Homepage / Technology / HP Enterprise let Russia scrutinize cyberdefense system used by Pentagon
Menyelami Dunia Slot Thailand: Keseruan dan Peluang Kemenangan Besar Menyelami Dunia Slot Thailand: Pengalaman Bermain yang Tak Terlupakan Take step one towards love and pleasure today Take control of your love life in order to find bbw mature lesbians today Bahis Sitelerinde Ücretsiz Deneme Bonusları Nasıl Kullanılır? Rulet Masalarında Bonuslarla Daha Fazla Kazanın Player women online dating| discover single video games women at Masalbet: En Çok Kazandýran Casino Sitesi Gambling in Australia and Modern Settlement Methods: The Rise of PayID TUAN88 Situs Main Game Online dengan Aman dan Nyaman Brit Cam Place — Singles From British Look For Pleasant Companions And Dating 1xbet Registration ᐉ 1xbet Sign Up برنامج المراهنات الرياضية تحميل التطبيق العميل Eg 1xbet Com Cassino Kto Jogos Para Cassino Online No Brasil” 1xbet Apk 1xbet للموبايل حمل تطبيق 1xbet لأنظمة أيفون و أندرويد 1xbet مصر Eg 1xbet Com Melhores Casas Sobre Apostas No País Brasileiro 2024 Casa-apostas Apresentando” قم بتنزيل 1xbet على جهاز الكمبيوتر ، وكيفية تنزيل تطبيق سطح المكتب على جهاز الكمبيوتر برنامج المراهنات الرياضية تحميل التطبيق العميل 1xbet Com How To Try Out Roulette Rules & Guide How To Win From Slots: Top Ideas To Boost Your Own Chances How To Win The Car In Gta 5 Casino Win The Particular Gta Online Scène Vehicle How To Win The Car In Gta 5 Casino Win The Particular Gta Online Scène Vehicle How To Perform Slot Machines Najlepsze kasyna bez depozytu 2025 The Best Different Roulette Games Strategy Tips In Order To Win At Roulette Promozioni effettive di 22Bet in Italia Отзывы о казино Stake от реальных игроков 2025 о выплатах и игре The Best Different Roulette Games Strategy Tips To Win At Roulette Cassinos legais no Brasil: novas regras e melhores sites Top 10 Biggest Casinos In The Usa 1xbet 보너스 받는법 및 출금 롤링조건 등 사용법 총정리 온라인카지노 Kr Your Current Reliable Partner Regarding Tent Manufacturing Online Kaszinó Játékok És Élő Kaszinó Játékok History Of Las Vegas Casinos Who Else Built It & How Sin City Emerged To Be En Güvenilir Canlı Bahis Empieza Casino Sitesi Игровые Автоматы На мнимые Деньги Играть Онлайн В Лучшие Слоты How To Available A Casino: A Detailed Six-steps Guide Gaming Paradise Is Just Around The Corner: Top Ten Casinos Throughout Las Vegas Find the right person: tips for effective singles dating over 60 10 Regarding The World’s Largest Casinos: The Greatest Casinos Ever! Gamification : la limite entre jeu vidéo et casino en ligne se brouille Ufc 302 Gdzie Oglądać Za Darmo I Na Żywo? 2 06 24 ‎Casino ua online casino club on the App Store 1xbet تسجيل الدخول للجوال قم بتسجيل الدخول إلى حساب 1xbet الخاص بك “원엑스벳1xbet 프로모션 코드 2024: Jbmax Vip! Sweet Bonanza Ücretsiz Demonstration İle Oyun Deneyimi Verde Kaszinó: Új Kaszinó Oldal Rendkívüli Bónuszokkal! Türkiye Casino Sitelerinin Adresi 2024 En Iyi Türk Online Casino En Güncel Ve Güvenilir On Line Casino Ve Bahis Sitelerinin Adresi 2024 Listesi 1xbet 모바일 앱-어플 2024, 버전, 다운로드, 설치, Ios, 안 Diocesan Development Services To The Particular North Karamoja Dds-n Sai Dwaraka In Nessun Caso Tours & Travels Pin-up On Line Casino Türkiye En İyi Canlı Casino Oyunları Ve Slot Makineleri Strategies for making a bisexual woman feel very special and loved Diamond Casino Heist The Big Disadvantage Walkthrough Play 17, 800+ Cost-free Us Online On Line Casino Games No Get” Jouez au casino en ligne numéro un dans le monde 1xbet Login Guide » The Way To Sign Inside To Your 1xbet Account 2024 Better United kingdom Casinos One Undertake Credit card 1вин Бесплатно нет Регистрации Играть и Игровые Автоматы 1win Top Tips For Just How To Beat Slot Machines: Become A New Winner! 원엑스벳 도메인 주소 1xbet 우회접속 가입방법 안내 토크 Deneme Bonusu ile Ücretsiz Oyun Deneyimi Bahis Dünyasında Sıkça Yapılan Hatalar ve Çözümleri 1win Мобильное Приложение На Ios И Android бесплатно Скачать Ücretsiz Slot Oyunları Silvergames’te Çevrimiçi Oynayın ️ Επίσημη Ιστοσελίδα Στην Ελλάδα Casino Bahis Siteleri Ara 2024 Yasal Casinoların Listesi ️” Türkiye’nin En İyi Bahis Şirketi Ve On-line Casino 짱구카지노 공식 평생 도메인 주소 Demo Slot Sweet Bonanza’yı Oynayın: Arkadaşlarınızla Eğlenceli Anlar Yaşayın Meet sexy milfs who’re selecting fun 1вин Игровые Слоты Казино Играть Бесплатно Без Регистрации 1вин Игровые Слоты Казино Играть Бесплатно Без Регистрации لماذا يجذب كازينو 1xbet كبار اللاعبين المصريين؟ 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports

