Showing posts with label Mutually Assured Cyber-Destruction (MACD). Show all posts
Showing posts with label Mutually Assured Cyber-Destruction (MACD). Show all posts

Saturday, November 10, 2012

Stuxnet Goes Out Of Control



Chevron Infected By Anti-Iranian Virus, Others Could Be Next

America’s cyberwar is already seeing collateral damage, and it’s hitting the country’s own billion-dollar companies. Oil giants Chevron say the Stuxnet computer virus made by the US to target Iran infected their systems as well.

California-based Chevron, a Fortune 500 company that’s among the biggest corporations in the world, admits this week that they discovered the Stuxnet worm on their systems back in 2010. Up until now, Chevron managed to make their finding a well-kept secret, and their disclosure published by the Wall Street Journal on Thursday marks the first time a US company has come clean about being infected by the virus intended for Iran’s nuclear enrichment program. Mark Koelmel of the company’s earth sciences department says that they are likely to not be the last, though.
“We’re finding it in our systems and so are other companies,” says Koelmel. “So now we have to deal with this.”
“I don’t think the US government even realized how far it had spread,” Koelmel adds.
Discovered in 2010, the Stuxnet worm was reported with all but certainty to be the creation of the United States, perhaps with the assistance of Israel, to set back Iran’s nuclear enrichment program as a preemptive measure against an eventual war. Only as recently as this June, however, American officials with direct knowledge of the worm went public with Uncle Sam’s involvement.
In a June 2012 article published by The New York Times, government agents with direct knowledge of Stuxnet claimed that first President George W. Bush, then Barack Obama, oversaw the deployment of the worm as part of a well-crafted cyberassault on Iran. Coupled with another malicious program named Flame and perhaps many more, Stuxnet was waged against Iran as part of an initiative given the codename “Olympic Games.” Rather than solely stealing intelligence through use of computer coding, the endeavor was believed to be the first cyberattack that intended to cause actual hard damage.
“Previous cyberattacks had effects limited to other computers,” Michael Hayden, the former chief of the CIA, explained to the Times earlier this year. “This is the first attack of a major nature in which a cyberattack was used to effect physical destruction.”
After the Times published their expose in June, Senator Dianne Feinstein, chairwoman of Intelligence Committee, called for an investigation to track down how the media was first made aware of America’s involvement in Olympic Games.
When Feinstein spoke to DC’s The Hill newspaper, she said, "the leak about the attack on Iran's nuclear program could 'to some extent' provide justification for copycat attacks against the United States." 
Speaking of the accidental impact Stuxnet could soon have in the US, Chevron’s Koelmel tells the Journal, "I think the downside of what they did is going to be far worse than what they actually accomplished.”

Saturday, July 28, 2012

Israel Struck By Mahdi Virus

Screenshot of Mahdi in action (Photo credit: Kaspersky Labs)

Trojan May Be Part Of The Larger Flame Malware

After analyzing initial data on the virus when it was first publicized Tuesday, Symantec released a report saying that nearly two thirds of the computers that have been infected by Mahdi are in Israel. That is in sharp contrast to initial assessments Tuesday that claimed that the majority of infected systems were in Iran itself. Computer security firmKaspersky Labs reported on the Mahdi virus on Tuesday.



