Cyberwarfare

Cyberwarfare raises issues of growing national interest and concern.

Cyberwarfare can be used to describe various aspects of defending and attacking information and computer networks in cyberspace, as well as denying an adversary’s ability to do the same. Some major problems encountered with cyber attacks, in particular, are the difficulty in determining the origin and nature of the attack and in assessing the damage incurred.

A number of nations are incorporating cyberwarfare as a new part of their military doctrine. Some that have discussed the subject more openly include the United Kingdom, France, Germany, Russia, and China. Many of these are developing views toward the use of cyberwarfare that differ from those of the United States, and in some cases might represent national security threats.

Cyberterrorism is also an issue of growing national interest. Many believe terrorists plan to disrupt the Internet or critical infrastructures such as transportation, communications, or banking and finance. It does seem clear that terrorists use the Internet to conduct the business of terrorism, but on closer inspection, however, it is not clear how or whether terrorists could use violence through the Internet to achieve political objectives.

Although the U.S. government is striving to consolidate responsibility for and focus more attention on cyberwarfare issues, it is not clear how successful those efforts will be. Congress may choose to examine critically the policies, organization, and legal framework that guides executive ranch decisionmaking on issues of cyberwarfare.
Showing posts with label cyberattacks. Show all posts
Showing posts with label cyberattacks. Show all posts

Friday, March 26, 2010

China to blame for repeated cyberattacks

http://t2.gstatic.com/images?q=tbn:mjaCK3TUf3gSsM:http://topnews.us/images/Google_Chinese-cyber-attacks.jpgThe computerized critical infrastructure of the US is "severely threatened" by cyberattacks now occurring on an "unprecedented scale with extraordinary sophistication."


Director of National Intelligence Dennis Blair testifies on Capitol Hill in Washington, Wednesday, before the House Intelligence Committee hearing on the annual threats assessment of the US intelligence community.

Manuel Balce Ceneta / AP

That's the headline Dennis Blair, director of national intelligence, offered the Senate Select Committee on Intelligence Tuesday. But it was the largely unreported details he unpacked that could provide the wake-up call for government and private industry, whose computer networks he says are now under persistent and subtle assault.

In his remarks, Mr. Blair concluded that:

• Sensitive information is “stolen daily from both government and private sector networks.”

• Investigations are finding "persistent, unauthorized, and at times unattributable presences on exploited networks, the hallmark of an unknown adversary...."

• The US cannot be certain its cyberspace infrastructure will be available and reliable in a crisis.

• The US and the world face greater vulnerability to disruption as a result of the trend toward convergence of voice, facsimile, video, computers, and controls that operate critical infrastructure on a single network: the internet. These include banking, power, and water supplies

• Cyberthreats are increasingly subtle and sophisticated. Last year saw the deployment of “self-modifying malware, which evolves to render traditional virus detection technologies less effective.”

Such attacks are already happening, confirmed Daniel Geer, chief information security officer for In-Q-Tel, a nonprofit venture capital firm funded by the Central Intelligence Agency, at a security conference for the oil and gas industry in Houston in November. Other cybersecurity experts cite a growing threat from so-called "polymorphic" spyware that can change its digital signature to millions of different combination to evade identification by anti-virus software.

In this new scenario, a single piece of malware often has multiple characteristics. Its digital signatures can morph to evade detection. At the same time, it can spin off decoys intended to be caught to make it appear as if an attack has been thwarted.

http://www.csmonitor.com/var/ezflow_site/storage/images/media/images/google-censorship-row-intensifies/7268269-1-eng-US/Google-censorship-row-intensifies_full_600.gifThe recent sophisticated attacks on Google should be a "wake-up call,” Blair said. His remarks echoed recent reports that show the problem is not only coming from clever hackers, advanced viruses, or organized cybercrime gangs – but from “nation states,” too.

"Many [of the most sophisticated attackers] have the capabilities to target elements of the US information infrastructure for intelligence collection, intellectual property theft, or disruption," Blair said.

Countries see repeated cyberattacks

More than half of the 600 IT managers operating critical infrastructure in 14 countries reported being recently hit by "high-level" adversaries such as organized crime, terrorists or nation states, according to a new global survey of information technology executives by the Center for Strategic and International Studies in Washington late last month.

A majority of the group hit, 59 percent, said they thought their computer networks and controls systems were under "repeated cyberattack, often from high-level adversaries like foreign nation-states."

