Showing posts with label Cyber Terrorism. Show all posts
Showing posts with label Cyber Terrorism. Show all posts

Wednesday, July 31, 2013

Has The US Started An Internet War?



By Bruce Schneier

Today, the United States is conducting offensive cyberwar actions around the world.
More than passively eavesdropping, we're penetrating and damaging foreign networks for both espionage and to ready them for attack. We're creating custom-designed Internet weapons, pre-targeted and ready to be "fired" against some piece of another country's electronic infrastructure on a moment's notice.
This is much worse than what we're accusing China of doing to us. We're pursuing policies that are both expensive and destabilizing and aren't making the Internet any safer. We're reacting from fear, and causing other countries to counter-react from fear. We're ignoring resilience in favor of offense.
Welcome to the cyberwar arms race, an arms race that will define the Internet in the 21st century.
Presidential Policy Directive 20, issued last October and released by Edward Snowden, outlines U.S. cyberwar policy. Most of it isn't very interesting, but there are two paragraphs about "Offensive Cyber Effect Operations," or OCEO, that are intriguing:
"OECO can offer unique and unconventional capabilities to advance U.S. national objectives around the world with little or no warning to the adversary or target and with potential effects ranging from subtle to severely damaging. The development and sustainment of OCEO capabilities, however, may require considerable time and effort if access and tools for a specific target do not already exist.
"The United States Government shall identify potential targets of national importance where OCEO can offer a favorable balance of effectiveness and risk as compared with other instruments of national power, establish and maintain OCEO capabilities integrated as appropriate with other U.S. offensive capabilities, and execute those capabilities in a manner consistent with the provisions of this directive."
These two paragraphs, and another paragraph about OCEO, are the only parts of the document classified "top secret." And that's because what they're saying is very dangerous.
Cyberattacks have the potential to be both immediate and devastating. They can disrupt communications systems, disable national infrastructure, or, as in the case of Stuxnet, destroy nuclear reactors; but only if they've been created and targeted beforehand. Before launching cyberattacks against another country, we have to go through several steps.
We have to study the details of the computer systems they're running and determine the vulnerabilities of those systems. If we can't find exploitable vulnerabilities, we need to create them: leaving "back doors" in hacker speak. Then we have to build new cyberweapons designed specifically to attack those systems.
Sometimes we have to embed the hostile code in those networks, these are called "logic bombs," to be unleashed in the future. And we have to keep penetrating those foreign networks, because computer systems always change and we need to ensure that the cyberweapons are still effective.
Like our nuclear arsenal during the Cold War, our cyberweapons arsenal must be pretargeted and ready to launch.
That's what Obama directed the U.S. Cyber Command to do. We can see glimpses in how effective we are in Snowden's allegationsthat the NSA is currently penetrating foreign networks around the world: "We hack network backbones -- like huge Internet routers, basically -- that give us access to the communications of hundreds of thousands of computers without having to hack every single one."
The NSA and the U.S. Cyber Command are basically the same thing. They're both at Fort Meade in Maryland, and they're both led by Gen. Keith Alexander. The same people who hack network backbones are also building weapons to destroy those backbones. At a March Senate briefing, Alexander boasted of creating more than a dozen offensive cyber units.
Longtime NSA watcher James Bamford reached the same conclusion in his recent profile of Alexander and the U.S. Cyber Command (written before the Snowden revelations). He discussed some of the many cyberweapons the U.S. purchases:
"According to Defense News' C4ISR Journal and Bloomberg Businessweek, Endgame also offers its intelligence clients -- agencies like Cyber Command, the NSA, the CIA, and British intelligence -- a unique map showing them exactly where their targets are located. Dubbed Bonesaw, the map displays the geolocation and digital address of basically every device connected to the Internet around the world, providing what's called network situational awareness. The client locates a region on the password-protected web-based map, then picks a country and city -- say, Beijing, China. Next the client types in the name of the target organization, such as the Ministry of Public Security's No. 3 Research Institute, which is responsible for computer security -- or simply enters its address, 6 Zhengyi Road. The map will then display what software is running on the computers inside the facility, what types of malware some may contain, and a menu of custom-designed exploits that can be used to secretly gain entry. It can also pinpoint those devices infected with malware, such as the Conficker worm, as well as networks turned into botnets and zombies -- the equivalent of a back door left open...
"The buying and using of such a subscription by nation-states could be seen as an act of war. 'If you are engaged in reconnaissance on an adversary's systems, you are laying the electronic battlefield and preparing to use it' wrote Mike Jacobs, a former NSA director for information assurance, in a McAfee report on cyberwarfare. 'In my opinion, these activities constitute acts of war, or at least a prelude to future acts of war.' The question is, who else is on the secretive company's client list? Because there is as of yet no oversight or regulation of the cyberweapons trade, companies in the cyber-industrial complex are free to sell to whomever they wish. "It should be illegal,' said the former senior intelligence official involved in cyberwarfare. 'I knew about Endgame when I was in intelligence. The intelligence community didn't like it, but they're the largest consumer of that business.'"
That's the key question: How much of what the United States is currently doing is an act of war by international definitions? Already we're accusing China of penetrating our systems in order to map "military capabilities that could be exploited during a crisis." What PPD-20 and Snowden describe is much worse, and certainly China, and other countries, are doing the same.
All of this mapping of vulnerabilities and keeping them secret for offensive use makes the Internet less secure, and these pre-targeted, ready-to-unleash cyberweapons are destabalizing forces on international relationships. Rooting around other countries' networks, analyzing vulnerabilities, creating back doors, and leaving logic bombs could easily be construed as an act of war. And all it takes is one over-achieving national leader for this all to tumble into actual war.
It's time to stop the madness. Yes, our military needs to invest in cyberwar capabilities, but we also need international rules of cyberwar, more transparency from our own government on what we are and are not doing, international cooperation between governments and viable cyberweapons treaties. Yes, these are difficult. Yes, it's a long slow process. Yes, there won't be international consensus, certainly not in the beginning. But even with all of those problems, it's a better path to go down than the one we're on now.
We can start by taking most of the money we're investing in offensive cyberwar capabilities and spend them on national cyberspace resilience. MAD, mutually assured destruction, made sense because there were two superpowers opposing each other. On the Internet there are all sorts of different powers, from nation-states to much less organized groups. An arsenal of cyberweapons begs to be used, and, as we learned from Stuxnet, there's always collateral damage to innocents when they are. We're much safer with a strong defense than with a counterbalancing offense.

