Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Thursday, July 14, 2011

'fight the net': pentagon unveils 'defensive' cyberwar strategy

'fight the net': pentagon unveils 'defensive' cyberwar strategy
from time: The Pentagon rolled out its new cyber-defense strategy Thursday, hyping it with the news that foreign hackers (from an unidentified country) invaded the computers of one of its (unidentified) contractors in March and pilfered 24,000 sensitive documents in one fell swoop. Cyber-security is a Pentagon growth area, make no mistake about. Lord knows, I've contributed to the deluge. But it's one of those arcane areas where progress is hard to measure. Is the threat as dire as sometimes portrayed? It's important to realize that the Pentagon doesn't store real secrets on networks linked to the Internet. Nonetheless, the press can't resist stories about offensive cyber warfare. Deputy Defense Secretary William Lynn, who unveiled the new cyber strategy, told an audience at the National Defense University in Washington that "crucial" files -- not "secret" or "top secret" -- have been stolen in recent years. Much taken was of little value, he said: "But a great deal of it concerns our most sensitive systems, including aircraft avionics, surveillance technologies, satellite communications systems and network security protocols." Over breakfast Thursday, Marine General James Cartwright, the vice chairman of the Joint Chiefs, said the Pentagon's current emphasis on cyber defense needs to change. It's currently 90% defensive and 10% offensive; he said those numbers need to be swapped. "This strategy talks more about how we are going to defend the networks," he said. "The next iteration will have to start to talk about here's a strategy that says to the attacker, ‘If you do this, the price to you is going to go up.'" Safe bet the price to us is going to go up, too.

related updates: former cia head keith alexander says we should 'build a new internet to improve cybersecurity'*
pentagon perception manager knows how to manipulate search engine algorithm*

Monday, June 20, 2011

defense firms see opportunity in cyber attacks

from baltimore sun: A spate of high-profile online break-ins has given defense firms at the Paris Air Show a new sales pitch: cyber security. Targeted by hackers looking to steal source codes, R&D information and trade secrets, aerospace and defense firms are turning the tables on the pirates and are making security a key sales argument. "We see huge potential to do deals this week because interest in cyber security has soared given recent events," Paul MacGregor, general manager of Finmeccanica's UK security arm, Vega Consulting Services, told Reuters. He added that cyber security was now an "arms race," with defense firms battling to stay one step ahead of the hackers. "Information is now used as a weapon and companies need to defend it at all costs or they themselves could lose out on contracts if they are seen as having weak defenses," he said.

Wednesday, May 25, 2011

dhs to gain 'autonomy' under obama cybersecurity plan

dhs merges with dod/nsa under obama's cyber threat plan
dhs merges with dod/nsa under obama's cyber threat planfrom kurt nimmo: Obama has proposed legislation that will give the Department of Homeland Security more “autonomy” in its effort to protect civilian computer networks from ostensible cyber attack, according to Information Week. White House officials testified Monday before the Senate Committee on Homeland Security and Governmental Affairs about the comprehensive plan presented by the administration two weeks ago to create legislation to protect critical infrastructure and networks. It will merge operations with the Pentagon.

“One key aspect of the plan is to put the DHS’s mission to protect U.S. federal civilian networks on par with the DOD’s mission to protect U.S. military networks, giving the DHS more autonomy to act against cyberthreats on behalf of the government than before,” writes Elizabeth Montalbano for the technology publication.

DHS has also sought to merge the effort with the NSA and various civilian operations.

Last October, the Obama administration adopted new procedures for using the Defense Department’s vast array of cyberwarfare capabilities in case of an attack on vital computer networks inside the United States, “delicately navigating historic rules that restrict military action on American soil,” according to the New York Times.

According to the Times, a team of military networking experts would be assigned to the operations center at the Homeland Security Department. The new approach will begin with a Department of Homeland Security team deploying to Fort Meade, Maryland, home to both the National Security Agency, which specializes in electronic espionage, and the military’s new Cyber Command.

At the time, government officials said the new rules contain “a rapid response to a cyberthreat while balancing concerns that civil liberties might be at risk should the military take over such domestic operations,” in other words the government announced effort to protect against the hyped threat of cyber terrorism would require a sacrifice of liberty.

