🎁 💸 Warren Buffett's Top Picks Are Up +49.1%. Copy Them to Your Watchlist – For FreeCopy Portfolio

Cisco reviews code after Juniper breach; more scrutiny expected

Published 12/21/2015, 07:24 PM
© Reuters. The Cisco Systems logo is seen as part of a display at the Microsoft Ignite technology conference in Chicago
CSCO
-
JNPR
-

By Jim Finkle

BOSTON (Reuters) - Networking equipment maker Cisco Systems Inc (O:CSCO) said on Monday it has launched a product review to look for tampering after rival Juniper Networks (N:JNPR) Inc's disclosure found code in firewall software that made in vulnerable to cyber attacks.

Juniper warned customers on Thursday that it had uncovered "unauthorized code" in its firewall software, saying it could be exploited to allow an attacker to unscramble encrypted communications that travel through the security devices.

That prompted the code review by Cisco. Security experts said they expect other technology companies to conduct similar investigations after last week's unprecedented news from Juniper.

It was the first time a major technology firm discovered the addition of an unauthorized 'back door," or code that could be exploited to facilitate cyber attacks, according to security experts.

"I can't imagine there is a major vendor that isn't doing a major code audit now," said HD Moore, chief research officer with Rapid7 Inc.

Technology companies regularly audit their code for bugs, including "back doors" that attackers could leverage to launch cyber attacks on customer networks.

But Moore said that such reviews focus on "back doors" that are unintentionally created, not ones inserted without the manufacturer's knowledge.

"The challenge is that nobody has been looking for this in the past," said Moore, an expert in software vulnerabilities. "If you know you are looking for a malicious backdoor, you have a much better chance of finding something."

Cryptologist Bruce Schneier said that technology companies should have long been looking for unauthorized code, but that many ignored the problem since the reviews boost expenses.

"The fundamental problem is that the market doesn't reward the things we want like secure code. Nobody wants to pay for it," he said.

Cisco said on its blog that the testing will include code reviews by engineers with deep networking and cryptography experience as well as penetration testing, a process where technicians attempt to attack products to find bugs the way malicious hackers might seek to exploit them.

Meanwhile, the U.S. Department of Homeland Security said it was investigating how the Juniper "back door" might impact government networks.

© Reuters. The Cisco Systems logo is seen as part of a display at the Microsoft Ignite technology conference in Chicago

"As we routinely do when such vulnerabilities are brought to light, we are assessing the potential impact, if any, on federal networks, and will take any appropriate mitigation measures in close coordination with interagency partners," said agency spokesman S.Y. Lee.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.