Monday, May 19, 2008

Cyber Attacks Against Palestinian Bloggers

Picked up a short blog posting concerning the high volume of attacks against bloggers who post articles concerning issues in Palestine. The article doesn't specify any technical details nor speculate on the source or motive...
"It's funny how every time I write about Palestine, I get a slew of hack attempts ranging from the most primitive to the most complicated scary ones. I won't get into much details, but I've been noticing a huge amount of unnatural activity."


H-a-c-k-e-r Friendly

Friday, May 16, 2008

Recommended Reading: Carpet Bombing in Cyberspace

The title is a misnomer - this article is a well written and thought provoking discussion on how the U.S. might build an offensive military cyber capability and what the ramifications would be of its use.

Col. Charles W. Williamson III wrote the feature article in Armed Forces Journal and begins with a discussion of the changing aspect of cyberspace in national defense. It gives several very good comparisons of the currently situation with previous challenges in military history - from Troy to WWII:
"Today, every Army outpost in America traces its roots to the walls, guards and gates of Troy. But none of today’s forts relies for boundary defense on anything more substantial than a chain-link fence, even though the base may contain billions of dollars in military equipment and the things most important to the soldiers — their families. The U.S. intends for defense of its “forts” to occur thousands of miles away. We intend to take the fight to the enemy before the enemy has a chance to come here. So, if the fortress ultimately failed, does history provide a different model?"
Col. Williamson reports on suggestions for creating a military botnet using existing Air Force systems to provide an U.S. offensive cyber capability and discusses defensive requirements.

However, probably the most interesting part of the article is the discussion of the pros and cons of developing and using this type of offensive capability:

"Lawyers have been known to trot out a “parade of horribles” to demonstrate weaknesses in an idea. These issues are difficult but not insurmountable. But before addressing them, it is important to note what the botnet is not.

"The af.mil botnet is not a replacement for law enforcement action or diplomacy. If the harm coming to U.S. systems is low enough that a military response is not required, the U.S. must default to traditional responses that respect the sovereignty of other nations, just as we expect them to respect our sovereignty and the primacy of our responsibility to stop harm coming to them from the U.S. With that understanding, what challenges remain?"


The article goes on to discuss several of the key concerns with offensive cyber warfare and attempts to address them. The most critical of these is The Difficulty in Identifying Source and Motive of Politically Motivated Computer Crimes. Col. Williamson writes:

"The truly difficult problems come in defending against attack from devices adversaries have captured from U.S. or allies’ civilians. Generally, the U.S. military is not going to attack a U.S. private computer. Harm coming from one of those machines will first be treated as a crime, and military forces should stay out of the situation in accordance with the Posse Comitatus Act. However, Title 10 of the United States Code, Section 333, allows the president to order use of the military in the U.S. under tightly controlled conditions when civil authorities are overborne.

"More challenging is the problem of an attack coming from an ally’s civilian computers. Obviously, the U.S. would seek allies’ cooperation if at all possible, but we could be in a position of launching an attack on a nation whom we have sworn to protect in a mutual defense pact. Together, the U.S. and its allies can reduce this risk by cooperating to maximize computer security. If we attack them as a matter of proportionate response, it would only be because computers in their territory are attacking us.

"The biggest challenge will be political. How does the U.S. explain to its best friends that we had to shut down their computers? The best remedy for this is prevention. The U.S. and its allies need to engage in a robust joint endeavor to improve net defense and intelligence to minimize this risk."


Regardless of whether you agree or disagree with the author, it is refreshing to see a well thought-out and nicely argued discussion on the topic of cyber warfare.

Thanks to Gareth Gange for the the pointer to this article.

Carpet bombing in cyberspace

Political Cyber Attacks As a Form of Censorship

Forbes magazine published an article discussing the censorship motive behind online political attacks against Estonia and Radio Free Europe.

