Showing posts with label Information Warfare. Show all posts
Showing posts with label Information Warfare. Show all posts

Friday, January 30, 2009

Gaza conflicts involved "Search Engine Optimization"

(Brafton) In what may prove to be one of the ways global conflicts are fought in the 21st century, Israel used search engine optimization (SEO) to halt the online backlash it was receiving during the recent conflict in Gaza.

As well as some search engine optimization work (SEO) done by a Texas company for the Israeli Defense Force (IDF), numerous pro-Israeli Facebook groups along with a YouTube channel from the IDF were created in the days after the clash began.

"The stickiness makes it a medium that lets people feel, rather than remain passive," search engine optimization (SEO) expert Joel Leyden told Media Post. "You can put messages in MySpace or Facebook, but it goes nowhere until you drive the content through search engines like Google News. Now you're reaching 60 million people instantly."

In addition, the Israeli consulate began using the micro-blogging service Twitter and even used the service to take questions during a news conference.

The Web 2.0 war continued during the course of the conflict with hackers from both sides creating online propaganda with various sites being defaced.

Friday, November 28, 2008

Social networking tool help drive knowledge sharing

Pass It Along is IBM’s social networking tool, which the company says is aimed at helping organisations to take “a more user-friendly, collaborative approach” to knowledge sharing.

Big Blue points out that nearly 22 million workers are set to retire this year in the US alone, exposing serious problems for companies needing to retain industry expertise. Hence the drive for a system designed to help companies, regardless of size, to get their workforces sharing information more easily.

IBM says that is tool integrates knowledge management, social networking and Web 2.0 to simplify the way information is shared. It enables users to access, share and rate essential information; while also categorising it, from the web or an intranet. Contributors can also determine how broadly their information is shared and who else can collaborate.

“Organizations looking to on-board new resources, conduct business process training, and complement formal education with an informal tool that serves up essential information will find Pass It Along useful,” comments Dr Tony O’Driscoll, professor at Duke University’s Fuqua School of Business.

“Software developers in particular can use the technology within their existing IT infrastructure without the typical administration costs associated with traditional knowledge management applications.”

Friday, July 25, 2008

The Truth About Chinese Hackers

Here another article on China and its hackers. Written by Bruce Schneier, it gives a different perspective on the many statements appeared recently on China and its Cyber activities. Unfortunately Schneier does not provide any reference to support his theory.

http://dsc.discovery.com/technology/my-take/computer-hackers-china.html
The scoop: Last week, Rep. Frank Wolf, a Virginia Republican, said four of his government computers had been hacked by sources working out of China. Bruce Schneier, an internationally renowned security technologist, gives us his take on what went down.
The popular media concept is that there is a coordinated attempt by the Chinese government to hack into U.S. computers -- military, government corporate -- and steal secrets. The truth is a lot more complicated.
There certainly is a lot of hacking coming out of China. Any company that does security monitoring sees it all the time.
These hacker groups seem not to be working for the Chinese government. They don't seem to be coordinated by the Chinese military. They're basically young, male, patriotic Chinese citizens, trying to demonstrate that they're just as good as everyone else. As well as the American networks the media likes to talk about, their targets also include pro-Tibet, pro-Taiwan, Falun Gong and pro-Uyghur sites.
The hackers are in this for two reasons: fame and glory, and an attempt to make a living. The fame and glory comes from their nationalistic goals. Some of these hackers are heroes in China. They're upholding the country's honor against both anti-Chinese forces like the pro-Tibet movement and larger forces like the United States.
And the money comes from several sources. The groups sell owned computers, malware services, and data they steal on the black market. They sell hacker tools and videos to others wanting to play. They even sell T-shirts, hats and other merchandise on their Web sites.

