customers from such threats, it becomes quite clear, the Chinese, in their hunger to support their modernization and economic rise, have compromised themselves before a global economy.

More Stories By Rich Barger

Rich is the Chief Intelligence Officer for Cyber Squared and the ThreatConnect Intelligence Research Team (TCIRT) Director.

@ThingsExpo Stories
Extracting business value from Internet of Things (IoT) data doesn’t happen overnight. There are several requirements that must be satisfied, including IoT device enablement, data analysis, real-time detection of complex events and automated orchestration of actions. Unfortunately, too many companies fall short in achieving their business goals by implementing incomplete solutions or not focusing on tangible use cases. In his general session at @ThingsExpo, Dave McCarthy, Director of Products...
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
Everyone knows that truly innovative companies learn as they go along, pushing boundaries in response to market changes and demands. What's more of a mystery is how to balance innovation on a fresh platform built from scratch with the legacy tech stack, product suite and customers that continue to serve as the business' foundation. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, discussed why and how ReadyTalk diverted from healthy revenue and mor...
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
You have great SaaS business app ideas. You want to turn your idea quickly into a functional and engaging proof of concept. You need to be able to modify it to meet customers' needs, and you need to deliver a complete and secure SaaS application. How could you achieve all the above and yet avoid unforeseen IT requirements that add unnecessary cost and complexity? You also want your app to be responsive in any device at any time. In his session at 19th Cloud Expo, Mark Allen, General Manager of...
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
Major trends and emerging technologies – from virtual reality and IoT, to Big Data and algorithms – are helping organizations innovate in the digital era. However, to create real business value, IT must think beyond the ‘what’ of digital transformation to the ‘how’ to harness emerging trends, innovation and disruption. Architecture is the key that underpins and ties all these efforts together. In the digital age, it’s important to invest in architecture, extend the enterprise footprint to the cl...
Bert Loomis was a visionary. This general session will highlight how Bert Loomis and people like him inspire us to build great things with small inventions. In their general session at 19th Cloud Expo, Harold Hannon, Architect at IBM Bluemix, and Michael O'Neill, Strategic Business Development at Nvidia, discussed the accelerating pace of AI development and how IBM Cloud and NVIDIA are partnering to bring AI capabilities to "every day," on-demand. They also reviewed two "free infrastructure" pr...
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
Businesses and business units of all sizes can benefit from cloud computing, but many don't want the cost, performance and security concerns of public cloud nor the complexity of building their own private clouds. Today, some cloud vendors are using artificial intelligence (AI) to simplify cloud deployment and management. In his session at 20th Cloud Expo, Ajay Gulati, Co-founder and CEO of ZeroStack, will discuss how AI can simplify cloud operations. He will cover the following topics: why clou...
"Dice has been around for the last 20 years. We have been helping tech professionals find new jobs and career opportunities," explained Manish Dixit, VP of Product and Engineering at Dice, in this SYS-CON.tv interview at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
More and more brands have jumped on the IoT bandwagon. We have an excess of wearables – activity trackers, smartwatches, smart glasses and sneakers, and more that track seemingly endless datapoints. However, most consumers have no idea what “IoT” means. Creating more wearables that track data shouldn't be the aim of brands; delivering meaningful, tangible relevance to their users should be. We're in a period in which the IoT pendulum is still swinging. Initially, it swung toward "smart for smar...
The Internet of Things will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform and how we integrate our thinking to solve complicated problems. In his session at 19th Cloud Expo, Craig Sproule, CEO of Metavine, demonstrated how to move beyond today's coding paradigm and sh...
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life sett...
We are always online. We access our data, our finances, work, and various services on the Internet. But we live in a congested world of information in which the roads were built two decades ago. The quest for better, faster Internet routing has been around for a decade, but nobody solved this problem. We’ve seen band-aid approaches like CDNs that attack a niche's slice of static content part of the Internet, but that’s it. It does not address the dynamic services-based Internet of today. It does...
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web ...
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.
"We're a cybersecurity firm that specializes in engineering security solutions both at the software and hardware level. Security cannot be an after-the-fact afterthought, which is what it's become," stated Richard Blech, Chief Executive Officer at Secure Channels, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.