The 2007 Estonia cyber attacks are some of the most widely reported and studied cyber attacks. Yet to date, no definitive conclusion can be made concerning the motive or exactly who sponsored the attacks. The article quotes various authorities who have widely varying theories of the motives behind the Estonia attacks. This is an excellent example of the difficulty in determining motive - or conversely, the ease in mis-identifying an attacker's motive.
"The difference between government-sponsored attacks and grassroots cyber terrorism is growing increasingly fuzzy, even as researchers try to sift through who did what on Estonia's Web. And the difficulty of tracing responsibility for even massive cyber attacks suggests that such maneuvers may become an effective tool not just for indiscriminate vandalism, but also for stealthy cyber censorship."


When Cyber Terrorism Becomes State Censorship

Attacks Target Specific Chinese Dialects

The Dark Visitor, a blog that tracks Chinese hacker activity, provides some technical details on attacks that selectively target systems based on the Chinese dialect used by web browsers. Although these types of attacks have been seen before, this is a good example of the trend toward selective targeting.

The post also provides a sample protest message sent in SQL-injection attacks:
"This is a mass invasion. Safeguard the motherland’s dignity!
F*** FRANCE! F*** CNN! I WILL ATTACK you ALWAYS !
I love my motherland!"


More Patriotic Hacking

Wednesday, May 14, 2008

NATO Announces Cyber Defence Centre in Estonia

NATO has announced it will open a Cooperative Cyber Defence (CCD) Centre of Excellence (COE) in Tallin, Estonia. This is in response to last year's cyber attacks against Estonia.
"The centre will conduct research and training on cyber warfare and include a staff of 30 persons, half of them specialists from the sponsoring countries, Estonia, Germany, Italy, Latvia, Lithuania, Slovakia and Spain."


NATO opens new centre of excellence on cyber defence

US Senate Report on Use of the Internet by Islamist Groups

The U.S. Senate Committee on Homeland Security and Governmental Affairs has released a report titled: "Violent Islamist Extremism, The Internet, and the Homegrown Terrorist Threat".

The following quotes [reformatted for readability] give an overview of the report's contents:

"This staff report concerns ... – how violent Islamist terrorist groups like al-Qaeda are using the Internet to enlist followers into the global violent Islamist terrorist movement and to increase support for the movement, ranging from ideological support, to fundraising, and ultimately to planning and executing terrorist attacks.

"In the second section of this report, we examine the increasing number of homegrown incidents and the judgments of the intelligence and law enforcement communities that there will likely be additional homegrown threats in the future.

"The third section explores the four-step radicalization process through which an individual can be enticed to adopt a violent Islamist extremist mindset and act on the ideology’s call to violence.

"Section four identifies the disturbingly broad array of materials available on the Internet that promote the violent Islamist extremist ideology. The availability of these resources is not haphazard, but is part of a comprehensive, tightly controlled messaging campaign by al-Qaeda and like-minded extremists designed to spread their violent message.

"The fifth section of the report examines how these materials facilitate and encourage the radicalization process.

"Finally, the report assesses the federal government’s response to the spread of the violent Islamist message on the Internet and concludes that there is no cohesive and comprehensive outreach and communications strategy in place to confront this threat."


Violent Islamist Extremism, The Internet, and the Homegrown Terrorist Threat

Zimbabwe State Newspaper Attacked in Protest of 1980s Killings

The BBC is reporting on an attack against the website of Zimbabwe's state-owned Herald newspaper. The report provides no technical details but links the attack to allegations that the government carried out mass killings in the 1980s:

"Headlines on the site were replaced by the word Gukurahundi.

"The word refers to a campaign of mass slaughter that the government has been accused of carrying out after independence."


Hackers shut Zimbabwe website

Friday, May 09, 2008

The Difficulty in Identifying Source and Motive of Politically Motivated Computer Crimes

In a textbook example of the difficulties in determining the true source and motive behind online attacks, there are several reports coming from Korea concerning the arrest of Chinese and Korean nationals involved in online identify thefts. In this case, the original attacks were attributed to Chinese 'hackers' attacking Korean systems for political reasons. This was because the attacks appeared to originate in China and the software used in the attack had an anti-Korean title.

