Monday, June 25, 2012

Flame malware: So big, so overlooked - CNET

How did everyone miss Flame?

by Michael Lee, zdnet.com.au
May 29th 2012

analysis The most "complex malware ever found" — Flame — has taken the information security world by surprise. Given that it is said to have been around for years, how did everyone miss it?

Several security research firms, including Symantec, Kaspersky and McAfee have been hard at work analysing a specific piece of malware in the past few days after the Iranian Computer Emergency Response Team posted an alert about malicious code designed to steal and exfiltrate information from infected computers back to a network of at least 10 command and control servers.

However, as Budapest University's Laboratory of Cryptography and System Security (CrySyS) reported in its analysis of the malware, it "may have been active for as long as five to eight years". CrySyS also reported that the malware's footprint is massive — some 20MB — in stark contrast to traditional malware, which attempts to keep as low a profile as possible to avoid detection. Furthermore, the malware also appears to regularly send out information to command and control servers, which should have raised the concerns of a discerning network administrator.

But despite these apparent red flags, the Flame war didn't heat up until just recently.

Stratsec manager for threat research and analysis Sergei Shevchenko told ZDNet Australia that it was possible that Flame had not been in the wild as long as initially reported. CrySyS' five-to-eight-year estimate relies on anecdotal evidence submitted by the Webroot community in 2007.

"The samples in those firstly reported cases happened to share the same filenames as Flame's own components, and could either have belonged to Flame family, or not ... could have been detected under different threat names and by different products, or not," Shevchenko said.

Kaspersky, McAfee and Symantec all believe that Flame has been around for two years, after detecting some of its components running back to 2010. So the issue wasn't necessarily that antivirus products weren't detecting Flame, but rather that they just didn't know what they were looking at until now.

Yet, Pure Hacking CTO Ty Miller believed it was simply a case of malware authors being a step ahead of antivirus companies.

"Malware detection is a tricky industry, as the hackers and the antivirus companies are both constantly racing for better bypass and detection techniques, respectively. Unfortunately, antivirus companies are behind the eight ball since it is easier to bypass known security controls, than it is to detect unknown threats," Miller said.

A well-trained network administrator could have been expected to detect the regular communications sent from the infected machines using intrusion detection/prevention systems (IPS/IDS). However, Miller notes there is a chicken-and-egg situation whereby IPS signatures are often only created once the malware is known. In addition, Flame's creators appear to have taken precautionary measures against network forensics. Flame uses SSL encryption, similar to that used to secure communications during online banking.

"The malicious network traffic is transferred over SSL and SSH tunnels, which are generally encrypted from end to end. This means that network-based intrusion prevention systems would not be able to detect rogue activities," Miller said.

Shevchenko agreed, stating that even if the traffic seemed odd, it would be impossible to decrypt without the right key to determine what was going on.

"Without knowing what algorithm the traffic is encrypted with and what keys were used to encrypt it, no security solution would be able to classify such traffic as malicious, without increasing the risk of false positive detections that may potentially block legitimate traffic," he said.

CrySiS' report also revealed that more than 50 domain names and over 15 distinct IP addresses were cycled to reduce and suspicious trends in activity that might be picked up by a network administrator.

Flame's larger file size didn't raise any flags; in fact, Kaspersky Labs security researcher Alexander Gostev noted that its large size was precisely why it wasn't discovered for so long — it simply didn't fit the profile.

Shevchenko said that the larger size of the malware points to a set of careless malware authors — who prefer to use high-level languages — or professional programmers that prefer to use third-party components and libraries that had evolved over time into highly reliable time-tested tools.

"This complacency might be explained with the fact the recently [hired] professional developers simply continued to work the way they used to ... developing lower-level components might sound like a nightmare idea to them," he said.

Original Page: http://www.zdnet.com.au/how-did-everyone-miss-flame-339338742.htm

Shared from Read It Later

 אל

How did everyone miss Flame? - Security - News

How did everyone miss Flame?

by Michael Lee, m.zdnet.com.au
May 29th 2012

analysis The most "complex malware ever found" — Flame — has taken the information security world by surprise. Given that it is said to have been around for years, how did everyone miss it?

