State Sponsored Hackers: Finding The Country Behind The Attack

Security experts don't just want to know how a cyberattack happens, but what country the attack is coming from.

Headlines about hacking incidents have become commonplace, particularly in the recent months leading up to the US Presidential election. Whether it's breaches of voter registration systems, the US Democratic National Committee, or the World Anti-Doping Agency, experts are feverishly trying to figure out who is behind the crimes.

More specifically, they want to know whether a sovereign state could be supporting those attacks. Lately, they especially want to know if it's Russia.

Experts say the WADA perpetrators were Russian hackers operating under the banner "Fancy Bear," with several US officials pointing fingers at the Russian government specifically.

Moscow has repeatedly denied involvement with that group and other international cyberattacks.

So how do experts assess whether a country could be behind a hacking operation? It's often simple economics. "I think that you can certainly make the argument that this group of repeat offenders, known as Tsar Team (Fancy Bear), is backed up by a government (allegedly Russian intelligence agencies), not only because of the substantial amount of money needed ... but also because of its level of coordination and sophistication," said Francesca Spidalieri, senior fellow for cyber leadership at the Pell Center for International Relations and Public Policy.

Other experts emphasize technological factors. Steve Grobman, CTO at Intel Security, told CNBC that a lot of the technology needed to execute an attack are available on the black market, for example, and are not necessarily all that expensive. "A better indication of who an attack can be attributed to," he said, "comes when you actually get to take a look at things like the source code and can understand the level of sophistication something was built with."

Grobman's team analyzed a portion of the technical forensics associated with the World Anti-Doping Agency attack and concluded that there was insufficient evidence to definitively point the finger at the Russian government.

"We investigated the technical details that were publicly available around the WADA hacking case and compared them against other technical indicators and TTPs [tactics, techniques and procedures] we have gathered over the years," he said. "The amount of available technical details combined with some similar TTPs are not enough evidence in our opinion to attribute this campaign to a certain group or state-sponsored operation."

Scott Borg, director and chief economist at US Cyber Consequences Unit, an independent, non-profit research institute, told CNBC that he's confident the attack was carried out by Russian groups tasked with spreading Russian President Vladimir Putin's political and military agenda.  "This is as certain as anything can ever be in the cyber realm," he said. 

Borg said the Russian government maintains close relationships with many hacker groups, and said it has a history of other cyber-attack campaigns designed to influence political outcomes, particularly in Eastern European countries.

Russia is widely blamed for a broad campaign of cyberattacks against Estonia in 2007, though some experts still question whether there's enough evidence to connect the Kremlin to that attack.

"The hacker groups that the Russian government employs to do its bidding range from consulting groups regularly hired by the Russian government to criminal enterprises with which the Russian government only has slight, arms-length contact," Borg said.

Borg cautioned, though, that just because he believes a nation state was responsible for these attacks does not mean infiltrating the systems themselves required the resources of a country's government.

Matthew Prince, CEO of internet security firm CloudFlare, told CNBC he is skeptical about claims that the Russian government is funding the latest spate of hacks. "The power of computers and of a single determined individual to be able to cause great harm, even if they are not well-financed, is pretty astonishing," he said.

The bottom line, said Bruce Schneier, security expert and CTO at Resilient, an IBM company, is that in terms of figuring out who's really behind a hack, "it's incredibly complicated."

"We do the best we can, but it's not great," Schneier said. "Attribution is just hard in cyber space."

CNBC:

 

« Drone-Visuality: The Psychology Of Killing
Difficult: Attracting Women To Cybersecurity »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Nordic IT Security

Nordic IT Security

Nordic IT Security is a cyber security business forum in Scandinavia bringing together the converging worlds of IT, Cyber and Information Security.

RSA Insurance Group

RSA Insurance Group

RSA is one of the world’s leading multinational quoted insurance groups. Commercial services include cyber risk insurance.

Dataguise

Dataguise

Dataguise provides a data-centric security solution to detect, protect, and monitor sensitive data in real time across all data repositories, both on premises and in the cloud.

Secarma

Secarma

Secarma provides penetration testing, security assessments, consultancy, and training services to ensure your digital infrastructure is secure from cybersecurity threats.

Belkasoft

Belkasoft

Belkasoft is a software vendor providing public agencies, corporate security teams, and private investigators with digital forensic solutions.

Bridewell

Bridewell

Bridewell provide cost effective Security & Risk Assurance Services across Information Security, Cyber Security, Technology Risk, Security Testing and Data Privacy.

Pluribus One

Pluribus One

Pluribus One develops customized solutions and other data-driven applications to secure your business and your devices.

Aergo

Aergo

Aergo offers an easier and more proven way to adopt blockchain and transform your business while building on your existing IT and cloud assets.

Intel Capital

Intel Capital

Intel Capital, Intel's strategic investment organization, backs innovative technology startups and companies worldwide. We invest in a broad range of hardware, software, and services.

CyberWhite

CyberWhite

CyberWhite is a disruptive provider of cyber security and risk mitigation solutions.

Cyway

Cyway

Cyway is a value-added cybersecurity distributor focusing on on-prem, cloud solutions and hybrid solutions, IoT, AI & machine learning IT security technologies.

Cigent Technology

Cigent Technology

Cigent keeps the most valuable asset in your organization safe—your data. Our advanced endpoint and managed network security solutions prevent ransomware and data theft.

Enginsight

Enginsight

Enginsight provides a comprehensive solution for monitoring and securing your servers and clients.

Eleviant Tech (CTG Group)

Eleviant Tech (CTG Group)

Eleviant Tech (CTG Group) is a USA based digital transformation company with expertise in Mobile, Cloud, Web, IoT, AR, RPA, Cyberseurity and AI Technologies.

Inroad Technologies

Inroad Technologies

Inroad Technologies provide IT services that help keep your business computers, servers and networks secure and trouble-free.

CyberNINES

CyberNINES

CyberNINES is a business specializing in helping US Department of Defense contractors become compliant and attest to federal cybersecurity regulation requirements.