However, in this case, it appears that Korean criminals involved in online identity thefts were using Chinese 'hackers' to gather the information for fraud:
"...Chinese hackers who claim there is something of a black market for Korean personal information in China. They say Koreans hire Chinese hackers to break into sites to get information, which is then handed over and sold in Korea."

"...the vice head of PR for “Auction” [eBay's Korean subsidiary] said on CBS radio last month that the hacking program employed in the attack was named “Fuck KR,” leading at the time to speculation that the attack was anti-Korean in nature."

This case demonstrated three important issues in analyzing politically motivated computer crimes (or any other computer crime):

1. Most attackers use a chain of connections between themselves and their target. Inexperienced investigators are often misled when they attribute the attack to the most immediate link. (This is not a new phenomena and has been employed for over 20 years by 'hackers'. See "International Intrusions: Patterns and Motives" specifically section 3 Intrusion Patterns and Dynamics for a discussion on how this technique was used in the 1980's and 1990's.)

2. 'Hackers' can be manipulated by more criminal elements thus disguising the actual motive behind the attack.

3. Motive is very difficult to determine in online attacks. There are many cases of politically motived computer crimes disguised as fraud or other types of attacks and also attacks (such as this example) where the motive is disguised as political. Another good example of this is the 'WANK' worm released in 1989:
"...in the internal network of Digital Equipment Corporation and later in the NASA / SPAN networks. This was jokingly named by the Australian authors as “Worms against Nuclear Killers” and has been misreported in several publications as an example of political hacking [See: Denning, Dorothy E., “Activism, Hacktivism, and Cyberterrorism: The Internet as a Tool for Influencing Foreign Policy”].

"However, the authors had no political motive in these attacks and were playing on the British meaning of the word 'wank' [Source: "Hacktivism & Politically Motivated Computer Crime"]."

Too often the source and motives behind attacks are attributed with little information or based on assumptions. This is inadequate when discussing cyberwar and when governments and corporations are considering online retaliation. Investigators and security professionals need better skills in determining actual sources and motives behind computer crimes - political or otherwise.

Also see Analyzing Goggle Attacks - Plenty of Room for Error


Auction Identity Thieves Nabbed

‘Auction’ Hacker Arrested in China?

NPR Report Discusses Online Attacks on Activists and Journalists

National Public Radio broadcast a report on attacks involving Chinese systems. The program discusses attacks targeting both Chinese opponents and attacks against pro-Chinese websites:

"Recently, Tibetan advocacy groups and China-based foreign journalists have been hit by a wave of sophisticated computer attacks that steal data, cripple Web sites and even monitor what computer users type on their computers.

"The attacks often come in the form of viruses attached to e-mails skillfully made to look like correspondence from people the recipient knows and trusts."


Cyber Attacks in China Target Activists, Journalists

Thursday, May 08, 2008

Cyberattacks against Belgium Attributed to China

Belgium has become the latest government to accuse China of attacks on their information infrastructures. As with other reports, there are no details or facts to allow proper analysis.

"Justice minister Jo Vandeurzen is reported to have claimed that the Federal Government had been targeted by Chinese hackers, backing up a separate statement by Belgium's foreign affairs minister, Karel De Grucht that his ministry had been hit by espionage in recent weeks.

"In both cases, the Belgians appear certain that the culprits were Chinese and that the Beijing authorities must know something about events, although no evidence has been offered to back up these allegations. The precise nature of the attacks has not been explained either."


Belgium accuses China of cyberattacks

EU Considers the Future of the European Network and Information Security Agency

EU lawmakers are considering extending funding for the European Network and Information Security Agency (ENISA) in response to cyber attacks on Estonia. However, the organization currently does not have the funding, remit or capability to act as an incident response organization:

"Euro-MPs believe Internet infrastructure security must be protected more effectively as the EU economy depends increasingly on a trouble-free Web.

