Posts Tagged ‘cyberwar’

Former CIA Chief: A Separate Internet Could Curb Cyber Threats

To combat cyber attacks, the U.S. may need more than new cyber defenses. It might need a whole new piece of Internet infrastructure. So says former CIA director Michael Hayden, who served under President G.W. Bush, and he’s not the only one. Several lawmakers and the current Cyber Command chief Gen. Keith Alexander are toying with the notion of creating a “.secure” domain where Fourth Amendment rights to privacy are voluntarily foregone in order to keep that corner of the Internet free of cyber criminals.

The idea goes something like this: China and other regimes around the world inherently have an upper hand when it comes to cyber defense because their lack of civil liberty protections lets the government freely monitor online activity. Things like “deep packet inspection” (which gained notoriety during Iranian election protests back in 2009) that let governments monitor citizens traffic also let them monitor for unusual activity.

That activity could be cyber criminals at work, or it could be foreign-backed cyber warriors and cyber spies working to weaken a nation’s infrastructure or penetrate sensitive government systems. Regardless, other countries are better protected. The U.S. Internet, by virtue of its adherence civil liberties, is more like the wild west. Everyone does everything online anonymously, and while that’s great for liberties, it’s also dangerous when cyber criminals/foreign hackers are roaming the cyber countryside.

The proposed solution: a dot-secure safe zone (basically, a seperate Internet) where things like financial institutions, sensitive infrastructure, government contractors, and the government itself can hide behind heavier defenses. Your fourth amendment privacy rights wouldn’t apply here, as you would consent to give them up upon entry; as when walking onto a military base or into an airport, users would have to show detailed identification and credentials to get in. Those who want to remain anonymous on the Web can still frolic about in the world of dot-com, but in the dot-secure realm you would have to prove you are you.

A wise man once warned about giving up a little liberty for a little security, but a tiered Internet with varying levels of freedom, security, and anonymity may be the way the Internet goes in the end. The Obama administration and members of Congress are finally taking cybersecurity quite seriously it appears, and big-league legislation is likely imminent. When the dust settles, you may not be able to go to certain neighborhoods of the Web without showing your papers at a checkpoint--and perhaps subjecting yourself to one of those humiliating electronic pat-downs as well.

[Nextgov]

Richard Clarke: China is Planting Digital Bombs Throughout the U.S. Power Grid

The U.S. government is doing little to protect American interests from cyber threats, claims Clarke in an op-ed

The cyber-security cat is slowly slinking out of the bag, it seems. It’s been a big month in cybersecurity news, ranging from some high-profile hacks at companies like Lockheed (home to sensitive American defense technologies) and a declaration from the Pentagon that cyber attacks perpetrated by foreign governments can be considered acts of war and dealt with accordingly. Now we’re hearing more war metaphors and cautionary talk from Richard Clarke in this morning’s Wall Street Journal, where he argues that China-backed hackers are systematically attacking America and meeting no resistance when they do so.

Clarke worked in various high-level security roles for every president from Reagan to G.W. Bush, leaving the White House in 2003 with the title Special Advisor to the President on cybersecurity. That is, he’s got some background on the topic at hand. And his assessment is pretty bleak: Senior U.S. officials know--and have known--that Chinese hackers are systematically infiltrating our networks, stealing source code, valuable R&D, and trade secrets from corporations while probing our power grids and other critical infrastructure for weaknesses, leaving behind easy access for themselves should they ever need to return and carry out more malicious acts.

Google, he says, has had the stones to stand up and admit it when its networks have been breached. But other companies, usually out of fear of being labeled “not secure,” haven’t done so. The recent RSA Security breach says it all; Chinese hackers--with government support--are walking all over us digitally, and the U.S. government is doing little to protect jeopardized American interests that aren’t on a .gov or .mil server.

How do we know the Chinese government is behind these hacks? The Chinese claim attacks originating on their soil are rogue hackers, not government-backed cyber warriors. But, Clarke says, cyber criminals breach companies for financial gain, swiping credit cards or otherwise making away with funds. There’s no money in hacking the U.S. electrical grid, yet President Obama himself has admitted that the grid has been thoroughly probed by hackers. Says Clarke:

“What would we do if we discovered that Chinese explosives had been laid throughout our national electrical system? The public would demand a government response. If, however, the explosive is a digital bomb that could do even more damage, our response is apparently muted—especially from our government.”

Tough words from a former cybersecurity czar. The op-ed is worth a read if you’re staying current on cyber threats and the larger geopolitical situation. Click through below for the whole story.

[WSJ]

Stuxnet Worm is a “Game Changer” for Global Cybersecurity, Top U.S. Official Tells Senate

The Stuxnet worm has generated plenty of commentary from computer industry experts and security pundits, but yesterday the U.S. government’s senior cybersecurity expert at the Department of Homeland Security weighed in, calling the malicious program a “game changer” in cyber warfare. The head of the DHS’s Cybersecurity Center, Sean McGurk, made the statement to the Senate Homeland Security Committee Wednesday.

