Innovating The Next Big Thing September 8, 2010 ph.gif
ph.gif
Our Publications

TechnologyInnovator
EnterpriseInnovator
SecurityInnovator
WirelessInnovator 

Contact

• NextInnovator(at)Live.com
• No spam, subscription newsletters, solicitations, or attachments please!
• Attn: Harold Abraham, Chief Innovator

CNN Technology


EnterpriseInnovator Headlines

IT Headline News
Mobile Enterprise Headline News
Grid & Supercomputing Headline News
Bio & Life Science Computing Headlines
Nano-Computing Headline News
Telecom Headline News
Network Headline News
Desktop & Workstation Headline News
Server Headline News
Chip Headline News
OS Headline News
Storage Headline News
Enterprise Security Headline News

SecurityInnovator Headlines

Cyberwarfare Headline News
Biometrics & Surveillance Headline News
Terrorism Headline News
Guerrilla Warfare Headline News
Nuclear Strategy Headline News
WMD Headline News

WirelessInnovator Headlines

SmartPhone Headline News
PDA Headline News
3G Headline News
Bluetooth Headline News
WiFi, WiMAX & WAN Headline News
Tablet Headline News
Laptop Headline News

EnergyInnovator Headlines

Solar Energy Headline News
Wind Energy Headline News
Fuel Cell Headline News
Fossil Fuel Headline News
Hydro Energy Headline News
Nuclear Energy Headline News

Transportation Headlines

Bike & Scooter Technology Headlines
Automotive Technology Headlines
Train & Trolley Technology Headlines
Marine Technology Headlines
Air & Space Technology Headlines

NextInnovator Headlines

Speech Interface Headline News
Telematics Headline News
Wearable Interface Headline News
Biometrics Headline News
Neural Interface Headline News
A.I. Headline News
3D Interface Headline News

Next Innovators

Over the River
eMarketer 
TechnologyPundits
Security Insights Blog 
McAfee AudioParasitics
Strand Consult
Ovum
The Eye For Innovation
Rethink Research
• Innovation Insights
Innoblog
Strategy and Innovation
The Gadgeteer
Handheld Speech
Ghost City

Writers Wanted

Writers Wanted

Amazon Ads: Cell Phones & Plans

Amazon Ads: Notebooks

Amazon Ads: PDAs and Handhelds

Amazon Ads: Desktop PCs

Amazon Ads: Computer Peripherals

Amazon Ads: More Cell Phones

Feedjit Live Web Stats


Ads

ph.gif ph.gif
Network & Information Security Security Insights: Source Code Repositories Targeted In Operation Aurora
Mar 3, 2010 – By George Kurtz

Operation Aurora continues to be a hot topic inside and outside of security circles. At this week’s RSA Conference in San Francisco many conversations are on the topic of the attacks that hit Google and dozens of other companies in January.

During a talk this afternoon Stuart McClure and I discussed how the attackers in Operation Aurora went after the crown jewels of the targeted companies, their intellectual property. Also, we disclosed some additional findings from the McAfee investigation into the attacks.

Specifically, we have concluded that, in several cases, the attackers executed precision strikes to gain access to source code configuration management systems (SCMs) at targeted companies. SCMs are used by software engineers to manage their projects and are used to store source code, the crown jewels of any tech company.

In our analysis of the attacks we found that the perpetrators went through several hoops to ultimately compromise the systems of the SCM users at the targeted organizations. This means that the attackers now had access to the SCM system and could siphon out source code or, worse, modify and add code.

As we continued our investigation, we realized that the SCM installations often aren’t properly secured. Many organizations have tight security around financial systems and other mission critical systems, but leave their intellectual property repositories broadly accessible. The company might have strong perimeter security, but once you’re in the SCM is readily available.

The SCM implementations were inherently insecure. A common SCM system we found in many of the Operation Aurora attacks, called Perforce, was researched by McAfee as to exactly how these attacks were targeting people with privileged access to intellectual property, including source code.

In the wake of Operation Aurora we published a white paper today that explores how SCM should be secured. We took a hard look at Perforce first and will look at other applications in the near future.

The main point: intellectual property is valuable, perhaps even more valuable than money, so it should be properly secured. If organizations today secured their financial assets as they secure their source code, they’d be broke.

You can follow George Kurtz on Twitter. Courtesy McAfee.



» Send this article to a friend...
» Comments? Tell us what you think...
» More Network & Information Security articles...

AddThis Social Bookmark Button

Search NextInnovator

ph.gif ph.gif
EnterpriseInnovator

Analyst Insights
Network & Information Security
Enterprise Mobility
Enterprise Insights
Reader Reactions
About

SecurityInnovator

Network & Information Security
Terrorism & Counterterrorism
Homeland Security & Defense
Strategic Thinkers
Weapons of Mass Destruction
Reader Reactions
About

WirelessInnovator

Enterprise Mobility
Mobile Telecom & mCommerce
Wireless Web
PDAs, Phones & Smart Devices
Mobile Arts & Entertainment
Mobile & Ultramobile PCs
Safety & Security
Voice & Speech Technology
The Next Interface
Remembering 9/11
Reader Reactions
About

HPInnovator

Innovation at HP
Leadership & Vision
The HP Ecosystem – Partners, Customers & Acquisitions
On the Go – Mobile & Wireless Solutions
Enterprise Solutions
The Fine Print – Imaging & Printing Solutions
Digital Arts & Entertainment
Analyst Insights
Enterprise Insights
Network & Information Security
Enterprise Mobility
About

EnergyInnovator

Climate Change: Causes and Solutions
Energy Insights
Solar and Wind Energy
Fuel Cells and The Hydrogen Economy
Nuclear Power
Fossil Fuels
Bio and Alternative Fuels
Geothermal, Hydro and Tidal Power
Reader Reactions
Energy Events
About

TransportationInnovator

Air & Space
Automotive
Marine & Submarine
Trains & Trolleys
Bikes & Scooters
Reader Reactions
About

Ads

ph.gif
ph.gif Top ph.gif

© 2008 NextInnovator. All rights reserved.