"A lot of staff are simply pushing papers, making reports and not doing what we need them to do. It's something you might see in the Soviet Union. There is an increase in network security problems," said Reino Paasilinna, a Finnish socialist."

[Editor's Note: After this article was published, I received a clarification on the staffing issues at ENISA from Ulf Bergström, Press and Communications Officer at ENSIA:

‘This year ADM has 17 staff in total, of which 13 are TAs (stable since 2006) to service 66 planned staff members (TAs and contract agents, SNEs and stagiaires).

There’s nothing imbalanced at ENISA. ENISA is even better as some agencies with regard to this ratio. The minimum number of admin staff (that we have) sounds much larger when the overall size of the agency is low.

About his ratio there's nothing what we could more improve, as the financial regulation and the whole set of administrative rules sets a minimum number in order to guarantee sound financial management ("checks and balances").']


Euro-MPs back longer term for EU Web security body

Monday, May 05, 2008

Indian Government Systems Are Being Mapped and Probed from China

The Times of India is reporting on cyber attacks they believe originate from China. While technical detail is limited, the attacks appear to follow the same pattern as reported in the U.S. and Europe:
"The sustained assault almost coincides with the history of the present political disquiet between the two countries.

"According to senior government officials, these attacks are not isolated incidents of something so generic or basic as "hacking" — they are far more sophisticated and complete — and there is a method behind the madness.

"Publicly, senior government officials, when questioned, take refuge under the argument that "hacking" is a routine activity and happens from many areas around the world. But privately, they acknowledge that the cyber warfare threat from China is more real than from other countries.

"The core of the assault is that the Chinese are constantly scanning and mapping India’s official networks. This gives them a very good idea of not only the content but also of how to disable the networks or distract them during a conflict."

China mounts cyber attacks on Indian sites

Saturday, May 03, 2008

Increase in Hacktivism?

Online protest and hacktivist attacks are gaining more publicity but does this reflect a sudden increase in activity or just more press coverage? A recent blog posting concluding a sudden increase in activity has gained some media attention:

"While incidents of Hacktivism are not new, they are beginning to become a lot more frequent — perhaps due to the availability of tools to conduct hacktivist mischief, but also perhaps due to the ubiquitous social networking mechanisms which can now be used as to build consensus when times of cultural or political unrest present the opportunity.

In any event, Hacktivism is becoming a disturbing trend, and one which can have serious ripple effects that interfere with Internet operational continuity — sometimes in ways which we may have not even thought of yet."

While the availability of social networks and 'hacktivist' tools do contribute to both increasing number of attacks and their effectiveness, most professionals that closely follow politically motivated computer crimes and hacktivism believe there has been a steady increase in activity for several years, with ups and downs following political events in the real world (such as Olympic protests, Israeli-Palestinian conflicts, etc.). What has become more frequent is press coverage of attacks which creates a cycle of more activity followed by more press (see Hacktivism & Politically Motivated Computer Crime for a detailed analysis of the relationship between hacktivism and media coverage).


‘Hacktivism’ Incidents Escalate, Become More Frequent

Activists Swarm French Olympic Boycott Voting

The website of French magazine 'Capital', conducting an online poll concerning boycotting the 2008 Chinese Olympics, was flooded with votes, apparently from China.

"On the first day, we had about 300 responses, which was normal for this type of poll, and they were 80 percent in favour of a boycott. The next day there were 20,000 responses, with 80 percent opposing a boycott," he [Jean-Joel Gurviez, publisher of the website for Capital magazine] said.

"Almost all of the responses arrived via Chinese servers, Gurviez said, leading technicians to initially think the influx was driven by Chinese sites directing patriotic fans to vote.

"But a few days later we had hackers operating off servers in China try to change our content, and there were 2.5 million attempts to access protected files. We had to shut down the site temporarily," he said."


Hackers hit French magazine website over China poll

Wednesday, April 30, 2008

Bank of Israel Website Attacked

The Bank of Israel is reporting that its website has been repeatedly attacked by Islamic 'hackers' using an Algerian server.

