Showing posts with label cyber warfare. Show all posts
Showing posts with label cyber warfare. Show all posts

Sunday, May 31, 2009

A Call for Action in Addressing Cyber Security

On Friday, President Obama addressed the nation on the importance of securing cyberspace and the reasons why it could be a danger to both our economy and national security. He also used the term, "weapons of mass disruption" and announced that he will appoint a cyber security czar.

The speech highlighted a 60-day study conducted at his direction, designed to take a look at how vulnerable we are to cyber attacks that could drastically change the whole way we exist.

Is this a far cry from reality? Perhaps not; if you can take command and control of the computer that controls something we use, you can do pretty much anything you want with it. This might be anything from a banking system to the system that controls an electrical grid or a sophisticated weapon. If you really think about, computers control just about everything nowadays.

As I was considering this, it reminded me that there are already millions of computers where some hacker has gained command and control of and formed into a botnet (essentially a supercomputer). All it took to do this was a little social engineering to trick someone into downloading some malicious code on a machine. While some of us might write this off as stupid people doing stupid things, people have even been tricked into doing this at government agencies and Fortune 500 companies. Trust me, not all the people who fall for some of this stuff are stupid. Social engineering is known to cause people to do things they normally would not!

While it takes a little technical sophistication to write malicious code, a person doesn't necessarily have to be a technical whiz to get their hands on it. They can buy it right on the Internet, complete with a do-it-yourself (DIY) kit to execute their intended misdeed. While most of the "misdeeds" seen in the wild have a financial intent, the intent is dictated by the person committing the act. In other words, the intent might be different depending on the person who is executing the deed.

Also mentioned, both in the report and in the speech, was cyber-warfare. For years now, the Chinese have been accused of hacking into government systems, although they always deny it. Also mentioned was an actual use of cyber warfare, or the Russian attack on Georgia that happened in the not very distant past.

Please note that botnets, which I mentioned above, were used to cripple the Georgian infrastructure. The zombie computers used in these botnets didn't come out of Russia, either. Some of them were traced right back to this country. In the current environment, you don't need to be in a physical location to take command and control; it might happen from anywhere.

The report also mentions attacking electrical grids and that the CIA has intelligence that this has already occurred in other countries. Just last month, the Wall Street Journal issued an article stating that Russian and Chinese hackers had mapped the U.S. power grid and left behind software that in theory could be used to attack our electrical grid. The article quoted unnamed officials from within the government. This set off a flurry of articles and in the end, most of the experts concluded that the threat, although real, wasn’t as bad as it was hyped up to be. Nonetheless, hacking certain utilities, such as electricity, water, and sewage could cause a lot of serious problems and there is evidence it has been accomplished in other countries.

While cyber warfare is an ominous subject, the report points out that we have already seen some pretty major events when financial systems were successfully attacked. Examples given were the TJX data breach (45 million payment cards compromised) and the more recent WorldPay payment card breach where a 30 minute exploit netted nine million dollars. This highly coordinated scheme took place all over the United States, Montreal, Moscow, and Hong Kong in a very short time-frame.

There is tangible evidence that so much personal and financial information has been stolen that the laws of supply and demand are driving prices down. Interestingly enough, a lot of this information is traded right over the Internet in anonymous forums using hard to trace forms of payment.

Two recent reports point to this. Symantec released a pretty interesting report on the underground economy and shortly afterwards, Verizon issued another report on the state of personal and financial information being stolen. The Verizon report, pointed out that the 285 million "known" records stolen in 2008 amounted to more than what was recorded in the previous three years. The Symantec report, which breaks down the going prices for information noted that the practice of spoofing (impersonating) financial institutions to steal information grew from 10 percent in 2007 to 29 percent in 2008. The Symantec report stated that 90 percent of the attacks being launched via botnets were designed to steal information and that the number of infected computers had grown 31 percent in 2008 over 2007, also.

Also cited in the report and in the speech was an estimated $1 trillion dollar loss per year in intellectual property. In recent years, the FBI has been busy catching numerous people stealing technology secrets and exporting them out of the country. This brings up another variable in the problem or if a person is given access to a system it is relatively easy to compromise it.

