Cyberwarfare

Cyberwarfare raises issues of growing national interest and concern.

Cyberwarfare can be used to describe various aspects of defending and attacking information and computer networks in cyberspace, as well as denying an adversary’s ability to do the same. Some major problems encountered with cyber attacks, in particular, are the difficulty in determining the origin and nature of the attack and in assessing the damage incurred.

A number of nations are incorporating cyberwarfare as a new part of their military doctrine. Some that have discussed the subject more openly include the United Kingdom, France, Germany, Russia, and China. Many of these are developing views toward the use of cyberwarfare that differ from those of the United States, and in some cases might represent national security threats.

Cyberterrorism is also an issue of growing national interest. Many believe terrorists plan to disrupt the Internet or critical infrastructures such as transportation, communications, or banking and finance. It does seem clear that terrorists use the Internet to conduct the business of terrorism, but on closer inspection, however, it is not clear how or whether terrorists could use violence through the Internet to achieve political objectives.

Although the U.S. government is striving to consolidate responsibility for and focus more attention on cyberwarfare issues, it is not clear how successful those efforts will be. Congress may choose to examine critically the policies, organization, and legal framework that guides executive ranch decisionmaking on issues of cyberwarfare.

Friday, March 26, 2010

I'm a nice hacker peeping at the accounts of President Barack Obama

Suspected Twitter infiltrator: 'I'm a nice hacker'

By ANGELA DOLAND (AP) – 23 hours ago

PARIS — He's unemployed and isn't much of a computer expert. The Frenchman accused of infiltrating Twitter and peeping at the accounts of President Barack Obama and singers Britney Spears and Lily Allen says he wanted to reveal just how vulnerable online data systems are to break-ins — and he says he didn't mean any harm.

"I'm a nice hacker," suspect Francois Cousteix told France 3 television Thursday, a day after he was released from police questioning, adding that his goal was to warn Internet users about data security.

"Hacker Croll," as he was known online, is accused of breaking into Twitter administrators' accounts and copying confidential data — as well as peeping at Obama's and the singers' accounts, though he didn't have access to sensitive information about them, a French prosecutor said.

FBI agents sat in on the sessions while French police questioned the young man for two days, said Jean-Yves Coquillat, prosecutor in Clermont-Ferrand, where the suspect will be tried in June for hacking.

If convicted on the charge of breaking into a data system, he risks up to two years in prison and a euro30,000 ($40,068) fine. The suspect lives near Clermont-Ferrand in central France.

"He says it's the challenge, the game, that made him do it," Coquillat said. Officials say preliminary investigations suggest Hacker Croll did not tweet in other peoples' names or try to make money out of his information.

"He had access to elements that were so confidential that he could very well have profited from them" through blackmail, for example, said Adeline Champagnat of the French police office on information technology crimes.

She compared the hacker's actions to "a burglar breaking into the headquarters of a big company, able to look at the files of the all employees and clients, with their passwords and confidential information."

"In a way, he succeeded in taking control of Twitter," Champagnat said.

Twitter, based in San Francisco, declined to comment on the case Thursday.

At one point, Champagnat said, the hacker attempted to find a password for Obama's account but didn't follow through with it. With administrator access, "he didn't even need" Obama's password, she said — but hacking into the president's account wasn't his goal.

Cousteix, who was identified as being 23 or 24, said he just wanted to prove a point about Internet security.

"It's a message I wanted to get out to Internet users, to show them that no system is invulnerable," he told France 3 television.

Hacker Croll confessed to the hacking under questioning, and analysis of his computer backs up his statements, police and the prosecutor said.

The suspect, who lives with his parents and has no college degree, didn't have any special computer training, the prosecutor said.

His technique was to get administrators' e-mail passwords' reset by correctly answering their security questions using information about his prey that he gathered from blogs and other public sites, officials said.

Twitter said in July that it was the victim of a security breach. Co-founder Biz Stone wrote at the time that the personal e-mail of an unnamed Twitter administrative employee was hacked, and through that the attacker got access to the employee's Google Apps account.

The French prosecutor said the suspect infiltrated the accounts of "several" Twitter administrative employees. He was able to access information such as contracts with partners and resumes from job applicants, Coquillat said.

Hacker Croll e-mailed some of the documents to TechCrunch, a widely read technology blog, and it subsequently published some of them, including financial projections. The material was also published on several French sites.

Some of the material was more embarrassing than damaging, like floor plans for new office space and a pitch for a Twitter TV show.

