Friday, November 14, 2008

U.S. Data Mining for Terrorist Activities Ineffective

Investor's Business Daily reviewed a report by the National Research Council on the U.S. Government's use of data mining to identify potential terrorists. The report, titled Protecting Individual Privacy in the Struggle Against Terrorists: A Framework for Program Assessment, concludes that the data mining initiative "is ineffective and threatens the privacy of millions of law-abiding Americans".

"We were consistently concerned that data mining does not have demonstrated efficacy for fighting terrorists," said Ben Shneiderman, a University of Maryland computer science professor and one of the 21 committee members."

The report discusses the danger is relying on databases that are notorious for inaccuracies:

"The DHS has purchased at least parts of databases from ChoicePoint, LexisNexis and Axiom, says [Stephen] Fienberg, who also works in Carnegie Mellon's CyLab, the largest university-based cybersecurity institute in the U.S."

"Merging data from various databases inevitably leads to mistakes. But government counterterrorism programs don't always take into account where its information comes from or whether it might not be true.

"It's basically a problem where government programs really are not focused on the data sources and the correctness, but rather the use of the data they have at hand," Fienberg said."


Data Mining Failing To Hit Mother Lode In Finding Terrorists

Wednesday, November 12, 2008

German Lower House of Parliament Passes New Cyber Investigative Powers

The German lower house of parliament has passed a bill extending search and monitoring capabilities to police in terrorism cases:
"Under the new law, a judge can issue a warrant allowing police the right to spy on a suspect's computer or hard drive, tap their telephone conversations and watch and eavesdrop on their homes."

The upper house still needs to approve the legislation before it becomes law.

German parliament moves to increase police powers

Monday, November 10, 2008

Death Penalty for Cyber Terrorism

Pakistani President Asif Ali Zardari has issued a decree that any act of "cyber terrorism" resulting in death may merit the death penalty:

"Whoever commits the offence of cyber terrorism and causes death of any person shall be punishable with death or imprisonment for life," according to a copy of the ordinance, published by the state-run APP news agency.

"The law will apply to Pakistanis and foreigners whether living in Pakistan or abroad.

"The ordinance described cyber terrorism as accessing of a computer network or electronic system by someone who then "knowingly engages in or attempts to engage in a terroristic act."

"The ordinance listed several definitions of a "terroristic act" including stealing or copying, or attempting to steal or copy, classified information necessary to manufacture any form of chemical, biological or nuclear weapon."


Pakistan Sets Death Penalty For "Cyber Terrorism"

Friday, November 07, 2008

U.K. Interception Modernisation Programme

The U.K. government is reportedly considering requiring major ISPs to allow the gather Internet traffic data:

"At Monday's meeting in London representatives from BT, AOL Europe, O2 and BSkyB were given a presentation of the issues and the technology surrounding the Government's Interception Modernisation Programme (IMP), the name given by the Home Office to the database proposal.

"They were told that the security and intelligence agencies wanted to use the stored data to help fight serious crime and terrorism."

The Interception Modernisation Programme has received a lot of attention in the U.K. press lately including a proposal to invest billions of pounds in the programme:

"Detica will very likely be among the first to profit from the IMP bonanza. Based in Guildford, it might warrant the title of The Most Important IT Company Most People Have Never Heard Of. According to sources with knowledge of systems that have long allowed GCHQ to eavesdrop on phone calls, Detica owns and operates the current "black box" infrastructure under contracts funded by the secret intelligence budget.

"In contrast to that arrangement, the proposed central communications database would not target the content of calls, emails, texts and other communications; rather, MI6 and GCHQ want to retain the powerful, searchable data detailing who contacted whom."
As a side note, the keywords "interception modernisation programme" is a major driver of traffic to this blog...


Internet black boxes to record every email and website visit
Spy chiefs plot £12bn IT spree for comms überdatabase


Obama, McCain Systems Compromised?

Newsweek magazine is reporting that the computer systems of both candidates for U.S. president were compromised last summer. However, few details were provided and there seems to be some issues with the story such as why there would be senior level White House involvement in the investigation:
"The following day, Obama campaign chief David Plouffe heard from White House chief of staff Josh Bolten, to the same effect: "You have a real problem ... and you have to deal with it."

The Newsweek article alleges that the source of the intrusions were from outside of the U.S. (again, the article provides no details or supporting evidence):
"Officials at the FBI and the White House told the Obama campaign that they believed a foreign entity or organization sought to gather information on the evolution of both camps' policy positions—information that might be useful in negotiations with a future administration. The Feds assured the Obama team that it had not been hacked by its political opponents."

Hackers and Spending Sprees

Monday, November 03, 2008

China's Cyber Warfare Capabilities

International-Relations.com has published a report hypothesizing that China plans to leapfrog U.S. military capabilities using cyber warfare capabilities. This lengthy report begins by providing details on China's traditional military capability and then discusses the U.S. military's dependence on technology (and perceived weakness) including:
  1. Network-centric warfare - "Militarily, the information revolution has given rise to an increasing reliance on situational awareness, weather monitoring, surveillance, communication, and precision strikes. Chinese military strategists have made special note of the US reliance on, and dominance with, electronic means in the Kosovo, Afghanistan, and Iraqi conflicts"

  2. Information operations - "...activities include PSYOPS troops who try to manipulate the adversary’s thoughts and beliefs, military deception and disinformation, media warfare, electronic warfare (EW), and computer network operations (CNO). Thus Information Operations Roadmap stands as an another example of the US commitment to transform military capabilities to keep pace with emerging threats and to exploit new opportunities afforded by innovation and rapidly developing information technologies."

  3. Future combat systems - "...places a particular emphasis on advanced robotics, including Unmanned Ground Vehicles (UGVs), Unmanned Aerial Combat Vehicles (UCAVs), Non- Line of Sight Launch Systems, and Unattended Systems. This system of systems seeks to make warfare as networked as the internet, as mobile as a mobile phone, and as intuitive as a video game. "

The report summarizes the importance of military cyber capabilities within China:
"The information revolution has given more power to individuals and increased globalization through the interconnectedness of economies, rapid dissemination of news, and improved access to communication and information of all types. Any attempt to compete on a global level without the use of these technologies would place the PRC at a significant military and financial disadvantage. For this reason, the benefits of electronic reliance outweigh the risks involved. Further, it is impossible for a state to develop a defence against cyber warfare without simultaneously learning how to execute attacks themselves."

The report also discusses the linkage between "offensive" and "defensive" capabilities:
"To learn how to conduct cyber security, the Chinese must have a full understanding of how attacks are conducted; therefore they will learn offence along with the defence - the two are inseparable. China has repeatedly stated its goal of military modernization, and cyber warfare is where modern militaries are headed. However, cyber warfare would unlikely be used alone. It could be used simultaneously with a traditional attack, perhaps as a first blow to take an opponent off guard, or in tandem with multiple non-traditional attacks, such as PSYOPS and economic operations, or variants of each. Additional combined tactics that will be discussed in the following sections include cyber attack, cyber reconnaissance, and market dominance."

Based on this concept the report delves into several cyber capabilities including:
  1. Internet security
  2. Cyber reconnaissance and attack
  3. Security hacking
  4. Military applications of hacking

The paper concludes:
"This research has shown that China seeks to leapfrog in military competitiveness by utilizing cyber warfare. Chinese military doctrine places an emphasis on asymmetric attack. Cyber warfare epitomizes this a low cost means of levelling the playing field. Cyber attack strikes at a superior adversary’s weakness – in the case of the US, a heavy reliance on hi-tech computerized weaponry and a civilian population reliant on an unsecured computer infrastructure. Cyber reconnaissance follows China’s tradition of technology transfer and reverse engineering for domestic production as a means of leapfrogging. Cyber reconnaissance gives the added benefit of providing deniability, low cost, a lack of legal framework against it, and the removal of geographical distance."


How China Will Use Cyber Warfare to Leapfrog in Military Competitiveness

Hamas Offers Cash Reward for Israeli Cyber Attacks

The Iranian branch of Hamas has offered a $2,000 reward to attack Israeli websites.
"Observers noted that the contest gives a chance for Iran's many under-employed but tech-savvy computer geeks to earn some quick cash with their expertise."


