Hello dear readers!
I wanted to let you know that we have moved to a new spot. Same posts that you like but now more integrated with our company webpage.
As always, we'd love to hear from you regarding topics and ideas that you'd like to hear about.
We appreciate all the input over the years and we hope you will join us and follow us at our new location.
http://www.fortalicesolutions.com/blog/
Other Links of Interest
Contributors
Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts
Friday, September 20, 2013
Tuesday, June 19, 2012
New Huffington Post Article: What Exactly is 'Internet Safety'?
Fortalice Chief Advisor, Theresa Payton, has written a new article for the Huffington Post in honor of June being "National Internet Safety Month." Check out the article and share cyber safety tips with friends and loved ones: http://www.huffingtonpost.com/theresa-payton/what-exactly-is-internet-_b_1600509.html!
Monday, May 14, 2012
Protecting Your Internet Identity Book Signing! May 31, 2012
Protecting Your Internet Identity: Are You NAKED Online? authors,Theresa Payton and Ted Claypoole will be holding their official book launch party Thursday May 31, 2012 at 7pm in Charlotte NC!
Come out to pick up your copy of this fabulous book as well as join the authors for book signings and refreshments! Ted and Theresa will also be on hand to answer any questions you might have about internet safety and privacy.
The event will be held at Park Road Book store.
Stay safe and don’t let your identity run around naked online!
Event details:
5/31/12, 7pm
Park Road Books:
Park Road Shopping Center at the intersection of Park Rd and Woodlawn Rd.
4139 Park Road
Charlotte, NC 28209
Tel: 704-525-9239
Wednesday, January 5, 2011
The new heist - your conversations and text messages
The good guys strike again. I have said before that technology functionality typically outpaces the ability to secure it. Good guys are constantly trying to think like the bad guys to expose weaknesses that put you at risk.
Also, the term "hacker" has been hijacked and is associated with bad guys. A hacker is someone who knows how to break into a system to override it. This skill can be used for good, or for evil. It's at the hands of the person's moral compass.
Two cybersecurity good-guy hackers worked on cell phone vulnerabilities for roughly a year designing ways to think like bad guys to see if they could steal text messages. They recently accomplished this feat and showed how they could steal text messages from any phone within 20 seconds. Wow!
The demonstration:
1. The hacker sends a ghost text message to a target phone which does NOT show up on the phone
2. By sending the message to the target phone, they are able to obtain the unique id number on the phone
3. Once they grab the id number, the recorded phone conversations and texts from that phone
4. The demonstration took place on the GSM Network which houses roughly 80% of all phones globally. (GSM - Global System for Mobile)
So, is this affordable or scalable? What was the cost of the technology? You'll be surprised:
Roughly 36 British Sterling for the 4 Motorola phones ($56.09 US) and some sweat equity in programming.
The good-guy hackers did this as a wake up call to the mobile security industry. It should also be a wake up call to consumers, businesses, and government agencies.
Great quote from one of the researchers pulled from the Security News Daily:
“This is all a 20-year-old infrastructure, with lots of private data and not a lot of security,” Karsten Nohl.
Sources:
"Cybersecurity Experts Create Program That Steals Text Messages", Matt Liebowtiz, Security News Daily, January 4, 2011.
"GSM Phones Vulnerable to Hacking, Claim Researchers", John Plunkett, The Guardian, December 31, 2010.
Also, the term "hacker" has been hijacked and is associated with bad guys. A hacker is someone who knows how to break into a system to override it. This skill can be used for good, or for evil. It's at the hands of the person's moral compass.
Two cybersecurity good-guy hackers worked on cell phone vulnerabilities for roughly a year designing ways to think like bad guys to see if they could steal text messages. They recently accomplished this feat and showed how they could steal text messages from any phone within 20 seconds. Wow!
The demonstration:
1. The hacker sends a ghost text message to a target phone which does NOT show up on the phone
2. By sending the message to the target phone, they are able to obtain the unique id number on the phone
3. Once they grab the id number, the recorded phone conversations and texts from that phone
4. The demonstration took place on the GSM Network which houses roughly 80% of all phones globally. (GSM - Global System for Mobile)
So, is this affordable or scalable? What was the cost of the technology? You'll be surprised:
Roughly 36 British Sterling for the 4 Motorola phones ($56.09 US) and some sweat equity in programming.
The good-guy hackers did this as a wake up call to the mobile security industry. It should also be a wake up call to consumers, businesses, and government agencies.
Great quote from one of the researchers pulled from the Security News Daily:
“This is all a 20-year-old infrastructure, with lots of private data and not a lot of security,” Karsten Nohl.
Sources:
"Cybersecurity Experts Create Program That Steals Text Messages", Matt Liebowtiz, Security News Daily, January 4, 2011.
"GSM Phones Vulnerable to Hacking, Claim Researchers", John Plunkett, The Guardian, December 31, 2010.
Thursday, December 16, 2010
Cybersecurity - It is a joint effort
Cybersecurity is a joint effort. The Federal Government cannot solve the problems without help from the Private Sector. The Private Sector does not have the full threat picture to go it alone.
There are a plethora of forums where the Federal Government and the Private Sector come together to share ideas and information to help fight the good fight. But, is it enough? Are these forums effective? What is your opinion?
One announcement that hit the media this week was that a research agreement was signed between financial services companies, insurance companies, NIST (National Institute of Standards and Technology), and the Department of Homeland Security's Directorate called S&T (Science and Technology).
The MOU (memo of understanding), which is a signed agreement, says they will collaborate on research.
