Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Thursday, July 23, 2015

Special Operators and Intelligence Analysts: the 21st Century’s Lead Warriors

1 hour panel at the link below.

Special Operators and Intelligence Analysts: the 21st Century’s Lead Warriors


Streamed live on Jul 23, 2015
Huge ground invasions and indefinite occupation forces are so last decade. Today’s wars, big and little, are being fought largely by the strategic deployment of limited Special Operators on the ground and intelligence analysts back stateside who dispatch them and drones to the world’s hot spots for quick “in and out” operations. Experts in this kind of 21st century warfare discuss the strengths and weaknesses of this approach to global crises.

Kathleen Hicks, Senior Vice President, Henry A. Kissinger Chair, and Director, International Security Program, Center for Strategic and International Studies

Eric Olson, former Commander of US Special Operations Command (SOCOM) and a member of the Aspen Institute Homeland Security Group

Michael Vickers, Former Under Secretary of Defense for Intelligence

Moderator: Kim Dozier, Contributing Writer, The Daily Beast; Global Analyst, CNN

Saturday, June 6, 2015

With a series of major hacks, China builds a database on Americans

You can access an original translation of Unrestricted Warfare here: https://www.dropbox.com/s/llltfszyecpj6s6/UnrestrictedWarfare.pdf?dl=0

As you read about the Chinese hack of OPM and over 4 million government employees I think it is worth reflecting on these excerpts from the 1999 book by Chinese PLA Colonels, Unrestricted Warfare.  This is from the first FBIS translation of the book that I have saved over all these years.  Of course you can also buy a commercial copy of the book from Amazon.  I wonder how many people have read these prescient words.  Please pay attention to the highlighted words.  I know many have criticized this book and those who read it and in 2004 when I was a student at the National War College I asked the visiting Chinese Defense Minister if this book was being used to inform Chinese doctrine and strategic thinking he replied that the book had bene discredited in China and for me not to believe everything I read. (though I am violating the non-attribution rule - but I will take my lumps for that when compared to what the Chinese have done to us).  So while we applaud Snowden (and he applauds himself) for defending our privacy from the NSA who is protecting not only our privacy but our national security from the Chinese?


[FBIS Editor's Note: The following selections are taken from "Unrestricted Warfare," a book published in China in February 1999 which proposes tactics for developing countries, in particular China, to compensate for their military inferiority vis-à-vis the United States during a high-tech war. The selections include the table of contents, preface, afterword, and biographical information about the authors printed on the cover. The book was written by two PLA senior colonels from the younger generation of Chinese military officers and was published by the PLA Literature and Arts Publishing House in Beijing, suggesting that its release was endorsed by at least some elements of the PLA leadership. This impression was reinforced by an interview with Qiao and laudatory review of the book carried by the party youth league's official daily Zhongguo Qingnian Bao on 28 June. Published prior to the bombing of China's embassy in Belgrade, the book has recently drawn the attention of both the Chinese and Western press for its advocacy of a multitude of means, both military and particularly non-military, to strike at the United States during times of conflict. Hacking into websites, targeting financial institutions, terrorism, using the media, and conducting urban warfare are among the methods proposed. In the Zhongguo Qingnian Bao interview, Qiao was quoted as stating that "the first rule of unrestricted warfare is that there are no rules, with nothing forbidden." Elaborating on this idea, he asserted that strong countries would not use the same approach against weak countries because "strong countries make the rules while rising ones break them and exploit loopholes . . .The United States breaks [UN rules] and makes new ones when these rules don't suit [its purposes], but it has to observe its own rules or the whole world will not trust it." (see FBIS translation of the interview, OW2807114599) [End FBIS Editor's Note]


Everyone who has lived through the last decade of the 20th century will have a profound sense of the changes in the world. We don't believe that there is anyone who would claim that there has been any decade in history in which the changes have been greater than those of this decade. Naturally, the causes behind the enormous changes are too numerous to mention, but there are only a few reasons that people bring up repeatedly. One of those is the Gulf War. One war changed the world. Linking such a conclusion to a war which occurred one time in a limited area and which only lasted 42 days seems like something of an exaggeration. However, that is indeed what the facts are, and there is no need to enumerate one by one all the new words that began to appear after 17 January 1991. It is only necessary to cite the former Soviet Union, Bosnia-Herzegovina, Kosovo, cloning, Microsoft, hackers, the Internet, the Southeast Asian financial crisis, the euro, as well as the world's final and only superpower -- the United States. These are sufficient. They pretty much constitute the main subjects on this planet for the past decade

