Tuesday, February 17, 2009

New Arrest in Indymedia Investigation in the U.K.

The investigation of the online activist site, Indymedia, as discussed several weeks ago, continues in the U.K. with the arrest of an individual hosting a server for the group. Police are investigating the publication of personal information belonging to a judge in an animal rights trial.

This case is an excellent study of the conflicting issues related to free speech and political dissent, the need to investigative crimes, international and cultural differences concerning privacy and how laws passed to give investigative powers in one area (terrorism) are quickly applied in unrelated areas (invasion of privacy).

Indymedia's view of the situation and events is provided below:

"This Monday, Kent Police arrested a man in Sheffield under the Serious Crime Act 2007 in relation to the recent Indymedia server seizure. His home was raided, all computer equipment and related papers taken. He was released after eight hours. The person had neither technical, administrative nor editorial access to the Indymedia UK website. He was only associated to the project by hosting its server.

"The arrest took place under Section 44-46 of the Serious Crime Act, which was passed into law on 1st October 2008 to combat serious international crime like drug trafficking, prostitution, money laundering and armed robbery. Sections 44-46 refer to “encouraging or assisting offences”.

"Kent police claim that they are after the IP address of the poster of two anonymous comments to a report about a recent animal liberation court case, which included personal details of the Judge. The IP address of the poster is not stored as Indymedia does not log IP addresses. This was acknowledged by British Transport Police in 2005, after the Bristol IMC server seizure.

"For the police to arrest the person who happened to sign the contract for server hosting, is sheer intimidation, in light of Indymedia’s openly stated policy of no IP logging.

"With the implementation of the EU Data Retention Directive in March 2009, the UK government attempts to turn every internet service provider in the country into part of the law enforcement apparatus. This legislation will provide a legal basis to track, intimidate, harass, and arrest people who are doing valuable and necessary work for social change, for example as peace activists, campaigners for economic and social justice or against police brutality."

Also of interest are the comments to this post discussing activists perceptions of this situation and similiar issues encountered by other political activists around the world.

Friday, February 13, 2009

DNI: Cyber Security a Top U.S. National Security Issue

The U.S. Director of National Intelligence, Dennis Blair, has provided his annual threat assessment to Congress. His Statement for the Record has been published and cyber security issues are defined as a major threat to the United States. Mr. Blair's statement includes the following summary of the threat (emphasis has been added):

"A growing array of state and non-state adversaries are increasingly targeting—for exploitation and potentially disruption or destruction—our information infrastructure, including the Internet, telecommunications networks, computer systems, and embedded processors and controllers in critical industries. Over the past year, cyber exploitation activity has grown more sophisticated, more targeted, and more serious. The Intelligence Community expects these trends to continue in the coming year.

"We assess that a number of nations, including Russia and China, have the technical capabilities to target and disrupt elements of the US information infrastructure and for intelligence collection. Nation states and criminals target our government and private sector information networks to gain competitive advantage in the commercial sector. Terrorist groups, including al-Qa’ida, HAMAS, and Hizballah, have expressed the desire to use cyber means to target the United States. Criminal elements continue to show growing sophistication in technical capability and targeting and today operate a pervasive, mature on-line service economy in illicit cyber capabilities and services available to anyone willing to pay. Each of these actors has different levels of skill and different intentions; therefore, we must develop flexible capabilities to counter each. We must take proactive measures to detect and prevent intrusions from whatever source, as they happen, and before they can do significant damage.

"We expect disruptive cyber activities to be the norm in future political or military conflicts. The Distributed Denial of Service (DDoS) attacks and Web defacements that targeted Georgia in 2008 and Estonia in 2007 disrupted government, media, and banking Web sites. DDoS attacks and Web defacements targeted Georgian government Web sites, including that of Georgian President Saakishvili, intermittently disrupting online access to the official Georgian perspective of the conflict and some Georgian Government functions but did not affect military action. Such attacks have been a common outlet for hackers during political disputes over the past decade, including Israel’s military conflicts with Hizballah and HAMAS in 2006 and 2008, the aftermath of the terrorist attacks in Mumbai last year, the publication of cartoons caricaturing the Prophet Mohammed in 2005, and the Chinese downing of a US Navy aircraft in 2001."
The report also discusses online activity by organized crime.

Annual Threat Assessment of the Intelligence Community for the Senate Select Committee on Intelligence

Recommended: Detailed Report on the State of Network and Information Security in Europe

For anyone that deals with cyber security issues in Europe, it is always a challenge to keep up on each member country's initiatives, institutions and regulations. A new report looks to be a valuable resource in navigating the complex European environment.

The European Network and Information Security Agency (ENISA) has published an extensive (over 600 pages) report on network and information security in its 30 member countries (the 27 EU member countries plus 3 members of the European Economic Community). This report is an excellent who's who of cyber security in Europe.

The report is structured by country and provided details of cyber security activities including:
  • General country information including statistics on IT use;
  • The major governmental and private stakeholders that set and implement cyber security policies and their relationships;
  • An overview and detailed look at current initiatives, focus points and activities of each entity;
  • Cyber security events taking place in each country;
  • Cyber security trends including information on security breaches
An excellent reference on the state of cyber security in Europe. Let's hope they plan to keep in updated.

ENISA Country Reports

Chinese Cyber Attacks Back in the News

Attacks from China have resurfaces in the news although its difficult to determine from the coverage if these are new attacks. In a recent interview, Rep. Bennie Thompson, Chairman of the House Homeland Security Committee, provided a few details concerning attack targets:

"Currency trading is among the financial networks targeted by hackers, Thompson said. An attack would be particularly damaging in light of the financial system’s troubled state, he said.

"He said electric utilities’ networks also have several points of weakness.

“We were provided alarming data on the vulnerability of our electrical grid in this country,” he said."

China strongly denies the allegations:

“Allegations that the Chinese government is behind cyber attacks against the U.S. computer networks are totally unwarranted and misleading for the America public,” Wang [Baodong, a spokesman for the Chinese Embassy in the U.S.] said in an e-mailed statement.

Wang said the Chinese government is “cracking down” on computer hacking and other cyber crimes.


Chinese Hackers Attack U.S. Computers, Thompson Says

Tuesday, February 10, 2009

More 'Political Hacking' in India

CyberMedia India Online (CIOL) looks at politically motivated computer crime in an article with the subtitle "Imagine if computer hackers, the daredevils of the networked world, turn into principled political activists".

The article mostly reviews incidents around the world, not all with political motivation. However, it does discuss some recent activity in India related to attacks that are alleged to have originated in Pakistan or are in support of Islamic causes:
"In a virtual act of mocking the cyber crime department of the police the official website of the Andhra Pradesh Crime Investigation Department (CID), www.cidap.gov.in, was hacked and defaced recently. Though no one has publicly claimed responsibility for the act, the abusive message posted on the website points to some Islamic fundamentalist group.

"The group had hacked nearly five India's site, including that of the ONGC, in a 'retaliatory' action against the hacking of the site of Pakistan's OGRA (Oil and Gas Regulatory Authority)

"Amidst reports from all over the world regarding hacking celebrity sites and other websites, the community site of the former President of India, Dr. APJ Kalam, in Orkut World, was recently targeted by Pakistani hackers."

Is hacking a war tool?

"Cyber War" to Protect Sharia Law?

In an article titled "Protection of Sharia (Islamic Law) and social reforms in AIMPLB [All India Muslim Personal Law Board]" the India-based ShahilOnline website is reporting on recent speeches given by Islamic scholars to more than 25,000 people.

During one of these speeches, the issue of cyberwar and technology came up:
"Moulana Salam Nadvi in his address said that the younger generation of the community should obtain higher education particularly they have to gain proficiency in the field of 'Information Technology' not for the purpose of accumulating wealth by getting employment in American companies in Bangalore, but to fight against the cyber-war being waged by anti-Islamic lobby particularly by western media [sic]."

Protection of Sharia (Islamic Law) and social reforms in AIMPLB

Monday, February 09, 2009

Why Are There No Internet Terrorist Attacks?

Strategy Page posted an analysis of the fact that we have not seen a significant Internet based terrorist attack:
"The Internet Jihad (struggle) has been mostly smoke, and very little fire.

"Attempts by terrorists to recruit hackers have had very poor results. There are a growing number of programmers and Internet specialists in the Moslem world, but most of them have legitimate jobs in software firms, or maintaining software and Internet services for companies."

