When it comes to stopping ransomware, sharing threat information between the government and private-sector companies “is the thoughts and prayers of the InfoSec community,” said Matt Olney, director of threat intelligence at Cisco Talos.
“It is certainly something that is made in goodwill.” But if private cybersecurity companies and government agencies want to do anything meaningful to combat ransomware, which both sides call an urgent national security risk, it will require “a step beyond” the traditional public-private partnership, Olney said.
“For example, not just say, ‘I saw this.’ But then I also took time to reverse engineer it, and I found this weakness, and while I am not legally able to take advantage of that, I can give it to you [government agency],” he added. “It’s that sort of additional work to use expertise on my side to prepare the government to do their role in the disruption. That’s the next-step things that we’re thinking about.”
Neil Jenkins, chief analytic officer at the Cyber Threat Alliance, calls this “active collaboration.”
“It’s not just direction from the government to the private sector to take an action, or a request for information,” he explained. “It’s an actual, routine, regular engagement on these prioritized ransomware actors to identify what we know, identify what their operational activity is, and then through that engagement, identify where we can work together to leverage the various authorities that government agencies have and leverage the relationship capabilities that the private sector has with their customers or with their infrastructure to be able to do that disruption.”
Ransomware Task Force’s RecommendationsBoth Olney and Jenkins sit on the private-sector led Ransomware Task Force — a 60-member organization that includes dozens of private companies such as Cisco, Amazon Web Services, Palo Alto Networks, and Microsoft, along with the FBI, U.S. Cybersecurity and Infrastructure Security Agency (CISA), and other law-enforcement groups.
In late April, the group presented the White House with an 81-page report with 48 recommendations to combat ransomware. A week later, cybercriminals breached Colonial Pipeline’s systems and shut down a major fuel supply for the East Coast. “And there was dismay, but no surprise when that happened,” Olney said. “I can’t think of another time where a group of industries has gotten together and said we need help in this way. I come from a security vendor, and I’m saying what we’re doing collectively as a society [to combat ransomware] is insufficient.”
Colonial Pipeline’s CEO authorized a $4.4 million ransom payment to restore the critical infrastructure systems, however, earlier this week the Justice Department recovered about $2.3 million of the ransom paid. Law enforcement tracked the bitcoin payment to a virtual wallet, and the FBI somehow had the private key to this wallet, which allowed the DOJ to recover the funds.
“In the security community the question is: How did the bureau have the private key for that wallet? And in the legal paperwork for that action, they have a throwaway line that just says the private key is in possession of the FBI California office,” Olney said, adding that this is an example of the type of “creative uses of government power and collaboration with the private sector,” that a new Talos report says is needed to disrupt ransomware campaigns.
Olney and Jenkins co-authored the Talos ransomware report. Before heading up the CTA’s analytics efforts, Jenkins served in various roles within the Department of Homeland Security, Department of Defense, and Center for Naval Analyses.
Why a Law-Enforcement Approach Won’t WorkThe Talos report says that a traditional law-enforcement approach to ransomware won’t work. “If this is truly a national security problem, then it requires a national security solution,” Jenkins said.
The Ransomware Task Force wants the government to establish an interagency Joint Ransomware Task Force to lead the country’s ransomware-disruption efforts. This group should include law enforcement agencies like the FBI and U.S. Secret Service, as well as the major players in the intelligence community such as the CIA, the Office of the Director of National Intelligence (ODNI), and the National Security Agency (NSA). It should also include CISA, U.S. Cyber Command, the State and Treasury departments, and possibly other government agencies.
“We believe that the best way to focus this effort is to formalize it under a task force, and get people assigned to it where that’s their job,” Jenkins said. “Their job is to identify the highest-priority ransomware threat actors and find ways to go after them and disrupt them.”
This, of course, requires a whole additional layer of collaboration beyond a public-private partnership, and cooperation between government agencies may be the tougher nut to crack.
“Both of those are big problems, and they are different flavors of issues, but a lot of times it comes down to trust and incentives,” Jenkins said. “If your work incentives are to arrest somebody, then you’re going to be focused on arresting somebody. But if your work incentives within a joint interagency task force are to find ways to disrupt threat actors, then suddenly your perspective changes.”
Additionally, building trust between groups, be it public-private partnerships or an inter-agency task force, takes time. “It isn’t something that happens at the snap of a finger because the government calls and says ‘we want you to participate.’ It’s built through engaging in relationships,” Jenkins said.
“What I am most concerned about is that the government move beyond treating this problem as a law-enforcement issue,” Olney said. “And so I hesitate to celebrate the Department of Justice forming its ransomware task force, because we’ve had this problem for many years, and we’ve treated it as a law enforcement issue for many years, and it’s an insufficient action to dissuade actors from participating in this activity.”
For this reason, Olney says it’s critical that a joint ransomware task force exist outside of the DOJ and include the comprehensive list of government agencies that the private-sector Ransomware Task Force proposed in its report. “We need all of these not-always-working-together groups need to come together, each with a very important role in ultimately tamping down how active ransomware is.”
Comments