Showing posts with label Cyberterrorism. Show all posts
Showing posts with label Cyberterrorism. Show all posts

Wednesday, March 11, 2009

Estonia attack: Russia admission...?

I spent a lot of time reading and studying what happened in Estonia with the famous attack. Few days after I flighted to Tallinn (what a beatiful city!!!) to meet with officials and people involved in defending the country from the cyberattack. Everyone had this question: was Russia behind the attack? Only an hypotesis, until now....

(From Betanews) A Russian official speaking on an infowar panel last week revealed that his assistant was responsible for the 2007 cyber-attacks that crippled the nation of Estonia. The only person surprised was Nargiz Asadova, the moderator of the discussion.

Sadly, the statement by Sergei Markov, an official from the pro-Kremlin Unified Russia party, has garnered only mild interest in the general press. (Almost no one I queried Tuesday even remembered the attacks, which knee-capped financial and government institutions as well as the nation's Internet traffic. It was started over the proposed relocation of a statue. Seriously.) Markov claimed that the assistant, whom he refused to name lest it imperil the man's visa applications, undertook the act as a patriotic gesture against perceived fascism (in, again, the relocation of a statue).



Wednesday, January 28, 2009

Another Cyberwar? DDoS attack boots Kyrgyzstan from net

(the Register) The central Asian republic of Kyrgyzstan was effectively knocked offline for more than a week by a Russian cybermilitia that continues to flood the country's internet providers with crippling data attacks, a security expert said.

The attacks, which began on January 18, bear the signature of pro-Russian nationalists believed to have launched similar cyber assaults on the republic of Georgia in August, said Don Jackson, a researcher with Atlanta-based security provider SecureWorks. The attacks on Kyrgyzstan were so potent that most net traffic in and out of the country was completely blocked during the first seven days.

Over the past 48 hours, ISP have managed to mitigate some of the damage by relocating the servers of their biggest customers to different IP address ranges and employing a technique known as source filtering, which is designed to block harmful traffic while still allowing friendly packets through. Some media organizations and government opposition groups in the country of 5.3 million have not been so fortunate.

"If you're still one of those online media sites or you're still one of the targets by domain names, it's going to be hit or miss," Jackson told The Register. "A lot of the web services are still unavailable."

[...]

The culprits in the attacks on Kyrgyzstan are most likely a group of technically capable Russian citizens recruited by Russian officials, Jackson said. The vast majority of the drones that are bombarding the Kyrgyz targets are located in Russia. The geographic concentration makes source blocking a more effective countermeasure than when the bots are scattered throughout the world.

Jackson speculated the attacks are designed to silence opponents of Kyrgyz President Kurmanbek Bakiyev, who are demanding the leader reverse his plans to close an airbase to the US military in its war in Afghanistan. The Russian government wants the base closed, Jackson said.

* * * * * *
The article on theregister.co.uk is the most complete one. If you want to read more, here are some additional links:
http://www.boingboing.net/2009/01/24/report-kyrgystan-und.html
http://www.secureworks.com/research/blog/index.php/2009/01/28/kyrgyzstan-under-ddos-attack-from-russia/ (very good article with an explanation of the political situation between Kyrgyzstan and Russia and US)

Here you find a few articles (mainly from Wired and Wired Blog) on recent "Cyberwars" (from Estonia to Georgia)

Saturday, November 8, 2008

Pakistan sets death penalty for "cyber terrorism"

ISLAMABAD (Reuters) - Causing death through "cyber terrorism" will be punishable by death in Pakistan, according to a decree issued by President Asif Ali Zardari on Thursday.

The Prevention of Electronic Crimes law will be applicable to anyone who commits a crime detrimental to national security through the use of a computer or any other electronic device, the government said in the ordinance.

"Whoever commits the offence of cyber terrorism and causes death of any person shall be punishable with death or imprisonment for life," according to a copy of the ordinance, published by the state-run APP news agency.

The law will apply to Pakistanis and foreigners whether living in Pakistan or abroad.

The ordinance described cyber terrorism as accessing of a computer network or electronic system by someone who then "knowingly engages in or attempts to engage in a terroristic act".

The ordinance listed several definitions of a "terroristic act" including stealing or copying, or attempting to steal or copy, classified information necessary to manufacture any form of chemical, biological or nuclear weapon.

