Innovating The Next Big Thing September 8, 2010 ph.gif
ph.gif
Sections

Network & Information Security
Terrorism & Counterterrorism
Homeland Security & Defense
Strategic Thinkers
Weapons of Mass Destruction
Reader Reactions
About

Our Publications

TechnologyInnovator
EnterpriseInnovator
SecurityInnovator
WirelessInnovator 

Contact

• NextInnovator(at)Live.com
• No spam, subscription newsletters, solicitations, or attachments please!
• Attn: Harold Abraham, Chief Innovator

SecurityInnovator Headlines

Cyberwarfare Headline News
Biometrics & Surveillance Headline News
Terrorism Headline News
Guerrilla Warfare Headline News
Nuclear Strategy Headline News
WMD Headline News

Security Innovators

Stratfor Geopolitical Report
Stratfor Daily Podcast
Computerworld Security Blog
eWeek Security Blog
Information Security
Infoworld Zero Day Security
Cheap Hack: Larry Seltzer's New Blog
McAfee Avert Labs Blog
Mike Rothman's Blog
Network Computing Daily Blog
NetworkWorld, Buzzblog
Security Fix, Brian Krebs
ZeroDay, Ryan Naraine

Next Innovators

Over the River
eMarketer 
TechnologyPundits
Security Insights Blog 
McAfee AudioParasitics
Strand Consult
Ovum
The Eye For Innovation
Rethink Research
• Innovation Insights
Innoblog
Strategy and Innovation
The Gadgeteer
Handheld Speech
Ghost City

Strategy for Combating Terror

Homeland Security

Writers Wanted

Writers Wanted

Books on Terrorism

Books on Network Security

Books on WMD

Terror Alert Level


Feedjit Live Web Stats


McAfee AudioParasitics


 
Ads

ph.gif ph.gif
Network & Information Security Security Insights: Source Code Repositories Targeted In Operation Aurora
Mar 3, 2010 – By George Kurtz

Operation Aurora continues to be a hot topic inside and outside of security circles. At this week’s RSA Conference in San Francisco many conversations are on the topic of the attacks that hit Google and dozens of other companies in January.

During a talk this afternoon Stuart McClure and I discussed how the attackers in Operation Aurora went after the crown jewels of the targeted companies, their intellectual property. Also, we disclosed some additional findings from the McAfee investigation into the attacks.

Specifically, we have concluded that, in several cases, the attackers executed precision strikes to gain access to source code configuration management systems (SCMs) at targeted companies. SCMs are used by software engineers to manage their projects and are used to store source code, the crown jewels of any tech company.

In our analysis of the attacks we found that the perpetrators went through several hoops to ultimately compromise the systems of the SCM users at the targeted organizations. This means that the attackers now had access to the SCM system and could siphon out source code or, worse, modify and add code.

As we continued our investigation, we realized that the SCM installations often aren’t properly secured. Many organizations have tight security around financial systems and other mission critical systems, but leave their intellectual property repositories broadly accessible. The company might have strong perimeter security, but once you’re in the SCM is readily available.

The SCM implementations were inherently insecure. A common SCM system we found in many of the Operation Aurora attacks, called Perforce, was researched by McAfee as to exactly how these attacks were targeting people with privileged access to intellectual property, including source code.

In the wake of Operation Aurora we published a white paper today that explores how SCM should be secured. We took a hard look at Perforce first and will look at other applications in the near future.

The main point: intellectual property is valuable, perhaps even more valuable than money, so it should be properly secured. If organizations today secured their financial assets as they secure their source code, they’d be broke.

You can follow George Kurtz on Twitter. Courtesy McAfee.



» Send this article to a friend...
» Comments? Tell us what you think...
» More Network & Information Security articles...

AddThis Social Bookmark Button

Search SecurityInnovator

ph.gif ph.gif
Support This Site



Newest Articles

• 4/1 Terror in the Age of Genocide
• 4/1 It Takes a Village: Hillary Warms Up to Inuit Rights
• 3/30 Surviving the Dragon: An Interview with Tibetan Lama and Author, Arjia Rinpoche
• 3/24 Cold Front: Lessons from History
• 3/12 Book Review: Peoples of the Earth: A sensitive & comprehensive portrait of the First Peoples of the 'New World'
• 3/6 Security Insights: Oscar nominees are more popular and risky online right now
• 3/6 Security Insights: Is Hybrid Email Security Right For You?
• 3/3 Security Insights: McAfee Featured on Army’s APL
• 3/3 Security Insights: Source Code Repositories Targeted In Operation Aurora
• 2/26 Security Insights: Go Team USA! But is your favorite Olympic star dangerous?
• 2/25 Security Insights: HITECH Name-And-Shame Goes Up A Gear
• 2/25 Security Insights: Phishing For Twitter Credentials
• 2/25 Security Insights: RSA – Locked and Loaded
• 2/24 Security Insights: McAfee Vulnerability Manager an SC Magazine “Best Buy”
• 2/23 Book Review: On Thin Ice, "A must read from the troubador of the land of the midnight sun"
• 2/20 Security Insights: Critical Control 20: Security Skills Assessment and Training to Fill Gaps
• 11/1 Tribe, State, and War: Balancing the Subcomponents of World Order
• 10/30 Decreasing Doc Fraud
• 10/26 President Obama: It’s Time for TRIBALCOM
• 9/30 Bracing for Bioterror
• 9/15 Over The River: Photography and Fatherhood
• 9/1 Power Hungry: Confronting the Dangers of American Myopia
• 8/30 Missile Defense: Hope or Hype?
• 7/1 The GWOT Reconsidered
• 6/30 UAVs to the Rescue: Fresh from the Battlefield, Unmanned Aerial Vehicles Now Protect the Home Front
• 5/1 Countdown to a Nuclear Iran
• 4/17 The Lingering Liquid Bomb Threat: Two Years On, New Technologies and Continued Carry-On Restrictions Promise to Make Air Travel Safer
• 4/1 War in the Tribal Zone: Planning for Victory in the Long War: Tribal Conflict, the War on Terror, and a New US Tribal Command
• 4/1 Lessons from the ‘Last Frontier’: Tribe/State Conflict and the Modern World
• 4/1 The GWOT Reloaded: After De-naming the War on Terror, it’s Now Time for a Rethinking of its Strategy
• 3/6 Special Delivery: After two centuries, letter-bombs continue their lethal legacy
• 2/15 Securing the Olympics: Lessons of Beijing: China’s huge investment in time, resources and manpower pays off
• 2/15 Geopolitics, Climate Change, and the Fate of the Arctic
• 2/1 Order in an Age of Absolute War: Brodie, Clausewitz and the Case for Complexity
• 1/15 Aviation Security at a Crossroads: Private Aircraft Face Increased Security as TSA Broadens its Reach from Commercial to General Aviation Sector
• 1/2 Herman Kahn: A Jomini for the Nuclear Age
• 1/1 Toward a Post-Arctic World
• 1/1 Bernard Brodie: A Clausewitz for the Nuclear Age
• 12/2 WMD Panel Releases Report to Congress: World at Risk: Nuclear and Biological Weapons Pose Greatest Peril
• 11/28 Opinion Journal: India's Antiterror Blunders; Years of appeasing militants has made the problem worse
• 11/27 Stratfor Red Alert: Red Alert: Possible Geopolitical Consequences of the Mumbai Attacks
• 11/27 Stratfor Red Alert: India: The Need to React
• 11/26 Security Insights: Three kids + one desk top computer = must have time limits
• 11/26 Stratfor Global Security and Intelligence Report: Workplace Violence: Myths and Mitigation
• 11/25 Heritage Web Memo: Pentagon Should Battle Pirates and Terrorists with Laser Technology
• 11/24 Stratfor Geopolitical Intelligence Report: Obama: First Moves
• 11/21 Heritage Web Memo: Anti-Piracy Initiatives Should Reflect U.S. Maritime Interests
• 11/20 Heritage Web Memo: Europe Anti-Missile Defense System: Standing Up to Russia's Threats
• 11/19 Stratfor Global Security and Intelligence Report: The Barrio Azteca Trial and the Prison Gang-Cartel Interface
• 11/18 Technology Pundits: Microsoft Moves to Zero Cost Anti Virus Service

AddThis Feed Button

DefenseLink

• 9/8 U.S. Remains Committed to Flood Relief, Commander Says
• 9/8 Family Matters Blog: Blogger Joins the 'Sandwich Generation'
• 9/8 Forces in Afghanistan Detain Suspected Insurgents
• 9/8 'New Dawn' Soldiers Arrive in Iraq
• 9/8 Face of Defense: Soldier Strives for Excellence
• 9/7 Cyber Task Force Passes Mission to Cyber Command
• 9/7 Department Joins in Call for Innovative Solutions
• 9/7 Marine Helicopters Join Flood-relief Efforts in Pakistan
• 9/7 More Army Helicopters Arrive in Pakistan
• 9/7 Family Matters Blog: Nonprofit Groups Step Up to Help Military Families
• 9/7 Officials in Afghanistan Detail Recent Operations
• 9/7 Obama to Award Medal of Honor to Vietnam-era Airman
• 9/7 Face of Defense: Marine Strives for Stronger Stride
• 9/4 Mullen Praises Turkey's Leadership, Assistance
• 9/3 General Seeks to Build Professional, Sustainable Afghan Forces
• 9/3 Petraeus Explains Afghanistan Strategy
• 9/3 Border Mission 'Not Unique' for Guardsmen
• 9/3 Family Matters Blog: First Lady, Dr. Biden: Support Military Families
• 9/3 Coalition, Afghan Forces Rescue Prisoners
• 9/3 Trainers Build New Afghan Health System
• 9/3 Face of Defense: Marine Follows Family Heritage
• 9/3 Gates Sees 'Positive Direction' in Afghanistan
• 9/3 Progress in Kandahar Will be Gradual, General Says
• 9/3 'We Can Solve' Soldier Suicides, General Says
• 9/3 First Lady, Dr. Biden Urge Troop, Family Support
• 9/3 Mullen: News Can't Convey Scope of Pakistan Floods
• 9/3 Mullen Gets Afghanistan Updates in Kabul
• 9/2 Air Strike Targets Senior Insurgent Leader
• 9/2 Afghanistan Gains Come at High Price, General Says
• 9/2 Gates, Karzai Discuss Way Ahead in Afghanistan

VOA News - War/Conflict stories

• 2/18 Obama Urges His Party Not to 'Run for the Hills'
• 2/18 Ambassador for Young Spreads a Love of Books
• 2/18 New Understanding of How Plants Use Water
• 2/18 Saying Goodbye to 2009, Hoping for a Better 2010
• 2/18 Time -- One of the Great Mysteries of Our Universe
• 2/18 American History Series: After Lincoln's Murder
• 2/18 New Treatment for Sleeping Sickness
• 2/18 Five New Year's Resolutions for Learners to Improve Their English

Ads

ph.gif
ph.gif Top ph.gif

© 2008 SecurityInnovator. All rights reserved.