State Sponsored Hackers: Finding The Country Behind The Attack

Security experts don't just want to know how a cyberattack happens, but what country the attack is coming from.

Headlines about hacking incidents have become commonplace, particularly in the recent months leading up to the US Presidential election. Whether it's breaches of voter registration systems, the US Democratic National Committee, or the World Anti-Doping Agency, experts are feverishly trying to figure out who is behind the crimes.

More specifically, they want to know whether a sovereign state could be supporting those attacks. Lately, they especially want to know if it's Russia.

Experts say the WADA perpetrators were Russian hackers operating under the banner "Fancy Bear," with several US officials pointing fingers at the Russian government specifically.

Moscow has repeatedly denied involvement with that group and other international cyberattacks.

So how do experts assess whether a country could be behind a hacking operation? It's often simple economics. "I think that you can certainly make the argument that this group of repeat offenders, known as Tsar Team (Fancy Bear), is backed up by a government (allegedly Russian intelligence agencies), not only because of the substantial amount of money needed ... but also because of its level of coordination and sophistication," said Francesca Spidalieri, senior fellow for cyber leadership at the Pell Center for International Relations and Public Policy.

Other experts emphasize technological factors. Steve Grobman, CTO at Intel Security, told CNBC that a lot of the technology needed to execute an attack are available on the black market, for example, and are not necessarily all that expensive. "A better indication of who an attack can be attributed to," he said, "comes when you actually get to take a look at things like the source code and can understand the level of sophistication something was built with."

Grobman's team analyzed a portion of the technical forensics associated with the World Anti-Doping Agency attack and concluded that there was insufficient evidence to definitively point the finger at the Russian government.

"We investigated the technical details that were publicly available around the WADA hacking case and compared them against other technical indicators and TTPs [tactics, techniques and procedures] we have gathered over the years," he said. "The amount of available technical details combined with some similar TTPs are not enough evidence in our opinion to attribute this campaign to a certain group or state-sponsored operation."

Scott Borg, director and chief economist at US Cyber Consequences Unit, an independent, non-profit research institute, told CNBC that he's confident the attack was carried out by Russian groups tasked with spreading Russian President Vladimir Putin's political and military agenda.  "This is as certain as anything can ever be in the cyber realm," he said. 

Borg said the Russian government maintains close relationships with many hacker groups, and said it has a history of other cyber-attack campaigns designed to influence political outcomes, particularly in Eastern European countries.

Russia is widely blamed for a broad campaign of cyberattacks against Estonia in 2007, though some experts still question whether there's enough evidence to connect the Kremlin to that attack.

"The hacker groups that the Russian government employs to do its bidding range from consulting groups regularly hired by the Russian government to criminal enterprises with which the Russian government only has slight, arms-length contact," Borg said.

Borg cautioned, though, that just because he believes a nation state was responsible for these attacks does not mean infiltrating the systems themselves required the resources of a country's government.

Matthew Prince, CEO of internet security firm CloudFlare, told CNBC he is skeptical about claims that the Russian government is funding the latest spate of hacks. "The power of computers and of a single determined individual to be able to cause great harm, even if they are not well-financed, is pretty astonishing," he said.

The bottom line, said Bruce Schneier, security expert and CTO at Resilient, an IBM company, is that in terms of figuring out who's really behind a hack, "it's incredibly complicated."

"We do the best we can, but it's not great," Schneier said. "Attribution is just hard in cyber space."

CNBC:

 

« Drone-Visuality: The Psychology Of Killing
Difficult: Attracting Women To Cybersecurity »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Baker McKenzie

Baker McKenzie

Baker & McKenzie is an international law firm. Practice areas include Data & Technology.

Cigniti Technologies

Cigniti Technologies

Cigniti Technologies provides Independent Software Testing (IST) Services including software security testing.

SBS CyberSecurity

SBS CyberSecurity

SBS CyberSecurity is a premier cybersecurity consulting and audit firm.

Sigma IT

Sigma IT

SIGMA IT is one of the largest IT services organizations in EMEA region providing a full range of solutions and services including cybersecurity, data protection and business continuity.

Norwest Venture Partners (NVP)

Norwest Venture Partners (NVP)

Norwest Venture Partners offer entrepreneurs a broad range of services to help them build their businesses at every stage of growth. Key sectors include AI, Infrastructure, SaaS and Security.

Amadeus Capital Partners

Amadeus Capital Partners

Amadeus Capital Partners offers over 20 years’ experience in technology investment. Our areas of focus include AI & machine learning and cyber security.

Qmulos

Qmulos

Qmulos’ real-time continuous monitoring risk management suite, Q-Compliance, provides a massively flexible and scalable solution to optimizing operational security.

CounterFind

CounterFind

CounterFind is turnkey technology that allows brands to find and remove counterfeit and infringing merchandise from online marketplaces and social media sites.

Spamhaus

Spamhaus

Spamhaus is the world leader in supplying realtime highly accurate threat intelligence to the Internet's major networks.

Code Intelligence

Code Intelligence

Code Intelligence offers a platform for automated software security testing to help developers make their software more robust and secure.

Ibento Global

Ibento Global

Ibento organises the CyberX series of cybersecurity conferences.

QA Consultants

QA Consultants

QA Consultants is North America’s largest software quality engineering services firm, an award-winning onshore provider of software testing and quality assurance solutions.

Abacus Group

Abacus Group

Abacus Group is a global IT services firm for alternative investment firms, providing an enterprise technology platform specifically designed to meet the unique needs of financial services.

Sekur Private Data

Sekur Private Data

Sekur Private Data Ltd. is a Cybersecurity and Internet privacy provider of Swiss hosted solutions for secure communications and secure data management.

Schellman

Schellman

Schellman is a leading provider of attestation and compliance services.

Cytidel

Cytidel

Cytidel is a vulnerability and risk management platform that utilises threat and business intelligence to help IT Security teams.