Staying One Step Ahead Of The Cyber Spies

If you want a job that rides the wave of the future, get hired by a firm that combats cyber-threats. Criminal and malicious hackers are endlessly inventive and every day dispatch novel viruses and other digital threats into cyber-space to wreak havoc. Getting paid to tackle these is about as cutting edge as you can get.

One emerging discipline in this field of cyber-incident response tackles the most skilled and serious of these hackers - those who work for nation-states.

The UK's GCHQ now estimates that 34 separate nations have serious, well-funded cyber-espionage teams targeting friends and foes alike.

The threat from these state-sponsored digital spies has been deemed so serious that the intelligence agency has designated five firms that victims can call on if they are caught out by these attackers.

"We get called when people have a big fire and we come along with our hoses and try to put it out," says James Allman-Talbot, head of incident response in the cybersecurity division of BAE Systems.

That captures the fact that, more often than not, the fire brigade arrives to find a building still in flames. When it comes to cyber-fires, that means the hackers are still embedded in a victim's network and are still trying to steal data or burrow more deeply. Unlike the fire service, the BAE team do not arrive in a blaze of lights and sirens. They have to be more, stealthy.

"If the attackers have access to the victim's email servers the last thing you want to do is discuss it on there," says Robin Oldham, head of the cyber-security consulting practice at BAE, who is also part of the incident response team.

Tipping off the bad guys could prompt them to delete evidence or, if they have more malicious motives, shut down key systems and destroy data, he says. Instead, responders first gather evidence to see how bad the incident is and how far the hackers have penetrated a network. It's at this point that the team use the skills picked up during earlier careers. All of the team have solid technical computer skills to which they have added particular specialities.

Prior to working at BAE, Mr Allman-Talbot did digital forensics for the Metropolitan Police and Mr Oldham has significant experience running large complex networks. The good news about most organisations is that they typically gather lots of information about their network and often it is anomalies in the logs that expose suspicious activity. But that extensive logging has a down side, says Mr Oldham.

"It can mean we have a large amount of data to work with and analyse. In some cases, that means a few hundred million lines of log files."

Once incident response teams get their hands on data from a victim they start analysing it to see what has happened. It's at this point that the allied discipline of threat intelligence comes into play. This involves knowing the typical attack tools and techniques of different hacking groups.

Good threat intelligence can mean responders hit the ground running, says Jason Hill, a researcher at security firm CyberInt.

"If you understand how they operate and deploy these tools and use them to attack the infrastructure you know what to look and how to spot the tell-tale signs."

In the past, nation state hackers have tried to bury themselves in a target network and siphon off data slowly.

"Criminal hackers have a more smash and grab mentality. They do it once and do it big," he says.

More recently, he adds, it has got harder to separate the spies from the cyber-thieves. One example was the attack on Bangladesh's central bank - widely believed to have been carried out by North Korea. It netted the rogue state about £58m ($81m).

Russian groups also span both sides of the divide. Some criminal groups have been seen working for the state and often they use the tools gained in spying for other jobs.

"The motivations of the groups have really become blurry of late," says Mr Hill.

Attribution - working out which group was behind a breach - can be difficult, says Mr Allman-Talbot, but spotting that one attack shares characteristics with several others can guide the investigators. 

One widespread attack, dubbed Cloud Hopper, sought to compromise companies selling web-based services to large businesses. Getting access to a service provider could mean that the attackers then got at all its customers.

Thoroughly investigated by BAE and others, Cloud Hopper has been blamed on one of China's state-backed hacking groups known as APT10 and Stone Panda. Knowing how they got at a victim can help free the hackers' hold on a network and reveal all the places that need cleaning up.

Even with up-to-date intelligence on attack groups and their chosen methods, there will still be unanswered questions thrown up by an investigation, says Mr Allman-Talbot. The joy of the job comes from during investigations as the team figures out how the bad guys got in, what they did and what data they got away with, he adds. He likens it to solving complex puzzles and problems using experience, good hunches, deep analysis and coding skills. It's a challenging profession that regularly bestows solid intellectual rewards.

