Showing posts with label CYBERWARFARE. Show all posts
Showing posts with label CYBERWARFARE. Show all posts

Saturday, April 20, 2013

Richard Clarke: China's Cyberassault on America - WSJ.com

In justifying U.S. involvement in Libya, the Obama administration cited the "responsibility to protect" citizens of other countries when their governments engage in widespread violence against them. But in the realm of cyberspace, the administration is ignoring its primary responsibility to protect its own citizens when they are targeted for harm by a foreign government.

Senior U.S. officials know well that the government of China is systematically attacking the computer networks of the U.S. government and American corporations. Beijing is successfully stealing research and development, software source code, manufacturing know-how and government plans. In a global competition among knowledge-based economies, Chinese cyberoperations are eroding America's advantage.

The Chinese government indignantly denies these charges, claiming that the attackers are nongovernmental Chinese hackers, or other governments pretending to be China, or that the attacks are fictions generated by anti-Chinese elements in the United States. Experts in the U.S. and allied governments find these denials hard to believe.

Three years ago, the head of the British Security Service wrote to hundreds of corporate chief executive officers in the U.K. to advise them that their companies had in all probability been hacked by the government of China. Neither the FBI nor the Department of Homeland Security has issued such a notice to U.S. executives, but most corporate leaders already know it.

David Gothard

Some, like Google, have the courage to admit that they have been the victims of Chinese hacking. We now know that the "Aurora" attack (so named by the U.S. government because the English word appears in the attack software) against Google in 2009 also hit dozens of other information technology companies—allegedly including Adobe, Juniper and Cisco—seeking their source code. Aurora wasn't an isolated event. This month Google renewed its charge against China, noting that the Gmail accounts of senior U.S. officials had been compromised from a server in China. The targeting of specific U.S. officials is not something that a mere hacker gang could do.

The Aurora attacks were followed by systematic penetrations of one industry after another. In the so-called Night Dragon series, attackers apparently in China went after major oil and gas companies, not only in the U.S. but throughout the world. The German government claims that the personal computer of Chancellor Angela Merkel was hacked by the Chinese government. Australia has also claimed that its prime minister was targeted by Chinese hackers.

Recently the computer-security company RSA (a division of EMC) was penetrated by an intrusion which appears to have stolen the secret sauce behind the company's SecureID. That system is widely used to protect critical computer networks. And this month, the largest U.S. defense contractor, Lockheed, was subject to cyberespionage, apparently by someone using the stolen RSA data. Cyber criminals don't hack defense contractors—they go after banks and credit cards. Despite Beijing's public denials, this attack and many others have all the hallmarks of Chinese government operations.

In 2009, this newspaper reported that the control systems for the U.S. electric power grid had been hacked and secret openings created so that the attacker could get back in with ease. Far from denying the story, President Obama publicly stated that "cyber intruders have probed our electrical grid."

There is no money to steal on the electrical grid, nor is there any intelligence value that would justify cyber espionage: The only point to penetrating the grid's controls is to counter American military superiority by threatening to damage the underpinning of the U.S. economy. Chinese military strategists have written about how in this way a nation like China could gain an equal footing with the militarily superior United States.

What would we do if we discovered that Chinese explosives had been laid throughout our national electrical system? The public would demand a government response. If, however, the explosive is a digital bomb that could do even more damage, our response is apparently muted—especially from our government.

Congress hasn't passed a single piece of significant cybersecurity legislation. When the Chinese deny senior U.S. officials' claims (made in private) that Beijing is stealing terabytes of data in the U.S., Congress should not leave the American people in doubt. It should demand answers to basic questions:

What does the administration know about the role of the Chinese government in cyberattacks on public and private computer networks in the United States?

If there is widespread Chinese hacking of sensitive U.S. networks and critical infrastructure, what has the administration said about it to the Chinese government? Specifically, did President Obama raise concerns about these attacks with Chinese President Hu Jintao at the White House this spring?

Since defensive measures such as antivirus software and firewalls appear unable to stop the Chinese penetrations, does the administration have any plan to address these cyberattacks?

In private, U.S. officials admit that the government has no strategy to stop the Chinese cyberassault. Rather than defending American companies, the Pentagon seems focused on "active defense," by which it means offense. That cyberoffense might be employed if China were ever to launch a massive cyberwar on the U.S. But in the daily guerrilla cyberwar with China, our government is engaged in defending only its own networks. It is failing in its responsibility to protect the rest of America from Chinese cyberattack.