Several security research firms, including Symantec, Kaspersky and McAfee have been hard at work analysing a specific piece of malware in the past few days after the Iranian Computer Emergency Response Team posted an alert about malicious code designed to steal and exfiltrate information from infected computers back to a network of at least 10 command and control servers.

However, as Budapest University's Laboratory of Cryptography and System Security (CrySyS) reported in its analysis of the malware, it "may have been active for as long as five to eight years". CrySyS also reported that the malware's footprint is massive — some 20MB — in stark contrast to traditional malware, which attempts to keep as low a profile as possible to avoid detection. Furthermore, the malware also appears to regularly send out information to command and control servers, which should have raised the concerns of a discerning network administrator.

But despite these apparent red flags, the Flame war didn't heat up until just recently.

Stratsec manager for threat research and analysis Sergei Shevchenko told ZDNet Australia that it was possible that Flame had not been in the wild as long as initially reported. CrySyS' five-to-eight-year estimate relies on anecdotal evidence submitted by the Webroot community in 2007.

"The samples in those firstly reported cases happened to share the same filenames as Flame's own components, and could either have belonged to Flame family, or not ... could have been detected under different threat names and by different products, or not," Shevchenko said.

Kaspersky, McAfee and Symantec all believe that Flame has been around for two years, after detecting some of its components running back to 2010. So the issue wasn't necessarily that antivirus products weren't detecting Flame, but rather that they just didn't know what they were looking at until now.

Yet, Pure Hacking CTO Ty Miller believed it was simply a case of malware authors being a step ahead of antivirus companies.

"Malware detection is a tricky industry, as the hackers and the antivirus companies are both constantly racing for better bypass and detection techniques, respectively. Unfortunately, antivirus companies are behind the eight ball since it is easier to bypass known security controls, than it is to detect unknown threats," Miller said.

A well-trained network administrator could have been expected to detect the regular communications sent from the infected machines using intrusion detection/prevention systems (IPS/IDS). However, Miller notes there is a chicken-and-egg situation whereby IPS signatures are often only created once the malware is known. In addition, Flame's creators appear to have taken precautionary measures against network forensics. Flame uses SSL encryption, similar to that used to secure communications during online banking.

"The malicious network traffic is transferred over SSL and SSH tunnels, which are generally encrypted from end to end. This means that network-based intrusion prevention systems would not be able to detect rogue activities," Miller said.

Shevchenko agreed, stating that even if the traffic seemed odd, it would be impossible to decrypt without the right key to determine what was going on.

"Without knowing what algorithm the traffic is encrypted with and what keys were used to encrypt it, no security solution would be able to classify such traffic as malicious, without increasing the risk of false positive detections that may potentially block legitimate traffic," he said.

CrySiS' report also revealed that more than 50 domain names and over 15 distinct IP addresses were cycled to reduce and suspicious trends in activity that might be picked up by a network administrator.

Flame's larger file size didn't raise any flags; in fact, Kaspersky Labs security researcher Alexander Gostev noted that its large size was precisely why it wasn't discovered for so long — it simply didn't fit the profile.

Shevchenko said that the larger size of the malware points to a set of careless malware authors — who prefer to use high-level languages — or professional programmers that prefer to use third-party components and libraries that had evolved over time into highly reliable time-tested tools.

"This complacency might be explained with the fact the recently [hired] professional developers simply continued to work the way they used to ... developing lower-level components might sound like a nightmare idea to them," he said.

Original Page: http://m.zdnet.com.au/how-did-everyone-miss-flame-339338742.htm

Shared from Read It Later

 אל

'US escalating intimidation of whistleblowers’ — RT

'US escalating intimidation of whistleblowers’ — RT

rt.com | Nov 30th -0001

See Video: http://www.vimeo.com/

By neglecting whistleblower protection laws and escalating the Manning and Assange cases, the US government is setting a precedent to be applied to journalists, future whistleblowers, activists and bloggers, activist Sibel Edmonds told RT.

