FBI worried as DoD sold counterfeit networking gear

May 11, 2008, 08:35 PM —  IDG News Service — 

The U.S. Federal Bureau of Investigation is taking the issue of counterfeit
Cisco equipment very seriously, according to a leaked
FBI presentation
that underscores problems in the Cisco supply chain.

The presentation gives an overview of the FBI Cyber Division's effort to crack
down on counterfeit network hardware, the FBI said Friday in a statement. "It
was never intended for broad distribution across the Internet."

In late February the FBI broke up a counterfeit distribution network, seizing
an estimated US$3.5 million worth of components manufactured in China. This
two-year FBI effort, called Operation Cisco Raider, involved 15 investigations
run out of nine FBI field offices.

According to the FBI presentation, the fake Cisco routers, switches and cards
were sold to the U.S. Navy, the U.S. Marine Corps., the U.S. Air Force, the
U.S. Federal Aviation Administration, and even the FBI itself.

One slide refers to the problem as a "critical infrastructure threat."

The U.S. Department of Defense is taking the issue seriously. Since 2007, the
Defense Advanced Research Projects Agency has funded a program called Trust
in IC, which does research in this area.

Last month, researcher Samuel King demonstrated how it was possible to alter
a computer chip to give attackers virtually undetectable back-door access to
a computer system.

King, an assistant professor in the University of Illinois at Urbana-Champaign's
computer science department, has argued that by tampering with equipment, spies
could open up a back door to sensitive military systems.

In an interview on Friday, he said the slides show that this is clearly something
that has the FBI worried.

The Department of Defense is concerned, too. In 2005 its Science Board cited
concerns over just such an attack in
a report
.

Cisco believes the counterfeiting is being done to make money. The company
investigates and tests counterfeit equipment it finds and has never found a
"back door" in any counterfeit hardware or software, said spokesman
John Noh. "Cisco is working with law enforcement agencies around the world
on this issue."

The company monitors its channel partners and will take action, including termination
of a contract, if it finds a partner selling counterfeit equipment, he said.
"Cisco Brand Protection coordinates and collaborates with our sales organizations,
including government sales, across the world, and it's a very tight integration."

The best way for channel partners and customers to avoid counterfeit products
is to buy only from authorized channel partners and distributors, Noh said.
They have the right to demand written proof that a seller is authorized.

The FBI doesn't seem satisfied with this advice, however. According to the
presentation, Cisco's gold and silver partners have purchased counterfeit equipment
and sold it to the government and defense contractors.

Security researcher King believes that the government is better off focusing
on detection rather than trying to secure the IT supply chain, because there
are strong economic incentives to keep it open and flexible -- even if this
means there may be security problems. "There are so many good reasons for
this global supply chain; I just think there's no way we can secure it."

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff

Enterprise 2.0 Implementation
By Aaron C. Newman, Jeremy Thomas
Published by McGraw-Hill
Learn more!

Deploying Cisco Wide Area Application Services
By Zach Seils, Joel Christner
Published by Cisco Press
Learn more!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources