Cyber Command Knows Its Tools Can Also Be Used By Their Targets

US military commanders say that when US Cyber Command and the National Security Agency use a capability against targets abroad, they understand it might eventually be used by an adversary.

The threat of having the NSA’s tools leaked has been an issue inside the agency for years now, former NSA contractor Edward Snowden brought it into the public domain when he revealed a trove of NSA programs in 2013, but the risk of having adversaries detect, obtain or reverse engineers NSA-used tools has become especially salient.

Researchers from cybersecurity firm Symantec revealed that a Chinese-linked hacking group had repurposed tools linked with the NSA as early as March of 2016 and used them to attack various targets around the world.

It is unclear how the group, known as Buckeye, obtained the tools, but Symantec assesses it is possible it observed an NSA-linked attack, then gathered enough info to repurpose the code. It is also possible Buckeye stole the tools from an unsecured server or leaked the code to the group, although Symantec said that was less likely.

“There’s always a risk calculus in any sort of operation that we take on in Cyber Command,” said David Luber, the executive director of US Cyber Command, during a recent media roundtable. “The commander Gen. Paul Nakasone looks at those scenarios every single day.”

According to The George Washington University’s National Security Archive, Cyber Command runs an internal deliberation process before deciding to launch a mission.

The deliberation includes an assessment of intelligence gain loss, a blowback assessment, an assessment of collateral effects, a legal review and a risk assessment report.

Through its Vulnerabilities Equities Process (VEP),  government officials determine to either withhold or disclose information to tech companies about newly discovered software flaws. The VEP allows the government to keep certain “limited categories” from being shared, the details of which remain classified.

According to an appendix the White House released two years ago, one of the factors officials consider in VEP deliberations is how widely used the affected product is. But the trade-off is to also consider whether flaws can be exploited to support intelligence collection and cyber operations.

Jordan Rae Kelly, the former director for Cyber Incident Response on the National Security Council who oversaw the VEP, said the deliberation is a balancing act.

“It’s about really looking and understanding vulnerabilities in a deep way,” Kelly, who is now senior managing director at FTI Consulting, told CyberScoop. “Understanding how agencies might use individual exploits or if the exploits will be used in a series of tools is part of the evaluation equation.”

Speaking to CyberScoop, Neil Jenkins, a former cyber adviser at the Department of Homeland Security, said that the Symantec research highlights possible flaws in the VEP.

“We have to be taking into better consideration how prominent an exploit is in the ecosystem. … This was a vulnerability in a Microsoft product in Windows,” Jenkins, now the chief analytic officer of the Cyber Threat Alliance, told CyberScoop. “That alone should have been enough to say … we should disclose this exploit.”

Kelly said she “wouldn’t say that any one factor is weighed more heavily” in the process.

The NSA, which is the executive secretariat of the VEP, has said in the past it’s disclosed 91 percent of the vulnerabilities it finds. In the case of the vulnerabilities that Buckeye was found to be using, the NSA shared its software vulnerabilities with Microsoft so it could patch the flaws, according to The New York Times.

The NSA would not comment on the VEP. Cyber Command and the White House’s National Security Council did not respond to request for comment.

The VEP’s review process, which traces its development back to the Obama administration, was only publicly disclosed for the first time in 2014. In those deliberations, the reviewers are supposed to consider whether exploiting the vulnerability will cause harm or if adversaries are likely to use the vulnerability for their own purposes.

Luber said that Cyber Command, just like other parts of the Department of Defense, participates in the review process.

“When it comes to working in an environment where our tools will be used in our operations, we participate just like other parts of the U.S. government in the VEP,” Luber said.

Cyberscoop

You Might Also Read:

‘Chinese Spies’ Had NSA Cyber Weapons Before The Shadow Brokers Leak:

America Remains Vulnerable To Cyber Attack:

 

 
« Two Years After WannaCry Severe Risks Remain
Is The US Planning A Cyber Attack On Iran? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

XBOSoft

XBOSoft

XBOSoft is a software QA and testing company. We cover the entire QA and testing life cycle including software and application security.

LEXFO

LEXFO

LEXFO specializes in the security of information systems, assisting clients in protecting information assets using an offensive and innovative approach.

DXC Technology

DXC Technology

DXC Technology helps global companies run their mission critical systems and operations while modernizing IT, optimizing data architectures, and ensuring security and scalability.

Pindrop Security

Pindrop Security

Pindrop solutions are leading the way to the future of voice by establishing the standard for security, identity, and trust for every voice interaction.

Cyberra Legal Services (CLS)

Cyberra Legal Services (CLS)

Cyberra Legal Services provides cyber law advisory, cyber crime consultancy, cyber law compliance audit, cyber security, cyber forensics and cyber training services.

Austrian Trust Circle

Austrian Trust Circle

Austrian Trust Circle is an initiative of CERT.at and the Austrian Federal Chancellery and consists of Security Information Exchanges in the areas of the strategic information infrastructure.

ZecOps

ZecOps

ZecOps is a cybersecurity automation company offering solutions for servers, endpoints, mobile devices, and custom devices.

ACET Solutions

ACET Solutions

ACET Solutions delivers a wide range of Automation, Cyber Security and Enterprise IT/OT Integration Solutions to industrial clients.

Measured Insurance

Measured Insurance

Measured Insurance are bridging the gap between technology and Insurance using AI-Powered analytics that track clients’ exposure in real time to create smarter insurance products.

Deepnet Security

Deepnet Security

Deepnet Security is a leading security software developer and hardware provider in Multi-Factor Authentication (MFA), Single Sign-On (SSO) and Identity & Access Management (IAM).

Crypto International

Crypto International

Crypto International offers comprehensive services for the operation of our customers’ IT and communication infrastructure, with a focus on cybersecurity and encryption solutions.

Securd

Securd

Securd takes opportunities away from your cyber adversaries. Cloud-delivered zero-trust DNS firewall and web filtering protection keep your business network and remote employees safe.

Ascent Solutions

Ascent Solutions

Ascent is built to help firms evolve their cybersecurity posture, modernize their Microsoft solutions, and accelerate their journey to the cloud.

SideChannel

SideChannel

At SideChannel, we match companies with an expert virtual CISO (vCISO), so your organization can assess cyber risk and ensure cybersecurity compliance.

Althammer & Kill

Althammer & Kill

Althammer & Kill offers pragmatic solution concepts for data protection and digitization. We advise in the field of data protection, information security and compliance.

Toro Solutions

Toro Solutions

Toro provide managed security & consultancy to keep governments, businesses & society resilient in the space where cyber, physical & people security converge.