State Sponsored Hackers: Finding The Country Behind The Attack

Security experts don't just want to know how a cyberattack happens, but what country the attack is coming from.

Headlines about hacking incidents have become commonplace, particularly in the recent months leading up to the US Presidential election. Whether it's breaches of voter registration systems, the US Democratic National Committee, or the World Anti-Doping Agency, experts are feverishly trying to figure out who is behind the crimes.

More specifically, they want to know whether a sovereign state could be supporting those attacks. Lately, they especially want to know if it's Russia.

Experts say the WADA perpetrators were Russian hackers operating under the banner "Fancy Bear," with several US officials pointing fingers at the Russian government specifically.

Moscow has repeatedly denied involvement with that group and other international cyberattacks.

So how do experts assess whether a country could be behind a hacking operation? It's often simple economics. "I think that you can certainly make the argument that this group of repeat offenders, known as Tsar Team (Fancy Bear), is backed up by a government (allegedly Russian intelligence agencies), not only because of the substantial amount of money needed ... but also because of its level of coordination and sophistication," said Francesca Spidalieri, senior fellow for cyber leadership at the Pell Center for International Relations and Public Policy.

Other experts emphasize technological factors. Steve Grobman, CTO at Intel Security, told CNBC that a lot of the technology needed to execute an attack are available on the black market, for example, and are not necessarily all that expensive. "A better indication of who an attack can be attributed to," he said, "comes when you actually get to take a look at things like the source code and can understand the level of sophistication something was built with."

Grobman's team analyzed a portion of the technical forensics associated with the World Anti-Doping Agency attack and concluded that there was insufficient evidence to definitively point the finger at the Russian government.

"We investigated the technical details that were publicly available around the WADA hacking case and compared them against other technical indicators and TTPs [tactics, techniques and procedures] we have gathered over the years," he said. "The amount of available technical details combined with some similar TTPs are not enough evidence in our opinion to attribute this campaign to a certain group or state-sponsored operation."

Scott Borg, director and chief economist at US Cyber Consequences Unit, an independent, non-profit research institute, told CNBC that he's confident the attack was carried out by Russian groups tasked with spreading Russian President Vladimir Putin's political and military agenda.  "This is as certain as anything can ever be in the cyber realm," he said. 

Borg said the Russian government maintains close relationships with many hacker groups, and said it has a history of other cyber-attack campaigns designed to influence political outcomes, particularly in Eastern European countries.

Russia is widely blamed for a broad campaign of cyberattacks against Estonia in 2007, though some experts still question whether there's enough evidence to connect the Kremlin to that attack.

"The hacker groups that the Russian government employs to do its bidding range from consulting groups regularly hired by the Russian government to criminal enterprises with which the Russian government only has slight, arms-length contact," Borg said.

Borg cautioned, though, that just because he believes a nation state was responsible for these attacks does not mean infiltrating the systems themselves required the resources of a country's government.

Matthew Prince, CEO of internet security firm CloudFlare, told CNBC he is skeptical about claims that the Russian government is funding the latest spate of hacks. "The power of computers and of a single determined individual to be able to cause great harm, even if they are not well-financed, is pretty astonishing," he said.

The bottom line, said Bruce Schneier, security expert and CTO at Resilient, an IBM company, is that in terms of figuring out who's really behind a hack, "it's incredibly complicated."

"We do the best we can, but it's not great," Schneier said. "Attribution is just hard in cyber space."

CNBC:

 

« Drone-Visuality: The Psychology Of Killing
Difficult: Attracting Women To Cybersecurity »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

European Business Reliance Centre (EBRC)

European Business Reliance Centre (EBRC)

EBRC is a leader in integrated Data Center, Cloud and Managed Services and a Centre of Excellence in Europe in the Management of Sensitive Information.

AppSec Labs

AppSec Labs

AppSec Labs specialise in application security. Our mission is to raise awareness in the software development world to the importance of integrating software security across the development lifecycle.

Israel Aerospace Industries (IAI)

Israel Aerospace Industries (IAI)

IAI offers a holistic approach that provides defense forces, governments, critical infrastructures and large enterprises with end-to-end cyber security & monitoring tools.

Nexcom International

Nexcom International

Nexcom operates six global businesses - IoT Automation, Intelligent Digital Security, Internet of Things, Intelligent Platform & Services, Mobile Computing Solutions, Network & Communications.

Ceerus

Ceerus

Ceerus was created to simplify the process of deploying and managing security across all the channels in an organisation.

CSO GmbH

CSO GmbH

CSO GmbH provide specialist consultancy services in the area of IT security.

Webtotem

Webtotem

Webtotem's mission is to prevent the global epidemic of website infection and provide every website owner with basic security rights.

Secure Technology Integration Group (STIGroup)

Secure Technology Integration Group (STIGroup)

Secure Technology Integration Group, Ltd. (STIGroup) is an innovative firm that provides CyberSecurity consulting, secure IT engineering, managed security services, and human capital solutions.

Information Services Group (ISG)

Information Services Group (ISG)

As a leading global research and advisory firm, ISG partners with our clients to determine a future vision, lead rapid change and realize the value of your digital investments at scale.

WhizHack Technologies

WhizHack Technologies

WhizHack's mission is to not only create a pipeline of cyber security products but also to empower people to sustainable innovation in securing digital assets of tomorrow.

Arctic Group

Arctic Group

Arctic Group is a Swedish service provider focusing on cybersecurity, integration services and deployment of software development tools.

Goldilock

Goldilock

Goldilock is redefining how sensitive data, devices, networks and critical infrastructure can be secured.

People Driven Technology

People Driven Technology

People Driven Technology is a customer-obsessed organization. We leverage our decades of business, technology, and engineering experience to deliver outcomes for our clients.

Block Harbor Cybersecurity

Block Harbor Cybersecurity

Block Harbor has worked closely with automakers, suppliers, and regulators since 2014 on vehicle cybersecurity.

ViCyber

ViCyber

ViCyber is an Australian based company whose mission is to simplify and strengthen cybersecurity for all businesses, irrespective of size.

GAM Tech

GAM Tech

GAM Tech is a Managed IT Service Provider that serves small and medium sized businesses in Alberta, British Columbia, Ontario and Quebec.