This week in cyber conflict: September 5th – September 9th

Relatively little going on this week other than stories being cleaned up from previous weeks. No hacker conferences going on, and no major conflagrations to report. There are some squeaky articles about planned hacktivism or “major” attacks through cyber means on 9/11. Though very little detailed and that would be a complete change in the way that most terrorism has ever been done. So little impact is expected leading into the weekend.

The big news this week has been the DigiNotar and the likely links to Iranian government entities. One question I would ask is why Iran and why China in all of these attack scenarios. Why would the media be leaning towards these entities so heavily. So lets do a little thought experiment and ask ourselves a question. Is China a massive hacking machine or is China just normal and sized extremely large? On the one hand you have America (as an example) with approximately 300 million Americans. Of that number about 1/3rd (100 million) are of the age where technology and hacktivism would make sense, and of that number about .01 percent (10K) might have the skills to be involved. I’m making all this up on the fly so just go with the flow and take another sip of your beer. Now take China with about 5 times as many people and you get around 50K bad boys. So we would expect all things being the same about 5K the hacking effort. So the media blitz about the evil dragon is either a) China hackers are really poor at what they do to get caught so often; b) the simple swell of numbers being noticed as the bell curve is swollen with a huge number of incompetent low level hackers in China; or c) nobody is looking for the other hackers in the mix from the other countries.

So, lets look at the other countries that could be involved and have the technical chops to whack, hack, and smack the information technology environment of other countries. The eight largest economies by GDP are 1) United States 2) Peoples Republic of China 3) Japan 4) India 5) Germany 6) Russia 7) United Kingdom 8 ) Brazil. If the GDP is associated with technology and there is a good case to be made that it does why don’t we see more stories about Japan, India, Germany etc. hacking away. There are very few threads about Japanese hackers and Brazilian hackers. Are there significant cultural differences that make those countries so “elite” that they don’t get caught or is it a case of we see fire everywhere but where we are? Why are China and Russia so over represented in the media reports as “hacking” and even though Anonymous and LulzSec were anchored in the United Kingdom and likely had presence in Germany they are not reported on as national security threats?

There really isn’t anything significant here just analyzing the trends of the reporting that is going on through out the weeks.

Monday September 5th

UK Law Enforcement Agencies Arrest Cyber Attack Suspects
ITProPortal
The hunt for hackitivists by UK law enforcement agencies continues as two more people were arrested and two others charged for having alleged ties to hacker outfits Anonymous and Lulz Security. According to a statement released by the Metropolitan 
See all stories on this topic »
Texas Police Department Network Under Cyber Attack by Hackitivist Group Anonymous
ITProPortal
Anonymous hacked into the Texas police department’s network and stolen vital emails and sensitive data as a part of their operation ‘Texas Takedown Thursday’. The hacktivist group then published 3GB of stolen sensitive data online. 
See all stories on this topic »

ITProPortal
Members of Hacktivist Group Anonymous Plead Not Guilty to Cyber Attack on Paypal
ITProPortal
Rebellious and anti-establishment hacktivist group Anonymous is showing no sign of stopping its attacks on government, law enforcement and judiciary systems all around the globe. According to recent reports, Anonymous targeted and took down the website
See all stories on this topic »

ITProPortal
CHINA: If The Government Doesn’t Like It, It Must Be Good
Strategy Page
Chinese neighbors agreed with this, as did more distant targets (of Chinese Cyber War attacks). China promptly denounced the American analysis as “baseless.” But the reality is otherwise. The growing Chinese navy is increasingly showing up to enforce 
See all stories on this topic »
Two freed in FG hacking inquiry
Irish Times
Two people arrested by gardaí investigating a cyber attack on the Fine Gael website have been freed without charge. During the attack, which took place in January, the site was modified and the personal information of 2000 site subscribers was stolen 
See all stories on this topic »

Irish Times
Hackers hit Friendswood police chief’s email account; How you can protect yourself
KHOU
by Doug Miller / KHOU 11 News FRIENDSWOOD, Texas—A cyber attack targeting Texas law enforcement officials has apparently exposed confidential investigative information as well as offensive emails purportedly written by police. 
See all stories on this topic »
Police Chief Says Racist Email Not His
MyFox Houston
Friendswood Police Chief Bob Weiners is speaking out following a cyber attack on the Texas Police Chiefs Association website late Thursday night. The hacker group Anonymous posted data from personal and work emails of law enforcement officers, 
See all stories on this topic »

