4 ms·
Nothing about "active command and control servers" is strongly attributable. They aren't signing them with Russian government certificates or running them from
by problems 10y ago
Nothing about "active command and control servers" is strongly attributable.
They aren't signing them with Russian government certificates or running them from Russian government IPs.
They're buying servers or VPN connections on public providers. The notion of "strong attribution" in and of itself is basically impossible in the field of malware unless someone steps up and shows you the source. Those are things anyone can do. They're only doing a probabilistic analysis assuming no one else knows them, which makes many very large assumptions - like no one else wanting to fake Russian malware.
He comes off quite partisan in my opinion - his Twitter pretty much confirms it as he compares Wired to Brietbart. I wouldn't listen to a word this guy says on the topic.
- mikeyouse 10y ago> They're buying servers or VPN connections on public providers. The notion of "strong attribution" in and of itself is basically impossible in the field of malware unless someone steps up and shows you the source. Those are things anyone can do. They're only doing a probabilistic analysis assuming no one else knows them, which makes many very large assumptions - like no one else wanting to fake Russian malware. Strong Attribution is definitely a difficult task and unless someone admits guilt, you'll have to rely on probabilities but the combined CrowdStrike, SecureWorks, and ThreatConnect reports give a fairly strong basis of where to place blame for the DNC servers. I'd imagine our intelligence agencies have their own methods of attribution that we won't learn of for a long time. As for Rob, this feels like a pretty balanced opinion: > The DNC hacks have strong evidence pointing to Russia. Not only does all the malware check out, but also other, harder to "false flag" bits, like active command-and-control servers. A serious operator could still false-flag this in theory, if only by bribing people in Russia, but nothing in the CIA dump hints at this. > The Sony hacks have weak evidence pointing to North Korea. One of the items was the use of the RawDisk driver, used both in malware attributed to North Korea and the Sony attacks. This was described as "flimsy" at the time []. The CIA dump [] demonstrates that indeed it's flimsy -- as apparently CIA malware also uses the RawDisk code. > In the coming days, biased partisans are going to seize on the CIA leaks as proof of "false flag" operations, calling into question Russian hacks. No, this isn't valid. We experts in the industry criticized "malware techniques" as flimsy attribution, long before the Sony attack, and long before the DNC hacks. All the CIA leaks do is prove we were right. On the other hand, the DNC hack attribution is based on more than just this, so nothing in the CIA leaks calls into question that attribution. https://www.threatconnect.com/blog/tapping-into-democratic-national-committee/ https://www.threatconnect.com/blog/tapping-into-democratic-n... https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign https://www.secureworks.com/research/threat-group-4127-targe... https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ https://www.crowdstrike.com/blog/bears-midst-intrusion-democ...
- problems 10y ago> Strong Attribution is definitely a difficult task and unless someone admits guilt, you'll have to rely on probabilities but the combined CrowdStrike, SecureWorks, and ThreatConnect reports give a fairly strong basis of where to place blame for the DNC servers. That's the thing though - you can place that blame whereever you want simply by making it look that way - buying servers from the right providers, modifying existing malware to suit your purposes via reverse engineering, etc. It's fairly straightforward stuff for someone in the know to do. The probabilistic analysis does not and cannot account for fakery of this sort - the posts you linked do not attempt to account for this at all, instead assuming blindly that "hey, this looks vaguely like this russian attack group". I read his posting there - it seemed sketchy to me - then I read his Twitter account and it explained why it seemed sketchy. He's a blatant partisan, looking only to prove his side. I'm not saying it's not possible it's Russia. It's quite possibly Russia. Probable even. Just that I don't trust the only possible analysis methods at a deep level such that I don't feel blame can be reliably laid in such a case.