The DHS plan announced on Monday will give “the DHS – recognizing our similar role to DOD with regard to federal civilian networks – similar authority with regard to personnel so we can bring them on board rapidly,” Philip R. Reitinger, deputy undersecretary for the DHS National Protection and Programs Directorate, told Congress.

The plan also gives DHS “much clearer authority and responsibility to work in a voluntary way” with the private sector, something it already has been doing, Reitinger added.

In 2009, Pentagon spokesman Bryan Whitman sidestepped answering if the Pentagon’s cyber command would be capable of offensive operations as well as protecting the Department of Defense. “This command is going to focus on the protection and operation of DoD’s networks,” he said. “This command is going to do what is necessary to be able to do that.”

In 2006, a Pentagon document entitled the Information Operation Roadmap was released to the public after a Freedom of Information Request by the National Security Archive at George Washington University. It states that the Pentagon has developed a “robust offensive suite of capabilities to include full-range electronic and computer network attack… We Must Fight the Net.”


related updates:
facebook & google join forces to oppose privacy bill*
18 places censored by google maps:
from aberdeen proving grounds in maryland to... north korea
*
nsa collects as much data as is stored in the entire library of congress every 6hrs?*
video: nsa whistleblower tom drake talks espionage act, 9/11 & intel with '60 minutes'*

Sunday, May 1, 2011

zeus attack kit: a steal for cybercriminals

zeus attack kit: a steal for cybercriminalsZeus attack kits are filling a niche in best spirit of capitalism and with as much moral perspective! Attack or exploit kits, as they are known in the industry, are growing more prevalent. You can become a cybercriminal without technical expertise or time dedicated to build your own exploit! Symantec, internet security firm and maker of Norton Anti-Virus, issued a recent threat report on proliferation of this cybercrime. Symantec TV also provides eye-opening video: Attack Toolkits in 90 seconds. A News.com.au article surveys threat posed by attack kits. Zeus sells for $700. "Other known crimeware tools include the Fragus Exploit Kit and the Spyeye." An M86 Security Lab Report supplies a nice history and growth of this cyber-threat! A must read for anyone interested in offensive computing!

Wednesday, April 27, 2011

langner warns stuxnet generic

langner warns stuxnet genericCyber security expert Ralph Langner reports his research into Stuxnet in a must see video from a recent Ted Talk. While an article by Washington's Blog, "Could a Rogue Computer Virus be Used to Shut Down Nuclear Plants Worldwide?", has gone viral; the real news is Langner's revelation that "Stuxnet is generic", which implies its flexible code can easily attack other industrial sites not just nuclear plants. The Ugly Truth quotes Langner's pointed comment, “you fail to understand that the hacker underground has been studying control systems for years without any success. You fail to understand that this community will eagerly dismantle Stuxnet as a blueprint for how to cyber-attack installations from the cookie plant next door to power plants.” Virus protection will be at a premium for commercial applications!

Saturday, March 5, 2011

latest salvo in korean cyberwar

latest salvo in korean cyberwarCybersecurity firm Ahnlab, in a guardian.co.uk article, reported a denial of service attack (DoS) that targeted "... websites belonging to South Korea's presidential office, the foreign ministry, the national intelligence service, US Forces Korea and major financial institutions." Park Kun-woo, Ahnlab spokesman, advised attacks were similar to past ones - a DoS type of attack, and largely, same websites involved. Ahnlab reported a computer user found a bug, and after analysis, discovered malware designed to attack websites. The targets were warned in advance, as a result, experienced only brief slow downs. South Korean officials, in the past, have traced cyberattacks back to China. The current article is only reporting, "it was not immediately clear from where Friday's attack originated." Does this represent new posturing - a reversal - in messages sent in a spirit of keeping peace?

Wednesday, January 19, 2011

internet routing structure most vulnerable

internet routing structure most vulnerable Cybersecurity expert Peter Sommer of the London School of Economics warns nations against following Pentagon's lead of developing a military division to defend against cyber threats in recent article at NewScientist website. "The military can only defend its own networks not the private-sector critical networks we all depend on for gas, water, electricity and banking, making such military efforts a waste of taxpayers' money." Sommer, co-author of a very readable new report, "Reducing Systemic Cybersecurity Risk", advises governments should quit panicking and take a disciplined approach. It's, possibly, time to sit up and take notice when advice is coming from the author of "The Hacker's Handbook," first published in 1985.