IRAN: Hamas' office declares cyber-war on Israel

Wednesday, October 29, 2008

Motivation for Cyber Attacks against al-Qaida Websites

In a classic example of how little is known about the motives of (potential) politically motivated cyber attacks, The Guardian newspaper reports on recent cyber attacks against al-Qaida websites and provides a string of speculation on potential motives including:

  • "...governments are targeting them in a shadowy new front in the "war on terror"

  • "...the websites have fallen victim to Shia groups engaged in tit-for-tat sectarian cyber warfare with Sunnis"

  • "technical problems"

  • "...al-Qaida sympathisers closed the forums themselves because they were too good a source of intelligence for their enemies"

  • "[I]nternet vigilantes"





Cyber-attack theory as al-Qaida websites close

Terrorist Twitters

The Federation of American Scientists has posted a draft report produced by an U.S. Army intelligence unit that looks at several uses of technology by al-Qaida and other terrorist organizations for communications include the use of the quick messaging system, twitter.com.


The short section titled "Potential for Terrorist Use of Twitter: A Red Teaming Perspective" provides background on twitter and discusses its use by activists protesting at the U.S. Republican Convention:
"...extremist and terrorist use of Twitter could evolve over time to reflect tactics that are already evolving in use by hacktivists and activists for surveillance. This could theoretically be combined with targeting. Twitter was recently used as a counter-surveillance, command and control, and movement tool by activists at the Republican National Convention (RNC). The activists would Tweet each other and their Twitter pages to add information on what was happening with Law Enforcement near realtime."

The article concludes with three simple scenarios of terrorist use of Twitter.

The full report can be found at:

Sample Overview: alQaida-Like Mobile Discussions & Potential Creative Uses

Monday, October 20, 2008

Georgian Government Releases Report on Cyber Attacks

The Government of Georgia has released a report concerning the cyber attacks on Georgia originating in Russia. The report provides details of attacks and makes allegations against individuals in Russia responsible for organizing the attacks.

The report directly blames the Russian government for the attacks:
"To help to make a final judgment regarding the cyberwar against Georgia these two declarations from Russian officials can help us to evaluate how Moscow thinks in regard to online warfare. The Russian State Duma deputy and member of the Security Committee Deputy Nikolai Kuryanovich stated in 2006 within a formal Russian parliamentary letter of appreciation to hackers who had taken down several Israeli web sites:
  • "In the very near future many conflicts will not take place on the open field of battle, but rather in spaces on the Internet, fought with the aid of information soldiers, that is hackers. This means that a small force of hackers is stronger than the multi-thousand force of the current armed forces."
"Should we interpret this declaration as a statement of intent, or merely a prediction? A few days ago, the Editor of the Russian Online journal cybersecurity.ru, made a similar statement that provides insight into the Russian war aims:
  • “Cyber-attacks are part of the information war, making your enemy shut up is a potent weapon of modern warfare.”


Russian Invasion of Georgia: Russian Cyberwar on Georgia

Friday, October 17, 2008

Recommended Reading: Analysis of Russian Cyber Attacks

Project Grey Goose have released a detailed study of the capabilities and methods used in cyber attacks believed to have originated in Russia. The report gives four high level findings:

  1. "We assess with high confidence that the Russian government will likely continue its practice of distancing itself from the Russian nationalistic hacker community thus gaining deniability while passively supporting and enjoying the strategic benefits of their actions."

  2. "We assess with high confidence that nationalistic Russian hackers are likely adaptive adversaries engaged in aggressively finding more efficient ways to disable networks."

  3. "We judge with moderate confidence that a journeyman-apprentice relationship will continue to be the training model used by nationalistic Russian hackers."

  4. "We estimate with moderate confidence that hacker forums engaged in training Russian cyber warriors will continue to evolve their feedback loop which effectively becomes their Cyber Kill Chain."
In reading this report, it is striking how similar the techniques used today are compared to historical cyber attacks and espionage. While the software tools used by modern cyber criminals have increased their efficiency by orders of magnitude, the basics are still the same.

Of particular interest is finding 3 concerning the "journeyman-apprentice relationship". This is not a new phenomenon and was seen in the earliest days of network intrusions, especially those with political motivation. For example, during the 1987-88 investigations of the cyber espionage case in which West German nationals where working for the Soviet Union, it was discovered that the five West German principals had set up a network of "apprentice hackers" to assist in network mapping and initial intrusions.

Unfortunately, very little information has been published in open sources concerning the investigation of these early intrusions. Clifford Stoll's 1989 book "The Cuckoo's Egg" documented a small portion of the overall activity and investigation. Some very generalized information concerning the techniques and methods used by the West Germans (and other cases) is provided in: International Intrusions: Motives and Patterns.



The full Grey Goose report is available at:

Russia/Georgia Cyber War – Findings and Analysis

A good summary article is also available from the Washington Post:

Report: Russian Hacker Forums Fueled Georgia Cyber Attacks

Wednesday, October 15, 2008

Computer Intrusions Rise to the Attention of South Korea's Prime Minister

The Prime Minister of South Korea has issued a warning to his cabinet on the growing threat of network intrusions from North Korea and China targeting government information:
"The National Intelligence Service (NIS), Seoul's main spy agency, said it had told [South Korean Prime Minister Han Seung-Soo] that about 130,000 items of government information had been hacked over the past four years."
and;
"The documents largely focused on foreign policy and national security, he [A NIS spokesman] added without elaborating."


SKorean PM warns of hacking threat by NKorea, China (AFP)

Friday, October 10, 2008

Increase in High-Tech Terrorists in India

Indian police are reporting and increase in recruiting of high-tech individuals to assist in terrorist attacks. Most recently was the arrest of three IT professionals that used computer intrusions to send e-mails just before and after bombings in India:
"Evidence is mounting that recruiters for Islamist terror groups have targeted the information technology and engineering sectors, in a successful effort to give India’s jihadist movement a quantum jump in skills and ideological focus.

"Most of the 15 men arrested in Mumbai on Monday, on charges of participating in the hit-teams which planted explosives in Ahmedabad and Surat, are criminals linked to Pakistan-based ganglord Amir Raza Khan.

"But three men in the group were, till their arrest, believed to be model citizens. Key among them is Mohammed Mansoor Asghar Peerbhoy, who worked as a software engineer at multinational Yahoo India."

India - White-collar jihadists,a cause for growing concern

Saudi Owned Television News Website Attacked

The defacement of Al Arabiya's website, a Dubai based, Saudi-owned television station, was in apparent retaliation for recent attacks on Shiite websites:



The number of web site defacements continues to escalate between opposing Sunni and Shiite groups:
"Last month, prominent Sunni religious commentator Sheikh Yusuf al-Qaradawi charged that Shiites are "invading" Sunni societies. Also, a tit-for-tat cyber war disabled 900 websites, belonging to both sects, as Shiite and Sunni hackers infiltrated religious websites and uploaded their own messages."

More information on these attacks is available at: Sunni-Shiite hacking war disables 900 websites


Al Arabiya hit by Sunni-Shiite hacking war

Wednesday, October 08, 2008

US Considering Automated Cyber Retaliation

The U.S. Department of Homeland Security is considering the development of an automated system to retaliate against cyber attacks:
"Homeland Security Secretary Michael Chertoff on Friday said he'd like to see a government computer infrastructure that could look for early indications of computer skullduggery and stop it before it happens.

"The system "would literally, like an anti-aircraft weapon, shoot down an attack before it hits its target," he said. "And that's what we call Einstein 3.0.""

"Einstein" is the name of the U.S. government's current intrusion detection system.

Homeland Security seeks cyber counterattack system

Sunday, October 05, 2008

More Details on Skype Surveillance in China

As a followup to an earlier report, The New York Times published an article with further details of the surveillance of Skype communications in China. Interesting details include how the interceptions were detected:

"The researchers stumbled upon the surveillance system when Nart Villeneuve, a senior research fellow at Citizen Lab, began using an analysis tool to monitor data that was generated by the Tom-Skype software, which is meant to permit voice and text conversations from a personal computer. By observing the data generated by the program, he determined that each time he typed a particular swear word into the text messaging program an encrypted message was sent to an unidentified Internet address.

