Foreign powers are main cyberthreat, U.K. says

By Tom Espiner, ZDNet UK
Wednesday, November 23, 2005 10:46 AM

Foreign governments are the primary threat to the U.K.'s critical national infrastructure because of their hunger for information, a British government agency said.

The National Infrastructure Security Co-ordination Centre said on Tuesday that the most significant electronic threats are content-based, targeted, Trojan horse e-mail attacks from the Far East.

"Foreign states are probing the CNI for information," said Roger Cummings, the director of NISCC, speaking at SANS Institute's launch of its Top 20 Critical Internet Vulnerability Listing in London.

The agency is in charge of defending the U.K.'s critical national infrastructure, which is made up of financial institutions; key transport, telecom and energy networks; and government organizations.

NISCC is working with its equivalents in the countries concerned to try to shut the attacks down, Cummings said. The agency cannot name the countries concerned as this may "ruin diplomatic efforts to halt the attacks," he added.

The attackers appear to be aiming to gather commercially or economically valuable information, according to NISCC research.

"We call it the 'malicious marketplace,'" Cummings said. "Exploit writers can make money by selling exploits. Who are the most capable organizations to make use of exploits? Foreign states are the most capable actors. They are currently sitting up at the top of the marketplace."

Cummings said the most significant element in the malicious marketplace is foreign states, whose target is information. Next are criminals who are trying to compromise the CNI in order to sell information. Hackers motivated by kudos or money have "a variable capability" when it comes to attacks, Cummings said. However, these pose a more serious threat than terrorists, who currently have a low capability, he said.

However, there is a chance that these groups will increasingly work together, Cummings noted.

"The risk from criminals increases when they get into bed with hackers. The capability of terrorists will increase if they employ hackers," he said. "We are concerned that the malicious marketplace will make available exploits that can do us damage."

Although foreign states are currently the most capable of launching attacks, NISCC expected criminal capability to "expand and start to bump against foreign states," Cummings said.

Cyberterrorism is a controversial subject within the security industry. Some experts, such as Bruce Schneier, have claimed the threat doesn't exist. Speaking in April, Schneier, the chief technology officer at Counterpane Internet Security, said that some organizations have been abusing the term in an attempt to fuel their budgets.

Cummings said people needed to be aware of the threat from terrorism, but stressed that he didn't want to hype the threat or alarm people.

"We are constantly aware that terrorists can attack us in a whole host of ways. There is concern that terrorists can acquire exploits through the malicious marketplace. We would say there is hype around cyberterrorism, but we need to remain eternally vigilant," Cummings said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Tech Jobs Now!

Five HTML oddities that you may not know

Web Development

Browsers are more compliant than Web developers think--find out why, as well as what other nuggets of insights from an industry observer's experience with HTML 5.


Read more »


Tags

  1. authentication and encryption
  2. bank
  3. blog
  4. computer
  5. data security
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. password
  13. phone
  14. researcher
  15. security
  16. software
  17. u.s.
  18. viruses and worms
  19. vulnerability
  20. web

What's in a name?

Blog thumbnail

Plenty, it seems, especially in tougher economic times. When the chips are down and almost every company in the market is clocking negative growth, some tech buyers rely on reputation..... by Eileen Yu

Read more »