Showing posts with label information warfare. Show all posts
Showing posts with label information warfare. Show all posts

Friday, November 13, 2009

China, is it our cyber defense red herring?

There are thousands of articles perpetuating the claim that China is out to get us on the Internet. And yet, all these discussions are begging the question, is it China attacking? Also, are they even the "usual suspects"?

While I can point to real facts of China making active use of information warfare, cyber warfare, or whatever else you choose to call it (such as the release of 0 days being patched by Microsoft
and originally reported by the Taiwanese government, search Microsoft's site), I can also point to Germany (intelligence Trojan horse), the US (The Farewell Dossier) and other countries such
as North Korea (without much detail, so questioned).

We have a failing, that even as experts we see an IP source in China for an attack, and as it is popular, and we are still used to think in the physical world, jump to the conclusion the actor is from China. The actor is often from the US, Eastern Europe, Russia, Brazil, and many other countries. That in turn does not mean these actors are then sponsored by these countries. Information warfare is about covertness, not about being loud. The Internet is perfect for plausible deniability, as I've learned when writing the postmortem analysis of the 2007 attacks against Estonia, for the Estonian CERT.

The Chinese know more about the uses of being covert than any of the rest of us, in their strategy, their actions, and their history. If they are being so indiscreet it is for a specific reason, perhaps as a smoke-screen, or indeed, they are not doing it to begin with.

I am not saying the Chinese government does not attack, I am saying naming them continually is nothing but a baseless red herring, and an easy scape-goat we have all grown used to. Thus, blaming China by itself has become acceptable just because people did it often enough. The story of Ethos manufacturing itself.

Malicious computers in China are a problem we can't and shouldn't deny. However, continually claiming China is the Big Bad and attributing every attack to them, is beyond ridiculous. Nothing to see here, move along.

Then again, maybe if we keep saying it's the Chinese with every attack we see, they will get some ideas and make it true for us. It may eventually prove true, but our current proof is based mainly on people claiming it in the past. We are better than this.

Gadi Evron,
ge@linuxbox.org.

Follow me on twitter! http://twitter.com/gadievron

Friday, March 20, 2009

My Blog on Dark Reading

I recently started blogging for Dark Reading, I will still be blogging here, but what I write there is for Dark Reading alone.

I noticed that because I didn't write for a while, my writing became rather poor (in my taste). I constantly move between between official and personal language, and find it more difficult to write short, and to the point. But I'm getting there.

So far I posted two blogs:
German Intelligence Caught Red-Handed In Computer Spying, Analysis
According to German Web site Der Spiegel, the German foreign intelligence agency BND has supposedly been spying on computer systems around the world in the past couple of years.

Everyone does it. Why not governments?


Authoritatively, Who Was Behind The Estonian Attacks?
In the past couple of weeks the press has been humoring a couple of rumors about who was behind the 2007 cyberattacks against Estonia [PDF]. During these attacks, Estonia's infrastructure, which relies heavily on the Internet, nearly collapsed.

This is not the first time such baseless attributions were made.

I was in Estonia when the attacks occurred. I wrote the post-mortem analysis and recommendations for the Estonian CERT, and I am going to authoritatively show you why these claims are baseless. I will list these accusations and responsibility claims, and show you why they should be ridiculed.
Gadi Evron,
ge@linuxbox.org.

Follow me on twitter! http://twitter.com/gadievron

Monday, October 06, 2008

Information warfare and defending organizations from computer espionage

This blog post is about computer-based espionage, and how we can defend our organizations against it. But I'd like to start from a mood piece of sorts.

There has been too much noise about information warfare lately. If we put DDoS (Distributed Denial of Service) and defacement attacks (such as in Estonia [PDF]) out of mind. The following two stories (coincidentally left to rot as Firefox tabs in my browser for the past two months) give a better understanding of what it is really about, without resorting to more scary stories about what China is, or isn't, doing.

We'll also touch on other interesting cases such as the Israeli Trojan horse case, when we talk about defensive measures in defending against computer-based espionage and targeted attacks.

The first is a report (without much detail or proof) on North Korea being involved in operations against South Korea using Trojan horses for espionage:
http://www.networkworld.com/community/node/32202

The second, is a lesson from history called The Farewell Dossier.