"To his surprise, the coded messages were being stored on Tom Online computers. When he examined the machines over the Internet, he discovered that they had been misconfigured and that the computer directories were readable with a simple Web browser.

"One directory on each machine contained a series of files in which the messages, in encrypted form, were being deposited. Hunting further, Mr. Villeneuve soon found a file that contained the numerical key that permitted him to decode the encrypted log files.

"What he uncovered were hundreds of files, each containing thousands of records of messages that had been captured and then stored by the filtering software. The records revealed Internet addresses and user names as well as message content. Also stored on the computers were calling records for Skype voice conversations containing names and in some cases phone numbers of the calling parties."

The original report from Citizen Lab can be found at: BREACHING TRUST: An analysis of surveillance and security practices on China’s TOM-Skype platform


Surveillance of Skype Messages Found in China

Friday, October 03, 2008

Study of Terrorist Recruitment in Europe and Use of the Internet

King’s College London has published an in-depth study of jihadist recruitment and mobilization for the European Commission. The paper provides an extensive background and history of terrorist recruitment that started in local mosques and moved to prisons and the Internet. It also discusses the psychological processes and rationalizations involved in recruitment.

The basic structure of online terrorist communications is provided:
"Despite the impression of anarchy, the ‘architecture’ of the Islamist militant Internet presence is relatively straightforward. First, there are the official web sites, representing clerics, strategists, or Islamist militant organisations. They are very unstable, but they are often well run and may contain downloadable videos, communiqués, discussion papers and religious rulings, and frequently also provide opportunities for interaction with leading personalities. Second, there are the web forums which are mostly administered and populated by grassroots supporters. The web forums are the soap boxes of the Islamist militant movement, where key debates about the latest news take place, networks are formed, and a real sense of community emerges. Often password-protected, they are also used to exchange videos, training material, and links to other web sites. The third element of the Islamist militant Internet architecture are so-called distributor sites, which include ‘jihadist’ web directories, ‘tribute’ sites, and the web pages of so-called ‘media groups’. These sites sustain the infrastructure of the Islamist militant web presence, as they distribute ‘jihadist’ material and provide updated links on where to locate official sites and web forums. Web forums can also perform the function of distributor site."

The researchers describe two elements of terrorist activity on the Internet:
  1. Internet supported recruitment; and,
  2. Virtual self recruitment
These elements can be summarized as follows:
"The Internet has come to play an increasingly important role. The main function is to support ‘real-world’ recruitment (by reinforcing religious and political themes; by facilitating networking; and by creating a climate of exaggeration). In recent years, however, new forms of Islamist militant online activism have emerged, which rely less on human contact and can be described as ‘virtual self-recruitment’."

The paper makes clear that the Internet has not replaced the human element in the recruiting process:
"Realworld social relationships continue to be pivotal in recruitment, therefore, but that does not exclude some role for the Internet altogether. On the contrary, whilst pointing out that the Internet is not the one dominant factor, nearly all our interviewees emphasised that it was important in supporting the process of recruitment."

The study provides several recommendations to combat terrorst recruitment. For online activity they recommend:
"More attention needs to be paid to extremist activities on the Internet. Governments need to become as Internet savvy as the extremists they are meant to counter, which requires investment in staff and technical capacity. Initiatives aimed at monitoring extremist activities on the net are important and welcome, but governments should not shy away from taking disruptive action where necessary. It has become a cliché to say that no extremist site can be taken down for long, but de-stabilising the extremist Internet ‘architecture’ – in particular distributor sites and large web forums – may produce valuable short-term gains. Also, the Internet may be difficult to regulate, but the successes in curbing the distribution of other ‘undesirable’ materials, such as child pornography, may hold valuable lessons for the fight against ‘jihadism online’."

Recruitment and Mobilisation for the Islamist Militant Movement in Europe

Thursday, October 02, 2008

Syria Increases Internet Censorship

The National newspaper in the UAE has an article discussing recent increases in Syrian censorship on the Internet. The article provides a good background on Internet use within Syria and the types of information that is censored:
"And in a sign that the censors are becoming more technologically advanced, a series of software gaps that existed in online controls a few months ago have been closed. It used to be a relatively simple matter for internet surfers to get around the censors using freely available programmes. Now accessing prohibited pages is much more difficult, and requires specialised knowledge."

Syria tightens control over internet

Skype Communications Monitored and Censored in China

Citizen Lab, an Internet and politics research lab at the University of Toronto has just released a detailed analysis of the interception, blocking and logging of text communications using TOM-Skype (the Chinese subsidiary of Skype).

More importantly, the analysis was made possible by poor security on the servers used to store intercepted and blocked communications and brings into question the complicity of western companies in aiding government surveillance and censorship:
"These findings should serve as a warning for groups engaging in political activism or promoting the use of censorship circumvention technology accessed through services provided by companies that have compromised on human rights. Private and politically sensitive messages sent through new communications technologies are only as secure as the robustness of the security of the technology companies themselves. In this case we were able to access volumes of sensitive data without the cooperation of the company involved due to lax security. There is no reason why an inquisitive government could not do the same.

"Trust in a well-known brand such as Skype is an insufficient guarantee when it comes to censorship and surveillance. This case demonstrates the critical importance of the issues of transparency and accountability by providers of communications technologies. It highlights the risks of storing personally identifying and sensitive private information in jurisdictions where human rights and privacy are under threat. It also illustrates the need to assess the security, privacy and human rights impact of such a decision."
The report listed the following key findings:

  • The full text chat messages of TOM-Skype users, along with Skype users who have communicated with TOM-Skype users, are regularly scanned for sensitive keywords, and if present, the resulting data are uploaded and stored on servers in China.
  • These text messages, along with millions of records containing personal information, are stored on insecure publicly-accessible web servers together with the encryption key required to decrypt the data.
  • The captured messages contain specific keywords relating to sensitive political topics such as Taiwan independence, the Falun Gong, and political opposition to the Communist Party of China.
  • Our analysis suggests that the surveillance is not solely keyword-driven. Many of the captured messages contain words that are too common for extensive logging, suggesting that there may be criteria, such as specific usernames, that determine whether messages are captured by the system.

BREACHING TRUST: An analysis of surveillance and security practices on China’s TOM-Skype platform

Wednesday, October 01, 2008

Myanmar's Cyber Warfare Capabilities

The Asia Times Online has an extensive article on Myanmar's cyber war capabilities and alleges that it has received training and assistance from China, Russia and Singapore. It also provides some details on the types of assistance and the history of Myanmar's cyber capabilities.

The article also alleges that Myanmar's government is using cyber warfare techniques to disrupt dissident groups around the world:
"...the junta's cyber-warfare specialists appear to have wider designs than just censoring an uncomfortable anniversary and they are receiving plenty of foreign assistance in upgrading their political dissent quashing capabilities."


Myanmar on the cyber-offensive

South Korean Missile Manufacturer Compromised with Malicious Code

This article provides very little information about an alleged breach of computer systems at South Korean guided missile manufacturer, LIGNex1 Hyundai Heavy Industries.

The report states that malicious code was planted "through which they stolen [sic] information.
"A spokesperson said: “The research institute suspects the culprits are Chinese or North Korean hackers but doesn't know specifically what information they stole. In the worst case, the blueprints of missiles and Aegis ship could have been stolen."


South Korean defence suppliers uncover malicious code

Information Security Is "on Vacation" in the U.S.

An interesting commentary on the state cyber war capabilities and vulnerabilities was recently published by Claremont College stating "[t]he security of America’s information infrastructure is on vacation". The article discusses recent cyber attacks, data losses and the nature of distributed denial-of-service (DDoS) attacks and concludes:
"This type of information espionage and Internet vandalism has the potential to be a serious form of assymetrical warfare, allowing state actors deniability and providing them with a powerful new tool in intelligence-gathering. International recognition of current U.S. military dominance has driven other nations to find alternative methods of strengthening their strategic position.

"While our dependency on the Internet grows both economically and politically, we need to provide stronger security regulation of government agencies and key industries..."


The State of Computer Security

GAO Report: US CERT's "Baseline Understanding" Inadequate

Last month, the U.S. Government Accountability Office (GAO) released yet another report condemning the Department of Homeland Security's cyber analysis and warning capability.

