Showing posts with label EU. Show all posts
Showing posts with label EU. Show all posts

Tuesday, March 31, 2009

Intercept Modernisation Programme to Include Social Networks

Following the implementation of the EU Data Retention Directive requiring member states to retain communication traffic information for law enforcement, the U.K. developed the "Intercept Modernisation Programme".
"The Home Office already has plans to log details of all phone calls, emails and websites visited by web users in the UK, as part of a grander scheme, a massive "mother of all databases" under the "Intercept Modernisation Programme" umbrella."
The Home Office is now looking at expanding beyond the EU Directive to include communications between users of social networking sites such as Facebook and Twitter:
"The Home Office minister Vernon Coaker told MPs that the fact that the EU Data Retention Directive lacks some features is "why the Government is looking at what we should do about the intercept modernisation programme because there are certain aspects of communications which are not covered by the directive."
This, of course, is stirring a significant debate on civil liberties. However, when investigating large-scale crimes involving the Internet (and especially international activity), traffic analysis of communications is probably the single best investigative tool available and this is one of the arguments put forth by proponents of the activity:
"The government said that it will not be interested in what is being discussed but rather who talks to whom online, something that the government says is vital in preventing criminals and terrorists' communicating facilities."


As an aside:

The keywords "Intercept Modernisation Programme" generates more traffic to this blog than any other so I'm always interested in performing traffic analysis on the spike after an article on the subject is posted. Historically, over 80% of traffic can be traced to U.K. defense or other governmental contractors.

UK Government Plans To Monitor Social Networking Websites


Social network sites 'monitored'

Friday, February 13, 2009

Recommended: Detailed Report on the State of Network and Information Security in Europe

For anyone that deals with cyber security issues in Europe, it is always a challenge to keep up on each member country's initiatives, institutions and regulations. A new report looks to be a valuable resource in navigating the complex European environment.

The European Network and Information Security Agency (ENISA) has published an extensive (over 600 pages) report on network and information security in its 30 member countries (the 27 EU member countries plus 3 members of the European Economic Community). This report is an excellent who's who of cyber security in Europe.

The report is structured by country and provided details of cyber security activities including:
  • General country information including statistics on IT use;
  • The major governmental and private stakeholders that set and implement cyber security policies and their relationships;
  • An overview and detailed look at current initiatives, focus points and activities of each entity;
  • Cyber security events taking place in each country;
  • Cyber security trends including information on security breaches
An excellent reference on the state of cyber security in Europe. Let's hope they plan to keep in updated.

ENISA Country Reports

Wednesday, February 04, 2009

Europe Needs More Work on Cyber Defense

Trend News in Azerbaijan is reporting on a German DPA interview with Estonia's Minister of Defense concerning European readiness to defend against cyber attacks:

"For the time being, Europe's capability to defend itself from cyber-attacks is on the level of some of the capabilities of member states. Little value-added on the European level has been developed: we need to do more," he [Estonian Defence Minister Jaak Aaviksoo] said.

"In particular, the 27-member bloc must work harder to coordinate the efforts of various national defence and law-enforcement agencies and push for better cooperation with third countries which can serve as a safe haven for web-based attackers, he said."

Minister: Europe has not yet done enough on cyber-defence

Friday, October 03, 2008

Study of Terrorist Recruitment in Europe and Use of the Internet

King’s College London has published an in-depth study of jihadist recruitment and mobilization for the European Commission. The paper provides an extensive background and history of terrorist recruitment that started in local mosques and moved to prisons and the Internet. It also discusses the psychological processes and rationalizations involved in recruitment.

The basic structure of online terrorist communications is provided:
"Despite the impression of anarchy, the ‘architecture’ of the Islamist militant Internet presence is relatively straightforward. First, there are the official web sites, representing clerics, strategists, or Islamist militant organisations. They are very unstable, but they are often well run and may contain downloadable videos, communiqués, discussion papers and religious rulings, and frequently also provide opportunities for interaction with leading personalities. Second, there are the web forums which are mostly administered and populated by grassroots supporters. The web forums are the soap boxes of the Islamist militant movement, where key debates about the latest news take place, networks are formed, and a real sense of community emerges. Often password-protected, they are also used to exchange videos, training material, and links to other web sites. The third element of the Islamist militant Internet architecture are so-called distributor sites, which include ‘jihadist’ web directories, ‘tribute’ sites, and the web pages of so-called ‘media groups’. These sites sustain the infrastructure of the Islamist militant web presence, as they distribute ‘jihadist’ material and provide updated links on where to locate official sites and web forums. Web forums can also perform the function of distributor site."

