Greater resource-sharing needed to fight growing cyberthreats
SAN FRANCISCO— IT executives who flocked to the RSA Conference this week heard more evidence that enterprise networks are increasingly vulnerable, while cybercriminals are becoming better organized and more dangerous. An estimated 250,000 computers are compromised every day by botherders, according to Robert Holleyman, president and CEO of the Business Software Alliance (BSA). The number of exploits is seven times higher than it was a year ago, and the cyberthreat is “growing exponentially,” he said.
SAN FRANCISCO— IT executives who flocked to the RSA Conference this week heard more evidence that enterprise networks are increasingly vulnerable, while cybercriminals are becoming better organized and more dangerous.(BSA). The number of exploits is seven times higher than it was a year ago, and the cyberthreat is “growing exponentially,” he said.
An estimated 250,000 computers are compromised every day by botherders, according to Robert Holleyman, president and CEO of the Business Software Alliance
While vendors are rallying to improve enterprise security options, no one suggests it will be easy. A number of the 550 speakers at RSA highlighted the need for more industry collaboration to better fight the threats.
Microsoft championed the need for a new generation of secure systems, an idea that the company is calling end-to-end trust. Craig Mundie, Microsoft’s chief research and strategy officer, called for industry cooperation to work out what protocols and formats will be needed to create these end-to-end trust systems, which could enable people to establish trust and disclose private information electronically in a manner similar to how it’s done in the real world.
Among the challenges are creating devices with hardware-based authentication, designing operating systems and programs that can talk to other programs about their own trustworthiness, and devising ways of keeping track of where data has been, Mundie said. “We need a lot of work; we can’t just do this by ourselves,” he said.
Separately, Art Coviello, executive vice president of EMC’s RSA division, said that security systems have a long way to go before they are intuitive. “Existing security technology … abounds with failures,” he said. “Tools aren’t even close to behaving the way that people think.”
He called for a “thinking security ecosystem that works across all components of the infrastructure.”collaboration with Cisco at the show. The two companies announced plans to do more to combine network security technology from Cisco and data security tools from EMC’s RSA division, focusing initially on data loss prevention, data center security, and data encryption and key management.
Toward that end, EMC highlighted its
By joining together, the companies can cover everything from data centers and servers to individual employees’ PCs, plus the network that connects them, said Richard Palmer, senior vice president and general manager of Cisco’s Security Technology Group.
In a demonstration of RSA’s data classification technology working with the Cisco Security Agent (CSA), the companies simulated an employee accidentally trying to copy a document containing customer credit-card numbers onto an external storage device. CSA produced a pop-up warning to the employee that included a box where the employee could give a business justification for going ahead with the process. Another tool let the user clean out the sensitive information before copying the document. Lessons learned from such incidents, if they happened frequently, could point to changes in business processes, the companies said.
Where the threats are
So, which threats are most pressing? For enterprises, one area of particular concern is browser-based exploits, which are branching out into such exotic areas as gaming, experts told RSA’s 17,000 attendees
New attacks from games and virtual-world Web sites can deliver bot-like control of browsers to attackers, said Ed Skoudis, a security consultant with Intelguardians. All that’s needed is for the infected image of an avatar to appear. “The character walks into view of the screen, and I take over the box,” he said.
Compromised browsers can act as a stage to launch further hacking of computers, Skoudis said. An attack could shut off corrupted machines’ keyboard and mouse control, making it more difficult to stop. Or a compromised browser could escalate a machine’s network privileges, and even change time stamps in registries to mask the attacks from later forensic investigation, he said.
Malware distributed via download could contain an entire, Java-based IP stack supporting a VPN endpoint, a tool demonstrated by Dan Kaminsky, a penetration tester for IOActive. That would give attackers unfettered access to other systems within corporate firewalls, Skoudis said.
Such downloads also could contain browser scripts that enable attackers to scan other systems on machines to find further vulnerabilities to exploit.
The implications can be dire, depending on the business infected. “There’s not a really solid answer for this,” said Michael Montecillo, an analyst with EMA attending the conference. “Protecting the browser against exploits really isn’t there yet.”
In the bigger picture, U.S. cyber-readiness in general is lagging, security experts warned.
Federal funding for cybersecurity research is lagging, legislation aimed at toughening up the laws against cybercrime is stalled, and cooperation between private and public sectors could be better, RSA panelists said
“It’s important to go after the criminals,” said BSA’s Holleyman, who added that legislation aimed at botherders is unlikely to pass this year.
U.S Rep. James Langevin (D-R.I.), chairman of the Homeland Security Subcommittee on Emerging Threats and Cybersecurity, said the issue of cybersecurity until recently had been, “largely ignored by government.”
Langevin agreed with Holleyman that meaningful legislation will probably not happen this year. “It’s frustrating for all of us,” he said.
He added that the two major priorities for the federal government are securing its own networks and securing the nation’s critical infrastructure. “We have a lot of work to do” on both counts, according to Langevin.
And he said he wasn’t satisfied with the efforts of the nation’s electric utilities to secure the power grid, which is often cited as an attractive target for cyberterrorists. (See related story.)
Greg Garcia, assistant secretary for cyber security and communications in the Department of Homeland Security, described the situation in Washington, D.C., as a “mud wrestling match” between Democrats and Republicans. “We need a better collaborative environment,” Garcia added.
He said the big task facing the Department of Homeland Security is “strengthening federal networks.” He acknowledged that cyber crime is a global problem and said his department is working to “build out a network of protectors” across the world.Estonia, cybercrime teams from NATO and the U. S. Department of Defense helped to get the network back up and “mitigate the damage.”
Garcia pointed out that when cybercriminals took down Internet access for the entire country of
But when it comes to sharing resources and best practices between countries, there’s plenty of room for improvement, according to panelists.
Botnets gone wild
Meanwhile, a lack of organization isn’t hampering the botnet economy, which is running wild, RSA experts said. Cybercriminals have created a global business with a supply chain every bit as organized and sophisticated as that of any legitimate business.
The criminals have become so adept at using phishing to fool customers into going to a fake pharmaceutical site, they will actually fulfill orders for drugs so they can get repeat business, for example. Patrick Peterson of Cisco’s IronPort division said this means the cybercriminals have a back-end ecosystem that takes orders, boxes up pills (which may or may not be the pills that the customer ordered) and sends a physical order to the customer.
Larry Baldwin, chief forensics officer at myNetWatchman, said cybercriminals are moving away from targeting individual consumers and are going after larger data stores, using keyloggers to gain information about credit-card numbers.
Baldwin said the big banks and credit-card companies are well protected, so hackers are going after retailers, small credit unions and banks. He said he’s aware of 30 such data breaches in the last two months, most of which have not been reported publicly.
The criminals are able to buy and sell credit-card numbers and remanufacture the physical cards. The next step is to lure people into becoming “money mules.”
Baldwin pointed out that the cybercriminals know that initiating a bunch of credit-card transactions from Eastern Europe would raise a red flag. So, they send spam to somebody in Denver, for example, telling them they can make money working at home. That person uses the phony credit card to make a bogus transaction at a Denver bank, then sends the money to the cybercriminal, still not aware that anything illegal is going on.
“It’s a business model as good or better than any corporate business model you’ll see,” said Joe St. Sauver, manager of security programs at the Internet2 networking consortium and the University of Oregon. And the risk of getting caught is extremely low.
How much money is being stolen by cybercriminals? No one knows, and no one even knows how to go about coming up with that number, IronPort’s Peterson said.
IDG News Service correspondents Stephen Lawson and Robert McMillan contributed to this story.