As previously observed, there is a deficiency in the most basic capabilities to understand (let alone protect) the national information infrastructure. The GAO report concluded:
"In seeking to counter the growing cyber threats to the nation’s critical infrastructures, DHS has established a range of cyber analysis and warning capabilities, such as monitoring federal Internet traffic and the issuance of routine warnings to federal and nonfederal customers. However, while DHS has actions under way aimed at helping US-CERT better fulfill attributes identified as critical to demonstrating a capability, US-CERT still does not exhibit aspects of the attributes essential to having a truly national capability. It lacks a comprehensive baseline understanding of the nation’s critical information infrastructure operations, does not monitor all critical infrastructure information systems, does not consistently provide actionable and timely warnings, and lacks the capacity to assist in mitigation and recovery in the event of multiple, simultaneous incidents of national significance [emphasis added]."


This lack of a "comprehensive baseline understanding" is not confined to the U.S. Government; it is also rampant in the private sector where risk and threat assessments are too often a simple compliance check-off with little regard to the quality of analysis. In both the public and private sectors, engineers and other technicians tasked with managing information security are not trained as security professionals who can analyze risks and threats across a single organization let alone across entire information infrastructures and global networks.

This lack of professional competence in the information security industry is one of the key factors driving the continued increase in vulnerabilities, attacks and data and monetary losses despite record investment and spending.

The full GAO report is available online:

CYBER ANALYSIS AND WARNING: DHS Faces Challenges in Establishing a Comprehensive National Capability

Tuesday, September 30, 2008

More Calls for U.S. Offensive Cyber Capabilities

The Washington Post reports on U.S. Representative Jim Langevin's (chairman of the House Homeland Security subcommittee on emerging threats, cybersecurity and science and technology and a member of the House Permanent Select Committee on Intelligence) call for the U.S. to develop an offensive cyber capability. Rep. Langevin sees this as a deterrence against potential attacks on U.S. systems. In order for the deterrence to be effective, he called for much of the Comprehensive National Cybersecurity Initiative (CNCI) to be declassified and for responsibility of cyber security to be taken away from the Department of Homeland Security.

The article also discusses some of the important issues in implementing an offensive capability, namely the identification of the motive and source of an attack:

"We have a tremendous amount of trouble determining attribution ... where an attack actually came from, who was responsible, who might have been behind that computer. And we have a very, very long way to go on that," commission member Paul Kurtz, a former White House cybersecurity official, told the House intelligence committee.

"Until we start to get clarity in that piece, it's going to be very difficult to contemplate the military option, of responding appropriately," Mr. Kurtz added."



U.S. urged to go on offense in cyberwar

Jihadist Websites Move to the U.S.

FrontPage Magazine has an editorial piece concerning the movement of extremist websites to US ISPs:
"In counterterrorism circles there is significant buzz about “Al-Qaeda 2.0”, warning of highly decentralized jihadist networks operating independently and driven by a highly toxic internet-inspired Islamic ideology. The sad reality is, however, that an increasing number of jihadist websites, especially those in the English language, are finding safe haven in the US – and the US government seems powerless, or unwilling, to stop them."


Mainstream US Islamic Websites -- and Terror


Monday, September 29, 2008

The Law of Unintended Consequences - Security Creates Its Own Threat

An anti-war blog has posted an article alleging Israeli spying on US government communications by installing backdoors into telephone systems. Regardless of the accuracy of the article or its political slant, it does bring up an interesting issue: When can security controls or measures create vulnerabilities?

Specifically, the article discusses the potential vulnerability created by implementation of the FBI's 1994 Communications Assistance for Law Enforcement Act (CALEA) that mandated telecommunication providers develop the capability for law enforcement agencies to wiretap any communication in the U.S.:
"The real novelty – and the danger – of CALEA is that telecom networks are today configured so that they are vulnerable to surveillance. "We've deliberately weakened the computer and phone networks, making them much less secure, much more vulnerable both to legal surveillance and illegal hacking," says former DOJ cybercrimes prosecutor Mark Rasch. "Everybody is much less secure in their communications since the adopting of CALEA."
This issue is not academic: I have investigated many serious computer crimes where the intruder(s) targeted security information and controls to determine the status of investigations, to introduce backdoors into control systems or lockout or monitor the activities of investigators. Too often the very tools used by security personnel and investigators were used against them or in some way compromised.

It is critical that security professionals and engineers understand that many technological controls can (and probably will be) used by an adversary to their advantage. This is particularly true of communication systems and any control that monitors activity or collects intelligence data such as log files, network and host vulnerability scans, IP based communication systems such as VoIP and IP based surveillance and access control systems.

Trojan Horse: How Israeli Backdoor Technology Penetrated the US Government's Telecom System and Compromised National Security

Thursday, September 25, 2008

Commentary: The Problem with Information Security

A recent article from Australian IT provided an Australian perspective of the international cyber warfare games named Cyber Storm II. The exercise was conducted by private and public sectors in Australia, Britain, New Zealand, Canada and the United States. It is available at: Govt can do more on cyber security: report.

However, one point stood out in the article's analysis:
"...participants [of Cyber Storm II], which included the private sector, were surprised by the "borderless nature" of cyber attacks and the "speed with which they can escalate"."

How can people who call themselves "security professionals" be surprised that the Internet is "borderless" or that attacks (or any online activity) can occur quickly? This lack of understanding the basic nature of threats is mindboggling and one of the most daunting problems in information security.

Too often, the "security experts" (in both the government and private sectors) are simply IT engineers who view security as a technical problem with technical solutions. This myopic world view is not only misguided, it precludes proper threat and risk assessments.

While understanding the technological infrastructure and its vulnerabilities are an important component of any threat assessment, it is just as critical to understand adversary motivations, capabilities and methods. Likewise, threats must be analyzed at both the macro and micro levels.

For some reason, physical security professionals and intelligence analysts "get this". However, IT security engineers not only have difficulty incorporating the "people" element but are often hostile to anything that strays from their technical comfort zone.

It is no wonder that security problems are only growing in numbers and impact and they will continue to do so as long as information security is viewed as an engineering issue and the "experts" are "surprised by the "borderless nature" of cyber attacks".

For more on this topic see:

Friday, September 19, 2008

Saudi Arabia Arrests Five for Internet Use

The Saudi Ministry of Interior announced the arrest of five individuals "who used the Internet to propagate extremism and incite youths to go to troubled areas".

"The group members "hid behind their computers and gave themselves several assumed names" in order to post material under one alias and post support for it under a different alias, the [interior] ministry said.

"The aim was to give the impression that their ideas "enjoy support from society and to encourage those deluded (by the propaganda) to communicate with them as a prelude to recruiting them for their despicable goals," it added."



Saudi arrests five web 'jihadis'

U.K. Sentences 18 Year Old for Downloading Terrorist Material

Eighteen year old Hammaad Munshi was sentenced in the U.K. to two years in prison for using the Internet to gather terrorist related information:
"During his trial at Blackfriars Crown Court, the jury heard that Munshi had spent many hours viewing jihadist websites and had downloaded guides to making napalm, detonators and explosives."

Computer terror teenager jailed

VP Candidate Sarah Palin's Personal Email Compromised

Sarah Palin, the Republican Vice Presidential candidate's personal Yahoo email account was compromised and emails and family photographs were made public:

"Among the emails posted on the Internet is a message sent from Palin to the vice-governor of Alaska, Sean Parnell, who is currently seeking election to Congress.

"The hacking comes at a time when Palin is suspected of using her personal email account for conducting public affairs in Alaska.

"According to law, all messages relating to the official functions of governor must be archived and not destroyed, but allows for personal messages to be destroyed."


Hackers infiltrate Palin's email account

Wednesday, September 17, 2008

U.S. Cyber Security Not Adaquate

The U.S. Government Accountability Office (GAO) has released a report (originally dated July 2008) critical of the U.S. Government's cyber security.

