ellen_messmer
Senior Editor, Network World

Decoy networks, separation tactics part of AT&T security chief’s infrastructure protection plans

News
Jan 14, 201110 mins

Edward Amoroso's book, 'Cyber Attacks: Protecting National Infrastructure,' envisions massive data collection for purposes of security

As chief security officer at AT&T, Edward Amoroso has long observed how cyberattacks impact customer and service-provider networks. In his newly published book, Amoroso says it’s time to unite to create the equivalent of a national cyber-protection shield to guard against attacks on industry and government networks by terrorists, state-sponsored attackers and plain old thieves.

Some of his ideas are controversial and bound to incite debates about privacy and practice. For instance in his book, “Cyber Attacks: Protecting National Infrastructure,” Amoroso suggests using large-scale and coordinated collection of network-traffic data as well as security information from end-user desktops to pinpoint botnet-compromised computers, identify suspicious anomalies and trace attack paths.

IN DEPTH: Cyberattacks seen as top threat to zap U.S. power grid

Amoroso is essentially taking widely accepted organizational security practices and suggesting that they be scaled up to a national level to protect critical infrastructure industries, such as energy generation, banking, chemical and defense manufacturing and telecommunications.

Cover of Cyber Attacks: Protecting National Infrastructure

“In my work at AT&T, I have a very unique vantage point,” says Amoroso, who is a senior vice president and CSO at the telecommunications company. He says he’s troubled by what he has seen for many years in critical network services, such as those for industrial SCADA systems in power-generation facilities, so exposed to network attacks due to improper access controls and connections.

After the terrorist attacks of Sept. 11, 2001, his sense of how vulnerable our national infrastructure services are only increased. Amoroso had already started writing a manuscript on the topic of national infrastructure protection, which would become his now-published “Cyber Attacks” book.

In it he writes: “The current risk of catastrophic cyber attack to national infrastructure must be viewed as extremely high, by any realistic means. Taking little or no action to reduce this risk would be a foolish national decision.”

“There are attacks against data centers in many, many sectors where services are in place,” says Amoroso about what he sees in his job at AT&T. “It’s frightening when you think about a power plant. Do you need to understand the traffic going in and out of it?” The answer would seem to be a definite yes, but few companies of any stripe really grasp this, he says. When personnel at AT&T ask for permission to divert attack traffic coming at them from upstream — “it’s diverting traffic away from a target” — more often than not, customers decline and still want it reach their gateway points.

Insider attacks are also far more commonplace in the enterprise than anyone would like to admit, Amoroso says. “People don’t like to talk about it,” he says. “The problem is coming from someone with legitimate access” who wants “to steal data useful to them.”

In his book, Amoroso argues any national infrastructure protection program is going to require network-based firewalls on high-speed networks specifically managed by service providers to throttle distributed denial-of-service (DDoS) attacks and designed specifically for SCADA protocols.

He also presents ideas that have almost no precedence in general practice today. Specifically, he suggests starting a “National Deception Program” that would be “created based on a collection of traps strategically planted across national infrastructure components, tied together by some sort of deception analysis backbone.” The National Deception Program would support networks that operate like a decoy with fake content and the ability to recognize an attacker is up to no good. Another idea, a “National Separation Program,” would ensure some critical infrastructure is simply not given general access to the Internet.

The goal of decoy networks would be to discover attackers going after critical networks used by energy, banking services, telecom, and other industrial and government resources that collectively comprise critical national infrastructure. Amoroso, who’s also a professor at Stevens Institute of Technology, says not enough research is dedicated today to the idea of using deception as a network defense and he’d like to see that explored further.

He admits many of these ideas are certain to face opposition based on privacy arguments and practical deployment obstacles, but he asks that anyone debating these ideas keep an open mind.

His book spells out his vision for security improvements on a national scale — if the service provider industry, customers, the government, and the American public at large can agree they should occur and unite in new ways for purposes of national network security protection of critical services.

In his book, Amoroso points to the rise of the botnet over the last five years as the single most significant type of attack weapon wielded by cyberattackers who can remotely control many thousands of compromised computers infected with bot malware.

“Any serious present study of cyber security must acknowledge the unique threat posed by botnets,” Amoroso writes in his book. “Virtually any Internet-connected system is vulnerable to major outages from a botnet-originated DDoS attack. The physics of the situation are especially depressing; that is, a botnet that might steal 500 Kbps of upstream capacity from each bot (which would generally allow for concurrent normal computing and networking) would only need three bots to collapse a target T1 connection. Following this logic, only 16,000 bots would be required theoretically to fill up a 10-Gpbs connection. Because most of the thousands of botnets that have been observed on the Internet are at least this size, the threat is obvious; however, many recent and prominent botnets such as Storm and Conficker are much larger, comprising as many as several million bots, so the threat to national infrastructure is severe and immediate.”