The researchers describe two elements of terrorist activity on the Internet:
  1. Internet supported recruitment; and,
  2. Virtual self recruitment
These elements can be summarized as follows:
"The Internet has come to play an increasingly important role. The main function is to support ‘real-world’ recruitment (by reinforcing religious and political themes; by facilitating networking; and by creating a climate of exaggeration). In recent years, however, new forms of Islamist militant online activism have emerged, which rely less on human contact and can be described as ‘virtual self-recruitment’."

The paper makes clear that the Internet has not replaced the human element in the recruiting process:
"Realworld social relationships continue to be pivotal in recruitment, therefore, but that does not exclude some role for the Internet altogether. On the contrary, whilst pointing out that the Internet is not the one dominant factor, nearly all our interviewees emphasised that it was important in supporting the process of recruitment."

The study provides several recommendations to combat terrorst recruitment. For online activity they recommend:
"More attention needs to be paid to extremist activities on the Internet. Governments need to become as Internet savvy as the extremists they are meant to counter, which requires investment in staff and technical capacity. Initiatives aimed at monitoring extremist activities on the net are important and welcome, but governments should not shy away from taking disruptive action where necessary. It has become a cliché to say that no extremist site can be taken down for long, but de-stabilising the extremist Internet ‘architecture’ – in particular distributor sites and large web forums – may produce valuable short-term gains. Also, the Internet may be difficult to regulate, but the successes in curbing the distribution of other ‘undesirable’ materials, such as child pornography, may hold valuable lessons for the fight against ‘jihadism online’."

Recruitment and Mobilisation for the Islamist Militant Movement in Europe

Thursday, June 12, 2008

Mandate Extended for the European Network and Information Security Agency

The European Network and Information Security Agency (ENISA) will release a media statement tomorrow announcing the extension of its mandate through 2012.

Mr. Andrea Pirotti, Executive Director of ENISA, stated:
“Network and information security is crucial for the European economy. The need for secure networks, systems and services will certainly not suddenly disappear in 2012. Following the EU parliamentary elections in 2009 and the establishment of a new European Commission, this extension allows for the necessary time to reflect thoroughly upon the activities of ENISA 'post-2012'. Network and information security touches business and the daily lives of citizens in Europe. It consequently needs constant reinforcement to keep up with the evolving threats landscape.”
www.enisa.europa.eu

Thursday, May 08, 2008

EU Considers the Future of the European Network and Information Security Agency

EU lawmakers are considering extending funding for the European Network and Information Security Agency (ENISA) in response to cyber attacks on Estonia. However, the organization currently does not have the funding, remit or capability to act as an incident response organization:

"Euro-MPs believe Internet infrastructure security must be protected more effectively as the EU economy depends increasingly on a trouble-free Web.

"A lot of staff are simply pushing papers, making reports and not doing what we need them to do. It's something you might see in the Soviet Union. There is an increase in network security problems," said Reino Paasilinna, a Finnish socialist."

[Editor's Note: After this article was published, I received a clarification on the staffing issues at ENISA from Ulf Bergström, Press and Communications Officer at ENSIA:

‘This year ADM has 17 staff in total, of which 13 are TAs (stable since 2006) to service 66 planned staff members (TAs and contract agents, SNEs and stagiaires).

There’s nothing imbalanced at ENISA. ENISA is even better as some agencies with regard to this ratio. The minimum number of admin staff (that we have) sounds much larger when the overall size of the agency is low.

About his ratio there's nothing what we could more improve, as the financial regulation and the whole set of administrative rules sets a minimum number in order to guarantee sound financial management ("checks and balances").']


Euro-MPs back longer term for EU Web security body

Monday, April 07, 2008

NATO and EU Concern on Cybercrime

In separate meetings last week, both the EU and NATO organizations discussed cyberterror issues and their need to respond.

The Council of Europe will review the new Convention on Cybercrime and discuss how to strengthen online anti-terrorism activities.

Separately, politically motivated computer crime was discussed at the NATO summit held in Romania including how member countries can better coordinate online defense activities.
"World leaders gathered in Bucharest for this week’s NATO summit are debating what role the trans-Atlantic alliance can play in containing “cyberterrorists,” “hacktivists” and other emerging menaces that experts concede are untraditional, but still potentially lethal."

Most of the concern quoted in the press center around the cyber attacks against Estonia.

European Union, NATO to tackle cybercrime

NATO grows increasingly concerned about terrorism on world's computer networks

Thursday, November 01, 2007

EU Considers Criminalizing Use of Internet by Terror Groups

The EU is considering recommendations to criminalize the use of the Internet by terrorist organizations to "inciting, recruiting and training for terrorism".
"In a memorandum on his proposals [EU Commissioner for Freedom, Security and Justice Franco] Frattini said the Internet served as one of the principal boosters of the process of radicalization and recruitment of militants, as well as "a source of information on terrorist means and methods, thus functioning as a 'virtual training camp'."
EU Commissioner Frattini wants to make online terrorism incitement a crime