Wednesday, August 6, 2008

Open Wi-Fi network wraps Mumbai man in bomb blast probe

The Register: Indian police raided the Mumbai home of an American expatriate after someone used his open wireless network to send an email that took responsibility for a bomb blast that killed at least 42 people.
Kenneth Haywood, whose internet-protocol address was included on an email sent just prior to the blasts, spent much of Thursday answering questions by the Maharashtra Anti-Terrorism Squad officials. Police seized his three computers, as well as the machines of several neighbors, and are examining them as part of an investigation.
tile++;
document.write('\x3Cscript src="http://ad.uk.doubleclick.net/adj/reg.security.4159/front;cta='+cta+';ctb='+ctb+';ctc='+ctc+';sc='+sc+';cid='+cid+';'+RegExCats+GetVCs()+'pid='+RegId+RegDT+';'+RegKW+';test='+test+';pf='+RegPF+';dcove=d;tile='+tile+';sz=336x280;ord=' + rand + '?" type="text/javascript">\x3C\/script>');


Haywood is not being detained but he has been instructed not to leave the country without permission. A technician who visited Haywood's flat to handle a password issue has also been questioned.
The email was sent by someone claiming to be connected to a little-known group called the Indian Mujahideen. The email address that sent the message was created 10 minutes before it was sent....

Tuesday, July 29, 2008

Homeland Security Cost-Benefit Analysis

From Bruce Schneier blog:

Homeland Security Cost-Benefit Analysis
This is an excellent paper by Ohio State political science professor John Mueller. Titled "The Quixotic Quest for Invulnerability: Assessing the Costs, Benefits, and Probabilities of Protecting the Homeland," it lays out some common send premises and policy implications.
The premises:
1. The number of potential terrorist targets is essentially infinite.
2. The probability that any individual target will be attacked is essentially zero.
3. If one potential target happens to enjoy a degree of protection, the agile terrorist usually can readily move on to another one.
4. Most targets are "vulnerable" in that it is not very difficult to damage them, but invulnerable in that they can be rebuilt in fairly short order and at tolerable expense.
5. It is essentially impossible to make a very wide variety of potential terrorist targets invulnerable except by completely closing them down.
The policy implications:
1. Any protective policy should be compared to a "null case": do nothing, and use the money saved to rebuild and to compensate any victims.
2. Abandon any effort to imagine a terrorist target list.
3. Consider negative effects of protection measures: not only direct cost, but inconvenience, enhancement of fear, negative economic impacts, reduction of liberties.
4. Consider the opportunity costs, the tradeoffs, of protection measures.
Here's the abstract:
This paper attempts to set out some general parameters for coming to grips with a central homeland security concern: the effort to make potential targets invulnerable, or at least notably less vulnerable, to terrorist attack. It argues that protection makes sense only when protection is feasible for an entire class of potential targets and when the destruction of something in that target set would have quite large physical, economic, psychological, and/or political consequences. There are a very large number of potential targets where protection is essentially a waste of resources and a much more limited one where it may be effective.
The whole paper is worth reading.

Monday, July 28, 2008

WSJ: U.S. Fears Threat of Cyberspying at Olympics

WASHINGTON -- A debate is brewing in the U.S. government over whether to publicly warn businesspeople and other travelers heading to the Beijing Olympics about the dangers posed by Chinese computer hackers.

According to government officials and security consultants, U.S. intelligence agencies are worried about the potential threat to U.S. laptops and cellphones. But others, including the State and Commerce departments and some companies, are trying to quiet the issue for fear of offending the Chinese, these people say.
Barack Obama became the first major presidential candidate to propose new cybersecurity policies Wednesday when he unveiled his cybersecurity strategy, which includes combating corporate espionage, shielding the country's Internet infrastructure and establishing a national cybersecurity adviser.
U.S. intelligence and security officials are concerned by the frequency with which spies in China and other countries are targeting traveling U.S. corporate and government officials. The Department of Homeland Security issued a warning last month to certain government and private-sector officials stating that business and government travelers' electronic devices are often targeted by foreign governments. The warning wasn't available to the public. [...]

Saturday, July 26, 2008

US. Cybersecurity and the presidential campaign

SC Magazine: In a speech delivered Wednesday at Purdue University, Sen. Barack Obama warned of the dangers of new forms of terrorism that could damage the United States. After detailing threats from nuclear and biological weapons, the presidential candidate outlined what he envisioned for a cybersecurity infrastructure that would protect the nation's computer networks and strengthen science and computer education programs. “Every American depends – directly or indirectly – on our system of information networks. They are increasingly the backbone of our economy and our infrastructure; our national security and our personal well-being. But it's no secret that terrorists could use our computer networks to deal us a crippling blow,” he said.

