Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Tuesday, February 9th 
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Macintosh
Wireless Tech
World Wide Web
Tech Trends
Data Storage
Software
Hardware
Communications
Spam & Hackers
Chips & Processors
E-Business
Personal Tech
 

Advertisement
Network Security

Nuclear Lab Breach Linked to China

Nuclear Lab Breach Linked to China
December 10, 2007 10:40AM

Bookmark and Share
While several security experts are pointing the finger at China over a phishing attack that resulted in the breach of a database at the Oak Ridge National Lab, Andrew Storms, director of security operations at nCircle Network Security, said the Chinese identity of the source computers hardly indicates a Chinese government attack.


Phishing attacks on the Oak Ridge National Laboratory in Tennessee, a nuclear weapons research facility, appear to have originated in China, raising concerns that the attacks represent some form of Internet warfare.

The United States Computer Emergency Response Team (US-CERT) prepared a memorandum that traced IP addresses involved in the attack to computers in China. The memo was distributed by the Department of Homeland Security to public and private security officials and obtained by the New York Times.

"The level of sophistication and the scope of these cyber security incidents indicate that they are coordinated and targeted at private sector systems," the memo said.

1,100 Phishing E-Mails

According to Thom Mason, the director of the Oak Ridge lab, attackers sent 1,100 phishing e-mails to lab employees, with attachments purporting to contain information Relevant Products/Services about a scientific conference or an FTC complaint.

"At this point, we have determined that the thieves made approximately 1,100 attempts to steal data Relevant Products/Services with a very sophisticated strategy that involved sending staff a total of seven phishing e-mails, all of which at first glance appeared legitimate," Mason wrote to employees. "At present we believe that about 11 staff opened the attachments, which enabled the hackers to infiltrate the system Relevant Products/Services and remove data."

The attackers stole a database containing personal information of visitors to the lab, about 3,000 researchers annually.

The fact that phishing attacks worked at a top-secret lab shows the power Relevant Products/Services of the technique, said Andrew Storms, director of security operations at nCircle Network Security. "One would think that despite technical security mechanisms in place, that employees at Oak Ridge and Los Alamos would be some of the most security-aware persons," he wrote in a e-mail.

Phishing a Way of Life

Still, Storms questioned the "sophistication" of the operation. "Calling it an attack at all seems nebulous," he said. "This was just one of thousands phishing e-mails private and government sectors receive daily. While we still coin phishing as an attack, it's more of a way of life for today's Internet user."

Storms said the Chinese identity of the source computers hardly indicates a Chinese government attack. "All of southeast Asia has been a popular hacker dwelling for years," he said. "Of all the security incidents I've personally researched in the last five years, 90 percent have all shown links back to Asian countries. This in no way means that government officials are behind the attacks. It's just the way of life, just as is phishing."

Another concern is whether the lab's secure Relevant Products/Services networks are properly protected. "This isn't the first time that a U.S. lab has been an attack target, nor is it the first time that private information left the building walls," Storms said. "While there are rules and guidelines for handling sensitive data, exactly what the public might deem classified takes on a different definition inside the workings at Los Alamos for example."

Advertisement



 Network Security
1. China Cyberattacks: Pervasive Threat
2. Patch Tuesday Will Tie MS Record
3. Cybersecurity Appears Hot for 2010
4. EPIC Objects To Google-NSA Ties
5. Torrent Traps Used To Harvest Logins


advertisement


 Most Popular Articles
1. iPhone Loses Global Market Share as Rivals Advance
2. Lessons To Learn from a Year of Big Data Breaches
3. New Sony Ericsson Aspen Handset Uses Windows Mobile
4. Apple Bans Location-Based Ads for iPhone Apps
5. EPIC Objects To Google-NSA Cyber Partnership

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Macworld Focuses on Mobile Apps
  MS: Windows 7 Doesn't Hurt Battery
  Macmillan Books Return To Amazon
  Tips for More Windows 7 Productivity
  Nexus One 'Support' Passes the Buck

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

To Love or Not To Love: Apple iPad Pros and Cons
Now that the iPad has officially been announced, opinions are rolling in on this device that combines the features of an iPod, e-reader, and tablet PC. Will the iPad turn fewer heads than the iPhone?

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

Advertisement
Enterprise Software Spotlight

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with CEO Léo Apotheker resigning, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Enterprise Hardware Spotlight

Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.

IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Security Spotlight

Chinese Cyberattacks Seen as a Pervasive Threat
Google's accusation that e-mail accounts were hacked from China landed like a bombshell because it cast light on a problem few firms will discuss: the pervasive threat from China-based cyberattacks.

Patch Tuesday Release Will Tie Microsoft's Record
After a light start to the year, Microsoft is getting ready to dump a heavy load on the shoulders of IT administrators. On Patch Tuesday next week, Microsoft will release 13 patches.

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Macintosh | Wireless Tech | World Wide Web
Tech Trends | Data Storage | Software | Hardware | Communications | Spam & Hackers | Chips & Processors
E-Business | Personal Tech
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Top Tech News. All rights reserved. Article rating technology by Blogowogo.