Thursday, July 24, 2008

How a Classic Man-in-the-Middle Attack Saved Colombian Hostages

This is a very intersting article, written by Bruce Schneier and appeared on his blog and Wired.com, that shows how a man-in-the-Middle attack has been used to save the colombian hostages. Many Critical Infrstructure services and processes are vulnerable to this kind of attack, in particular when traditional communication media are used (telephone lines).
WIRED: Last week's dramatic rescue of 15 hostages held by the guerrilla organization FARC was the result of months of intricate deception on the part of the Colombian government. At the center was a classic man-in-the-middle attack.
In a man-in-the-middle attack, the attacker inserts himself between two communicating parties. Both believe they're talking to each other, and the attacker can delete or modify the communications at will.
The Wall Street Journal reported how this gambit played out in Colombia: "The plan had a chance of working because, for months, in an operation one army officer likened to a 'broken telephone,' military intelligence had been able to convince Ms. Betancourt's captor, Gerardo Aguilar, a guerrilla known as 'Cesar,' that he was communicating with his top bosses in the guerrillas' seven-man secretariat. Army intelligence convinced top guerrilla leaders that they were talking to Cesar. In reality, both were talking to army intelligence."
This ploy worked because Cesar and his guerrilla bosses didn't know one another well. They didn't recognize one anothers' voices, and didn't have a friendship or shared history that could have tipped them off about the ruse. Man-in-the-middle is defeated by context, and the FARC guerrillas didn't have any. [...]

Tuesday, July 22, 2008

ECIW 09 8th European Conference on Information Warfare and Security

The program for ECIW09 has been published on the ECIW website. The call for papers is open, deadline 15th of December 2008.

http://academic-conferences.org/eciw/eciw2009/eciw09-home.htm

Sunday, June 29, 2008

China's cyber warfare against India

IndiaPost.com - China's cyber warfare against India: China's intensified cyber warfare against India is becoming a serious threat to national security. The desire to possess 'electronic dominance' over India has compelled Chinese hackers to attack many crucial Indian websites and over the past one and a half years, they have mounted almost daily attacks on Indian computer networks - both government and private.
In October 2007, for example, Chinese hackers defaced over 143 Indian websites. Phishing is a term derived from fishing, and is a fraudulent activity on the Internet to acquire personal information. In phishing, the hackers use spoofed e-mails to lure innocent Internet users and get their personal information like bank account number, credit card details, and password and so on.
In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system. Though the intelligence agencies failed to get the identity of the hackers, the IP addresses left behind suggested Chinese hands.
While hacking is a normal practice around the world, the cyber warfare threat from China has serious implications. At the core of the assault is the fact that the Chinese are constantly scanning and mapping India's official networks.
According to India's CERT-In, in the year 2006, a total of 5,211 Indian websites were defaced, on an average of about 14 websites per day. Of the total number of sites that were hacked and defaced, an overwhelming majority were in the .com domain (90 cases) followed by 26 in the .in domain. As many as 11 defacement incidents were also recorded in the .org domain."

Saturday, June 28, 2008

What Constitutes an Act of Cyber War? : Cleveland IMC (((i)))

