News Analysis   More News Analysis

Cisco's IOS Code 'Compromised'

Hackers have obtained source code for Cisco Systems Inc.'s (Nasdaq: CSCO) Internetwork Operating System (IOS) 12.3 Operating System, according to a report released over the weekend.

The significance is hard to determine, but it could help hackers identify security vulnerabilities that would enable them to disable routers and take down parts of the Internet.

The risk of this happening depends on how many security vulnerabilities exist in the code and what exactly has been stolen. Different versions of IOS Release 12.3 are used in a wide variety of Cisco equipment, including its 7000 series routers and Catalyst 6000 switches (see Cisco's Release Notes).

Cisco issued the following statement this morning: "Cisco is aware that a potential compromise of its proprietary information occurred and was reported on a public website just prior to the weekend. The Cisco Information Security team is looking into this matter and investigating what happened."

Russian Website SecurityLab.ru broke the news of the IOS theft. One of the parties claiming responsibility fed snippets of code to the site's administrators as proof of the deed; the snippets are posted at http://www.securitylab.ru/45222.html and http://www.securitylab.ru/45223.html.

To the extent that Web translations can be trusted, the site appears to be saying Cisco's network was hacked, leading to 800 Mbytes of source code being taken.

There's a chance it's the real thing. Routing expert and former Cisco employee Tony Li posted to a mailing list for the North American Network Operators' Group (NANOG) saying the code appears "(approximately) genuine" and includes "normal calls to IOS infrastructure routines." Comments in the posted code indicate it was written in June 1996 by Kirk Lougheed.

On the plus side, router code is more complex than Microsoft Corp. (Nasdaq: MSFT) code. Routing expertise isn't as widespread as PC operating system knowledge. And to do any damage, a hacker probably would have to determine how the modules link to each other and find vulnerabilities in those links, says Frank Dzubeck, president of consulting firm Communications Network Architects.

Another factor is the age of the compromised code. Newer elements of IOS haven't been implemented yet or, in the case of IPv6, may apply primarily to Asia but not to Cisco's entire customer base, making any damage less apocalyptic. On the other hand, certain aspects of routing code trace back to IOS's beginnings; should that code fall in the wrong hands, it could force Cisco to issue patches applying to every prior release, a case worse than what Microsoft faces with its patches, Dzubeck says.

"There are people running [Cisco code] six or eight releases back," he says. "The average guy running a small router never changes code. And then, AT&T and some of these big guys are running several different instances of code."

Possibly worst of all, though, are the implications to Cisco's business should the code become public domain. "Now you have no problems with any vendor being compatible with Cisco. You suddenly reduce the hardware to a commodity," Dzubeck says. "It would disenfranchise Cisco, because if you ask what Cisco is as a company, it's IOS."

Of course, Cisco could try to litigate or use the criminal justice system to track down the thieves, if in fact their were any -- but even then it will be hard to undo any damage.

That -- along with the possibility that Cisco's own network was breached, bringing its security features under question -- makes Cisco's explanation of the weekend's events crucial. "This week, a whole lot of information has to come out of Cisco," Dzubeck says. "If they stonewall, there are going to be a lot of problems."

— Craig Matsumoto, Senior Editor, Light Reading

Newest Comments First       Display in Chronological Order
Page 1 of 3 Next >
digerato
User Ranking
Monday October 11, 2004 1:33:09 PM
"My overall impression is that Huawei doesn't make a habit of copying. I can't prove this, and if someone *can* prove otherwise, I'd love to have the evidence."

Peter,

To do this, you are going to need a Cisco 3640 and a Huawei Quidway Refiner 3600. Open both boxes. Observe how the circuit boards are identical. Now, tell me that's a coincidence.

Cheers,

Digerato

Abby
User Ranking
Thursday May 20, 2004 9:05:08 PM
no ratings
>>Might I suggest that this discussion is somewhat pointless? First, I can promise you that Cisco certainly provides "reasonable" care for its source code. Second, none of here (hopefully) is the judge or jury on this case. What they have to say is relevant, what we have to say is not.

Light, not heat please...

------------------

I somewhat disagree with you. Specifically, because we don’t know for sure if this was a hack or not. Therefore, if it wasn’t and this was just some disgruntled employee, then John Chambers is not the only very paranoid CEO in the industry right now.