Using the administrator logins, Hacker Croll looked at Twitter details of Obama, Allen, Spears and other well-known personalities and was able to see information such as IP addresses, when they were last connected and when they signed up, French officials said.

Twitter's equivalent of an elusive masked bandit was caught in France this week, according to an Agence France-Presse story citing police sources, after the FBI began working with authorities there. A 25-year-old who goes by the name "Hacker Croll," believed to be responsible for two high-profile Twitter hacking incidents in which both celebrity accounts and internal servers were breached, was reportedly in police custody in the French city of Clermont-Ferrand before being released later on Wednesday.

The hacker was allegedly behind an attack about a year ago in which the Twitter accounts of celebrities ranging from Britney Spears to President Obama were breached; he gained access to a Twitter administrator's password by hacking that administrator's Yahoo Mail account first. (Another, similar incident involving celebrity Twitter accounts had taken place several months prior, also after a sabotage on a weak password; an 18-year-old hacker named "GMZ" claimed responsibility.)

It's also likely that the hacker arrested in France was responsible for an internal Twitter security breach that gave him access to hundreds of sensitive company documents--which he then turned over to industry blog TechCrunch. The TechCrunch incident wasn't mentioned in the AFP story, but since the name "Hacker Croll" was associated with that one, too, it's likely that the same person was responsible.

The hacker, whom AFP reports is unemployed and lives with his parents, appears to have told police what he did to sabotage Twitter's servers and was then released with a court date set for June 24. He was already on authorities' radar for some minor online scam activity, and allegedly has also targeted Facebook and Gmail--though has never attempted to profit financially from his hijinks

Obama's Alleged Twitter Hacker Guessed Passwords
By Jennifer LeClaire
March 25, 2010 1:30PM

Bookmark and Share
A 24-year-old Frenchman who allegedly hacked Twitter accounts of President Obama and other celebrities has been arrested. French police said Francois Cousteix acted on a bet, and he told a TV station, "I'm a nice hacker." Cousteix may also be involved in other Facebook and Twitter hacks, and he could face years in prison instead of a security job.

Related Topics

Hacker
Twitter
Obama
Facebook
Security

Latest News
New Measures Target Port Pollution
Former Priest Wins Templeton Prize
A Third of Breast Cancer Is Avoidable
New Dinosaur Species Discovered
GM Goes Green with EN-V Concept Car

On Thursday, French police arrested a man who allegedly hacked into celebrity Twitter accounts in the United States. Among his victims was President Barack Obama.

French authorities described the hacker as a 24-year-old Frenchman. Rather than revealing his true identity, police are publicly calling him "Hacker Croll," a pseudonym the hacker used during his criminal activities. However, the Associated Press has identified him as Francois Cousteix.

"He was a young man spending time on the Internet," French prosecutor Jean-Yves Coquillat told London's Telegraph newspaper. "He acted as a result of a bet, out of the arrogance of the hacker. He is the type who likes to claim responsibility for what he has done."

Easy as 1, 2, 3?

Cousteix allegedly accessed Obama's Twitter page, as well as the Twitter pages of famous people like Britney Spears and Lily Allen, by guessing passwords, according to French police.

Whether Cousteix obtained any sensitive information from the president's micro-blog was not disclosed. However, news reports put Cousteix on the scene of the crime of dozens of Facebook and Twitter account hacks. Cousteix could spend up to two years in prison on each count of hacking if convicted.

"For a long time, when people got caught for doing this stuff, they got some kind of lucrative security Relevant Products/Services job," said Rob Enderle, principal analyst at the Enderle Group. "Nowadays companies realize that providing incentives to people who are hacking this stuff wasn't a wise thing to do."

Although French authorities took the lead on the investigation, they reportedly relied on the Federal Bureau of Investigation to monitor Cousteix's online activities. The FBI also reportedly took part in the arrest of the hacker.

No System is Invulnerable

Cousteix has admitted to hacking. "I'm a nice hacker ... It's a message I wanted to get out to Internet users, to show them that no system Relevant Products/Services is invulnerable," Cousteix told France 3 television on Thursday. He had been released from police questioning on Wednesday.

Cousteix also leaked some internal Twitter documents to web sites, including TechCrunch in July. At that time, Twitter cofounder Biz Stone said he thought the hacker was able to access an employee's Google Apps account, which contained Docs, Calendars and other Google apps Twitter relies on for sharing notes, spreadsheets, ideas, financial details, and more within the company.

Stone also stressed that the stolen documents downloaded and offered to various blogs and publications were not Twitter user accounts, nor were any user accounts compromised, except a screenshot of one person's account. In that case, Twitter contacted the user and recommended a password change.

