After cybersecurity lab wouldn’t use AV software, US accuses Georgia Tech of fraud
Full article943 words · extracted from arstechnica.com · click to collapse
Network security
Researchers allegedly found security protocols “burdensome.”
Credit: Georgia Tech
Credit: Georgia Tech
Dr. Emmanouil “Manos” Antonakakis runs a Georgia Tech cybersecurity lab and has attracted millions of dollars in the last few years from the US government for Department of Defense research projects like “Rhamnousia: Attributing Cyber Actors Through Tensor Decomposition and Novel Data Acquisition.”
The government yesterday sued Georgia Tech in federal court, singling out Antonakakis and claiming that neither he nor Georgia Tech followed basic (and required) security protocols for years, knew they were not in compliance with such protocols, and then submitted invoices for their DoD projects anyway. (Read the complaint.) The government claims this is fraud:
At bottom, DoD paid for military technology that Defendants stored in an environment that was not secure from unauthorized disclosure, and Defendants failed to even monitor for breaches so that they and DoD could be alerted if information was compromised. What DoD received for its funds was of diminished or no value, not the benefit of its bargain.
AV hate
Given the nature of his work for DoD, Antonakakis and his lab are required to abide by many sets of security rules, including those outlined in NIST Special Publication 800–171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations.”
One of the rules says that machines storing or accessing such “controlled unclassified information” need to have endpoint antivirus software installed. But according to the US government, Antonakakis really, really doesn’t like putting AV detection software on his lab’s machines.
Georgia Tech admins asked him to comply with the requirement, but according to an internal 2019 email, Antonakakis “wasn’t receptive to such a suggestion.” In a follow-up email, Antonakakis himself said that “endpoint [antivirus] agent is a nonstarter.”
According to the government, “Other than Dr. Antonakakis’s opposition, there was nothing preventing the lab from running antivirus protection. Dr. Antonakakis simply did not want to run it.”
The IT director for Antonakakis’ lab was allowed to use other “mitigating measures” instead, such as relying on the school’s firewall for additional security. The IT director said that he thought Georgia Tech ran antivirus scans from its network. However, this “assumption” turned out to be completely wrong; the school’s network “has never provided” antivirus protection and, even if it had, the lab used laptops that were regularly taken outside the network perimeter.
The school realized after some time that the lab was not in compliance with the DoD contract rules, so an administrator decided to “suspend invoicing” on the lab’s contracts so that the school would not be charged with filing false claims.
According to the government, “Within a few days of the invoicing for his contracts being suspended, Dr. Antonakakis relented on his years-long opposition to the installation of antivirus software in the Astrolavos Lab. Georgia Tech’s standard antivirus software was installed throughout the lab.”
But, says the government, the school never acknowledged that it had been out of compliance for some time and that it had filed numerous invoices while noncompliant. In the government’s telling, this is fraud.
Self-assessment
The second problem was that Georgia Tech had to self-assess its security and submit a score showing how many of the 110 NIST-listed security controls it had in place. Georgia Tech submitted an “overall security plan” for the whole campus with a score of 98 out of 110.
But this “overall” plan was basically fictional—it was a model, and apparently not an accurate one. Georgia Tech doesn’t have a unified IT setup; it has hundreds of different IT setups, including a different one at most research labs. Rather than score each setup—such as the Antonakakis lab—differently, Georgia Tech officials simply submitted the modeled “98” overall score for the Antonakakis projects.
The government was not amused by these shenanigans, which in no way reflected the actual security of the labs doing the DoD research.
The enterprise-level score of 98 that Georgia Tech and GTRC submitted to DoD in December 2020 is false. It does not reflect a score for any information system used to process, store, or transmit Controlled Defense Information in connection with Defendants’ DoD contracts.
How we got here
How did things get this lax? In the government’s telling, the school routinely missed compliance obligations in large part because the researchers found dealing with security protocols “burdensome.” And when the researchers complained, admins gave in.
According to these former employees, senior leadership at Georgia Tech gave in to the demands of these researchers to avoid compliance with cybersecurity regulations because “of the money [the researchers] bring in” from government contracts.
As one former employee described it, Georgia Tech had a cybersecurity compliance “culture of somebody up the line is going to overturn me… [so] I might as well go ahead and ignore the policy.” Another former employee described Georgia Tech’s “attitude” to its “obligations to meet cybersecurity requirements” as “oh, I don’t want to bother with that.”
Not everyone felt this way, of course; in fact, this case came to light due to a couple of whistleblowers on Georgia Tech’s IT staff.
Security certainly can be a pain, and it can be especially antithetical to the open nature of most academic research and culture. But that very openness can make academic labs tempting targets for nation-state espionage.
By suing a major institution like Georgia Tech, the US government seems to be firing a shot across the bow of all the other schools running labs with federal security money. “We don’t care if you don’t like it,” the suit seems to say. “If you want the money, get serious about the obligations.”
Listing image: Georgia Tech
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/08/oh-your-cybersecurity-researchers-wont-use-antivirus-tools-heres-a-federal-lawsuit/