Showing posts with label cyber warfare. Show all posts
Showing posts with label cyber warfare. Show all posts
Monday, May 15, 2017
Special Interest Groups’ Use of Social Media as a Weapon
There are hundreds of special interest groups involved in a wide variety of interests ranging from commerce, health, or art, to community development or religion. There are also groups that are involved in political and social causes. This excerpt from Social Media Warfare: Equal Weapons for All examines well-established special interest groups and the various types of special interest groups, as well as issues related to these groups: health care; guns, hate, and social media warfare; abortion debates and violent acts of extremists; environmentalists and eco-terrorists; lesbian, gay, bisexual and transsexual (LGBT) rights and social media warfare; and religious bias and discrimination in social media warfare.
Monday, November 7, 2016
Hacking the Elections
Quick key take aways from Hacking the Elections by Ian Gray
-- The U.S. election landscape is made up of approximately 9,000 different state and local jurisdictions, providing a patchwork of laws, standards, processes, and voting machines. This environment is a formidable challenge to any actor -- nation-state or not -- who seeks to substantially influence or alter the outcome of an election. Doing so would require mastering a large number of these disparate cyber environments and finding a multitude of ways to manipulate them. An operation of this size would require vast resources over a multi-year period -- an operation that would likely be detected and countered before it could come to fruition.
-- WikiLeaks founder Julian Assange continues to claim objectivity and transparency in his reporting; however, recent events have shown that WikiLeaks may be a pawn -- witting or unwitting -- that has been leveraged by the Russian government as an outlet for stolen information damaging to the Democratic National Party
-- While Guccifer 2.0’s sources are debatable, the hacker has indeed been effective in launching an information and propaganda campaign that has, at least to some degree, disrupted the track of the U.S. election.
-- Aside from the various political-influence campaigns, the FBI has confirmed that malicious actors have been scanning and probing state voter databases for vulnerabilities. Though the actors were operating on servers hosted by a Russian company, those attacks are not, for the moment, being attributed to an actual Russian state-sponsored campaign.
Click here to read the entire article.
-- The U.S. election landscape is made up of approximately 9,000 different state and local jurisdictions, providing a patchwork of laws, standards, processes, and voting machines. This environment is a formidable challenge to any actor -- nation-state or not -- who seeks to substantially influence or alter the outcome of an election. Doing so would require mastering a large number of these disparate cyber environments and finding a multitude of ways to manipulate them. An operation of this size would require vast resources over a multi-year period -- an operation that would likely be detected and countered before it could come to fruition.
-- WikiLeaks founder Julian Assange continues to claim objectivity and transparency in his reporting; however, recent events have shown that WikiLeaks may be a pawn -- witting or unwitting -- that has been leveraged by the Russian government as an outlet for stolen information damaging to the Democratic National Party
-- While Guccifer 2.0’s sources are debatable, the hacker has indeed been effective in launching an information and propaganda campaign that has, at least to some degree, disrupted the track of the U.S. election.
-- Aside from the various political-influence campaigns, the FBI has confirmed that malicious actors have been scanning and probing state voter databases for vulnerabilities. Though the actors were operating on servers hosted by a Russian company, those attacks are not, for the moment, being attributed to an actual Russian state-sponsored campaign.
Click here to read the entire article.
Monday, November 9, 2015
Russia's Undeclared Cyber Wars
Post-Soviet Russia continues to exercise a get-tough attitude toward its former possessions. With each successful foray, its treatment toward the newly independent states that were once part of the Russian Empire becomes more and more assertive if not more aggressive. This excerpt from Vladimir Putin and Russia's Imperial Revival discusses Russia's cyberwar tactics and analyzes its 2007 Cyber War with Estonia.
Tuesday, October 14, 2014
Russian Hackers Spying on NATO: Business as Usual
Following the news of the new Russian 'Sandworm' hack that is exploiting a bug in Microsoft Windows to spy on NATO, EU, Ukraine and others, Tim Erlin, director of IT security and risk strategy for Tripwire explains why this is no surprise:
"It's a short path from shoe phones to zero days. It's simply not surprising that this kind of activity has been going on. Russia, the United States, Britain and others have long histories of very strong and effective spy organizations. There should be little surprise that these groups have continued their missions through the boom of technology.
"Defending against such a targeted attack is extremely difficult. When the attacker is willing to spend significant resources to compromise you specifically, the playing field can be very uneven. As an industry, we tend to focus on the many broad threats that exist, but these kinds of targeted and sophisticated campaigns may actually do more damage."