"We'll wee what happens, but I have a feeling that hacking into the U.S. president's Twitter account is not something that's going to result in a pat on the head and a lucrative job," Enderle said. "But the hacker is right. It does show that these social networks are fairly vulnerable. Then again, they are also pretty public. The value of stealing somebody's Twitter account is relatively low unless you use that to run a scam."

Thursday, March 18, 2010

Federal Communications Commission wider cybersecurity role

Broadband plan gives FCC wider cybersecurity role
Plan calls for securing communications networks against cyberthreats
http://ceoworld.biz/ceo/wp-content/uploads/2009/09/US-FCC-Seal.svg.png

By Jaikumar Vijayan

Click on the link for the 360-page broadband plan.
The National Broadband Plan released by the Federal Communications Commission this week contains several recommendations that are designed to boost the preparedness of communications networks to deal with cyberthreats.

The plan gives the FCC a greatly enhanced role in developing and promoting cybersecurity measures and calls for closer cooperation between the FCC and the U.S. Department of Homeland Security on security matters.

The 360-page broadband plan is a blueprint for modernizing the country's aging communications networks and for delivering broadband services to a majority of U.S. homes over the next decade. It contains six long-term policy goals and other recommendations for ensuring the availability of affordable 100Mbit/sec. service to 100 million U.S. homes, and 1Gbit/sec. service to institutions such as hospitals and schools, by 2020.

While a vast majority of the recommendations deal with building out the communications infrastructure, several touch on cybersecurity and communications networks' ability to survive a cyberattack.

One key recommendation calls on the FCC to develop a cybersecurity "road map" in collaboration with the executive branch. The recommendation gives the FCC 180 days to identify the top five cyberthreats facing the communications infrastructure and to come up with a two-year plan for addressing those threats.

The plan also requires the FCC to enhance its network outage reporting requirements for broadband service providers. The "timely and disciplined" reporting of network outages will help the FCC better understand the causes of cyberattacks and develop more effective responses to them.

One recommendation calls for the FCC and the DHS to collaborate on a cybersecurity information reporting system (CRIS). Currently, the FCC, others government agencies and Internet service providers lack the "situational awareness" needed to identify and respond in a coordinated fashion to large-scale cyberattacks, the plan noted. The FCC and the DHS need to develop an IP network CRIS that would quickly disseminate information to providers about unfolding cyberattacks. The CRIS should be a real-time, voluntary threat-monitoring system, with the FCC acting as a "trusted facilitator" to ensure reciprocal information-sharing among participants in the system, the plan states.

The FCC and the National Communications System will also work on creating priority network access and routing capabilities for broadband users in law enforcement and public safety roles. The goal is to ensure that critical, "time-sensitive, safety-of-life information" does not get lost or delayed because of network congestion issues.

The plan also directs the FCC to explore network resilience and preparedness to deal with simultaneous failure or damage to major network components and facilities. As part of the effort, the agency will examine the ability of commercial networks to withstand major traffic overloads that might result from a bioterrorism attack or a pandemic

The recommendations reflect concern over the perceived susceptibility of U.S. critical infrastructure targets to major cyberattacks. The broadband document refers specifically to the recent attacks on Google and several oil companies as examples of the sort of threats facing the U.S. government and industry. Private sector networks in the U.S. "have been a major target for attacks," the document noted.

"Despite the significant resources that the private sector devotes to cybersecurity, there have been a number of successful attacks on its networks," the document stated, calling for sufficient defenses to protect networks against them.

The Cybersecurity Act, S. 773

Cybersecurity Bill Trims President's Power
Current version of Senate legislation eliminates provision that permitted the president to shut down the Internet in the event of a major cyber attack.

Elizabeth Montalbano
http://www.howtoarchives.com/wp-content/uploads/2009/07/cyber-security-defense.jpg

The Senate Wednesday re-introduced a cybersecurity bill it considered last year, minus a provision that would have allowed the president to shut down the Internet in the event of a major cyber attack.

The Cybersecurity Act, S. 773, co-sponsored by Senators Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine), is aimed at protecting critical U.S. network infrastructure against cybersecurity threats by fostering collaboration between the federal government and the private sectors that maintain that infrastructure.

The legislation was originally introduced last April in a two-bill package that together called for the creation of a national cybersecurity adviser, as well as aimed to revise cybersecurity processes and oversight in government, facilitate public-private partnerships on keeping computer systems safe, fund cybersecurity research, and encourage the hiring of more cybersecurity specialists.

