Showing posts with label Cyber War. Show all posts
Showing posts with label Cyber War. Show all posts

Tuesday, January 8, 2013

Nations prepare for cyber war

Security analysts are predicting that 2013 is when nation-sponsored cyberwarfare goes mainstream -- and some think such attacks will lead to actual deaths.

 

In 2012, large-scale cyberattacks targeted at the Iranian government were uncovered, and in return, Iran is believed to have launched massive attacks aimed at U.S. banks and Saudi oil companies. At least 12 of the world's 15 largest military powers are currently building cyberwarfare programs, according to James Lewis, a cybersecurity expert at the Center for Strategic and International Studies.
So a cyber Cold War is already in progress. But some security companies believe that battle will become even more heated this year.
"Nation states and armies will be more frequent actors and victims of cyberthreats," a team of researchers at McAfee Labs, an Intel (INTC, Fortune 500) subsidiary, wrote in a recent report.
Michael Sutton, head of security research at cloud security company Zscaler, said he expects governments to spend furiously on building up their cyber arsenals. Some may even outsource attacks to online hackers.
The Obama administration and many in Congress have been more vocal about how an enemy nation or a terrorist cell could target the country's critical infrastructure in a cyberattack. Banks, stock exchanges, nuclear power plants and water purification systems are particularly vulnerable, according to numerous assessments delivered to Congress last year.
Related story: Malware attacks on the rise
But after legislation aimed at preventing such attacks stalled in Congress last year, some experts believe this will be the year when cyberattacks turn deadly.
"Nation-state attackers will target critical infrastructure networks such as power grids at unprecedented scale in 2013," predicted Chiranjeev Bordoloi, CEO of security company Top Patch. "These types of attacks could grow more sophisticated, and the slippery slope could lead to the loss of human life."
Security firm IID also predicted that cyberattacks will lead to the loss of life this year.
But others say that such event is unlikely. Our most potent online foes, Russia and China, haven't shown an interest in infrastructure attacks. Those that would pursue them -- Iran is often mentioned -- haven't yet proven capable of pulling off something on that scale.
Verizon (VZ, Fortune 500), which runs an extensive cybersecurity business, is in the doubters' camp. "Many security experts are using anecdote and opinion for their predictions, whereas Verizon's researchers are applying empirical evidence," said Wade Baker, head of Verizon's security division. "First and foremost, we don't believe there will be an all-out cyber war, although it's possible."

Sunday, September 9, 2012

Editorial: The Invisible (Cyber) War in West Asia

Almost imperceptibly, West Asia has become the new frontline of the current manifestation of cyber warfare with various types of cyber weapons being deployed by parties whose identities can only be speculated upon, but presumed to be state and non-state actors from within the region and beyond. Since the discovery of the Stuxnet malware in 2010, no less than five other “cyber weapons” have made their appearance over the past two years. The two recent attacks on energy companies are particularly worrisome since they represent a relentless and rapid escalation in capabilities and intent on the part of the perpetrators.

Stuxnet was directed against the Iranian nuclear programme, and suspicions of US and Israeli involvement were confirmed by subsequent reports. These suspicions arose in the first place because of the sophistication of the malware, which, experts declared, could only be engineered through the resources available to a nation state. After a lull of a year, the Duqu worm was discovered in September 2011, followed in quick succession by the Mahdi, Gauss and Flame malware. While Flame, Duqu and Gauss were said to share similar digital DNA with Stuxnet, being spread predominantly via USB sticks, their primary purpose seemed to be espionage, with their targets ranging from banking to governmental to energy networks. Flame, in particular, was noted for its modular nature, and its size, averaging 20 MB. Its capabilities ranged from recording Skype conversations and downloading information from smart phones to more mundane activities such as recording audio, screenshots, keystroke and network traffic recording. The Mahdi Trojan seemed to have different godfathers and was spread via phishing emails even though its purpose was also apparently espionage. Infections were reported from Iran, Israel, Afghanistan, the United Arab Emirates, Saudi Arabia, Syria, Lebanon and Egypt.