MyFox Houston
DHS Warns of Anonymous Cyber-Attack Tools, Planned Mass Protests
eWeek
The Department of Homeland Security is beginning to take Anonymous and other non-professional cyber-attackers more seriously as it issues a warning about potential attacks. The United States Department of Homeland Security warned the security community 
See all stories on this topic »
Stolen information worth £300m recovered by GCHQ
Telegraph.co.uk
By Duncan Gardham, Security Correspondent William Hague, the Foreign Secretary, said the agency had joined forces with the Serious and Organised Crime Agency to obtain the information as part of the ongoing cyber war against foreign states and criminal 
See all stories on this topic »
There is no Geneva Convention online
Computing
by John Mitchell I am not a lawyer, but to my mind cyber crime is committed by individuals, or groups, whereas cyber warfare is committed by governments. Does it matter? Not from a cyber defence point of view, but rather from the way it is played and 
See all stories on this topic »

Computing
Hackers Forge Certificates to Break into Spy Agencies
PCWorld
The cyber attack on DigiNotar, a Dutch subsidiary of VASCO Data Security International Inc, is much more serious than previously thought. In July, hackers gained access to the network and infrastructure of several of DigiNotar’s CAs. 
See all stories on this topic »

Tuesday September 6th

ACRES accused of ‘cyber attack
TODAYonline
by Tan Weizhen SINGAPORE – The controversy over the capture and captivity of 25 wild dolphins for Resorts World Sentosa’s (RWS) Marine Life Park attraction has taken a new twist, with the resort accusing animal welfare group Animal Concerns Research 
See all stories on this topic »
Cyberwar & Certified Lies: 531 Spy Certs target CIA, Google, Microsoft, Mozilla
Network World (blog)
DigiNotar was blacklisted by Microsoft, Google and Mozilla browsers, but the attack targeted 531 rogue digital certificates including domains for the CIA, the UK’s MI6, and the Israeli Mossad. Pretty much if you use the web, then a site you accessed 
See all stories on this topic »
The Calm Before the Storm – by Joel Brenner
Foreign Policy (blog)
Cyberwar is already happening — and it’s about to get much, much worse. A veteran cyberwarrior explains how America can prepare itself. BY JOEL BRENNER | SEPTEMBER 6, 2011 Revelations of wholesale electronic fraud and massive data heists have become 
See all stories on this topic »
Watch Out Hackers! Sony Hired a Homeland Security Official
Kotaku
This spring, a cyber attack resulted in a 23 day outage of the PSN and the theft of personal details from over 77 million accounts. Sony is strengthening its online network and stepping up its security. Sony created a new chief information security 
See all stories on this topic »
Iran may be behind cyber attack against Mossad and CIA websites, experts say
Ha’aretz
By Oded Yaron and The Associated Press Tags: Iran Mossad The Iranian government could be behind a mass cyber attack that hit some 300000 Iranian internet users and the websites of intelligence agencies including Israel’s Mossad and the CIA, 
See all stories on this topic »

Ha’aretz

Wednesday September 7th

Strategic News Service Welcomes Cleantech Group as Alliance Partner
MarketWatch (press release)
Recent calls include the 2007 global economic meltdown, the emergence of “Currency Wars” and of “Economic Cyberwar,” together with increasing global IP theft by China, among other major global trends. SNS is delivered each week to a subscriber base of 
See all stories on this topic »
300000 Iranian IP Addresses Compromised In DigiNotar SSL Hack
CRN
By Stefanie Hoffman, CRN Google Web mail was likely compromised for 300000 Iranian customers by hackers issuing fraudulent security certificates following a cyber attack against Dutch certificate authority DigiNotar, according to investigators. 
See all stories on this topic »
Naval Academy Expands on Cyber Security
Military.com
ANNAPOLIS, Md. — The new academic year marks the beginning of the Naval Academy’s new cyber security curriculum, in which midshipmen are required to take classes that will enhance their knowledge of cyber warfare and the threat it poses to national 
See all stories on this topic »
Sony hires former Homeland Security officer in wake of data breach
TechSpot
The move comes after Sony was the target of a devastating cyber attack earlier this year that subsequently caused shares in the company to fall 55 percent, according to Reuters. Philip Reitinger is the former head of the US National Cyber Security 
See all stories on this topic »