War in the age of technological integration and globalization has eliminated the right of weapons to label war and, with regard to the new starting point, has realigned the relationship of weapons to war, while the appearance of weapons of new concepts, and particularly new concepts of weapons, has gradually blurred the face of war. Does a single "hacker" attack count as a hostile act or not? Can using financial instruments to destroy a country's economy be seen as a battle? Did CNN's broadcast of an exposed corpse of a U.S. soldier in the streets of Mogadishu shake the determination of the Americans to act as the world's policeman, thereby altering the world's strategic situation? And should an assessment of wartime actions look at the means or the results? Obviously, proceeding with the traditional definition of war in mind, there is no longer any way to answer the above questions. When we suddenly realize that all these non-war actions may be the new factors constituting future warfare, we have to come up with a new name for this new form of war: Warfare which transcends all boundaries and limits, in short: unrestricted warfare.

Mao Zedong's theory concerning "every citizen a soldier" has certainly not been in any way responsible for this tendency. The current trend does not demand extensive mobilization of the people. Quite the contrary, it merely indicates that a technological elite among the citizenry have broken down the door and barged in uninvited, making it impossible for professional soldiers with their concepts of professionalized warfare to ignore challenges that are somewhat embarrassing. Who is most likely to become the leading protagonist on the terra incognita of the next war? The first challenger to have appeared, and the most famous, is the computer "hacker." This chap, who generally has not received any military training or been engaged in any military profession, can easily impair the security of an army or a nation in a major way by simply relying on his personal technical expertise. A classic example is given in the U.S. FM100-6 Information Operations regulations. In 1994, a computer hacker in England attacked the U.S. military's Rome Air Development Center in New York State, compromising the security of 30 systems. He also hacked into more than 100 other 46 systems. The Korea Atomic Energy Research Institute (KAERI) and NASA suffered damage, among others. What astounded people was not only the scale of those affected by the attack and the magnitude of the damage, but also the fact that the hacker was actually a teenager who was merely 16 years old. Naturally, an intrusion by a teenager playing a game cannot be regarded as an act of war. The problem is, how does one know for certain which damage is the result of games and which damage is the result of warfare? Which acts are individual acts by citizens and which acts represent hostile actions by non-professional warriors, or perhaps even organized hacker warfare launched by a state? In 1994, there were 230,000 security-related intrusions into U.S. DOD networks. How many of these were organized destructive acts by non-professional warriors? Perhaps there will never be any way of knowing [see Endnote 7].

More murderous than hackers--and more of a threat in the real world--are the non-state organizations, whose very mention causes the Western world to shake in its boots. These organizations, which all have a certain military flavor to a greater or lesser degree, are generally driven by some extreme creed or cause, such as: the Islamic organizations pursuing a holy war; the Caucasian militias in the U.S.; the Japanese Aum Shinrikyo cult; and, most recently, terrorist groups like Osama bin Ladin's, which blew up the U.S. embassies in Kenya and Tanzania. The various and sundry monstrous and virtually insane destructive acts by these kinds of groups are undoubtedly more likely to be the new breeding ground for contemporary wars than is the behavior of the lone ranger hacker. Moreover, when a nation state or national armed force, (which adheres to certain rules and will only use limited force to obtain a limited goal), faces off with one of these types of organizations, (which never observe any rules and which are not afraid to fight an unlimited war using unlimited means), it will often prove very difficult for the nation state or national armed force to gain the upper hand.



During the 1990's, and concurrent with the series of military actions launched by nonprofessional warriors and non-state organizations, we began to get an inkling of a non-military type of war which is prosecuted by yet another type of non-professional warrior. This person is not a hacker in the general sense of the term, and also is not a member of a quasi-military organization. Perhaps he or she is a systems analyst or a software engineer, or a financier with a 48 large amount of mobile capital or a stock speculator. He or she might even perhaps be a media mogul who controls a wide variety of media, a famous columnist or the host of a TV program. His or her philosophy of life is different from that of certain blind and inhuman terrorists. Frequently, he or she has a firmly held philosophy of life and his or her faith is by no means inferior to Osama bin Ladin's in terms of its fanaticism. Moreover, he or she does not lack the motivation or courage to enter a fight as necessary. Judging by this kind of standard, who can say that George Soros is not a financial terrorist? Precisely in the same way that modern technology is changing weapons and the battlefield, it is also at the same time blurring the concept of who the war participants are. From now on, soldiers no longer have a monopoly on war. Global terrorist activity is one of the by-products of the globalization trend that has been ushered in by technological integration. Non-professional warriors and non-state organizations are posing a greater and greater threat to sovereign nations, making these warriors and organizations more and more serious adversaries for every professional army. Compared to these adversaries, professional armies are like gigantic dinosaurs which lack strength commensurate to their size in this new age. Their adversaries, then, are rodents with great powers of survival, which can use their sharp teeth to torment the better part of the world.