­Edmonds is the founder of the National Security Whistleblowers coalition, an independent alliance. The activist believes Bradley Manning and Julian Assange are just the beginning.

RT: Is Bradley Manning a hero or a criminal in your view?

Sibel Edmonds: Bradley Manning is a hero, no doubt about it. And you have to look back at the bigger picture here, because the intention here is not only to make an example out of Bradley Manning by punishing him, and this is without any due process, basically ignoring all his rights both as a US citizen and a military officer. They have not followed the process that is supposed to be at work here under government whistleblower protection laws. Looking beyond just setting an example by punishment, this is also to set precedents, and this is what the American public and, actually, people around the world need to understand because by setting precedents, they are showing that they are not going to stop with Bradley Manning or Julian Assange. So then you are looking at an escalation with each case, whether it is Bradley Manning or Julian Assange or the recent whistleblowers who have faced indictment. What they are doing is, they are waiting to see what kind of reaction they are going to get from the public, and this is not only the US government, but also other governments. And with Assange the case is going to be very interesting because what is going to be established here is unprecedented. His precedent will apply to journalists, to other whistleblowers, to activists and to media, to any kind of bloggers.

RT: Do you think Assange will be extradited to Sweden?

SE: This is what it looks like, and unfortunately, it is not only limited to the US government because you should also look at this as a rule of reciprocity. In the future you are going to see one government asking another government to extradite someone who is a political activist, someone who may even be a political refugee. And again, it is very ironic, as on the one hand, you have the US State Department with Hillary Clinton pointing the finger at China and saying "how dare you punish dissidents and jail them," and the other that’s exactly what we are doing, and not only here nationally, but on a global scale.

RT: Do you think the recent cases of guests from the Julian Assange Show being interrogated by the FBI might deter potential whistleblowers from coming forward with their stories?

SE: Absolutely. It already has. My organization during the Bush administration gathered more than 150 national security whistleblowers from the Pentagon, the CIA, the FBI, the Department of Homeland Security. In the past two or three years, that number has fallen down to one or two whistleblowers. I still get reports from government insiders, but they are saying that what they are seeing with the Obama administration is that all these cases are not going to come forward, and they are also seeking ways to make the information they have available because they believe that the American people have a right to know this information. This is not classifying some really necessary intelligence gathering methods. We are looking at classifying the government's criminal activities, government fraud, government waste, government abuse, and so yes, they have been deterred. The intimidation tactic by the FBI is not new. This was happening even in the early 2000s under the Bush administration with other government whistleblowers. It is happening in my case, when the FBI visited people who were going to come forward to Congress and be witnesses to my case; these were senior FBI agents. So they are escalating these intimidation tactics.

Original Page: http://www.rt.com/news/us-whistleblower-assange-manning-232/

Shared from Read It Later

 אל

The U.S. Cyber Consequences Unit

The U.S. Cyber Consequences Unit

usccu.us

One of the reasons that many corporations are happy to cooperate with the US-CCU’s research is that it helps government policy makers to take better account of their concerns. The US-CCU provides . . .

The US-CCU’s Analytic Method

The primary analytic method that the US-CCU employs is called Value Creation Analysis. This method was first pioneered and applied to information problems by the US-CCU’s director in the mid-1990's. It draws on his earlier work in culture-based economics, on Harborne Stuart and Adam Brandenburger's work in value-based business strategy, and, more broadly, on cooperative game theory. The value-based approach has been part of the business school curricula at Harvard, Columbia, Wharton, UCLA, Dartmouth, NYU, and other leading universities for a number of years. It resulted in breakthroughs in pricing theory and in other areas of business strategy. It is only recently, however, that this approach was developed into a theory of value destruction by the US-CCU’s director and applied to the analysis of cyber-attacks. As far as the staff of the US-CCU are aware, this value creation/value destruction model is currently the only method for evaluating the economic consequences of cyber-attacks that can stand up to critical scrutiny.

