Innovating The Next Big Thing September 3, 2010 ph.gif
ph.gif
Sections

Analyst Insights
Network & Information Security
Enterprise Mobility
Enterprise Insights
Reader Reactions
About

Our Publications

TechnologyInnovator
EnterpriseInnovator
SecurityInnovator
WirelessInnovator 

Contact

• NextInnovator(at)Live.com
• No spam, subscription newsletters, solicitations, or attachments please!
• Attn: Harold Abraham, Chief Innovator

Next Innovators

Over the River
eMarketer 
TechnologyPundits
Security Insights Blog 
McAfee AudioParasitics
Strand Consult
Ovum
The Eye For Innovation
Rethink Research
• Innovation Insights
Innoblog
Strategy and Innovation
The Gadgeteer
Handheld Speech
Ghost City

CNN Technology


EnterpriseInnovator Headlines

IT Headline News
Mobile Enterprise Headline News
Grid & Supercomputing Headline News
Bio & Life Science Computing Headlines
Nano-Computing Headline News
Telecom Headline News
Network Headline News
Desktop & Workstation Headline News
Server Headline News
Chip Headline News
OS Headline News
Storage Headline News
Enterprise Security Headline News

Writers Wanted

Writers Wanted

Amazon Ads: Cell Phones & Plans

Amazon Ads: Computer Peripherals

Amazon Ads: PDAs and Handhelds

Amazon Ads: Notebooks

Amazon Ads: Desktop PCs

Amazon Ads: More Cell Phones

Feedjit Live Web Stats


McAfee AudioParasitics


 
Ads

ph.gif ph.gif
Network & Information Security Security Insights: Source Code Repositories Targeted In Operation Aurora
Mar 3, 2010 – By George Kurtz

Operation Aurora continues to be a hot topic inside and outside of security circles. At this week’s RSA Conference in San Francisco many conversations are on the topic of the attacks that hit Google and dozens of other companies in January.

During a talk this afternoon Stuart McClure and I discussed how the attackers in Operation Aurora went after the crown jewels of the targeted companies, their intellectual property. Also, we disclosed some additional findings from the McAfee investigation into the attacks.

Specifically, we have concluded that, in several cases, the attackers executed precision strikes to gain access to source code configuration management systems (SCMs) at targeted companies. SCMs are used by software engineers to manage their projects and are used to store source code, the crown jewels of any tech company.

In our analysis of the attacks we found that the perpetrators went through several hoops to ultimately compromise the systems of the SCM users at the targeted organizations. This means that the attackers now had access to the SCM system and could siphon out source code or, worse, modify and add code.

As we continued our investigation, we realized that the SCM installations often aren’t properly secured. Many organizations have tight security around financial systems and other mission critical systems, but leave their intellectual property repositories broadly accessible. The company might have strong perimeter security, but once you’re in the SCM is readily available.

The SCM implementations were inherently insecure. A common SCM system we found in many of the Operation Aurora attacks, called Perforce, was researched by McAfee as to exactly how these attacks were targeting people with privileged access to intellectual property, including source code.

In the wake of Operation Aurora we published a white paper today that explores how SCM should be secured. We took a hard look at Perforce first and will look at other applications in the near future.

The main point: intellectual property is valuable, perhaps even more valuable than money, so it should be properly secured. If organizations today secured their financial assets as they secure their source code, they’d be broke.

You can follow George Kurtz on Twitter. Courtesy McAfee.



» Send this article to a friend...
» Comments? Tell us what you think...
» More Network & Information Security articles...

