How Does the FBI Respond to DDoS Attacks?

6.0K views
May 1, 2014
by
RSAC Cybersecurity
YouTube video player
How Does the FBI Respond to DDoS Attacks?

TL;DR

Effective DDoS response begins when victim organizations promptly notify the FBI and share relevant attack information with consent. The FBI triages each report, deploys appropriate resources, examines the tools and operating methods involved, and distributes useful threat information, while sustained public-private dialogue builds the trust and preparation needed for future incidents.

Transcript

The topic today is mitigating DDoS attacks. It's my pleasure to be speaking with Malcolm Palmore. He's the Assistant Special Agent in Charge of the FBI office in San Francisco. Hi, I'm Tom Field, Vice President of Editorial with Information Security Media Group. Malcolm, thank you so much for joining me today. Thanks for having me, Tom. To start ou... Read More

Key Insights

  • The FBI’s cyber responsibilities are divided into criminal intrusions and national security matters. Criminal cases can involve DDoS attacks or malware, while national security work addresses threats that may originate from countries intending harm on the national security spectrum.
  • A DDoS attack is not necessarily simple, despite sometimes being described that way. Malcolm Palmore calls that characterization an oversimplification and presents DDoS response as part of an ongoing, developing area within the FBI’s broader cyber mission.
  • The FBI’s DDoS response begins with notification from a victim organization. Established private-sector relationships often allow companies to contact the bureau directly, after which the FBI triages the available information and determines which investigative resources should be assigned.
  • The FBI gathers evidence to identify the tools and operating methods used by attackers. It then attempts to assemble that information and distribute useful findings to other organizations and professionals working within the cyber-threat field.
  • Private-sector partnerships extend the FBI’s visibility into cyber threats. Companies encounter more day-to-day threat activity than the bureau can observe independently, so closer relationships can deliver attack information faster and improve preparation for future incidents.
  • On-site FBI assistance depends on direct relationships and company consent. When a threat event occurs, agents may respond to the affected organization and collect appropriate information concerning the tools and methods used to initiate the attack.
  • Partnership success is reflected in continued notification and existing intelligence. A call from a partner during the next attack indicates developing trust, while previously collected threat information can show that law enforcement and intelligence organizations already understand aspects of the incident.
  • Constant dialogue is the central best practice for public-private cyber cooperation. Regular interaction, including engagement at industry conferences, helps the FBI understand private-sector needs, while isolated work by either side makes comprehensive threat response more difficult.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How does the FBI respond when a company reports a DDoS attack?

The FBI begins by receiving notification, often directly from a victim company through an established private-sector relationship. It triages the information and decides what resources should be used to help address the attack. Agents may respond at the company, collect information with its consent, examine the tools and operating methods involved, and assemble findings for broader threat-information sharing.

Q: What types of cyber cases does the FBI handle?

The FBI organizes its cyber work into two main categories: criminal intrusions and national security matters. Criminal cases range from DDoS attacks to intrusions in which malicious actors intend to introduce malware. National security cases concern threats that may come from countries intending harm. The San Francisco office is responsible for relevant cyber actions within and around its region.

Q: Why are private-sector partnerships important for DDoS response?

Private-sector partnerships bring the FBI closer to the organizations that experience cyber threats directly. Companies are likely to see more day-to-day activity than the bureau can observe on its own. Close relationships therefore support faster notification, better access to attack information, stronger preparation, and more useful guidance for organizations responding to similar issues in the future.

Q: What information does the FBI collect during a DDoS investigation?

With the affected company’s consent, the FBI gathers information related to the tools and methods used to start the attack. Investigators try to identify how the malicious actors operated and combine the collected details into a clearer understanding of the threat. The bureau can then distribute useful information to others working in the cyber-threat field.

Q: What does the FBI contribute to public-private cyber partnerships?

The FBI contributes investigative personnel, cyber expertise, direct contacts, and access to broader law-enforcement and intelligence relationships. When an incident occurs, it can place agents at the affected company and gather appropriate evidence with permission. It also analyzes attacker tools and methods, connects new incidents with information already held, and shares relevant findings with cyber-threat participants.

Q: What does the FBI need from private-sector organizations during an attack?

The FBI needs timely notification, direct communication, consent for appropriate evidence collection, and information about what the organization observed. Private companies have closer visibility into attacks occurring within their environments, so their observations help the bureau understand the problem more quickly. Continued dialogue also gives investigators better insight into private-sector needs and improves collective readiness for future threats.

Q: How does the FBI measure whether a cyber partnership is successful?

One indicator is whether a private-sector partner calls the FBI when the next attack happens. That notification suggests that trust is developing and that the company recognizes the bureau’s useful capabilities. Another indicator is whether the intelligence community already possesses relevant threat information after investigators determine what the incident involved. Palmore notes that these measurements are still developing.

Q: What is the main best practice for stronger DDoS cooperation?

The main best practice is constant dialogue between the FBI and private-sector partners. More frequent communication and interaction help the bureau understand organizational needs and prepare for future attacks. Industry gatherings such as the RSA Conference provide opportunities for that engagement. When government and private organizations operate separately, covering the full cyber-threat landscape becomes considerably more difficult.

Summary & Key Takeaways

  • The FBI’s San Francisco Cyber Branch handles criminal intrusions and national security threats affecting its region. Its cases include DDoS attacks, malware-related intrusions, and activity connected to countries that may intend harm. Cyber matters are a major FBI priority, although individual attacks can be technically complex and difficult to address.

  • A DDoS investigation commonly starts when a victim company contacts the FBI through an established private-sector relationship. The FBI triages the report, determines which resources are needed, and may place agents at the company. With the organization’s consent, agents collect information about the tools and methods used during the attack.

  • Public-private partnerships help compensate for limits involving geography and personnel. Companies observe threats more frequently and directly than the FBI, so close relationships can accelerate notification and improve preparation. The FBI contributes investigative resources and shares assembled threat information, while private organizations provide timely observations and relevant evidence from affected environments.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