The article also rightly points out that what little activity we have seen has been ineffective and isolated:

"At most, there have been some defacing of web pages, often by hackers driven more by nationalism than religion."

The post goes on to explain categorically why:

"Counter-terrorism organizations know why there have not been more of these attacks by al Qaeda, or any other self-proclaimed Islamic warriors. The fact is that the Islamic terrorists are not nearly as well organized or skilled as the mass media would lead you to believe."
The premise that we are not seeing major cyber terrorist attacks is correct but I disagree with the conclusion. The potential of the Internet is the fact that it does not take a lot of organization to exploit it's strengths (positively or negatively). This is why an individual or small (unorganized) group can have a presence and voice on the world stage. As the article points out, "there are Cyber War tools available that even the poorly educated terrorist computer user could operate."

If a group has the organization to recruit a suicide bomber, they have at least the potential to launch a cyber attack. Furthermore, if the almost chaotic organization of various hacktivist protesters can launch (mostly ineffective) cyber attacks then most terrorist organizations could do at least the same; and that's the key - the effectiveness of these types of attacks.

A more likely explanation is that they choose not to use them for the same reason that they choose not to carry out low-level physical attacks - only a large, physical attack causes the damage groups such as al-Qaeda believe furthers their cause - creating fear and inspiring their followers. Even the best DDoS attack would only cause temporary outages. It might gain some headlines (which the hacktivist is happy to have) but would hardly inspire uneducated Jihadists in the slums of Middle East cities to rise up.

Terrorists groups do see the power of the Internet for communication, intelligence gathering and propaganda and will continue to use it for these purposes. Only if they truly believe a cyber attack will further their cause will they be motivated to carry one out. Even then, it won't have the same impact as a physical attack - inconvenience does not translate to fear.


What Happened To The Internet Jihad?

Indian Summary of Davos Discussions

The Hindu Newspaper's Business Line reports on the discussions of cyber crime at the World Economic Forum in Davos and provides an Indian perspective:

"We, in India, have often seen reports of many Government of India Web sites being defaced, possibly from attacks originating from Pakistan.

"Fortunately these have been isolated instances, not amounting to a major cyber war. There is, however, no room for complacence. The government may not be able to share with us all that it has done to protect systems in India. We will have to rest content with the belief that we remain in a perpetual state of alertness to meet a severe challenge from neighbouring countries."


Don’t let down guard

Thursday, February 05, 2009

Guessing at the Source of Cyber Attacks

Yet another example of how difficult it is to determine both motive and source of cyber attacks. As with most "cyber war" attacks, it is pure speculation as to who is behind the latest activity against Kyrgyzstan and arguments can be made for any number of sources.

The New York Times has an article discussing two different possibilities for the most recent Kyrgyzstan attacks:
  1. Russian "cyber-militias" are attacking to intimidate the Kyrgyzstan government for any number of reasons; or,
  2. Kyrgyzstan hired Russian "hackers" to attack itself in order to "crackdown on an opposition party in Kyrgyzstan that uses the Internet to organize".
This is the danger: Without better intelligence and investigative capabilities, it will be next to impossible to determine exact source and motive. This leads to an inability to respond properly to a cyber attack or, potentially worse, responding inappropriately.

I have been involved in numerous complex, international cyber investigations where the source and motive were determined. However, it is almost never simple and requires extensive intelligence gathering and analysis (beyond basic Internet traffic analysis). This requires time and expenses beyond what most organizations are willing to invest in. Yet doing anything less leaves only guesswork.

Also see Analyzing Goggle Attacks - Plenty of Room for Error

Are ‘Cyber-Militias’ Attacking Kyrgyzstan?

NATO Officers Targeted by Trojan Code

This BBC article looks at several aspects of NATO cyber defenses including Trojan code that is specifically designed and targeted to NATO officers for espionage purposes:

"Mr Anil reveals that there has been more than one incidence of Nato officials being socially profiled, and then subjected to "targeted trojans".

"He explains how their unseen adversaries gather as much information as possible about the individual then send them an email purporting to come from a friend or a relative."


Nato's cyber defence warriors

Convergence of Electronic and Network Warfare

The Fort Leavenworth Lamp discusses the convergence of traditional electronic warfare (EW) with computer network operations (CNO):
"In the operational environment, the lines between CNO and EW are blurred," [Lt. Col. John] Bircher said. "We can use EW to disable our enemies' cellular phone device or we can use CNO to deny the device's access to its network."

"Do we use CNO or EW to deny our adversary, and does it matter to the tactical commander?" Bircher continued, "and in our conceptual research we found that it didn't matter. What's important is controlling the data, the bandwidth and the electromagnetic spectrum."

Electronic Warfare Proponent: Changes by adversaries, advances in technology drive EW's operational importance

Thailand Struggles with Internet Content

The Bangkok Post ran an lengthy article discussing the issue of freedom of speech and control of inappropriate content. Much of the article is concerned with controlling disparaging comments made online about the Thai Monarchy.

The article provides an excellent example of how each culture is struggling to deal with these issues and the difficulty in enforcing any regulations that are passed:
"Blocking content on over 2,000 web sites just prevents Thai residents accessing them while others worldwide still can. This method therefore cannot truly protect the honour of the monarchy," added Chiranuch Premchaiporn, director of Prachathai, an online news web site.

"The ICT [Information and Communication Technology] Ministry's combative stance on cyperspace is viewed as another draconian measure, in addition to the Computer Crime Act 2007 that deals with cyber-dissidents or online criminals. But the group at the seminars fears that such extreme measures will do more harm than good.

"We support the law and the policy to handle such crimes as hacking, deception, child pornography, pirate video clips, and theft of personal information, but the measure that allows state agents to block and close web sites can also lead to a violation of freedom of speech and limits public access to information," said Supinya Klangnarong, CPMR [the Campaign for Popular Media Reform]."

IN NETIZEN, WE TRUST

Wednesday, February 04, 2009

Social Networks Limit Undercover Work

Yet another "security" issue with social networks - intelligence agency recruitment:

"Herein lies the problem: if you're planning on having a second identity for undercover work, it doesn't help if your photos, friends and real name are splattered all over various social networking sites. Try finding a student at a university who hasn't done just that.

"The UK's intelligence agencies are worried. From schoolchildren on Bebo, through Facebook-obsessed young professionals, to well-networked CEOs on LinkedIn, having an online presence is a must in this day and age. But with the explosion of social networking sites, it has become virtually impossible to find recruits who don't have some sort of an online trail."

I would expect this to be a similar problem for law enforcement...

Social networking websites make recruiting spies difficult

Cyber Security Is a National Security Problem for the United States

Vice Adm. Carl Mauney, deputy commander for the U.S. Strategic Command told the 2009 Network Centric Warfare conference that "cyber security is a national security problem".

During his presentation he told the audience some of the problems the DoD is facing and that cyber defense required better coordination of effort:
"Also complicating cyber sleuths’ lives is the world’s billions of eye-blink-fast interconnected computers. But keeping up is vital. “Cyberspace has become a warfighting domain like land, sea, air, space,” Mauney told attendees. “And in light of growingly astute cyber enemies, it’s in our interest to maintain freedom of action,” he said.

"However, he cautioned, “It can’t be done in isolation.” There’s a “compelling need to integrate all elements of cyberspace operation and to [move] at net speed.” This is because the DOD on a daily basis faces millions of denial-of-service attacks, hacking, malware, bot-nets, viruses and other ruinous intrusions, some of which are associated with nations and nation-states, he said."
More importantly, Admiral Mauney stressed the need for individual accountability:
"What is needed is “a focus on accountability, from leadership to the user level. Our mindset needs to reflect the way we treat other military systems,” he said. “We don’t accept substandard performance in maritime, air and ground ops — and this is no different.” [emphasis added]

Hear Hear!


Greater cooperation needed to defeat cyber enemies

Europe Needs More Work on Cyber Defense

Trend News in Azerbaijan is reporting on a German DPA interview with Estonia's Minister of Defense concerning European readiness to defend against cyber attacks:

"For the time being, Europe's capability to defend itself from cyber-attacks is on the level of some of the capabilities of member states. Little value-added on the European level has been developed: we need to do more," he [Estonian Defence Minister Jaak Aaviksoo] said.

"In particular, the 27-member bloc must work harder to coordinate the efforts of various national defence and law-enforcement agencies and push for better cooperation with third countries which can serve as a safe haven for web-based attackers, he said."

