Private security firms will soon be allowed to hack overseas cybercriminals

Private security firms will soon be allowed to hack overseas cybercriminals

私营安全公司即将获准攻击海外网络犯罪分子

The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyberattacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities. In a National Security Presidential Memorandum issued Thursday, US President Donald Trump directed the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to develop a program for conducting specific cyber operations that combat foreign transnational criminal organizations (TCOs). The Departments of Justice and Homeland Security will provide oversight. The lynchpin of that program is bringing in private sector companies to participate.

特朗普政府正在招募私营安全公司,以执行联邦政府授权的行动(包括网络攻击),针对那些对美国个人、组织或政府实体实施黑客攻击的海外犯罪组织。在周四发布的一份国家安全总统备忘录中,美国总统唐纳德·特朗普指示在国土安全特别工作组下运作的国家协调中心(NCC)制定一项计划,开展旨在打击外国跨国犯罪组织(TCOs)的特定网络行动。司法部和国土安全部将负责监督。该计划的核心在于引入私营部门公司参与其中。

Devil will be in the still-undefined details. A fact sheet that accompanied Thursday’s memo listed ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as activities eligible for private-sector security firms to target. The memo said such firms could “conduct Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” TCOs. Such groups are defined as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”

魔鬼藏在尚未明确的细节中。随周四备忘录发布的一份情况说明书列出了勒索软件、性勒索计划、网络钓鱼活动、金融欺诈和冒充诈骗等活动,这些均属于私营安全公司可针对的目标。备忘录称,此类公司可以针对“网络驱动型”跨国犯罪组织“开展网络监视行动和网络效应行动”。此类组织被定义为“任何针对美国政府、美国个人或美国利益实施网络犯罪,且不属于外国政府机构组成部分或完全受外国政府指挥的外国团体”。

The new program is the first time the federal government will authorize private companies to conduct offensive cyber operations against overseas hackers. The memo appears to permit companies participating in the program to use spyware or launch offensive attacks intended to destroy TCO data or systems. The memo doesn’t rule out certain types of offensive attacks, such as those that use encryption to lock targets out of their networks or performing distributed denial-of-service attacks. Up until now, the government has prohibited the private sector from taking such actions without court-authorized approval.

这项新计划是联邦政府首次授权私营公司对海外黑客进行进攻性网络行动。备忘录似乎允许参与该计划的公司使用间谍软件或发动旨在破坏跨国犯罪组织数据或系统的进攻性攻击。备忘录并未排除某些类型的进攻性攻击,例如使用加密技术将目标锁定在其网络之外,或执行分布式拒绝服务攻击。在此之前,政府一直禁止私营部门在未经法院授权批准的情况下采取此类行动。

“There’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen (don’t ask me how I know),” independent security researcher Kevin Beamont said in response to the memo. “But the correct incentives have gotta be there.” He added: “The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”

“黑掉勒索软件组织的想法确实有其价值,而且实际上已经发生了(别问我怎么知道的),”独立安全研究员凯文·博蒙特(Kevin Beamont)在回应这份备忘录时表示。“但必须具备正确的激励机制。”他补充道:“过去5年我在打击勒索软件方面遇到的最大问题是,私营网络公司基本上在游说维持现状。许多公司已经赚了很多钱,所以让他们负责阻止勒索软件似乎过于乐观了。”

The memo placed specific limits on the scope of the new program. Private companies must first be approved after vetting by the Departments of Justice and Homeland Security. Cyber Effects Operations and Cyber Surveillance Operations may not result in “Critical Outcomes,” meaning those that result in the loss of life or serious injury or “rise to the level of use of force or armed attack under international law.”

备忘录对新计划的范围设定了具体限制。私营公司必须先经过司法部和国土安全部的审查并获得批准。网络效应行动和网络监视行动不得导致“关键后果”,即导致生命损失、严重伤害,或“达到国际法规定的使用武力或武装攻击的程度”。

The memo also notes: [M]inimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company’s ability to perform successfully. Participating companies must also deposit $1 million in an escrow account. The deposit will be forfeited “should the Participating Company enter non‑compliance with its contractual agreement described” in the memo.

备忘录还指出:参与公司为参加该计划必须满足的最低标准,应包括适当的技术熟练程度、已证明的网络行动表现、设施安全、人员审查、能力、可靠性,以及项目执行董事在与国土安全委员会协调后认为对于确保参与公司成功执行任务具有高信心相关的或必要的其他因素。参与公司还必须在托管账户中存入100万美元。如果“参与公司未能遵守备忘录中描述的合同协议”,该押金将被没收。

Many of the specifics of the policy remain undefined. These details will be crucial to determining how effective and judicious the program will be. The memo directs the Justice and Homeland Security departments to deliver the particulars in the next 60 days.

该政策的许多具体细节仍未明确。这些细节对于确定该计划的有效性和审慎性至关重要。备忘录指示司法部和国土安全部在未来60天内提供具体细则。