Saturday, July 13, 2013

Obama Orders List For Overseas Cyber-Attacks



By Glenn Greenwald and Ewen MacAskill

Barack Obama has ordered his senior national security and intelligence officials to draw up a list of potential overseas targets for US cyber-attacks, a top secret presidential directive obtained by the Guardian reveals.
The 18-page Presidential Policy Directive 20, issued in October last year but never published, states that what it calls Offensive Cyber Effects Operations (OCEO) "can offer unique and unconventional capabilities to advance US national objectives around the world with little or no warning to the adversary or target and with potential effects ranging from subtle to severely damaging".
It says the government will "identify potential targets of national importance where OCEO can offer a favorable balance of effectiveness and risk as compared with other instruments of national power".
The directive also contemplates the possible use of cyber actions inside the US, though it specifies that no such domestic operations can be conducted without the prior order of the president, except in cases of emergency. 
The aim of the document was "to put in place tools and a framework to enable government to make decisions" on cyber actions, a senior administration official told the Guardian.
The administration published some declassified talking points from the directive in January 2013, but those did not mention the stepping up of America's offensive capability and the drawing up of a target list.
Obama's move to establish a potentially aggressive cyber warfare doctrine will heighten fears over the increasing militarization of the internet.
The directive's publication comes as the president plans to confront his Chinese counterpart Xi Jinping at a summit in California on Friday over alleged Chinese attacks on western targets.
Even before the publication of the directive, Beijing had hit back against US criticism, with a senior official claiming to have "mountains of data" on American cyber-attacks he claimed were every bit as serious as thoseChina was accused of having carried out against the US.
Presidential Policy Directive 20 defines OCEO as "operations and related programs or activities … conducted by or on behalf of the United States Government, in or through cyberspace, that are intended to enable or produce cyber effects outside United States government networks."
Asked about the stepping up of US offensive capabilities outlined in the directive, a senior administration official said: "Once humans develop the capacity to build boats, we build navies. Once you build airplanes, we build air forces."
The official added: "As a citizen, you expect your government to plan for scenarios. We're very interested in having a discussion with our international partners about what the appropriate boundaries are."
The document includes caveats and precautions stating that all US cyber operations should conform to US and international law, and that any operations "reasonably likely to result in significant consequences require specific presidential approval".
The document says that agencies should consider the consequences of any cyber-action. They include the impact on intelligence-gathering; the risk of retaliation; the impact on the stability and security of the internet itself; the balance of political risks versus gains; and the establishment of unwelcome norms of international behaviour.
Among the possible "significant consequences" are loss of life; responsive actions against the US; damage to property; serious adverse foreign policy or economic impacts.
The US is understood to have already participated in at least one major cyber attack, the use of the Stuxnet computer worm targeted on Iranian uranium enrichment centrifuges, the legality of which has been the subject of controversy. US reports citing high-level sources within the intelligence services said the US and Israel were responsible for the worm.
In the presidential directive, the criteria for offensive cyber operations in the directive is not limited to retaliatory action but vaguely framed as advancing "US national objectives around the world".
The revelation that the US is preparing a specific target list for offensive cyber-action is likely to reignite previously raised concerns of security researchers and academics, several of whom have warned that large-scale cyber operations could easily escalate into full-scale military conflict.
Sean Lawson, assistant professor in the department of communication at the University of Utah, argues: "When militarist cyber rhetoric results in use of offensive cyber attack it is likely that those attacks will escalate into physical, kinetic uses of force."
An intelligence source with extensive knowledge of the National Security Agency's systems told the Guardian the US complaints again China were hypocritical, because America had participated in offensive cyber operations and widespread hacking – breaking into foreign computer systems to mine information.
Provided anonymity to speak critically about classified practices, the source said: "We hack everyone everywhere. We like to make a distinction between us and the others. But we are in almost every country in the world."
The US likes to haul China before the international court of public opinion for "doing what we do every day", the source added.
One of the unclassified points released by the administration in January stated: "It is our policy that we shall undertake the least action necessary to mitigate threats and that we will prioritize network defense and law enforcement as preferred courses of action."
The full classified directive repeatedly emphasizes that all cyber-operations must be conducted in accordance with US law and only as a complement to diplomatic and military options. But it also makes clear how both offensive and defensive cyber operations are central to US strategy.
Under the heading "Policy Reviews and Preparation", a section marked "TS/NF" - top secret/no foreign - states: "The secretary of defense, the DNI [Director of National Intelligence], and the director of the CIA … shall prepare for approval by the president through the National Security Advisor a plan that identifies potential systems, processes and infrastructure against which the United States should establish and maintain OCEO capabilities…" The deadline for the plan is six months after the approval of the directive.
The directive provides that any cyber-operations "intended or likely to produce cyber effects within the United States" require the approval of the president, except in the case of an "emergency cyber action". When such an emergency arises, several departments, including the department of defense, are authorized to conduct such domestic operations without presidential approval.
Obama further authorized the use of offensive cyber attacks in foreign nations without their government's consent whenever "US national interests and equities" require such nonconsensual attacks. It expressly reserves the right to use cyber tactics as part of what it calls "anticipatory action taken against imminent threats".
The directive makes multiple references to the use of offensive cyber attacks by the US military. It states several times that cyber operations are to be used only in conjunction with other national tools and within the confines of law.
When the directive was first reported, lawyers with the Electronic PrivacyInformation Center filed a Freedom of Information Act request for it to be made public. The NSA, in a statement, refused to disclose the directive on the ground that it was classified.
In January, the Pentagon announced a major expansion of its Cyber Command Unit, under the command of General Keith Alexander, who is also the director of the NSA. That unit is responsible for executing both offensive and defensive cyber operations.
Earlier this year, the Pentagon publicly accused China for the first time of being behind attacks on the US. The Washington Post reported last month that Chinese hackers had gained access to the Pentagon's most advanced military programs.
The director of national intelligence, James Clapper, identified cyber threats in general as the top national security threat.
Obama officials have repeatedly cited the threat of cyber-attacks to advocate new legislation that would vest the US government with greater powers to monitor and control the internet as a means of guarding against such threats.
One such bill currently pending in Congress, the Cyber Intelligence Sharing and Protection Act (Cispa), has prompted serious concerns from privacy groups, who say that it would further erode online privacy while doing little to enhance cyber security.
In a statement, Caitlin Hayden, national security council spokeswoman, said: "We have not seen the document the Guardian has obtained, as they did not share it with us. However, as we have already publicly acknowledged, last year the president signed a classified presidential directive relating to cyber operations, updating a similar directive dating back to 2004. This step is part of the administration's focus on cybersecurity as a top priority. The cyber threat has evolved, and we have new experiences to take into account.
"This directive establishes principles and processes for the use of cyber operations so that cyber tools are integrated with the full array of national security tools we have at our disposal. It provides a whole-of-government approach consistent with the values that we promote domestically and internationally as we have previously articulated in the International Strategy for Cyberspace.
"This directive will establish principles and processes that can enable more effective planning, development, and use of our capabilities. It enables us to be flexible, while also exercising restraint in dealing with the threats we face. It continues to be our policy that we shall undertake the least action necessary to mitigate threats and that we will prioritize network defense and law enforcement as the preferred courses of action. The procedures outlined in this directive are consistent with the US Constitution, including the president's role as commander in chief, and other applicable law and policies."