Taya365 Casino Login⁚ A Comprehensive Guide

Isle Gambling Establishment Hotel Black Hawk Now Under Horseshoe Brand, Changes Label” Top True Money Casino Apps For 2025: Twelve Best Online Casinos Resmi Sitesi Çevrimiçi Oyna, Para İle Oyna 6 Ways To Start An Online Casino تنزيل تطبيق 1xbet قم بتثبيت تطبيق 1xbet للهاتف المحمول Get ready for the ultimate craigslist sex experience Stake Casino Russia официальный Сайт Для Онлайн Игр И Бонусов “bukmacherskie Zakłady Sportowe Najlepsze Oferty W Ggbet Sports Welcome on ultimate dating platform for ssbbw lesbians 1вин Казино ᐉ Вход а Регистрация На 1win Официальный Сайт 1win Encouraged Bonuses As Well As How To Work With Them In Bangladesh 1win Encouraged Bonuses As Well As How To Work With Them In Bangladesh 1win: Spor Bahisleri Ve Internet Casino Bonus 500% Glory Casino On-line ️ Play With The Authorized Web Site In Bangladesh Тотал В Ставках На Спорт%3A не Такое И только Рассчитать Ставка Tv Mostbet Türkiye: En Iyi Oranlar Ve Spor Bahisleri Καζίνο Και Στοιχηματική Σε Έναν Ιστότοπο “1xbet App 1xbet Cellular ᐊ تنزيل 1xbet Apk Android و Iphone ᐊ 1xbet Com Get started on mature sex dating sites now “horseshoe Casino Baltimore Wikipedia Judi Online, Kenali Bahaya, Ciri-Ciri Kecanduan, dan Penanganannya Cassino Apresentando Bônus De Boas-vindas: Veja As Opções Disponíveis Casino Mostbet ᐈ Oficiální Stránky Online Kasin V České Republice Casino E Apostas Desportivas No Brasil Bônus 5000 Brl No Depósito Entrar Beginner’s Explained Casino Wagering: Tips & Strategies Beginner’s Explained Casino Wagering: Tips & Strategies Лучшие Букмекерские Конторы Онлайн Рейтинг Бк 2024

Technology

HP Enterprise let Russia scrutinize cyberdefense system used by Pentagon

Hewlett Packard Enterprise allowed a Russian defense agency to review the inner workings of cyber defense software used by the Pentagon to guard its computer networks, according to Russian regulatory records and interviews with people with direct knowledge of the issue.

