Feeds

NSA tactics no better than a CYBERCRIME GANG, says infosec'er

Detailed analysis reveals they're on par with banking scammers

The Essential Guide to IT Transformation

The NSA operates like a state-sponsored cybercrime gang using much the same tools and techniques as miscreants slinging banking trojans, one cynic has suggested.

Anyone following the Snowden revelations knows by now that the NSA uses exploits and malware to spy on the online activities of targets, but ponytailed infosec expert Bruce Schneier has put together the clearest explanation to date on its methodology for running such attacks.

Encryption guru Schneier has pored over recent Snowden leaks to work out the methodology for deploying Foxacid, the NSA's Exploit Kit.

According to Schneier, the NSA normally carry out reconnaissance prior to tricking their targets into visiting Foxacid exploit servers. Usually the NSA resorts to “man-in-the-middle” hack attempts through an NSA-run set of servers codenamed “Quantum” that sit on the Internet's “backbone”. These redirect targets away from their intended destinations. In other cases, forms of phishing might be deployed.

Targets might be TOR-using terrorism suspects, foreign dignitaries or others targeted by the NSA's cyber-warriors. These tactics exist at the opposite end of the spectrum from dragnet-style programs such as PRISM.

Information on the relative importance and technical sophistication of someone targeted by Foxacid is used to decide the ferocity of a cyber-attack, Schneier explains.

"If the target is a high-value one, Foxacid might run a rare zero-day exploit that it developed or purchased," Schneier explains in a blog post, based on an essay that first appeared in The Atlantic.

"If the target is technically sophisticated, Foxacid might decide that there's too much chance for discovery, and keeping the zero-day exploit a secret is more important. If the target is a low-value one, Foxacid might run an exploit that's less valuable. If the target is low-value and technically sophisticated, Foxacid might even run an already-known vulnerability."

"We know that the NSA receives advance warning from Microsoft of vulnerabilities that will soon be patched; there's not much of a loss if an exploit based on that vulnerability is discovered. Foxacid has tiers of exploits it can run, and uses a complicated trade-off system to determine which one to run against any particular target."

The NSA's Tailored Access Operations (TAO) unit, which runs Foxacid, has detailed rules of engagement and a well-thought-out procedure that allows relatively unskilled operators to act with subtlety and sophistication, Schneier adds.

"Operators running the Foxacid system have a detailed flowchart, with tons of rules about when to stop," Schneier explains. "If something doesn't work, stop. If they detect a PSP, a personal security product, stop. If anything goes weird, stop. This is how the NSA avoids detection, and also how it takes mid-level computer operators and turn them into what they call 'cyberwarriors'. It's not that they're skilled hackers, it's that the procedures do the work for them."

Schneier notes the variety of catchy code-names applied to different approaches of attack by the TAO crew.

"According to a top-secret operational procedures manual provided by Edward Snowden, an exploit named Validator might be the default, but the NSA has a variety of options. The documentation mentions United Rake, Peddle Cheap, Packet Wrench, and Beach Head - all delivered from a Foxacid subsystem called Ferret Cannon."

The security guru contrasts the nuanced attacks carried out by TAO on a tactical level with the blanket collection of data through dragnet programmes favoured on a policy level by the NSA's chiefs.

However some, such as computer security researcher “the grugq”, were less impressed by the NSA's tactical savviness, comparing the spy agency's tools to well-known underground utilities such as the Blackhole Exploit Kit and the ZeuS banking trojan.

The Electronic Frontier Foundation's more serious redux of the latest NSA spying revelations also concludes that the techniques in play aren't particularly sophisticated. EFF reckons knowing more about these approaches might help browser makers – and others – develop more secure technologies.

"The NSA's system for deploying malware isn't particularly novel, but getting some insight into how it works should help users and browser and software vendors better defend against these types of attacks, making us all safer against criminals, foreign intelligence agencies, and a host of attackers," it concludes. ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.