TechSpot
Turkish hackers strike websites with DNS hack
IDG News Service
Due to a reporting error, the story posted Monday, “Turkish hackers strike websites with DNS hack,” inaccurately portrayed the scale of a cyber-attack as well as the sites targeted. The story has been edited on the wire and the changes are detailed 
See all stories on this topic »

Thursday September 8th

Former general says Israel unprepared for cyber war
infolive.tv
The chairman of Israel’s Electric Corporation and a former IDF general warned Israel is inadequately prepared to defend itself against growing cyber threats. Speaking at the Zvi Meitar Institute for Land Warfare conference, Yitzhak Ron-Tal said Israel 
See all stories on this topic »
How Do You Tell When You’re Under Cyber Attack?
Huffington Post (blog)
I’ve talked in a previous posting about the term “cyber attack” and why I don’t particularly like it — because in many cases it’s very difficult to tell whether you’ve been attacked. That’s because the attacker’s complete objective is to avoid being 
See all stories on this topic »
Would the United States win a cyberwar?
SC Magazine US
A while back I taught a week-long class for aspiring hackers, a war room of sorts with attack and defend scenarios, points tallied for successful exploits, and stuff like that. We balanced the war room with plenty of classroom and lecture time. 
See all stories on this topic »
Dutch government broadens cyber-attack probe
Social Barrel
Last week, DigiNotar disclosed information regarding a July cyber-attack into its systems after releasing certificates to a third-party applicant, unwittingly allowing hackers to verify Web site authenticity. The hacking scandal went full blast when 
See all stories on this topic »

Social Barrel
infolive.tv news 08/09/2011
infolive.tv
Hamas terrorists with ties to Syria arrested Palestinian official blasts US Former general says Israel unprepared for cyber war US official: revolution in Iran, a matter of time Israel’s Ambassador returns to Cairo Syria continues killing activists.
See all stories on this topic »
McAfee: Modern cars can be hacked and disabled remotely
Computing
by Stuart Sumner Modern cars’ reliance on computer systems makes them vulnerable to cyber attack, which could allow hackers to be disable them remotely, according to a report from McAfee released today. The report was released in conjunction with 
See all stories on this topic »

Computing
What would a Stuxnet-type attack in US look like?
GCN.com
Cyber warfare, like conventional warfare, has its own objectives, said James Howe, vice president for threats, technology and future requirements with Vision Centric. He noted that cyber warfaremust be integrated into conventional warfare. 
See all stories on this topic »

Friday September 9th

Cyber defenders study the art of cyber war
Defense Systems
By Henry Kenyon The country’s cyber defenders need to master the art — as much as the science — of cybersecurity through continuous education, an information security expert said at the Defense Systems Summit on Cyber Defense Sept. 7. 
See all stories on this topic »
Mozilla Wants Answers After Digital Certificate Hacks
PC Magazine
Specifically, the browser maker wants all Certificate Authorities (CA) to complete a series of security checks by September 16 to make sure they too won’t fall prey to a cyber attack like the one that hit DigiNotar. The requests are mostly technical in 
See all stories on this topic »
Doctrineless and self-absorbed
The MIT Tech
Our warnings are coming in the form of panicked reports of intensifying cyber warfare and increasing volumes of weapons-grade nuclear material on the black market. We are facing a paradigm shift just as important as that brought about by nuclear-tipped 
See all stories on this topic »
Many firms ‘do not have sufficient ecrime insurance’
Comms-express.com
Companies that have recently set up with network kits may want to take out ecrime insurance in case their newly established system is breached in a cyber-attack. Malcolm Marshall, UK head of information security at research firm KPMG, observed that 
See all stories on this topic »
Science & Tech: Council website shut down after Russian hackers cause security 
Scottish Daily Record
East Lothian Council suspended their edubuzz.org blog network after the cyber attack. Security experts are repairing the damage. A council spokesman said: “Hackers in Russia had been putting links into the site which caused us security concerns, 
See all stories on this topic »
Cyber hijackers pose threat to planes, vehicles
msnbc.com
Some unfriendly countries are working on so-called cyber warfare programs, and there are also “al-Qaida cells that are acting as training centers for hackers,” said Alan Paller, director of research at the SANS Institute, an information-security 
See all stories on this topic »

 

Leave a Reply