Thursday, July 24, 2008

How a Classic Man-in-the-Middle Attack Saved Colombian Hostages

This is a very intersting article, written by Bruce Schneier and appeared on his blog and Wired.com, that shows how a man-in-the-Middle attack has been used to save the colombian hostages. Many Critical Infrstructure services and processes are vulnerable to this kind of attack, in particular when traditional communication media are used (telephone lines).
WIRED: Last week's dramatic rescue of 15 hostages held by the guerrilla organization FARC was the result of months of intricate deception on the part of the Colombian government. At the center was a classic man-in-the-middle attack.
In a man-in-the-middle attack, the attacker inserts himself between two communicating parties. Both believe they're talking to each other, and the attacker can delete or modify the communications at will.
The Wall Street Journal reported how this gambit played out in Colombia: "The plan had a chance of working because, for months, in an operation one army officer likened to a 'broken telephone,' military intelligence had been able to convince Ms. Betancourt's captor, Gerardo Aguilar, a guerrilla known as 'Cesar,' that he was communicating with his top bosses in the guerrillas' seven-man secretariat. Army intelligence convinced top guerrilla leaders that they were talking to Cesar. In reality, both were talking to army intelligence."
This ploy worked because Cesar and his guerrilla bosses didn't know one another well. They didn't recognize one anothers' voices, and didn't have a friendship or shared history that could have tipped them off about the ruse. Man-in-the-middle is defeated by context, and the FARC guerrillas didn't have any. [...]

Saturday, June 28, 2008

What Constitutes an Act of Cyber War? : Cleveland IMC (((i)))

What Constitutes an Act of Cyber War? : Cleveland IMC (((i)))In the U.S. Army's Cyber Operations and Cyber Terrorism Handbook 1.02 I found the following reference to the definition of Cyber Warfare & Terrorism: "the premeditated use of disruptive activities, or the threat thereof, against computers and/or networks, with the intention to cause harm or to further social, ideological, religious, political or similar objectives or to intimidate any person in furtherance of such objectives." This was an excerpt from an article I wrote back in 2003 when the issue of cyber war was in its infancy. While this frames acts of cyber war, in retrospect it does not address a measure of the disruptive acts or provide guidance assess if individual acts, or a collection of acts rise to the level to be considered an act of cyber war.
June 18, 2008 10:58 AM Throughout history wars have been triggered by events. Being at war is a state or condition. To be legal, a war must be declared by a branch of the government entrusted by the Constitution with this power. In the Constitution of the United States, Article I provides Congress the power to declare war. War is defined as a contention by force; or the art of paralyzing the forces of an enemy. An act of war is typically defined as an aggressive act that constitutes a serious challenge or threat to national security, armed conflict, whether or not war has been declared, between two or more nations; or armed conflict between military forces of any origin. This frames the discussions around traditional war. In the physical sense it is easy to define such infractions; enemy troops crossing another countries border, military strikes by missiles or bombs, basically you know it when you see it. What constitutes a serious challenge and a threat to our national security in cyber space? That is much more difficult to define. In the U.S. Army's Cyber Operations and Cyber Terrorism Handbook 1.02 I found the following reference to the definition of Cyber Warfare & Terrorism: "the premeditated use of disruptive activities, or the threat thereof, against computers and/or networks, with the intention to cause harm or to further social, ideological, religious, political or similar objectives or to intimidate any person in furtherance of such objectives." This was an excerpt from an article I wrote back in 2003 when the issue of cyber war was in its infancy. While this frames acts of cyber war, in retrospect it does not address a measure of the disruptive acts or provide guidance assess if individual acts, or a collection of acts rise to the level to be considered an act of cyber war. If a foreign government hacks a sensitive system of another government and accesses security and defense information, is that an act of cyber war? If so, that has already occurred. If a foreign government hacks a sensitive system of another government and places software on the system that collects data and sends it back, is that an act of war? If military personal from a foreign government infiltrates another nation's networks or systems through the use of counterfeit hardware and monitors communications, is that an act of cyber war? Both are certainly acts of espionage and have already taken place. The factor that will determine if an act or acts of cyber attack rise to the level of an act of war rests in the magnitude of disruption that accompany the acts. Adding to the complexity is the fact that much of our critical infrastructure that are prime targets for cyber attacks are owned or operated by the private sector not the government. This infrastructure in some cases carries military communications, supports civilian emergency services as well business and consumer services. An attack on the infrastructure impacts multiple segments. The question of what constitutes an act of cyber war remains unanswered. Given that we are in relatively new territory, each individual attack must be examined and the forensic evidence weighed to determine the source of attack. Little physical evidence will ever exist that you can hold up and point to or take a picture of and say "they did this." Much debate is currently taking place over the legality of cyber warfare tactics and their use. Is a cyber attack on our networks and systems an act of war? Are acts of cyber espionage a violation of international law? It is better we investigate and answer these questions now rather than reacting to cyber events in the heat of the moment when they occur. -- Kevin Coleman http://www.defensetech.org/archives/004256.html