Federal News Radio quoted Aneesh Chopra, the Federal Chief Technology Officer as saying, "Financial services-banking and credit card transactions, insurance, trading and funds management, and many other business and consumer financial activities-are increasingly provided online," ... emphasizing the importance of collaboration.
White House Cybersecurity Coordinator and Special Assistant to the President, Howard A. Schmidt, posted on his blog, "As a result, threats to these services are threats to individuals, companies and the nation. Ensuring these online services are reliable, accurate, safe and secure against threats is a shared responsibility of the public and private sectors alike. Many of the innovations emerging from the partnership will extend beyond financial services to online health services, the Smart Grid, and the nation's water, transportation, and other critical infrastructures."
Sources:
Press Release by NIST: "Financial Services Sector Signs Cybersecurity Research Agreement with NIST, DHS", Contact: Evelyn Brown, December 8, 2010.
"NIST, DHS to partner with financial industry on cybersecurity", Jason Miller - Executive Editor, Federal News Radio, December 7, 2010.
Blog Post, Office of Science and Technology Policy, Executive Office of the President, Howard A. Schmidt, December 6, 2010.
There are a plethora of forums where the Federal Government and the Private Sector come together to share ideas and information to help fight the good fight. But, is it enough? Are these forums effective? What is your opinion?
One announcement that hit the media this week was that a research agreement was signed between financial services companies, insurance companies, NIST (National Institute of Standards and Technology), and the Department of Homeland Security's Directorate called S&T (Science and Technology).
The MOU (memo of understanding), which is a signed agreement, says they will collaborate on research.
Federal News Radio quoted Aneesh Chopra, the Federal Chief Technology Officer as saying, "Financial services-banking and credit card transactions, insurance, trading and funds management, and many other business and consumer financial activities-are increasingly provided online," ... emphasizing the importance of collaboration.
White House Cybersecurity Coordinator and Special Assistant to the President, Howard A. Schmidt, posted on his blog, "As a result, threats to these services are threats to individuals, companies and the nation. Ensuring these online services are reliable, accurate, safe and secure against threats is a shared responsibility of the public and private sectors alike. Many of the innovations emerging from the partnership will extend beyond financial services to online health services, the Smart Grid, and the nation's water, transportation, and other critical infrastructures."
Sources:
Press Release by NIST: "Financial Services Sector Signs Cybersecurity Research Agreement with NIST, DHS", Contact: Evelyn Brown, December 8, 2010.
"NIST, DHS to partner with financial industry on cybersecurity", Jason Miller - Executive Editor, Federal News Radio, December 7, 2010.
Blog Post, Office of Science and Technology Policy, Executive Office of the President, Howard A. Schmidt, December 6, 2010.
Wednesday, November 24, 2010
Leading Cyber Official Says "Yes" We are At A Great Disadvantage for a Cyber Attack
Admiral J. Michael McConnell, the former Director of National Intelligence now at Booz Allen Hamilton was interviewed recently by Forbes.
He indicated that a cyber attack is inevitable.
When he was asked, "Are we at a greater disadvantage than any of our adversaries?" He answered, "
Yes, and there’s a very simple reason: We’re more vulnerable because we’re more dependent [on technology]."
Mr. McConnell said change will only come about through dialogue otherwise it will happen after a catastrophe.
Mr. McConnell noted that intellectual capital is also at risk, not just information and money.
Sources:
"Former Intelligence Chief Says A Cyber Attack Is Inevitable", Brian Wingfield, Business in the Beltway - Forbes Blog, November 23, 2010.
He indicated that a cyber attack is inevitable.
When he was asked, "Are we at a greater disadvantage than any of our adversaries?" He answered, "
Yes, and there’s a very simple reason: We’re more vulnerable because we’re more dependent [on technology]."
Mr. McConnell said change will only come about through dialogue otherwise it will happen after a catastrophe.
Mr. McConnell noted that intellectual capital is also at risk, not just information and money.
Sources:
"Former Intelligence Chief Says A Cyber Attack Is Inevitable", Brian Wingfield, Business in the Beltway - Forbes Blog, November 23, 2010.
Friday, October 22, 2010
U.S. Military Expands Its Cybersecurity Role
A series of new processes and procedures for cybersecurity were put into place this month. They pave the way to better leverage the Defense Department's cyberwarfare capabilities in case there is an attack on the U.S. networks.
Think about the situation where you have a wildfire raging or a major hurricane. The President can sign an order that allows FEMA to organize and coordinate recovery efforts using U.S. military forces. The new procedures adopted for cybersecurity follow similar guidelines.
In this case, DHS would direct the work of the U.S. military.
According to a New York Times article, DHS team will deploy to a military base on Fort Meade, Md where the NSA and the military have instituted the Cyber Command. A team of experts from Cyber Command will be assigned to the operations center at DHS.
Protection of civil liberties will be managed through a team of lawyers.
Sources:
"Pentagon Will Help Homeland Security Department Fight Domestic Cyberattacks', Thom Shanker, New York Times, October 20, 2010.
Think about the situation where you have a wildfire raging or a major hurricane. The President can sign an order that allows FEMA to organize and coordinate recovery efforts using U.S. military forces. The new procedures adopted for cybersecurity follow similar guidelines.
In this case, DHS would direct the work of the U.S. military.
According to a New York Times article, DHS team will deploy to a military base on Fort Meade, Md where the NSA and the military have instituted the Cyber Command. A team of experts from Cyber Command will be assigned to the operations center at DHS.
Protection of civil liberties will be managed through a team of lawyers.