Corporate Cyber-Security Exercises

In addition to its research activities, the US-CCU regularly conducts cyber-security exercises for critical infrastructure corporations and other institutions. These exercises normally consist of four table-top sessions . . .

The US-CCU’s Role as a Trend-Setter

The US-CCU director, chief technology officer, and staff have been among the leaders in each of the changes in cyber-security focus over the last several years. They have helped to shift the focus from cyber-attacks that merely interrupt services to those that use false information to do active damage or destroy trust, from mass attack viruses and worms to attacks targeted at specific businesses and processes, from perimeter defense to internal monitoring and recovery, from cyber-vandalism and petty theft to large indirect-payoff cyber-crimes, and from cyber-security as a separate field to the integration of cyber and physical security. Almost every recent trend in cyber-attack strategies and technologies has been anticipated or identified in its earliest stages by US-CCU researchers.

Although US-CCU’s research lays out the possible consequences of cyber-attacks and the likely effects of counter-measures in some detail, it does not make specific recommendations about how to bring about the needed security reforms. Instead, the US-CCU attempts to identify the ways in which counter-measures need to take account of the special circumstances and business conditions in specific industries. Despite the urgency of this subject, it is not an area in which hasty or one-size-fits-all solutions are likely to be good solutions.

The US-CCU's International Outreach

International cooperation is essential if we are to have any chance of limiting the destruction that can be caused by cyber-attacks. Cyber-attacks can now be launched from virtually anywhere, and their targets . . .

The Urgency of This Cyber-Security Work

Based on the work the US-CCU has already done, it is evident that the potential economic and strategic consequences of cyber-attacks are very great. The US-CCU’s research has demonstrated that the numbers widely quoted for the costs of denial-of-service cyber-attacks lasting up to three days are actually wildly inflated. But the US-CCU’s findings show that other types of cyber-attacks are potentially much more destructive. Especially worrisome are the cyber-attacks that would hijack systems with false information in order to discredit the systems or do lasting physical damage. At a corporate level, attacks of this kind have the potential to create liabilities and losses large enough to bankrupt most companies. At a national level, attacks of this kind, directed at critical infrastructure industries, have the potential to cause hundreds of billions of dollars worth of damage and to cause thousands of deaths.

Some of the attack scenarios that would produce the most devastating consequences are now being outlined on hacker websites and at hacker conventions. The overall patterns of cyber intrusion campaigns suggest that a number of potentially hostile groups and nation states are actively acquiring the capability to carry out such attacks. Meanwhile, the many ways in which criminal organizations could reap huge profits from highly destructive attacks are also now being widely discussed. This means that American corporations and American citizens need urgently to be informed, not just of their technical vulnerabilities, but of the economic and strategic consequences if those vulnerabilities are exploited. It is only by basing our cyber-defenses on a comprehensive assessment of cyber-attack consequences that we can make sure those defenses are sensible and adequate.


Original Page: http://www.usccu.us/

Shared from Read It Later

 אל

US unleashed Stuxnet cyber war on Iran to appease Israel – report — RT

US unleashed Stuxnet cyber war on Iran to appease Israel – report — RT

rt.com | Nov 30th -0001

The US and Israel made the Stuxnet virus as a new kind of weapon targeted against Iran, a media investigation revealed. The operation reportedly started in the Bush era, but was intensified by Obama administration.

­The top-secret massive sabotage targeting Iran’s Natanz uranium enrichment facility was arguably the first episode of a new age of warfare, similar to the first use of nuclear weapons or the first military drone attack, according to an investigation by the New York Times.

The newspaper interviewed current and former American, European and Israeli officials involved in the clandestine program called Olympic Games. None of them agreed to have his name mentioned due to the highly sensitive nature of the operation.

The US and Israeli authorship of the Stuxnet virus, which caused damage to Iranian uranium enrichment effort by destroying hundreds of centrifuges at the Natanz facility, was long hinted at by the media. The virus is estimated to have pushed back the controversial nuclear program by as much as 18 months, although skeptical assessments say the impact may have been lower.

