Two Dimensional Thinking and APT

January 30th, 2010 admin

I expect many readers will recognize the image at left as representing part of the final space battle in Star Trek II: The Wrath of Khan. During this battle, Kirk and Spock realize Khan’s tactics are limited. Khan is treating the battle like it is occuring on the open seas, not in space. Spock says: He is intelligent, but not experienced. His pattern indicates two-dimensional thinking. I though this quote could describe many of the advanced persistent threat critics, particularly those who claim “it’s just espionage” or “there’s nothing new about this.” Consider this one last argument to change your mind. (Ha, like that will happen. For everyone else, this is how I arrive at my conclusions.) I think the problem is APT critics are thinking in one or two dimensions at most, when really this…


Originally posted on TAOSecurity

 
  Related Posts
Reaction to 60 Minutes Story
Reaction to 60 Minutes Story
I found the new 60 Minutes update on information warfare to be interesting. I fear that the debate over whether or not “hackers” disabled Brazil’s electrical grid will overshadow the real issue presented in the story: advanced persistent threats are here, have been here, and will continue to be here. Some critics claim APT must... 
What Is APT and What Does It Want?
What Is APT and What Does It Want?
This has been the week to discuss the advanced persistent threat , although some people are already telling me Google v China with respect to APT is “silly,” or that the attack vectors were what everyone has been talking about for years, and were somewhat sloppily orchestrated at that. I think many of these critics are missing the... 
Mandiant M-Trends on APT
Mandiant M-Trends on APT
If you want to read a concise yet informative and clue-backed report on advanced persistent threat , I recommend completing this form to receive the first Mandiant M-Trends report. Mandiant occupies a unique position with respect to this problem because they are one of only two security service companies with substantial counter-APT consulting... 
Example of Threat-Centric Security
Example of Threat-Centric Security
In my last post I mentioned the need to take threat-centric approaches to advanced persistent threat . No sooner than I had posted those thoughts do I read this: Beijing ’strongly indignant’ about U.S.-Taiwan arms sale The Obama administration announced the sale Friday of $6 billion worth of Patriot anti-missile systems, helicopters,... 
Answering APT Misconceptions
Answering APT Misconceptions
There’s finally some good reporting on advanced persistent threat appearing in various news sources. A new Christian Science Monitor story, one by Federal Computer Week , and one by Wired are making progress in raising awareness. Unfortunately, there’s plenty of Tweeting and blogging by people who refuse to understand what is happening... 
Mechagodzilla v Godzilla
Mechagodzilla v Godzilla
After posting Google v China I realized this is a showdown like no other. In my experience, no one “ejects” the advanced persistent threat. If you think they are gone, it’s either 1) because they decided to leave or 2) you can’t find them. Now we hear Google is the latest victim. Google is supposed to be a place where IT... 
Energy Sector v China
Energy Sector v China
The aftershocks of Google v China continue to rumble as more companies are linked to the advanced persistent threat . Mark Clayton from the Christian Science Monitor wrote a story titled US oil industry hit by cyberattacks: Was China involved? I found these excerpts interesting. At least three US oil companies were the target of a series of previously... 
Attribution Is Not Just Malware Analysis
Attribution Is Not Just Malware Analysis
In a recent Tweet I recommended reading Joe Stewart’s insightful analysis of malware involved in Google v China . Joe’s work is stellar as always, but I am reading more and more commentary that shows many people don’t have the right frame of reference to understand this problem. In brief, too many people are focusing on the malware... 
Caught on Tape – Selling Americas Secrets – 60 Minutes
(CBS) “60 Minutes” has obtained an FBI videotape showing a Defense Department employee selling secrets to a Chinese spy for cash. The video, which has never been made public before, offers a rare glimpse into the secretive world of espionage and illustrates how China’s spying may now pose the biggest espionage threat to the This story... 
Look Beyond the Exploit
Look Beyond the Exploit
The post One Exploit Should Not Ruin Your Day by Dino Dai Zovi made me think: Finally, the larger problem is that it only took one exploit to compromise these organizations. One exploit should never ruin you day. [sic] No, that is wrong. The larger problem is not that it “only took one exploit to compromise these organizations.” I... 
  Related Tweets from Twitter
PH1218 (Jo Ellen)  : $PMCS back from the dead, busting it's coop now $APT needs vol, great earnings and heavily shorted $FAS $JPM $USB $DOW..
Updated : 2010-03-10T15:42:15Z   |  Reply  |  View Tweet
St_Mediocrity (Jon)  : fuck, 15h/week in the bus is really starting to break me up mentally... 3 more weeks till my new a'dam apt is livable :)..
Updated : 2010-03-10T15:41:54Z   |  Reply  |  View Tweet
zaianne (Zaianne Sparrow)  : Does anyone have any leads for a room/apt/studio for rent in NYC? A friend of mine just moved there and needs to find something soon! Thanks..
Updated : 2010-03-10T15:41:23Z   |  Reply  |  View Tweet
ExpletiveDleted (Dawn Erickson)  : The sound quality on 2012 on BluRay is frickin' awesome. The surround sound feels like my apt is breaking apart..
Updated : 2010-03-10T15:41:01Z   |  Reply  |  View Tweet
bruce_arthur (Bruce Arthur)  : You mean he threw something out there that he wants back? Apt. RT @espn Derek Anderson regrets lashing out at Browns fans following release..
Updated : 2010-03-10T15:40:50Z   |  Reply  |  View Tweet
  Related News from Digg
No comments yet.

Spam Protection by WP-SpamFree

TOP