Commentary

J. Nicholas Hoover
Senior Editor, InformationWeek  

The Secret Sauce of Cybersecurity

More than half the cyber forensics analysts with government security clearances in the United States work for General Dynamics, which does about $2 billion in annual cybersecurity-related business. Too often, though, what's behind work like that done by General Dynamics is obscured.

More than half the cyber forensics analysts with government security clearances in the United States work for General Dynamics, which does about $2 billion in annual cybersecurity-related business. Too often, though, what's behind work like that done by General Dynamics is obscured.Though General Dynamics can't show off what's going on behind the scenes of its classified business, the company's services have played key roles in the clean-up and responses to several recent prominent attacks against the private sector, such as the theft of $9.5 million from RBS WorldPay ATMs in a 24 hour period and that of millions of TJX credit card numbers. In the case of RBS WorldPay, for example, General Dynamics' team found out that hackers had reverse engineered PIN numbers in order to create counterfeit ATM cards.

With that in mind Thursday, General Dynamics execs gave me a tour of a digital forensics lab in Annapolis Junction, Md., near NSA headquarters, where it carries out cyber forensics for commercial clients, and shined some light on the process by which cyber investigators track down the bad guys in preparation for a potential trial.


More Government Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

"It really is a science," says Michael Buratowski, General Dynamics' senior program manager for the Department of Defense's Cyber Crime Center (DC3), which sets standards for and assists in cybercrime investigations being carried out by DoD (General Dynamics is prime contractor on three of DC3's five subgroups). "Sure, there is a certain art to it, but in many ways it's a science, and sometimes I think that gets lost."

To demonstrate, he walks me through a mock-up scenario of a spearphishing attack where an attacker sends a targeted email to an employee, masking the attacker's true identity as a friend or colleague, but when an image in the e-mail is loaded, malware hidden in the image executes and infects the employee's machine.

Once the attack grows, General Dynamics might be called in to stop the bleeding and figure out just what's going on. Swinging into motion, General Dynamics acts in many ways like an investigative police unit one might see on television, arriving with cases -- Buratowski calls them "fly-away kits" -- full of laptops, imaging machines, interface cards, write blockers (which allow access to a drive without allowing any code to be written to the drive), and other gadgets designed to assist in the investigation.

That said, it's not CSI/Miami. "You don't need some $40 million lab to do this work," says Nadia Short, VP and GM of the cyber systems division at General Dynamics Advanced Information Systems. "You need the right systems, the right people and a decent environment."

The point, therefore, is largely the process and the execution, not shiny new toys. That means, for example, that when it brings hard drives, CDs, computers and documents back to the lab, General Dynamics follows very specific chain of custody requirements to ensure the evidence will remain valid in a court case, if the investigation gets that far. An evidence room down the hall from a bank of computers where much of the actual investigation is done is under 24-7 alarms and is under coded entry, the codes for which not even Short or Buratowski have.

Once called in after (or during) an attack, General Dynamics decides to take one of two tacks for analyzing the attack: dead box analysis, where the company brings that offending hardware into the lab and does things like look at the directory structure and analyze the drive; or live network analysis, where the company will observe a machine that may be currently being attacked without shutting that machine down (often because of the criticality of the system under attack to the vitality of the organization).

In some ways, here's where the art comes in, as forensic analysts' experiences shape their understanding of and ability to spot anomalous behavior or files on the machines in question, but there's also a science to it, as General Dynamics employs tools like Microsoft's SysInternals Troubleshooting Utilities to observe processes taking place in the background of an attack, particularly in sandboxed machines where General Dynamics might have recreated the attack after first isolating the malware involved. Other tools in the chest might include determining when files were created and checking MAC times (file system metadata recording when certain events occurred).

This science of cybersecurity isn't learned overnight, and though General Dynamics doesn't have problems with bringing in talent, the government sometimes does. Next week I'll have a feature article detailing the work government's doing to bolster its cyber workforce so that it can do more of the things that General Dynamics does for it today.

Amid many cybersecurity threats, the feds are shorthanded. Here's how they're acquiring hard-to-find skills. Download the latest issue of InformationWeek Government here (registration required).


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links