JPL privileged-account compromise involving Chinese-based IP addresses, November 2011
What happened
In November 2011 JPL IT Security reported suspicious network activity involving Chinese-based IP addresses. NASA's Inspector General told Congress in February 2012 that the OIG review had disclosed that the intruders compromised the accounts of the most privileged JPL users, giving them access to most of JPL's networks, and that with full system access they were able to modify, copy or delete sensitive files; add, modify or delete user accounts for mission-critical JPL systems; upload hacking tools to steal user credentials and compromise other NASA systems; and modify system logs to conceal their actions. His summary was that the attackers had full functional control over these networks. NASA OIG's 2019 JPL cybersecurity audit gave the same intrusion a fuller account: the intruders gained full access to 18 servers supporting key JPL missions, including the Deep Space Network and the Advanced Spaceborne Thermal Emission and Reflection Radiometer mission, and to sensitive user accounts; they resided within the system for two weeks before detection; and analysis of intrusion-detection log files revealed that 87 gigabytes of data had been uploaded to the attackers' IP addresses. In response JPL implemented automated means of identifying malicious activity and placed Security Operations Center personnel on call.
Two Tier 1 government sources seven years apart describe this intrusion and agree, which is why confidence is high although no actor is named. Attribution is deliberately absent: both sources say only that the activity involved Chinese-based IP addresses, which is an observation about network origin rather than an attribution, so date_attributed is null. The mapping stops where the sources stop. The Inspector General attests that the intruders were ABLE to modify files and mission-critical accounts, not that they did so, and no source reports a command reaching a spacecraft, so IA-0007.02 is rejected despite the intruders holding exactly the position from which it would be executed. One behaviour the testimony states plainly, modifying system logs to conceal their actions, has no SPARTA edge at all: the defence-evasion tactic has no ground-side anti-forensics technique. This record is one of the events contained in nasa-agency-network-intrusions-2010-2011; the relationship is containment, not duplication, and it is kept separate because IG-19-022 gives it a documentary record the portfolio does not have.
Attack vector
Compromise of the accounts of the most privileged JPL users, from network origins in Chinese-based IP address space. Neither source states how those accounts were obtained.
Operational impact
Not stated as an operational effect on any mission. What is recorded is the extent of access: full access to 18 servers supporting key JPL missions including the Deep Space Network and ASTER, access to most of JPL's networks, and the ability to modify, copy or delete sensitive files and to add, modify or delete user accounts for mission-critical systems. No source reports that a spacecraft was commanded or that a mission was interrupted.
Data compromised
87 gigabytes of data uploaded to the attackers' IP addresses, per analysis of intrusion-detection system log files. Neither source itemises the contents.
Affected segments
ground
Disclosed
2012-02-29
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
Analysis of intrusion-detection system log files revealed that 87 gigabytes of data had been uploaded to the attackers' IP addresses from servers supporting key JPL missions. EXF-0007 is exfiltration at scale from a resident position inside mission ground infrastructure; here the volume, the direction and the method of detection are all on the record.
The intruders gained full access to 18 servers supporting key JPL missions, including the Deep Space Network, and compromised the accounts of the most privileged JPL users, giving them access to most of JPL's networks. IA-0007's enumerated targets include mission control software, data gateways and antenna control; the DSN is that infrastructure, and the access is stated in a Tier 1 audit report rather than inferred.
87 gigabytes left servers supporting key JPL missions, among them the Advanced Spaceborne Thermal Emission and Reflection Radiometer mission, whose supporting servers hold the products an Earth-observing instrument gathers and downlinks. Confidence is moderate rather than high because neither source itemises what the 87 gigabytes contained, so the mission-data character of the loss is read from which servers were reached rather than from any description of the files themselves.
The intruders resided within the system for two weeks before being detected and modified system logs to conceal their actions, which is presence deliberately maintained rather than a single opportunistic entry. Confidence is moderate because two weeks is short against PER-0003's long-lived framing, and because what the sources describe is a dwell period ended by detection rather than an established persistence mechanism inside the ground infrastructure.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Log modification to conceal actions is defence evasion, but DE-0002.01's subject is the ground system's ability to process, render or interpret spacecraft telemetry. System logs are not telemetry, and no source reports telemetry processing being affected.
The most tempting rejection in this batch. The intruders had full functional control of servers supporting the DSN and could add, modify or delete user accounts for mission-critical systems. That is the position from which IA-0007.02 is executed, and neither source says a command was ever sent to a spacecraft. Martin's careful phrasing is that the intruders "were able to" do a list of things; ability is what he attests to.
One of the two techniques SPARTA cites for this incident, via a WIRED report on the testimony. That report describes no reconnaissance behaviour whatever: it summarises the intrusion, the figures and the quotations. This is a context citation. Its sibling
REC-0009is rejected on the same ground.One of the two techniques SPARTA cites for this incident, via a WIRED report on the testimony. That report describes no reconnaissance behaviour whatever: it summarises the intrusion, the figures and the quotations. This is a context citation. Its sibling
REC-0008is rejected on the same ground.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Cybersecurity Management and Oversight at the Jet Propulsion Laboratory (Report No. IG-19-022, A-18-012-00)Government report
Tier 1: A federal Inspector General audit report with direct access to JPL systems, officials and incident records. Primary and official. Where a record cites both this report and the February 2012 congressional testimony, this one is preferred as primary, being the more specific of the two.
Tier 2: Named contemporaneous reporting by a specialist security journalist on the Inspector General's report to Congress. Reports on the primary document rather than on independent access, so no claim in this record rests on it alone.
- NASA Cybersecurity: An Examination of the Agency's Information Security. Hearing before the Subcommittee on Investigations and Oversight, Committee on Science, Space, and Technology, House of Representatives, 112th Congress, Second Session (Serial No. 112-66)Government reportcorroborating
Tier 1: The published record of a congressional oversight hearing, containing the written statement of the NASA Inspector General in full. Primary, official, and permanently addressable at congress.gov.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.