Feeds

Foreign intelligence agencies are biggest online threat, ex-Fed warns

Pot, meet the kettle of color – allegedly

5 things you didn’t know about cloud backup

Black Hat 2012 Former FBI executive assistant director Shawn Henry has warned that the biggest threat online comes not from terrorists or hackers, but from foreign intelligence organizations looking to steal intellectual property.

"The threat from computer attack is the most significant threat we face as a society, other than a weapon of mass destruction," he said in his opening keynote at the Black Hat 2012 conference in Las Vegas. "Everything we do – R&D, intellectual property, and corporate strategies – is stored or transmitted electronically. The DNA of companies is available to bad guys."

Henry said that the FBI had seen cases where a company had lost a billion dollars of intellectual property in a weekend. Other companies were facing a stacked deck in trade negotiations, he said, because all too often their opposite numbers know what their negotiating positions will be.

Some might say this is a case of the pot calling the kettle black. It has been over a decade since the first complaints from the EU that the ECHELON eavesdropping system was being used to spy on competitors of US corporations – but when El Reg raised this, Henry denied that the US had ever carried out such spying.

Shawn Henry

Spies like us play nice, Henry asserts

This may be true now, but it was not always so, said Marcus Ranum, a Black Hat alumnus and faculty member of the Institute for Applied Network Security.

"Our entire industrial revolution was based on stolen European technology," said Ranum. "We're complaining now we are on top, but it's buyer's remorse. There are a lot of corporations who exposed far too much information online, and rather than fixing the problem, let's blame the Chinese."

The answer to the cybersecurity conundrum, Ranum opined, was to get a lot more proactive against threats by sharing information between the government and the private sector. There are a number of bills being considered by Congress to make this easier, and he acknowledged that in the past this had been too much of a one way street, with the government taking in information but not sharing it.

A proactive response doesn't mean the NSA hacking the hackers, he said, but instead taking an attitude to building defensive systems so that if and when a breach occurs, the attackers either don't get the information they are after, or they get wrong information.

"There's denial and deception, corrupt packets and misinformation, so that when you sit down at negotiation they have the wrong answers to the test," Henry explained. "You can cause them pain if they've spent four months and two zero-day attacks to get on there and then find they have the wrong missile and it doesn't even work."

Rather than basing CSO and CIO bonuses on stopping breaches in the network, companies should aim to find out about a breach quickly after they happen, he said. A secure perimeter is impossible; instead, we need to work on mitigation, and that would take the active support of Black Hat delegates.

While the industry has woken up to this threat in the last few years, there were still not enough people taking it seriously, Henry said, adding that it will take a serious physical attack launched online to put it to the top of the agenda. The intelligence community had heard of Osama bin Laden for years, but it wasn't until the world watched the planes hitting the buildings that the threat was taken seriously. ®

Next gen security for virtualised datacentres

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.