The report defined, in part, the threat:
"There is increasing concern among both government officials and industry experts regarding the potential for a cyber attack on the national critical infrastructure, including the infrastructure’s control systems. The Department of Defense (DOD) and the Federal Bureau of Investigation, among others, have identified multiple sources of threats to our nation’s critical infrastructure, including foreign nation states engaged in information warfare, domestic criminals, hackers, virus writers, and disgruntled employees working within an organization. In addition, there is concern about the growing vulnerabilities to our nation as the design, manufacture, and service of information technology have moved overseas. For example, according to media reports, technology has been shipped to the United States from foreign countries with viruses on the storage devices. Further, U.S. authorities are concerned about the prospect of combined physical and cyber attacks, which could have devastating consequences. For example, a cyber attack could disable a security system in order to facilitate a physical attack."
The GAO broadly assessed operations in four areas: Monitoring, Analysis, Warning and Response and found issues in each domain.

One of the key challenges the report identified was organizational and management issues within the U.S. Department of Homeland Security (DHS) stating that the cyber security initiative is:
"...operating without organizational stability and leadership within DHS—the department has not provided the sustained leadership to make cyber analysis and warning a priority. This is due in part to frequent turnover in key management positions that currently also remain vacant. In addition, US-CERT’s role as the central provider of cyber analysis and warning may be diminished by the creation of a new DHS center at a higher organizational level."

Until DHS addresses these challenges and fully incorporates all key attributes into its capabilities, it will not have the full complement of cyber analysis and warning capabilities essential to effectively performing its national mission."

CRITICAL INFRASTRUCTURE PROTECTION: DHS Needs to Better Address Its Cybersecurity Responsibilities

Thursday, September 11, 2008

U.S. Considers Developing Offensive Cyber Warfare Capabilities

The Los Angeles Times reports on Pentagon debates about developing offensive cyber capabilities. It appears the renewed discussion is at least partially driven by the Russian Georgian conflict.

The article touches on some of the high level issues involved in cyber war. Like many technical revolutions in military history, cyber warfare presents many challenges and unknowns:
"To some, the tension over cyberspace echoes military debates through the centuries. Maj. Gen. William T. Lord, head of the Air Force cyber-effort, said that such discussions were akin to an old military puzzle known as "intelligence gain-loss."

"Do you not destroy a target because you can exploit it? Or do you destroy the target -- and lose the ability to exploit -- because troops are in harm's way?" Lord said. "That is not a debate. It is a discussion that goes on in war fighting."

Pentagon debates development of offensive cyberspace capabilities

Facebook Used to Target Israeli Interests

The Middle East Times ran an article discussing issues with the social networking site Facebook including accusations that Hezbollah uses Facebook to gather intelligence on Israel. Of more interest is that this surprising to anyone.
"...reports from the Lebanese capital, Beirut, are emerging that Hezbollah ... is using Facebook to learn of potential Israeli military movements, to gather possibly sensitive information about Israeli military bases and to pick up intelligence that could be harmful to Israel's security."

Cyber Terrorism: Perils of the Internet's Social Networks

Friday, September 05, 2008

Terrorism and Engineers - An Indian Perspective

CyberMedia India Online Ltd. (CIOL) published an interesting article on the relationship between terrorist groups and high tech individuals. The article discusses both why terror groups are interested in recruiting engineers for their operations (both cyber and physical) and why well educated and paid people would be attracted to terrorist organizations:
"Engineers that come from societies that are in themselves under threat from internal and external influences, and where alternate (and legal) means of expression are either banned or methodically suppressed will have the third terrorism necessity, a socio/political cause, and will be recruited by (or be found offering their services to) terrorist organizations."

Terror minds look for techie brainpower

Thursday, September 04, 2008

Various Articles on Russian Georgian Cyber Attacks

In an attempt to catch up on past articles concerning the Russian Georgian cyber attacks, I'll just post links to several articles that provide at least some factual information - Thanks to S.Y. for the pointers.

July 2008:

Wednesday, September 03, 2008

Recommended Reading: "Georgia Cyber Attacks By Russian Gov't? Not So Fast"

Gadi Evron, the founder of Israel's Government CERT group, wrote an article that was published in the Australian version of CIO.com (notably absent from the U.S. site) concerning the recent attacks on Georgia.

It is always refreshing to hear an experienced investigator discuss the issues:

"Running security for the Israeli government Internet operation and later founding the Israeli government CERT, I found that such attacks were routine. Seeing the panicked reaction this type of attack has generated seems quaint from my perspective. Not all fighting is warfare. While Georgia is obviously under DDoS attacks that are political in nature, it doesn't so far seem different from any other online aftermath by fans. Political tensions are always followed with online attacks by sympathizers.

"DDoS attacks harm the Internet itself rather than just this or that website, which often requires some of us in the vetted Internet security operations community to get involved in mitigating the attacks, if they don't just drop on their own. Our purpose is not to get involved in any local situation, but rather to preserve our common global critical infrastructure - the Internet.

"Could this somehow be indirectly related to Russian military action? Yes, but there is no evidence to indicate it is the case as of yet. If anything, the opposite seems likely at this point in time."

As with similar online attacks, there is wild speculation and near hysteria in the media concerning cyber attacks against Georgia originating in Russia. It is rare to have a commentator that can take a step back and analyze the situation based on known facts and an understanding based on real-world investigations.

Mr. Evron also notes the effect of the traditional media as both a motivator and as propogandia. This symbiotic relationship between poitically motivated cyber attacks and PR is documented in Hacktivism & Politically Motivated Computer Crime.

Georgia Cyber Attacks by Russian Gov't? Not So Fast

Researching Politically Motivated Computer Crimes

The Washington Post provides details of two groups researching politically motivated computer crimes. The article provides some information concerning the Georgian Russian online attacks as well as a discussion about online tactics and the effects of attacks:
"It's unclear who is behind the attacks, however. In some cases, the locations of botnet controllers can be traced, but it's impossible to know whether an attacker is working on the behalf of another organization or government."


A New Breed of Hackers Tracks Online Acts of War

Tuesday, August 26, 2008

Chinese "Hacker" Discusses Chinese Underground and Attacks on Western Systems

An interview with a Chinese "hacker" who claims to have participated in pro-Chinese attacks against CNN and other western organizations has been posted on YouTube.
"If there is a cyber war between two countries and if our country needs us, as cyber citizens or as IT fans, we can work together and we can certainly protect ourselves."



Dutch Websites Defaced in Protest of Film Release

An attacker using the pseudonym of "nEt^DeViL" has attacked and defaced several hundred websites in the Netherlands in protest of the release of the Dutch film "Fitna" critical of Islamic extremists.

Part of the message left in the defacements states:
"If you think that ” Insulting GOD Religion is a Freedom of Speech as your country did , then allow me to show you my Freedom knowledge of Hacking ;)" [sic].

Hundreds of Dutch web sites hacked by Islamic hackers

Tuesday, June 24, 2008

Islamic Jihad Creates Cyber War Unit

Islamic Jihad, a Palestinian Islamist group, has created a cyber-war unit to aid its armed Al-Quds Brigades in attacks on Israel:
"It was a response to years of attacks by Israeli hackers, and according to the Brigades spokesman, Abu Hamza, it equals the playing field in cyber-space.

"The Israeli's have worked very hard the past few years on monitoring all the Palestinian websites, especially those of Islamic Jihad and Al-Quds Brigades," Hamza told MENASSAT.

"They (Israeli hackers) hacked these websites and erased them from the electronic boards or even added indecent pictures to them," he said.
"Hamza told MENASSAT that the Brigades had to establish an e-media military unit "because we had to fight the enemy in the electronic media to resist being assaulted on two fronts – physically and virtually."

The article discusses several specific attacks against Israeli interests; mostly web defacements but also discusses attempts at system based attacks against Israeli infrastructure targets:
"Abu Hamza said that the e-media military unit doesn't just work on breaking the security of the Israeli websites – both governmental and civilian –, but it is also "expanding its cyber-reach to include attempts at hacking and bugging the Israeli telecommunications network."

"So far, these attempts have not succeeded," he [said]."

Islamic Jihad’s cyber-war brigades

India's Military Concerned over Chinese Cyber Attacks

India's military is taking steps to counter alleged Chinese intrusions into Indian systems:
"In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system. Though the intelligence agencies failed to get the identity of the hackers, the IP addresses left behind suggested Chinese hands."