Thursday, November 22, 2012

Our Cyber-Wars Will Trigger Blowback



By Richard Silverstein,


Defense Secretary Leon Panetta made his first major speech about U.S. cyber-war policy to a business roundtable group this week. He invoked 9/11 and Pearl Harbor in warning of the danger of a cyber-attack on the U.S:
[He] spoke in … stark language about potential military responses to cyber-attacks that threaten national security.
The United States is now in a “pre-9/11 moment,” Panetta said, at risk of crippling online attacks against public utilities, trains, or chemical factories…. [Such] attacks … could spark the “cyber Pearl Harbor” that the defense secretary has often referred to.
“An aggressor nation or extremist group could use these kinds of cyber tools to … derail passenger trains, or even more dangerous, trains loaded with lethal chemicals,” he said. “They could contaminate the water supply in major cities, or shut down the power grid across large parts of the country.”
The most damaging attacks could combine a multi-pronged attack: knocking civil and military computer systems offline, with a physical attack on the country.
One of the most troubling aspects of Panetta’s statement was his total amnesia when it comes to the role of our own country in this field. It’s one of the world’s worst-kept secrets (in fact, the Obama administration itself couldn’t leak fast enough in boasting of its involvement) that the U.S. and Israel together jointly developed the Stuxnet and Flame computer viruses in a program code-named Olympic Games. It attacked Iran’s nuclear facilities, destroyed 20% of their uranium-enrichment capability, and penetrated the computer systems of Iran’s military and political leadership.
We did this before Iran waged any sort of cyber-attack on us. We did this knowing it would induce Iran to develop its own capabilities and strike back. It’s the ultimate hypocrisy for us to shake our fist at any potential attackers and threaten them with massive retaliation when we ourselves have done far worse.
No one has ever given the U.S. high marks when it comes to sensitivity concerning the ways in which it wields power in the world. This is yet another example of how we arrogate to ourselves ultimate power and the right to make life-and-death decisions over our enemies, while we deny them the right to do precisely the same thing to us.
As one U.S. government cyber security consultant told The New York Times: “What the Iranians want to do now is make it clear they can disrupt our economy, just as we are disrupting theirs. And they are quite serious about it.”
Further proof of our hypocrisy is the U.S. announcement over the past days that Iran is suspected in a series of cyber-attacks on major U.S. banks, which brought down their computer systems over the course of several days. In addition, oil facilities and infrastructure in Saudi Arabia and other Gulf States were attacked. It appears that Panetta’s speech is a response to such news and a tacit warning to the Iranians that they’re playing with fire, though likening attacks on a Saudi oil company and bringing down the websites of a few banks to a “cyber 9/11” seems far-fetched in the extreme.
What the U.S. media has failed to note is that Iran recently conceded that its own maritime facilities and oil industry had come under cyber-assault that could easily have been the work of U.S. cyber-warriors. The electrical power lines to Iran’s Fordow uranium-enrichment plant were bombed as well, in an attack a high-level Israeli source told me originated with the Mossad and its Mujahedeen e-Khalq (MEK) accomplices.
What’s especially troubling is that we will try to use Iran’s alleged efforts to sabotage our economy as proof that it is a rogue nation worthy of ostracism, while we deserve no less opprobrium for our own policies and behavior. This is nothing less than the equivalent of the victor’s justice that governed the Nuremberg trials. Somehow our enemies become moral pariahs while the depravity of our own misdeeds (Hiroshima, Nagasaki, Dresden, Tokyo) is excused as morally just or expedient.
So, for example, the defense secretary’s reassurance that we accept the rule of international law over the use of cyber-weapons does nothing to reassure. After all, this is the same administration that prepares terror kill lists and somehow finds that targeted killing falls within the bounds of international law. 
You’ll recall the high moral dudgeon into which we flew in this country after a so-called Iranian plot to assassinate the Saudi ambassador to the U.S. was exposed. The notion that Iranian agents might export their grudges here and spill blood on American soil seemed especially outrageous. We conveniently forgot that Israel’s Mossad and its MEK accomplices had assassinated the cream of the Iranian nuclear scientist corps. While the U.S. may not have directly participated, Sy Hersh showed that U.S. special forces had trained the MEK in covert ops at a secret Nevada training facility as late as 2007.
The Pentagon has backed up Panetta’s threats against our cyber-enemies by making cyber weapons and technology one of the few growth industries inside the military-industrial complex. Recently, DARPA, the Pentagon’s research agency, circulated a request for proposals to the defense industry notifying it that the military was willing to spend hundreds of millions on new technology in this field. The new program has been dubbed Plan X.
Daryl Kimball, the executive director of the Arms Control Association, noted the danger of the U.S. government’s headlong flight toward cyber-war with this warning: “It makes it sound like the U.S. is preparing to be able to wage a full-out cyber-war. Those kinds of statements could come back to haunt the U.S. down the road.”