Companion legislation that would create the national cybersecurity adviser position -- the National Cybersecurity Advisor Act, S.778 -- is still pending before the Senate Committee on Homeland Security and Government Affairs.

The new Cybersecurity Act more or less maintains the goals of the original bill, but also has some key differences.

One big one is that it no longer gives the president unilateral power to disconnect networks from the Internet in the event of a major cyber attack.

As written now, the bill requires the president to work with organizations that own critical network infrastructure to come up with cybersecurity emergency response plans rather than take action on his own.

The bill also includes new provisions. One creates a process for the president and those in the private sector that maintain and own critical infrastructure to come together to decide which IT systems are most crucial to national security and how they should be secured.

Another provision requires the president to provide security clearances to some private-sector officials at those organizations so they have access to classified cyber-threat information they wouldn't otherwise be privy to.

Cybersecurity is a major priority for the Obama Administration, which requested $866 million to protect networks and data in its recently announced fiscal 2011 budget.

Though that figure is slightly less than what was allocated in 2010, officials maintain cybersecurity remains top of mind for the administration, a sentiment reflected in the reintroduction of the Senate bill and other recent government actions.

The House last month passed its own cybersecurity bill, the Cybersecurity Enhancement Act of 2009 (HR 4061), first introduced by Rep. Daniel Lipinski (D-IL) last year.

That bill, though not as broad in scope as the Senate bill, funds research and development for a comprehensive cybersecurity plan that would involve the cooperation of several federal agencies.

The Department of Homeland Security also is taking steps to foster better communication between government intelligence officials and private-sector organizations looking after critical networks.

Through a pilot program the DHS recently launched, CIOs and CSOs from state and local governments as well as private-sector organizations will periodically be allowed to access classified intelligence information regarding cyber threats from state and local fusion centers.

Friday, March 5, 2010

Cyber terrorism AFCOM , RSA Conference 2010

Data centers tackling cyber terrorism

Typical IT shop unprepared, AFCOM says By Jon Brodkin, Network World

The data center is receiving more public scrutiny than ever before, with IT managers facing a range of challenges from making systems run more efficiently to protecting computers from cyber terrorism, says AFCOM chief executive Jill Eckhaus

The 30-year-old organization for data center managers is holding its twice-yearly Data Center World show from March 7-11 in Nashville, Tenn., where IT folks will learn about the most pressing issues facing data centers today and share their own experiences.

Gov't builds secret database to fight cyber-terrorism

Cyber terrorism is one of the topics Eckhaus is looking forward to examining further. AFCOM’s recent survey of more than 400 data center pros found that only one-third have included cyber terrorism in disaster recovery plans, only one-quarter have addressed cyber terrorism in policies and procedures manuals, and only one-fifth provide cyber terrorism employee training. These low numbers were recorded despite the fact that 61% of data center managers said they recognize cyber terrorism as a threat they need to address.

No data center manager is likely to ignore security, but AFCOM officials say they need to recognize that cyber terror poses a more serious threat than a typical hacker.

“A hacker might be a student just looking for a challenge,” Eckhaus says. “Cyber terrorists want to destroy the United States. That’s the difference.”

AFCOM will host two sessions on cyber terrorism during the conference. Unfortunately, in a bad economy companies that already have security plans “tend to say what we have is good enough,” Eckhaus says. “They’re really at the very beginning stages.”

Even beyond security, public scrutiny of data centers seems to be increasing, as the 24/7 business world expects computer systems that never fail or slow down. Eckhaus says this is both good and bad for data center managers, because the public is recognizing the important work they do, but also demanding more.

“This is a really unique time, because for the first time in history the data center is in the public eye,” Eckhaus says. “People are starting to understand how vital data centers are. We could not do business as usual without data centers.”

Corporate management is demanding that data centers run more efficiently, both to save money on power costs and to appear environmentally friendly in the public eye, Echuas notes. Going green is important, in part because providing enough power and cooling to data centers is becoming more difficult, she says. But the IT industry is “saturating” data center managers with the green buzzword, she says.

“It’s a buzzword that’s been around for a few years, because the data center sucks up so much energy,” Eckhaus says. “Corporate management is really looking down at the data center now and saying ‘what are you going to do.’”

Even as data centers strive to reduce power consumption, they must deal with the reality that demand for information services is growing. Storage needs are booming, as is global Internet traffic and use of mobile Internet devices, says Brian Lillie, who is CIO of co-location provider Equinix and the keynote speaker at the Data Center World conference.