The article rambles somewhat between discussion of web defacements in India (with no apparent link to China) and discussion of India's vulnerability to cyber attacks:

"Unless India takes adequate steps to protect itself from external cyber threats, the world famous IT giant could be facing a grim situation. Cyber attacks are dangerous for India because of the growing reliance on networks and technology to control critical systems that run power plants and transportation systems. Cyber attacks on banks, stock markets and other financial institutions could likewise have a devastating effect on a nation's economy.

"As a countermeasure, the Indian armed forces are trying to enhance their C4ISR capabilities, so that the country can launch its own cyber offensive if the need arises. Given Chinese cyber attacks, there is need for the army to fight digital battles as well."

China's cyber warfare against India

Kurdish Immigrant in Germany Convicted for Promoting Terrorism Online

An unnamed Kurdish immigrant to Germany has been convicted and sentenced to three years in prison for posting files and making statements that supported al-Qaeda leaders.

"The court in the northern German city of Celle convicted him on 22 counts of recruiting on behalf of a non-German terrorist organization, which is a crime under German law.

"Defence lawyers had called for the acquittal of the man, who has Iraqi nationality. Presiding judge Wolfgang Siolek said the verdict sets a legal precedent in Germany, as the first where a person has been jailed for remarks on the internet in support of a foreign terrorist cause.

"The court said the internet postings had the purpose of urging others to join in the jihad, and went well beyond a mere statement of sympathy with al-Qaeda, which would have been protected by free-speech laws and would not have been punishable."

Kurd used internet to urge terrorists on: three years jail

Friday, June 13, 2008

China Denies Attacks on U.S. Congressional Computer Systems Becuase It Lacks the Capability

China's Foreign Ministry has denied reports that China was the source of attacks on U.S. Congressional systems because it lacks the technology to do so:
"China denied accusations by two U.S. lawmakers that it hacked into congressional computers, saying Thursday that as a developing country it wasn't capable of sophisticated cybercrime.

"Is there any evidence? ... Do we have such advanced technology? Even I don't believe it," Foreign Ministry spokesman Qin Gang told a regularly scheduled news conference."

The article discusses the inconsistency in this statement - China is a leader in high technology; not only manufacturing but in design and development:

"China has a thriving information technology industry and claims to have 221 million Internet users — equal to the U.S. as the most in the world.

"I'd like to urge some people in the U.S. not to be paranoid," Qin said. "They should do more to contribute to mutual understanding, trust and friendship between the U.S. and China."


China denies hacking into US computers

U.S. Congressional Systems Targeted for Chinese Dissident Info - Maybe

Two U.S. congressmen have gone public accusing China as the source of intrusions into their computer systems searching for information on Chinese dissidents.

"Two congressmen, both longtime critics of Beijing's record on human rights, said the compromised computers contained information about political dissidents from around the world. One of the lawmakers said he'd been discouraged from disclosing the computer attacks by other U.S. officials.

"Rep. Frank Wolf, R-Va., said four of his computers were compromised beginning in 2006. New Jersey Rep. Chris Smith, a senior Republican on the House Foreign Affairs Committee, said two of the computers at his global human rights subcommittee were attacked in December 2006 and March 2007.

"Wolf said that following one of the attacks, a car with license plates belonging to Chinese officials went to the home of a dissident in Fairfax County, Va., outside Washington and photographed it."

The article discusses other potential intrusions in the US government systems from China and attempts by investigators to keep the attacks secret:

"Wolf said the FBI had told him that computers of other House members and at least one House committee had been accessed by sources working from inside China. The Virginia Republican suggested that Senate computers could have been attacked as well.

"He said the hacking of computers in his Capitol Hill office began in August 2006, that he had known about it for a long time and that he had been discouraged from disclosing it by people in the U.S. government he refused to identify.

"The problem has been that no one wants to talk about this issue," he said. "Every time I've started to do something I've been told 'You can't do this.' A lot of people have made it very, very difficult."

"The FBI and the White House declined to comment.

"The Bush administration has been increasingly reluctant publicly to discuss or acknowledge cyber attacks, especially ones traced to China."


Other articles have been published discussing the lack of specific evidence that the source of these attacks is actually China and discusses the difficulty in determining both source and motive.

Lawmakers say Capitol computers hacked by Chinese

Weak Evidence Links Congressmen's Cyber-attacks to China

Thursday, June 12, 2008

Mandate Extended for the European Network and Information Security Agency

The European Network and Information Security Agency (ENISA) will release a media statement tomorrow announcing the extension of its mandate through 2012.

Mr. Andrea Pirotti, Executive Director of ENISA, stated:
“Network and information security is crucial for the European economy. The need for secure networks, systems and services will certainly not suddenly disappear in 2012. Following the EU parliamentary elections in 2009 and the establishment of a new European Commission, this extension allows for the necessary time to reflect thoroughly upon the activities of ENISA 'post-2012'. Network and information security touches business and the daily lives of citizens in Europe. It consequently needs constant reinforcement to keep up with the evolving threats landscape.”
www.enisa.europa.eu

Thursday, May 29, 2008

Belgian Woman Convicted for Islamist Website

A Belgian woman has been convicted in Switzerland for maintaining a website supporting Islamist groups including al-Qa'eda. Malika El Aroud (who's husband Abdessatar Dahmane killed the anti-Taliban resistance leader Ahmed Shah Massoud in Afghanistan two days before September 11th) is quoted in the article:

"I have a weapon. It's to write. It's to speak out. That's my jihad. You can do many things with words. Writing is also a bomb."

"I write in a legal way. I know what I'm doing. I'm Belgian. I know the system."

"...ask your mothers, your wives to order your coffins Vietnam is nothing compared to what awaits you on our lands [sic]".


Female al-Qa'eda supporter uses internet as 'bomb' to recruit others to wage jihad on West

Spanish Police Arrest Online Protest Group

This was originally posted several weeks ago in Gary Warner's CyberCrime & Doing Time blog.

Spanish police announced on May 17, 2008 the arrest of at least four members of a Spanish speaking group called D.O.M. This group is alleged to be one of the more prolific web defacement groups in the world. Spanish police estimate they were responsible for as many as 21,000 attacks on websites - most as political protests:
"Some of the more high-profile attacks credited to the group, at least from an American perspective, would include having hit the US government's National Cancer Institute with an SQL injection attack back in July of 2007, ( archived from Zone-H). In February, an0de defaced an MIT server with an anti-American, anti-Bush message, archive from Zone-H ."

Spanish Arrest D.O.M. Team

Wednesday, May 28, 2008

Russian Radiation Level Website Knocked Offline

RIA Novosti, the Russian News Agency, is reporting a denial-of-service attack against a public website used to inform citizens about radiation levels associated with nuclear power plants. It appears the attacks coincided with the release of false reports of a radiation leak.
"This was a planned action by hackers, which has brought down almost all sites providing access to the Automatic Radiation Environment Control System (ASKRO), including the Leningrad NPP site, the rosatom.ru site, and others. For several hours users were unable to reach the sites and obtain reliable information on the situation at the plant."


Russian nuclear power websites attacked amid accident rumors

Monday, May 19, 2008

Hate Speech on the Internet

The Anti-Defamation League (ADL) has published a speech by Christopher Wolf, Chair, ADL Internet Task Force and Chair, International Network Against Cyber-Hate (INACH) to the Commission on Security and Cooperation in Europe. The speech discusses the use of the Internet to facilitate hate speech:
"The Internet allows haters to communicate, collaborate and plot in ways simply not possible in the off-line world. The Internet inspires and facilitates real-world violence.And the misuse of the Internet to propagate hate victimizes those vulnerable to hurtful words and images, especially minorities, and it serves to mislead and even recruit young people to become the next generation of hate-mongers."


Hate in the Information Age

North America Hosts Terrorist Web Sites

Israel 21c posted an article discussing the use of North American ISPs to host terrorist supporting websites:
"Prof. Niv Ahituv, academic director of the Netvision Institute for Internet Studies (NIIS) at Tel Aviv University (TAU), said that some of the world's most dangerous organizations, including Hezbollah and al-Qaeda, host their web sites on servers owned by popular American and Canadian ISPs used by most North Americans."
This issue has been documented since 2000 when the first serious cyber conflicts occurred between Israeli and Palestinian supporters during the second Intifada. Since both sides targeted systems hosted by North American ISPs, the attacks affected many U.S. companies not directly involved with the conflict - a form of electronic collateral damage (See: Hacktivism and Politically Motivated Computer Crime).