Recently, it was even disclosed that computers in Congress were hacked. It appears that even government intellectual property is being targeted.

When it comes to intellectual property theft, often we do not know what the motive is. Again, the intent is largely dictated by the end user. If you wanted to see a real world example, you might take a look at software piracy. The Business Software Alliance puts worldwide losses at over $50 billion, yearly. If you were to look at counterfeiting in general – which can involve the theft of intellectual property – the International Anticounterfeiting Coalition estimates the losses at $200 to $250 billion just in the U.S., every year.

The report, which is posted on WhiteHouse.gov, also addresses the growing problem of privacy in the digital world. Personal and financial information is worth a lot of money to businesses and criminals alike. Unfortunately, because of this, a lot of people are leery of putting in controls that might make it harder to profit from information. Because of this, a lot of people’s personal and financial information has gone missing.

The American Library Association, the Cato Institute, the Center for Democracy and Technology, Carnegie Mellon University, Consumer Action, the Center on National Security Studies, Cornell University, the Electronic Frontier Foundation, the Electronic Privacy Information Center, George Washington University, Harvard University, Indiana University, Johns Hopkins University, OMB Watch, Ohio State University, the National Security Archive, the University of California-San Diego and the American Civil Liberties Union were all consulted in the initial 60-day report.

While the report isn't clear on how privacy will be dealt with, it nonetheless is calling out that a problem exists. The problem is too much information being stored in too many not very well secured places.

For a real example here, one could refer to the DATALOSSdb Open Security Foundation, which tries to document all the known data breaches. The problem is getting worse all the time, and although some might argue that greater transparency is the reason for this, there are probably many more unknown data breaches that occur out there. After all, it’s unlikely that the hackers or other criminals stealing the information are going to come right out and tell us where they are getting it from. From a business perspective, it isn’t in their best interests.

The real casualties in this part of it are the individual victims, who suffer a lot when their information is used after it stolen. With the sheer amount of victims out there, some could argue we are facing an identity crisis.

To add to the problem, technology is now also being used to produce high-quality counterfeit documents and financial instruments in places, such as garages. This makes the information being stolen all the more dangerous, or easy to abuse.

Another thing the report addresses is the need for education and that laws need to catch up to the technology we are using. An interesting section at the end of the report highlights the history of modern communication technology. There is little doubt that as technology grows at a rapid pace; it is hard for the legal community to keep up with it.

In the end, in my humble opinion, the study is the first step in a positive direction. We have already seen too many examples of the abuse of technology, which has a lot of potential for good, too! The problem is how to deal with those who abuse it. The good news is that a large part of solution can be achieved by using a little more common sense and the clean slate approach (mentioned in the report) will go a long way towards making this a viable effort. In the end, a responsible balance is the key, and this is what it seems the report seems to be calling for.

Sunday, August 17, 2008

Cyber Warfare, Not Just a Theory Anymore?

Last week, the news of a cyber attack by Russia against Georgia made this type of warfare become a chilling reality. According to an article in the LA Times, it also revealed how ill-prepared most of the world is to deal with this new threat.

Most of the experts now agree that cyber attacks started well before lead started flying and were not very sophisticated by current standards. Most of the attacks were run of the mill DDOS (Distributed Denial of Service) type events designed to deface and shut down government sites.

One of the problems is that no one can actually pin the attacks to the Russians. As usual, botnets of zombie computers were used to facilitate the assault on the sites in question. Since these zombie computers are taken over by malicious software -- normally after an unsuspecting user clicks on a link in a spam e-mail -- the computers used in the attack probably resided in locations all over the world. Botnets are also used to send out the spam e-mails with the malicious links that turn systems into what are known as zombie computers, which add to the power of the botnet.

Researchers at Shadowserver, a volunteer group monitoring cyber attacks, have traced the attacks against Georgia as starting in July and being based out of the United States, according to an article in the New York Times. The Times article suggested that there might be ties in this attack to Russian organized cyber criminals.

It should be noted that the words Russia and cyber crime bring up pages of results on most search engines. Russian organized crime is also known to have a global reach so it is no surprise that some of the current DDOS attacks were traced to a server in the United States. Simply stated, these attacks can be made to appear as if they are coming from just about anywhere.

