Contributor

Don’t Trust Trusted Third Parties

Opinion
Oct 1, 20083 mins

I have been presenting my thoughts on cyber warfare at various venues across the US this autumn.   A major point, that I have also stressed in this security blog, is that China is engaged in active industrial and military espionage.  I follow up my presentation with my theory of Secure Network Fabric which briefly stated is:  Networks should be secure. If you own a network you should prevent worms, viruses, and hacking attempts from spreading across that network.  (Note that this is the polar opposite of both NAC, which stated in the same vein is:  have dirty networks but trust hosts only after verifying their state, and de-perimeterization which would be summed up: dirty networks, clean hosts. )

When I present in Southeast Michigan I am shaken by what I discover. One attendee who is responsible for security assessments at one of the largest auto manufacturers in the world didn’t buy my theory of Secure Networks.  He said

“that can’t work.  What about trusted third party networks? You can’t firewall and filter their traffic!” 

  He cited as a “Trusted Third Party” joint venture operations in – your guessed it – China!   OMG.  One of the US’s industrial giants has unfettered connections to China.

What about the suppliers to the auto companies?  Are they trusted third parties?  You bet.

While at PricewaterhouseCoopers I did a lot of security assessments at some of the largest organizations in the world.  Third party connections were one of my favorite holes to focus on. I wrote the PwC best practices for third party connections.  I had the most fun when I wrote up a client who had a non-firewalled T1 connection to the outsourced HR service offered by PwC!  Even your auditor should not be “trusted” in the sense that their networks are safe, they aren’t.

Another attendee, responsible for network architecture at the largest auto supplier in the world said:

“it’s crazy, I raise all these warnings about dealing with partners and the top executives always over-ride them based on financial necessity.”  

Do not trust any network you are connected to.  Government agencies, partners, out-sourcers, and your auditors must be firewalled with explicit policies restricting their access to your resources. In addition, full IPS and AV filtering should be applied at those network connections.  Use network behavior analysis to alert you to changes or unusual activity on those links. (Mazu, Arbor, Lancope, Intellitactics) At the application layer use database and web application monitoring and firewalling as an additional layer. (Imperva, AppSec Inc.)

And do not trust your connection to any third party remotely connected to the automotive industry. Their networks are probably owned by China.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author