The HPE system, called ArcSight, serves as a cybersecurity nerve center for much of the U.S. military, alerting analysts when it detects that computer systems may have come under attack. ArcSight is also widely used in the private sector.

The Russian review of ArcSight’s source code, the closely guarded internal instructions of the software, was part of HPE’s effort to win the certification required to sell the product to Russia’s public sector, according to the regulatory records seen by Reuters and confirmed by a company spokeswoman.

Six former U.S. intelligence officials, as well as former ArcSight employees and independent security experts, said the source code review could help Moscow discover weaknesses in the software, potentially helping attackers to blind the U.S. military to a cyber attack.

“It’s a huge security vulnerability,” said Greg Martin, a former security architect for ArcSight. “You are definitely giving inner access and potential exploits to an adversary.”

Despite the potential risks to the Pentagon, no one Reuters spoke with was aware of any hacks or cyber espionage that were made possible by the review process.

The ArcSight review took place last year, at a time when Washington was accusing Moscow of an increasing number of cyberattacks against American companies, U.S. politicians and government agencies, including the Pentagon. Russia has repeatedly denied the allegations.

The case highlights a growing tension for U.S. technology companies that must weigh their role as protectors of U.S. cybersecurity while continuing to pursue business with Washington’s adversaries such as Russia and China, say security experts.

The review was conducted by Echelon, a company with close ties to the Russian military, on behalf of Russia’s Federal Service for Technical and Export Control (FSTEC), a defense agency tasked with countering cyber espionage.

Echelon president and majority owner Alexey Markov said in an email to Reuters that he is required to report any vulnerabilities his team discovers to the Russian government.

But he said he does so only after alerting the software developer of the problem and getting its permission to disclose the vulnerability. Echelon did not provide details about HPE’s source code review, citing a non-disclosure agreement with the company.

FSTEC confirmed Markov’s account, saying in a statement that Russian testing laboratories immediately inform foreign developers if they discover vulnerabilities, before submitting a report to a government “database of information security threats.”

One reason Russia requests the reviews before allowing sales to government agencies and state-run companies is to ensure that U.S. intelligence services have not placed spy tools in the software.

HPE said no “backdoor vulnerabilities” were discovered in the Russian review. It declined to provide further details.

HPE said it allows Russian government-accredited testing companies to review source code in order to win the Russian defense certifications it needs to sell products to Russia’s public sector.

An HPE spokeswoman said source code reviews are conducted by the Russian testing company at an HPE research and development center outside of Russia, where the software maker closely supervises the process. No code is allowed to leave the premises, and HPE has allowed such reviews in Russia for years, she said.

Those measures ensure “our source code and products are in no way compromised,” she said.

Some security experts say that studying the source code of a product would make it far easier for a reviewer to spot vulnerabilities in the code, even if they did not leave the site with a copy of the code.

In a 2014 research paper, Echelon directors said the company discovered vulnerabilities in 50 percent of the foreign and Russian software it reviewed.

Still, security analysts said the source code review alone, even if it yielded information about vulnerabilities, would not give hackers easy entry into the military systems. To infiltrate military networks, hackers would need to first overcome a number of other security measures, such as firewalls, said Alan Paller, founder of the SANS Institute, which trains cybersecurity analysts

Paller also said HPE’s decision to allow the review was not surprising. If tech companies like HPE want to do business in Russia, “they don’t really have any choice,” he said.

HPE declined to disclose the size of its business in Russia, but Russian government tender records show ArcSight is now used by a number of state firms and companies close to the Kremlin, including VTB Bank and the Rossiya Segodnya media group.