Mr. Clarke was a national security official in the White House for three presidents. He is chairman of Good Harbor Consulting, a security risk management consultancy for governments and corporations.

Thursday, August 23, 2012

Obama faces delicate decisions as cyberattack fears rise

President Barack Ob, ... ] White House photo

At the height of the economic crisis in 2008, Saturday Night Live’s “Weekend Update” comedy news show rolled out the character Oscar Rogers as a faux financial commentator. His advice on how to restore the economy? “Fix it! It needs to be fixed! Now!”

Four years later, lawmakers are grappling with a cybercrisis, and despite rising concerns, legislative debates over how to secure U.S. networks and infrastructure have often resembled nothing so much as Oscar Rogers yelling “Fix it!”

Now, with Congress looking unlikely to act anytime soon to fix vulnerabilities in the nation’s computer systems that leave them open to cyberattacks, President Obama is weighing the pros and cons of using anexecutive order to do what Congress hasn’t.

Experts in government and industry alike report a tide of attacks aimed at stealing information from individuals, companies, and government agencies, potentially making a strong case for presidential action.

Further bolstering the case are warnings from top national-security officials that a catastrophic attack on a critical system like those that run energy grids or chemical plants could cause damage to the economy or even loss of life.

But Obama needs to consider his options carefully, because any unilateral steps could invite accusations from his critics of overstepping his authority. As the acrimonious debate over antipiracy legislation illustrated earlier this year, simmering Internet issues can easily explode.

In the final days before the August recess, the Senate hit an impasse on broad cybersecurity legislation that the White House and national-security and defense leaders support. The bill stalled after businesses and Republicans said the legislation would create burdensome regulations for industry without doing enough to shore up defenses against cyberattacks.

Top White House counterterrorism aide John Brennan said earlier this month that Obama was looking at the possibility of an executive order but that there is no decision yet.

Lee Hamilton, a Democratic former House member who sits on a board that advises the Homeland Security Department and who examined government security failures as cochair of the 9/11 Commission, said that Obama is right to consider moving forward on his own. He said the stalemate in Congress is a “serious breakdown” reminiscent of failures before the terrorist attacks on Sept. 11, 2001.

“The preference would be to work together with Congress, but the threat is serious enough that an executive order is in line,” he said. “There is certainly a lack of urgency in dealing with this, and it’s not a business-as-usual problem. Given the fact that Congress hasn’t acted, the president has the obligation to put together options to secure the country.”

While the debate in Congress largely broke down along party lines, some prominent Republicans support the cybersecurity standards backed by the White House.

Top national-security advisers for GOP presidential candidate Mitt Romney, such as former Homeland Security Secretary Michael Chertoff and former National Security Agency and Central Intelligence Agency chief Michal Hayden, differed with Republicans in Congress and publicly called for the Senate to pass provisions that have Obama’s support.

Romney campaign spokeswoman Andrea Saul declined to elaborate on the Republican candidate’s assertion that more needs to be done to secure American networks, or comment on whether he would favor using an executive order in the absence of legislation. But she reiterated Romney’s promise to make cybersecurity an early priority and didn’t rule out executive action. Romney's plan would require agencies to begin developing a new national cybersecurity strategy within the first 100 days of his administration. “Once the strategy is formulated he will determine how best it can be implemented,” Saul said in an e-mail.

Polls show that while Americans express concerns over cyberattacks, they, too, are divided over what should be done.

Separate surveys published by United Technologies/National Journal and The Washington Post over the summer found that a majority of Americans prefer that the government either not create standards for private companies, or keep any standards voluntary.

Backers of the White House’s proposals, however, say an executive order could add clarity to the debate and prove to skeptics that the government can play a greater role in protecting American networks without violating privacy or burdening private businesses.

“I think it’s hard to make things any messier than it was politically,” said James Lewis, an expert at the Center for Strategic and International Studies. “If done right, an executive order could help critics reconsider their arguments.”

That’s an analysis echoed by University of California (Berkeley) professor Steven Weber who said many people seem to be “sleepwalking” when it comes to the threat of cyberattacks. An executive order, he said, could reform cybersecurity policies before a catastrophic attack galvanizes public opinion.

An executive order could give Obama the chance to take a strong stand on a rising national-security concern while portraying Republicans in Congress as ditherers.

But an order is unlikely to accomplish all of the White House’s aims. It couldn’t hand DHS wider authority to ensure that certain private networks are secure. Nor could it entirely ease legal restrictions that prevent businesses from sharing threat information. Even policy changes for some federal network-security policies would likely need congressional action. Additionally, any action would need to avoid inciting privacy watchdogs who fear cybersecurity could be used as an excuse to undermine civil liberties.