Wednesday, October 03, 2012

Epoch Of 'Computer Virus Wars' Starts

The US is launching a new stage of the arms race – a race of offensive computer weapons.Namely, the US is going to arm itself with computer viruses in order to destroy the enemy’s computer networks. Besides, the US Defense Department is developing a computer program which would deduce the level of information security of the enemy’s strategic facilities.

Until now, the US has been denying that it had any plans of developing “computer weapons”.

A website devoted to US state procurements recently announced two tenders. The first one, announced by the US Air Force, is a tender for creating computer programs which would be able to destroy the enemy’s computer networks and put computer-operated devices out of order. The Air Force is planning to spend $ 10 mln on that.

The second tender was announced by the US Defense Advanced Research Projects Agency. The agency is ready to spend $ 110 mln on creating a program which has already received the name “Plan X” – a digital map which would reflect the enemy’s military infrastructure.

“Most probably, this map will show, first of all, military bases, transport systems and electricity systems,” expert in the work of intelligence services Evgeny Yuschuk said in an interview with the Voice of Russia.

“In the case of a war, it would be quite expectable for the warring sides to try to put each other’s transport and electricity systems out of order. If these systems are operated by computers, they would try to use computer viruses.”

Analysts say that wars of computer programs, in fact, have already started. For example, in May, Iran’s top officials discovered regular disappearances of secret information from their computers. Later, Iranian computer experts discovered that this information was stolen by a new virus spy program called “Flame”.

The abilities of this new spy program shocked computer experts. Specialists from the Kaspersky Laboratory (a Russian company which develops anti-virus programs, probably the most popular ones in Russia) say that “Flame” is currently the world’s most advanced hacker program.

“Strategically important facilities in Russia have also come under US virus programs’ attacks,” another Russian expert in the work of intelligent services, Andrey Masalovich, says.

“Attacks of virus programs have already become permanent – mainly, on nuclear power plants and on objects that have to do with the trade of weapons,” Mr. Masalovich says. “There have even been attacks on computer search engines, like the Russian Yandex."

Sometimes, after an attack of a virus on a computer-operated facility or a computer network, it is hard to say who was behind this attack – amateur hackers or a secret intelligence service of a certain country.

Russia is now insisting that the UN should introduce a ban on creating and producing computer viruses and hacker programs.

Via: "The Voice Of Russia"

Sunday, July 01, 2012

U.S., Israel Developed Flame Virus

By Ellen Nakashima, Greg Miller and Julie Tate,
Published: June 19, 2012
Courtesy Of "The Washington Post"


The United States and Israel jointly developed a sophisticated computer virus nicknamed Flame that collected intelligence in preparation for cyber-sabotage aimed at slowing Iran’s ability to develop a nuclear weapon, according to Western officials with knowledge of the effort.

The massive piece of malware secretly mapped and monitored Iran’s computer networks, sending back a steady stream of intelligence to prepare for a cyber­warfare campaign, according to the officials.

The effort, involving the National Security Agency, the CIA and Israel’s military, has included the use of destructive software such as the Stuxnet virus to cause malfunctions in Iran’s nuclear-enrichment equipment.
The emerging details about Flame provide new clues to what is thought to be the first sustained campaign of cyber-sabotage against an adversary of the United States.

“This is about preparing the battlefield for another type of covert action,” said one former high-ranking U.S. intelligence official, who added that Flame and Stuxnet were elements of a broader assault that continues today. “Cyber-collection against the Iranian program is way further down the road than this.”

Flame came to light last month after Iran detected a series of cyberattacks on its oil industry. The disruption was directed by Israel in a unilateral operation that apparently caught its American partners off guard, according to several U.S. and Western officials who spoke on the condition of anonymity.

There has been speculation that Washington had a role in developing Flame, but the collaboration on the virus between the United States and Israel has not been previously confirmed. Commercial security researchers reported last week that Flame contained some of the same code as Stuxnet. Experts described the overlap as DNA-like evidence that the two sets of malware were parallel projects run by the same entity.

Spokesmen for the CIA, the NSA and the Office of the Director of National Intelligence, as well as the Israeli Embassy in Washington, declined to comment.

The virus is among the most sophisticated and subversive pieces of malware to be exposed to date. Experts said the program was designed to replicate across even highly secure networks, then control everyday computer functions to send secrets back to its creators. The code could activate computer microphones and cameras, log keyboard strokes, take screen shots, extract geo­location data from images, and send and receive commands and data through Bluetooth wireless technology.

Flame was designed to do all this while masquerading as a routine Microsoft software update; it evaded detection for several years by using a sophisticated program to crack an encryption algorithm.

“This is not something that most security researchers have the skills or resources to do,” said Tom Parker, chief technology officer for FusionX, a security firm that specializes in simulating state-sponsored cyberattacks. He said he does not know who was behind the virus. “You’d expect that of only the most advanced cryptomathematicians, such as those working at NSA.”