Moreover, the action of this individual(s) is deplorable, and although the intent may have been to hurt Cisco, we all got hurt because it builds mistrust in the global community as to the viability of the Internet. IMHO, if you know who the S.O.B. is, do us all a favor and turn him or her in.
ragho
User Ranking
Thursday May 20, 2004 1:45:07 PM
Tony,

Point well made, succinctly. Sometimes I wonder whether folks post here simply to hear themselves talk, so to speak..
GooblyWoobly
User Ranking
Wednesday May 19, 2004 6:16:44 PM
Look at the brighter side guys. The evil folks will look at Cisco coad, find the bugs, kill the internet for a few days (loss of billions??).

But at the end of all these, at least that part of Cisco code will be bug free (unless the great IOS guys introduce more bugs in the process of fixing them!!).
Tony Li
User Ranking
Wednesday May 19, 2004 4:09:07 PM
Gentlebeings,

Might I suggest that this discussion is somewhat pointless? First, I can promise you that Cisco certainly provides "reasonable" care for its source code. Second, none of here (hopefully) is the judge or jury on this case. What they have to say is relevant, what we have to say is not.

Light, not heat please...

Tony
whyiswhy
User Ranking
Wednesday May 19, 2004 12:44:34 PM
"Second, Huawei can't show cause with code that may have pre-existed in public hands."

This is the fundamantal arguement Cisco is using against Huawei, just turned around.

"The code is still owned and copyrighted by Cisco. It may just be a bunch of bits and bytes but Cisco retains all rights to their code, regardless of condition precedents."

This is called begging the question.

"Huawei is not immune to claims of rights infrigement from Cisco, if they did have Cisco code; regardless of their origin. Period."

And I never said they were. But it does go to damages. Let me give you a very straight example: if Cisco knew, or should have reasonably known about the Russian site, and failed to even try to close it down, or remove their material, they might fail the reasonable care test.

And so it goes....

-Why
coreghost
User Ranking
Wednesday May 19, 2004 11:41:57 AM
Huawei has admitted to stealing software, ignoring
patents, having access to the source code of
their major competitor internally and directly
copying large parts of their competitors
documentation.

While Huawei can say by its actions that it is
no longer selling a product with stolen software,
unlicenced patented technology and stolen
documentaiton, there is nothing Huawei can do
to change the criminal nature of what they have
done in the past.

They are totally guilty and they will lose if
the case proceeds. The rogue developers defense
will not work in court.

As far as their internal investigation, what
they did was to remove the obvious evidence of
copying at the level of the executables that
cisco found. But if cisco gets access to the actual
source code, its very possible that more copying
would be discovered. Of course some people
would believe that Huawei's internal
investigation showing no examples of copying
beyond what cisco already found is some sort
of vindication.

If cisco finds a pattern of copying, meaning
multiple examples in the source code, its still
possible that Huawei's entire software could
be declared tainted and therefore beyond
fixing.

bobcat
User Ranking
Wednesday May 19, 2004 8:05:10 AM
Interesting BioDiesel information.
And not to be disrespectful. BUT..

>>Perhaps the "thief" thought he/she was being helpful?

I'm thinking you're spending too much time in the kitchen.

As for post #16

>>Reasonable care (in protecting your property) has tons of legal precedence: and the case law says if you fail to exercise reasonable care, you lose most of your rights to damages.
Yes, you get the victory in court but it is meaningless: no money changes hands, or the amount is so small as to be trivial.

Sounds like you might be smokin some of that "green fuel" in post #15.

Ask companies like Microsoft, Rambus, or IBM if their victory in court is meaningless or trival.

Pay-up!

ragho
User Ranking
Wednesday May 19, 2004 6:15:30 AM

Whoa, you're taking quite a leftist stance there.



You seem to under-estimate the power of the judicial system while at the same time making a stretchy case. First, no company in their right mind would fail to exercise reasonable care of their intellectual property. If standard practices of corporate network protection and access authorization are in use, I doubt how anyone can lawfully contend that Cisco was negligent in it's care of IOS code.


Second, Huawei can't show cause with code that may have pre-existed in public hands. The code is still owned and copyrighted by Cisco. It may just be a bunch of bits and bytes but Cisco retains all rights to their code, regardless of condition precedents. Huawei is not immune to claims of rights infrigement from Cisco, if they did have Cisco code; regardless of their origin. Period.