FBI Director Promises Privacy, Information About Attacks To Breach Victim Organizations

Robert Mueller tells attendees FBI 'cannot act' if businesses don't report cyberattacks

Mar 05, 2010 | 07:55 AM

By Kelly Jackson Higgins
DarkReading

SAN FRANCISCO -- RSA Conference 2010 -- Organizations are typically hesitant to disclose cyberattacks to the FBI, and their disclosure is "the exception, not the rule," FBI director Robert Mueller told attendees here today in a keynote address.

Mueller said the bureau understands organizations' concerns about privacy and image when it comes to deciding whether to report a cyberattack to the authorities, but promised the FBI would provide more information-sharing and protection of victim organizations' privacy.

"We do not want you to feel victimized a second time by an investigation. And we know that putting on raid jackets, courting the media, and shutting down your systems is not the best way to get the job done," he said. "We will minimize the disruption to your business. We will safeguard your privacy and your data. Where necessary, we will seek protective orders to preserve trade secrets and business confidentiality. And we will share with you what we can, as quickly as we can, about the means and methods of attack."

Mueller cited a recent partnership between the financial industry and the FBI to put together an intelligence report on threats in banking transactions. "We shared that report with more than 4,000 partners. Together we worked to limit the breadth and scope of this potential threat, and we closed the door to countless hackers," Mueller said. He did not provide any details on the threats or the report.

Meanwhile, the threat of cyberterrorism is "real and rapidly expanding," Mueller said. "To date, terrorists have not used the Internet to launch a full-scale cyberattack. But they have executed numerous denial-of-service attacks. And they have defaced numerous Websites, including Congress' Website following President Obama's State of the Union speech," he said, referring to the so-called Iranian Cyber Army hacking group.

"We in the FBI, with our partners in the intelligence community, believe the cyber terrorism threat is real, and it is rapidly expanding. Terrorists have shown a clear interest in pursuing hacking skills. And they will either train their own recruits or hire outsiders, with an eye toward combining physical attacks with cyberattacks."

Targeted attacks for intelligence and espionage are also a major threat, according to Mueller. He noted that intelligence-gathering efforts by hackers to grab "seemingly innocuous" data about a company can provide them a foot in the door into the company's network.

These targeted attacks have resulted in the loss and corruption of victims' data. "We are concerned with the integrity of your source code. If hackers made subtle, undetected changes to your code, they would have a permanent window into everything you do," he said.

The FBI and other law enforcement officials are currently reverse-engineering botnets with plans to knock them offline: Most recently, the collaborative effort resulted in the takedown of the Mariposa botnet.

Mueller said the FBI has special agents "embedded" with law enforcement in Romania, Estonia, and other countries to help coordinate cybercrime investigations. "Together we are making progress. Last October we worked with Egyptian authorities to dismantle a computer-intrusion and money-laundering scheme operating in the United States and Egypt," he said.

FBI Wants You For The mobile cyberaction teams

Mueller

to Cybersecurity Experts:

The FBI Wants

You

http://www.friedpost.com/wp-content/uploads/2008/09/fbi.jpg


http://www.technewsworld.com/images/rw998685/cybersecurity.jpg
By Richard Adhikari
TechNewsWorld

The Federal Bureau of Investigation on Thursday joined the Department of Homeland Security in seeking to hire cybersecurity experts from the private sector.

"I want to send out an invitation to those of you in the audience who want to serve the country to join the FBI," FBI Director Robert Mueller said at the RSA Conference 2010 in San Francisco on Thursday.

Mueller also urged the private sector to cooperate with the FBI in fighting cybercrime, as did DHS Secretary Janet Napolitano when she spoke at RSA 2010 on Wednesday.

Taking On More Staff

The FBI has cybersquads in each of its 56 fields nationwide, and more than 1,000 specially trained agents, analysts and digital forensic examiners who run complex undercover operations, share intelligence with partners in law enforcement and intelligence, and provide training to their counterparts around the world, Mueller said.

It also has mobile cyberaction teams -- agents, analysts and experts highly trained in both computer forensics and malicious code -- who travel worldwide to respond to fast-moving cyberthreats.

In addition, it has created and leads the National Cyber Investigative Joint Task Force, which combines 17 law enforcement and intelligence agencies to predict what's on the horizon, to prevent attacks, and to pursue the enterprises responsible for planning them.

http://www.pnl.gov/breakthroughs/issues/2005-issues/fall/images/cyber_security.jpg

The FBI also has small groups of analysts and agents from different agencies who focus on different threats, Mueller said. For example, its botnet fusion focus cell investigates high-priority botnets, reverse engineers those botnets, and searches for their creators.