Sources:
"Pentagon Will Help Homeland Security Department Fight Domestic Cyberattacks', Thom Shanker, New York Times, October 20, 2010.
Thursday, September 2, 2010
China - Builds Up Cyber Capabilities
The Wall Street Journal posted an article in August focusing on China's military build up. They referred to the annual report released by the Pentagon to Congress.
This recent report is consistent with a briefing that took place earlier this year at the House Armed Services Committee. During the briefing back in January of 2010, the discussion included China's warfare capabilities. Admiral Robert Willard indicated that the military and government systems in the USA are targets of cyber attacks and that many of those attacks appear to originate from within China. He also noted that most of the attacks focus on taking information.
In the report, it indicated that China's military has built up their electronic warfare capabilities. They have designed information warfare units to protect their networks and to attack their foes. Tactics include creating viruses to attack adversaries' systems.
This recent report is consistent with a briefing that took place earlier this year at the House Armed Services Committee. During the briefing back in January of 2010, the discussion included China's warfare capabilities. Admiral Robert Willard indicated that the military and government systems in the USA are targets of cyber attacks and that many of those attacks appear to originate from within China. He also noted that most of the attacks focus on taking information.
The capabilities are considered part of China's Peoples' Liberation Army military modernization program.
Wall Street Journal Article, "U.S. Sounds Alarm at China's Military Buildup", Adam, Entous, August 17, 2010
Defense News Article, "Chinese Buildup of Cyber, Space Tools Worries U.S.", January 13, 2010
Wall Street Journal Article, "U.S. Sounds Alarm at China's Military Buildup", Adam, Entous, August 17, 2010
Defense News Article, "Chinese Buildup of Cyber, Space Tools Worries U.S.", January 13, 2010
Coming to a bank account near you...cyberattacks
Some recent surveys caught my attention as I was preparing to address the Business Innovation Growth council to discuss cyberattacks and what businesses should do to protect themselves.
Symantec released their Internet Security Threat Report in April providing analysis of what happened in 2009 and a look forward to help businesses prepare for the next cyber threats. From their site: "Symantec estimates that the top 10 bot networks now control at least 5 million compromised computers. Throughout 2009, Symantec saw botnet-infected computers being advertised in the underground economy for as little as 3 cents per computer." These are staggering numbers.
Verizon and the United States Secret Service collaborated on a review of approximately 900 cyber breaches. One of their findings was astonishing - 94% of the breaches they reviewed could have been caught if the victims had implemented existing tools and best practices.
The security firm, Kindsight, firm talked to 1200 people aged 18 through 55 about security. 81% of those surveyed said they were victims of computer infections. Almost a third of those infections were in the last 90 days.
Panda Security, which provides security software, did a survey of 1,500 U.S. based businesses and 13% of the companies said they do not use anti virus protection. A different survey indicates that 20% of small businesses do not use antivirus software.
The consequences for businesses that suffer an attack can be devastating:
1. Business banking accounts hacked
Talk to Hillary Machinery Inc and you will feel their pain. Cybercriminals stolen over $800,000 from their bank account. Their bank could only recover $600,000 leaving Hillary Machinery Inc with a gap of $200,000! They have filed a lawsuit against their bank.
2. Losing your customer's data & confidence
3. Theft of intellectual property - I call this the carbon monoxide of cybercrimes - silent, stealthy, and deadly
4. Loss of equipment & productivity after an infection
As we have discussed before, if you are a business customer, your bank account is not offered the same regulatory protections that consumers have for fraud (Regulation E).
Symantec released their Internet Security Threat Report in April providing analysis of what happened in 2009 and a look forward to help businesses prepare for the next cyber threats. From their site: "Symantec estimates that the top 10 bot networks now control at least 5 million compromised computers. Throughout 2009, Symantec saw botnet-infected computers being advertised in the underground economy for as little as 3 cents per computer." These are staggering numbers.
Verizon and the United States Secret Service collaborated on a review of approximately 900 cyber breaches. One of their findings was astonishing - 94% of the breaches they reviewed could have been caught if the victims had implemented existing tools and best practices.
The security firm, Kindsight, firm talked to 1200 people aged 18 through 55 about security. 81% of those surveyed said they were victims of computer infections. Almost a third of those infections were in the last 90 days.
Panda Security, which provides security software, did a survey of 1,500 U.S. based businesses and 13% of the companies said they do not use anti virus protection. A different survey indicates that 20% of small businesses do not use antivirus software.
The consequences for businesses that suffer an attack can be devastating:
1. Business banking accounts hacked
Talk to Hillary Machinery Inc and you will feel their pain. Cybercriminals stolen over $800,000 from their bank account. Their bank could only recover $600,000 leaving Hillary Machinery Inc with a gap of $200,000! They have filed a lawsuit against their bank.
2. Losing your customer's data & confidence
3. Theft of intellectual property - I call this the carbon monoxide of cybercrimes - silent, stealthy, and deadly
4. Loss of equipment & productivity after an infection
As we have discussed before, if you are a business customer, your bank account is not offered the same regulatory protections that consumers have for fraud (Regulation E).