Everyone has a job to do, I think Peter is doing his. I respect your opinion, but stop blowing smoke up people's ass with unsound legal points. What you've said about Cisco's dimished rights and Huawei's damage limits isn't true, period. Your argument will never stand the legal muster for an hour in court.

whyiswhy
User Ranking
Tuesday May 18, 2004 9:13:13 PM
Come on Dash, Peter has to make a living with the few optical communication companies left. This is a real ethical dilemma: be flexible and eat, or be perfectly honest and hungry. The days of the crusading reporter are gone, if they ever did exist. I am sure Peter will figure out creative ways to let us his readers know some of "the whole truth". Like this message board for example. Who knows who posts, right? A jab here, a poke there...

-Why
Page 1 of 3 Next >
LIGHT READING MARKET PLACE
Virtual Network Tool Guide
Choose the Right Tools with Our Online Guide and Resolve Network Issues Faster.
Your Customer Experience Defines You
OnProcess helps market leaders proactively improve their customers' experiences
Send & Sign Documents Online
Close Contracts in Minutes, Online. Send & Sign Sales Contracts, HR Forms, and More Electronically!
Used and Refurbished HP ProCurve Switches
Lifetime Warranties, Professional Testing & Shipping on all HP Equipment Purchases!
Conferencing System
Enter Now to Win Two Polycom Video Conferencing Systems. Details Here!
The blogs and comments are the opinions only of the writers and do not reflect the views of Light Reading. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
Related Content
White Papers SPONSORED CONTENT
Featured
Podcasts SPONSORED CONTENT
Services Transformation - by Alcatel-Lucent Communications service providers want to be able to bring new services to...
Rural Ops Bridge the Digital Divide - by Tellabs Tellabs helps IOCs build triple play networks
Driving Network Transformation - by Alcatel-Lucent In order to deal with competitive pressures, the change in service models...
Back(haul) to the Future - by Tellabs Tellabs works with Vodafone to meet growing mobile broadband demands.
MRS Logistica - by Tellabs Tellabs helps MRS Logistica transform its existing, largely outdated TDM networks to IP.
Carrier Ethernet Offers an Enterprising Solution - by Tellabs What is VPLS and how does it work? Tellabs takes a closer look.
Swisscom’s Network Makeover - by Tellabs Fresh off the launch of 7.2 Mbps HSDPA, Swisscom sees 3G as an opportunity to launch a unifying ...
Telecom in Namibia - by Tellabs Tellabs helps Telecom Namibia with next-gen challenges
Companies
Alcatel-Lucent (5872), AT&T (1948), BellSouth (848), BT (1287), Cablevision (615), Cisco (5297), Comcast (1910), Cox Communications (858), Deutsche Telekom (807), eBay (Skype) (345), Ericsson (1617), France Telecom (964), Google (489), Huawei (1045), Intel (1127), Juniper (2022), Microsoft (1115), Motorola (1486), Nokia Siemens Networks (2645), Nortel (3956), NTT (173), Siemens (1359), Sprint (1059), Telefonica (439), Time Warner Cable (969), Verizon (2587), Vodafone (510), Yahoo (339)

Broadband
Access equipment (2169), Access technologies (2378), Broadband loop carriers / multiservice access nodes (388), Cable modem termination systems (CMTSs) (1104), Cable TV chips (286), DSL (2425), DSL chips (227), DSLAMs (703), Free-space optics (35), FTTx (3265), Gaming consoles (58), Gaming servers (22), Media adapters (23), Municipal networks (106), PON (1364), PON chips (217), Satellite (497), WiMax (880), Wireless LAN (354)

Cable Digital
Cable Modems (681), Cable/MSO equipment (2802), CableLabs (470), Compression (MPEG-2 and MPEG-4) (279), Docsis (1046), Embedded multimedia terminal adapters (E-MTAs) (213), Head-ends (233), PacketCable (129), QAM (307)

Chips, Components & Subsystems
ASICs & FPGAs (101), ATCA (480), ATM chips (13), Comm chips (2360), Dispersion compensators (149), Lasers (920), Modulators (163), Mux/demuxes (299), Network processors (933), Optical amplifiers (349), Optical channel monitors (92), Optical components (2824), Speciality fiber (94), Switches & OADMs (397), Transceivers (1247), Transmission fiber (419), Variable optical attenuators (139)

Ethernet
10-Gbit/s Ethernet switches (1454), Access devices (272), ATM switches (333), Circuit emulation (16), Converged access (103), Ethernet chips (573), Ethernet equipment (2212), Ethernet over copper (231), Ethernet PONs (160), Ethernet services (1909), Ethernet technologies (568), Multipoint (131), Multiservice edge equipment (143), Multiservice provisioning platforms (622), Multiservice switches (389), PBT (Provider Backbone Transport) (256), Point-to-point (139), Pseudowire (Layer 2 tunnels) (132)