From Wikipedia:
The Farewell Dossier was a collection of documents containing intelligence gathered and handed over to NATO by the KGB defector Colonel Vladimir Vetrov (code-named "Farewell") in 1981-1982, during the Cold War.

...

This information led to a mass expulsion of Soviet technology spies. The CIA also mounted a counter-intelligence operation that transferred modified hardware and software designs over to the Soviets, resulting in the spectacular trans-Siberian incident of 1982. The details of the operation were declassified in 1996.
The resulting explosion was so big, it was supposedly confused for a Nuclear explosion by American decision makers until the CIA said: "oh, that's one of our operations."

A quote from this article puts it in a computer security perspective:
In June 1982, in a remote patch of Russian wilderness, a huge explosion ripped apart a trans-Siberian pipeline.

It wasn't a bomb that destroyed the natural gas pipeline and sent shock waves through the economy of what was then the Soviet Union. Instead, it was a software virus created by the CIA, according to a book by Thomas Reed, a former U.S. Air Force secretary and National Security Council member.
What does this mean?

While incapacitating and destruction-based attacks are certainly of significance, and important to defend against as they impact us directly, regardless of who the attacked party is or where in the world they are (DDoS attacks harm the Internet and its' users), smarter, quieter attacks, are all around us. How do we defend against them?

I expect most information warfare acts to be targeted, quiet, and covert. Espionage, or spying if you like, is not relevant to us unless we are the target. The diplomats and the intelligence communities of different countries can figure it out for us. It is an old occupation, and well covered by international law. Computers are simply another tool, or capability, to be used by these same people. There is nothing new here as far as how the game is played.

And yet, what if you are a target?

Recognizing there is a threat

You may have to defend against computer-based espionage for your own employer. Recent case studies, as well as research, have shown industrial espionage is indeed a big deal, and here are two examples.

One famous case from a few years ago which I had the unfortunate opportunity to study, lead incident response for in the Government, and brief Fortune 100 companies on, is the Israeli Trojan horse case.

Leading IT companies (most of which were local Israeli branches of Fortune 100 companies) were spied on using a Trojan horse built by an incompetent programmer, leaving traces of itself everywhere on the affected systems. This went on for for a long period of time, undetected by any of these companies.

The issue was only detected by chance when the creator of the Trojan horse used it for his own private purposes, and discovered during the investigation into this harassment case. The stolen information was fed directly to their competitors, which was most of the rest of the Israeli IT industry. The services themselves were rendered by civilian intelligence and investigation firms.

In another case Israeli case, the attackers broke into a local branch of the Post Office (also a small bank in Israel) and placed a wireless gateway connected to a switch inside. Through it they stole a few tens of thousands of Shekels in the few days they were in operation (the Israeli Post Office is a sort of a small bank). This case was also broken by complete chance, originally, as nothing was stolen, this was to be ignored by the bank and local authorities.

In other cases, intelligence agencies for various countries, such as France as a prominent example, have been spying on their own to make sure their own local companies have an edge competing with companies from other countries.

Here is an interesting quote from "The Industrious Spies, Industrial Espionage in the Digital Age".
This transition fosters international tensions even among allies. "Countries don't have friends - they have interests!" - screamed a DOE poster in the mid-nineties. France has vigorously protested US spying on French economic and technological developments - until it was revealed to be doing the same. French relentless and unscrupulous pursuit of purloined intellectual property in the USA is described in Peter Schweizer's "Friendly Spies: How America's Allies Are Using Economic Espionage to Steal Our Secrets."
Defending against computer-based espionage

For the purpose of defense, while I'd certainly hope for more resources (read a larger budget) and change my focus on where I apply it--there is no inherent difference in how you defend your organization from computer-based espionage than in protecting against any Joe hacker.

In espionage, the attacker has more resources, both technical and operational. That is the one technical difference, others are motive and legal standing.

Some of what I would do differently

I'd concentrate a bit more of my resources on network behavior analysis (which unfortunately, not many tools exist for, so good network security analysts are the main alternative), as well as on social engineering training and procedures.

Further, I'd prioritize cooperation with the physical security part of the organization, and HR (for personnel screening).

I'd also consider putting up a good deterrent as a cyber security policy. Both to add to the attackers risk, as well as to increase their cost.