Monday, August 16, 2010
Intern Guest Post - Steven Elliott - Cyberwarfare: Fact or Fiction
Topic: Cyberwarfare
Research by: Steven Elliott
Date: 07/25/2010; Final Version: 8/14/2010
TEASER/TITLE: Cyberwarfare: Fact or Fiction
SUMMARY PARAGRAPH
“There is no cyberwar,” stated Howard Schmidt, the cybersecurity czar for President Obama; however in a Washington Post article Michael McConnell, the former Director of the National Security Agency (NSA), wrote “the United States is fighting a cyberwar today, and we are losing.” (Singel 2010, McConnell 2010). These contrasting statements represent a critical quandary in the cyber security field: whether or not cyberwarfare exists. The opposing sides are adamant that they are correct and wish to implement different security strategies dependent upon their beliefs. The conflict is not disputing the vulnerability of the United States’ network infrastructure or cyber attacks on numerous corporations and nations but rather the definition of cyberwar. Both camps cite a wide variety of evidence to support their drastically differing opinions but both will need to come to a consensus in order for the U.S. to work towards a more secure future.
KEY FINDINGS
· The cyber security community is divided on the definition and implications of the term “cyberwar”.
· Experts that do not believe war can be fought entirely in cyber space argue that government and military expansion into cyberspace would cause massive privacy violations.
· Some cyber security experts desire the capability to retaliate if there were a cyber attack on the U.S.
· The government and military has already started moving towards an expansive definition of cyber space with the creation of Cyber Command, the NSA’s Perfect Citizen program, and the new bill asserting that protecting cyber space is a national asset.
BACKGROUND
Cyberwar has created a division amongst information security specialists – not regarding the existence of cyber attacks but rather the term itself.
WHY THE TERM “CYBERWAR” CONCERNS EXPERTS:
WHY USING THE TERM “CYBERWAR” MAY BE APPROPRIATE:
o Pre-debate: Yes (Exaggerated)-24% No (Not Exaggerated)-54% Undecided-22%
o Post-debate: Yes-23% No-71%, Undecided-6%
o “In a nation as free and as wonderful as ours is, leading the world in human rights and privacy and civil liberties, it's getting the debate framed right to mitigate the risk, to protect the nation consistent with our values and our laws” (Mike McConnell, 2010).
STRATEGIC PLANNING ASSUMPTIONS
· The NSA will start to “detect cyber assaults on private companies and government agencies running [sic] critical infrastructure” with a new program entitled “Perfect Citizen” (Gorman 2010). This program demonstrates that the government believes that cyberspace defense is within its jurisdiction.
· New U.S. legislation could be implemented to ensure that the government takes responsibility for cyber attacks. For example, the ‘Protecting Cyberspace as a National Asset Act of 2010’ S.3480 is a bill introduced to Congress in June 2010. (Community Central 2010)
· Congress and the U.S. military will ultimately need to define cyberwar and the consequences of cyberwarfare attacks on the United States.
· Regardless of the definition of cyberwar, thousands of attacks are being deployed on the private sector and government networks. These important networks will need to be secured (as much as currently possible) or cyber attacks will result in the loss of sensitive data.
ANALYSIS
The differing opinions concerning cyberwar represent a challenge for security professionals. Some private sector companies may believe that the government should be responsible for securing cyber space and, in turn, slacken security procedures. Other companies may benefit greatly from the cyberwar hype by receiving millions of dollars in government contracts. (Schneier 2010) Many of those opposed to cyberwarfare point out that Mike McConnell is an Executive Vice President with cyberwar contractor Booz Allen Hamilton (Doesburg 2010). The constant argument over cyberwar will not likely disappear. Those that believe that there is a cyberwar will highlight the attacks on Estonia, Georgia, South Korea, the United States, Google, and Lockheed Martin and argue that the government should prepare itself for cyberwar. On the other hand, those opposing the concept of cyberwar argue that nationalist hackers could have performed many of those attacks, that blocked websites are simply an annoyance, and that stolen data is actually espionage, not war.
While the definition of cyberwarfare is still a hot debate topic, the cyber security community agrees that gaping holes in United States’ network infrastructure need to be fixed.
There is a clear consensus that U.S. networks are unsecure and the government, private industries, and private citizens need to work towards securing their networks and avoiding unsafe Internet practices. The cyber security community understands the potential threat to the U.S., but in order to move towards a comprehensive cyber security strategy, the cyber security community must come to a consensus on the definition of cyberwar.
RECOMMENDATIONS
· The cyber security community will need to continue to define and reach consensus on the term “cyberwar”. Definitions and industry standard protocols will focus the community on fixing unsecure networks.
· The United States needs to create a comprehensive strategy for securing its networks.
· Private corporations, especially those involved with critical infrastructure, must focus on improving cyber security.
· The government should take responsibility for cyber warfare but should also avoid massive violations of privacy.
· Educating Internet users in basic security practices will help reduce the risk of a successful cyber attack.
SOURCES
Alexander, Keith B. "Video: Cybersecurity Discussion with General Keith B. Alexander, NSA Director, Commander Cyber Command." Speech. Center for Strategic and International Studies. 3 June 2010. Web. 28 July 2010. .
Chabrow, Eric. "Defining, Surviving Cyberwar." Government Information Security News,GovInfoSecurity.com. 26 May 2010. Web. 28 July 2010. .
"Cyberwar: War in the Fifth Domain." The Economist. 1 July 2010. Web. 28 July 2010. .
Doesburg, Anthony. "Anthony Doesburg : Cyberwar? It's a Phoney War, Says IT Expert." NZ Herald. 2 Aug. 2010. Web. 03 Aug. 2010. .
Gorman, Siobhan. "U.S. Program to Detect Cyber Attacks on Infrastructure - WSJ.com." The Wall Street Journal. 8 July 2010. Web. 28 July 2010. .
Greenberg, Andy. "The Real Meaning Of Cyberwarfare." Forbes.com. 3 Mar. 2010. Web. 28 July 2010. .
