All the latest UK technology news, reviews and analysis

Commercial software opens cyber-terror backdoor

by Robert Jaques

22 May 2006

Comments: 3

  • Tweet this
Life-cycle attacks could be buried deep within millions of lines of software code
Software can be exposed to threats such as the insertion of malicious code

US military, government, security and critical infrastructure agencies are being warned against using commercial software which could be hacked by foreign cyber-terrorists.

The warning was issued by Cyber Defense Agency (CDA), an information security consulting and research company specialising in services for the US government and infrastructure sectors.

CDA said that gas, electricity, telecoms, banking and water companies are among the critical service providers that could fall victim to cyber-terrorism caused by so-called life-cycle attacks buried deep within millions of lines of software code.

Life-cycle attacks occur when one line of code is rigged to open vulnerabilities within the software, thus exposing the software and the company to external threats, CDA stated.

The firm claimed that the US Department of Defense recently commissioned an evaluation for top security experts to report and analyse the threats of foreign influence on the government and military's use of commercial software.

It went on to suggest that software built by less expensive overseas labour is exposed to "several threats such as the insertion of malicious code".

These so-called "adversarial foreign interests" or "trans-national criminal and terrorist groups" will then be able to exploit these pieces of inserted code in "strategic attacks against the US".

"Outsourced commercial software used by the military and critical infrastructures poses a silent but significant security risk to the defence and welfare of the US," said Sami Saydjari, chief executive and president of CDA.

"The chances of strategic damage from a cyber-terrorist attack on the US increases the longer it takes the US military and critical infrastructures to remedy the risks posed by using outsourced software."

The company advises governments, organisations and firms responsible for critical infrastructure to architect critical systems with defence-in-depth security mechanisms from different vendor sources under the assumption that some of the software contains life-cycle attacks.

It is also necessary to limit software privileges using fine-grained security control software technology already developed under government research programmes, and to configure intrusion detection systems to detect the activation and use of such life-cycle attacks.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Information Security Manager

My client is a well established, non profit organisation;...

PHP Web Developer

PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...

HEAD OF DIGITAL - London - £80-95K+

HEAD OF DIGITAL - London - £80-95K + Excellent Bens...

Agile C# Developer - (North London)

Agile C# Developer - (North London) £55,000 - £65,000...

To send to more than one email address, simply separate each address with a comma.