First, by doing my job--making myself too difficult of a target in any way available to me, and letting people know about it. Stating the obvious with saying "do your job" is not too helpful, but is solid advice. It is a strong 180 degrees turn from strategies of the 1990's such as "let's not make ourselves a juicy challenge for these kids!"

Second, I'd invest anything I can spare on monitoring my network for anomalies and security incidents, starting with mapping what my network actually looks like. This might add to the risk factor for opponents that can't afford to be caught, and scare them. Covertness is the name of the game, or they would have come through the front door.

Entering am "industrial espionage defense" clause into your budget, or creating a “five year plan” to better protect your organization from organized industrial espionage, may just get you a larger budget to cope with your organization's security needs.

Do you have something you'd do different from (or in addition to) regular security practices when facing espionage from "organized" hackers? Any experience, or thoughts, you can share?

Gadi Evron,
ge@linuxbox.org.

Follow me on twitter! http://twitter.com/gadievron

Friday, September 26, 2008

Estonian Cyber Security Strategy document -- now available online

The Estonian cyber security strategy document is now available online. I must say once again the concept of a national cyber security stance is quite interesting.

Those who wish to download the document:
http://www.mod.gov.ee/?op=body&id=518

My contact there specified she'd be happy to answer any questions. To avoid spam of her inbox, email me for her address.

Gadi Evron,
ge@linuxbox.org.

Follow me on twitter! http://twitter.com/gadievron

Tuesday, September 23, 2008

Estonian Cyber Security Strategy document, translated and public

The Estonians have a public version of their cyber security strategy translated into English (currently available offline only). The concept of a national strategy for cyber security is one which I am particularly fond of (also see previous post, An Account of the Estonian Internet War).

The following is the Summary section from the document which might be of interest (Estonian Cyber Security Strategy — Cyber Security Strategy Committee, Ministry of Defence, ESTONIA, Tallinn 2008):

* * *

The asymmetrical threat posed by cyber attacks and the inherent vulnerabilities of cyberspace constitute a serious security risk confronting all nations. For this reason, the cyber threats need to be addressed at the global level. Given the gravity of the threat and of the interests at stake, it is imperative that the comprehensive use of information technology solutions be supported by a high level of security measures and be embedded also in a broad and sophisticated cyber security culture.

It is an essential precondition for the securing of cyberspace that every operator of a computer, computer network or information system realises the personal responsibility of using the data and instruments of communication at his or her disposal in a purposeful and appropriate manner.

Estonia's cyber security strategy seeks primarily to reduce the inherent vulnerabilities of cyberspace in the nation as a whole. This will be accomplished through the implementation of national action plans and through active international co-operation, and so will support the enhancement of cyber security in other countries as well.

In advance of our strategic objectives on cyber security, the following policy fronts have been identified:

  • application of a graduated system of security measures in Estonia;
  • development of Estonia's expertise in and high awareness of information security to the highest standard of excellence;
  • development of an appropriate regulatory and legal framework to support the secure and seamless operability of information systems;
  • promoting international co-operation aimed at strengthening global cyber security.

Policies for enhancing cyber security

1. The development and large-scale implementation of a system of security measures

The dependence of the daily functioning of society on IT solutions makes the development of adequate security measures an urgent need. Every information system owner must acknowledge the risks related to the disturbance of the service he or she provides. Up-to-date and economically expedient security measures must therefore be developed and implemented. The key objectives in developing and implementing a system of security measures are as follows:

  • to bolster requirements for the security of critical infrastructures in order to increase its resistance, and that of related services, against threats in cyberspace; to tighten the security goals of the information systems and services provided by the critical infrastructure;
  • to strengthen the physical and logical infrastructure of the Internet. The security of the Internet is vital to ensuring cyber security, since most of cyberspace is Internet-based. The main priorities in this respect are: strengthening the infrastructure of the Internet, including domain name servers (DNS); improving the automated restriction of Internet service users according to the nature of their traffic, and increasing the widespread use of means of authentication;
  • to enhance the security of the control systems of Estonia's critical infrastructure,
  • to improve on an incessant basis the capacity to meet the emergence of newer and technologically more advanced assault methods;
  • to enhance inter-agency co-operation and co-ordination in ensuring cyber security and to continue public and private sector co-operation in protecting the critical information infrastructure.