Conventional Plus Cyber


Flame was developed at least five years ago as part of a classified effort code-named Olympic Games, according to officials familiar with U.S. cyber-operations and experts who have scrutinized its code. The U.S.-Israeli collaboration was intended to slow Iran’s nuclear program, reduce the pressure for a conventional military attack and extend the timetable for diplomacy and sanctions.

The cyberattacks augmented conventional sabotage efforts by both countries, including inserting flawed centrifuge parts and other components into Iran’s nuclear supply chain.

The best-known cyberweapon let loose on Iran was Stuxnet, a name coined by researchers in the antivirus industry who discovered it two years ago. It infected a specific type of industrial controller at Iran’s uranium-
enrichment plant in Natanz, causing almost 1,000 centrifuges to spin out of control. The damage occurred gradually, over months, and Iranian officials initially thought it was the result of incompetence.

The scale of the espionage and sabotage effort “is proportionate to the problem that’s trying to be resolved,” the former intelligence official said, referring to the Iranian nuclear program. Although Stuxnet and Flame infections can be countered, “it doesn’t mean that other tools aren’t in play or performing effectively,” he said.

To develop these tools, the United States relies on two of its elite spy agencies. The NSA, known mainly for its electronic eavesdropping and code-breaking capabilities, has extensive expertise in developing malicious code that can be aimed at U.S. adversaries, including Iran. The CIA lacks the NSA’s sophistication in building malware but is deeply involved in the cyber-campaign.

The CIA’s Information Operations Center is second only to the agency’s Counterterrorism Center in size. The IOC, as it is known, performs an array of espionage functions, including extracting data from laptops seized in counter­terrorism raids. But the center specializes in computer penetrations that require closer contact with the target, such as using spies or unwitting contractors to spread a contagion via a thumb drive.

Both agencies analyze the intelligence obtained through malware such as Flame and have continued to develop new weapons even as recent attacks have been exposed.

Flame’s discovery shows the importance of mapping networks and collecting intelligence on targets as the prelude to an attack, especially in closed computer networks. Officials say gaining and keeping access to a network is 99 percent of the challenge.

“It is far more difficult to penetrate a network, learn about it, reside on it forever and extract information from it without being detected than it is to go in and stomp around inside the network causing damage,” said Michael V. Hayden, a former NSA director and CIA director who left office in 2009. He declined to discuss any operations he was involved with during his time in government.

Years In The Making


The effort to delay Iran’s nuclear program using cyber-techniques began in the mid-2000s, during President George W. Bush’s second term. At that point it consisted mainly of gathering intelligence to identify potential targets and create tools to disrupt them. In 2008, the program went operational and shifted from military to CIA control, former officials said.

Despite their collaboration on developing the malicious code, the United States and Israel have not always coordinated their attacks. Israel’s April assaults on Iran’s Oil Ministry and oil-export facilities caused only minor disruptions. The episode led Iran to investigate and ultimately discover Flame.

“The virus penetrated some fields — one of them was the oil sector,” Gholam Reza Jalali, an Iranian military cyber official, told Iranian state radio in May. “Fortunately, we detected and controlled this single incident.”

Some U.S. intelligence officials were dismayed that Israel’s unilateral incursion led to the discovery of the virus, prompting counter­measures.

The disruptions led Iran to ask a Russian security firm and a Hungarian cyber-lab for help, according to U.S. and international officials familiar with the incident.

Last week, researchers with Kaspersky Lab, the Russian security firm, reported their conclusion that Flame — a name they came up with — was created by the same group or groups that built Stuxnet. Kaspersky declined to comment on whether it was approached by Iran.

“We are now 100 percent sure that the Stuxnet and Flame groups worked together,” said Roel Schouwenberg, a Boston-based senior researcher with Kaspersky Lab.

The firm also determined that the Flame malware predates Stuxnet. “It looks like the Flame platform was used as a kickstarter of sorts to get the Stuxnet project going,” Schouwenberg said.



Staff writer Joby Warrick contributed to this report.

Tuesday, June 19, 2012

Mutually Assured Cyber-Destruction

Obama's Virus Wars: By Officially Sanctioned Leaks, The US Brags Of Its Cyber Warfare Alliance With Israel Against Iran. Is This Wise Or Safe Policy?

By Richard Silverstein and Muhammad Sahimi
Friday 8 June 2012 08.30 EDT
Courtesy Of "The Guardian"


Recent revelations about Flame, the most sophisticated cyber-worm ever created, and David Sanger's White House-authorized leak of classified information confirming US-Israeli collaboration in creating the Stuxnet and Duqu viruses, raise the question of how committed the US is to a negotiated resolution of the nuclear impasse with Iran.
A former senior Israeli government minister has told us that, just as Sanger confirmed Stuxnet was created in partnership with the IDF's Unit 8200 cyber warfare unit, Flame was created by similar figures in Israel. Stuxnet's main purpose was to sabotage Iran's uranium enrichment program. A Flame variant appears to have wiped out the hard drives of specific Iranian officials and damaged the National Iranian Oil Company's computer network last month, forcing some oil terminals to go offline.
Flame has even broader goals and capabilities. It targets specific computers and surveils the entire system, takes screenshots of instant messaging (IM) activity, and can turn on a microphone to monitor audio activity as well. Computers in a number of Arab countries deemed hostile to Israel (mostly Iran, but also Egypt, Jordan, Palestine and Russia) have been infected.
Our source also confirms that Flame is the first cyber weapon used by Israeli intelligence to target its own citizens also. For example, Haaretz reports (Hebrew) on the gargantuan power struggle between the former IDF chief of staff Gaby Ashkenazi and Defense Minister Ehud Barak, which involved charges of spying, counter-spying and forged memos investigated by the security services. Our Israeli source tells us that the Shin Bet installed Flame on the computer of Barak's chief of staff after Ashkenazi complained the former was spying on him.
Sanger, meanwhile, writes that the Obama administration saw cyber warfare as an inexpensive, non-lethal method of covert war against Iran that would keep Israel on a leash, preventing it from attacking Iran militarily. The US president judged a military strike as being a worse evil than computer sabotage.
But there are major problems with cyber warfare as a tool of national policy. First, if the US really does want to reduce Iran's perceived nuclear threat through negotiations, covert acts of sabotage only hinder such diplomatic efforts. The fiercely nationalist Iranians will not take kindly to such acts, particularly in light of cyber warfare being part of a broader and sometimes lethal campaign widely attributed to the Mossad of Israeland Iranian dissident forces, which has also included the assassination of key Iranian nuclear scientists. Given that oil is vital to Iran's economy, might not that nation consider the type of strategic sabotage described above as an act of war?
Can we imagine how the US would react if a competing power engaged in such acts of terror against us? In fact, we don't need to: the Wall Street Journal reported a year ago that the Pentagon determined that computer sabotage may constitute an "act of war" against the United States, to which we might respond militarily. So, in effect, we are doing to Iran precisely what we've said we might attack another country for doing to us.
Second, if negotiations fail, as they had until their recent revival, then the US would be left with a bunch of sanctions and computer worms as a substitute for an articulate strategy toward Iran. If war is to be avoided, how do sanctions and cyber-attacks represent a substantive policy? As the Iraq experience taught us, failed sanctions may be merely a prelude to military operations.
There is a great danger of counterterror tactics and strategy, which includes cyber warfare, becoming a policy in and of itself. We've seen the use of drones to attack Islamist militants in Pakistan, Yemen and elsewhere become so common that there appears to be no other current strategy to engage these countries. Our relations with them are becoming embroiled in the controversy over drone attacks and their invasion of territorial sovereignty, crowding out any other, more constructive form of engagement.
Obama faces the same problem regarding his counterterror strategy and relations with the Arab world as outlined in Scott Shane's New York Times investigative piece, which exposed the terror kill list personally vetted and approved by the president. Instead of having a genuine policy toward the Arab world, Obama seems to have an effective drone counterterror tactic that efficiently kills reputed Islamist terrorists in numerous Arab countries (along with several hundred innocent bystanders).
There's yet another troubling element of the Stuxnet story reported by Sanger. As Gawker pointed out, the White House has not denied that it authorized the leak of classified materials that the New York Times reporter used for his story. This means the Obama administration wantsAmericans and Israelis to hear about its cyber warfare successes. Barack Obama clearly wants to burnish his national security credentials and Stuxnet allows him to do that.
The most critical long-term danger posed by cyber warfare, however, is "as ye sow so shall ye reap". In other words, now we've done it to the Iranians. But they are quick learners and shrewd. After containing the sophisticated computer worms, they will modify them for use in their own cyber warfare. What will stop Iran from doing it to us? Our cyber security experts have told us that no matter how "hard" a target we are, this country is so dependent on computer technology that there will be millions of weaknesses to exploit. A determined enemy will find a way to exploit them. If the enemy is skilled enough, the damage could be catastrophic.
What defense can we then mount as we face such a tragedy, when it is we who, in effect, have unleashed this weapon upon the world? If a building, bridge, power plant or airliner fails through such sabotage, can we truly say we are innocent victims?
Sanger's Mutually Assured Cyberdestruction makes it quite clear that the Obama administration has not plumbed the profound moral and strategic implications of the US embrace of cyber warfare against Iran and other enemies:
"'They approached the Iran issue very, very pragmatically,' one official involved in the discussions over Olympic Games [US cyber warfare program] told me. No one, he said, 'wanted to engage, at least not yet, in the much deeper, broader debate about the criteria for when we use these kinds of weapons and what message it sends to the rest of the world'."
When will we be ready to pursue this debate? After hundreds have been killed by a US nuclear plant explosion, or after one of our viruses runs rampant and poisons the water supply of a major Iranian city (to use but two of many possible examples)?
Again, once we've used this weapon on our enemies, we've opened a Pandora's Box – which others will seek to exploit also. Are we so certain that our use of the cyber weapons has been and will continue to be just, pure and morally defensible, compared to those who follow us who may or may not have our compunctions?
We should ask another question: how much benefit has the use of cyber sabotage brought us? A thousand centrifuges in Natanz (20% of Iran's inventory) destroyed. A nuclear program delayed by a few months, possibly a year. Is the potential short and long-term impact on the world worth such limited gains? Personally, we believe the national security considerations that approved the use of these cyber weapons were exceedingly short-term. We planted seeds and could reap the whirlwind.

Sunday, June 17, 2012

Cyberweapons: Bold Steps In A Digital Darkness?




BY R. SCOTT KEMP
7 JUNE 2012
Courtesy Of "The Bulletin"