However, that's not enough; the FBI is seeking to beef up the ranks of its cybersecurity experts.

"We -- both you and I -- serve the American people, and we must do everything we can together to minimize and stop these attacks," Mueller said. Without support from the private sector, law enforcement will find it difficult to fight cybercrime, Mueller said.

"We need your help, so let me emphasize the importance of private sector partnerships," he told his audience.

Mueller pledged that the FBI will minimize disruption to companies that report crimes.

"Historically, there has been a dichotomy between network security and the investigative process," he pointed out. "We in the FBI understand you have practical reasons for being concerned about reporting breaches of security."

The FBI doesn't want enterprises to feel victimized a second time by an investigation, Mueller promised.

"We know that putting on raid jackets, courting the media, and shutting down your operations does not get the job done," he said, echoing what he said in 2005 when he complained about the reluctance of the private sector to report cybercrime. "For every investigation in the news, there are hundreds that never make the headlines. Disclosure is the exception, not the rule."

Private enterprises have been reluctant to report cyberattacks for fear that investigations will hurt their operations, a fact acknowledged by the U.S. Department of Justice and other law enforcement agencies.

"We will share with you what we can as quickly as we can about the means and the methods of the attacks," Mueller said, "but we cannot act if we are not aware of the problem, and maintaining a code of silence will not help you or your clients in the long run."

http://www.wpimg.com/pk/landing/cyber_landing.jpg

For example, the FBI managed to crack a crime ring that stole millions of dollars from more than 280 cities worldwide within 24 hours by using fake ATM cards because the company in question reported the crime, Mueller said.

"In 24 hours, the attackers stole hundreds of millions of dollars in more than 280 cities worldwide," Mueller told his audience. "If the company hadn't come forward, we could not have prevented these hackers from hitting their next victim."

The top three hackers behind this attack are now in custody in eastern Europe, Mueller said.

A New World Cybersecurity Order

Fighting cybercrime effectively requires international cooperation among nations and law enforcement, Mueller pointed out. "Today, no one country, no one company, no one agency can stop cybercrime," he explained. "We see borders as obstacles, whereas criminals see them as opportunities."

Cybercriminal gangs cooperate easily across national borders, while law enforcement agencies cannot because of jurisdictional and legal issues and other differences. Some countries also protect well-connected cybercriminals.

The FBI has more than 60 attachés based in nations around the globe who share information and intelligence with their host countries, Mueller pointed out.

Cooperation between the FBI and Spanish authorities helped crack the Mariposa botnet and take down the three men behind it.

"This case, like so many others, emphasizes the need for global cooperation," Mueller said.

The FBI has also cooperated with Egyptian authorities to dismantle an intrusion and money-laundering scheme, and with German and other authorities to dismantle "Dark Market," one of the largest underground markets for stolen cyberinformation.

"Together we must work towards an international standard for dealing with cybercrime," Mueller said. "We're playing the cyberequivalent of cat and mouse, and the mouse seems to be one step ahead most of the time."

Wednesday, January 20, 2010

F.U.D (fear, uncertainty, and doubt)




In the above “60 Minutes” video, correspondent Steve Kroft spoke with former and current US government officials and private-sector security about the nation’s vulnerability to cyber attack.

“If I were an attacker and I wanted to do strategic damage to the United States, I would either take the cold of winter or the heat of summer, I probably would sack electric power on the U.S. East Cost, maybe the West Coast, and attempt to cause a cascading effect. All of those things are in the art of the possible from a sophisticated attacker,” Retired Admiral Mike McConnell told Kroft.

To most IT professionals, this revelation isn’t, or at least shouldn’t be, news. Before joining TechRepublic 10 years ago, I worked for a regulated utility–a power company. Even then, before anyone was seriously pushing a “smart grid” we were keenly aware of digital threats to our organization. But, just because IT is aware of a threat, doesn’t mean the business is dedicated to addressing those threats. Corporate management is usually most focused on maximizing profit. (I am not referring to my former employer, but making a general statement about the disconnect that often occurs between IT staff and corporate leadership.)

In fact, this disconnect isn’t confined to IT or even the corporate world. Whenever you have individuals or groups with different and/or competing interests, disconnects are common. Yet it is IT’s job to help protect the organization from cyber threats, and in many cases the stakes are too high to allow a communication gap, lack of understanding, or just pure apathy to prevent good security.