2. Increasing competence in cyber security

In order to achieve the necessary competence in the field of cyber security, the following objectives have been established for training and research:

  • to provide high quality and accessible information security-related training in order to achieve competence in both the public and private sectors; to this end, to establish common requirements for IT staff competence in information security and to set up a system for in-service training and evaluation;
  • to intensify research and development in cyber security so as to ensure national defence in that field; to enhance international research co-operation; and to ensure competence in providing high-level training;
  • to ensure readiness in managing cyber security crises in both the public and private sectors;
  • to develop expertise in cyber security based on innovative research and development.

3. Improvement of the legal framework for supporting cyber security

The development of domestic and international legislation in the field of cyber security is aimed at:

  • aligning Estonia's legal framework with the objectives and requirements of the Cyber Security Strategy;
  • developing legislation on protection of the critical information infrastructure;
  • participating in international law-making in the field of cyber security and taking steps internationally to introduce and promote legislative solutions developed in Estonia.

4. Bolstering international co-operation

In terms of developing international co-operation in ensuring cyber security, the Strategy aims at:

  • achieving worldwide moral condemnation of cyber attacks given their negative effects on people's lives and the functioning of society, while recognising that meeting the cyber threats should not serve as a pretext for undermining human rights and democratic freedoms;
  • promoting countries' adopting of international conventions regulating cyber crime and cyber attacks, and making the content of such conventions known to the international public;
  • participating in the development and implementation of international cyber security policies and the shaping of the global cyber culture;
  • developing co-operative networks in the field of cyber security and improving the functioning of such networks.

5. Raising awareness on cyber security

Raising public awareness on the nature and urgency of the cyber threats might be achieved by:

  • presenting Estonia's expertise and experience in the area of cyber security at both the domestic and international level, and supporting co-operative networks;
  • raising awareness of information security among all computer users with particular focus on individual users and SMEs by informing the public about threats existing in the cyberspace and improving knowledge on the safe use of computers;
  • co-ordinating the distribution of information on cyber threats and organising the awareness campaigns in co-operation with the private sector.
Gadi Evron,
ge@linuxbox.org.

Follow me on twitter! http://twitter.com/gadievron

Thursday, August 21, 2008

House Armed Services Committee discussion on EMP

A friend of mine recently brought to my attention the 2008 report of the Commission to Assess the Threat to the United States From Electromagnetic Pulses (EMP) Attack. That report
is dated April 2008, but the US House Armed Services Committee held hearings on that report July 10th, 2008.

The 2008 report (208 pages/7MB+) is available from
http://www.empcommission.org/reports.php
A video copy of the House Hearings in Windows Media format is available from
http://armedservices.house.gov/hearing_information.shtml

I listened to it once, and then a second time to get the quotes I wanted. Especially interesting to those of us who study affecting change and existential risks.

Event mentioned:
August 13 2003--Power transmission line got hot, sagged down, touched a tree and shorted the ground. Next hour 2000 megawatts of generating capacity were looking for a route to get to the northern US. Whole North-East was blacked out.

Nice buzzword/terminology:
Graceful degradation

Facts and "realistic" assessments mixed in, shared:
1, Estimation of approximately 90% death toll is possible "within parameters"
2. Estimation of a year and a half to order replacement equipment to key systems, from abroad
3. Tested, estimation of 10% of cars to stop working, most (not all) to restart regularly
4. Launch over Caspian sea and tests of Shahab 3 to detonate in orbit show EMP intentions, no others come to mind
5. Explicit Iranian doctrine including EMP
6. It doesn't take advanced or large-yiled nuclear weapons
7. China and Russia have been developing such EMP devices, as opposed to their Cold War strategies
8. With a Scud B you could cover one of the coasts
9. Estimated we'd have three days supply of food

Mentioning of (not explored further):
"Intelligence interdiction and deterrence"
"Deter, dissuade, and if necessary intercept"