Tuesday, June 24, 2008

CIP Report - new International Issue

On this month CIP report, published by George Mason University School of Law, you find an article I wrote on Protecting the Critical Infrastructure in Europe.
You can access the report on the GMU CIP website: http://cipp.gmu.edu
Or directly here

Friday, June 20, 2008

UK Ministry of Defence to bolster internet intelligence

Ministry of Defence to bolster internet intelligence - SC Magazine UK: "The Ministry of Defence is aiming to increase its online intelligence gathering in a growing realisation of the threat to the UK from international cybercrime activity.

Air Commodore Graham Wright, a senior information professional from the Ministry of Defence said it is placing great focus on analysing the internet threats to the UK and being able to compromise the data of enemy countries.

'Computer Network Defence is something we take a great deal of interest in. There is a huge shift towards holding information on networks,' Wright told a conference in Westminster yesterday organised by the government-funded Cyber Security Knowledge Transfer Network."

Sunday, June 15, 2008

Fighting cyber terrorism

IMPACT, or International Multilateral Partnership Against Cyber Terrorism, is the first global public-private initiative against cyber terrorism.
Malaysia’s Prime Minister Abdullah Badawi has approved a US$13 million grant to lay the foundation of IMPACT, a not-for-profit global organisation, to rally efforts from governments, the private sector, and academia worldwide, against the growing threat of cyber terrorism. IMPACT, or International Multilateral Partnership Against Cyber Terrorism, is the first global public-private initiative against cyber terrorism. It drives collaboration among governments, industry leaders and cyber security experts to enhance the global community’s capacity to prevent and respond to cyber threats.The start-up grant will be used to construct the IMPACT building in Cyberjaya, Malaysia, and operations are expected to start in December. The fund will also finance the infrastructure for the four centres of IMPACT: the Centre for Training & Skills Development; the Centre for Security Certification, Research & Development; the Centre for Global Response; and, the Centre for Policy, Regulatory Framework & International Co-operation. Currently chaired by the Malaysian PM, the leadership of the International Advisory Board of IMPACT will be handed over to other member countries after the initial three-year term. “From the standpoint of the Malaysian government, their contribution is a gift to the global community. Someone has to start. They feel they’re just giving the seed,” said Mohd Noor Amin, Chairman, Management Board, IMPACT.
Warning SystemIMPACT is currently building two systems for its member countries. One is an early warning system. which will aggregate ‘feeds’ from IMPACT’s security partners and member countries, which will be redistributed across the world to member countries.Another is a collaboration system that, according to Amin, is a secure electronic platform enabling experts from member countries to collaborate with one another based on their specialty and niche areas.

Saturday, June 14, 2008

Chinese hackers blamed for power cuts - The INQUIRER

Chinese hackers blamed for power cuts : "Chinese hackers blamed for power cuts"
From the Inquirer
CYBER WAR CLAIMS are now getting out of hand, with US government spinners being prepared to blame everything on the Chinese.
A report in the National Journal, claims that Chinese hackers were responsible for a recent power outage in Florida, and the widespread blackout which struck the northeastern US in 2003.
In a literal game of Chinese whispers, the story quotes insecurity experts, who in turn cite unnamed US military intelligence [surely a contradiction in terms. Ed]
The story is that the People's Liberation Army may have cracked the computers controlling the US power grid to trigger the cascading 2003 blackout that cut off electricity to 50 million people in eight states and a Canadian province.
Unfortunately it is not just a bit, but completely, untrue.
At the time investigators blamed 'overgrown trees' that came into contact with strained high-voltage lines near facilities in Ohio owned by FirstEnergy.
No one suggested the trees were a Chinese plant.
But according to Wired, the recent claim is all part of a cunning plan to convince the citizens of the US that they are at grave risk from cyber terrorists.
It all started when intelligence boss Michael McConnell decided that cyber terrorism would be a wizard way of getting warrantless NSA surveillance. He claimed cyber terrorists were costing the US a $100 billion a year.
But this is the first time that the yarn has been linked to one of the most thoroughly-investigated power incidents in US history.
Next it will be found that Chinese hackers were responsible for the housing credit crunch, Miley Cyrus, television reality talent shows and other atrocities.

