The National Security Agency (NSA) has a unique vantage point into the threat adversary landscape, being tasked in part with collecting signals intelligence for the U.S. government.
At the RSA Conference 2023, Rob Joyce, director of cybersecurity at the NSA delivered what felt like a de-classified intelligence briefing on what the U.S. is seeing as the current and future state of hacks and threats. In the nearly hour-long session, Joyce provided a sobering view of nation-state-backed attacks from both Russia and China as well as an assessment of steps U.S. based organizations can take to limit risks in an increasingly hostile cyber-landscape.
[ Follow SDXCentral’s complete RSA Conference 2023 coverage ]
A key theme that has permeated nearly every session at RSA Conference 2023 is that of the impact of artificial intelligence (AI), and Joyce didn't break that streak, providing his viewpoint on the potential threats and benefits the emerging technology provides both to attackers and defenders at home and abroad.
From Russia with malice – takes a three-pronged approachWith the ongoing war in Ukraine, it's no surprise that Russia is very active in using cyberattacks as part of its campaign.
Joyce said that from a foreign intelligence mission perspective the NSA is seeing three primary classes of attacks executed by various divisions of the Russian government. First off is intelligence gathering activities to help prosecute the war. The second big set of attacks are disruptive activities that try to break down and interfere with civil society and the war effort itself. And then finally, the third big class is hacktivist activity.
Russia's cyberattacks against Ukraine did not start with the current war. Rather they have been ongoing for multiple years according to Joyce. In 2015 and 2016, Russian based groups attacked the Ukraine's electric grid with the 'sandworm' attacks. In 2017, the NotPetyah attack initially targeted Ukraine before spawning out of control and impacting organizations around the world.
Russia apparently is trying not to replicate the NotPetyah incident with the current conflict with the destructive attacks primarily remaining inside the borders and confines of Ukraine.
"We've seen Russia actually take some care not to unleash the NotPetyah-type activity that can go and propagate across the internet to have an escape from Ukraine and cause damage indiscriminately," Joyce said. "So that's a good news story for the rest of the world."
For the most part, Joyce said that in terms of attacks against U.S. based organizations, to date activities have largely been around intelligence gathering by Russia. To date he noted that Russia has not specifically tried to disrupt U.S operations with cyberattacks though he said the NSA is watching the situation very closely.
Made in China: More zero-day attacks are comingJoyce reserved his harshest criticism for China, which according to U.S. intelligence officials represents the broadest, most-active and persistent espionage threat to the U.S.
"China is a country whose aspiration is to upset the world order and use cyber as one of the means to do that," Joyce said. "They are strategic, agile, brazen, innovative and enduring."
According to the NSA's assessment, China has goals in big data, AI. pharmaceuticals, healthcare and military technologies. As a result Joyce said that companies in those sectors can expect to be challenged by intrusions from China.
"They're happening today, they're not going to relent, they're the official policy and resource targets of that government and they're going to keep coming at us," Joyce said.
The U.S. is not sitting idly by while China attacks either. Joyce said that U.S.-based enterprises have been able to impact hacking attempts from China through increased patching and security. To date, China has largely been able to benefit from the fact that many organizations do not patch all security vulnerabilities.
The impact of improved patching is, however, leading to a new situation when the NSA expects China to develop more zero day attacks than ever before.
"If China is going to transition from exploited vulnerabilities over to zero days, we have to start thinking about architecture and capabilities that will discover and prevent lateral movement," Joyce said. "If you are a high end target for China, you need to start thinking about your posture for a world of increasing zero days, especially against your edge devices."
'Buckle up' for a wild ride with AIThe NSA is also taking a hard look at the potential impact of generative AI on the threat landscape.
Joyce said that the NSA has already seen both nation states and regular cybercriminals starting to experiment with ChatGPT types of text generation to expand their English language attack capabilities.
On a positive note, he said that AI can be an accelerant for defense, providing a huge amplification capability to make defenders better.
"Buckle up, I think that the innovation cycle on the development and the innovation cycle on many use cases with it is going to be really rapid," he said.
Comments