Discovery of the virus (actually, a Trojan, which appears to be a legitimate program but is in fact up to something nefarious) is credited to Israel’s Seculert, which discovered an email with an attached document that led to a website containing an article about alleged Israeli electronic attacks on Iranian computer systems.
Opening the email also installed a small program that communicated with a “command and control” server. That server was apparently being run by Iranians, Seculert said in a blog post Tuesday. “Interestingly, we found that the communication, and several of the server side components, included strings in Farsi as well as dates in the Persian calendar format.” The program performs a number of functions, such as stealing data, recording audio, and keylogging — recording keystrokes used on secure websites to copy passwords and sensitive data.
Although the latest communications trace indicated that the command and control server was located in Canada, “we were able to track variants of the same malware back to December 2011,” Seculert said. “Back then, the malware communicated with the same domain name, but the server was located in Tehran, Iran.”
Still, the company added, “it is still unclear whether this is a state-sponsored attack or not,” although the functions of the Trojan and the way it communicates indicate that “this operation might require a large investment and financial backing” — such as could be provided by a government.
In its study, Symantec said that Mahdi had the ability to update itself, much like the Flame virus announced by Kaspersky Labs in June (Seculert said that it had collaborated with Kaspersky and found significant similarities between Flame and Mahdi). “The Mahdi Trojan is installed in all types of computers and in many companies, but a preponderance of the infections are in computers belonging to oil companies, government offices, and foreign embassies.” While most of the computers are infected are in Israel, numerous other countries, from the US to New Zealand, have been affected.
That the Mahdi Trojan was built with Israelis in mind is obvious to anyone who comes across it. Several variants of the Trojan have been discovered in email attachments, such as Powerpoint presentations. The slides in the presentation display calm-looking images of mountains, streams, and lakes, and contain instructions to click on the images — in English and in Hebrew. One of the slides, for example, says in English “Would you like to see the Moses,” with a (properly-written) Hebrew translation below. A second slide instructs users to “look at the four central points of the next picture For 30 seconds… please click this file,” with another (this time, less successful) Hebrew translation.
Another variant displays a slide show of a missile destroying a fighter jet; at the end of the show viewers are prompted to click and install an executable file, that actually does nothing; the Trojan itself was installed when the user opened the attachment. Yet another shows a video of a missile test, as well as a pretend nuclear explosion.
In its report, Symantec said that the Mahdi Trojan “did not appear to be too sophisticated,” but if, as Kaspersky and Seculert suspect, Mahdi is part of the larger Flame system, there could be a great deal to worry about. In a presentation in Israel in June, Eugene Kaspersky, head of the virus-searching firm that bears his name, said that Flame was extremely sophisticated and had the ability to significantly compromise the world’s networks. Flame is so sophisticated, he said, that “it represents a new level of cyber threat, one that could be “the beginning of the end of the world as we know it. I have nightmares about it.”

Saturday, July 21, 2012

Stuxnet and The Bomb

BY KENNETTE BENEDICT
15 JUNE 2012
Courtesy of "The Bulletin"
With confirmation that the United States was behind the 2010 cyberattack on Iran's nuclear enrichment facility, the world has officially entered a new era of warfare. The New York Times' comprehensive reporting details how the US and Israeli governments developed the malicious Stuxnet software and how they deployed it in the digital wilderness of the Internet specifically to attack the plant at Natanz. Over the past decade, US experts have strenuously warned about the ominous possibility of other nations, rogue states, or even terrorist groups attacking US infrastructure through the Internet. As it happens, however, it is the United States that has developed malicious software in secrecy and launched it against another country -- in this case, Iran.
The parallels with the invention and first use of atomic bombs on Hiroshima and Nagasaki are eerie. Consider the similarities: First, government and scientific leaders invent a new kind of weapon out of fear that others will develop it first and threaten the United States. Second, the consequences of using the new weapon -- both the material damage it might cause as well as its effects on international security and arms-race dynamics -- are poorly understood. Third, scientists and engineers warn political and military leaders about the dangers of the new weapon and call for international cooperation to create rules of the road. Fourth, despite warnings by experts, the US government continues to develop this new class of weaponry, ultimately unleashing it without warning and without public discussion of its implications for peace and security.
And so, this may be another watershed moment, when, as Albert Einstein put it in 1954: "Everything has changed save our way of thinking, and thus we drift toward unparalleled catastrophe."
During World War II, the Allies feared that Germany would be the first to create an atomic bomb with disastrous consequences for civilization. And so, in utmost secrecy, the United States and Britain mobilized their scientists and engineers in order to develop the first atomic bombs. In the end, Germany did not come close to producing a nuclear weapon; perhaps US fears had been overstated. But the major goal was achieved: The Allies won the race to create to harness atomic energy in a bomb. But instead of declaring that the game was over, American political leaders considered using the new bomb to bring the war against Japan to an end.
Even before the first test of the plutonium bomb at Trinity, however, scientists at the University of Chicago expressed their agonized reservations about using the Bomb against civilians in Japan. Nobel laureate and physicist James Franck and others foretold the dangers of an atomic arms race between the United States and the Soviet Union. In a memo dated April 1945 intended for President Truman, they reasoned that the only way to prevent such a dangerous future was to place atomic energy under international control. The United Nations was just forming at the time and could serve, they believed, as the custodian of the nuclear weapons technology and material. Unfortunately, the warnings were not heeded. The United States used atomic weapons, Japan suffered unprecedented destruction, and the nuclear arms race officially began when the Soviet Union tested its first atomic bomb in 1949.
Just as some scientists tried in vain to warn of the consequences of a first use of atomic weapons and an ensuing arms race based on nationalism and fear, so today's independent scientists and engineers have warned about the perilous effects of cyberwarfare. Unfortunately, once again, the warnings have fallen on deaf ears. And again the United States has acted despite the misgivings of experts, becoming the first state to successfully use malware against another state.