McConnell, Mike. "Mike McConnell on How to Win the Cyber-war We're Losing." Washingtonpost.com. 28 Feb. 2010. Web. 03 Aug. 2010. .
"New Cybersecurity Bill Introduced in US." Continuity Central. 15 June 2010. Web. 28 July 2010. .
Rotenberg, Marc, Bruce Schneier, Mike McConnell, and Jonathan Zittrain. "The Cyber War Threat Has Been Grossly Exaggerated." Debate. Intelligence Squared U.S. 8 June 2010. Web. 28 July 2010. .
Schneier, Bruce. "The Threat of Cyberwar Has Been Grossly Exaggerated." Schneier on Security. 7 July 2010. Web. 28 July 2010. .
Singel, Ryan. "White House Cyber Czar: ‘There Is No Cyberwar’." Wired News. 4 Mar. 2010. Web. 28 July 2010. yberwar/>.
Intern Guest Post - Steven Elliott - Cyber Warfare and its Impact on the Conflict in Iraq
Topic: Cyber Warfare
Research by: Steven Elliott
Date: 7/12/2010; Final Draft: 8/14/10
TEASER/TITLE: Cyber Warfare and its Impact on the Conflict in Iraq
SUMMARY PARAGRAPH:
When most Americans think about the conflict in Iraq, cyber warfare does not immediately come to mind. However, this high-tech advancement is starting to become more popular with United States military officials and is being utilized in the current conflict in Iraq. Therefore, the U.S. must develop legislation regulating cyber warfare or the slow process of receiving top-level approval could harm future efforts. This paper recognizes some denied and approved cyber attacks that have been used in Iraq, identifies the major causes of the United States’ apprehension about using cyber warfare, and analyzes how the United States can streamline future use of cyber warfare.
KEY FINDINGS
· Former President George W. Bush’s administration cancelled several planned cyber attacks during the Iraq invasion of 2003 because they were concerned about the potential collateral damage of the attack.
· Since as early as 2005, the United States has used cyber attacks to jam Taliban and Iraqi insurgent’s communications devices (Harris 2009).
· Cyber attacks have proved beneficial to the war effort.
· Fear of retaliatory attacks and collateral damage is the main reason the U.S. government is wary of using cyber warfare.
RECOMMENDATIONS
· Learn from past mistakes to hone cyber attack skills.
· Form effective policies that will guide future cyber war.
· Harden U.S. networks against potential pre-emptive and retaliatory threats.
BACKGROUND
Before the conflict in Iraq, there was almost no precedence for U.S. employment of cyber attacks. Although there had been a couple of assaults on Iraqi communications systems, using bombs and attacks to disrupt the power flow using carbon-carbon fiber during the Persian Gulf War, neither of which involved true “cyber warfare” (PBS 2003). In Kosovo, the United States hacked into the Serbian air defense system and distorted images to deceive the Serbian air traffic controllers (PBS 2003). This cyber attack was “essential to the high performance of the air campaign” said John Arquilla, a professor of defense analysis at the U.S. Naval Postgraduate School, in a 2003 PBS interview (PBS 2003).
In 2003, during the months leading up to the invasion of Iraq, the United States planned a cyber attack that would have affected Iraq’s financial system and frozen billions of dollars during the opening stages of the war (Markoff and Shanker 2009). This attack would have effectively shut off Saddam Hussein’s cash flow and, according to one senior Pentagon official, it was planned and could have worked (Markoff and Shanker 2009). However, the plan was never approved by former President George W. Bush’s administration for fear of the potential collateral damage. The Iraqi banking system is connected to networks in France and an attack could have shut down banks and ATM’s all across Europe and even in the United States (Smith 2003). Since this first aborted attack, there have been several successful attacks during the Iraq war on both infrastructural and military targets. Also, President Obama’s administration appears to be increasing its cyber warfare capabilities.
STRATEGIC PLANNING ASSUMPTIONS:
· There will be new international laws pertaining to cyber war. In 2005, the United Nations Institute for Training and Research posted ideas for a law regarding cyber space (Kamal 2005). A formal law has not been written but with the increasing rate of cyber attacks, that may change soon.
· There will be an increase in the use of cyber warfare by the United States especially give the new Cyber Command Center (Daniel 2010).
· The Cyber Command Center and Congress will work collaboratively to create policies regarding cyber warfare (Daniel 2010).
ANALYSIS:
There have been some successful cyber attacks during the Iraq conflict. In 2007, former President George W. Bush’s administration ordered a cyber attack on cell phones, computers, and other communication devices that terrorists were using to plan and carry out roadside bombs (Harris 2009). This attack was coordinated with the surge of military troops. The operation allowed National Security Agency (NSA) hackers to provide false information to the insurgents to lead them into a trap (Harris 2009). These cyber attacks are credited with allowing the military to kill some of the most influential insurgents, according to former U.S. officials (Harris 2009). One other assault occurred at the beginning of the war and involved electronic jamming and destroying communication grids (Markoff and Shanker 2009). Former President G. W. Bush’s administration approved the attack because the collateral damage, inconveniencing telephone services in countries that share cell phone and satellite systems with Iraq, was an acceptable tradeoff (Markoff and Shanker 2009).
