#980 1986 · Clifford Stoll, Lawrence Berkeley National Laboratory · Cybersecurity / counter-espionage
An astronomer chased a 75-cent accounting error and uncovered a KGB hacking ring
问题
A hacker was moving through US military networks, and no existing tool could trace an intruder across shared systems
背景
In 1986, Clifford Stoll, an astronomer working as a systems administrator at Lawrence Berkeley National Laboratory, was asked to resolve a trivial 75-cent discrepancy between two accounting systems tracking computer usage — nine seconds of computer time nobody had been billed for. The lab had no budget for a formal security investigation and no precedent for treating a rounding error as anything but a bookkeeping nuisance; the obvious move was to write off 75 cents and move on.
Instead of dismissing the discrepancy, Stoll traced it to an unauthorized user account and, rather than locking the account out immediately, chose to let the intruder keep working while he built makeshift monitoring — printers rigged to log every keystroke, alarm pagers wired to alert him overnight — turning his own lab into a live surveillance operation on a budget of essentially nothing.
换别人会怎么做
Write off the 75-cent discrepancy as a rounding error or minor accounting glitch, which is what any organization would normally do with a nine-second, sub-dollar anomaly. It would have let a live foreign espionage operation inside US military networks continue undetected indefinitely, because nothing about the size of the discrepancy hinted at the scale of what was actually happening.
他们看到了什么
Stoll refused to treat an anomaly's size as its importance. A 75-cent gap meant something was touching the system no record had captured — and the dollar amount said nothing about how serious that was.
那一手
Stoll spent nearly a year tracing the intruder's connections back through a chain of university and military networks to a hacker operating out of Hannover, West Germany, ultimately identified as Markus Hess. To confirm what Hess was after and pin down his location precisely, Stoll built a fake trove of classified-sounding but fabricated military documents on the lab's system as bait, keeping Hess connected long enough for West German authorities to trace the call. Stoll's own account of the trace, published in the journal Communications of the ACM and later the book The Cuckoo's Egg, became the first widely read public documentation of state-sponsored computer espionage.
为什么管用
Most intrusion signals get dismissed because their immediate cost looks trivial, but a discrepancy's size measures the symptom, not the cause — an intruder who took nine seconds of unbilled computer time could just as easily be using the same access for something with no dollar figure attached at all, like copying military files. By treating the mismatch as a signal worth following rather than a cost worth writing off, and then choosing to observe the intruder instead of blocking him immediately, Stoll converted a routine access log into a live surveillance channel that eventually mapped the intruder's entire chain of hops back to Hannover — information an instant lockout would have destroyed the moment it triggered.
值了多少
Hess and two co-conspirators were arrested in 1987 and convicted of espionage in 1990 for selling US military data to the KGB.
什么时候会失灵
Treating every small anomaly as a major signal doesn't scale — most tiny discrepancies really are noise, and an organization that investigates every rounding error with Stoll's intensity will exhaust its resources chasing nothing. The approach works because Stoll had enough technical latitude to build ad hoc monitoring cheaply and enough patience to watch an intruder for months without leadership pressure to shut the account immediately; environments demanding immediate lockout on any detected breach, for compliance or liability reasons, can't leave an intruder connected long enough to trace them the way he did.
后来呢
The Cuckoo's Egg sold over a million copies and is credited with introducing an entire generation of network administrators and early cybersecurity professionals to intrusion detection and digital forensics; Stoll's honeypot bait-document technique became a foundational method still used in cybersecurity today.
资料来源
- [1]COMPUTER HACKERS FACE SPY CHARGESThe Washington Post, 1989washingtonpost.com
- [2]A cybersecurity talk by an astronomer who brought down a KGB hackerOregon State University, College of Science, 2018science.oregonstate.edu