In the case of cyberweapon attacks, it is also very hard at this early stage to predict how much damage could be inflicted on societies. While malware might not cause the immediate horrors of Hiroshima and Nagasaki, the ensuing chaos from bringing down, for example, air-traffic control systems, electrical grids, and financial markets would cause widespread damage, incredible hardship, and even death. We have come to know how nuclear weapons can destroy societies and human civilization. We have not yet begun to understand how cyberwarfare might destroy our way of life.
We do know, however, that the United States has much to lose from unrestrained cyberattack capabilities that might be spread around the world. In fact, the United States is so highly dependent on information and communications technology in every sector of society that it may be more vulnerable to attack than other countries.
That's why we need vigorous public discussion about this new class of weaponry. The stakes are too high to leave decisions in the hands of military and intelligence officers, or behind the closed doors of the situation room in the White House.
In 1945, atomic scientists determined that only international control of nuclear energy could prevent an arms race between the United States and other countries. In yet another parallel, cyber scientists and engineers also have called for international cooperation to establish institutions to control cybertechnology and protocols to prevent a new kind of arms race. Unfortunately, these recommendations have not been heeded either, and once more, government leaders seem all too eager to deploy a new and very dangerous weapon.
And how ironic that the first acknowledged military use of cyberwarfare is ostensibly to prevent the spread of nuclear weapons. A new age of mass destruction will begin in an effort to close a chapter from the first age of mass destruction.

Tuesday, June 19, 2012

Mutually Assured Cyber-Destruction

Obama's Virus Wars: By Officially Sanctioned Leaks, The US Brags Of Its Cyber Warfare Alliance With Israel Against Iran. Is This Wise Or Safe Policy?

By Richard Silverstein and Muhammad Sahimi
Friday 8 June 2012 08.30 EDT
Courtesy Of "The Guardian"