Minister: Europe has not yet done enough on cyber-defence

Monday, February 02, 2009

Indymedia Server Seized - A Lesson in Network Resilience

Indymedia - one of the largest international clearinghouses of news and information for social activism - was recently raided by police in the UK. The raid was apparently the result of an investigation into the publication of personal information belonging to a trail judge in a comment to an article on an animal rights trial.

Indymedia had already removed the offending article per their own policies, however, police seized a server containing a large quantity of information:
"...by seizing this server they [the police] are not only getting information on Indymedia but also on wholly unrelated groups."
However, the seizure of the server did not interrupt Indymedia operations. Indymedia's network is highly distributed and redundant with extensive mirroring of data:
"As with previous cases, Indymedia UK stayed online this time. This was possible due to a system of "mirrors", which was set up to protect the technical infrastructure of the alternative media project. Despite the resource intensive interruptions caused by server seizures, the DIY-media activists continue to provide a platform for "news straight from the streets"."
Although it appears the police were not attempting to censor the information, this case shows both the flexibility, power and dynamic nature of online communication. However, this resilience cuts both ways: Activists and other politically motivated sites are difficult to censor or disrupt, but likewise, when commercial or government sites are the target of online protests by hacktivists, their online attacks often have limited or no operational impact on their targets for the same reason.

Other case studies of this phenomenon are documented in Hacktivism and Politically Motivated Computer Crime.

Police Seize UK Indymedia Server (Again)

Turkish "Hacker" Spied for PKK

The Turkish newsite,Today's Zaman, is reporting that a "hacker" originally arrested for theft is now accused of supporting the Kurdistan Workers' Party (PKK).

Analysis of his system and recovered media revealed classified information which he is alleged to have transferred to the PKK in Northern Iraq.

The article discusses an interesting method of obtaining the information:
"[The suspect] said during police interrogation that the contact between him and the PKK's Karayılan was established through a terrorist friend of his who resides in France. He also stated that he acquired confidential information belonging to the General Staff, MİT [the Turkish National Intelligence Organization] and other institutions through computer virus programs he placed on pornographic Web sites visited by army members."

PKK hacker faces up to 10 years in prison

Sunday, February 01, 2009

World Economic Forum Short on Answers to Cyber Warfare and Computer Crime

The World Economic Forum in Davos held a panel discussion on cyber threats and named cyber warfare as one of the top three (crime and the basic design of the web were the other two).

Most of the discussion of cyber warfare centered around Russian attacks against its neighbors but also discussed the difficulty of control on the Internet:

"...the internet[sic] is a global network, it doesn't obey traditional boundaries, and traditional ways of policing don't work," one expert said."
The panel also discussed what should be done about the problem and it appears from news reports that there were no new ideas. In fact, some panelists seemed to think just letting things work themselves out was the best answer:

"But several panellists worried about the heavy hand of government. The internet's strength was its open nature. Centralising it would be a huge threat to innovation, evolution and growth of the web.

"The amount of control required [to exclude all risk] is quite totalitarian," one of them warned.

"Instead they suggested to foster the civic spirit of the web, similar to the open source software movement and the team that had sorted the YouTube problem"

While no one wants "totalitarian" control of the Internet, it is dangerously naive to think that fostering "civic spirit" would even begin to make a dent in computer crime. In fact, one could argue that civic spirit is a major motivator for politically motivated cyber attacks.

Cybercrime threat rising sharply

Looking at the Pattern of Cyber Attacks from Russia

Terming cyberattacks against Russian's neighbors as "cyber bullying", Strategy Page provides a synopsis of previous attacks originating from Russia and discusses their escalation to the present attack against Kyrgyzstan. The article also discusses NATO reaction including the creation of the Cyber Defense Center in Estonia last year:
"The Center will study Cyber War techniques and incidents, and attempt to coordinate efforts by other NATO members to create Cyber War defenses, and offensive weapons."

CyberBully

Wednesday, January 28, 2009

A Cyber Iron Curtain?



HOSTEXPLOIT.com has published an interesting article summarizing recent cyber attacks allegedly originating from Russia and suggesting there is a new Cyber Iron Curtain:
"Hence from a ‘Cyber Iron-Curtain’ perspective there is now provided a ‘control at will’ by Russia of communication and increasing cyber influence over its former Soviet satellites, a modern parallel to Winston Churchill’s post second world war description of the Soviet sphere of influence. Separately, the blocking of these major websites in Kyrgyzstan suggests that we should probably move this country up the relative scale of importance for the monitoring cyberwar around the world."

Cyberwar – The Cyber Iron Curtain: Now Kyrgyzstan – Part 1

Denial-of-Service Attack against Kyrgzstan

The Wall Street Journal is reporting that Kyrgzstan's Internet infrastructure is under attack allegedly from Russia. There is very little detail in the report and only speculation on possible motives:
"Theories for the reason behind the current attack in Kyrgyzstan center on the U.S. use of an air base in the country to help with its military operations in Afghanistan. Another theory is that the attack was directed at the fledgling Kyrgyz opposition movement, which has used the Internet to express its discontent."
Wired Magazine offers a little more in-depth speculation:
"Using denial-of-service to clamp down opposition sounds a bit more plausible. During Kyrgyzstan's "Tulip Revolution" in 2005, demonstrators often depended on cell phones and text messages to organize. In post-Soviet states, where a smaller portion of the population is online, the authorities often allow the Internet to thrive as an outlet for dissent and free expression while clamping down on traditional media. But when the net becomes a more effective organizing tool -- or a more effective medium for investigative reporting -- the powers that be begin to take note."


Kyrgyzstan Knocked Offline (WSJ)

Russian 'Cyber Militia' Takes Kyrgyzstan Offline? (Wired)

Tuesday, January 27, 2009

Parent Support Website Attacked in China

In China, a webite was set up for parents of children affected by tainted milk. The Dark Visitor, a website that follows the computer underground in China, is reporting that the parent's website, jieshibaobao.com, has been attacked by "patriotic" hackers:
"A group of patriotic Chinese hackers have joined together to attack the website and force it down. They claim the website is illegal, posting photoshopped pictures and fabricating the condition of the patients. This casts a bad light on China’s period of prosperity and therefore, jieshibaobao.com has become the target of resentful patriotic youth."

Patriotic Chinese hackers attack website of melamine poisoned children

Egyptian Use of Socal Networks for Protest

Last week, I posted on how Saudis were using social networking sites to protest when physical protests were limited. The New York Times ran a lengthy report on the same phenomenon in Egypt:
"Freedom of speech and the right to assemble are limited in Egypt, which since 1981 has been ruled by Mubarak’s National Democratic Party under a permanent state-of-emergency law. An estimated 18,000 Egyptians are imprisoned under the law, which allows the police to arrest people without charges, allows the government to ban political organizations and makes it illegal for more than five people to gather without a license from the government. Newspapers are monitored by the Ministry of Information and generally refrain from directly criticizing Mubarak. And so for young people in Egypt, Facebook, which allows users to speak freely to one another and encourages them to form groups, is irresistible as a platform not only for social interaction but also for dissent."
The article discusses how social networks (Facebook in particular) and blogging was used to protest and discuss various aspects of the Gaza conflict:
"In most countries in the Arab world, Facebook is now one of the 10 most-visited Web sites, and in Egypt it ranks third, after Google and Yahoo. About one in nine Egyptians has Internet access, and around 9 percent of that group are on Facebook — a total of almost 800,000 members. This month, hundreds of Egyptian Facebook members, in private homes and at Internet cafes, have set up Gaza-related “groups.” Most expressed hatred for Israel and the United States, but each one had its own focus. Some sought to coordinate humanitarian aid to Gaza, some criticized the Egyptian government, some criticized other Arab countries for blaming Egypt for the conflict and still others railed against Hamas."
The article then looks at internal protest within Egypt, in particular, the April 6 Youth Movement that attempted to organize a national strike in Egypt. The case study not only shows how social networks can be used for protest but that they are not risk free:
"[Facebook] ...members who identified themselves as government security agents joined the April 6 group, too, posting comments under the insignia of the Egyptian police, and as April 6 approached, the government issued a strong warning against participation in the strike."
Shortly after, the Facebook organizer, Esraa Rashid was arrested.

