Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Friday, November 20th 
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Macintosh
Wireless Tech
World Wide Web
Tech Trends
Data Storage
Software
Hardware
Communications
Spam & Hackers
Chips & Processors
E-Business
Personal Tech
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Network Security

Nuclear Lab Breach Linked to China

Nuclear Lab Breach Linked to China
December 10, 2007 10:40AM

Bookmark and Share
While several security experts are pointing the finger at China over a phishing attack that resulted in the breach of a database at the Oak Ridge National Lab, Andrew Storms, director of security operations at nCircle Network Security, said the Chinese identity of the source computers hardly indicates a Chinese government attack.


Phishing attacks on the Oak Ridge National Laboratory in Tennessee, a nuclear weapons research facility, appear to have originated in China, raising concerns that the attacks represent some form of Internet warfare.

The United States Computer Emergency Response Team (US-CERT) prepared a memorandum that traced IP addresses involved in the attack to computers in China. The memo was distributed by the Department of Homeland Security to public and private security Relevant Products/Services officials and obtained by the New York Times.

"The level of sophistication and the scope of these cyber security incidents indicate that they are coordinated and targeted at private sector systems," the memo said.

1,100 Phishing E-Mails

According to Thom Mason, the director of the Oak Ridge lab, attackers sent 1,100 phishing e-mails to lab employees, with attachments purporting to contain information about a scientific conference or an FTC complaint.

"At this point, we have determined that the thieves made approximately 1,100 attempts to steal data Relevant Products/Services with a very sophisticated strategy that involved sending staff a total of seven phishing e-mails, all of which at first glance appeared legitimate," Mason wrote to employees. "At present we believe that about 11 staff opened the attachments, which enabled the hackers to infiltrate the system and remove data."

The attackers stole a database containing personal information of visitors to the lab, about 3,000 researchers annually.

The fact that phishing attacks worked at a top-secret lab shows the power of the technique, said Andrew Storms, director of security operations at nCircle Network Security. "One would think that despite technical security mechanisms in place, that employees at Oak Ridge and Los Alamos would be some of the most security-aware persons," he wrote in a e-mail.

Phishing a Way of Life

Still, Storms questioned the "sophistication" of the operation. "Calling it an attack at all seems nebulous," he said. "This was just one of thousands phishing e-mails private and government sectors receive daily. While we still coin phishing as an attack, it's more of a way of life for today's Internet user."

Storms said the Chinese identity of the source computers hardly indicates a Chinese government attack. "All of southeast Asia has been a popular hacker dwelling for years," he said. "Of all the security incidents I've personally researched in the last five years, 90 percent have all shown links back to Asian countries. This in no way means that government officials are behind the attacks. It's just the way of life, just as is phishing."

Another concern is whether the lab's secure Relevant Products/Services networks are properly protected. "This isn't the first time that a U.S. lab has been an attack target, nor is it the first time that private information left the building walls," Storms said. "While there are rules and guidelines for handling sensitive data, exactly what the public might deem classified takes on a different definition inside the workings at Los Alamos for example."

Advertisement


 Network Security
1. Peer-to-Peer Software Ban Sought
2. Los Alamos Computer Security Weak
3. Security Firm Fortinet Plans IPO
4. Heartland Restraining Order Denied
5. Social-Networking Security a Concern


advertisement


 Most Popular Articles
1. Verizon's Buzz for Motorola's Droid Fizzles at Day's End
2. Facebook Hijacking Points To Social-Networking Holes
3. Motorola's Droid 'Doing Fine' with About 100,000 Sold
4. Dell Will Debut Mini 3 Smartphone in China and Brazil
5. Sophos, Microsoft Disagree on Windows 7 Security

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Barnes & Noble Nook Is Delayed
  Ballmer Says Windows 7 Sales Good
  New Pogoplug 'Cloud' Gets Social
  Chrome OS Team Aims for Speed
  FAA Glitch Causes Air Travel Delays

 Technology Marketplace
Business Intelligence
IBM - Smarter business for a Smarter Planet.
 
Compliance
Webcast: SOX, GLBA, HIPAA Compliance and IT security controls.
 
Customer Service
Rackspace Hosting: 24x7x365 Support, Windows and Linux Certified
 
Data Security
Secure your data center today with the TippingPoint N-Platform
 
Enterprise Hardware
IT Costs out of Control? Download APC's FREE Cooling Efficiency kit.
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Rackspace: It makes a difference when you focus on support
IBM - Smarter technology for a Smarter Planet.
Simplify. Automate. Innovate. The new network is here.
IT Costs out of Control? Download our FREE Cooling Efficiency kit.
Windows 7 Enterprise designed specifically for IT Professionals
 
Enterprise Software
Open cross-network software provides rich user experiences and fast time to market.
 
Innovation
3-D scaling lets networks support more subscribers, services & bandwidth -- at the same time.
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
Check out the new Windows 7 features. Download the FREE trial.
 
Network Security
Junos software platform and Juniper systems provide new cloud-networking & security solutions.
 
Security Products
Secure your data center today with TippingPoint's N-Platform
 
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Macintosh | Wireless Tech | World Wide Web
Tech Trends | Data Storage | Software | Hardware | Communications | Spam & Hackers | Chips & Processors
E-Business | Personal Tech
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 Top Tech News. All rights reserved. Article rating technology by Blogowogo.