The halted 2003 attack, illustrated a large gap in our understanding of cyber weapons and the policies that govern the use of them. Because the world is so interconnected, “it’s virtually certain that there will be unintended consequences,” said Herbert Lin, a senior scientist at the National Research Council in a 2009 interview (Markoff and Shanker 2009). Cyber space is an entity with no bounds and, as such, it is difficult to only hit the intended target. Understanding the consequences of cyber attacks has a tremendous effect on whether attacks will be authorized and how public policy should outline cyber warfare techniques. “Policy makers are tremendously sensitive to collateral damage by virtual weapons, but not nearly sensitive enough to damage by kinetic weapons,” said John Arquilla, an expert in military strategy at the U.S. Naval Postgraduate School (Markoff and Shanker 2009). The worst-case scenario in a cyber attack would involve shutting down the power to a hospital that had been linked to a targeted network. Keeping these scenarios in mind, Congress will need to work with top cyber warfare experts to devise a set of policies because “cyber [war] was moving so fast that we were always in danger of building up precedent before we built up policy," said former CIA director Michael V. Hayden in relation to the former President G. W. Bush administration’s attempts to cultivate policy as operations took place (Nakashima 2010).
Seven years after the denied 2003 attack, there was still no official policy on how the U.S. can and should attack using cyber war techniques. Without definitive policy “cyber warriors are held back by extremely restrictive rules of engagement,” noted Arquilla (Markoff and Shanker 2009). General Keith Alexander, the director of the NSA and commander of the U.S. Cyber Command, believes that the United States needs “the cyber-equivalent of the Monroe Doctrine, a set of clearly defined interests and the steps the government would take to protect them” (Harris 2009).
The use of cyber warfare techniques is also hindered by the fear of a retaliatory attack. In 2003 a meeting involving prominent figures in academia, industry, and government was held at the Massachusetts Institute of Technology (MIT) to discuss whether or not cyber warfare should be used by the United States (Graham 2003). One major concern voiced at this meeting was U.S. vulnerability to attacks. "A lot of institutions and people are worried about becoming subject to the same kinds of attack in reverse," said Harvey M. Sapolsky, an MIT professor (Graham 2003). Unfortunately, in the world of cyber warfare, "our defense is informed by our offense" noted Bob Gourley, the former chief technology officer for the Defense Intelligence Agency (Harris 2009). In order to develop a strong defense the U.S. must have strong offensive capabilities. Furthermore, the United States should ensure that cyber security is a top priority for the military as well as hospitals, power plants, and other infrastructural necessities. The military understands that cyber warfare is a valuable asset that can and should be utilized in Iraq and other future conflicts, but the lack of policy governing this evolving technology and weak infrastructural cyber security is hindering what could be an indispensable tool.
IMPLICATIONS:
· Given the success of cyber warfare techniques in Iraq, it seems logical to assume the U.S. will increase the frequency of attacks.
· The military is expanding their mission to focus on cyber war. In May 2010 the U.S. Air Force announced that 30,000 troops would be re-assigned to “the frontlines of cyber warfare” (Beaumont 2010).
· With the formation of Cyber Command and the growing importance of cyber warfare the defense budget will shift from physical weapons to electronic ones.
· The government and military will be forced to create policies regarding cyber war in order to utilize its capabilities.
· The new policies created will most likely limit the capabilities of cyber weapons to lessen the impact of cyber war on civilian networks.
· The United States will accept cyber security as a necessity and focus on hardening its networks.
RECOMMENDATIONS:
· Limit the disruptive capabilities of cyber weapons through scenario planning and ensuring that the rules of engagement minimize effects on civilians.
· Adopt policies that define cyber warfare and official acts of cyber war.
· Adopt policies and legislation that regulate the use of cyber weapons, but also minimize civilian impacts.
· Adopt policies to ensure that the United States is adequately protected against cyber attacks.
· Continue to use cyber warfare to benefit the current conflicts and any future conflicts.
· Train more men and women in the science of cyber warfare to ensure that the cyber war effort has well-trained U.S. Armed Forces.
SOURCES:
Beaumont, Peter. "US Appoints First Cyber Warfare General." Latest News, Comment and Reviews from the Guardian | Guardian.co.uk. 23 May 2010. Web. 15 July 2010. .
Daniel, Lisa. "Cyber Command Synchronizes Services’ Efforts." United States Department of Defense (defense.gov). American Forces Press Service, 09 July 2010. Web. 15 July 2010. .
"Frontline: Cyber War!" PBS. 24 Apr. 2003. Web. 15 July 2010. .
Graham, Bradley. "Washingtonpost.com: Bush Orders Guidelines for Cyber-Warfare." Stanford University. Washington Post, 7 Feb. 2003. Web. 15 July 2010. .
Harris, Shane. "The Cyberwar Plan." National Journal Online. 14 Nov. 2009. Web. 15 July 2010. .
Kamal, Ahmad. The Law of Cyber-space: an Invitation to the Table of Negotiations. Geneva: UNITAR, 2005. Print.
Markoff, John, and Thom Shanker. "Halted ’03 Iraq Plan Illustrates U.S. Fear of Cyberwar Risk." The New York Times. 1 Aug. 2009. Web. 15 July 2010. .
Nakashima, Ellen. "Dismantling of Saudi-CIA Web Site Illustrates Need for Clearer Cyberwar Policies." Washingtonpost.com. Washington Post, 19 Mar. 2010. Web. 15 July 2010. .
Smith, Charles R. "Cyber War Against Iraq." NewsMax.com: America's News Page. 13 Mar. 2003. Web. 15 July 2010. .
Cyberwarfare - The Debate
Two security leaders - two quotes - two positions?
1. “There is no cyberwar,” Quote from Howard Schmidt, White House Cybersecurity Director for President Obama.
Or,
2. "The United States is fighting a cyberwar today, and we are losing," Quote from Michael McConnell, the former Director of the National Security Agency, written in a Washington Post article.