From the report, it appears the bank's IT staff had not adequately addressed known security vulnerabilities.
"Governor of the Bank of Israel Prof. Stanley Fischer was taken by surprise by the hacking of the bank's website last week, and in a moment of anger announced that he would fire those responsible."

Fischer incensed at website security breakdown

Cyber Warfare Article

TechNewsWorld has published a series of articles on politically motivated attacks. The articles discuss the Estonia attacks and Russian and Chinese 'hackers'. The second part discussed the broader issues of asymmetric warfare and the (mostly U.S.) response to the issues.
"These cyber attacks are extremely worrisome because politically supported attacks have the backing of strong entities. Sponsors of these cyber attacks are trying to gain control to the keys to the kingdom..."

The Art of Cyber Warfare, Part 1: The Digital Battlefield
The Art of Cyber Warfare, Part 2: Digital Defense

Radio Free Europe Websites Hit by DoS Attacks

Several websites owned by Radio Free Europe/Radio Liberty (RFE/RL) have been shutdown by denial of service attacks in recent days.

RFE/RL stated the attacks started on the website for Belarus service and spread to other RFE/RL sites and other organizations in Minsk.

RFE/RL believe the attacks are attempts by regional governments to censor news:
"RFE/RL President Jeffrey Gedmin said he is deeply concerned by the attacks. "If free and independent media existed in these countries where we're working and broadcasting, we would have no reason to exist," Gedmin said. "The Belarusians, the Iranians -- they all have basically the same objective. They see free information -- flowing information of ideas and so forth -- as the oxygen of civil society. They'll do anything they can to cut it off. If it means jamming, if it means cyberattacks, that's what they'll do."

US radio websites in Eastern Europe hit by cyberattack: bosses


Other related articles:

Belarus: RFE/RL Cites Online 'Solidarity' in Face of Cyberattack

U.S. Denounces Attack On RFE/RL Websites


Wednesday, April 09, 2008

Estonia Preparing for Further Attacks

The Guardian newspaper has a brief article on Estonian concerns for further cyber attacks on the one year anniversary of the attacks believed to have been motivated by Russian anger over the movement of a Soviet war memorial.
"With the anniversary of the attacks looming, senior officials are preparing for a repeat performance. One official said there had been many smaller attempts to hack into government systems during the last 12 months but they were not as organised or successful as last year's attacks."


Estonia prepares for repeat of cyberattacks on anniversary

Monday, April 07, 2008

NATO and EU Concern on Cybercrime

In separate meetings last week, both the EU and NATO organizations discussed cyberterror issues and their need to respond.

The Council of Europe will review the new Convention on Cybercrime and discuss how to strengthen online anti-terrorism activities.

Separately, politically motivated computer crime was discussed at the NATO summit held in Romania including how member countries can better coordinate online defense activities.
"World leaders gathered in Bucharest for this week’s NATO summit are debating what role the trans-Atlantic alliance can play in containing “cyberterrorists,” “hacktivists” and other emerging menaces that experts concede are untraditional, but still potentially lethal."

Most of the concern quoted in the press center around the cyber attacks against Estonia.

European Union, NATO to tackle cybercrime

NATO grows increasingly concerned about terrorism on world's computer networks

Israeli Websites Defaced

A London-based Arabic-language newspaper, al-Sharq al-Awsat, reported a claim of responsibility by Islamic Jihad supporters for attacks on Israeli websites. The attacks are apparent protests for the killing by IDF of Hassan Shakura, the former head of the Islamic Jihad's media warfare division.

The article points out this type of attack alone is not a major threat:

"Website defacement of this nature requires only basic programming know-how and usually boils down to changing the main page – a file easy to reconstruct.

"Smaller sites are the ones most vulnerable to defacement, since large sites, databases and electronic commerce website usually have high-level security systems at their disposal.

"A statement by any terror group pointing to a unit dedicated to defacing websites does not necessarily indicate any operational sophistication, since any teenager with basic programming skills can do the same."



Islamic Jihad says hacked Israeli websites