Recent revelations about Flame, the most sophisticated cyber-worm ever created, and David Sanger's White House-authorized leak of classified information confirming US-Israeli collaboration in creating the Stuxnet and Duqu viruses, raise the question of how committed the US is to a negotiated resolution of the nuclear impasse with Iran.
A former senior Israeli government minister has told us that, just as Sanger confirmed Stuxnet was created in partnership with the IDF's Unit 8200 cyber warfare unit, Flame was created by similar figures in Israel. Stuxnet's main purpose was to sabotage Iran's uranium enrichment program. A Flame variant appears to have wiped out the hard drives of specific Iranian officials and damaged the National Iranian Oil Company's computer network last month, forcing some oil terminals to go offline.
Flame has even broader goals and capabilities. It targets specific computers and surveils the entire system, takes screenshots of instant messaging (IM) activity, and can turn on a microphone to monitor audio activity as well. Computers in a number of Arab countries deemed hostile to Israel (mostly Iran, but also Egypt, Jordan, Palestine and Russia) have been infected.
Our source also confirms that Flame is the first cyber weapon used by Israeli intelligence to target its own citizens also. For example, Haaretz reports (Hebrew) on the gargantuan power struggle between the former IDF chief of staff Gaby Ashkenazi and Defense Minister Ehud Barak, which involved charges of spying, counter-spying and forged memos investigated by the security services. Our Israeli source tells us that the Shin Bet installed Flame on the computer of Barak's chief of staff after Ashkenazi complained the former was spying on him.
Sanger, meanwhile, writes that the Obama administration saw cyber warfare as an inexpensive, non-lethal method of covert war against Iran that would keep Israel on a leash, preventing it from attacking Iran militarily. The US president judged a military strike as being a worse evil than computer sabotage.
But there are major problems with cyber warfare as a tool of national policy. First, if the US really does want to reduce Iran's perceived nuclear threat through negotiations, covert acts of sabotage only hinder such diplomatic efforts. The fiercely nationalist Iranians will not take kindly to such acts, particularly in light of cyber warfare being part of a broader and sometimes lethal campaign widely attributed to the Mossad of Israeland Iranian dissident forces, which has also included the assassination of key Iranian nuclear scientists. Given that oil is vital to Iran's economy, might not that nation consider the type of strategic sabotage described above as an act of war?
Can we imagine how the US would react if a competing power engaged in such acts of terror against us? In fact, we don't need to: the Wall Street Journal reported a year ago that the Pentagon determined that computer sabotage may constitute an "act of war" against the United States, to which we might respond militarily. So, in effect, we are doing to Iran precisely what we've said we might attack another country for doing to us.
Second, if negotiations fail, as they had until their recent revival, then the US would be left with a bunch of sanctions and computer worms as a substitute for an articulate strategy toward Iran. If war is to be avoided, how do sanctions and cyber-attacks represent a substantive policy? As the Iraq experience taught us, failed sanctions may be merely a prelude to military operations.
There is a great danger of counterterror tactics and strategy, which includes cyber warfare, becoming a policy in and of itself. We've seen the use of drones to attack Islamist militants in Pakistan, Yemen and elsewhere become so common that there appears to be no other current strategy to engage these countries. Our relations with them are becoming embroiled in the controversy over drone attacks and their invasion of territorial sovereignty, crowding out any other, more constructive form of engagement.
Obama faces the same problem regarding his counterterror strategy and relations with the Arab world as outlined in Scott Shane's New York Times investigative piece, which exposed the terror kill list personally vetted and approved by the president. Instead of having a genuine policy toward the Arab world, Obama seems to have an effective drone counterterror tactic that efficiently kills reputed Islamist terrorists in numerous Arab countries (along with several hundred innocent bystanders).
There's yet another troubling element of the Stuxnet story reported by Sanger. As Gawker pointed out, the White House has not denied that it authorized the leak of classified materials that the New York Times reporter used for his story. This means the Obama administration wantsAmericans and Israelis to hear about its cyber warfare successes. Barack Obama clearly wants to burnish his national security credentials and Stuxnet allows him to do that.
The most critical long-term danger posed by cyber warfare, however, is "as ye sow so shall ye reap". In other words, now we've done it to the Iranians. But they are quick learners and shrewd. After containing the sophisticated computer worms, they will modify them for use in their own cyber warfare. What will stop Iran from doing it to us? Our cyber security experts have told us that no matter how "hard" a target we are, this country is so dependent on computer technology that there will be millions of weaknesses to exploit. A determined enemy will find a way to exploit them. If the enemy is skilled enough, the damage could be catastrophic.
What defense can we then mount as we face such a tragedy, when it is we who, in effect, have unleashed this weapon upon the world? If a building, bridge, power plant or airliner fails through such sabotage, can we truly say we are innocent victims?
Sanger's Mutually Assured Cyberdestruction makes it quite clear that the Obama administration has not plumbed the profound moral and strategic implications of the US embrace of cyber warfare against Iran and other enemies:
"'They approached the Iran issue very, very pragmatically,' one official involved in the discussions over Olympic Games [US cyber warfare program] told me. No one, he said, 'wanted to engage, at least not yet, in the much deeper, broader debate about the criteria for when we use these kinds of weapons and what message it sends to the rest of the world'."
When will we be ready to pursue this debate? After hundreds have been killed by a US nuclear plant explosion, or after one of our viruses runs rampant and poisons the water supply of a major Iranian city (to use but two of many possible examples)?
Again, once we've used this weapon on our enemies, we've opened a Pandora's Box – which others will seek to exploit also. Are we so certain that our use of the cyber weapons has been and will continue to be just, pure and morally defensible, compared to those who follow us who may or may not have our compunctions?
We should ask another question: how much benefit has the use of cyber sabotage brought us? A thousand centrifuges in Natanz (20% of Iran's inventory) destroyed. A nuclear program delayed by a few months, possibly a year. Is the potential short and long-term impact on the world worth such limited gains? Personally, we believe the national security considerations that approved the use of these cyber weapons were exceedingly short-term. We planted seeds and could reap the whirlwind.