You will read a post by Fortalice intern, Steven Elliott, about Cyberwarfare shortly.
It has been an interesting debate out there about the term, "Cyberwarfare".
Ask anyone in law enforcement or even a small business who has been hacked and they may tell you that they feel they are at war with cybercriminals.
The term cyberwarfare has been used and critiqued by leaders in the security community.
Critics: "Warfare" in the traditional sense implies a level of involvement from Department of Defense. You cannot label trojans, viruses, and other malware that steals identities or helps criminals commit fraud as "warfare".
Supporters of Warfare: Typically use the term "Warfare" in a broader sense. A focus on the larger picture sees fraud as a potential source to fund criminal activities that fund terrorists. An assault on our critical infrastructure that creates a lack of confidence in the infrastructure is also seen as "warfare".
Whatever your position on the debate, I hope you will enjoy Steven's posts.
As always, we are open to ideas, suggestions, and feedback.
1. “There is no cyberwar,” Quote from Howard Schmidt, White House Cybersecurity Director for President Obama.
Or,
2. "The United States is fighting a cyberwar today, and we are losing," Quote from Michael McConnell, the former Director of the National Security Agency, written in a Washington Post article.
You will read a post by Fortalice intern, Steven Elliott, about Cyberwarfare shortly.
It has been an interesting debate out there about the term, "Cyberwarfare".
Ask anyone in law enforcement or even a small business who has been hacked and they may tell you that they feel they are at war with cybercriminals.
The term cyberwarfare has been used and critiqued by leaders in the security community.
Critics: "Warfare" in the traditional sense implies a level of involvement from Department of Defense. You cannot label trojans, viruses, and other malware that steals identities or helps criminals commit fraud as "warfare".
Supporters of Warfare: Typically use the term "Warfare" in a broader sense. A focus on the larger picture sees fraud as a potential source to fund criminal activities that fund terrorists. An assault on our critical infrastructure that creates a lack of confidence in the infrastructure is also seen as "warfare".
Whatever your position on the debate, I hope you will enjoy Steven's posts.
As always, we are open to ideas, suggestions, and feedback.
Tuesday, June 29, 2010
Summer Intern - Guest Post - Steven Elliott - Cyber Warfare
Topic: Cyber Warfare
Research by: Steven Elliott
Date: Final Version 6-28-10
TITLE: Cyber Warfare: an Introduction
SUMMARY PARAGRAPH:
The art of war has dramatically changed over the last hundred years with the invention of the airplane and the atom bomb. The next evolution could involve the Internet, computer security experts, and cyber warfare. In a recent ABC interview, CIA Director Leon Panetta declared “we are now in a world in which cyber warfare is very real. It could threaten our grid system. It could threaten our financial system…it could paralyze this country, and I think that's an area we have to pay a lot more attention to.” Cyber warfare attacks are becoming increasingly popular and these attacks can and have caused significant damage to both countries and companies by stealing massive amounts of classified data and crippling economies. This report focuses on what cyber warfare is, how it can affect the wars of tomorrow, and which nations are at the forefront of developing cyber war offensive and defensive strategies.
KEY FINDINGS
· There is a growing concern over cyber warfare and cyber terrorism.
· Many countries, such as China, Russia, and the United States, are starting to increase their cyber warfare offensive and defensive capabilities.
· Cyber attacks are mainly focused on gathering information or causing financial or infrastructural damage.
RECOMMENDATIONS
· Increase private sector cyber security by using up-to-date antivirus software, firewalls, encryption, strong passwords, and training employees on safe computing practices.
· Increase research in cyber security, to which the White House has allocated around 350 million dollars for the 2011 fiscal year (NITRD budget).
· Assess whether or not cyber warfare will help with current conflicts.
BACKGROUND
Cyber warfare is a relatively new concept that, as of May 2010, is still undefined by the United States Department of Defense (Jackson 2010). In a broad sense, cyber warfare is a war fought in cyberspace using computers and the Internet. Cyber war is not limited necessarily just between countries, as Google found out earlier this year (Zetter 2010). Countries have the ability to attack private companies, which could cause power outages, massive financial theft, or the loss of private information of millions of people. This very real high tech threat has the potential to become a dangerous and damaging new tool for nations to gain the upper hand in an international conflict.
STRATEGIC PLANNING ASSUMPTIONS:
· There is a dramatic increase in the number of cyber warfare attacks and attempted attacks.
· Enemy nations are developing new techniques to break into computers and networks.
· There will be an increase in cyber defense spending and the development of new national and international laws related to permissible types of cyber warfare.
· Nations will form cyber warfare divisions creating an increased need for computer security professionals.
· Private companies will have restrictions on how unprotected their networks are allowed to be and will be forced to increase their cyber security.
ANALYSIS:
Cyber attacks are happening more frequently and the threat from cyber attacks are growing every day. Israel, Estonia, the United States, Brazil, Russia, Georgia, and several other countries have been assaulted in the last three years alone (Eshel 2010, Boyd 2010, Kroft 2009, Danchev 2008). Also, in the last few months, at least 34 companies were attacked by a “highly sophisticated” strike that originated from China (Zetter 2010). There are also thousands of unreported attacks on banks and companies every year (Kroft 2009). These attacks are largely underreported or kept quiet because companies are afraid to report their concern since “it might impact their business” said Sean Henry, formerly in charge of FBI’s cyber division (Kroft 2009). These assaults steal terabytes of classified data, personal information, hundreds of millions of dollars, and plunge cities into darkness (Kroft 2009).