The problem is that ordinary, everyday PCs used by people in the U.S. and elsewhere are infected with botnet malware of which they’re unaware. Typical computers in the home and office around the world are “Windows-based operating system on an Intel platform with Internet Explorer being used for Google searches,” writes Amoroso, lamenting that the “nondiversity of end-user configurations plays right into the hands of the botnet operator. Combine this with the typically poor system administrative practices on most PCs, and the result is lethal. Worse, many security managers in business and government do not understand this risk.”

Amoroso hopes for more diversity, perhaps because some secure form of cloud-based computing or mobile devices might one day present a different prospect. For networks as well, he encourages the adoption of a “National Diversity Program” which “would require coordination between companies and government agencies” to tackle issues such as critical-patch modeling.” He’d also like to see a single agreed-upon audit standard for national infrastructure protection.

Bring on the data

Amoroso steps straightforward into areas he knows will be controversial. He presents the idea for massive data collection on a national level, first by local or regional sources, is order to get a bird’s eye view of what is going on from a technical level, such as detecting the kinds of anomalies that often indicate some kind of attack is commencing.

“Such a national collection process does not exist today in any organized manner,” he points out. “To build one will require considerable resolve. From a technical perspective, each collection point requires that decisions be made about which data is gathered, what methods will be used for collection, how it will be used, and how it will be protected.”

Amoroso indicates he’s wary of the way he’s seen some agencies sometimes promote information-sharing with companies in various industry sectors.

“Government groups are political by nature, and sensitive information provided by industry serves as a type of ‘power currency’ that is used to push political objectives within government,” he writes in his book. “That is rarely stated, but no government official would deny its validity.”

He goes on to say that information-sharing between government and industry “tends to provide spotty results for both parties. The idea of government providing direct cyber security assistance to industry, for example, is mostly theoretical.” He says the political aspects in information-sharing as they exist today, which are sometimes fumbled through mishandling of confidential information, should be set aside in favor of finding “an agreed-upon situational awareness objective.”

In the kind of data collection program suggested by Amoroso, these could be collection of data from mainframes, servers and PCs as well.

“Operating system logs, mainframe collection event summaries, and PC history records provide excellent evidence that malicious activity might be ongoing,” he writes.

While such ideas might be well-accepted technically within a single enterprise, the question of how data collection of data in companies and government agencies for purposes of national infrastructure protection would play out in the area of public debate is another matter.

Amoroso’s idea is that large-scale and distributed security information and event management (SIEM) systems, the type of security-analysis and correlation gear increasingly in use today in the enterprise, would be the means to analyze collected data to pinpoint on as near a real-time basis as possible any national infrastructure security problems that arise. These SIEM systems would be part of distributed security operations centers, or “fusion centers,” monitoring national critical infrastructure round the clock.

“Readers might cringe at the idea of collecting data in this manner, especially from end-user PCs scattered across a nation, but this practice is more common than one might think,” he writes. “Every large enterprise and government agency, for example, routinely embeds integrity management software, such as tripwire functionality, into their mainframes and servers. Furthermore, almost every enterprise and agency uses software agents on PCs to collect relevant security and management data. Perhaps ironically, botnet operators have also perfected the idea of collecting data from massive numbers of end-user computers for the purpose of an attack. The idea that this general schema would be extended to benevolent national infrastructure protection seems straightforward.”

He acknowledges the potential for abusing such a system cannot be dismissed. But other possibilities, he offers, include “some sort of citizen-sponsored, citizen-run, grassroots data collection effort for PCs and servers, where participants agree to provide security information to a massive distributed system of peers. Such a system would not perfectly match the geographic or political perimeter of a nation, and many citizens would refuse to participate based on principle. Few members, however, of massive peer-to-peer networks for music or video complain about the privacy implications of running such software, often questionable or illegal, on their local machine. They just enjoy getting free content. The idea that a similar construct could be used to help secure national infrastructure would require demonstrating some sort of benefit to participants.”

Amoroso admits, “This may not be possible, but the effort is worthwhile from a security perspective because data collected from a massive deployment of computers across a given nation would provide a valuable and unmatched window into the security posture of national infrastructure.”

Having expressed these ideas, which are certain to prompt debate, Amoroso says any attempt to bring ideas he’s outlined in his book into fruition will require cooperation among service providers, participation by the main industries considered to be critical to the national infrastructure, and government.

He notes there are industry-related groups today where service providers come together to discuss security issues. These include the North American Network Operators Group (NANOG) and the Network Security Telecommunications Advisory Committee (NSTAC).

As to how any of this should play out, Amoroso answers that government could be expected to take the lead, but individual industries such as banking, which coordinate well today through the BITS division of the Financial Services Roundtable, might well decide to try something without government. Regardless, Amoroso says he’d be glad to just see a start towards well-organized national critical infrastructure protection.