And some analysts said the politics of an executive order could cut both ways for Obama. Presidents often win political debates that pit them against an unpopular Congress, especially one perceived as unable to do anything substantive, said Peter Feaver, a former National Security Council staffer during the Clinton and George W. Bush administrations. But if Obama were to take unilateral action, it would give his critics on the right an opening to paint him as an “imperial” president and to accuse him of saddling business with new regulations, Feaver said.

“In general, White Houses win in these fights with Congress, but this White House has played this card many times,” Feaver said. “This is an issue where there are bound to be unintended consequences and any cybersecurity measures will need a system to fix and update the provisions down the road. This administration has a hard sell assuring people to trust them to fix things later.”

Paul Rosenzweig, a consultant and visiting fellow at the conservative Heritage Foundation, said a cybersecurity executive order could play into both the “imperial presidency and do-nothing-Congress” narratives, but said he thinks there is a genuine possibility for a future compromise and unilateral action by Obama would do little to actually help secure private networks

http://m.nextgov.com/cio-briefing/2012/08/obama-faces-delicate-decisions-cybe...

Tuesday, July 24, 2012

Stuxnet thwarted by control code update

Stuxnet thwarted by control code update

Iranian nuclear plant workers Iran's nuclear enrichment efforts have been targeted by sophisticated cyber attacks

Related Stories

German engineering giant Siemens has issued a fix for the software loopholes used by the notorious Stuxnet worm.

Stuxnet was discovered in 2010 after investigations into malfunctions at many industrial plants and factories.

Iran's nuclear enrichment efforts were hit hard by Stuxnet which targeted the devices that control delicate industrial processes.

The fix comes as reports circulate of a fresh cyber attack on Iranian nuclear enrichment project.

Burn out

Stuxnet exploited loopholes in the software Siemens wrote to oversee the running of its programmable logic controllers - devices used in many industrial facilities to automate a production process.

When a controller was infected with Stuxnet it made the motors it was typically connected to run out of control and burn out. This is believed to have been behind Iran's need to replace many of the centrifuges it was using in its Natanz uranium enrichment plant.

Siemens has issued advisories saying it has updated the Simatic code in the controllers to remove the loopholes.

It is not yet clear who created Stuxnet, but security researchers say it is so complex and tightly targeted that only a nation would be able to marshal the resources to put it together.

Stuxnet is just one of several similar malicious programs created to attack industrial control systems.

Experts speculate that many were made to slow down and disrupt Iran's nuclear production processes.

Iran has regularly denied that the viruses have hit its nuclear programme.

The Siemens update comes as security firm F-Secure received an email believed to have been sent by a scientist working at Iran's Atomic Energy Organization.

In the message, the scientist said its plants at Natanz and Qom have been hit again by a worm.

Top F Secure security researcher Mikko Hypponen said it had not been able to confirm any of the details in the message. However, digital detective work did reveal that the message had come from within the Atomic Energy agency.

On 23 July, Iran issued a statement saying it had successfully "confronted" sophisticated malware and thwarted all the cyber attacks against the nation's infrastructure.

Reza Taqipur, Iran's minister of communication and information technology, said it was sometimes hit by as many as two million cyber attacks a day, but its ability to deal with them was growing daily.

Sunday, July 1, 2012

Reality Bytes: CyberBusted 12/21/2010 Posted on Firetown.com

CyberBusted 12/21/2010 Posted on Firetown.com

FIRETOWN-- THIS IS YOU! I HOPE YOU ALL APPRECIATE THAT I WENT OUT ON A FUCKING LIMB TO PROTECT THE INTEGRITY OF THIS FORUM, BUT I WOULD LIKE AN APOLOGY FROM THE ADMINISTRATOR(S) OF THIS "CLOSED GROUP" AS TO WHY NOBODY RESPONDED [EXCEPT FROMMES- AND HE CAUSED EVEN MORE OF A MESS BY SUPPORTING YOU!]

@firetown URGENT log out of all accounts and change your pass... on Twitpic

MIKE-- I'M CALLING IT AS I SEE IT. IF YOU RUN THIS FORUM THAN YOU HAVE AN OBLIGATION TO PROTECT IT AND EACH OF US FOR SUPPORTING YOU BY GIVING US A SAFE PLACE TO SHARE IDEAS.