What Constitutes an Act of Cyber War? : Cleveland IMC (((i)))In the U.S. Army's Cyber Operations and Cyber Terrorism Handbook 1.02 I found the following reference to the definition of Cyber Warfare & Terrorism: "the premeditated use of disruptive activities, or the threat thereof, against computers and/or networks, with the intention to cause harm or to further social, ideological, religious, political or similar objectives or to intimidate any person in furtherance of such objectives." This was an excerpt from an article I wrote back in 2003 when the issue of cyber war was in its infancy. While this frames acts of cyber war, in retrospect it does not address a measure of the disruptive acts or provide guidance assess if individual acts, or a collection of acts rise to the level to be considered an act of cyber war.
June 18, 2008 10:58 AM Throughout history wars have been triggered by events. Being at war is a state or condition. To be legal, a war must be declared by a branch of the government entrusted by the Constitution with this power. In the Constitution of the United States, Article I provides Congress the power to declare war. War is defined as a contention by force; or the art of paralyzing the forces of an enemy. An act of war is typically defined as an aggressive act that constitutes a serious challenge or threat to national security, armed conflict, whether or not war has been declared, between two or more nations; or armed conflict between military forces of any origin. This frames the discussions around traditional war. In the physical sense it is easy to define such infractions; enemy troops crossing another countries border, military strikes by missiles or bombs, basically you know it when you see it. What constitutes a serious challenge and a threat to our national security in cyber space? That is much more difficult to define. In the U.S. Army's Cyber Operations and Cyber Terrorism Handbook 1.02 I found the following reference to the definition of Cyber Warfare & Terrorism: "the premeditated use of disruptive activities, or the threat thereof, against computers and/or networks, with the intention to cause harm or to further social, ideological, religious, political or similar objectives or to intimidate any person in furtherance of such objectives." This was an excerpt from an article I wrote back in 2003 when the issue of cyber war was in its infancy. While this frames acts of cyber war, in retrospect it does not address a measure of the disruptive acts or provide guidance assess if individual acts, or a collection of acts rise to the level to be considered an act of cyber war. If a foreign government hacks a sensitive system of another government and accesses security and defense information, is that an act of cyber war? If so, that has already occurred. If a foreign government hacks a sensitive system of another government and places software on the system that collects data and sends it back, is that an act of war? If military personal from a foreign government infiltrates another nation's networks or systems through the use of counterfeit hardware and monitors communications, is that an act of cyber war? Both are certainly acts of espionage and have already taken place. The factor that will determine if an act or acts of cyber attack rise to the level of an act of war rests in the magnitude of disruption that accompany the acts. Adding to the complexity is the fact that much of our critical infrastructure that are prime targets for cyber attacks are owned or operated by the private sector not the government. This infrastructure in some cases carries military communications, supports civilian emergency services as well business and consumer services. An attack on the infrastructure impacts multiple segments. The question of what constitutes an act of cyber war remains unanswered. Given that we are in relatively new territory, each individual attack must be examined and the forensic evidence weighed to determine the source of attack. Little physical evidence will ever exist that you can hold up and point to or take a picture of and say "they did this." Much debate is currently taking place over the legality of cyber warfare tactics and their use. Is a cyber attack on our networks and systems an act of war? Are acts of cyber espionage a violation of international law? It is better we investigate and answer these questions now rather than reacting to cyber events in the heat of the moment when they occur. -- Kevin Coleman http://www.defensetech.org/archives/004256.html