We already knew Stuxnet was unprecedented, but it’s what is unknown about it that makes it so unsettling. The code can enter systems undetected, steal information or alter processes, and basically live there causing a mess of things while the system appears to security software to be working properly. But authorities don’t know where the Stuxnet worm came from, or what it was specifically designed to attack, McGurk told Senators.

That last part is debatable. While there is still a degree of uncertainty about Stuxnet’s aims, cybersecurity firm Symantec released a report Friday saying that all evidence points to Iran as the target of the worm. “Stuxnet is a threat targeting a specific industrial control system likely in Iran, such as a gas pipeline or power plant,” the report reads. “The ultimate goal of Stuxnet is to sabotage that facility by reprogramming programmable logic controllers (PLCs) to operate as the attackers intend them to, most likely out of their specified boundaries.”

Symantec researchers were able to deduce this from the fact that Stuxnet requires specific industrial control systems from very specific vendors (one in Finalnd, the other in Tehran) to work, and more than 60 percent of infections have been reported in Iran (there have been approximately 44,000 unique infections reported; just 1,600 are in the United States). That has led to speculation that Stuxnet was designed to sabotage Tehran’s controversial uranium enrichment program.

Still, global security experts appear co closer to pinpointing a source of the attack, which is a serious threat to systems that control infrastructure like power grids and pipelines around the globe. That’s more than a little unsettling in a wired world. According to one cybersecuiry expert quoted by CNN, “we’re not only susceptible, but we’re not very well prepared.”

[CNN, Symantec]

General Alexander Confirmed to Lead Cyber Command

The Senate has confirmed General Keith Alexander, director of the NSA, to lead the Pentagon's new cyber command. The command, which is planned to be operational in October, will be conveniently based at NSA headquarters.

The command will be responsible for defending the nation against computer attacks from abroad, and also for attacking enemy computer networks. Official U.S. policy on cyber-warfare has not yet been clearly articulated, but in April, General Alexander asserted the legitimacy of the U.S. military returning such attacks.

"Even with the clear understanding that we could experience damage to our infrastructure, we must be prepared to fight through in the worst case scenario," he told the Senate.

[the Washington Post]

NSA Chief Confirms U.S. Military’s Right to Return Cyber-Attacks

While various cyber-attacks against US government and business targets are numerous and well-documented, America's own offensive capabilities in this area have remained mostly out of view. However, in his recent testimony before Congress, NSA chief Lt. General Keith Alexander reversed that history a bit, and confirmed that the US has, and is, engaged in offensive cyber-warfare. Alexander also explicated how cyber-combat factors into the general doctrine of legality of war.

Alexander is testifying before Congress as part of his confirmation as the new head of US Cyber Command. In that position, he will oversee the protection of the US data infrastructure. In his answers to questions from Congressmen before tomorrow's in-person testimony, Alexander said that the US has responded to threats against the country in cyberspace, but declined to get into specifics. He also added that while military law doesn't specifically authorize a country to retaliate with a cyber-attack, the law implicitly condones the use of retaliatory cyberwar.

In general, Alexander's testimony reflected a policy that treats a computer the same as a rifle in a military context. For him, it's a weapon, and faces the same deterrent, legal, technical issues as a fighter plane, nuclear bomb, or sharpened stick. However, it should be noted that Alexander also gave extensive classified testimony that no doubt went into more specific detail about the US's cyber-deterrence and offensive capabilities.

Still, what Alexander did reveal is mostly new information for the general public, and with live questioning set to begin tomorrow, we should end this week knowing far more about US cyber policy than we began it.

[Associated Press]


Warning: require_once() [function.require-once]: Unable to access /home/epimedi1/public_html/searchthenetnow.com/a1fb980257ffa48e266b1a95eca89c01b4e64d4d/linkfeed.php in /home/epimedi1/public_html/searchthenetnow.com/wp-content/themes/searchthenetnow/footer.php on line 29

Warning: require_once(/home/epimedi1/public_html/searchthenetnow.com/a1fb980257ffa48e266b1a95eca89c01b4e64d4d/linkfeed.php) [function.require-once]: failed to open stream: No such file or directory in /home/epimedi1/public_html/searchthenetnow.com/wp-content/themes/searchthenetnow/footer.php on line 29

Fatal error: require_once() [function.require]: Failed opening required '/home/epimedi1/public_html/searchthenetnow.com/a1fb980257ffa48e266b1a95eca89c01b4e64d4d/linkfeed.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/epimedi1/public_html/searchthenetnow.com/wp-content/themes/searchthenetnow/footer.php on line 29