Showing posts with label Security Intelligence. Show all posts
Showing posts with label Security Intelligence. Show all posts

Friday, January 30, 2009

Gaza conflicts involved "Search Engine Optimization"

(Brafton) In what may prove to be one of the ways global conflicts are fought in the 21st century, Israel used search engine optimization (SEO) to halt the online backlash it was receiving during the recent conflict in Gaza.

As well as some search engine optimization work (SEO) done by a Texas company for the Israeli Defense Force (IDF), numerous pro-Israeli Facebook groups along with a YouTube channel from the IDF were created in the days after the clash began.

"The stickiness makes it a medium that lets people feel, rather than remain passive," search engine optimization (SEO) expert Joel Leyden told Media Post. "You can put messages in MySpace or Facebook, but it goes nowhere until you drive the content through search engines like Google News. Now you're reaching 60 million people instantly."

In addition, the Israeli consulate began using the micro-blogging service Twitter and even used the service to take questions during a news conference.

The Web 2.0 war continued during the course of the conflict with hackers from both sides creating online propaganda with various sites being defaced.

Tuesday, December 16, 2008

EU Information Sharing Legislation Proposal - CIWIN (Critical Infrastructure Warning Information Network)


On the European Parliament Web Site is now available the proposal for an European Legislation on Information Sharing. 

The document can be accessed here. 

This legislation proposal is part of the European Program for Critical Infrastructure Protection (EPCIP) and its aim is to support the Critical Infrastructure Warning Information Network (CIWIN), a prototype developed by the European Commission in 2007. 



Friday, July 25, 2008

The Truth About Chinese Hackers

Here another article on China and its hackers. Written by Bruce Schneier, it gives a different perspective on the many statements appeared recently on China and its Cyber activities. Unfortunately Schneier does not provide any reference to support his theory.

http://dsc.discovery.com/technology/my-take/computer-hackers-china.html
The scoop: Last week, Rep. Frank Wolf, a Virginia Republican, said four of his government computers had been hacked by sources working out of China. Bruce Schneier, an internationally renowned security technologist, gives us his take on what went down.
The popular media concept is that there is a coordinated attempt by the Chinese government to hack into U.S. computers -- military, government corporate -- and steal secrets. The truth is a lot more complicated.
There certainly is a lot of hacking coming out of China. Any company that does security monitoring sees it all the time.
These hacker groups seem not to be working for the Chinese government. They don't seem to be coordinated by the Chinese military. They're basically young, male, patriotic Chinese citizens, trying to demonstrate that they're just as good as everyone else. As well as the American networks the media likes to talk about, their targets also include pro-Tibet, pro-Taiwan, Falun Gong and pro-Uyghur sites.
The hackers are in this for two reasons: fame and glory, and an attempt to make a living. The fame and glory comes from their nationalistic goals. Some of these hackers are heroes in China. They're upholding the country's honor against both anti-Chinese forces like the pro-Tibet movement and larger forces like the United States.
And the money comes from several sources. The groups sell owned computers, malware services, and data they steal on the black market. They sell hacker tools and videos to others wanting to play. They even sell T-shirts, hats and other merchandise on their Web sites.

Sunday, June 29, 2008

China's cyber warfare against India

IndiaPost.com - China's cyber warfare against India: China's intensified cyber warfare against India is becoming a serious threat to national security. The desire to possess 'electronic dominance' over India has compelled Chinese hackers to attack many crucial Indian websites and over the past one and a half years, they have mounted almost daily attacks on Indian computer networks - both government and private.
In October 2007, for example, Chinese hackers defaced over 143 Indian websites. Phishing is a term derived from fishing, and is a fraudulent activity on the Internet to acquire personal information. In phishing, the hackers use spoofed e-mails to lure innocent Internet users and get their personal information like bank account number, credit card details, and password and so on.
In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs forcing the government to think about devising a new strategy to fortify the system. Though the intelligence agencies failed to get the identity of the hackers, the IP addresses left behind suggested Chinese hands.
While hacking is a normal practice around the world, the cyber warfare threat from China has serious implications. At the core of the assault is the fact that the Chinese are constantly scanning and mapping India's official networks.
According to India's CERT-In, in the year 2006, a total of 5,211 Indian websites were defaced, on an average of about 14 websites per day. Of the total number of sites that were hacked and defaced, an overwhelming majority were in the .com domain (90 cases) followed by 26 in the .in domain. As many as 11 defacement incidents were also recorded in the .org domain."