Wednesday, June 25, 2008

US: Chinese counterfeit routers sold to US Military

ESR June 23, 2008 FBI confidential
According to a leaked secret FBI document, Chinese counterfeiters have sold close to $75 million of fake Cisco Systems routers to the U.S. military. While this revelation has been largely ignored by the mainstream media, it raises troubling questions about both the integrity of U.S. defense cyber networks and the possible motives of a foreign government with a long rap sheet for military espionage and cyber hacking.
Routers are specialized computers that provide the virtual "pipes" to move millions of information packets through the world wide web, and it's no accident that China is counterfeiting Cisco designs. Cisco not only holds about 80% of the world's router market. It also outsources a significant share of its router production to China. Of course, once an American company outsources to China, the likelihood that its technology will be stolen and then reproduced for sale into world markets is extraordinarily high.
In fact, China is the counterfeit capital of the world. It accounts for two thirds of all the world's pirated and counterfeited goods and fully 80% of all counterfeit goods seized at U.S. borders. The long list of purloined products includes everything from auto parts, baby food, and cigarettes to prescription drugs like Viagra and Lipitor and high tech equipment like routers and switches.
In each case, Chinese counterfeit products pose significant health and safety risks. For example, fake Viagra jazzed with strychnine or "Lipitor" with no active ingredients can both cause heart attacks. Counterfeit brake pads made from inferior materials can lead to deadly crashes. Cigarettes laced with cadmium and lead make one of the most efficient killers in the world even more deadly.
In this particular case, one obvious danger with America's national cyber defense system being run through fake inferior routers is system failure at critical junctures. However, the more subtle - and far more disturbing - problem identified by the FBI is this: At least some of China's fake routers may be specially designed to provide Chinese hackers with undetectable "back doors" into the highest echelons of classified information throughout the defense department bureaucracy. That this possibility is closer to science fact than science fiction is bolstered by the work of scientists from the University of Illinois who recently demonstrated how it is possible to alter a computer chip to provide such undetectable access.
This specter of a virtual Chinese Trojan Horse deep in the bowels of the Pentagon raises an even bigger question, likewise posed by the FBI report: Are China's sales of fake Internet equipment to America's defense industry driven purely by the profit-seeking of rogue Chinese entrepreneurs?
Alternatively, are these sales the result of state-sponsored cyber-terrorism specifically designed to penetrate U.S. defenses - and perhaps disable those defenses in time of conflict?
In support of the profit motive, there is this salient fact: According to FBI data, a typical router made by Cisco costs about $1400 to make while the inferior counterfeit can be knocked off for a little over $200. That allows for a bigger mark-up than even drug trafficking - which is why counterfeiting is such big business in China. That said, anybody who believes that China's counterfeiters "come in peace" merely to make a quick buck needs to read some of the strategic tomes on cyber warfare generated by China's military think tanks.
Exhibit A in the state-sponsored terrorism case is the work of Chinese Air Force Colonels Qiao Ling and Wang Xiangsui. They have written that "the first rule of unrestricted warfare is that there are no rules, with nothing forbidden." They go on to describe a scenario in which China "buries a computer virus and hacker detachment in the opponent's computer system . so that the civilian electricity network, traffic dispatching network, financial transactions network, telephone communications network, and mass media network are completely paralyzed." Their overriding goal is to "cause the enemy nation to fall into social panic, street riots, and a political crisis."
These are sobering dangers indeed, particularly in light of how easy it seems to be to dupe even America's defense establishment into buying counterfeit goods. But what is ultimately so disturbing about all of this may well be how little attention either our government or the American people or the American media seem to want to pay to America's growing China threat.

Friday, June 20, 2008

UK Ministry of Defence to bolster internet intelligence

Ministry of Defence to bolster internet intelligence - SC Magazine UK: "The Ministry of Defence is aiming to increase its online intelligence gathering in a growing realisation of the threat to the UK from international cybercrime activity.

Air Commodore Graham Wright, a senior information professional from the Ministry of Defence said it is placing great focus on analysing the internet threats to the UK and being able to compromise the data of enemy countries.

'Computer Network Defence is something we take a great deal of interest in. There is a huge shift towards holding information on networks,' Wright told a conference in Westminster yesterday organised by the government-funded Cyber Security Knowledge Transfer Network."

Tuesday, June 17, 2008

'Connected' UK vulnerable in face of cyber attack

'Connected' UK vulnerable in face of cyber attack - Public Sector - Breaking Business and Technology News at silicon.com:
The government has said it is engaged in tackling ongoing state-sponsored cyber attacks on UK national infrastructure.
Security minister Lord West told the House of Lords that the UK continues to be targeted by a "large number of attacks" and that the government is "taking action" to deal with those backed by hostile regimes.

Lord West refused to confirm the nature or origin of these attacks but said cyber security is a "very dangerous area" and that the UK has become "more vulnerable as we become more connected".