Thursday, August 9, 2012

Army Test Verifies Glitches In Software

Updates planned, but not Palantir

The Army's intelligence-processing software that was developed to help soldiers in Afghanistan understand the enemy and predict actions suffers from "poor reliability" and is "not survivable" against cyberattacks, the service's top tester said in a confidential memo to the Army chief of staff.

The highly critical Aug. 1 report on the Distributed Common Ground System was submitted as the Army was under fire for making it difficult for commanders in Afghanistan to buy a competing software platform called Palantir, which soldiers say helps them find roadside bombs, the top killer of U.S. troops.

The House Oversight and Government Reform Committee last week announced that it was investigating the Army's decision to kill an April evaluation that favored Palantir. The Army ordered the assessment destroyed and replaced it with a second report less favorable to Palantir.

The Aug. 1 memo, a copy of which was obtained by The Washington Times, was written by Maj. Gen. Genaro Dellarocco, who heads the Army Test and Evaluation Command - the same command that conducted the in-country survey of Palantir users, then killed it.

Thursday, July 26, 2012

Hunt down hackers, cyber defenders urged

Computer security champions on Wednesday were urged to hunt down and eliminate hackers, spies, terrorists and other online evildoers to prevent devastating Internet Age attacks.

The first day of briefings at a prestigious Black Hat computer security gathering here opened with a former FBI cyber crime unit chief calling for a shift from defense to offense when it comes to protecting networks.

"We need warriors to fight our enemies, particularly in the cyber world right now," Shawn Henry said in a Black Hat keynote presentation that kicked off with dramatic video of hostage rescue teams training.

"I believe the threat from computer network attack is the most significant threat we face as a civilized world, other than a weapon of mass destruction."

The peril grows as water supplies, power grids, financial transactions, and more rely on the Internet and as modern lives increasingly involve working and playing on smartphones or tablet computers, according to Henry.

He rolled off a list of adversaries ranging from spies and well-funded criminals to disgruntled employees with inside knowledge of company networks.

"Cyber is the great equalizer," Henry said.

"With a $500 laptop with an Internet connection anybody, anywhere in the world can attack any organization, any company," he continued. "The last time I checked, that was about 2.3 billion people."

Saturday, July 21, 2012

4000 Computer Viruses Targeting Iranian Users



A few days ago several local news websites reported that more than 4000 computer viruses are targeting Iranian users. Ismail Radkani, director-general for management and technical support at the state Information Technology Company, made some comments on these reports.
“Currently we don’t have any exact number of the total active computer viruses in Iran’s virtual world. But sometimes the producers of anti-viruses and anti-malwares publish reports about the number of malwares. Base on this information we can estimate the approximate number of computer viruses in Iran. But if we increase our knowledge we can face with any number of threats.” Ismail Radkani said.

Saturday, July 14, 2012

Indian Navy Raises Army For Cyber Front: Recruiting Cadets Against Chinese Hackers

With the rise in cyber terrorism in the country, the Indian Navy will soon induct an exclusive cyber cell to counter terror attacks on cyber space and to protect its computer-enabled communication networks from notorious hackers.

The Navy force recently has instituted an anti-hacking wing to guard its valuable information. The departments belonging to the Indian Defence have constantly faced several challenges while tackling cyber terror, while fire-walling its communication networks from espionage, mainly from China and Pakistan. Noting the requirement for experts in information technology, Indian Navy is raising a new crop of cyber warriors against hostile Chinese hackers and others as well. 

Reports suggest that the recruiting process is already underway, and that the officials are considering men with information technology and engineering educational background for short-service commissioned officers in its cyber cadre. Women who are interested to be part of this special cyber security wing will have to wait as these positions are currently admissible to men.

The recruited cadets will be undergoing training at Naval Academy Ezhimala (NAVAC), which is located in the Kannur (Cannanore) district of Kerala, before they get posted on board warships and other establishments. They will be trained in maintaining the security of communication networks, which are used to send and receive sensitive information related to national security.

NAVAC is the premier training establishment of the Indian Navy, which conducts the basic training for all officers being commissioned into the Indian Navy under various schemes.

The commissioned officials will be handling state-of-the-art networks and niche applications, both in operational and administrative areas. Meanwhile, the officers will have to engineer and operate secure and critical networks, including manning of security operation and network operation centres.