The article discusses a presentation on this topic that Professor Ahituv made at a NATO conference earlier this year. The article also addresses the debate on shutting down this type of activity and the U.S. First Amendment issues involved:
"Unfortunately, in the wired world, the base location is a technical matter. Geography is not a limiting factor. "A half an hour after a website is shut down in the US, it is registered in Malaysia, Saudi Arabia, or Iran. The FBI has shut down a few websites, but it is like chasing the wind," warns Ahituv."


Israeli study shows US a digital haven for terrorists

Cyber Attacks Against Palestinian Bloggers

Picked up a short blog posting concerning the high volume of attacks against bloggers who post articles concerning issues in Palestine. The article doesn't specify any technical details nor speculate on the source or motive...
"It's funny how every time I write about Palestine, I get a slew of hack attempts ranging from the most primitive to the most complicated scary ones. I won't get into much details, but I've been noticing a huge amount of unnatural activity."


H-a-c-k-e-r Friendly

Friday, May 16, 2008

Recommended Reading: Carpet Bombing in Cyberspace

The title is a misnomer - this article is a well written and thought provoking discussion on how the U.S. might build an offensive military cyber capability and what the ramifications would be of its use.

Col. Charles W. Williamson III wrote the feature article in Armed Forces Journal and begins with a discussion of the changing aspect of cyberspace in national defense. It gives several very good comparisons of the currently situation with previous challenges in military history - from Troy to WWII:
"Today, every Army outpost in America traces its roots to the walls, guards and gates of Troy. But none of today’s forts relies for boundary defense on anything more substantial than a chain-link fence, even though the base may contain billions of dollars in military equipment and the things most important to the soldiers — their families. The U.S. intends for defense of its “forts” to occur thousands of miles away. We intend to take the fight to the enemy before the enemy has a chance to come here. So, if the fortress ultimately failed, does history provide a different model?"
Col. Williamson reports on suggestions for creating a military botnet using existing Air Force systems to provide an U.S. offensive cyber capability and discusses defensive requirements.

However, probably the most interesting part of the article is the discussion of the pros and cons of developing and using this type of offensive capability:

"Lawyers have been known to trot out a “parade of horribles” to demonstrate weaknesses in an idea. These issues are difficult but not insurmountable. But before addressing them, it is important to note what the botnet is not.

"The af.mil botnet is not a replacement for law enforcement action or diplomacy. If the harm coming to U.S. systems is low enough that a military response is not required, the U.S. must default to traditional responses that respect the sovereignty of other nations, just as we expect them to respect our sovereignty and the primacy of our responsibility to stop harm coming to them from the U.S. With that understanding, what challenges remain?"


The article goes on to discuss several of the key concerns with offensive cyber warfare and attempts to address them. The most critical of these is The Difficulty in Identifying Source and Motive of Politically Motivated Computer Crimes. Col. Williamson writes:

"The truly difficult problems come in defending against attack from devices adversaries have captured from U.S. or allies’ civilians. Generally, the U.S. military is not going to attack a U.S. private computer. Harm coming from one of those machines will first be treated as a crime, and military forces should stay out of the situation in accordance with the Posse Comitatus Act. However, Title 10 of the United States Code, Section 333, allows the president to order use of the military in the U.S. under tightly controlled conditions when civil authorities are overborne.

"More challenging is the problem of an attack coming from an ally’s civilian computers. Obviously, the U.S. would seek allies’ cooperation if at all possible, but we could be in a position of launching an attack on a nation whom we have sworn to protect in a mutual defense pact. Together, the U.S. and its allies can reduce this risk by cooperating to maximize computer security. If we attack them as a matter of proportionate response, it would only be because computers in their territory are attacking us.

"The biggest challenge will be political. How does the U.S. explain to its best friends that we had to shut down their computers? The best remedy for this is prevention. The U.S. and its allies need to engage in a robust joint endeavor to improve net defense and intelligence to minimize this risk."


Regardless of whether you agree or disagree with the author, it is refreshing to see a well thought-out and nicely argued discussion on the topic of cyber warfare.

Thanks to Gareth Gange for the the pointer to this article.

Carpet bombing in cyberspace

Political Cyber Attacks As a Form of Censorship

Forbes magazine published an article discussing the censorship motive behind online political attacks against Estonia and Radio Free Europe.

The 2007 Estonia cyber attacks are some of the most widely reported and studied cyber attacks. Yet to date, no definitive conclusion can be made concerning the motive or exactly who sponsored the attacks. The article quotes various authorities who have widely varying theories of the motives behind the Estonia attacks. This is an excellent example of the difficulty in determining motive - or conversely, the ease in mis-identifying an attacker's motive.
"The difference between government-sponsored attacks and grassroots cyber terrorism is growing increasingly fuzzy, even as researchers try to sift through who did what on Estonia's Web. And the difficulty of tracing responsibility for even massive cyber attacks suggests that such maneuvers may become an effective tool not just for indiscriminate vandalism, but also for stealthy cyber censorship."


When Cyber Terrorism Becomes State Censorship

Attacks Target Specific Chinese Dialects

The Dark Visitor, a blog that tracks Chinese hacker activity, provides some technical details on attacks that selectively target systems based on the Chinese dialect used by web browsers. Although these types of attacks have been seen before, this is a good example of the trend toward selective targeting.

The post also provides a sample protest message sent in SQL-injection attacks:
"This is a mass invasion. Safeguard the motherland’s dignity!
F*** FRANCE! F*** CNN! I WILL ATTACK you ALWAYS !
I love my motherland!"


More Patriotic Hacking

Wednesday, May 14, 2008

NATO Announces Cyber Defence Centre in Estonia

NATO has announced it will open a Cooperative Cyber Defence (CCD) Centre of Excellence (COE) in Tallin, Estonia. This is in response to last year's cyber attacks against Estonia.
"The centre will conduct research and training on cyber warfare and include a staff of 30 persons, half of them specialists from the sponsoring countries, Estonia, Germany, Italy, Latvia, Lithuania, Slovakia and Spain."


NATO opens new centre of excellence on cyber defence

US Senate Report on Use of the Internet by Islamist Groups

The U.S. Senate Committee on Homeland Security and Governmental Affairs has released a report titled: "Violent Islamist Extremism, The Internet, and the Homegrown Terrorist Threat".

The following quotes [reformatted for readability] give an overview of the report's contents:

"This staff report concerns ... – how violent Islamist terrorist groups like al-Qaeda are using the Internet to enlist followers into the global violent Islamist terrorist movement and to increase support for the movement, ranging from ideological support, to fundraising, and ultimately to planning and executing terrorist attacks.

"In the second section of this report, we examine the increasing number of homegrown incidents and the judgments of the intelligence and law enforcement communities that there will likely be additional homegrown threats in the future.

"The third section explores the four-step radicalization process through which an individual can be enticed to adopt a violent Islamist extremist mindset and act on the ideology’s call to violence.

"Section four identifies the disturbingly broad array of materials available on the Internet that promote the violent Islamist extremist ideology. The availability of these resources is not haphazard, but is part of a comprehensive, tightly controlled messaging campaign by al-Qaeda and like-minded extremists designed to spread their violent message.

"The fifth section of the report examines how these materials facilitate and encourage the radicalization process.

"Finally, the report assesses the federal government’s response to the spread of the violent Islamist message on the Internet and concludes that there is no cohesive and comprehensive outreach and communications strategy in place to confront this threat."


Violent Islamist Extremism, The Internet, and the Homegrown Terrorist Threat

Zimbabwe State Newspaper Attacked in Protest of 1980s Killings

The BBC is reporting on an attack against the website of Zimbabwe's state-owned Herald newspaper. The report provides no technical details but links the attack to allegations that the government carried out mass killings in the 1980s:

"Headlines on the site were replaced by the word Gukurahundi.