My favorite quotes:
"This report presents the results of the commission's assessment of an EMP attack to our critical national infrastructures sometimes referred to as civilian infrastructures, but since they are as important to our military capabilities and our national security as they are to our civilian economy and citizenship we chose to call it critical national infrastructures." -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
The subject of critical infrastructure is dear to my heart, and I've challenged its definition in the past year, following the "Estonian war" incident.
"EMP is one of a small number of threats that can hold our society at risk of catastrophic consequences. A well coordinated and wide-spread cyber attack is another potential example." -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
Dr. Graham putting cyber attacks right beside the nuclear (EMP) strategic threat.
"Our vulnerability is increasing daily as our use and dependence on electronics and automated systems continues to grow." -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
Although mentioned in relevance to EMP, it reflects well the vulnerability advanced countries face in a connected world, as I discuss in my Georgetown Journal of International Affairs article about the "Estonian war" [PDF].
"The impact of EMP is asymmetric in relation to potential adversaries who are not as dependent on modern electronics as we are." -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
They can get us, we can't necessarily get them. Georgia is equivalent to "them" here, in being less reliant on the Internet and thus suffering mostly a PR and PR communication blow in the recent cyber attacks incident in Georgia.
"The current vulnerability of our critical infrastructures can both invite and reward attack if not corrected." -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
Being vulnerable, not working on a correction and then, not only doesn't deter an attack, but invites it. Assuming the other side isn't aware of this vulnerability in this case is false, and yet statements have been made discussing it is a mistake.

When writing the post-mortem analysis for the Estonian CERT, I wanted to avoid a certain issue as it places a target on the backs of the local banks. The Estonian mentality of "if you write about it, we can fix it" truly surprised me.

It is a culture which has secrets and a place for security agencies, but puts full disclosure as part of its ideology.
"It's unlikely my home will burn but I would not sleep well if I did not have an insurance policy. I don't hire somebody to stand there watching for a fire to yell fire! fire! but i do have an insurance policy. That's what I'd like my nation to have for EMP protection." -- Rep. Roscoe Bartlett, House Armed Services Committee hearing on EMP, July 10, 2008.
You can't always protect against everything, but you can plan for most of it.
[Answering on if EMP is the most asymmetric attack possible] "One as I mentioned was a cyber attack, possibly a very wide-spread and contagious biological attacks, but this is one of a very small set and very asymmetric." -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
Dr. Graham putting cyber attacks right beside the nuclear (EMP), and the biological, strategic threats.
When asked: "Why is there so little interest in the part of our leadership to do something about it? Is it just too hard they just don't want to face it?" -- Asked by Rep. Roscoe Bartlett, Dr. William R. Graham answered:

"It might be better to ask a sociologist than an engineer and physicist that question, but it falls into the category of a problem which hasn't happened yet. Certainly our ability to predict very unusual and significant events whether it's Pearl Harbor, the start of the Korean war, 9/11 and whatever, we have, to paraphrase Winston Churchill "much to be humble about" in our ability to predict these events before they happen. Of course once they happen then there tends to be massive response, but somehow it's just not within our character and our society to look for these events before they occur." -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
This brings to mind one of my favorite quotes:
"My biggest obstacle is people's unrealistic belief that if a given disaster hasn't happened yet, it won't ever happen."
--Scott Borg, director and chief economist, U.S. Cyber Consequences Unit

Humans are reactive beings, and we kill fires. In fact, most human endeavor is so busy with current and "interrupting" events as to think or follow-through on long-term strategy.

Before a disaster occurs, you're crying wolf. After it does you're one hair on the back of one sheep asking for calm in a huge panicky herd.

Convincing people a threat is real, isn't easy either. Those who do believe you, may want live examples (show me a PowerPoint presentation of a live exploit!), or may have an interest in how this may impact them, their budget, and their work-load.
"This may be the all-time asymmetric threat but it is also the all-time esoteric threat" - Rep. John Spratt, House Armed Services Committee hearing on EMP, July 10, 2008.
Yeah, it's huge in being scary and potential impact, but how likely is it compared to everything else? Can we afford to ignore it even so?
"Affordability is like beauty, it tends to be in the eye of the beholder" -- Dr. William R. Graham, Chair, Commission to Assess the Threat to the United States from Electromagnetic Pulse (EMP) Attack before the House Armed Services Committee hearing on EMP, July 10, 2008.
Beautiful analogy.
"If you are preparing for something like this in advance, say years ahead, you're now a patriot, you're stimulating the economy, but if you do it hours before it happens, now you're a hoarder [and] you're doing exactly the same thing and timing is critical." -- Rep. Roscoe Bartlett, House Armed Services Committee hearing on EMP, July 10, 2008.
Brilliant summary of existential risks, as viewed by the public and by decision makers.

Gadi Evron,
ge@linuxbox.org.

Follow me on twitter! http://twitter.com/gadievron