"He said: 'It ranges from individual hackers right through to state sponsored issues. It is something we should be worried about. We discussed the issue in a Cabinet meeting two months ago, I think we are going in the right direction.'
National and international bodies are in place to defend against these cyber attacks, and cyber attacks occupied recent G8 discussions in Tokyo, he said.
He said there are several layers of defence on the domestic front, ranging from computer emergency response teams protecting the public sector, to the Centre for the Protection of National Infrastructure (CPNI) security response teams defending the private sector. The national response to cyber attacks is co-ordinated by the Central Sponsor for Information Assurance, which is part of the Cabinet Office.
West was unable to give guarantees of total security for data held on the National Identity Register and large NHS databases, saying he did not have the relevant information but added that 'if a system is connected then there is a possibility of getting into a system'.
He admitted past failings in the public sector security due to delays in issuing patches in time but said that the government is committed to continuing to improve response times."

Saturday, June 14, 2008

Chinese hackers blamed for power cuts - The INQUIRER

Chinese hackers blamed for power cuts : "Chinese hackers blamed for power cuts"
From the Inquirer
CYBER WAR CLAIMS are now getting out of hand, with US government spinners being prepared to blame everything on the Chinese.
A report in the National Journal, claims that Chinese hackers were responsible for a recent power outage in Florida, and the widespread blackout which struck the northeastern US in 2003.
In a literal game of Chinese whispers, the story quotes insecurity experts, who in turn cite unnamed US military intelligence [surely a contradiction in terms. Ed]
The story is that the People's Liberation Army may have cracked the computers controlling the US power grid to trigger the cascading 2003 blackout that cut off electricity to 50 million people in eight states and a Canadian province.
Unfortunately it is not just a bit, but completely, untrue.
At the time investigators blamed 'overgrown trees' that came into contact with strained high-voltage lines near facilities in Ohio owned by FirstEnergy.
No one suggested the trees were a Chinese plant.
But according to Wired, the recent claim is all part of a cunning plan to convince the citizens of the US that they are at grave risk from cyber terrorists.
It all started when intelligence boss Michael McConnell decided that cyber terrorism would be a wizard way of getting warrantless NSA surveillance. He claimed cyber terrorists were costing the US a $100 billion a year.
But this is the first time that the yarn has been linked to one of the most thoroughly-investigated power incidents in US history.
Next it will be found that Chinese hackers were responsible for the housing credit crunch, Miley Cyrus, television reality talent shows and other atrocities.

Friday, June 13, 2008

Hezbollah Has Hacking Chops - Security Blog - InformationWeek

Hezbollah Has Hacking Chops - Security Blog - InformationWeek: "
Michael Chertoff, Homeland Security secretary, recently stated that Hezbollah is the greatest threat to U.S. national security. And Western intelligence agencies are increasingly taking the organization's cyberattack skills more seriously. What do you think their targets would be?
The topic of cyberwarfare reared its head again in this DefenseTech.org post. There's been talk about cyberwar for quite some time. Kevin Coleman writes that a 2002 CIA report noted that several groups were beginning to plan attacks on Western networks. I wrote this cover story about cyberwarfare on the eve of the Iraqi war."

Tuesday, June 3, 2008

China Cybarmageddon

China Cybarmageddon

The notion that Chinese hackers are noodling around blacking-out American cities at will is a truly extraordinary assertion. Makes the wildest fantasies of 1950s McCarthyism look quite tame.
"A big week for cyber security news stories. Newsbites editor Ed Skoudis put it in perspective, "Consider this NewsBites in its totality (nation state espionage, power grid vulnerabilities, nuclear facilities, radiation dispersal rumors, congressman discussing threats, and more), and you can see we're in the midst of a sea change in the willingness to discuss the threats we now face. It's not just petty cyber crime any more. Increasingly, there are national security implications and massive safety issues associated with information security vulnerabilities in our critical infrastructure. Lives are at stake."

http://blog.wired.com/sterling/2008/06/china-cybarmage.html

Monday, June 2, 2008

Combating Enemies Online: State-Sponsored and Terrorist Use of the Internet

The authors Dr. James Jay Carafano and Dr. Richard Weitz give an interesting overview of different threats connected to State-sponsored attacks and Terrorist use of the Internet. THe article, published by the Heritage Foundation, can be downloaded here.