The popularity of Egyptian and other online protests has caught the attention of the U.S. State Department:
"State Department officials ... believe that social-networking software like Facebook’s has the potential to become a powerful pro-democracy tool. They pointed to recent developments in Saudi Arabia, where in November a Facebook group helped organize a national hunger strike against the kingdom’s imprisonment of political opponents, and in Colombia, where activists last February used Facebook to organize one of the largest protests ever held in that country, a nationwide series of demonstrations against the FARC insurgency."


Revolution, Facebook-Style

Friday, January 23, 2009

China Releases a White Paper on National Defense

The Chinese government has released a white paper on their national defense strategy. The paper discusses information warfare and what the call the "informationizing" of the People's Liberation Army (PLA). The preface summarizes the cyber strategy:

"Conducting training in complex electromagnetic environments. The PLA is spreading basic knowledge of electromagnetic-spectrum and battlefield-electromagnetic environments, learning and mastering basic theories of information warfare, particularly electronic warfare. It is enhancing training on how to operate and use informationized weaponry and equipment, and command information systems. It is working on the informationizing of combined tactical training bases, and holding exercises in complex electromagnetic environments."

White paper on national defense published

Saudis Turn to the Internet for Protest

The Middle East Online discusses the increase in protest blogging in Saudi Arabia and makes the case that part of the driving force in its popularity is due to Saudi limitations on other forms of physical protest:
"Since the police’s dispersal of a demonstration in support for Palestinians in Gaza with rubber bullets and tear gas last December in the east of Saudi Arabia, hundreds of blogs and forums have flourished on the Web to carry out jihad (holy war) against Israel and the "puppet" Arab regimes."
This ability to voice anger and decent online has increased use of the Internet within the Kingdom:
"Today, the kingdom - with a population of 28.14 million, including 5.57 million expatriates - is under the influence of “Internet fever”. With over 6.2 million users in 2007, Saudi Arabia has got the 37th largest number of Internet users in the world, according to statistics compiled on December 18, 2008 by the CIA.

"By heavily showing their anger on the Web, Saudis prove they are the most faithful (Muslims) to the Palestinian cause," wrote a Saudi blogger.

"So we avoid the demagogy of rowdy street demonstrations," he added."
The article gives several examples of the use of blogs and social networks to vent anger over the Gaza conflict such as:
"We are the promoters of the Electronic Intifada. Our supporters are no less numerous than the demonstrators on the streets. We put our expertise to the resistance, to denounce the war against Gaza and the Arab silence ... without red lines to prevent us from expressing our anger," said a Saudi on YouTube."

Barrage of fire in Gaza, online ‘intifada’ in Saudi

Al Jazeera Report on Isaeli-Palistinian Online Conflict


Al Jazeera's English website has posted an analysis of the Israeli-Palestinian cyber conflict and provides a good summary of the classic pattern on online escalation:

"With the internet becoming a battleground of ideas, the average person, armed with a keyboard and an internet connection, became a participant in the conflict.

"On December 27, 2008, Israel launched 'Operation Cast Lead' against Hamas targets in the Gaza Strip. Within minutes of the first missile landing in Gaza, global reactions appeared online.

"During the first few days of the war, online discussions were restricted to war of words. Both sides engaged in heated debates and blamed each other for the fatal surge in military operations.

"As the discussions grew, attempts were then made by supporters of both sides to establish a coordinated response aimed at combatting [sic] the other side's propaganda."

Waging the web wars


Obama Adminstration Releases National Security Agenda Including Cyber Security

The new Obama Administration has posted their strategy for national security on the White House website. The document specifies a number of agenda items including terrorism, nuclear weapons and... information security.

The agenda is broad and encompasses many areas of information security that historically have been neglected, drowned in red tape and infighting or handed over to technical PhDs that can't see beyond the length of an encryption key to develop "solutions" that can't be implemented.

It remains to be seen if the new Administration can implement real change. However, if even a few of these initiatives were properly implemented it would be a major step forward.

Here is the full text of the cyber security section:

"Protect Our Information Networks

"Barack Obama and Joe Biden -- working with private industry, the research community and our citizens -- will lead an effort to build a trustworthy and accountable cyber infrastructure that is resilient, protects America's competitive advantage, and advances our national and homeland security. They will:

  • Strengthen Federal Leadership on Cyber Security: Declare the cyber infrastructure a strategic asset and establish the position of national cyber advisor who will report directly to the president and will be responsible for coordinating federal agency efforts and development of national cyber policy.

  • Initiate a Safe Computing R&D Effort and Harden our Nation's Cyber Infrastructure: Support an initiative to develop next-generation secure computers and networking for national security applications. Work with industry and academia to develop and deploy a new generation of secure hardware and software for our critical cyber infrastructure.

  • Protect the IT Infrastructure That Keeps America's Economy Safe: Work with the private sector to establish tough new standards for cyber security and physical resilience.

  • Prevent Corporate Cyber-Espionage: Work with industry to develop the systems necessary to protect our nation's trade secrets and our research and development. Innovations in software, engineering, pharmaceuticals and other fields are being stolen online from U.S. businesses at an alarming rate.

  • Develop a Cyber Crime Strategy to Minimize the Opportunities for Criminal Profit: Shut down the mechanisms used to transmit criminal profits by shutting down untraceable Internet payment schemes. Initiate a grant and training program to provide federal, state, and local law enforcement agencies the tools they need to detect and prosecute cyber crime.

  • Mandate Standards for Securing Personal Data and Require Companies to Disclose Personal Information Data Breaches: Partner with industry and our citizens to secure personal data stored on government and private systems. Institute a common standard for securing such data across industries and protect the rights of individuals in the information age."


THE AGENDA • HOMELAND SECURITY

Information Security Makes GAO High Risk Report for the 12th Year

The U.S. Government Accountability Office (GAO) has updated its list of governmental projects that are at risk "due to their greater vulnerabilities to fraud, waste, abuse, and mismanagement. GAO also identifies high-risk areas needing broad-based transformation to address major economy, efficiency, or effectiveness challenges."

Information security continues to make the list - for the 12th year. In the section titled: "Protecting the Federal Government’s Information Systems and the Nation’s Critical Infrastructures", the report makes note that the Department of Homeland Security (DHS) has made some progress but still falls short:
"Federal information security has been on GAO’s list of high-risk areas since 1997; in 2003, GAO expanded this high-risk area to include cyber CIP [Critical Infrastructure Protection]. The continued risks to information systems include escalating and emerging threats; the ease of obtaining and using hacking tools; the steady advance in the sophistication of attack technology; and the emergence of new and more destructive attacks."
Specifically, the report refers to numerous detailed past GAO reports and summarizes several areas requiring attention:
"Since 2006, GAO has made numerous recommendations in the following key areas:
  • bolstering cyber analysis and warning capabilities.
  • reducing organizational inefficiencies.
  • completing actions identified during cyber exercises.
  • developing sector-specific plans that fully address all cyber-related criteria.
  • improving cyber security of infrastructure control systems.
  • strengthening DHS’s ability to help recover from Internet disruptions.
"Until these and other key cyber security areas are effectively addressed, the nation’s cyber critical infrastructure is at risk of increasing threats posed by terrorists, nation-states, and others."
HIGH-RISK SERIES: An Update

Monday, January 19, 2009

A Look at the Future of U.S. Cyberwar

Aviation week takes a look at the future (and convergence) of cyber and other electronic warfare. Some of the more notable quotes from the article include:
"In a few years, the U.S. Army, Navy and Marine Corps expect to be delivering airborne electronic fires and cyber-attacks for ground troops with a fusion of radio battalions, EA-6B Prowlers, EA-18G Growlers and a range of UAVs."

"...As cyber- and electronic attack technologies emerge, it is becoming harder to distinguish between cyberwarfare, directed energy and electronic attack, intelligence gathering and information operations. Rationalization of all these elements also is complicated by shrinking manpower and funding."

"...However, researchers are worried that pieces of the digital puzzle are still missing - in particular, projection of new threats that foes may throw at the U.S."

Cyber-Attack Operations Near

Wednesday, January 14, 2009

Social Networks Becoming an Important Method of Online Protest

The importance of social networking in online protest is becoming more apparent during the Israeli Palestinian conflict in Gaza. The use of various networks such as YouTube and Flickr allow both side to show and tell their story but it appears that Facebook is where the action is.



These social networks are used by individuals, groups and governments to convey their messages, rally support, solicit donations and organize physical protests.