Blair's comments might be news to the Senate, but cybersecurity experts face these threats daily. The "persistent" threat he referred to, for instance, is known widely as the "Advanced Persistent Threat" or APT within the security community. It's also shorthand for state-sponsored "foreign intelligence" operations and sometimes just "China."

"These are not ‘slash-and-grab jobs’,” says Rob Lee, a director at Mandiant, a leading cyber security firm. "The goal of the intruder is to occupy the network. These are professionals, not people doing this at night. This is someone's full-time job from the initial breach to lateral movement across the network, the actual occupation, then the ex-filtration of data - there are clear lines of responsibility between different actors going on."

Is China to blame?

According to Mr. Lee and other experts, the common thread in the APT is connected to China. Among 40-45 very sophisticated attacks in the past year, about two-thirds were “China related,” he said.

Shawn Carpenter, principal forensics analyst at NetWitness Corporation, concurs. He says that in a number of cases he has traced malware code back to Chinese hacker sites and to Chinese character sets in software compilers used to create the code. "You can put together some pretty compelling links that trace their way back to China," he says.

Representatives of the Chinese Embassy regularly rebut such criticisms, as they did with a Monitor report last month on cyber attacks targeting the US oil and gas industries.

Washington: Internet domain company GoDaddy.com said it planned to stop registering domain names in China, joining Google Inc in protesting cyber attacks and censorship in that country.

"We believe that many of the current abuses of the Internet originating in China are due to a lack of enforcement against criminal activities by the Chinese government," said Go Daddy Group Inc general counsel, Christine Jones.

She said GoDaddy had repelled dozens of extremely serious attacks that appear to have originated in China in the first three months of 2010.

Jones said GoDaddy, based in Scottsdale, Arizona, would continue to manage .cn domain names of existing customers.

"Our experience has been that China is focused on using the Internet to monitor and control the legitimate activities of its citizens, rather than penalizing those who commit Internet-related crimes," Jones said.

Google said in January that it had sustained a hacking attack that it said originated in China. This week Google shut its Chinese portal over censorship and said it planned to phase out deals to provide filtered search services to other online or mobile firms in China.

Google said visitors to its China search engine, google.cn, were being redirected to Hong Kong-based google.com.hk.

"I compliment Google and I compliment GoDaddy," said Democratic Senator Byron Dorgan, chairman of the Congressional-Executive Commission on China, which focuses on human rights in China.

Republican Representative Chris Smith said GoDaddy's action was "a powerful sign that American IT companies want to do the right thing in repressive countries."

Google told the commission it was seeing intermittent censorship of some Internet queries from mainland China that had been rerouted to Hong Kong.

"We are well aware that the Chinese government can, at any time, block access to our services," said Google's director of public policy, Alan Davidson.

"Indeed we have already seen intermittent censorship of certain search queries on both google.com.hk and google.com."

Internet censorship has drawn increased attention from U.S. lawmakers since Google's spat with China began and a policy initiative by US Secretary of State Hillary Clinton to promote global Internet freedom.

"This is a foreign policy priority of the United States," said Democratic Senator Ted Kaufman, co-chair of the Senate's newly formed Global Internet Freedom Caucus.

Friday, March 5, 2010

Cyber terrorism AFCOM , RSA Conference 2010

Data centers tackling cyber terrorism

Typical IT shop unprepared, AFCOM says By Jon Brodkin, Network World

The data center is receiving more public scrutiny than ever before, with IT managers facing a range of challenges from making systems run more efficiently to protecting computers from cyber terrorism, says AFCOM chief executive Jill Eckhaus

The 30-year-old organization for data center managers is holding its twice-yearly Data Center World show from March 7-11 in Nashville, Tenn., where IT folks will learn about the most pressing issues facing data centers today and share their own experiences.

Gov't builds secret database to fight cyber-terrorism

Cyber terrorism is one of the topics Eckhaus is looking forward to examining further. AFCOM’s recent survey of more than 400 data center pros found that only one-third have included cyber terrorism in disaster recovery plans, only one-quarter have addressed cyber terrorism in policies and procedures manuals, and only one-fifth provide cyber terrorism employee training. These low numbers were recorded despite the fact that 61% of data center managers said they recognize cyber terrorism as a threat they need to address.

No data center manager is likely to ignore security, but AFCOM officials say they need to recognize that cyber terror poses a more serious threat than a typical hacker.