AddThis Social Bookmark Button

Search EnterpriseInnovator

ph.gif ph.gif
Support This Site



Newest Articles

• 3/6 Faultline: Apple case against HTC could be the defining patent case for touch
• 3/6 Security Insights: Oscar nominees are more popular and risky online right now
• 3/6 Security Insights: Is Hybrid Email Security Right For You?
• 3/4 Innovation Insights: The Bloom Box's Disruptive Potential
• 3/4 Faultline: OTT fever stalks European set top deals – as old school collapses
• 3/3 Wireless Watch: Orange backs MeeGo to support its three-screen content strategy
• 3/3 Wireless Watch: LiMO supports operator software drive, but Vodafone 360 will be litmus test
• 3/3 Security Insights: McAfee Featured on Army’s APL
• 3/3 Security Insights: Source Code Repositories Targeted In Operation Aurora
• 3/3 What I Couldn't Say: An Individual’s Agenda
• 3/2 Datamonitor: Greener-homes strategy will face key challenges
• 2/26 Datamonitor: LBG and RBS: courting yet more public anger in the UK
• 2/26 Security Insights: Go Team USA! But is your favorite Olympic star dangerous?
• 2/25 Datamonitor: Google: managing its energy demand is the key to a low-cost supply
• 2/25 Datamonitor: Centrica: unfair criticism for record profits
• 2/25 Innovation Insights: How to Kill Innovation: Keep Asking Questions
• 2/25 Security Insights: HITECH Name-And-Shame Goes Up A Gear
• 2/25 Security Insights: Phishing For Twitter Credentials
• 2/25 Security Insights: RSA – Locked and Loaded
• 2/24 Security Insights: McAfee Vulnerability Manager an SC Magazine “Best Buy”
• 2/23 Rethink Research: Tablets, smartbooks and cloudbooks; the first battlefield in the PC phone wars - Forecasts to 2014
• 2/22 Technology Pundits: Why Microsoft Should Not Be in Consol Gaming Part II
• 2/22 WiMAX Directions: Mobile World Congress: WiMAX community looks to a 2G/4G future
• 2/20 Security Insights: Critical Control 20: Security Skills Assessment and Training to Fill Gaps
• 2/19 Technology Pundits: Why Microsoft Should Not Be in Console Gaming
• 2/18 Innovation Insights: Featuring the Flaw
• 2/10 Innovation Insights: Four Innovation Lessons from Anheuser-Busch
• 2/3 WiMAX Directions: WiMAX’ ratings surge, but beware of WiMAX2 confusion
• 2/1 Innovation Insights: Soothing the Customer's Itch
• 1/28 Datamonitor: iPad: Apple takes a bite of the e-books market
• 1/27 Innovation Insights: Does the Apple iPad Make Strategic Sense?
• 1/22 Innovation Insights: Why Do We Care about Disruption?
• 1/22 What I Couldn't Say: Where Life Takes Me Next
• 1/20 WiMAX Directions: LTE can only dream as WiMAX starts to deliver the flat IP network
• 1/18 Rethink Research: The Rise of the ATSC M/H machines; The Battle for American Mobile TV
• 1/14 Innovation Insights: The Disruptors of the Decade
• 1/7 Innovation Insights: A Postcard of Disruption in India
• 1/6 WiMAX Directions: CES: Why Apple really does need a WiMAX iSlate
• 1/5 Innovation Insights: The Google Phone's Disruptive Potential
• 12/22 Over The River: Technology finally bites me

AddThis Feed Button

VOA News: Science and Technology

• 9/3 India to Extend Crackdown On Online Communication Companies
• 9/2 Physicist Stephen Hawking: God Did Not Create Universe
• 9/1 Fun and Games
• 8/31 Technology Changes Peace Corps Experience
• 8/31 Iran Plans to Create Domestic Internet Search Engine
• 8/31 Where Did All The Oil Go?
• 9/1 Apple Introduces New iPod Music Player
• 8/27 Companies Race to Bring 3D to Consumers
• 8/27 Footprints on the Internet
• 8/26 Cyber Attacks Againts US Military Computers Increase Sharply
• 8/25 New Corn Varieties Could Combat Famine During Drought
• 8/25 The Electronic Rumor Mill
• 8/19 US-Sponsored Fellowship Program Benefits Women Scientists in Africa
• 8/20 Deep Water Plume Persists Months After BP Oil Well Blowout
• 8/18 Astronaut Twins Rendezvous in Space

Ads

ph.gif
ph.gif Top ph.gif

© 2008 EnterpriseInnovator. All rights reserved.