The report casts doubt whether cyberwarfare will ever have global significance on a scale, of say, a pandemic or a bank run. Sommer feels it's more likely attacks on the internet's routing structure will cause pockets of misery at the local level. PricewaterhouseCoopers security manager Jay Abbott, also, believes the routing structure is vulnerable. "Short of physically cutting the wires, it's the best way to take down a country from the internet." It makes an interesting read to take in opinions of cybersecurity experts.

Wednesday, December 15, 2010

stuxnet remains problem for iran nuke sites

stuxnet remains problem for iran nuke sitesCybersecurity experts in the United States report an increase in internet traffic to their websites from Iran. The experts add there appears to be, also, strenuous efforts to hide the traffic's origin. A Fox News article, "Stuxnet Worm Still Out of Control at Iran's Nuclear Sites, Experts Say", infers from the internet traffic there are still problems. The article describes the Stuxnet worm as "...equipped with a warhead that targeted and took over the controls of the centrifuge systems at Iran’s uranium processing center in Natanz, and it had a second warhead that targeted the massive turbine at the nuclear reactor in Bashehr". Ralph Langner, a German expert, believes Iranians need to throw out their computers but adds they can't, "they will just continually reinfect themselves".

Wednesday, August 25, 2010

defense official discloses cyberattack

or: dod & cfr vs usb
defense official discloses cyberattackfrom washington post: Now it is official: The most significant breach of U.S. military computers was caused by a flash drive inserted into a U.S. military laptop on a post in the Middle East in 2008. In an article to be published Wednesday discussing the Pentagon's cyberstrategy, Deputy Defense Secretary William J. Lynn III says malicious code placed on the drive by a foreign intelligence agency uploaded itself onto a network run by the U.S. military's Central Command. "That code spread undetected on both classified and unclassified systems, establishing what amounted to a digital beachhead, from which data could be transferred to servers under foreign control," he says in the Foreign Affairs article.

update: insiders doubt hack was foreign spy attack

Tuesday, June 29, 2010

cybersecurity measures would mandate govt 'id tokens' to use the net

cybersecurity measures would mandate govt 'id tokens' to use the netfrom paul joseph watson & alex jones: The move to shut down and regulate the Internet under a new government-controlled system has accelerated into high gear with the announcement that the government’s cybersecurity strategy revolves around issuing Internet users with ID “tokens” without which they will not be able to visit websites, the latest salvo against web freedom which, in combination with Senator Joe Lieberman’s ‘kill switch’ bill, will serve to eviscerate the free Internet as we know it.

Under the guise of “cybersecurity,” the government is moving to discredit and shut down the existing Internet infrastructure in the pursuit of a new, centralized, regulated world wide web.

This exact strategy was outlined in a paper published by Obama’s cybersecurity co-ordinator Howard Schmidt, which was compiled with the aid of the National Security Council.

The strategy revolves around, “The creation of a system for identity management that would allow citizens to use additional authentication techniques, such as physical tokens or modules on mobile phones, to verify who they are before buying things online or accessing such sensitive information as health or banking records,” reports the FInancial Times.

Only with this government-issued “token” will Internet users be allowed to “able to move from website to website,” a system not too far removed from what China proposed and rejected for being too authoritarian.

Sunday, June 27, 2010

obama internet 'kill switch' plan approved by US senate

obama internet 'kill switch' plan approved by US senatefrom techworld: A US Senate committee has approved a wide-ranging cybersecurity bill that some critics have suggested would give the US president the authority to shut down parts of the Internet during a cyberattack.

Senator Joe Lieberman and other bill sponsors have refuted the charges that the Protecting Cyberspace as a National Asset Act gives the president an Internet "kill switch." Instead, the bill puts limits on the powers the president already has to cause "the closing of any facility or stations for wire communication" in a time of war, as described in the Communications Act of 1934, they said in a breakdown of the bill published on the Senate Homeland Security and Governmental Affairs Committee website.

The committee unanimously approved an amended version of the legislation by voice vote Thursday, a committee spokeswoman said. The bill next moves to the Senate floor for a vote, which has not yet been scheduled.

Thursday, May 13, 2010

pentagon says military response to cyber attack 'possible'

prepping us for the coming of 'virtual flag terrorism'
pentagon says military response to cyber attack 'possible'from defence talk: The Pentagon would consider a military response in the case of a cyber attack against the United States, a US defense official said on Wednesday. Asked about the possibility of using military force after a cyber assault, James Miller, undersecretary of defense for policy, said: "Yes, we need to think about the potential for responses that are not limited to the cyber domain."