“A hacker might be a student just looking for a challenge,” Eckhaus says. “Cyber terrorists want to destroy the United States. That’s the difference.”

AFCOM will host two sessions on cyber terrorism during the conference. Unfortunately, in a bad economy companies that already have security plans “tend to say what we have is good enough,” Eckhaus says. “They’re really at the very beginning stages.”

Even beyond security, public scrutiny of data centers seems to be increasing, as the 24/7 business world expects computer systems that never fail or slow down. Eckhaus says this is both good and bad for data center managers, because the public is recognizing the important work they do, but also demanding more.

“This is a really unique time, because for the first time in history the data center is in the public eye,” Eckhaus says. “People are starting to understand how vital data centers are. We could not do business as usual without data centers.”

Corporate management is demanding that data centers run more efficiently, both to save money on power costs and to appear environmentally friendly in the public eye, Echuas notes. Going green is important, in part because providing enough power and cooling to data centers is becoming more difficult, she says. But the IT industry is “saturating” data center managers with the green buzzword, she says.

“It’s a buzzword that’s been around for a few years, because the data center sucks up so much energy,” Eckhaus says. “Corporate management is really looking down at the data center now and saying ‘what are you going to do.’”

Even as data centers strive to reduce power consumption, they must deal with the reality that demand for information services is growing. Storage needs are booming, as is global Internet traffic and use of mobile Internet devices, says Brian Lillie, who is CIO of co-location provider Equinix and the keynote speaker at the Data Center World conference.


FBI Director Promises Privacy, Information About Attacks To Breach Victim Organizations

Robert Mueller tells attendees FBI 'cannot act' if businesses don't report cyberattacks

Mar 05, 2010 | 07:55 AM

By Kelly Jackson Higgins
DarkReading

SAN FRANCISCO -- RSA Conference 2010 -- Organizations are typically hesitant to disclose cyberattacks to the FBI, and their disclosure is "the exception, not the rule," FBI director Robert Mueller told attendees here today in a keynote address.

Mueller said the bureau understands organizations' concerns about privacy and image when it comes to deciding whether to report a cyberattack to the authorities, but promised the FBI would provide more information-sharing and protection of victim organizations' privacy.

"We do not want you to feel victimized a second time by an investigation. And we know that putting on raid jackets, courting the media, and shutting down your systems is not the best way to get the job done," he said. "We will minimize the disruption to your business. We will safeguard your privacy and your data. Where necessary, we will seek protective orders to preserve trade secrets and business confidentiality. And we will share with you what we can, as quickly as we can, about the means and methods of attack."

Mueller cited a recent partnership between the financial industry and the FBI to put together an intelligence report on threats in banking transactions. "We shared that report with more than 4,000 partners. Together we worked to limit the breadth and scope of this potential threat, and we closed the door to countless hackers," Mueller said. He did not provide any details on the threats or the report.

Meanwhile, the threat of cyberterrorism is "real and rapidly expanding," Mueller said. "To date, terrorists have not used the Internet to launch a full-scale cyberattack. But they have executed numerous denial-of-service attacks. And they have defaced numerous Websites, including Congress' Website following President Obama's State of the Union speech," he said, referring to the so-called Iranian Cyber Army hacking group.

"We in the FBI, with our partners in the intelligence community, believe the cyber terrorism threat is real, and it is rapidly expanding. Terrorists have shown a clear interest in pursuing hacking skills. And they will either train their own recruits or hire outsiders, with an eye toward combining physical attacks with cyberattacks."

Targeted attacks for intelligence and espionage are also a major threat, according to Mueller. He noted that intelligence-gathering efforts by hackers to grab "seemingly innocuous" data about a company can provide them a foot in the door into the company's network.

These targeted attacks have resulted in the loss and corruption of victims' data. "We are concerned with the integrity of your source code. If hackers made subtle, undetected changes to your code, they would have a permanent window into everything you do," he said.

The FBI and other law enforcement officials are currently reverse-engineering botnets with plans to knock them offline: Most recently, the collaborative effort resulted in the takedown of the Mariposa botnet.

Mueller said the FBI has special agents "embedded" with law enforcement in Romania, Estonia, and other countries to help coordinate cybercrime investigations. "Together we are making progress. Last October we worked with Egyptian authorities to dismantle a computer-intrusion and money-laundering scheme operating in the United States and Egypt," he said.