Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

US Spent Billions On System To Detect Hacks. The Russians Outsmarted It.

US Spent Billions On System To Detect Hacks. The Russians Outsmarted It.

The Russians, whose operation was discovered this month by a cybersecurity firm that they hacked, were good.
When Russian hackers first slipped their digital Trojan horses into federal government computer systems, probably in the spring, they sat dormant for days, doing nothing but hiding. Then the malicious code sprang into action and began communicating with the outside world.

At that moment - when the Russian malware began sending transmissions from federal servers to command-and-control computers operated by the hackers - an opportunity for detection arose, much as human spies behind enemy lines are particularly vulnerable when they radio home to report what they've found.

Why, then, when computer networks at the State Department and other federal agencies started signaling to Russian servers, did nobody in the U.S. government notice that something odd was afoot?

The answer is part Russian skill, part federal government blind spot.

The Russians, whose operation was discovered this month by a cybersecurity firm that they hacked, were good. After initiating the hacks by corrupting patches of widely used network monitoring software, the hackers hid well, wiped away their tracks and communicated through IP addresses in the United States rather than ones in, say, Moscow, to minimize suspicions.

The hackers also used novel bits of malicious code that apparently evaded the U.S. government's multibillion-dollar detection system, Einstein, which focuses on finding new uses of known malware and detecting connections to parts of the Internet used in previous hacks.

But Einstein, operated by the Department of Homeland Security (DHS), was not equipped to find novel malware or Internet connections, despite a 2018 report from the Government Accountability Office suggesting that building such capability might be a wise investment. Some private cybersecurity firms do this type of "hunting" for suspicious communications - maybe an IP address to which a server has never before connected - but Einstein does not.

"It's fair to say that Einstein wasn't designed properly," said Thomas Bossert, a top cybersecurity official in both the George W. Bush and Trump administrations. "But that's a management failure."

The DHS did not respond to a request for comment.

Russia has denied involvement in the intrusions.

The federal government has invested heavily in securing its myriad computers, especially since the extent of the devastating Chinese hack of the Office of Personnel Management was discovered in 2015, when more than 20 million federal employees and others had their personal information, including Social Security numbers, compromised.

But this year's months-long hack of federal networks, discovered in recent days, has revealed new weaknesses and underscored some previously known ones, including the federal government's reliance on widely used commercial software that provides potential attack vectors for nation-state hackers.

The Russians reportedly found their way into federal systems by first hacking SolarWinds, a Texas-based maker of network-monitoring software, and then slipped the malware into automatic updates that network administrators, in the federal government and elsewhere, routinely install to keep their systems current. The company reported that nearly 18,000 of its customers may have been affected worldwide.

More broadly, the hack highlighted the struggles of the government's network-monitoring systems to detect threats delivered through newly written malicious code communicating to servers not previously affiliated with known cyberattacks. This is something advanced nation-state hackers, including from Russia, sometimes do - presumably because it makes intrusions harder to detect.

The full scope of the hack remains unknown, though it's clear that a growing number of agencies have been penetrated, including the departments of State, Treasury, Homeland Security and Commerce and the National Institutes of Health. They are among victims that include consulting, technology, telecom, and oil and gas companies in North America, Europe, Asia and the Middle East.

The Pentagon was assessing Tuesday whether there had been intrusions at the sprawling department and what impact they may have had, a spokesman said.

The FBI and Department of Homeland Security are investigating the scope and nature of the breaches, which intelligence officials say were carried out by the Russian Foreign Intelligence Service, the SVR. The U.S. government has not publicly attributed the hacks to anyone.

Emails were one target of the hackers, officials said. Although it's not yet clear what the Russians may be intending to do with the information, their victims, including a variety of State Department bureaus, suggest a range of motives.

At the State Department, they may want to know what policymakers' plans are with respect to regions and issues that affect Russia's strategic interests. At the Treasury, they may have sought insights into potential Russian targets of U.S. sanctions. At the National Institutes of Health (NIH), they may be interested in information related to coronavirus vaccine research.

As the investigative work continues, some lawmakers are focused on probing why and how federal cybersecurity efforts have fallen short despite years of damaging hacks by Russian and Chinese spies and major federal investments in defensive technologies.

Einstein, which was developed by the DHS and is operated by the department's Cybersecurity and Infrastructure Security Agency (CISA), was made to be a backbone of federal protection of civilian agency computers, but the 2018 GAO report found significant weaknesses.

The capability to "identify any anomalies that may indicate a cybersecurity compromise" was planned for deployment by 2022, the report said. It also said network monitoring by individual agencies is spotty. Of 23 federal agencies surveyed, five "were not monitoring inbound or outbound direct connections to outside entities," and 11 "were not persistently monitoring inbound encrypted traffic." Eight "were not persistently monitoring outbound encrypted traffic."

"DHS spent billions of taxpayer dollars on cyber defenses and all it got in return was a lemon with a catchy name," said Sen. Ron Wyden, D-Ore., a member of the Senate Intelligence Committee. "Despite warnings by government watchdogs, this administration failed to promptly deploy technology necessary to identify suspicious traffic and catch hackers using new tools and new servers."

It was not just this administration.

Bossert, who worked on the original Einstein concept in the George W. Bush administration, said the idea was to place active sensors at an agency's Internet gateway that could recognize and neutralize malicious command-and-control traffic. "But the Bush, Obama and Trump administrations," he said, "never designed Einstein to meet its full potential."

