I have been presenting my thoughts on cyber warfare at various venues across the US this autumn. A major point, that I have also stressed in this security blog, is that China is engaged in active industrial and military espionage. I follow up my presentation with my theory of Secure Network Fabric which briefly stated is: Networks should be secure. If you own a network you should prevent worms, viruses, and hacking attempts from spreading across that network. (Note that this is the polar opposite of both NAC, which stated in the same vein is: have dirty networks but trust hosts only after verifying their state, and de-perimeterization which would be summed up: dirty networks, clean hosts. )
When I present in Southeast Michigan I am shaken by what I discover. One attendee who is responsible for security assessments at one of the largest auto manufacturers in the world didn’t buy my theory of Secure Networks. He said
“that can’t work. What about trusted third party networks? You can’t firewall and filter their traffic!”
He cited as a “Trusted Third Party” joint venture operations in – your guessed it – China! OMG. One of the US’s industrial giants has unfettered connections to China.
What about the suppliers to the auto companies? Are they trusted third parties? You bet.
While at PricewaterhouseCoopers I did a lot of security assessments at some of the largest organizations in the world. Third party connections were one of my favorite holes to focus on. I wrote the PwC best practices for third party connections. I had the most fun when I wrote up a client who had a non-firewalled T1 connection to the outsourced HR service offered by PwC! Even your auditor should not be “trusted” in the sense that their networks are safe, they aren’t.
Another attendee, responsible for network architecture at the largest auto supplier in the world said:
“it’s crazy, I raise all these warnings about dealing with partners and the top executives always over-ride them based on financial necessity.”
Do not trust any network you are connected to. Government agencies, partners, out-sourcers, and your auditors must be firewalled with explicit policies restricting their access to your resources. In addition, full IPS and AV filtering should be applied at those network connections. Use network behavior analysis to alert you to changes or unusual activity on those links. (Mazu, Arbor, Lancope, Intellitactics) At the application layer use database and web application monitoring and firewalling as an additional layer. (Imperva, AppSec Inc.)
And do not trust your connection to any third party remotely connected to the automotive industry. Their networks are probably owned by China.




