Innovating The Next Big Thing September 4, 2010 ph.gif
ph.gif
Sections

Analyst Insights
Enterprise Insights
Enterprise Mobility
Network & Information Security
Reader Reactions

Our Publications

TechnologyInnovator
EnterpriseInnovator
SecurityInnovator
WirelessInnovator 

Contact

• NextInnovator(at)Live.com
• No spam, subscription newsletters, solicitations, or attachments please!
• Attn: Harold Abraham, Chief Innovator

NASA News Feed


Transportation Innovators

• Advanced Transit Association
• Advanced Vehicles and Fuels Research
• Airbus A380 Revealed
• Boeing Dreamliner
• European Space Agency
• Inst. for Transportation & Develop't Policy
• NASA: Main Page
• NASA: Deep Impact Mission
• NASA: Mars Exploration Rovers
• NASA: New Horizons: Pluto-KB Mission
• Railway-Technology
• SpaceShip One
• Transportation Journal
• Transportation Planning and Technology
• Transport Research Knowledge Centre
• U. Internationale des Transports Publics
• Virgin Atlantic Global Flyer

Next Innovators

Over the River
eMarketer 
TechnologyPundits
Security Insights Blog 
McAfee AudioParasitics
Strand Consult
Ovum
The Eye For Innovation
Rethink Research
• Innovation Insights
Innoblog
Strategy and Innovation
The Gadgeteer
Handheld Speech
Ghost City

Transportation Headlines

• Bike & Scooter Technology Headlines
• Automotive Technology Headlines
• Train & Trolley Technology Headlines
• Marine Technology Headlines
• Air & Space Technology Headlines

Writers Wanted

Writers Wanted

Transportation Books

Feedjit Live Web Stats


Buy Our Books!



 


 


 
Ads

ph.gif ph.gif
Enterprise Insights Security Insights: Source Code Repositories Targeted In Operation Aurora
Mar 3, 2010 – By George Kurtz

Operation Aurora continues to be a hot topic inside and outside of security circles. At this week’s RSA Conference in San Francisco many conversations are on the topic of the attacks that hit Google and dozens of other companies in January.

During a talk this afternoon Stuart McClure and I discussed how the attackers in Operation Aurora went after the crown jewels of the targeted companies, their intellectual property. Also, we disclosed some additional findings from the McAfee investigation into the attacks.

Specifically, we have concluded that, in several cases, the attackers executed precision strikes to gain access to source code configuration management systems (SCMs) at targeted companies. SCMs are used by software engineers to manage their projects and are used to store source code, the crown jewels of any tech company.

In our analysis of the attacks we found that the perpetrators went through several hoops to ultimately compromise the systems of the SCM users at the targeted organizations. This means that the attackers now had access to the SCM system and could siphon out source code or, worse, modify and add code.

As we continued our investigation, we realized that the SCM installations often aren’t properly secured. Many organizations have tight security around financial systems and other mission critical systems, but leave their intellectual property repositories broadly accessible. The company might have strong perimeter security, but once you’re in the SCM is readily available.

The SCM implementations were inherently insecure. A common SCM system we found in many of the Operation Aurora attacks, called Perforce, was researched by McAfee as to exactly how these attacks were targeting people with privileged access to intellectual property, including source code.

In the wake of Operation Aurora we published a white paper today that explores how SCM should be secured. We took a hard look at Perforce first and will look at other applications in the near future.

The main point: intellectual property is valuable, perhaps even more valuable than money, so it should be properly secured. If organizations today secured their financial assets as they secure their source code, they’d be broke.

You can follow George Kurtz on Twitter. Courtesy McAfee.



» Send this article to a friend...
» Comments? Tell us what you think...
» More Enterprise Insights articles...

AddThis Social Bookmark Button

Search SMBInnovator

ph.gif ph.gif


Newest Articles

• 3/6 Faultline: Apple case against HTC could be the defining patent case for touch
• 3/6 Security Insights: Oscar nominees are more popular and risky online right now
• 3/6 Security Insights: Is Hybrid Email Security Right For You?
• 3/4 Innovation Insights: The Bloom Box's Disruptive Potential
• 3/4 Faultline: OTT fever stalks European set top deals – as old school collapses
• 3/3 Wireless Watch: Orange backs MeeGo to support its three-screen content strategy
• 3/3 Wireless Watch: LiMO supports operator software drive, but Vodafone 360 will be litmus test
• 3/3 Security Insights: McAfee Featured on Army’s APL
• 3/3 Security Insights: Source Code Repositories Targeted In Operation Aurora
• 3/3 What I Couldn't Say: An Individual’s Agenda
• 3/2 Datamonitor: Greener-homes strategy will face key challenges
• 2/26 Datamonitor: LBG and RBS: courting yet more public anger in the UK
• 2/26 Security Insights: Go Team USA! But is your favorite Olympic star dangerous?
• 2/25 Datamonitor: Google: managing its energy demand is the key to a low-cost supply
• 2/25 Datamonitor: Centrica: unfair criticism for record profits
• 2/25 Innovation Insights: How to Kill Innovation: Keep Asking Questions
• 2/25 Security Insights: HITECH Name-And-Shame Goes Up A Gear
• 2/25 Security Insights: Phishing For Twitter Credentials
• 2/25 Security Insights: RSA – Locked and Loaded
• 2/24 Security Insights: McAfee Vulnerability Manager an SC Magazine “Best Buy”
• 2/23 Rethink Research: Tablets, smartbooks and cloudbooks; the first battlefield in the PC phone wars - Forecasts to 2014
• 2/22 Technology Pundits: Why Microsoft Should Not Be in Consol Gaming Part II
• 2/22 WiMAX Directions: Mobile World Congress: WiMAX community looks to a 2G/4G future
• 2/20 Security Insights: Critical Control 20: Security Skills Assessment and Training to Fill Gaps
• 2/19 Technology Pundits: Why Microsoft Should Not Be in Console Gaming
• 2/18 Innovation Insights: Featuring the Flaw
• 2/10 Innovation Insights: Four Innovation Lessons from Anheuser-Busch
• 2/3 WiMAX Directions: WiMAX’ ratings surge, but beware of WiMAX2 confusion
• 2/1 Innovation Insights: Soothing the Customer's Itch
• 1/28 Datamonitor: iPad: Apple takes a bite of the e-books market
• 1/27 Innovation Insights: Does the Apple iPad Make Strategic Sense?
• 1/22 Innovation Insights: Why Do We Care about Disruption?
• 1/22 What I Couldn't Say: Where Life Takes Me Next
• 1/20 WiMAX Directions: LTE can only dream as WiMAX starts to deliver the flat IP network
• 1/18 Rethink Research: The Rise of the ATSC M/H machines; The Battle for American Mobile TV
• 1/14 Innovation Insights: The Disruptors of the Decade
• 1/7 Innovation Insights: A Postcard of Disruption in India
• 1/6 WiMAX Directions: CES: Why Apple really does need a WiMAX iSlate
• 1/5 Innovation Insights: The Google Phone's Disruptive Potential
• 12/22 Over The River: Technology finally bites me

AddThis Feed Button

Ads

ph.gif
ph.gif Top ph.gif

© 2008 SMBInnovator. All rights reserved.