But he said it remained unclear what constituted an act of war in cyberspace. "Those are legal questions that we are attempting to address," Miller said at a conference in Washington, adding that "there are certainly a lot of grey areas in this field."

He said hostile acts in cyberspace covered a wide range, from digital espionage to introducing false data into a network, that did not necessarily represent full-blown war.

But he said the threat to US networks from terrorists, criminals and others was real and growing. "Over the past decade, we've seen the frequency and the sophistication of intrusions into our networks increase," he said. "Our systems are probed thousands of times a day."

The Defense Department has about 90,000 employees and troops using computer networks, with about seven million computer devices, he said.

The US military recently created a new cyber command that will be led by Lieutenant General Keith Alexander, head of the secretive National Security Agency. Alexander was confirmed in his post by the US Senate last week.

In his written testimony to Congress, Alexander said that the new cyber command would be prepared to wage offensive operations as well, despite the risk of sustaining damage to US networks. He told lawmakers that he expected digital operations to take place as part of a wider military campaign, but that special legal authority would be required to respond to a cyber attack staged from a neutral country.

Saturday, May 1, 2010

rockefeller calls for 'public-private action' on cybersecurity

rockefeller calls for 'public-private action' on cybersecurityfrom fcw: Cyberattacks aren’t confined by governmental or national boundaries, and neither should cybersecurity programs, Sen. Jay Rockefeller (D-W. Va.), said recently in calling on government and industry to work together to meet the rapidly rising tide of attacks on U.S. information systems.

“National borders and traditional notions of security do not always apply to 21st--century threats, especially in the cybersecurity arena,” he said April 29 at the Business Software Alliance’s Cybersecurity Forum 2010 in Washington. “The idea that government alone can protect our citizens’ security within clear national borders is outdated. Therefore, to secure our country from cyberattacks we must have shared responsibility — public sector and private sector.”

Rockefeller’s bill (S. 773), co-sponsored with Sen. Olympia Snowe (R-Maine), was approved by the Senate Commerce, Science and Transportation Committee March 24. It builds on the idea that cybersecurity is a shared responsibility between the public and private sectors, Rockefeller said. “That’s what this whole bill is about,” he said. Rockefeller chairs the committee.


flashback: cyberbill to give president new emergency powers

Tuesday, April 27, 2010

cia head panetta says 'cyber attack could be next pearl harbor'

cyberwar & repression: corporatist synergy made in hell
from sacramento press: Central Intelligence Agency director Leon Panetta told 300 Sacramento Metro Chamber Cap-to-Cap delegates that the next “Pearl Harbor” is likely to be an attack on the United States’ power, financial, military and other Internet systems.

Panetta addressed the Sacramento delegation that includes 43 elected officials and hundreds of business and civic leaders who are in Washington D.C. for the annual program that advocates for the region’s most pressing policy issues. He spoke on Monday, April 19, during the Cap-to-Cap opening breakfast.

“Cyber terrorism” is a new area of concern for the CIA, Panetta said. The United States faces thousands of cyber attacks daily on its Internet networks. The attacks are originating in Russia, China, Iran and from even hackers.

“The next Pearl Harbor is likely to be a cyber attacking going after our grid… and that can literally cripple this country,” Panetta said. “This is a whole new area of threat.”

But cyber terrorism is just one of four primary missions for Panetta, who took over directing the CIA last year after appointment by President Obama. The CIA is also focusing on counter-terrorism, reducing the proliferation of weapons of mass destruction and fighting narcotics trafficking.


Al Qaeda is becoming a viscous target, and as CIA and military operations tamp it down in Pakistan, Afghanistan and Iraq, the terrorist elements are moving to places like Somalia, Yemen and North Africa—as well changing its tactics, he said.

“The president’s direction…is we must dismantle and destroy Al Qaeda and its known elements,” he said. “It’s a fundamental mission….The primary effort takes place in Pakistan and tribal areas. We are now focused on Afghanistan and have increased our presence there.”

Meanwhile, CIA is working to help Iraqis fight Al Qaeda. “Even as our military draws down in Iraq, we’ll keep our presence there…to provide intelligence to the Iraqis so they can secure their own country.”

