Email this article   Print article 


Lockheed Martin Discloses 'Significant And Tenacious' Cyber Attack

By Stefanie Hoffman
May 31, 2011    5:43 PM ET

Page 2 of 2

Ullrich said that RSA's recent SecureID exploit wouldn't likely result in widespread attacks, but could possibly emerge in targeted attacks on organizations -- such as weapons manufacturers -- of geo-political interest.

"It is generally assumed that the attack against RSA was conducted by China, and the Chinese government is in the possession of the information. As a result, I would expect the information to be used against specified targets that are of importance to China," he said.

RSA, the Security Division of EMC, became the focal point of public scrutiny in March after its SecureID tokens were subjected to a sophisticated and targeted attack known as an Advanced Persistent Threat .

Art Coviello, RSA executive chairman, publicly disclosed that the company had detected the cyber attack in progress, appearing to be an attempt to extract intellectual property and other sensitive information from corporate networks. The cyber criminals could potentially use the stolen information to emulate a token and essentially get around the SecureID security measures.

Meanwhile, RSA channel partners contend that the breach doesn't imply any kind of failing with two–factor authentication as a security measure. 'No one could look at RSA's security precautions and say they were inadequate," said Ken Phelan, chief technology officer of Montvale, N.J.-based Gotham Technology Group. he said. "I don't think a lot of people are saying 'it's important not to go two-factor.'"

Instead, Phelan said that recent Lockheed breach indicated the need for high-profile targets, such as Lockheed Martin, to diversify their security infrastructure and step up their response to cyber attacks.

"It's a wake-up call to a lot of people because they thought they were safe because of this one particular thing, and there's no one thing that makes you safe," Phelan said. "If you're the kind of company that's going to be targeted, you need to raise your game."



<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...