The anti-hacking batch of the Indian Navy will be part of its executive branch.

Lately, a bug that infiltrated the Indian Navy computers at its Eastern Command headquartered at Visakhapatnam enabled Chinese hackers to break into the system. A bulk of sensitive information, which reportedly details the position of marine forces, was compromised in the attack.

Monday, July 2, 2012

China hackers enter Navy computers, plant bug to extract sensitive data

Hackers have broken into sensitive naval computer systems in and around Visakhapatnam, the headquarters of the Eastern Naval Command, and planted bugs that relayed confidential data to IP addresses in China.
The Eastern Naval Command plans operations and deployments in the South China Sea — the theatre of recent muscle-flexing by Beijing — and beyond. India’s first nuclear missile submarine, INS Arihant, is currently undergoing trials at the Command.
The extent of the loss is still being ascertained, and officials said it was “premature at this stage” to comment on the sensitivity of the compromised data. But the Navy has completed a Board of Inquiry (BoI) which is believed to have indicted at least six mid-level officers for procedural lapses that led to the security breach.
The naval computers were found infected with a virus that secretly collected and transmitted confidential files and documents to Chinese IP addresses. Strict disciplinary action against the indicted officers is imminent.
Responding to a questionnaire sent by The Sunday Express on whether highly classified data had been sent to IP addresses in China due to the bug, the Navy said: “An inquiry has been convened and findings of the report are awaited. It needs to be mentioned that there is a constant threat in the cyber domain from inimical hack ers worldwide.”
Sources, however, confirmed that classified data had been leaked, and the breach had possibly occurred because of the use of pen drives that are prohibited in naval offices. The virus was found hidden in the pen drives that were being used to transfer data from standalone computers to othersystems, said a person familiar with the investigation.
The Navy — and the other armed forces — stores sensitive data only in standalone computers that are not connected to the Internet. These computers are not supposed to have ports or access points for pen drives or external storage devices.
The virus apparently created a hidden folder and collected specific files and documents based on certain ‘key words’ that it has been programmed to identify.
The documents remained hidden on the pen drives until they were put in computers that were connected to the Internet, after which the bug quietly sent the files to specific IP addresses.
The cyber espionage came to light in January-February this year. Besides the Navy’s resources, other cyber forensic agencies were involved in tracing the hackers, sources said. China has been accused earlier of using “cyber battalions” — specially trained military staff — to break into sensitive computer systems across the world.
The Naval HQ in New Delhi is monitoring the case closely. Besides the Arihant trial, several other sensitive projects are being undertaken near Visakhapatnam, including an upcoming underground nuclear submarine base that is expected to house India’s strategic assets.

Friday, June 15, 2012

The cyber war is coming to Eurosatory

It is a sign of the times. The Eurosatory defense exhibition opened in the cyber war for a day of conferences.

This first edition of Cyberdef-Cybersec forum brought together experts (Nicolas Arpagian, scientific director of Cyber ​​Security to INHES , Ardavan Amir-Aslani, a lawyer specializing in issues of public international law, Professor Thomas Rid, Department of Studies War of Kings College London), soldiers (including Lt. Gen. Hernandez, head of U.S. Army Cyber ​​Command and Rear Admiral Coustillière, General Officer in charge of cyber defense at the Ministry of Defence) and industry (EADS Cassidian and Thales Communication & Security).

The program of the day addressed the doctrines of use of cyber weapons, legal considerations, and threats against-measures, or the cost of cyber attacks, both for states that private firms.
On this last point, Sebastien Heon (EADS Cassidian) aptly summarized the situation: protection against cyber risks is still too often seen by the Directorates-General as the case of single RSSI, then it is a governance issue that is beyond the scope of the ISS to reach to that enterprise risk.  It's a question of risk, which is not work but that the RSSI of those responsible in the company to quantify the risk and wear the proper hierarchical level ", he says. Thus, according to Sebastian Heon, if DGs do not give the cyber risk due importance is primarily due to poor positioning of the latter. What do you think?

Small arrangements between States

Finally, the palm of the subject returns to the most original Master Ardavan Amir-Aslani, who asked the question of legal recourse against a cyber-aggression between states. An exercise that is not as obvious as it seems and that demonstrates how the fight cyber still operates in a legal limbo.