The Olympic Games operation dates back to 2006, the NYT reports. The Bush administration at the time had its credibility at a low, after being to have falsely accused Saddam Hussein of having weapons of mass destruction. This limited the amount of international pressure Washington could put on Tehran.

At the same time Iran’s renewed enrichment of uranium made Israel extremely nervous, because it suspected the Islamic Republic would build up a stockpile of enough nuclear fuel to enrich it further to a weapons-grade level later. If Iran’s enrichment program remained unhindered, Israel would be prompted to launch a pre-emptive military attack on it and trigger a major regional war, Washington believed, as several US officials told the newspaper.

Launching a secret cyber attack on Iran and making Israelis part of the operation both bought more time for sanctions and gave Israel’s hawks a tangible alternative to trying to bomb the Natanz plant.

The report names General James E. Cartwright, who had established a small cyber operation unit inside the United States Strategic Command, as the father of Olympic Games operation. George W. Bush was skeptical over the risky and radical proposal, but nevertheless approved it.

The virus that was programmed by American and Israeli cyber weapons experts especially for the operation was more sophisticated than anything the world had seen before. Also, unlike the overwhelming majority of malware, which can only damage computer performance or steal information, the new virus could cause actual damage to machinery. The code infecting control computers at Natanz was designed to abruptly speed up or slow down the fast-spinning centrifuges, tearing them apart.

Before attacking the Iranian facilities, the people in charge of the operation reportedly tested it at several of the Energy Department’s secret national laboratories. They built a replica of the Natanz site with centrifuges similar to those used by Iran. The US obtained them from Libyan leader Muammar Gaddafi after he abandoned his own nuclear program in 2003.

With proof of the potential power of the new cyber weapon at hand, the Olympic Games went into the next phase in 2008. Through agents and unsuspicious accomplices the virus was downloaded into Natanz computers and spread across the facility. It then began to occasionally destroy centrifuges, giving the impression of a series of unrelated malfunctions plaguing the enrichment site.

According to the report, Iranians facing centrifuge malfunctions were convinced that their problems were with faulty parts (which the US was actually working hard to supply to them with), incompetence or human sabotage. Some specialists were actually fired over the disruptions.

The effect Olympic Games had on the plant was also confirmed by video taken by the International Atomic Energy Agency cameras, which had been put in place to monitor Iranian activities at Natanz between inspections.

The game changed in 2010, when the virus infected a laptop of one of the engineers and later escaped into the internet, quickly spreading “in the wild”. This contingency was not expected, as the malware was supposed to infect only computers at Natanz.

The Americans blamed Israeli programmers’ contributions to the code, claiming they “went too far”, as US Vice President Joe Biden reportedly commented at a secret meeting after the news broke. It was then just a matter of time before the virus would be detected by cyber security experts, its code dissected and analyzed.

Still, President Obama ordered the operation to continue, the NYT was told. Within a week from that moment, a newer version of the virus brought down just under 1,000 Iranian centrifuges.

The report says American cyber attacks are not limited to Iran, but the focus was overwhelmingly on Tehran’s nuclear program. Obama reportedly was hesitant to expand the use of the new brand of weapon. In fact, the US is arguably the one country in the world most vulnerable to cyber attacks on its infrastructure. Pioneering such operations would give other countries and power groups a justification to target America.

­It is not clear whether the US has anything to do with the recently-discovered Flame virus. The malware is a sophisticated cyber weapon, which is believed to be part of a major spy operation in the Middle East, including Iran and Israel. Cyber security experts say a government-level effort must be behind Flame.

Kosovo Serbs clash with NATO forces over roadblocks, 4 injured (VIDEO, PHOTOS)

At least three Serbs and one NATO soldier were injured in a gunfight in Northern Kosovo as NATO Kosovo Force attempted to dismantle Serb roadblocks.

Original Page: http://www.rt.com/news/iran-us-israel-cyberwar-virus-weapon-770/

Shared from Read It Later

 אל