"The word refers to a campaign of mass slaughter that the government has been accused of carrying out after independence."


Hackers shut Zimbabwe website

Friday, May 09, 2008

The Difficulty in Identifying Source and Motive of Politically Motivated Computer Crimes

In a textbook example of the difficulties in determining the true source and motive behind online attacks, there are several reports coming from Korea concerning the arrest of Chinese and Korean nationals involved in online identify thefts. In this case, the original attacks were attributed to Chinese 'hackers' attacking Korean systems for political reasons. This was because the attacks appeared to originate in China and the software used in the attack had an anti-Korean title.

However, in this case, it appears that Korean criminals involved in online identity thefts were using Chinese 'hackers' to gather the information for fraud:
"...Chinese hackers who claim there is something of a black market for Korean personal information in China. They say Koreans hire Chinese hackers to break into sites to get information, which is then handed over and sold in Korea."

"...the vice head of PR for “Auction” [eBay's Korean subsidiary] said on CBS radio last month that the hacking program employed in the attack was named “Fuck KR,” leading at the time to speculation that the attack was anti-Korean in nature."

This case demonstrated three important issues in analyzing politically motivated computer crimes (or any other computer crime):

1. Most attackers use a chain of connections between themselves and their target. Inexperienced investigators are often misled when they attribute the attack to the most immediate link. (This is not a new phenomena and has been employed for over 20 years by 'hackers'. See "International Intrusions: Patterns and Motives" specifically section 3 Intrusion Patterns and Dynamics for a discussion on how this technique was used in the 1980's and 1990's.)

2. 'Hackers' can be manipulated by more criminal elements thus disguising the actual motive behind the attack.

3. Motive is very difficult to determine in online attacks. There are many cases of politically motived computer crimes disguised as fraud or other types of attacks and also attacks (such as this example) where the motive is disguised as political. Another good example of this is the 'WANK' worm released in 1989:
"...in the internal network of Digital Equipment Corporation and later in the NASA / SPAN networks. This was jokingly named by the Australian authors as “Worms against Nuclear Killers” and has been misreported in several publications as an example of political hacking [See: Denning, Dorothy E., “Activism, Hacktivism, and Cyberterrorism: The Internet as a Tool for Influencing Foreign Policy”].

"However, the authors had no political motive in these attacks and were playing on the British meaning of the word 'wank' [Source: "Hacktivism & Politically Motivated Computer Crime"]."

Too often the source and motives behind attacks are attributed with little information or based on assumptions. This is inadequate when discussing cyberwar and when governments and corporations are considering online retaliation. Investigators and security professionals need better skills in determining actual sources and motives behind computer crimes - political or otherwise.

Also see Analyzing Goggle Attacks - Plenty of Room for Error


Auction Identity Thieves Nabbed

‘Auction’ Hacker Arrested in China?

NPR Report Discusses Online Attacks on Activists and Journalists

National Public Radio broadcast a report on attacks involving Chinese systems. The program discusses attacks targeting both Chinese opponents and attacks against pro-Chinese websites:

"Recently, Tibetan advocacy groups and China-based foreign journalists have been hit by a wave of sophisticated computer attacks that steal data, cripple Web sites and even monitor what computer users type on their computers.

"The attacks often come in the form of viruses attached to e-mails skillfully made to look like correspondence from people the recipient knows and trusts."


Cyber Attacks in China Target Activists, Journalists

Thursday, May 08, 2008

Cyberattacks against Belgium Attributed to China

Belgium has become the latest government to accuse China of attacks on their information infrastructures. As with other reports, there are no details or facts to allow proper analysis.

"Justice minister Jo Vandeurzen is reported to have claimed that the Federal Government had been targeted by Chinese hackers, backing up a separate statement by Belgium's foreign affairs minister, Karel De Grucht that his ministry had been hit by espionage in recent weeks.

"In both cases, the Belgians appear certain that the culprits were Chinese and that the Beijing authorities must know something about events, although no evidence has been offered to back up these allegations. The precise nature of the attacks has not been explained either."


Belgium accuses China of cyberattacks

EU Considers the Future of the European Network and Information Security Agency

EU lawmakers are considering extending funding for the European Network and Information Security Agency (ENISA) in response to cyber attacks on Estonia. However, the organization currently does not have the funding, remit or capability to act as an incident response organization:

"Euro-MPs believe Internet infrastructure security must be protected more effectively as the EU economy depends increasingly on a trouble-free Web.

"A lot of staff are simply pushing papers, making reports and not doing what we need them to do. It's something you might see in the Soviet Union. There is an increase in network security problems," said Reino Paasilinna, a Finnish socialist."

[Editor's Note: After this article was published, I received a clarification on the staffing issues at ENISA from Ulf Bergström, Press and Communications Officer at ENSIA:

‘This year ADM has 17 staff in total, of which 13 are TAs (stable since 2006) to service 66 planned staff members (TAs and contract agents, SNEs and stagiaires).

There’s nothing imbalanced at ENISA. ENISA is even better as some agencies with regard to this ratio. The minimum number of admin staff (that we have) sounds much larger when the overall size of the agency is low.

About his ratio there's nothing what we could more improve, as the financial regulation and the whole set of administrative rules sets a minimum number in order to guarantee sound financial management ("checks and balances").']


Euro-MPs back longer term for EU Web security body

Monday, May 05, 2008

Indian Government Systems Are Being Mapped and Probed from China

The Times of India is reporting on cyber attacks they believe originate from China. While technical detail is limited, the attacks appear to follow the same pattern as reported in the U.S. and Europe:
"The sustained assault almost coincides with the history of the present political disquiet between the two countries.

"According to senior government officials, these attacks are not isolated incidents of something so generic or basic as "hacking" — they are far more sophisticated and complete — and there is a method behind the madness.

"Publicly, senior government officials, when questioned, take refuge under the argument that "hacking" is a routine activity and happens from many areas around the world. But privately, they acknowledge that the cyber warfare threat from China is more real than from other countries.

"The core of the assault is that the Chinese are constantly scanning and mapping India’s official networks. This gives them a very good idea of not only the content but also of how to disable the networks or distract them during a conflict."

China mounts cyber attacks on Indian sites

Saturday, May 03, 2008

Increase in Hacktivism?

Online protest and hacktivist attacks are gaining more publicity but does this reflect a sudden increase in activity or just more press coverage? A recent blog posting concluding a sudden increase in activity has gained some media attention:

"While incidents of Hacktivism are not new, they are beginning to become a lot more frequent — perhaps due to the availability of tools to conduct hacktivist mischief, but also perhaps due to the ubiquitous social networking mechanisms which can now be used as to build consensus when times of cultural or political unrest present the opportunity.

In any event, Hacktivism is becoming a disturbing trend, and one which can have serious ripple effects that interfere with Internet operational continuity — sometimes in ways which we may have not even thought of yet."

While the availability of social networks and 'hacktivist' tools do contribute to both increasing number of attacks and their effectiveness, most professionals that closely follow politically motivated computer crimes and hacktivism believe there has been a steady increase in activity for several years, with ups and downs following political events in the real world (such as Olympic protests, Israeli-Palestinian conflicts, etc.). What has become more frequent is press coverage of attacks which creates a cycle of more activity followed by more press (see Hacktivism & Politically Motivated Computer Crime for a detailed analysis of the relationship between hacktivism and media coverage).


‘Hacktivism’ Incidents Escalate, Become More Frequent

Activists Swarm French Olympic Boycott Voting

The website of French magazine 'Capital', conducting an online poll concerning boycotting the 2008 Chinese Olympics, was flooded with votes, apparently from China.

"On the first day, we had about 300 responses, which was normal for this type of poll, and they were 80 percent in favour of a boycott. The next day there were 20,000 responses, with 80 percent opposing a boycott," he [Jean-Joel Gurviez, publisher of the website for Capital magazine] said.

"Almost all of the responses arrived via Chinese servers, Gurviez said, leading technicians to initially think the influx was driven by Chinese sites directing patriotic fans to vote.

"But a few days later we had hackers operating off servers in China try to change our content, and there were 2.5 million attempts to access protected files. We had to shut down the site temporarily," he said."


Hackers hit French magazine website over China poll