IP & Convergence
B-RASs (229), Cell/WLAN (77), Compression equipment (13), Core routers (1294), DNS (56), Edge routers (1686), ENUM (53), Fixed/Mobile Convergence (485), GMPLS (76), IMS (1088), IMS Control Layer (27), IMS Service Layer (27), IP equipment (1224), IP software (381), IP technologies (1482), IPv6 (99), Layer 3 VPNs (194), MPLS (1774), MPLS (687), Multicast (36), P2P (258), Pseudowire (Layer 2 tunnels) (132), QOS (350), SIP (396), Traffic managers (808), Wireline/Wireless (59)

Mobile/Wireless
3G Evolution (175), Broadcast (Mobile TV, etc.) (189), Carrier WiFi (226), CDMA (3G) (367), Core Network (173), EV-DO (126), Femtocells (30), Fixed Wireless (Microwave, etc.) (71), Fourth Generation (4G) Wireless (70), GSM/EDGE (430), HSDPA/HSUPA (321), IMS Core (47), Long-Term Evolution (LTE) (188), Mobile Advertising (24), Mobile Music (31), Mobile TV (130), Mobile Video (65), Mobile WiMax/WiBro (92), Mobile/Wireless (5877), Packet Core (61), Radio Access Network (236), TD-SCDMA (Chinese 3G) (67), Transmission (38), Ultra-Mobile Broadband (UMB) (8), UMTS(3G) (340), Voice Core (21), WiMax (880), Wireless Backhaul (272), Wireless Chips (191), Wireless LAN (354)

Optical Networking
40-Gbit/s transmission (452), Core optical switches (760), CWDM (289), DWDM (1842), Long-haul WDM equipment (654), Metro optical switches, ROADMs (1173), Metro WDM equipment (773), Multiservice provisioning platforms & add/drop muxes (375), Optical equipment (2191), Optical switches & crossconnects (398), Optical technologies (417), Sonet/SDH (1036), Sonet/SDH chips (351), Wavelength services (305)

Security
Anti-virus (29), Denial-of-service attacks (44), Encryption (97), Endpoint security (22), Firewalls (61), Intrusion detection & prevention (45), IPSec VPN (801), Security (1835), SSL VPN (862), URL filtering (12), User authentication (24)

Services Software
Activation (415), Billing systems (761), Content/software downloads (231), Customer relationship management (231), Data Integrity (61), Element management systems (36), Fault management (69), Inventory management (153), Mediation systems (204), Messaging (231), Middleware (72), Mobile location (41), OSS (2584), Performance monitoring (335), Policy control (269), Provisioning (553), Revenue assurance & fraud management (334), Service delivery platforms (SDPs) (328), Service management (220), Service-oriented architectures (310), Services (2480), Web gateways (56), Web services (124), XML (51)

Test & Measurement (Sponsored by Etaliq Inc)
Access equipment Access test & measurement equipment (126), Comm chips Comm chips test & measurement equipment (29), Ethernet equipment Ethernet test & measurement equipment (170), IP equipment IP test & measurement equipment (122), MPLS MPLS test & measurement equipment (14), Optical components Optical components test & measurement equipment (113), Optical equipment Optical test & measurement equipment (886), OSS OSS test & measurement (1059), Sonet/SDH Sonet/SDH test & measurement equipment (1599), Test & measurement (1755), VOIP equipment VOIP test & measurement equipment (145)

Video (Sponsored by Ericsson Televisionary)
Broadcast (Mobile TV, etc.) (189), Broadcast video equipment (including encoding) (730), Content delivery network (CDN) (394), Content protection (270), DVRs (665), Internet Video (840), IPTV (3461), Middleware & business support systems (845), Set-top boxes (1624), Stored video servers (379), TV (3581), Video equipment (2448), Video services (4130), Video software (1349), Videophone (185), VOD (2635)

VOIP
Application servers (186), Centrex (198), Conferencing (78), Contact centers (38), Enhanced voice (34), Enterprise (637), Media gateways (357), Messaging (73), Presence management (43), Residential (835), Session border controllers (398), Signaling gateways (104), Softswitches (1090), VOIP chips (167), VOIP equipment (3423), VOIP services (3768), VOIP software (620), VOIP VPNs (28), Wholesale (220)