The heart of the matter lies in the precise definition of what constitutes an armed attack. Because of this distinction will depend on the ability of victims to obtain compensation or justify any act of self-defense. The physical destruction of an industrial complex, even if it involves any conventional weapon, he is an armed attack? (Bet that Iran follows this thinking very carefully!)

For the United Nations, a cyber attack is currently an assault course, but not armed. The use of self-defense would not be possible under these conditions.

But international opinion seems to change about it: most recently in Estonia participants in the fourth International Conference on Cyber ​​Conflict (Cycon, organized by a branch of NATO) all seemed to agree to consider aggression as a cyber attack army. And this is what the United States for some years already profess reserving the right to respond to a cyber attack by a conventional military strike. It is likely that in future the rest of the world lines up behind the U.S. position.

From a strictly legal standpoint, Mr. Amir-Aslani is a reflection of two steps: first define aggression in a cyber: unauthorized access to a computer system, with amendment thereto, and all with intent harm.Next, define the look "armed" of the thing. And then he's looking at the impact tool. Thus, if the purpose is the destruction or neutralization of an industrial site, this would be much of an armed attack.Following this reasoning it would be possible to distinguish between a Stuxnet destructive purpose, and a Flame, which regardless of how advanced it is the intelligence operation (which, once discovered, is generally the rule a friendly and discreet service between the countries concerned)

If the armed attack is proven, yet he remains to find a remedy. To do this two ways are proposed: the International Court of Justice if both parties consent to the jurisdiction thereof, or possibly the Security Council of the United Nations (which seems to have initiated discussions on the issue  cyber)

Wednesday, May 30, 2012

Iran: Iran Shows Prompt Response to Israeli Cyber War

Wednesday, May 30, 2012
Iran: Iran Shows Prompt Response to Israeli Cyber War
Iran Shows Prompt Response to Israel's Cyber War
News number: 9103080189 12:00 | 2012-05-30
http://english.farsnews.com/newstext.php?nn=9103080189
TEHRAN (FNA)- Iran declared on Tuesday that it has produced an anti-virus
program against "Flame," an extraordinarily sophisticated malware that
attacked its servers recently.
In a statement, Iran's National Computer Emergency Response Team said that
"investigations during the last few months" had resulted in the detection of
the virus, which has been dubbed Flame and is capable of stealing data from
infected computers.
"It seems there is a close relation to the Stuxnet and Duqu targeted
attacks," the statement said, adding that the malware's "propagation
methods, complexity level, precise targeting and superb functionality" were
reminiscent of the Stuxnet and Duqu cyber threats to which Iran had also
fallen victim.
Stuxnet was designed to damage Iran's nuclear sites, specially Natanz
uranium enrichment facility. Duqu, like Flame, was apparently built for
espionage but shared characteristics with Stuxnet.
Iran's National Computer Emergency Response Team also said it has developed
tools to detect and remove Flame from infected computers.
It said that the detection and clean-up tool was finished in early May and
is now ready for distribution to organizations at risk of infection.
Security companies said Flame, named after one of its attack modules, is one
of the most complex threats ever seen.
Iran says its home-grown defense could both spot when Flame is present and
clean up infected PCs.
Flame was discovered after the UN's International Telecommunications Union
asked for help from security firms to find out what was wiping data from
machines across the Middle East.
An investigation uncovered the sophisticated malicious program which, until
then, had largely evaded detection.
An in-depth look at Flame by the Laboratory of Cryptography and System
Security at Hungary's University of Technology and Economics in Budapest,
said it stayed hidden because it was so different to the viruses, worms and
trojans that most security programs were designed to catch.
In addition, said the report, Flame tried to work out which security
scanning software was installed on a target machine and then disguised
itself as a type of computer file that an individual anti-virus program
would not usually suspect of harboring malicious code.
Graham Cluley, senior technology consultant at security firm Sophos, said
the program had also escaped detection because it was so tightly targeted.
"Flame isn't like a Conficker or a Code Red. It's not a widespread threat,"
he told the BBC. "The security firm that talked a lot about Flame only found
a couple of hundred computers that appeared to have been impacted."
Mr. Cluley said detecting the software was not difficult once it had been
spotted.
"It's much much easier writing protection for a piece of malware than
analyzing what it actually does," he said. "What's going to take a while is
dissecting Flame to find out all of its quirks and functionality."
It is not yet clear who created Flame but experts say its complexity
suggests that it was the work of a nation state rather than hacktivists or
cyber criminals.
Figures released by Kaspersky Labs in a report about the malicious program
said 189 infections were reported in Iran, compared to 98 in
Israel/Palestine and 32 in Sudan. Syria, Lebanon, Saudi Arabia and Egypt
were also hit.
Israel has tried to take the credit for the malware with its Deputy Prime
Minister Moshe Ya'alon saying on Tuesday that "whoever sees the Iranian
threat as a serious threat would be likely to take different steps,
including these, in order to hurt them."
Speaking in an interview with Israel's Army Radio, Ya'alon further hinted
that Jerusalem was behind the cyber attack.
"These achievements of ours open up all kinds of possibilities for us,"
Ya'alon added.
In April, Iran briefly disconnected servers from the net at its Kharg island
oil terminal as it cleared up after a virus outbreak - now thought to be
caused by Flame.

