Life-cycle attacks could be buried deep within millions of lines of software code
Software can be exposed to threats such as the insertion of malicious code

Commercial software opens cyber-terror backdoor

US firm warns of life-cycle attacks buried deep within millions of lines of code

Robert Jaques

US military, government, security and critical infrastructure agencies are being warned against using commercial software which could be hacked by foreign cyber-terrorists.

The warning was issued by Cyber Defense Agency (CDA), an information security consulting and research company specialising in services for the US government and infrastructure sectors.

Advertisement

CDA said that gas, electricity, telecoms, banking and water companies are among the critical service providers that could fall victim to cyber-terrorism caused by so-called life-cycle attacks buried deep within millions of lines of software code.

Life-cycle attacks occur when one line of code is rigged to open vulnerabilities within the software, thus exposing the software and the company to external threats, CDA stated.

The firm claimed that the US Department of Defense recently commissioned an evaluation for top security experts to report and analyse the threats of foreign influence on the government and military's use of commercial software.

It went on to suggest that software built by less expensive overseas labour is exposed to "several threats such as the insertion of malicious code".

These so-called "adversarial foreign interests" or "trans-national criminal and terrorist groups" will then be able to exploit these pieces of inserted code in "strategic attacks against the US".

"Outsourced commercial software used by the military and critical infrastructures poses a silent but significant security risk to the defence and welfare of the US," said Sami Saydjari, chief executive and president of CDA.

"The chances of strategic damage from a cyber-terrorist attack on the US increases the longer it takes the US military and critical infrastructures to remedy the risks posed by using outsourced software."

The company advises governments, organisations and firms responsible for critical infrastructure to architect critical systems with defence-in-depth security mechanisms from different vendor sources under the assumption that some of the software contains life-cycle attacks.

It is also necessary to limit software privileges using fine-grained security control software technology already developed under government research programmes, and to configure intrusion detection systems to detect the activation and use of such life-cycle attacks.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

Summit: Views From the Valley

V3.co.uk's US office weighs in on the information overload crisis

John Chambers speaks on collaboration

Cisco boss talks up new offerings

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Nikos Drakos

Summit: Dealing with communications overload

We ask Gartner Research director Nikos Drakos for advice on...

HP logo

HP scoops up 3Com for $2.7bn

Deal nearly doubles size of HP's networking operation

Data security

Summit video: Open Rights Group discusses data privacy

ORG's Jim Killock calls on the government to become more...

John Chambers speaks on collaboration

Cisco boss talks up new offerings

Primary Navigation