Upcoming Events

A Network Computing Webinar:
Avoiding Downtime: How Virtualization Can Help In Times of Trouble

June 12, 2013
11:00 AM PT / 2:00 PM ET

Are you caught between a desire for the benefits of the cloud and concerns about security and control? Then you should attend this insight-packed webinar to learn how private data networking technologies like MPLS IP-VPNs can address your concerns and allow you to safely and intelligently reap the savings, agility and other benefits associated with cloud computing.

Join us to hear top industry experts discuss the private data network technologies that are best suited for enterprise cloud access requirements. You won't want to miss this opportunity to learn how your organization can best mitigate risk while reaping the full potential benefits of the cloud.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

More Data On Attackers, But Attribution Still Dodgy


Identifying the groups behind attacks is still a dicey proposition, but security firms are collecting more information on attackers' techniques and their infrastructure

Following the compromise of The New York Times' network, Mandiant--the company that responded to the incident and conducted the forensics analysis--collected enough evidence to identify the attacker. Yet, "identify" is a loaded word in the field of digital forensics and the name that the company had for the perpetrators came down to an internal designation: APT group 12.

Mandiant tracks some 20-odd information-stealing groups--all related to China--basing its identification on characteristics of the attackers' tactics, techniques and procedures, including the specific pieces of malware that are being used, the command-and-control (C2) channels, the specific domains from which they attack, and the sorts of data they target.

While the firm does not necessarily identify individuals in the monitored groups, by linking the attackers to APT-12, Mandiant also linked them to China, which can help inform a target's strategy, says Nick Bennett, principal consultant with the firm.

"We can tie this activity to a specific group that we've been tracking through our forensic analysis," Bennett says. "This group, and other groups like it, we have been able to monitor over months and years, and based on that, their activities fall in line with the interests of the Chinese."

... Read full story on Dark Reading

Post a comment to the original version of this story on Dark Reading

Related Reading


More Insights



Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | Please read our commenting policy.
 

Best of the Web

VXLAN termination on physical devices

VXLAN is an Experimental IETF draft of protocols to enable the creation of a large overlay, multi-tenant network.

Quick Read

ONF Deadly Serious About OpenFlow-Based SDNs

: OpenFlow is poised to reach over-hyped status, yet there are practical, useful reasons for keeping an eye on Openflow. The biggest cloud players are involved and driving the feature creation.

Quick Read

Practical Introduction to Applied OpenFlow

Get a primer on the Openflow protocol and what it can do for networking.

Quick Read

On Resilience of Spit-Architecture Networks

This research papers investigates the practical issues in split-architecture networks and the placement of the controllers, such as Openflow controllers, in the network.

Quick Read

Vendor Comparisons
Network Computing’s Vendor Comparisons provide extensive details on products and services, including downloadable feature matrices. Our categories include:

Research and Reports

May 2013
Network Computing: May 2013


TechWeb Careers