This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here

 

RSA: Nation states and criminals working together to commit cybercrime

By Sooraj Shah

09 Oct 2012

View Comments
Hand shake

In a Q&A with press at the RSA European conference today, RSA executive chairman Art Coviello revealed how criminals and nation states are working together to launch cyber attacks.

Further reading

"What we found in our Antifraud Centre was that criminals that were using malware became so pervasive [a phenomenon], that criminals themselves were having a big data problem. They have so much data that they don't know how to monetise [cybercrime]," he stated.

This means that criminals have a common goal with nation states looking to use stolen resources and data for cyber espionage – allowing the two to strike a deal that benefits them both.

"The chilling things that are going on are that the nation states are buying criminal information and they are also selling sophisticated APT attacks to the criminals," he said.

New strategy

Coviello's keynote today at the RSA's European conference touched on a new intelligence-based strategy that focuses on predictive analytics and information sharing.

At the Q&A, Coviello and RSA president Tom Heiser tackled the topic in greater depth.

The new strategy based on big data analytics seeks to assess risk in an agile and contextual way, and is not just for RSA as an organisation, Coviello stated, but for industry as a whole.

"If you look at the way security infrastructure has been built over the years, they never really started with risk management but with a problem on the network. Thereafter a layer of controls developed: identity, infrastructure and data controls. All of these tended to be siloed but even worse they were developed on the perimeter so over time a lot of these controls have lost effectiveness," he said.

Reader comments

blog comments powered by Disqus

Newsletters

Does Google know too much about you?

Google's linked data policy, which came into effect on March 1, allows the company to collect information about its users across all its products, services and websites and store it in one place. This has been criticised by organisations ranging from CNIL to Microsoft, all of whom have expressed concerns that it's difficult to tell which data Google collects and how it's used. Now the Information Commissioner's Office is investigating whether Google's privacy policy is compliant with UK law. Are you worried that Google knows too much about you?

41 %

5 %

15 %

39 %