Whether the customer is Russia or the United States, overlooked errors in software code can allow foreign governments and hackers to penetrate a user’s computer.

Exploiting vulnerabilities found in ArcSight’s source code could render it incapable of detecting that the military’s network was under attack, said Allen Pomeroy, a former ArcSight employee who helped customers build their cyber defense systems.

“A response to the attack would then be frankly impossible,” Pomeroy said.

The HPE spokeswoman said Reuters’ questions about the potential vulnerabilities were “hypothetical and speculative in nature.”

HPE declined to say whether it told the Pentagon of the Russian review, but said the company “always ensures our clients are kept informed of any developments that may affect them.”

A spokeswoman for the Pentagon’s Defense Information Systems Agency, which maintains the military’s networks, said HPE did not disclose the review to the U.S. agency. Military contracts do not specifically require vendors to divulge whether foreign nations have reviewed source code, the spokeswoman said.

The U.S. military agency itself did not require a source code review before purchasing ArcSight and generally does not place such requirements on tech companies for off-the-shelf software like ArcSight, the Pentagon spokeswoman said. Instead, DISA evaluates the security standards used by the vendors, she said.

Echelon operates as an official laboratory and software tester of FSTEC and Russia’s FSB spy agency, according to Russian government registries of testing laboratories and software certifications reviewed by Reuters. U.S. intelligence has accused the FSB of helping mount cyber attacks against the United States and interfering in the 2016 presidential election.

Markov, Echelon’s president, defended the reviews, saying that “if a vulnerability is found, everyone is happy” because the detected flaw means laboratory experts are “able to demonstrate their qualifications” and “the developer is happy that a mistake was detected, since by fixing it the product will become better.”

Russia in recent years has stepped up demands for source code reviews as a requirement for doing business in the country, Reuters reported in June.

A number of international companies, including Cisco Systems, the world’s largest networking gear maker, and German software giant SAP, have agreed to the reviews, though others, including cybersecurity firm Symantec, have refused because of security concerns.

U.S. government procurement records show ArcSight is used as a key cyberdefense bulwark across much of the U.S. military including the Army, Air Force and Navy. For example, ArcSight is used to guard the Pentagon’s Secret Internet Protocol Router Network (SIPRNet), which is used to exchange classified information, according to military procurement records.

The Pentagon spokeswoman declined to comment on risks posed by specific products to its network but said all software used by DISA is “extensively evaluated for security risks,” and continually monitored once deployed.

Created in 2000 as an independent company, ArcSight broke new ground by allowing large organizations to receive real-time alerts about potential cyber intrusions.

The software draws activity records from servers, firewalls, and individual computers across a network – up to hundreds of thousands per second. The system then searches for suspicious patterns, such as a high number of failed login attempts within a few seconds, and alerts analysts.

A decade later, ArcSight had become “the core” cyber network defense tool the Pentagon’s analysts “rely on to defend DoD networks,” DISA said in a 2011 ArcSight procurement request.

Today ArcSight is a virtually irreplaceable tool for many parts of the U.S. military, at least for the immediate future, Pentagon records show.

“HP ArcSight software and hardware are so embedded,” the Pentagon’s logistics agency wrote in April, that it could not consider other competitors “absent an overhaul of the current IT infrastructure.”

HPE agreed last year to sell ArcSight and other security products to British tech company Micro Focus International in a transaction that was completed in September.

Jason Schmitt, the current head of the ArcSight division, said the product makes up a little less than half of the $800 million in annual revenue Micro Focus expects to get from the security software business purchased from HPE.

Schmitt said he could not comment on any source code review that took place before this year, when he took the job, but stressed such reviews do not currently take place. Micro Focus did not respond to requests for comment on whether it would allow Russia to do similar source code reviews in the future or whether Micro Focus executives knew of the review prior to the acquisition.

Source: Tech CNBC
HP Enterprise let Russia scrutinize cyberdefense system used by Pentagon

Comments are closed.