Saturday, June 28, 2008

What Constitutes an Act of Cyber War? : Cleveland IMC (((i)))

What Constitutes an Act of Cyber War? : Cleveland IMC (((i)))In the U.S. Army's Cyber Operations and Cyber Terrorism Handbook 1.02 I found the following reference to the definition of Cyber Warfare & Terrorism: "the premeditated use of disruptive activities, or the threat thereof, against computers and/or networks, with the intention to cause harm or to further social, ideological, religious, political or similar objectives or to intimidate any person in furtherance of such objectives." This was an excerpt from an article I wrote back in 2003 when the issue of cyber war was in its infancy. While this frames acts of cyber war, in retrospect it does not address a measure of the disruptive acts or provide guidance assess if individual acts, or a collection of acts rise to the level to be considered an act of cyber war.
June 18, 2008 10:58 AM Throughout history wars have been triggered by events. Being at war is a state or condition. To be legal, a war must be declared by a branch of the government entrusted by the Constitution with this power. In the Constitution of the United States, Article I provides Congress the power to declare war. War is defined as a contention by force; or the art of paralyzing the forces of an enemy. An act of war is typically defined as an aggressive act that constitutes a serious challenge or threat to national security, armed conflict, whether or not war has been declared, between two or more nations; or armed conflict between military forces of any origin. This frames the discussions around traditional war. In the physical sense it is easy to define such infractions; enemy troops crossing another countries border, military strikes by missiles or bombs, basically you know it when you see it. What constitutes a serious challenge and a threat to our national security in cyber space? That is much more difficult to define. In the U.S. Army's Cyber Operations and Cyber Terrorism Handbook 1.02 I found the following reference to the definition of Cyber Warfare & Terrorism: "the premeditated use of disruptive activities, or the threat thereof, against computers and/or networks, with the intention to cause harm or to further social, ideological, religious, political or similar objectives or to intimidate any person in furtherance of such objectives." This was an excerpt from an article I wrote back in 2003 when the issue of cyber war was in its infancy. While this frames acts of cyber war, in retrospect it does not address a measure of the disruptive acts or provide guidance assess if individual acts, or a collection of acts rise to the level to be considered an act of cyber war. If a foreign government hacks a sensitive system of another government and accesses security and defense information, is that an act of cyber war? If so, that has already occurred. If a foreign government hacks a sensitive system of another government and places software on the system that collects data and sends it back, is that an act of war? If military personal from a foreign government infiltrates another nation's networks or systems through the use of counterfeit hardware and monitors communications, is that an act of cyber war? Both are certainly acts of espionage and have already taken place. The factor that will determine if an act or acts of cyber attack rise to the level of an act of war rests in the magnitude of disruption that accompany the acts. Adding to the complexity is the fact that much of our critical infrastructure that are prime targets for cyber attacks are owned or operated by the private sector not the government. This infrastructure in some cases carries military communications, supports civilian emergency services as well business and consumer services. An attack on the infrastructure impacts multiple segments. The question of what constitutes an act of cyber war remains unanswered. Given that we are in relatively new territory, each individual attack must be examined and the forensic evidence weighed to determine the source of attack. Little physical evidence will ever exist that you can hold up and point to or take a picture of and say "they did this." Much debate is currently taking place over the legality of cyber warfare tactics and their use. Is a cyber attack on our networks and systems an act of war? Are acts of cyber espionage a violation of international law? It is better we investigate and answer these questions now rather than reacting to cyber events in the heat of the moment when they occur. -- Kevin Coleman http://www.defensetech.org/archives/004256.html

Tuesday, June 24, 2008

CIP Report - new International Issue

On this month CIP report, published by George Mason University School of Law, you find an article I wrote on Protecting the Critical Infrastructure in Europe.
You can access the report on the GMU CIP website: http://cipp.gmu.edu
Or directly here

Friday, June 20, 2008

UK Ministry of Defence to bolster internet intelligence

Ministry of Defence to bolster internet intelligence - SC Magazine UK: "The Ministry of Defence is aiming to increase its online intelligence gathering in a growing realisation of the threat to the UK from international cybercrime activity.

Air Commodore Graham Wright, a senior information professional from the Ministry of Defence said it is placing great focus on analysing the internet threats to the UK and being able to compromise the data of enemy countries.

'Computer Network Defence is something we take a great deal of interest in. There is a huge shift towards holding information on networks,' Wright told a conference in Westminster yesterday organised by the government-funded Cyber Security Knowledge Transfer Network."