Conflict and Cooperation in Cyberspace: The Challenge to National Security, edited by Panayotis Yannakogeorgos and Adam Lowther of the Air Force Research Institute, brings together some of the world’s most distinguished military leaders, scholars, cyber operators, and policymakers in a discussion of current and future challenges that cyberspace poses to the United States and the world. Maintaining a focus on policy-relevant solutions, it offers a well-reasoned study of how to prepare for war, while attempting to keep the peace in the cyberspace domain.
Wednesday, May 21, 2014
Russia, China urge to develop and introduce rules for information security
First, I don't believe this for a minute. It's like Cold War propaganda. But wait, we're now in a new Cold War.
But you'd think they'd have better translators for this stuff.
I just finished the latest novel from Tom Clancy, Inc., Command Authority. What's interesting about this, aside from Tom, like L. Ron Hubbard, writing books from the grave, is how closely the book comes to recent events in the Ukraine. Of course, the Putin-liked Russian leader controls all media and is given to long diatribes against enemies, internal and external, real and imaginary.
So, I decided to read the last year or so of the Russian English-language press to see how they covered the lead to the Russian invasion of the Urkaine.
What I found, and this applies to the Chinese English-language press, were barely literate articles, many penned by "Americans." What this amounted to was illiterate propaganda. The outrageous claims were funny enough (and I know our politicians are wont to make outrageous claims that can't be substantiated), but the writing was abysmal. (One editorial printed the lyrics to "Feel Like I'm Fixin' to Die Rag" verbatim. I'm willing to bet they didn't get permission to do that.)
Anyway, how effective can propaganda be when its laughable on so many levels?
Wednesday, December 18, 2013
New Auerbach Series on Critical Infrastructure and Cybersecurity Engineering
Edited by Ross Leo, Chief Systems and Security Architect at Cirrus Informatics, Inc., the objectives of this series include providing timely, well-researched, and informative pieces on the specific areas and issues associated with safeguarding America's critical infrastructures.
Critical Infrastructure and Cybersecurity Engineering Series
If you're interested in finding out more about the series and participating in it, contact Ross Leo.
Monday, July 1, 2013
Hong Kong university warns students and staff about US hackers
The India Times reports that following the Snowden leaks, the Chinese University in Hong Kong warned students and staff about basic computer security to ward off an onslaught of US hackers. Is this calling the pot calling the kettle black, or another skirmish in the new Cold War?
Friday, May 3, 2013
Infosecworld 2013
Last week was Infosecworld. Not surprisingly, as in 2012 the main topics were Big Data, BYOD, mobility and cloud security, and risk. Jeff Crume had several sessions on access control and identity management, including Federated identity management and single sign-on. It’s interesting to think that the big social networking sites—Facebook, Twitter, LinkedIn, Yahoo—use Federated identity. Now, I can log into Yahoo mail using Facebook or Google, not that I want to do it. I’m not sure whether this is good or bad, but it is interesting that while this is being discussed within the enterprise, the social world went ahead and implemented it. Of course, the security and privacy concerns are vastly different between the two worlds.
I heard a lot of talk about cyber espionage, both in sessions and in keynotes. Also, that the defensive focus has changed from cyber crime to cyber espionage and warfare. Of course, APT came into the discussion, although there was some disagreement about what it was. There was even a demo session on hacking SCADA, ICS, programmable controllers, etc.
Jay LaRosa and a colleague from ADP gave an interesting presentation on its next-generation security management platform system. It integrated passive data access network, SIEM, GRC tools, and massively scalable data warehouse; added advanced threat modeling, and provided real-time analysis and reporting. I recall from an earlier presentation about SEIM that between hardware, software, and personnel requirements it was out of reach of most places. This presentation confirmed that observation, but it is a very impressive system.
BTW, I still need proposal for books on DLP, SEIM, BYOD, APT.
Wednesday, March 20, 2013
NATO cyberwar manual: Civilian hackers can be targets
Salon reports that the handbook is first attempt to codify how international law applies to state-sponsored online attacks.
Use kinetic force against cyber aggressors? Yes! Make the cost of playing too dear.
Use kinetic force against cyber aggressors? Yes! Make the cost of playing too dear.
Wednesday, February 6, 2013
Pentagon to Expand Cyber Force
And it's on!