Article Highlights

  • The United States rushed into the nuclear age eager to cement its technical superiority, disregarding warnings of key statesmen and scientists that a decades-long nuclear arms race would ensue. Before they go too far, policymakers should consider the implications -- both intended and unintended -- of cyberweapons.
  • Though Israel and the United States may have vast resources to support sophisticated and creative cyberweapons programs, it is worth remembering that such advantage could be its disadvantage: Each new cyberattack becomes a template for other nations -- or sub-national actors -- looking for ideas.
  • As nations begin to develop cyberwarfare organizations, they run the risk of creating bureaucratic entities, which will protect offensive cyber capabilities that simultaneously subject their own publics to cyber vulnerabilities. Since the United States has the most to lose in this area, the safe approach is to direct cyber research at purely defensive applications.
In 1945, the United States organized a committee to investigate whether nuclear weapons should become a central military technology, or whether to abjure the weapons and, through self-restraint, avoid a costly and potentially deadly nuclear arms race. Led by Undersecretary of State Dean Acheson and Chairman of the Tennessee Valley Authority David Lilienthal, the committee produced the eponymous Acheson-Lilienthal Report, which, after it failed to gather reasonable support, marked a turning point in the Cold War and signaled the beginning of the nuclear arms race. Almost 70 years later, we find ourselves at a similar juncture with cyberwarfare. Cyber weapons do not appear to be capable of mass destruction in the way nuclear weapons clearly are, but they hold at risk some of the most precious assets of our time: the information storage and control mechanisms on which modern society has been built. It is not difficult to imagine catastrophic scenarios such as the destruction of a banking sector, the elimination of a stock market, the flooding of a dam, or the poisoning of a water supply -- all initiated by malfunctions induced by malicious software. The United States rushed into the nuclear age eager to cement its technical superiority, causing a decades-long nuclear arms race that threatened global extinction. Before policymakers go too far, they should now take a moment to consider the implications -- both intended and unintended -- of cyberweapons.
While digital spying has taken place for decades, the era of computer-mediated destruction has only recently begun. Early this month The New York Times published an investigative feature that explored Olympic Games, a cyberweapons program designed to sabotage an element of another country's infrastructure. Started during the Bush administration, this is the first known program of its kind. In embarking on Olympic Games, the United States and Israel stepped boldly, but naively, into uncharted territory.
The first battle of Olympic Games reached the public eye in July 2010, when news broke of Stuxnet, a creative worm designed to cause Iran's uranium-enrichment centrifuges to explode by changing, with software, their operating parameters. On its heels were Duqu, Wiper, and Flame, a set of multipurpose tools that collected intelligence, identified vulnerabilities, and sabotaged information systems.
In some small way, the strategic vision of Olympic Games is commendable. Cyberattacks might have reduced Israeli pressure for conventional military strikes that could have led to a deadly and protracted war with Iran and triggered Iran to race for the bomb. The cyberstrategy might have also been rationalized as providing more opportunity for diplomacy -- but as with most experimental programs, events did not go according to plan and unforeseen consequences soon emerged.
Consider as a case study Stuxnet: First injected into Iran's computers in June 2009, the worm appears to have destroyed more than 1,000 of Iran's 5,000 gas centrifuges, according to data reported by the International Atomic Energy Agency (IAEA). However, by drawing from its centrifuge reserves, Iran was able to replace quickly its destroyed centrifuges and compensate for the losses, even while the Stuxnet attack was ongoing.
Indeed, if the measure of Iran's progress toward a nuclear weapon is its inventory of enriched uranium, then Iran came out ahead. IAEA data indicates that Iran was able to boost output enough to reverse all Stuxnet-induced production losses by March 2010, about eight months after the attack first began to have an effect. After the successful eradication of Stuxnet in the summer of 2010, Iran sustained its heightened level of production, expanding its low-enriched uranium stockpile at rates exceeding the pre-Stuxnet trend. If, without Stuxnet, Iran would have expanded production according to its historical trajectory, then one would conclude that the cyberattack wound up enhancing Iran's ability to make nuclear weapons instead of setting the program back.
What went wrong? Stuxnet was designed to operate on an ongoing basis without being detected: a strategy of steady attrition in the pursuit of time. The worm was not supposed to leave Iran or be discovered -- but it soon spread beyond the confines of Iran's nuclear facilities until, ultimately, members of the computer-security community identified PDF it. Stuxnet both failed to operate according to plan and failed to have a long-term benefit. Perhaps, then, the lesson for the authors of future cyberweapons is to recognize the short-lived and unpredictable nature of cyberattacks and aim for more acute, immediate destruction, rather than persistent manipulation of another nation's assets -- a worrisome conclusion suggesting that cyberweapons may be better suited for terror than for strategic affairs.
After Stuxnet, other components of the cyber affront were quickly exposed and removed, and Iran's uranium-enrichment capabilities grew faster than ever. The American and Israeli leaders who launched the games suddenly found themselves in a state of panic. Their ability to influence Iran's nuclear program had dropped precipitously, yet no diplomatic progress had been made to ensure a soft landing. Perhaps leaders had grown too narrowly focused on the play-by-play excitement of a new cyberattack and too comfortable with relative inaction on the diplomatic front. Or perhaps leaders began to feel that a technical fix was potentially within reach, or at least that cyberattacks could hold Iran's nuclear program at bay until its leaders capitulated to the pressure of sanctions. Whatever the likely reasons, the current reality is that the United States finds the diplomatic challenge harder than ever before: After Stuxnet, Iran, with even larger centrifuge reserves, has more to sacrifice, but now trusts the United States even less. Furthermore, Israeli threats of armed conflict have reached a new high. The situation has become unstable, and Olympic Games has yet to realize any enduring benefits.
Despite their questionable utility, the cyberattacks have not been without consequence. Immediately after Iran admitted to being a victim of Stuxnet, it created a new Cyber Command of its own. Brig. Gen. Gholamreza Jalali, the head of Iran's Passive Defense Organization, said that the Iranian military was prepared "to fight our enemies" in "cyberspace and Internet warfare," a formula that may imply aspirations to go on the offensive. The US Defense Department responded by announcing a new policy in which cyberattacks against US assets are considered to be acts of war. More bold steps into the darkness.
In the world of armaments, cyber weapons may require the fewest national resources to build. That is not to say that highly developed nations are not without their advantages during early stages. Countries like Israel and the United States may have more money and more talented hackers. Their software engineers may be more skilled and exhibit more creativity and critical thinking owing to better training and education. However, each new cyberattack becomes a template for other nations -- or sub-national actors -- looking for ideas. Stuxnet revealed numerous clever solutions that are now part of a standard playbook. A Stuxnet-like attack can now be replicated by merely competent programmers, instead of requiring innovative hacker elites. It is as if with every bomb dropped, the blueprints for how to make it immediately follow. In time, the strategic advantage will slowly fade and once-esoteric cyber weapons will slowly become weapons of the weak.
Whatever the greater nature of cyberwarfare, it is clear that individual cyberweapons are inherently fragile. They work because they exploit previously unknown vulnerabilities. Stuxnet, for example, exploited four "zero day" vulnerabilities in the Windows operating system. As soon as Stuxnet made them public, they were patched and thus no longer available vectors for future attacks or intelligence gathering. Such vulnerabilities are also closed through routine software updates and patches. Powerful hacker entities like the US National Security Agency must continue to discover new weaknesses in an attempt to stay ahead, and probably maintain a sizable list of unpublished vulnerabilities for future exploitation -- but to what end? These security gaps apply to all computer systems of a specific type regardless of national borders. Every vulnerability kept secret for the purpose of enabling a future cyberattack is also a decision to let that vulnerability remain open in one's own national infrastructure, allowing it to be exploited by an enemy state or even a terrorist hacker. This raises a basic philosophical question about how states should approach the question of cyberwarfare: Should countries try to accrue offensive capabilities in what amounts to a secret arms race and, in doing so, hold their own publics at risk? Or should states take a different tack, releasing knowledge about vulnerabilities in a controlled way to create patches to shore up their own digital frontiers?
We are at a key turning point -- the Acheson and Lilienthal moment of the digital age in which a nation must decide what role cyberweapons will play in its national defense. As nations begin to build out cyberwarfare organizations, they run the risk of creating bureaucratic entities that will seek to protect offensive cyber capabilities and in doing so will necessarily subject their own publics to cyber vulnerabilities. For states that have little to lose on the cyber front, an offensive approach may be interesting. But for the United States and other highly developed nations whose societies are critically and deeply reliant on computers, the safe approach is to direct cyber research at purely defensive applications. Fortunately, unlike the Acheson and Lilienthal moment of the nuclear age, the United States can make this choice unilaterally. The alternative approach, to continue to launch ambitious cyberattacks, is to cross the Rubicon with an unpracticed weapon, naked to the attacks of enemies and terrorists alike.
Editor's note: This article was updated on June 7, 2012.