Part of IT’s security mission must therefore be to educate the greater community about relevant security threats and convince them to take or approve the necessary countermeasures. It’s the second goal that’s often the most difficult. Even your best descriptions of DoS attacks, rootkits, SQL injection attacks, social engineering, and all the other threats we face can fall on deaf ears unless you impress upon your audience the consequences of inaction. This is when fear can help.
Fear does not equal F.U.D (fear, uncertainty, and doubt)

Whether you’re trying to convince senior management to ban USB drives or your three-year old not to touch the stove, fear is a powerful motivator. Yet, fear is a double-edged sword. If used inappropriately fear will win you more enemies than supporters and can undermine your ultimate goal of improved security. Therefore, I recommend the following guidelines:

1. Avoid the hype. Be truthful and realistic. Don’t make outlandish or unsubstantiated claims of IT destruction and massive financial loss, if the threats you’re discussing aren’t likely to cause such outcomes. Present the threat as you understand it, explain the likelihood of occurrence, and describe your organization’s level of exposure.
2. Temper fear with solutions. Once you’ve explained a threat, follow up with your best recommendations on how to mitigate it. You’re goal is to motivate the audience into changing their behavior or giving their approval for an action, not merely to scare them. And, don’t come in with an all or nothing plan. Be prepared to offer a range of mitigation options, which vary in scope and cost.
3. Don’t overuse fear. Remember the tale of the boy who cried wolf? If you constantly predict IT catastrophes that never materialize, your audience will eventually stop listening to you.
4. Focus on an audience who can act. Narrowly target your message to those who can address the threat or have significant influence of those who can. Inducing fear in those who can’t benefit from point 2 is counterproductive.

Is fear effective?

Yet, not everyone agrees that fear is an effective motivator. In April 2009, I published a ZDNet video on the possibility of a digital Pearl Harbor event. On the video, Bruce Schneier, noted cryptographer and Chief Security Technology Officer of BT Counterpane, suggests IT is better off avoiding fear as a motivator. “We’re better as an industry, if we don’t stoke fear, if we don’t talk about the digital Pearl Harbor. People turn off from that,” Schneier said.

I agree with Schneier’s statement that IT shouldn’t “stoke” people’s fears unnecessarily–see all my above points. But, I still think a little fear can be a powerful motivator. And remember, all fear isn’t created equal. Rationally explaining the negative consequences of not upgrading your network’s intrusion detection system is a far cry yelling fire in a crowded theater. What do you think?

War Against Computer

Companies Fight

Endless War Against

Computer Attacks


http://wwwimage.cbsnews.com/images/2005/05/31/image698632x.jpg
Published: January 17, 2010

The recent computer attacks on the mighty Google left every corporate network in the world looking a little less safe.

"Fighting computer crime is a balance of technology and behavioral science,” said Edward M. Stroz, a former agent with the F.B.I.

Google’s confrontation with China — over government censorship in general and specific attacks on its systems — is an exceptional case, of course, extending to human rights and international politics as well as high-tech spying. But the intrusion into Google’s computers and related attacks from within China on some 30 other companies point to the rising sophistication of such assaults and the vulnerability of even the best defenses, security experts say.

“The Google case shines a bright light on what can be done in terms of spying and getting into corporate networks,” said Edward M. Stroz, a former high-tech crime agent with the F.B.I. who now heads a computer security investigation firm in New York.

Computer security is an ever-escalating competition between so-called black-hat attackers and white-hat defenders. One of the attackers’ main tools is malicious software, known as malware, which has steadily evolved in recent years. Malware was once mainly viruses and worms, digital pests that gummed up and sometimes damaged personal computers and networks.

Malware today, however, is likely to be more subtle and selective, nesting inside corporate networks. And it can be a tool for industrial espionage, transmitting digital copies of trade secrets, customer lists, future plans and contracts.

Corporations and government agencies spend billions of dollars a year on specialized security software to detect and combat malware. Still, the black hats seem to be gaining the upper hand.

In a survey of 443 companies and government agencies published last month, the Computer Security Institute found that 64 percent reported malware infections, up from 50 percent the previous year. The financial loss from security breaches was $234,000 on average for each organization.

“Malware is a huge problem, and becoming a bigger one,” said Robert Richardson, director of the institute, a research and training organization. “And now the game is much more about getting a foothold in the network, for spying.”

Security experts say employee awareness and training are a crucial defense. Often, malware infections are a result of high-tech twists on old-fashioned cons. One scam, for example, involves small U.S.B. flash drives, left in a company parking lot, adorned with the company logo. Curious employees pick them up, put them in their computers and open what looks like an innocuous document. In fact, once run, it is software that collects passwords and other confidential information on a user’s computer and sends it to the attackers. More advanced malware can allow an outsider to completely take over the PC and, from there, explore a company’s network.