Saturday, May 31, 2008

Counterterrorism Blog: Virtual Assassination as a Counterterrorism tool

Counterterrorism Blog: Virtual Assassination as a Counterterrorism tool

In this article the author Roderick Jones, a former member of the UK Counter-Terrorism Command, describes how a Virtual assasination could bring to similar effects as a real assasination.

I decided to publish this article because it is in line with what I think about Cyberwar, Cybercrime and Cyberterrorism. Most of the actual definitions used to set the context for Cyberterrorism and Cyberwar are based on the equivalent definition used for the "Kinetic" (or real) world. But cyberspace does not follow the rules of the real world, so I doubt we can simply translate the traditional definition, adapting them to the Cyberspace.

Friday, May 30, 2008

China’s Cyber-Militia

Chinese hackers pose a clear and present danger to U.S. government and private-sector computer networks and may be responsible for two major U.S. power blackouts.

Computer hackers in China, including those working on behalf of the Chinese government and military, have penetrated deeply into the information systems of U.S. companies and government agencies, stolen proprietary information from American executives in advance of their business meetings in China, and, in a few cases, gained access to electric power plants in the United States, possibly triggering two recent and widespread blackouts in Florida and the Northeast, according to U.S. government officials and computer-security experts.
One prominent expert told National Journal he believes that China’s People’s Liberation Army played a role in the power outages.

http://www.nationaljournal.com/njmagazine/cs_20080531_6948.php

Thursday, May 22, 2008

Critical infrastructure central to cyber threat

Critical infrastructure central to cyber threat: "Critical infrastructure central to cyber threat
The United States is increasingly vulnerable to cyberattacks that could have catastrophic effects on critical physical infrastructure, and severely damage the country’s economic, military and strategic interests, cybersecurity specialists said today.

The conventional strategic thinking that has driven defense efforts over the past century is becoming irrelevant in today’s networked world, according to specialists from the U.S. Cyber Consequences Unit (US-CCU), who spoke at the GovSec, U.S. Law and Ready Conference and Exposition today in Washington.
[...]
Borg said the distinction between physical and information attacks is disappearing, and he cited the lasting effects the terrorist attacks of 2001 had on the information technology infrastructure. Borg said Industrial-era distinctions between the local and the remote, personal and public communications, and military and economic targets are fading and very sophisticated cyberattacks could damage major nations. Scalable cyberattacks could physically destroy large numbers of electricity generators that would take years to replace, Borg said, adding that if a sizable region’s electricity was shut down for an extended period, a majority of that economy would shut down and people likely would die. Security experts worry that last spring’s denial-of-service attacks on facilities in Estonia may be a precursor. Developed countries are considered to be most susceptible to the threats.“Looking at the many wake-up calls that the international community has had over the past decade…I would say that we have entered an era of cyberterror and perhaps even an era of cyberwar,” said Lauri Almann, Estonia’s Permanent Undersecretary of Defence, at the conference.Also, cybersecurity specialists warned that a cyberattack could cause greater economic and physical damage than the United States has suffered.“We are talking about things much bigger than the Great Depression,” said Borg. “We are talking about consequences that are only exceeded by use of nuclear weapons.” His colleague at US-CCU, John Bumgarner, said attacks that could cripple an entire industry can be carried out by a handful of knowledgeable people. The specialists said the primary target of cyberattacks presently is business information that has been consolidated in a company’s information system. This can allow thieves to open a new factory with the exact specifications and settings it took the business they victimized years to perfect. [...]

Wednesday, May 21, 2008

Information Operations paper published by CSS ETHZ

The Centre for Security Studies at the Swiss Federal Institute of Technology Zurich (ETH), published a new paper written by Myriam Dunn about Information Operations - Trends and Controversies.

Even if Information Operations are not considered part of the traditional protection approach, it is a subject that is getting more and more attention.



http://www.isn.ethz.ch/pubs/ph/details.cfm?lng=en&id=55474