Depending on the target and the attacker’s motive, the way that attacks can occur, can be vastly different. Attackers could hack into a network and just sit and watch the network traffic, which would allow the intruder to read documents and capture sensitive information (Kroft 2009). The attacker could shut down a network using a denial of service attack, which could cost a company millions of dollars or shut an entire country down (Boyd 2010). Electric providers are one of the most vulnerable and most dangerous targets of attacks. In a demonstration, security experts were able to hack into a power generator and literally made it destroy itself (Kroft 2009). The real world consequences of an actual assault could knock out a power plant for months. The US has started making its own computer chips for nuclear missiles because evidence of embedded applications put in place by foreign intelligence agencies has been found (Kroft 2009). Ebombs can be used to actually fry computer systems (Knapp, Kenneth J., and William R. Boulton 2006), and according to Senator Carl Levin the Chairman of the Senate Committee on Armed Services “cyber weapons are approaching weapons of mass destructions in their effect” (Singel 2010).
To prevent future attacks, many nations are creating cyber defenses to protect their citizens against the threat of cyber warfare. The main powers in the cyber warfare arena are China, Russia, and the United States, but many other countries are developing their own programs, such as Great Britain, South Korea, France, Israel, Iran, and North Korea (Kroft 2009, Clark 2009, Sung-ki 2009, Eshel 2010, Coleman 2008). NATO has even started planning for the next generation of warfare by building the Cooperative Cyber Defence Centre of Excellence built in Estonia, after the cyber attacks on that nation in 2007. The US Congress has set aside $17 billion for cyber security offensive and defensive initiatives (Kroft 2009). The amount is a massive increase from even ten years ago, but money alone will not be enough to solve an impending problem from an unknown source.
IMPLICATIONS:
· The number of cyber attacks will increase, both on private industry and governments. According to Symantec, they “identified more than 240 million distinct new malicious programs in 2009, a 100% increase over 2008.” (Symantec annual report)
· Many nations, including Israel, China, South Korea, and the United States, will further develop cyber armies to combat a new threat.
· Research funding for computer security will increase. From the 2008 fiscal year to the 2011 fiscal year, the amount spent on computer security research has increased by 133 million dollars (NITRD budget).
· There will be a push for countries to educate children in high tech fields. The United States 2011 fiscal budget has set aside 477.2 million dollars for Science, Technology, Engineering, and Math (STEM) programs (US budget 2011).
· Policies will be implemented to ensure that the US is at the forefront of both the offensive and defensive ends of cyber warfare.
· International policies will be put in place to limit the damage one nation may do to another.
· Policies will be implemented to determine what constitutes an act of cyber war.
RECOMMENDATIONS:
· Policies must be put in place to ensure a standard for private companies’ computer and network security.
· Policies have to be enacted so that the military knows which techniques they are and are not allowed to perform, when engaging in cyber warfare.
· The US military mindset has to evolve to include high tech well-trained computer security experts in cyber attack and defensive units.
· Create defensive plans against known attack methods.
· Increase funding for computer security research.
· Increase public awareness of the potential threat and give tips for effective computer security practices.
SOURCES:
Boyd, Clark. "Cyber-war a Growing Threat Warn Expert." BBC NEWS. 17 June 2010. Web. 24 June 2010. .
Clark, Colin. "StratCom Plows Ahead on Cyber." DoD Buzz | Online Defense and Acquisition Journal. 29 June 2009. Web. 24 June 2010. .
Coleman, Kevin. "Iranian Cyber Warfare Threat Assessment | Defense Tech." Defense Tech. 23 Sept. 2008. Web. 24 June 2010. .
Danchev, Dancho. "Coordinated Russia vs Georgia Cyber Attack in Progress." ZDNet. 11 Aug. 2008. Web. 24 June 2010. .
Eshel, David. "Israel Adds Cyber-Attack to IDF." Military.com. 10 Feb. 2010. Web. 24 June 2010. .
Jackson, William. "DOD Struggles to Define Cyber War -- Government Computer News." Government Computer News. 12 May 2010. Web. 24 June 2010. .
Knapp, Kenneth J., and William R. Boulton. "Cyber-Warfare Threatens Corporations: Expansion Into Commercial Environmentspansion Into Commercial Environments." AllBusiness.com. 1 Apr. 2006. Web. 24 June 2010. .
Kroft, Steve. "Cyber War: Sabotaging the System - 60 Minutes - CBS News." CBS News. 8 Nov. 2009. Web. 24 June 2010. .
Singel, Ryan. "Cyberwar Commander Survives Senate Hearing." Wired News. 15 Apr. 2010. Web. 24 June 2010. .
Sung-ki, Jung. "Cyber Warfare Command to Be Launched in January." The Korea Times. 01 Dec. 2009. Web. 24 June 2010. .
Zetter, Kim. "Google Hack Attack Was Ultra Sophisticated, New Details Show." Wired News. 14 Jan. 2010. Web. 24 June 2010. .
Cooperative Cyber Defence Centre of Excellence. Tallinn, Estonia. .
"FY 2011 ED Budget Summary: Summary." U.S. Department of Education. Web. 28 June 2010. .
"NITRD Goes Open." National Coordination Office for Networking and Information Technology Research and Development (NCO/NITRD). Web. 28 June 2010. .
"Symantec Report Shows No Slowdown in Cyber Attacks." Symantec - AntiVirus, Anti-Spyware, Endpoint Security, Backup, Storage Solutions. 27 May 2010. Web. 28 June 2010. .Topic: Cyber Warfare
Subscribe to:
Posts (Atom)