"On Dec. 30, the Israeli consulate in New York conducted a news conference on the war entirely on Twitter, the social messaging site where users communicate in short, rapid-fire notes, or "tweets."

"As a chance to field questions from a world audience, the experiment succeeded, but with questions and answers limited by Twitter to 140 characters, it didn't exactly make for nuanced discussion, even when consulate staffers rewrote the abbreviations." - McClatchy

"The IDF itself has also begun an Internet effort, making use of YouTube and a blog to post official army videos and information about the situation in Gaza. ...its videos had been viewed over 750,000 times. " - The Jerusalem Post
There are even meta-protest sites that allow visitors to vote or pick which side they want to support:
"It doesn't get any simpler than www.israel-vs-palestine.com, where visitors can just pick sides. With nearly 500,000 votes cast, the race is a virtual tie, while the Web site's server is overloaded." - McClatchy
This isn't limited to the current Israel-Gaza conflict. Ukraine-vs-Russia.com allows people to voice their opinion on the gas standoff with the EU.

Online and traditional media are increasingly reporting not just the use of social networking but their effectiveness:
"More than 1,000 students and ethnic minorities swarmed the streets of Hong Kong Sunday responding to a Facebook call to march against Israel’s deadliest assault yet on impoverished Gaza." - Saudi Gazette
Traditional social networks are not the only places online protest is showing up. Virtual worlds such as Second Life are developing protest movements as well:
"Virtual worlds have been left mostly to their own devices and the picture is somewhat different with no overt ‘official’ presence from the Israeli government or Hamas. Both sides of the conflict are therefore, represented in Second Life by, Second Life Israel and the Palestinian Holocaust Memorial Museum (slurl) hosted by the IslamOnline site. Second Life Israel (slurl) has been the focus of some limited protest within Second Life, while the Palestinian Holocaust Memorial Museum is much more of an information hub." - MetaSecurity
In fact, the issue of security and protest in virtual worlds now has its own blog, MetaSecurity.net which states its purpose as:

"... a blog that seeks to explore ideas relating to the security implications of virtual communities. The blog will post articles and commentary relating to security events in this rapidly growing sector. Specific topics include:

  • Fraud
  • Money Laundering
  • Inworld criminal activity
  • Legal responses
  • Inworld extremist acvivity
  • Software Security"
The introduction of social networks and virtual worlds has increased the relevance of online protest but the importance of the media in furthering online political causes is not new and was seen in the 1980s and 1990s:
"Politically motivated computer crime differs from traditional “hacking” in that the target is chosen - and the attack is designed - to effect a change in the behavior or activity of the victim. Therefore, a cyber attack, in isolation, most likely will not accomplish the goal of the attacker. It is for this reason that politically motivated cyber attacks are often combined with extensive public relation campaigns." - Politically Motivated Computer Crime and Hacktivism
It is obvious that this activity will evolve quickly. As the effectiveness of these types of protests increase, I'm sure we will see an increase in attempts to censor or block them. We're not in Kansas anymore...

Some other media quotes related to social network protest movements:

"As soon as Operation Cast Lead began to take shape just over a week ago, Dan Peguine started the program QassamCount, a system that updates users' statuses on Facebook with the number of Kassams that hit Israel.

"Within the first three days, 10,000 people had donated their statuses to the cause.

"Peguine first started a program counting Kassams about a week before the operation in Gaza began. He used Twitter, which sends users' statuses to all their "followers," to help people understand how often rockets hit the South" - The Jerusalem Post


"An enormous number of people around the world are using blogs, YouTube and social networking sites such as Facebook and Twitter to register their support or opposition to the war. Thousands of images — from Palestinians under siege in Gaza to Israeli neighborhoods that have been hit by Hamas rocket attacks — have filled photo-sharing sites such as Flickr and Picasa."

"So how are young people protesting the conflict in Gaza through Facebook? Well, in many, and often time creative ways, such as through status messages, notes, and most significantly through the formation of groups. Some of the groups that have been created in response to the airstrikes include, “Stop Israeli attacks on Gaza,” “Gaza is bleeding,” “Prayers for Gaza People,” and “Let’s collect 50,000 signatures to support the Palestinians in Gaza.” - The Examiner

Gaza War's New Front: Facebook (Wired Magazine)
Social networking boost for Gazans (Saudi Gazette)
Gaza war also being waged in cyberspace (McClathy)
Twitter, Facebook users show solidarity with QassamCount (The Jerusalem Post)
Gaza, Information War and Second Life (MetaSecurity)
Increased Use of Social Networks in Protests (PoliticalHacking)
Politically Motivated Computer Crime and Hacktivism

Online Attacks against Anti-War Group

The U.K. based anti-war group, "Stop the War", claims its website, Facebook and YouTube sites are being disrupted:

"Stop the War believes pro-Israeli groups could be behind the internet campaign, although a spokesman admitted it had no proof this was the case.

"A spokesman said of the cyber-war it was facing: "It's a well-known tactic. The same thing happened to us before our anti-Iraq war protests in 2003. We obviously can't prove any connection but the timing would suggest that it's a supporter of Israel."

"The spokesman told The Independent: "At the same time that our website was under attack, a number of videos went up on YouTube which claimed the demonstration had been cancelled. Someone posted notices on our Facebook groups saying the same thing."


Stop the War's website 'disabled by pro-Israeli hackers'

Tuesday, January 13, 2009

Timing Chinese Attacks?

With all the news, speculation and hysteria concerning cyber attacks from China, it would be great if we could predict when the "next big attack" will occur. Well, the Dark Visitor has provided just such an analysis and a 2009 calender to help get ready!

The conclusion:
"That’s right! [Chinese] Off days, holidays and late at night are the perfect time to cyber mobilize a massive number of people for a “Cyber People’s War”."

The perfect time for a massive Chinese cyber attack

Online Propaganda Explodes during Gaza Strip Conflict

Propaganda has always been a part of any conflict and the Israeli-Palestinian war is no exception. The Internet just makes dissemination faster, easier and to a wider audience than ever before.

The manipulation of video and other media is easier as well:

"As the Israeli military spokesman Major Avital Leibovich said, explaining why Israel had set up a YouTube page: "The Blogosphere and the new media are basically a war zone [in a battle for world opinion]."

"It is fitting, then, that the famous first casualty of war - truth - should have been so swiftly slain and laid to rest online.

"This month, both sides have posted hoax stories and misleading videos in order to demonise their opponents."

The article provides several examples.

Gaza propaganda war escalates on the internet

Monday, January 12, 2009

Radio Station Attacked by Jihadist Supporters

A U.K. radio station's website was defaced by Jihadist sympathizers in apparent support for Ahmed Al-Qahtani (who is suspected of involvement in the 9/11 attacks). The radio station also believes the attack may have been in retaliation for some of the Christmas music they had recently played.
"The site was compromised on Monday morning and again on Wednesday. The hijacker used the name ‘Soldier of Allah’ and ‘M03sl3m H4ck3rs’ - or Muslim Hackers written with numbers.

"The message warned: ‘Whoever thinks of insulting Islam or Muslims will suffer the same fate.
‘We are the nightmare of western websites in the cyber war.’

"The hackers claim they are defending Islam from harassment by America, Israel and Denmark."

Radio hijacked by Muslims as they are offended Cliff Richards halleluiah

NATO and US Army Systems Targeted by Palistinian Supports

Supports of Palestine have defaced several US Army, NATO and UN websites in the continuing escalation of cyber attacks related to the current situation in the Gaza Strip:
"Four websites belonging to the United States Army's Military District of Washington... have been defaced by a Turkish hacker affiliated with a group called “Peace Crew.” The attacker, who identified himself as Agd_Scorp, has posted threatening messages in English. “Stop attacks u Israel and USA! You cursed nations! One day Muslims will clean the world from you!,” the pages displayed.
"The website of the Joint Force Headquarters, National Capital Region... of the Northern Command has also been defaced by Agd_Scorp, and the same message has been posted along with the image of a Palestinian throwing a rock at a tank. In addition, the same attacker also hacked the websites of the NATO Parliamentary Assembly... and UNICEF Italy, in order to express his support for Palestine."