Pentagon to Drastically Expand Cyber Force
As Adam B. Lowther, a Research Professor at the Air Force Research Institute and co-author with Panayotis A Yannakogeorgos of "Conflict and Cooperation in Cyberspace: The Challenge to National Security," to be published by Auerbach in August 2013, said, "With governments and societies believing that cyber attack is something less than an act of war, it should come as no surprise that President Obama is preparing for what may be the opening salvo in America's next confrontation. In fact, it may be the United States that attacks first. Given the cyber vulnerabilities of American society, preemption may be the only option."
Pentagon to Drastically Expand Cyber Force
As Adam B. Lowther, a Research Professor at the Air Force Research Institute and co-author with Panayotis A Yannakogeorgos of "Conflict and Cooperation in Cyberspace: The Challenge to National Security," to be published by Auerbach in August 2013, said, "With governments and societies believing that cyber attack is something less than an act of war, it should come as no surprise that President Obama is preparing for what may be the opening salvo in America's next confrontation. In fact, it may be the United States that attacks first. Given the cyber vulnerabilities of American society, preemption may be the only option."
Thursday, January 24, 2013
Iran as Latest Cyberthreat. Payback's a Bitch.
This article quotes the head of the Air Force cyber command on Iran's growing cyberthreat.
Well, the Air Force has its cyberwarriors, and wants more, so it stands to reason all our enemies and frenemies want the same. Iran's already hit the financial sector. Only 17 critical infrastructure sectors left to go.
Well, the Air Force has its cyberwarriors, and wants more, so it stands to reason all our enemies and frenemies want the same. Iran's already hit the financial sector. Only 17 critical infrastructure sectors left to go.
Monday, November 12, 2012
Huawei too dangerous to do business with?
Here's more on the supply chain security thing from John Dix, editor of Network World.
Last week, three US service providers came out in support of the Chinese companies. (Sorry, I can't find or recall the reference for this.)
In March, the GAO found that defense agencies claimed to have no supply chain security issues, and discovered that DOD had suspect components.
Is this just New Cold War posturing?
Last week, three US service providers came out in support of the Chinese companies. (Sorry, I can't find or recall the reference for this.)
In March, the GAO found that defense agencies claimed to have no supply chain security issues, and discovered that DOD had suspect components.
Is this just New Cold War posturing?
Monday, October 8, 2012
Chinese firms draw fire in House Intelligence report; Cisco cuts ties to China's ZTE after Iran probe
Well, of course the Chinese firms would call the charges "baseless."
Seems like the House Intelligence Committee did something right. Reuters reports that the committee is recommending that Huawai and ZTE be barred from buying US companies because of fears that they could be used for cyber-espionage. Of course, depending on who wins the Presidential election next month, the committee's recommendation has a good chance of being ignored. I'm suprised we allow them to sell kit into the US, or at least the defense establishment. As I said before, cyber-espionage is still esponiage. Is it any easier done over networks than by coopting employees of target companies or government agencies? I'd be more concerned about cyberwarfare. And didn't India ban Chinese telecom firms from selling into the country because of security concerns? Frankly, I'd be as worried about French and Israeli providers.
10/9/12 -- According to Reuters, Cisco cuts ties to China's ZTE after Iran probe. Shall I rest my case now?
Seems like the House Intelligence Committee did something right. Reuters reports that the committee is recommending that Huawai and ZTE be barred from buying US companies because of fears that they could be used for cyber-espionage. Of course, depending on who wins the Presidential election next month, the committee's recommendation has a good chance of being ignored. I'm suprised we allow them to sell kit into the US, or at least the defense establishment. As I said before, cyber-espionage is still esponiage. Is it any easier done over networks than by coopting employees of target companies or government agencies? I'd be more concerned about cyberwarfare. And didn't India ban Chinese telecom firms from selling into the country because of security concerns? Frankly, I'd be as worried about French and Israeli providers.
10/9/12 -- According to Reuters, Cisco cuts ties to China's ZTE after Iran probe. Shall I rest my case now?
Friday, June 29, 2012
GAO: Cyber Threats Facilitate Ability to Commit Economic Espionage
Another day, another warning, another restatement of the obvious. In the summary, it's noted that in past reports the GAO has made hundreds of recommendations to better protect federal systems, critical infrastructures, and intellectual property. The implication is that prior warnings have gone unheeded, and little's been done about these threats and vulnerabilities from both technology and personnel.
Subscribe to:
Posts (Atom)