With this approach, the hackers do not need to break through a company’s network defenses because a worker has unknowingly invited them inside.

Another approach, one used in the Google attacks, is a variation on so-called phishing schemes, in which an e-mail message purporting to be from the recipient’s bank or another institution tricks the person into giving up passwords. Scammers send such messages to thousands of people in hopes of ensnaring a few. But with so-called spear-phishing, the bogus e-mail is sent to a specific person and appears to come from a friend or colleague inside that person’s company, making it far more believable. Again, an attached file, once opened, unleashes the spy software.

Other techniques for going inside companies involve exploiting weaknesses in Web-site or network-routing software, using those openings as gateways for malware.

To combat leaks of confidential information, network security software looks for anomalies in network traffic — large files and rapid rates of data transmission, especially coming from corporate locations where confidential information is housed.

“Fighting computer crime is a balance of technology and behavioral science, understanding the human dimension of the threat,” said Mr. Stroz, the former F.B.I. agent and security investigator. “There is no law in the books that will ever throw a computer in prison.”

As cellphones become more powerful, they offer new terrain for malware to exploit in new ways. Recently, security experts have started seeing malware that surreptitiously switches on a cellphone’s microphone and camera. “It turns a smartphone into a surveillance device,” said Mark D. Rasch, a computer security consultant in Bethesda, Md., who formerly prosecuted computer crime for the Justice Department.

Hacked cellphones, Mr. Rasch said, can also provide vital corporate intelligence because they can disclose their location. The whereabouts of a cellphone belonging to an investment banker who is representing a company in merger talks, he said, could provide telling clues to rival bidders, for example.

Security experts say the ideal approach is to carefully identify a corporation’s most valuable intellectual property and data, and place it on a separate computer network not linked to the Internet, leaving a so-called air gap.

“Sometimes the cheapest and best security solution is to lock the door and don’t connect,” said James P. Litchko, a former government security official who is a manager at Cyber Security Professionals, a consulting firm.

Some companies go further, building “Faraday cages” to house their most critical computers and data. These cages typically have a metal grid structure built into the walls, so no electromagnetic or cellphone transmissions can come in or out. Defense contractors, aerospace companies and some automakers have built Faraday cages, named for the 19th-century English scientist Michael Faraday, who designed them to shield electrical devices from lightning and other shocks.

But in the Internet era, isolationism is often an impractical approach for many companies. Sharing information and knowledge with industry partners and customers is seen as the path to greater flexibility and efficiency. Work is routinely done by far-flung project teams. Mobile professionals want vital company data to be accessible wherever they are.

Most of that collaboration and communication is done over the Internet, increasing the risk of outside attacks. And the ubiquity of Internet access inside companies has its own risks. In a case of alleged industrial theft that became public recently, a software engineer at Goldman Sachs was accused last year of stealing proprietary software used in high-speed trading, just before he left for another firm. The engineer, who pleaded not guilty, had uploaded the software to a server computer in Germany, prosecutors say.

The complexity of software code from different suppliers, as it intermingles in corporate networks and across the Internet, also opens the door to security weaknesses that malware writers exploit. One quip among computer security experts is: “The sum of the parts is a hole.”

But, security experts say, the problem goes well beyond different kinds of software not playing well together. The software products themselves, they say, are riddled with vulnerabilities — thousands of such flaws are detected each year across the industry. Several weaknesses, it seems, including one in the Microsoft Internet Explorer browser, were exploited in the recent attacks on Google that were aimed at Chinese dissidents.

The long-term answer, some experts assert, lies in setting the software business on a path to becoming a mature industry, with standards, defined responsibilities and liability for security gaps, guided by forceful self-regulation or by the government.

Just as the government eventually stepped in to mandate seat belts in cars and safety standards for aircraft, says James A. Lewis, a computer security expert at the Center for Strategic and International Studies, the time has come for software.

Mr. Lewis, who advised the Obama administration about online security last spring, recalled that he served on a White House advisory group on secure public networks in 1996. At the time, he recommended a hands-off approach, assuming that market incentives for the participants would deliver Internet security.

Today, Mr. Lewis says he was mistaken. “It’s a classic market failure — the market hasn’t delivered security,” he said. “Our economy has become so dependent on this fabulous technology — the Internet — but it’s not safe. And that’s an issue we’ll have to wrestle with.”