NOTICE THIS IS YOUR ACCOUNT THAT WAS HACKED ALONG WITH MINE.
ARE YOU A BLACK SHEEP OR A ASLEEP AT THE WHEEL? YOU HAD THE ABILITY TO CLEAR MY NAME AND PUT AN END TO THIS SITUATION BEFORE IT ESCALATED TO THIS POINT.SO, WHEN I AM BEING ACCUSED OF SOMETHING UNETHICAL AND ILLEGAL AND YOU HAVE THE ABILITY NOT ONLY CLEAR MY NAME BUT TO CONFIRM THAT YOU ALSO HAVE EVIDENCE TO PUT AN END TO DISINFO AGENTS AND PROVOCATEURS THEN YOU OWE IT TO EACH AND EVERY ONE OF US TO COME FORWARD.

I EXPECT YOU TO DO SOMETHING AND DO IT QUICKLY. REMOVE ANYONE WHO THREATENS THE SAFETY AND INTEGRITY OF THIS FORUM.

WHO IS GUARDING YOUR HOUSE TONIGHT? I HAVE BEEN ON WATCH NOW FOR WAY TOO FUCKING LONG WITH NO END IN SIGHT.

"FIRST THEY CAME FOR THE JEWS?"

WRONG!

FIRST THEY CAME FOR THE COMMUNISTS! [REF: NIEMOLLER]

WAKE THE FUCK UP.
HOW WOULD YOU FEEL IF YOU WERE ACCUSED OF NOT ONLY A CRIME, BUT BEING UNETHICAL AND DISLOYAL TO YOUR FOLLOWERS - WHICH BTW, YOU WERE!

WELL GUESS WHAT? I STEPPED UP FOR YOU AND YOU BETTER STEP UP TO THE FUCKING PLATE FOR THE REST OF US. WHEN DID YOU TURN INTO A GREY SHEEP? WAKE THE FUCK UP AND GET YOUR SHIT TOGETHER.

GET YOUR SHIT AND MY SHIT OUT OF THIS MESS BEFORE WE ALL GO DOWN WITH THIS SINKING SHIP.

I HAVE PAID DEARLY FOR BEING SO OUTSPOKEN AND DEDICATED IN MY SEARCH TO FIND A PLACE WHERE WE CAN CELEBRATE INDIVIDUAL FREEDOMS FREE FROM REPRESSIVE GOVERNMENT AND TOXIC PEOPLE.

I WOULD REALLY APPRECIATE A FUCKING ANSWER AS TO WHY WE ALLOW THIS KIND OF BULLSHIT TO CONTINUE? DON'T YOU GET IT... DIVIDE AND CONQUER.  [REF: COINTELPRO]

DIVIDED WE FAIL. 

FACE IT WE ARE NOT ON ANIMAL FARM-- WE ARE ON PLANET FUCKING PLUTO WHERE WE ARE TOO BUSY WATCHING THE MICKEY MOUSE CLUB INSTEAD OF OUR CHILDREN. [REF: THE CORPORATION]

WE ARE NOT ALL CREATED EQUAL. SOME ARE MORE EQUAL THAN OTHERS.  [REF: ORWELL, ANIMAL FARM]

SO WHEN I AM SENDING AN SOS FROM WHATEVER PLATFORM... THAN I DESERVE THE COURTESY OF SOMEONE TRYING TO DELIVER THE MESSAGE IN A LANGUAGE OR FORMAT THEY CAN UNDERSTAND. AND, TRYING TO SHOW SOME SUPPORT IN A LANGUAGE OR FORMAT THAT I CAN UNDERSTAND. [REF: #ONE]

#911 IS THE SAME IN EVERY LANGUAGE. #thatisall

NOTICE THIS IS YOUR ACCOUNT THAT WAS HACKED ALONG WITH MINE. SO, WHEN I AM BEING ACCUSED OF SOMETHING UNETHICAL AND ILLEGAL AND YOU HAVE THE ABILITY TO BOTH CLEAR MY NAME AND PUT AN END TO THE SITUATION I EXPECT YOU DO IT AND QUICKLY REMOVE ANYONE WHO THE MEMBERS OF THIS FORUM.

WHO IS GUARDING YOUR HOUSE TONIGHT? PUT AN END TO DISINFO AGENTS AND PROVOCATEURS.

IF YOU WON'T DO IT FOR ME, DO IT FOR YOURSELF. IF NOT FOR YOURSELF THEN DO IT FOR THE WORLD. [REF: STEVIE NICKS TIMESPACE]

#911 IS THE SAME IN EVERY LANGUAGE. #thatisall

see for yourself!

no response. none.