Saturday, June 16, 2012

Why Antivirus Companies Failed To Catch Flame and Stuxnet



By Mikko Hypponen
June 1, 2012 | 12:00 pm
Courtesy Of "Wired"


A couple of days ago, I received an e-mail from Iran. It was sent by an analyst from the Iranian Computer Emergency Response Team, and it was informing me about a piece of malware their team had found infecting a variety of Iranian computers. This turned out to be Flame: the malware that has now been front-page news worldwide.

When we went digging through our archive for related samples of malware, we were surprised to find that we already had samples of Flame, dating back to 2010 and 2011, that we were unaware we possessed. They had come through automated reporting mechanisms, but had never been flagged by the system as something we should examine closely. Researchers at other antivirus firms have found evidence that they received samples of the malware even earlier than this, indicating that the malware was older than 2010.

Mikko Hypponen

What this means is that all of us had missed detecting this malware for two years, or more. That’s a spectacular failure for our company, and for the antivirus industry in general.
That’s a spectacular failure for our company, and for the antivirus industry in general.
It wasn’t the first time this has happened, either. Stuxnet went undetected for more than a year after it was unleashed in the wild, and was only discovered after an antivirus firm in Belarus was called in to look at machines in Iran that were having problems. When researchers dug back through their archives for anything similar to Stuxnet, they found that a zero-day exploit that was used in Stuxnet had been used before with another piece of malware, but had never been noticed at the time. A related malware called DuQu also went undetected by antivirus firms for over a year.
Stuxnet, Duqu and Flame are not normal, everyday malware, of course. All three of them were most likely developed by a Western intelligence agency as part of covert operations that weren’t meant to be discovered. The fact that the malware evaded detection proves how well the attackers did their job. In the case of Stuxnet and DuQu, they used digitally signed components to make their malware appear to be trustworthy applications. And instead of trying to protect their code with custom packers and obfuscation engines — which might have drawn suspicion to them — they hid in plain sight. In the case of Flame, the attackers used SQLite, SSH, SSL and LUA libraries that made the code look more like a business database system than a piece of malware.
Someone might argue that it’s good we failed to find these pieces of code. Most of the infections occurred in politically turbulent areas of the world, in countries like Iran, Syria and Sudan. It’s not known exactly what Flame was used for, but it’s possible that if we had detected and blocked it earlier, we might have indirectly helped oppressive regimes in these countries thwart the efforts of foreign intelligence agencies to monitor them.
But that’s not the point. We want to detect malware, regardless of its source or purpose. Politics don’t even enter the discussion, nor should they. Any malware, even targeted, can get out of hand and cause “collateral damage” to machines that aren’t the intended victim. Stuxnet, for example, spread around the world via its USB worm functionality and infected more than 100,000 computers while seeking out its real target, computers operating the Natanz uranium enrichment facility in Iran. In short, it’s our job as an industry to protect computers against malware. That’s it.
Yet we failed to do that with Stuxnet and DuQu and Flame. This makes our customers nervous.
It’s highly likely there are other similar attacks already underway that we haven’t detected yet. Put simply, attacks like these work.
The truth is, consumer-grade antivirus products can’t protect against targeted malware created by well-resourced nation-states with bulging budgets. They can protect you against run-of-the-mill malware: banking trojans, keystroke loggers and e-mail worms. But targeted attacks like these go to great lengths to avoid antivirus products on purpose. And the zero-day exploits used in these attacks are unknown to antivirus companies by definition. As far as we can tell, before releasing their malicious codes to attack victims, the attackers tested them against all of the relevant antivirus products on the market to make sure that the malware wouldn’t be detected. They have unlimited time to perfect their attacks. It’s not a fair war between the attackers and the defenders when the attackers have access to our weapons.
Antivirus systems need to strike a balance between detecting all possible attacks without causing any false alarms. And while we try to improve on this all the time, there will never be a solution that is 100 percent perfect. The best available protection against serious targeted attacks requires a layered defense, with network intrusion detection systems, whitelisting against known malware and active monitoring of inbound and outbound traffic of an organization’s network.
This story does not end with Flame. It’s highly likely there are other similar attacks already underway that we haven’t detected yet. Put simply, attacks like these work.
Flame was a failure for the antivirus industry. We really should have been able to do better. But we didn’t. We were out of our league, in our own game.