Worrisome, he added, is how Al Qaeda is “coming at us in other ways.” These include using individuals who have clean records and are not being tracked; individuals who are already in the U.S.A. and in contact with Al Qaeda; and individuals who decided to “self-radicalize” and are easily and quickly recruited as terrorists.

Previously, Panetta served as a congressional representative from the Monterey area, rising to the House Budget committee chair, and then latter as President Clinton’s Director of the Office of Management and Budget.

“I’ve spent most of my life on budget issues,” he said, noting the “work we did eventually produced a balanced budget for the country.” When he’s asked why he took on the job at the CIA, he told the group, “Because considering the size of the federal deficit, I’d rather fight Al Qaeda.”

Monday, April 19, 2010

pentagon's cybercom says civilian infrastructure a 'legitimate' target

pentagon's cybercom says civilian infrastructure a 'legitimate' targetfrom antifascist calling: When U.S. Secretary of Defense Robert M. Gates launched Cyber Command (CYBERCOM) last June, the memorandum authorizing its stand-up specified it as a new "subordinate unified command" under U.S. Strategic Command (STRATCOM), one that "must be capable of synchronizing warfighting effects across the global security environment as well as providing support to civil authorities and international partners."

As Antifascist Calling reported at the time, Gates chose Lt. General Keith Alexander, the current Director of the National Security Agency (NSA), to lead the new DOD entity. The agency would be based in Ft. Meade, Maryland, where NSA headquarters are located and the general would direct both organizations.

In that piece I pointed out that STRATCOM is the successor organization to Strategic Air Command (SAC). One of ten Unified Combatant Commands, STRATCOM's brief includes space operations (military satellites), information warfare, missile defense, global command and control, intelligence, surveillance and reconnaissance (ISR), as well as global strike and strategic deterrence, America's first-strike nuclear arsenal. Designating CYBERCOM a STRATCOM branch all but guarantees an aggressive posture.
As an organization that will unify all military cyber operations from various service branches under one roof, CYBERCOM will coordinate for example, Air Force development of technologies to deliver what are called "D5 effects" (deceive, deny, disrupt, degrade and destroy).

Ostensibly launched to protect military networks against malicious attacks, the command's offensive nature is underlined by its role as STRATCOM's operational cyber wing. In addition to a defensive brief to "harden" the "dot-mil" domain, the Pentagon plan calls for an offensive capacity, one that will deploy cyber weapons against imperialism's adversaries.

As a leading growth sector in the already-massive Military-Industrial-Security-Complex, the cyberwar market is hitting the corporate "sweet spot" as the Pentagon shifts resources from Cold War "legacy" weapons' systems into what are perceived as "over-the-horizon" offensive capabilities.

In association with STRATCOM, the Armed Forces Communications and Electronics Association (AFCEA), will hold a Cyberspace Symposium, "Ensuring Commanders' Freedom of Action in Cyberspace," May 26-27 in Omaha, Nebraska.

Chock-a-block with heavy-hitters in the defense and security world such as Lockheed Martin, HP, Booz Allen Hamilton, CACI, Cisco, CSC, General Dynamics, QinetiQ, Raytheon and the spooky MITRE Corporation, the symposium seeks to foster "innovation and collaboration between the private sector and government to delve into tough cyber issues." The shin-dig promises to "feature defense contractors and government agencies showcasing their solutions to cyberspace and cyber warfare issues."

During pro forma hearings before the Senate Armed Services Committee (SASC) April 15, Alexander's testimony was short on specifics, as were his written responses to "Advance Questions" submitted to the general by the SASC.

During Thursday's testimony, Alexander told the Senate panel that the command "isn't about efforts to militarize cyberspace," but rather "is about safeguarding the integrity of our military's critical information systems."

"If confirmed" Alexander averred, "I will operate within applicable laws, policies and authorities. I will also identify any gaps in doctrine, policy and law that may prevent national objectives from being fully realized or executed."

What those "national objectives" are and how they might be "executed" are not publicly spelled out, but can be inferred from a wealth of documents and statements from leading cyberwar proponents.

As we will explore below, despite hyperbole to the contrary, CYBERCOM represents long-standing Pentagon plans to militarize cyberspace as part of its so-called "Revolution in Military Affairs" and transform the internet into an offensive weapon for waging aggressive war.