Cybersecurity Firms Ditch Defense, Learn To 'Hunt' | WAMU 88.5 - American University Radio

Cybersecurity Firms Ditch Defense, Learn To 'Hunt'

Play associated audio

The most challenging cyberattacks these days come from China and target Western firms' trade secrets and intellectual property. But a problem for some is a business opportunity for others: It's boom time for cybersecurity firms that specialize in going after Chinese hackers.

"It's the next big thing," says Richard Stiennon, an industry analyst who specializes in information security firms.

'An Adversary Problem'

One of the top competitors in this sector is Mandiant, a company founded in 2004 by Kevin Mandia, a former Air Force officer with a background in security consulting. The company distinguished itself early by helping companies learn more about who was attacking them, as opposed to protecting the companies from the malicious software, or malware, the attackers were using.

"It's a lot more fun to fight the adversary than to guard against him," Mandia says. The adversary he and his colleagues focused on from the start was China, the source of the most costly attacks affecting his customers.

In contrast with what he calls "the protection guys" in other security firms, Mandia and his colleagues emphasized intelligence gathering. They studied actors responsible for what cybersecurity officials euphemistically called "advanced persistent threats," or APTs, a term that generally refers to cyberattacks emanating from China.

Such attacks are "advanced" because they employ especially sophisticated methods to penetrate a computer network, and they are "persistent" because the attackers have specific targets and will linger inside a network until they have found the information they are after and extracted it.

"The Russians have done that for a while, but not in the same way the Chinese have," says Richard Bejtlich, the chief security officer for Mandiant. "The Chinese are very loud and broad and aggressive."

Understanding The Enemy

Mandiant threat researchers will monitor cyber-intrusions at a company until they have identified the attackers' characteristic work patterns and what Bejtlich calls their operational "playbook." He says there are signs of an interplay between junior people and senior people in the process.

"You see them fumbling around, and they can't do whatever it is they need to do, and then there's a pause and someone else comes in," Bejtlich says. "You can tell someone else is there because they type at a different frequency. They're entering different commands, [with] no spelling mistakes, whatever. They will get that part of the playbook to work, and then it goes back to whoever the first guy was."

The Mandiant researchers have so far identified 20 distinct groups responsible for the "advanced persistent threats" affecting their clients. Mandia says if his security consultants can identify which APT group is attacking a company, they will be better able to help the company deal with the threat.

"We can [tell] a team that's going to some Fortune 500 company, 'All the evidence points to APT Group 1 or APT Group 5,' " Mandia says. "[They will] immediately know the tools they use, the IP addresses they use, the pass phrases they use when they encrypt data, and where they store their files on the machine."

The Industry Expands

The surge in attacks from China has spurred other cybersecurity firms to follow the Mandiant lead, with services and products designed to deal with targeted threats.

"There are dozens, if not hundreds, of service providers doing things similar to Mandiant," says industry analyst Stiennon, "and product companies coming out of the woodwork."

A new entrant in the field is CrowdStrike, a company co-founded by Dmitri Alperovitch, the former chief of threat research at McAfee, where he led a team that uncovered several major cyber-espionage intrusions from China.

Like the researchers at Mandiant, Alperovitch says his company will focus on adversaries, not on the malware they use. "At the end of the day, you want to know what they are after," he says.

A Shift In Thought

For Alperovitch, the key element in the APT phenomenon is the persistence of the threat.

"There's really no organization, including government agencies, that can prevent this type of attack," Alperovitch says. "So you need to shift your mode into thinking that you are always in a state of compromise, and you need to start thinking about how to hunt on the network."

This is the new cybersecurity game: hunting the cyber adversary, tracking him down wherever he goes on a computer network, and confronting him over and over.

Copyright 2012 National Public Radio. To see more, visit


Miss Colombia Wins Pageant; Miss Jamaica Wins Twitter?

Days later, bad feelings linger among the Miss Universe pageant viewers who believe that the wrong contestant won. Many watchers on social media say Miss Jamaica should being wearing the crown.

Watch 'Bob's Burgers'? Now You Can Eat Them, Too

What happens when you try to make a burger out of a pun? One blog, two years, and dozens of recipes later, millions of fans can now cook up their very own Bob's burgers.
WAMU 88.5

Drilling Off Virginia Coast Could Harm Neighboring States, Cardin Says

The Obama administration has decided to open up the Atlantic states to offshore drilling, a move that is not playing well among East Coast democrats like U.S. Sen. Cardin (D-MD).

Facebook Suffers Self-Inflicted Outage

A Facebook statement said the disruption was caused by a technical change it made to the site and wasn't a cyberattack. The outage lasted an hour.

Leave a Comment

Help keep the conversation civil. Please refer to our Terms of Use and Code of Conduct before posting your comments.