CISA officials told congressional staff on a Monday evening call that the system did not have the capacity to flag the malware that was signaling back to its Russian masters.

The officials said federal agencies had not given CISA the information necessary to identify agency servers that should not be communicating with the outside world, said one congressional aide, who spoke on the condition of anonymity to discuss a sensitive matter.

"To CISA, all internal agency computers look the same, and so Einstein only flags samples of known malware or connections to 'known bad' IP addresses," the aide said.

Other cybersecurity experts say the breaches highlight the "desperate" need for a government board that can conduct a deep investigation of an incident such as SolarWind's, whose corrupted patches enabled the compromises - and crucially, make the report public.

"We need people to read the report, and say, 'Oh, wow, we need to secure our [information technology] pipeline,' " said Alex Stamos, head of the Stanford Internet Observatory, a research group. He previously was chief security officer at Facebook and Yahoo.

He said there are "hundreds or thousands of companies" in this space that may have security flaws without knowing. These firms do network monitoring, IT management and log aggregation. "Enterprise IT is a $2 trillion market," Stamos said. "There's no agency in charge of ensuring its security."
AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
Woman Receives Gift Card for Christmas – Discovers It Is ‘Worth’ 63,000,000,000,000,000 Pounds
United Nations Calls for Global Action Against Disinformation and Hate Speech Online
Tucker Carlson warns of an inevitable clash in Western societies over mass migration
OpenAI CEO Sam Altman praises the rapid progress of Chinese tech companies.
Poland's President Karol Nawrocki ENDS support for Ukrainian citizens:
Italy's PM Giorgia Meloni highlights record employment and economic growth
Chancellor Friedrich Merz Re-elected as CDU Leader, Opposes AfD Influence
Trump Directs Government to Release UFO and Alien Information
Trump Signs Global 10% Tariffs on Imports
UK Government Considers Law to Remove Prince Andrew from Royal Line of Succession
Two teens arrested in France for alleged terror plot.
US Supreme Court Voids Trump’s Emergency Tariff Plan, Reshaping Trade Power and Fiscal Risk
Greek Prime Minister Kyriakos Mitsotakis advocates for a ban on minors using social media.
Meanwhile in Time Square, NYC One of the most famous landmarks
Jensen Huang just told the story of how Elon Musk became NVIDIA’s very first customer for their powerful AI supercomputer
Former British Prince Andrew Arrested on Suspicion of Misconduct in Public Office
Former President Yoon Suk Yeol Sentenced to Life in Prison for Abuse of Authority
Unitree Robotics founder Wang Xingxing showcases future robot deployment during Spring Festival Gala.
German Chancellor Friedrich Merz calls for real name use on social media.
Italian Police Arrest Man After Alleged Attempt to Abduct Toddler at Bergamo Supermarket, Child Hospitalised With Fractured Femur
British Tourist Arrested at Hong Kong Airport After Meltdown and Vandalism
European Commission Plans Purchase Incentives Limited to Vehicles Manufactured Largely in the EU
French District of Pas-de-Calais Introduces Immediate License Suspension for Drivers Using Mobile Phones
Volkswagen Targets €60 Billion in Cost Reductions as Sales Decline and Global Pressures Intensify
Eighty-Year-Old Lottery Winner Sentenced to 16.5 Years for Drug Trafficking
Rubio Calls for Sweeping U.N. Reform, Saying It Has Failed to End Wars in Gaza and Ukraine
10,000 Condoms Distributed at Winter Olympics 2026 Athlete Village Depleted Within 72 Hours
Poland's President Advocates for Evaluating Independent Nuclear Weapons Development
Mayor of Serdobsk in Russia’s Penza Region Resigns After Housing Certificates Granted to Migrant Family Trigger Public Outcry
China’s EV Makers Face Mandatory Return to Physical Buttons and Door Handles in Driver-Distraction Safety Overhaul
UK Green Party Considering Proposal to Legalize Heroin for an Inclusive Society
OpenAI and DeepCent Superintelligence Race: Artificial General Intelligence and AI Agents as a National Security Arms Race
We will protect them from the digital Wild West.’ Another country will ban social media for under-16s
Heineken announces cut of 6,000 jobs due to declining beer demand
Apple iPhone Lockdown Mode blocks FBI data access in journalist device seizure
Belgium: Man Charged with Rape After Faking Payment to Sex Worker
KPMG Urges Auditor to Relay AI Cost Savings
Canada Opens First Consulate in Greenland Amid Rising Geopolitical Tensions
China unveils plans for a 'Death Star' capable of launching missile strikes from space
Investigation Launched at Winter Olympics Over Ski Jumpers Injecting Hyaluronic Acid
U.S. State Department Issues Urgent Travel Warning for Citizens to Leave Iran Immediately
Wall Street Erases All Gains of 2026; Bitcoin Plummets 14% to $63,000
Eighty-one-year-old man in the United States fatally shoots Uber driver after scam threat
Political Censorship: French Prosecutors Raid Musk’s X Offices in Paris
AI Invented “Hot Springs” — Tourists Arrived and Were Shocked
France Begins Phasing Out Zoom and Microsoft Teams to Advance Digital Sovereignty
Tech Market Shifts and AI Investment Surge Drive Global Innovation and Layoffs
Global Shifts in War, Trade, Energy and Security Mark Major International Developments
Markets Jolt as AI Spending, US Policy Shifts, and Global Security Moves Drive New Volatility
Tesla Ends Model S and X Production and Sends $2 Billion to xAI as 2025 Revenue Declines
×