Feeds

Security world ill-equipped to solve digital whodunnits

'Unqualified and pedestrian'

Protecting against web application threats using SSL

When anthrax-laced letters killed five people and sickened 17 others shortly after the September 11 terrorist attacks in 2001, investigators were able to pin point the precise lab where the deadly spores were manufactured. And when Confederate General Stonewall Jackson was shot on the battle field some 150 years ago, forensics showed only one of his own forces could have pulled the trigger.

While the physical world is chock full of methods for solving high-stakes whodunits, sleuths in the digital realm remain woefully ill-equipped at figuring out who is behind the increasing number of attacks hitting government, private industry and consumer networks, says Tom Parker, a security researcher who is scheduled to speak on the topic at next week's Black Hat security conference in Las Vegas. That hasn't stopped security researchers, often armed with little more than inferences, from pointing fingers at nation states, and that could have important consequences for geopolitical relations.

“A lot of those efforts are very unqualified and pedestrian,” said Parker, who is director of security consulting services at Washington, DC-based Securicon. “There's really not any science behind the efforts that many people have been making recently that have resulted in stories like China is attacking us, Russia is attacking us, Korea is attacking us.”

Parker holds out the so-called Aurora attacks that hit Google and dozens of other large companies late last year as a prominent example. Google has yet to offer any evidence for its contention that China was behind the attacks besides saying some of them targeted email accounts used by Chinese dissidents. Evidence that error-checking code used in the exploits had circulated for years on English-speaking sites later cast doubt on claims by a private researcher that the code could only have been written by someone fluent in simplified Chinese.

The dearth of commercial products and widespread methods for discovering who is behind online attacks is ironic, Parker says, because many of the raw materials needed have existed for years. A technique known as isomorphism – which quickly spots similarities between two or more pieces of code – is one possible solution. It could be used to identify the developers behind an unknown piece of malware if one or more of their previous works are already known.

Similar techniques – such as small prime product calculation, API structure analysis and Black Axon – could also bring more rigor to investigations.

“It's important to have these tools that non-technical people can use to try and dumb down that knee-jerk reaction to miss-point fingers” said Parker. “There's a lot of people that the second they see a big company get compromised we immediately think its a state-sponsored effort and likewise when we see a power company get some malware we immediately think that it's a targeted attack sponsored by a nation state when in actual fact it turns out to be someone viewing a Viagra commercial they shouldn't have looked at. There needs to be more focus, I think, on the threat rather than on what the malware does to the machine and what the attackers that we really need to be concerned about are doing.”

Parker's talk, titled Finger Pointing for Fun, Profit and War?, is scheduled for Day 1 of the conference. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.