Friday, June 13, 2008

Hezbollah Has Hacking Chops - Security Blog - InformationWeek

Hezbollah Has Hacking Chops - Security Blog - InformationWeek: "
Michael Chertoff, Homeland Security secretary, recently stated that Hezbollah is the greatest threat to U.S. national security. And Western intelligence agencies are increasingly taking the organization's cyberattack skills more seriously. What do you think their targets would be?
The topic of cyberwarfare reared its head again in this DefenseTech.org post. There's been talk about cyberwar for quite some time. Kevin Coleman writes that a 2002 CIA report noted that several groups were beginning to plan attacks on Western networks. I wrote this cover story about cyberwarfare on the eve of the Iraqi war."

Wednesday, June 4, 2008

Did Hackers Cause the 2003 Northeast Blackout? Umm, No - from Wired.com

Did Hackers Cause the 2003 Northeast Blackout? Umm, No Threat Level from Wired.com: "Did Hackers Cause the 2003 Northeast Blackout? Umm, No"

I found this article appeared on Wired.com blog, quite interesting and I decided to post it after I reported an article on the suspects that the Chinese People Liberation Army could be behind some of the most important US blackouts. It provides a very different perspective on the discussion.

Tuesday, June 3, 2008

China Cybarmageddon

China Cybarmageddon

The notion that Chinese hackers are noodling around blacking-out American cities at will is a truly extraordinary assertion. Makes the wildest fantasies of 1950s McCarthyism look quite tame.
"A big week for cyber security news stories. Newsbites editor Ed Skoudis put it in perspective, "Consider this NewsBites in its totality (nation state espionage, power grid vulnerabilities, nuclear facilities, radiation dispersal rumors, congressman discussing threats, and more), and you can see we're in the midst of a sea change in the willingness to discuss the threats we now face. It's not just petty cyber crime any more. Increasingly, there are national security implications and massive safety issues associated with information security vulnerabilities in our critical infrastructure. Lives are at stake."

http://blog.wired.com/sterling/2008/06/china-cybarmage.html

"Cyberwarfare and Critical Information Infrastructure Protection (CIIP)" - dinner at the EU Parliament

On Tuesday, 27 May 2008, in the Private Salons of the European Parliament in Brussels, the European Internet Foundation has organized a Dinner to discuss "Cyberwarfare and Critical Information Infrastructure Protection (CIIP). The agenda of the event is available here.

I have been invited to talk about the Impact of CIIP incidents on end users and their role in CIIP. You can find my speech here.

Monday, June 2, 2008

Combating Enemies Online: State-Sponsored and Terrorist Use of the Internet

The authors Dr. James Jay Carafano and Dr. Richard Weitz give an interesting overview of different threats connected to State-sponsored attacks and Terrorist use of the Internet. THe article, published by the Heritage Foundation, can be downloaded here.

Saturday, May 31, 2008

Counterterrorism Blog: Virtual Assassination as a Counterterrorism tool

Counterterrorism Blog: Virtual Assassination as a Counterterrorism tool

In this article the author Roderick Jones, a former member of the UK Counter-Terrorism Command, describes how a Virtual assasination could bring to similar effects as a real assasination.

I decided to publish this article because it is in line with what I think about Cyberwar, Cybercrime and Cyberterrorism. Most of the actual definitions used to set the context for Cyberterrorism and Cyberwar are based on the equivalent definition used for the "Kinetic" (or real) world. But cyberspace does not follow the rules of the real world, so I doubt we can simply translate the traditional definition, adapting them to the Cyberspace.

Friday, May 30, 2008

Home Office plans surveillance of all online activity | 22 May 2008 | ComputerWeekly.com

Home Office plans surveillance of all online activity 22 May 2008 ComputerWeekly.com
The Home Office is considering radical plans to develop a centralised surveillance system to track in real-time every kind of electronic activity undertaken by citizens.
The project, driven by intelligence services, would require the development of a surveillance system unprecedented in its scope and technical sophistication.
The work is still at the discussion stage and has not been agreed by ministers. But if the project goes ahead as expected, it would require the development of untried technology to tap into phone lines and the internet, retrieve details on every individual's browsing and communications traffic, and store it in a central database.
The envisaged database would not record the content of telephone calls, e-mails or other internet messages. However, it could hold records of telephone and interent traffic data, which would enable investigators to build up a proile of an individual and identify their network of contacts.

The information gathered, for example, could include the time an individual sent an e-mail or instant message, and who received it. It could also record details of websites visited by members of the public, and even who had used which online computer game or video clip, when and for how long.
The project represents a major esclation in the government's powers and the speed at which electronic surveillance can be undertaken.

European Data Protection Supervisor condemns data protection legislation >>
Government plans database to connect every citizen record >>