While this is one the first times cyber warfare has actually occurred, it's starting to become a topic of concern in government circles. As a matter of fact, in April it was a hot topic at the NATO summit and an EU conference. China is also known to be actively seeking a cyber warfare capability and gets accused of hacking into other government's websites all the time.

Last year, Estonia suffered cyber attacks, which were allegedly facilitated by Russian Hackers, also. In an interesting development, Network World reported that they are sending cyber defense advisors to assist the Georgians.

Wikipedia has an interesting article (Wiki) on cyber warfare. It cites that McAfee stated in their 2007 annual report that approximately 120 countries have been developing cyber warfare capabilities designed to disrupt financial markets, government computer systems and utilities. The article also lists several examples of attacks, which many suspect were facilitated by the Russians or the Chinese, that have recently occurred.

The McAfee report surmised that cyber attack capabilities are becoming a global issue as well as a threat to national security. Current events seem to be making that prediction turn into reality.

Thursday, March 13, 2008

London e-crime conference suggests that hackers are becoming more organized and politically motivated

In the past several years, we've seen a lot of corporate and government systems compromised by hackers. With corporate systems, we assume the intent is financial, however more and more, we hear the term, "corporate espionage" being used. In the global economy, information is often worth more than money.

With regards to government systems being hacked, it's hard to speculate that the attack was financially motivated.

Mandy Clark of Voice of America wrote an interesting article on this subject, while covering an International e-crime congress in London:

British opposition lawmaker David Davis warned an e-crime conference in London that the danger of cyber terrorism is real.

"In America, hackers have already broken into the Pentagon's computer systems; in India, into government ministers' files; in Germany, into the chancellor's," Davis said. "Such attacks could be designed to compromise safety systems, critical national infrastructure, to overwhelm communication systems, or even to cause a run on the bank."

Included in the VOA article is a video containing a lot of commentary from experts from both the government and private sectors:

Cyber Threat report / Broadband - Download (WM)

Cyber Threat report / Broadband - Watch (WM)



Unfortunately, many consider this type of activity open to speculation, or point out that it might be mere propoganda. In the end -- IF this activity is caused by organized crime or those with more political intentions -- it's going to be hard to get the people behind it to comment.

Political misfits, criminals, spies and hackers normally want to keep their activity confidential because transparency often compromises whatever goal they are trying to achieve.

Nonetheless, a lot of experts and lay people agree that we are seeing more of this type of activity and that it is becoming a lot more sophisticated than it used to be.

VOA article by Mandy Clark, here.

United Press International covered this story from a NATO cyber warfare perspective, here.

Wednesday, September 26, 2007

Video shows mock cyber attack on power grid

Ted Bridis and Eileen Sullivan of the AP are reporting about a video, which shows how a cyber attack might shut down our utilities.

From the AP article (courtesy of the Washington Post):

The video, produced for the Homeland Security Department and obtained by The Associated Press on Wednesday, was marked "Official Use Only." It shows commands quietly triggered by simulated hackers having such a violent reaction that the enormous turbine shudders as pieces fly apart and it belches black-and-white smoke.

Although, this attack never took place, the article quotes goverment sources as saying:

President Bush's top telecommunications advisers concluded years ago that an organization such as a foreign intelligence service or a well-funded terror group "could conduct a structured attack on the electric power grid electronically, with a high degree of anonymity, and without having to set foot in the target nation." Ominously, the Idaho National Laboratory _ which produced the new video _ has described the risk as "the invisible threat."
Experts said the affected systems were not developed with security in mind.

Now for the good news:

The Homeland Security Department has been working with industries, especially electrical and nuclear companies, to enhance security measures. The electric industry is still working on their internal assessments and plans, but the nuclear sector has implemented its security measures at all its plants, the government said.

In July the Federal Energy Regulatory Commission proposed a set of standards to help protect the country's bulk electric power supply system from cyber attacks. These standards would require certain users, owners and operators of power grids to establish plans and controls.
The bad news, not mentioned in this article, is that some say foreign nations (China in particular) routinely attempt to hack into government systems.

Previous posts, I've written about alleged hacking attempts from China can be seen, here.

Of course, the Chinese government denies this is the case!

AP Story, courtesy of the Washington Post, here.