Saturday, June 23, 2018
News Roundup

What makes cyberattacks so hard to trace?

NEW YORK — The attacks that knocked South Korean banks offline this week appear to be the latest examples of international "cyberwar." But among the many ways that digital warfare differs from conventional combat: there's often no good way of knowing who's behind an attack.

South Korean authorities said Thursday that the attack, which shut down scores of cash machines and hampered business, had been traced to an "Internet Protocol" address in China. But that doesn't mean the attack was launched from there. The general assumption in South Korea is that the attack originated in North Korea.

"IP" addresses are, roughly speaking, the phone numbers of the Internet. Each connected computer has a number that identifies it uniquely on the network, so the Chinese IP address implies that a computer in China was involved in the attack.

However, that computer could have been controlled from elsewhere, either because someone bought access to it, or because it's been infected with malicious software. To determine the location from which it's being controlled, investigators would need access to that computer, or to the records of the company hosting the computer. That's unlikely to be forthcoming from a Chinese company.

"China is obviously a popular place to hide things," said Dan Holden, director of security research at Arbor Networks' Security Engineering & Response Team. Chinese authorities are difficult to work with, and there's a language barrier, he said.

In addition, China is believed to be conducting its own campaign of cyber-espionage, which means that attacks launched from there are often simply attributed to the Chinese government, even if it isn't responsible for the aggression, Holden said.

"If you are any nation state or even any attacker right now, why wouldn't you hide in China right now?" Holden asked rhetorically.

Apart from tracing the path an attack takes through the Internet, there's another way to figure out who's behind it: analysis of the software involved. Malicious software, or "malware," can provide clues to its creator. Some of those are obvious, like comments inserted into the written code. However, such comments can be easily faked to lead investigators astray. More subtle analysis can be fruitful, according to Christopher Novak, managing principal of the global investigative response team at Verizon Communications Inc.

"In many cases, the malware that you see on the computer is very similar to a cold or an illness that a person gets ... The strain of the cold that I have and the strain of the cold that you have may be slightly different, but when we look at the DNA and makeup and see they're 99.9 percent the same, there's a pretty good chance one of us transmitted it to the other," Novak said. "When we analyze malware codes, we see the elements that are copied and reused, certain programming styles."

Such analysis can yield important clues, but rarely rock-solid attribution. The U.S. Department of Defense has said that a cyberattack can merit a violent response, but first you have to know who to target.

"Digital attribution is extremely difficult and if you want to do it, it takes some serious effort," Holden said.

Comments
First step for Hillsborough schools facing biggest challenges: Hire more teachers

First step for Hillsborough schools facing biggest challenges: Hire more teachers

TAMPA — As chief of diversity for the Hillsborough County School District, Minerva Spanner-Morrow tries to keep her expectations realistic."We want the best of the best and I know that’s very difficult," she told principals last week as they prepared...
Published: 06/23/18
Rodney Page’s takeaways from Rays-Yankees

Rodney Page’s takeaways from Rays-Yankees

1. SS Willy Adames had a nice night, and there appear to be many more in his future. He had two hits, an RBI and an inning-ending leaping catch on a line drive by Didi Gregorius in the fifth.2. DH C.J. Cron needs to shake things up. Take a different ...
Updated: 5 hours ago
Marc Anthony pays a visit to the Trop

Marc Anthony pays a visit to the Trop

By Allana BarefieldTimes Staff WriterST. PETERSBURG — Latin pop star Marc Anthony visited Tropicana Field on Friday to see his beloved Yankees play the Rays.Anthony spent nearly an hour on the field before the game as fans and players surrounde...
Updated: 5 hours ago
Rays journal: Daniel Robertson’s return crowds up infield

Rays journal: Daniel Robertson’s return crowds up infield

ST. PETERSBURG — The Rays reinstated INF Daniel Robertson from the 10-day disabled list (left hamstring strain). To make room, RHP Austin Pruitt was sent to Triple-A Durham."It's out of my mind. I don't think about (the hamstring) when I'm bend...
Updated: 5 hours ago
Brady Singer, Gators eliminated by Arkansas at CWS

Brady Singer, Gators eliminated by Arkansas at CWS

Times wiresOMAHA, Neb.  —Defending champion Florida failed to win a third straight elimination game, losing to Arkansas 5-2 Friday night and departing the College World Series.The Gators (49-21) had to win to force a rematch. The Razorback...
Updated: 5 hours ago
Rays hang on for a 2-1 win over Yankees

Rays hang on for a 2-1 win over Yankees

ST. PETERSBURG – Many times this season the Rays' strategy of opening the game with a short reliever and using the bullpen to finish hasn't had much success.Friday wasn't one of those nights.A total of six pitchers held the Yankees and their va...
Updated: 6 hours ago
Rowdies fall to Penn FC

Rowdies fall to Penn FC

By Darek SharpTimes CorrespondentST. PETERSBURG — For the second time this season, Penn FC got two goals from a former Rowdie that led the way to a win over Tampa Bay.Lucky Mkosana doubled his season total Friday in a comeback 2-1 win before an...
Updated: 6 hours ago
Ronald Darby’s friend: Jameis Winston got into second Uber ride alone

Ronald Darby’s friend: Jameis Winston got into second Uber ride alone

New details emerged Friday night about the Uber ride in Arizona in March 2016 that led to Bucs quarterback Jameis Winston's three-game suspension to start the upcoming season, including the fact that Winston was in a car that night with a former Vand...
Updated: 8 hours ago
Tampa boy, 14, shot on bike, police asking for help

Tampa boy, 14, shot on bike, police asking for help

TAMPA — Police want to know who shot 14-year-old De’Nico Thomas after a night of playing video games.Thomas was at a friend’s home Wednesday night and walking home when Tampa police said he was shot, resulting in life-threatening injuries.As he faces...
Updated: 8 hours ago
Carlton: That snake-like thing living under your refrigerator? It’s a skink. Welcome to Florida

Carlton: That snake-like thing living under your refrigerator? It’s a skink. Welcome to Florida

At first I thought it was a snake.Because wouldn’t it be typically Florida to come home and find a snake poking its nose out from under your stove? Which wouldn’t be a problem or anything. I would just have to move out is all.But no, the creature tha...
Updated: 9 hours ago