Palestinian Supporters Hack NATO and U.S. Army Sites

Botnet Set Up to Support Israel in Conflict

A group of Israeli supporters have set up a web site to download code to create a botnet allowing denial-of-service attacks against Palestinian targets. It appears to be modeled after a similar system used by Russian sympathizers during the Georgian conflict.
"Installing this program onto a computer will turn it into a drone, and will place it at the disposal of the hacktivists. What differentiates this tool from regular malware is that the installation is performed voluntarily by individuals who sympathize with Israel's efforts.
“Our goal is to use this power in order to disrupt our enemy's efforts to destroy the state of Israel. The more support we get, the more efficient we are,” the website set up by the group reads. The hackers included an uninstaller for the application and vowed to dismantle the botnet, once the conflict in Gaza Strip is over."


Botnet Tool to Support Israel's Offensive: End-users willingly turn their computers into zombies

Tuesday, January 06, 2009

U.K. Police Can Compromise Computer Systems without a Warrant

The U.K. Home Office has adopted plans to allow investigators to remotely search computers without a court order. The reports to date do not discuss the legal issues of using these techniques outside of the U.K.:
"Even though remote searching has existed in Britain since the '90s, when it was introduced as an amendment to the Computer Misuse Act, it has rarely been used until now and has been strictly controlled under the Regulation of Investigatory Powers Act. According to the new proposal, police forces or MI5 agents will be able to conduct such intrusive surveillance based merely on the decision of a senior officer that it is “proportionate” and necessary to the investigation of an offense that is punishable with a minimum sentence of three years in jail.

"In order to conduct the remote searching, the police will be able to act much like the cyber-criminals do, by developing malicious code, distributing the spyware via e-mail attachments, installing keylogging software or intercepting WLAN traffic. "

British Police Can Hack Computers Without Requiring Court-Issued Warrants

Monday, January 05, 2009

More Attacks on Israeli Websites

As expected, more reports of web defacements related to the Israeli-Palestinian conflict are coming in. Current estimate is around 10,000 websites have been attacked worldwide.

"The defacements have primarily affected small businesses and vanity Web pages hosted on Israel's .il Internet domain space. One such site was that of Israel's Galoz Electronics Ltd. On Wednesday, the hacked Web site read "RitualistaS GrouP Hacked your System!!! The world isn't insurance!!! For a better world."

"Other attackers have placed more incendiary messages condemning the U.S. and Israel and adding graphic photographs of the violence."
We should expect this trend to escalate as events on the ground continue.

With Gaza Conflict, Cyberattacks Come Too

Tunisia Bloggers Protest Government Censorship

Bloggers in Tunisia are debating an online protest against government censorship. The campaign known in English as Action Post Blank called for bloggers to only post a protest graphic on their website.

The article also discusses online action by the Tunisian government to censor websites:
"Numerous bloggers complained in 2008 of intrusions and blockages of websites by the Tunisian Internet Agency (ATI). Many Tunisians also accuse ATI of supporting bans on a number of popular websites. It was this issue that prompted journalist Ziad El Heni to file a lawsuit against the agency, accusing it of blocking the social networking website Facebook before it was re-opened last August based on an order from the President."

Online censorship protest turns into debate among Tunisian bloggers

Attacks on Israeli News Sites

Debkafile has reported a denial of service attack on its servers which they believe was in retaliation for Israel's military action in Gaza.
"DEBKAfile's two sites in English and Hebrew came under a massive cyber attack on our servers at the moment Israeli ground forces crossed into the Gaza Strip Saturday night, Jan. 3."

Important Notice

Sunday, January 04, 2009

Increased Use of Social Networks in Protests

MetaSecurity has posted a discussion and analysis of the use of social network sites by protest groups around the world.
"Networked inchoate anarchic protest is in itself a significant potential trend over the medium-term. The global economic crash will create new systems and ideas or at least new ways of using old ideas. As the Economist [magazine] notes the traditional mass staged rally aimed at G8 gatherings seems particularly quaint when put against the practice and potential of networked spontaneous protest. The key element these new technologies provide is the ability to amplify the protest message to a wider networked audience – this trend will only increase."

Globally Networked Anarchism (#Griot)

Indian and Pakistani Cyber Conflicts

UAE based The National ran an article on the ongoing and escalating cyber attacks between India and Pakistan with the following analysis:
"One New Delhi-based IT specialist, who works on government websites and did not want to be named for security reasons, said in the cyber war Pakistanis have an upper hand because Pakistani hackers are organised in groups whereas most of the Indian ones are working alone. Also, hackers based in Pakistan were motivated by religious reasons, experts said."

After Mumbai, Pakistan and India wage war in cyberspace

Friday, December 19, 2008

U.S. Unprepared for Cyber Attacks

Reuters reported on the results of a two-day "cyber war game" and concluded that the U.S. still is not prepared for a significant attack.
"Billions of dollars must be spent by both government and industry to improve security, said U.S. Rep. Dutch Ruppersberger of Maryland, the Democratic chairman of the intelligence subcommittee on technical intelligence."

This is unlikely without serious legislation and government regulation (see Commentary: U.S. CEOs to Assist in Critical Infrastructure Protection? - Not Likely).

The article goes on to quote U.S. Homeland Security Secretary Michael Chertoff:
"International law and military doctrines need to be updated to deal with computer attacks, Chertoff said.

"We know that if someone shoots missiles at us, they're going to get a certain kind of response. What happens if it comes over the Internet?," he said."


U.S. not ready for cyber attack

Wednesday, December 17, 2008

U.S. Nuclear Regulatory Commission Issues New Cyber Security Rules

The U.S. Nuclear Regulatory Commission (NRC) issued a press release concerning new security requirements for nuclear power plants. The release had one line referring to increased cyber security. No other details were provided:
"Additionally, there are new sections requiring a comprehensive cyber security program at nuclear power plants..."

NRC APPROVES FINAL RULE EXPANDING SECURITY REQUIREMENTS FOR NUCLEAR POWER PLANTS

Tuesday, December 16, 2008

2009 Georgia Tech Cyber Threat Report

The Georgia Tech Information Security Center (GTISC) 2nd annual report on cyber threats covers five broad areas of interest:
  1. Malware
  2. Botnets
  3. Cyber warfare
  4. Threats to VoIP and mobile devices
  5. The evolving cyber crime economy
The cyber warfare section provides a discussion of the Russian-Georgian cyber conflict and the uncanny timing between online and kinetic attacks and then quotes several security commentators on the situation.

The report concludes with a discussion of the need and types of government regulation required to address these threats.

The full report is available at:
Emerging Cyber Threats Report for 2009

Sunni-Shi'ite Cyber Attacks Motivated by Religious Beliefs




The Middle East Media Research Institute (MEMRI) has published a summary of the history and religious motivation of Sunni-Shi'ite cyber attacks:
"The Sunni-Shi'ite cyberwar started in 2007 when a group of Sunni hackers calling itself "XP Group" threatened to attack all Shi'ite websites on the Internet, and proceeded to hack some 120 Shi'ite sites."

Sunni groups escalated the cyber confrontation in 2008 adding the religious motivation behind the attacks:
"Among them were two groups called Shabab Al-Salafiyin and Al-Ayyoubiyoun. The latter declared on various forums that the war against Shi'ite sites was a form of jihad that brought one closer to Allah."

The article concludes with quotes from Egyptian columnist Diana Muqallid:
"Battles between Sunni and Shi'ite sites are being waged [on the Internet], with each side virtually killing and harming the other by targeting the websites of religious figures, political leaders, and media outlets... In our lifetimes, [we have seen] journalists murdered, incarcerated, tortured and exiled. Media outlets have been closed in our region or placed under supervision, [and their premises] have been burned down. Electronic attacks convey the very same sentiment of wanting to negate the other..."


Recent Rise in Sunni–Shi'ite Tension (Part I): Sunni – Shi'ite Hacker War on the Internet

View of Cyber Terrorism from Taipei

The Taipei Times ran an editorial (by a US author) on they growing threat of cyber-terrorism. Unfortunately, for the most part it simply rehashed recent international cyber events such as the Russian-Georgia-Estonia conflict. However, the article's summary did make several good points:
"Governments can hope to deter cyber attacks just as they deter nuclear or other armed attacks. But deterrence requires a credible threat of response against an attacker. And that becomes much more difficult in a world where governments find it hard to tell where cyber attacks come from, whether from a hostile state or a group of criminals masking as a foreign government.

"While an international legal code that defines cyber attacks more clearly, together with cooperation on preventive measures, can help, such arms-control solutions are not likely to be sufficient. Nor will defensive measures like constructing electronic firewalls and creating redundancies in sensitive systems.