Monday, January 2, 2012

Japan developing cyber weapon

JAPAN has been developing a virus that could track down the source of a cyber attack and neutralise its program, the daily Yomiuri Shimbun reported on Sunday 01/01/12. The weapon is the culmination of a ¥179 million ($2.3 million), three-year project entrusted by the government to technology maker Fujitsu to develop a virus and equipment to monitor and analyse attacks, according to the report. The US and China reportedly also have put so-called cyber weapons into practical use.
 Japan will have to make legal amendments to use a cyber weapon, as it could violate the country's law against the manufacture of a computer virus, the newspaper said. Japan's parliament came under cyber attack in October, apparently from the same emails linked to a China-based server that already hit several lawmakers' computers. It also was reported that Japanese computers at embassies and consulates in nine countries were infected with viruses in the summer.

Currently, the virus is being tested in a "closed environment" to examine its applicable patterns.

Sunday, January 1, 2012

China’s Cyber Command - Proof that IT EXISTS

Chinese analysts and officials like to point out that it was the United States that first set up Cyber Command and thus, in their view, militarized cyberspace. Yet Chinese military thinkers are clearly thinking about what type of organizations and institutions they will need to conduct offensive cyber operations and to defend their own networks against attacks. An interesting piece in China Defense Daily lays out some of the characteristics necessary for “a highly effective command system for cyber war mobilization.”

-- Military and civilian networks are interconnected, and the resources needed for cyber war permeate society; military units, social organizations, and even individuals “will all possibly become combat forces during a cyber war.”
-- Given this diffusion of resources, there is a need for a cyber war mobilization command system with a “vertical command hierarchy” that reaches into all of society.

-- Each of the branches of the military should have its own command division, manage necessary resources, cultivate forces, and organize training and drills. Once a war breaks out, there needs to be a “coordinated strategic level” command structure that mobilizes resources and launches combat operations.
-- There must be specialized troops within industrial sectors, with especially strong ties to the information industries.
-- Need to enlarge specialized cyber troops, recruiting computer network experts. The People’s Liberation Army should also reach out to all segments of society and create cyber reserves and people’s militias.
-- Offense and defense in cyber war have distinct characteristics, and they change frequently. Offensive technologies include computer viruses, EMP bombs, microwave bombs, and computer and microchip backdoors.  For defense, there are network scanners, network wiretapping devices, password breaking devices, electromagnetic detectors and firewalls, and anti-virus software.
-- Because the technological requirements of these weapons are very high, there must be extensive R&D programs into new offensive weapons as well as the defensive and offensive capabilities of the potential adversary.

This is a very “whole of society” approach, one that seems to fundamentally grasp that power in cyberspace is multi-faceted and spread throughout society. And while we assume that Chinese policymakers can simply mobilize these social forces to bolster state power, is that actually the case? And if it’s true now, might that change?

linkwithin

Related Posts Plugin for WordPress, Blogger...
© Copyright 2012-2013 — Asian Defence News. All Rights Reserved