Access and Feeds

Security: The Threat of State-Based Cyber Attacks

By Dick Weisinger

“Cyberspace has become a full-blown war zone as governments across the globe clash for digital supremacy in a new, mostly invisible theater of operations. Once limited to opportunistic criminals, cyber attacks are becoming a key weapon for governments seeking to defend national sovereignty and project national power,” says a report from FireEye called “World War C: Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks.
A recent report by Lieberman software found the following results from a survey of large companies about their preparedness for defending against state-sponsored cyber attacks:
  • 74 percent of businesses aren’t confident that their network hasn’t already been breached
  • 52 percent are not confident that they would be able to detect an attacker on their network
  • 58 percent think that the US is losing the battle against state-sponsored cyber attacks
  • 63 percent of businesses surveyed think it is likely that a state-sponsored attacker will try to breach their network within the next six months
  • 96 percent think that hacking episodes will only get worse in the future
Philip Lieberman, President and CEO of Lieberman Software, said that “the threat of state-sponsored attacks is extremely serious for government and commercial entities. The probing of IT infrastructures in both environments is occurring 24/7, with attacks being launched on a regular basis. These types of attacks are very difficult to stop, almost impossible to attribute to a specific country, and a pain in the neck to anyone who gets caught in the middle of their battles. We cannot stop these attacks; we can only build taller and thicker walls to keep the hordes out… The majority of organizations are prepared for amateur hackers and low-level criminals, but are completely ill-equipped to deal with today’s advanced nation-state foes. The most dangerous threats are highly personalized attacks designed for one-time use against specific individuals. Many state-sponsored attackers can now create perfect email attacks that insert remote control software onto corporate networks. Most corporations and government agencies would benefit from better security training, documented security processes, and enterprise-level products that can manage and secure powerful privileged accounts that grant access to critical IT assets.”
 
Martyn Croft, CIO of The Salvation Army UK, said that “since I would assume that state sponsored attacks are a covert operation, it sort of begs the question whether anyone can know the full extent. I guess a certain amount of inference from the known attacks, for example Stuxnet, would lead one to believe that it’s become a commonplace occurrence.”
 
Costin Raiu, director at Kaspersky Labs, said that “I would say if we’re talking about [cyber-criminal] groups operating from China, we’re talking maybe between 100 and 200 different groups. I would say that’s the largest operating base of threat actors in the world, but then, pretty much every big nation state is doing some form of cyber-espionage. Some are more noisy that others; they hit everyone and don’t care if it’s in the news, all they care about is getting the documents from your systems. While others are more careful, more advanced, and are very scared of being exposed.”
Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*