"Given the enormous uncertainties involved, the new cyber dimensions of security must be high on every government’s agenda."


Modern society faces growing cyber-terror threat

Monday, December 15, 2008

Commentary: U.S. CEOs to Assist in Critical Infrastructure Protection? - Not Likely

Coverage and analysis of the report "Securing Cyberspace for the 44th Presidency" released by the Center for Strategic and International Studies continues.




A recent article from NetworkWorld discusses the recommendation to create a C-level panel of advisers called The President’s Committee for Secure Cyberspace. This panel would represent four key industries: Energy, finance, information technology/communications and government.
"The four industries were chosen for the committee because they “form the backbone of cyberspace. … Keep these sectors running and cyberspace will continue to deliver services in a crisis. Bring them down, and all other sectors will be damaged.”

There will be no problem getting CEOs to sit on a highly visible presidential committee where they can be seen to be doing something for little or no cost. However, expecting for-profit corporations to voluntarily make costly security changes and investments, especially during an economic down-turn, is wishful thinking at best. It will never happen. Remember, these are the same CEOs that require extensive ROIs for the most mundane security investment.

Therefore, the report also recommends new regulatory powers to force security changes:
"The report also seeks new regulations with the teeth to enforce standards that would establish a more secure infrastructure."

The article discusses several possible forms these regulations could take. Unfortunately, if past behavior provides any insight of future behavior, these regulations will be passed with little forethought or, if there is open discussion and debate, will be significantly weakened via lobbying when corporations realize the cost of compliance.

Top execs would roll up sleeves to fight cyber war, according to think tank study

Friday, December 12, 2008

Greenpeace Reports Computer Compromises Allow Environmental Damage in Brazil

Greenpeace has just released a story concerning a major investigation in Brazil in which computers that control the logging and exporting of timber in the Amazon rain forest have been compromised to allow logging companies to exceed their timber quotas:
"Police started investigating the suspect hackers in April 2007, swooping a couple of months later to arrest 30 ring leaders. One is still in jail - the intermediary who brought the hackers and the loggers together - and in total, 202 people are facing prosecution. "
Greenpeace is highlighting this activity in advance of a vote by the Brazilian congress allowing greater legal logging of timber:
"If this scandal weren't bad enough, it comes as the Brazilian national congress prepares to vote on a change to the country's forest code which could massively increase the amount of legal logging that will be allowed"

Hackers help destroy the Amazon rainforest

Wednesday, December 10, 2008

Calls to Define Cyberwar

One of the critical points made in the recently released report from the Commission on Cybersecurity for the 44th President was the need to actually define what is and is not cyber war.
"The U.S. military , meanwhile , lacks a formal doctrine on offensive military operations in cyberspace, although the Bush administration is " racing " to finalize such a policy before it leaves office, says one person familiar with the White House ' s work on the issue."
It is always concerning when we see a government body "racing" to do anything and this issue is too important to be done in a haphazard fashion.

However, the report does define three important questions that need to be answered sooner rather than later:

"There are three central issues with which the international legal community must grapple as the debate continues, says James Lewis, the project director of the Commission on Cybersecurity of the 44th Presidency, which issued its report this week. Each country might have different answers, but the questions will be universal.

  • "At what point does a cyberattack constitute an act of war or a violation severe enough to justify a response?
  • "How do we protect the civil liberties of the Internet-using public while improving security?
  • "Which legal authorities will assume responsibility for investigating a cyberattack—the intelligence community, the military, or law enforcement?"
Answering these questions, combined with the creation of Rules of Engagement for Cyber Warfare and better investigative capabilities to determine actual source and motive, would be excellent first steps in gaining some measure of control over the situation.

When Do Online Attacks Cross the Line Into Cyberwar?

Monday, December 08, 2008

China to Require Disclosure of Security

The Chinese government is moving forward with plans to require companies operating in China to obtain approval before using any type of security technology. The rules are scheduled to take effect May 1, 2009 and have resulted in pressure from the U.S. government to scrap the requirement.
"Giving [Chinese] regulators the power to reject foreign technologies could help to promote sales of Chinese alternatives. But that might disrupt foreign manufacturing, research or data processing in if companies have to switch technologies or move operations to other countries to avoid the controls. Requiring disclosure of technical details also might help Beijing read encrypted e-mail or create competing products."


China irks US with computer security review rules

Thursday, December 04, 2008

Myopic Focus on Technology Creates "Achilles' Heel" in Military Cyber Security

One of the greatest failures of both commercial and governmental IT security programs is their tactical and myopic focus on technology at the expense of the larger issues in understanding and mitigating cyber threats. These include organizational, process and people issues.

This dysfunctional situation was noted during a keynote address by the U.S. Air Force's chief information officer, Lt. Gen. Michael Peterson:

"This is our Achilles' heel," he said. "It's not about a denial-of-service attack; it's about the information on the network -- ensuring it's accurate, protected, and available. [But] we're still fighting over what patch to put on."

Lt. General Peterson also tried to put military cyber attacks in a more strategic perspective:

"Despite Russia's cyberwarfare tactics against Estonia and Georgia, Peterson said an all-out cyberwar won't happen; instead, cyberattacks will become one of many combat strategies used by adversaries to bring government to its knees.

"It won't be a pure fight," he said. "It will incorporate all domains … The battle is ongoing and these guys are very good."

Air Force CIO says cybersecurity federal "Achilles' heel"

U.S. Military Officials Look to Obama Administration for Better Cyber Security

StratagyPage.com is reporting that cyber attacks against U.S. military systems are not only growing in numbers but they are being targeted against specific information or individuals.

The article also claims that U.S. military officials want the new Administration to give a higher priority to cyber security:
"U.S. commanders are hoping president-elect Obama, the most computer literate presidents ever, will provide more support for Cyber War efforts, both defensive and offensive."

Pentagon Pounding Persists

Australian Prime Minister Sees National Cyber Threat

Prime Minister Kevin Rudd commented in Australia's National Security Statement that technological dependence and cyber threats from "hackers, ...commercial entities and foreign states" place Australia's information infrastructure at risk. Prime Minister Rudd stated:
"The irony of technology today is that, while on the one hand we are seeking to invest in sophisticated information, intelligence and military technology, on the other, we have to protect ourselves from the extreme use of basic, readily available technology and hardware by terrorist groups."

Hacker threat: Rudd promises action

Wednesday, December 03, 2008

Media Coverage of Cyber Attacks on U.S. Military Systems in Afghanistan

There have been several sketchy news articles on attacks against unclassified U.S. military systems in Afghanistan resulting in the banning of removable media by the U.S. Army's Strategic Command.

This article summarizes a variety of other media coverage. Once again, China is alleged to be the source of the attacks with little or no data related to the true motive or source of the attacks:
"According to the same source, there is still no indication whether the Chinese hackers were sponsored by the government in Beijing or if they were working independently. This seems to be a recurring question that never gets its answer, even though it is not the first time that attacks on U.S. government systems originate in China."

Cyber-Attack Cripples Critical U.S. Military Networks

Sunday, November 30, 2008

Rules of Engagement for Cyber Warfare

An interesting article calling for the development of rules of engagement for cyber warfare:
"Cyber attack and warfare rules of engagement will undoubtedly require hundreds of pages to establish a decision framework. That being said, there are a few critical areas that will pose the most significant challenge to policy makers. One of these areas will be the level of confidence in the identification of the entity behind an attack on a nation. Tracing and tracking cyber attacks back to those responsible is not an easy task. Usually this takes months or years not minutes and hours. Current intelligence and surveillance capabilities will provide only minimal assistance in this effort."

Cyber Attacks & Warfare - Rules of Engagement

Friday, November 28, 2008

More Indian-Pakistani Cyber Attacks

As an update to the previous post, further reports of tit-for-tat cyber attacks between Indian and Pakistani "hackers" are surfacing. From the Indian online business magazine, domain-b.com:

"Hostilities between India and Pakistan seem to have reached cyberspace even as the two neighbors strive to resolve differences through dialogue. The first casualty in the cyber war appears to be the Andhra Pradesh Crime Investigation Department (CID) website that was hacked by pro-Pakistan hackers.

"Ohter [sic] Indian web sites that have come in for similar treatment are web sites of Bank of Baroda and that of a news channel."

And from the Pakistani Daily website:

"In what seems to be an intensifying cyber war between hackers of Pakistan and India, Pakistani hackers managed to hack website of ONGC (Oil and Natural Gas Corporation) of India on Tuesday.