"There are lots of eureka moments," he says.

The deep knowledge built up by the responders as they investigate and clean up a breach can also help others that might not even know they have been penetrated, says Mr Oldham.

"There are people that see the smoke alarm go off and pick up the phone and tell us that something is wrong. There's others that we go to and tell them that their house is on fire," he adds.

Mr Allman-Talbot says some of the satisfaction with the job comes from helping people and making life online safer.

"Just as with criminal cases, there's a real sense of doing good. We are investigating incidents that have badly affected these organisations."

There's little doubt that the job is only going to more important as time goes on. The cyber-spies will not stop and are only going to get better at what they do.

"It's just going to get more and more complex," says Mr Allman-Talbot. "It's the next form of warfare."

BBC:      Image: Nick Youngson

You Might Also Read:

Spy vs Spy - Cozy Bear Hackers Hacked:

Dutch Intelligence Agency Pinpoints Cyberattacks:

 

« Snowden Says Bitcoin Is Not Private
Healthcare Security Should Use More Sophisticated Tools »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Advenica

Advenica

Advenica develops, manufactures and sells innovative cybersecurity solutions for encryption and secure information exchange.

Cyanre

Cyanre

Cyanre delivers state of the art cyber forensic services through software technologies and procedures that exceed conformities of major law enforcement agencies across the globe.

Sequitur Labs

Sequitur Labs

Sequitur Labs is developing seminal technologies and solutions to secure and manage connected devices of today and in the future.

th4ts3cur1ty.company

th4ts3cur1ty.company

th4ts3cur1ty.company specialize in delivering intelligence lead adversary emulation purple teaming & the bespoke building of Security Operation Centers.

Sponge

Sponge

Sponge is a world-renowned digital learning provider on a mission to make learning unforgettable.

Haechi Audit

Haechi Audit

Haechi Audit is a leading smart contract security audit firm. We provide the most secure smart contract security audit and smart contract development services to our global clients.

Glocomms

Glocomms

Glocomms is a leading specialist recruitment agency for the tech sector, providing permanent, contract, and multi-hire recruitment from our global hubs in San Francisco, New York, London and Berlin.

1Password

1Password

1Password combines industry-leading security with award-winning design to bring private, secure, and user-friendly password management to everyone.

Robo Shadow

Robo Shadow

Robo Shadow are trying to bridge the gap between the top tier organisations that can afford everything and everyone else who has to “Make it up as they go along” when it comes to Cyber.

Sure Valley Ventures

Sure Valley Ventures

Sure Valley Ventures is an entrepreneur led venture capital fund focused on helping software entrepreneurs grow and scale businesses that will have a global impact.

CYMAR

CYMAR

CYMAR The “CYBER” Smart Solution to offer sustainability and bring resilience to Global SMART Terminals and protect the supply chain of the World’s economy.

Commission Nationale de l'Informatique et des Libertés (CNIL) - France

Commission Nationale de l'Informatique et des Libertés (CNIL) - France

The mission of CNIL is to protect personal data, support innovation, and preserve individual liberties.

TAFEcyber

TAFEcyber

TAFEcyber is an Australian based consortium focusing on the skilling of the fast-growing cyber security workforce through education and training.

MiDO Technologies

MiDO Technologies

MiDO Technologies has a mission to change the narrative around digital enabling tools on the continent of Africa and prepare African youth.

DigitalXForce

DigitalXForce

DigitalXForce is the Digital Trust Platform for the New Era – SaaS based solution that provides Automated, Continuous, Real Time Security & Privacy Risk Management.

Panasonic Automotive Systems

Panasonic Automotive Systems

Panasonic Automotive Systems brings together security technologies and human resources cultivated across an extensive range of businesses into the automotive field.