"A group named ‘Pakistan Cyber Army’ (PCA) said that it hacked Indian ONGC website in response to hacking of the website of Pakistan’s OGRA (Oil and Gas Regulatory Authority) by Indian hackers."

Andhra Police website hacked

Pakistani group hacks Indian websites

Ongoing Indian-Pakistani Cyber Attacks

Underneath the current terrorist attacks in Mumbai, a string of cyber attacks between Indian and Pakistani groups has been simmering for the last few weeks. At this point, the intrusions do not seem related to the ongoing physical attacks, however, with the potential for tensions between the two countries to intensify, cyber attacks will almost certainly increase as well.
"The cyber warfare began in mid-November when an Indian group of hackers known as HMG or "Guards of Hindustan" defaced the website of Pakistan's Oil and Gas Regulatory Authority and deleted all its data."

"Apparently acting in retaliation, a group calling itself the Pakistan Cyber Army (PCA) yesterday [25-Nov-2008] hacked five Indian websites, including those of ONGC, Indian Institute of Remote Sensing (IIRS), Indian Railways and the Kendriya Vidyalaya in Ratlam."

Indian, Pak hackers deface govt websites

Thursday, November 20, 2008

REVIEW: 2008 Report on US-China Economic and Security Review

The U.S.-China Economic and Security Review Commission has published its 2008 report to the U.S. Congress. As in previous years, the report discusses Chinese Cyber capabilities and initiatives. This year's report concludes:
"The Nature and Extent of China’s Space and Cyber Activities and their Implications for U.S. Security
  • Cyber space is a critical vulnerability of the U.S. government and economy, since both depend heavily on the use of computers and their connection to the Internet. The dependence on the Internet makes computers and information stored on those computers vulnerable.
  • China is likely to take advantage of the U.S. dependence on cyber space for four significant reasons. First, the costs of cyber operations are low in comparison with traditional espionage or military activities. Second, determining the origin of cyber operations and attributing them to the Chinese government or any other operator is difficult. Therefore, the United States would be hindered in responding conventionally to such an attack. Third, cyber attacks can confuse the enemy. Fourth, there is an underdeveloped legal framework to guide responses.
  • China is aggressively pursuing cyber warfare capabilities that may provide it with an asymmetric advantage against the United States. In a conflict situation, this advantage would reduce current U.S. conventional military dominance."
The report provides further details into U.S. perceptions of Chinese cyber capabilities and intentions including:
"China has an active cyber espionage program. Since China’s current cyber operations capability is so advanced, it can engage in forms of cyber warfare so sophisticated that the United States may be unable to counteract or even detect the efforts."

"By some estimates, there are 250 hacker groups in China that are tolerated and may even be encouraged by the government to enter and disrupt computer networks. The Chinese government closely monitors Internet activities and is likely aware of the hackers’ activities. While the exact number may never be known, these estimates suggest that the Chinese government devotes a tremendous amount of human resources to cyber activity for government purposes. Many individuals are being trained in cyber operations at Chinese military academies..."

"In the past two decades, China has observed how the U.S. military has operated successfully overseas and also has noted that the United States in many cases utilizes a deployment or buildup phase. Examples include the first Gulf War, Kosovo, and Operation Iraqi Freedom. Due to the great distances in the Pacific area of operations, were the United States to think a conflict near China was probable, the U.S. military would begin its preparations with a deployment or buildup phase. China is depending on this and believes that, by cyber attacking U.S. logistics functions in the early buildup stages of a conflict, it can delay or disrupt U.S. forces moving to the theater. This conceivably could alter the course of a conflict over Taiwan."

The report discusses China's motivation to develop cyber warfare capabilities:
"...authors of China’s military doctrine have articulated five key elements. These elements are the following:
  • Defense. Many Chinese authors believe the United States already is carrying out offensive cyber espionage and exploitation against China. China therefore must protect its own assets first in order to preserve the capability to go on the offensive.
  • Early use. PLA analysts believe that in many cases a vulnerable U.S. system could be unplugged in anticipation of a cyber attack. Therefore, for an attack to be truly effective, it must be launched early in a conflict before the adversary has time fully to protect itself.
  • Information operations. Cyber operations can be used to manipulate an adversary’s perception of the crisis, such as by planting misinformation. This could obviate the need for a conventional confrontation or advantageously shape an adversary’s response.
  • Attacking an enemy’s weaknesses. China’s strategists believe the United States is dependent on information technology and that this dependency constitutes an exploitable weakness.
  • Preemption. Many PLA strategists believe there is a first mover advantage in both conventional and cyber operations against the United States. Therefore, in order to succeed, they should strike first."
Finally, the report notes the vulnerabilities to telecommunication systems:
"The global supply chain for telecommunications items introduces another vulnerability to U.S. computers and networks. Components in these computers and networks are manufactured overseas— many of them in China. At least in theory, this equipment is vulnerable to tampering by Chinese security services, such as implanting malicious code that could be remotely activated on command and place U.S. systems or the data they contain at risk of destruction or manipulation. In a recent incident, hundreds of counterfeit routers made in China were discovered being used throughout the Department of Defense. This suggests that at least in part, Defense Department computer systems and networks may be vulnerable to malicious action that could destroy or manipulate information they contain."

The full report is available at:

2008 REPORT TO CONGRESS of the U.S.-CHINA ECONOMIC AND SECURITY REVIEW COMMISSION

ITU Passes Anti-Cyberwar Resolution

The International Telecommunication Union (ITU) has passed a resolution to attempt to curb cyber warfare between nation states. The core of the resolution states:
"resolves to invite Member States
  1. to refrain from taking any unilateral and/or discriminatory actions that could impede another Member State from accessing public Internet sites, within the spirit of Article 1 of the ITU Constitution and the WSIS principles;
  2. to report to the Director of the Telecommunication Standardization Bureau on any incident referred to in 1 above,"
"instructs the Director of the Telecommunication Standardization Bureau
  1. to integrate and analyse the information on incidents reported from Member States;
  2. to report this information to Member States, through an appropriate mechanism,"
"invites Member States and Sector Members

to submit contributions to the ITU-T study groups that contribute to the prevention and avoidance of such practices."
The full resolution is available here:

Resolution 69 – Non-discriminatory access and use of Internet resources

For a broader view of the political context this resolution is mired in and the international infighting between Internet governance organizations see:

Controversy Over Internet Governance: ITU Families And ICANN Cosmetics?

Wednesday, November 19, 2008

Israeli "Hackers" Penetrate Gaza Phone Network to Offer Reward

StrategyPage.com reports of an intrusion into the Gaza phone network to offer rewards for the return of an Israeli soldier:
"Israeli Cyber War troops again hacked into the cell phone networks in Gaza, and sent a message offering a $10,000 reward for anyone who could provide information that led to the rescue of kidnapped Israeli soldier Gilad Shalit."



Tuesday, November 18, 2008

Estonian Spy Passes NATO Cyber Defense Info to Russians

In September 2008, Herman Simm, an Estonian defense ministry official and Estonia's liaison with NATO, was arrested for allegedly passing NATO classified information to Russia. The U.K. Times is reporting that some of that information included NATO cyber security strategies:

"...Mr Simm was not some relic from the days of Kim Philby or other notorious deep-cover agents. He was at the cutting edge of one of Nato’s most important new strategic missions: to defend the alliance against cyber-attack.

"Mr Simm headed government delegations in bilateral talks on protecting secret data flow. And he was an important player in devising EU and Nato information protection systems."


Russian spy in Nato could have passed on missile defence and cyber-war secrets

Mauritanian Government Shuts Down Critics with Botnet Attacks

StrategyPage reports on use of bot nets by the Mauritanian government to censor online critics. No sources or technical details are given in the article:
"In the African nation of Mauritania, the military dictatorship has used Cyber War techniques to shut down two opposition web sites that provide the most information on what is going on inside the country. The generals apparently hired several botnets" to perform denial-of-service attacks.

Dictators Prefer Botnets

Saturday, November 15, 2008

IMF Systems Compromised

There are several reports of allegations that the International Monetary Fund (IMF) systems were penetrated last month with speculation that the source of the attacks was China. The Dark Visitor, a site that follows the Chinese computer underground, reports on why the Chinese might be interested in IMF communications.

Chinese hackers hit International Monetary Fund