With a series of major hacks, China builds a database on Americans


By Ellen Nakashima June 5 at 5:55 PM  
China is building massive databases of Americans’ personal information by hacking government agencies and U.S. health-care companies, using a high-tech tactic to achieve an age-old goal of espionage: recruiting spies or gaining more information on an adversary, U.S. officials and analysts say.
Groups of hackers working for the Chinese government have compromised the networks of the Office of Personnel Management, which holds data on millions of current and former federal employees, as well as the health insurance giant Anthem, among other targets, the officials and researchers said.
“They’re definitely going after quite a bit of personnel information,” said Rich Barger, chief intelligence officer of ThreatConnect, a Northern Virginia cybersecurity firm. “We suspect they’re using it to understand more about who to target [for espionage], whether electronically or via human ­recruitment.”
The targeting of large-scale data­bases is a relatively new tactic and is used by the Chinese government to further its ­intelligence-gathering, the officials and analysts say. It is government espionage, not commercial espionage, they say.
(Continued at the link below)



Saturday, January 25, 2014

SecDef Should Crack Whip On Cyber, Drones, & Training Foreigners

Sydney analyzes the just released CNAS report on roles and missions by the their active duty military fellows.  I think it is worth reading and debating.  I have one comment to offer on Sydney's analysis and "competition" (Sydney's word) between the Army, Marine Corps, and SOF in Phase Zero operations.  Excerpt:

So-called Phase Zero Operations, in which US troops train foreign forces, conduct exercises with them, and even quietly help them secure their countries. Historically, Special Operations Forces did the small-scale, low-profile, long-term work in the shadows, while the four services occasionally showed up for big high-profile exercises. But after 9/11, the “Big Army” andMarine Corps both had to build up Afghan and Iraqi forces, expertise they don’t want to lose. Now now they are to some extent competing (my word, not the authors’) with each other and with SOCOM for Phase 0 business around the world, especially in the high-profile Pacific“The Department of Defense needs to provide the services guidance on their primary mission responsibilities in Phase 0 operations,” the four officer write, “instead of letting the services make their own decision about the force size and mix required.”

What is really required is simply to use the right forces for the right missions.  The Army, Marine Corps, and SOF are different forces with different capabilities (and as an old boss used to say "jointness does not equal sameness" - our joint force is better by having the right mix of different capabilities rather than trying to make the organizations that make up the joint force the same or do the same things, but I digress).  While DOD does need to provide service guidance what is really necessary to prevent "competition" (which of course is not always bad but in this case might lead to redundancy vice efficiency among capabilities) is a comprehensive strategy with supporting campaign plans that will determine the right mix of capabilities and forces to support the strategy.  i think the DOD guidance will end up being focused on force structure and budget with "competition" to employ their capabilities in support of the geographic combatant commands in order to justify their force structure and share of the resource pie.  In effect there is a lot of push, but is there a real pull from the combatant commands and the chiefs of mission for these capabilities?  Again more fundamentally, are we developing a comprehensive national strategy and regional campaign plans and country team mission strategic plans that will call for and then orchestrate the right service capabilities to accomplish the required ends of the strategy?
V/R
Dave


A Croatian soldier and a Minnesota National Guardsman train together for Afghanistan.
A Croatian soldier and a Minnesota National Guardsman train together for Afghanistan.
Yesterday, four mid-grade military officers — one from each armed service – made a remarkable public recommendation to their boss, Secretary of Defense Chuck Hagel: It’s time to force the four services back into clearly demarcated “lanes” and reduce overlap between them as budgets shrink and competition escalates. They focused on three high-priority areas:
  1. Cybersecurity, the one area of the budget that’s actually growing. As a result, all four services are training “cyber warriors” and creating “cyber” units — but with no clear guidance from the Defense Department on which service should specialize in what, so everyone is doing a bit of everything. “The services risk building similar capabilities in different ways to conduct the same mission,” the co-authors write, “[with] significant duplication and overlap.” Their (tentative) solution: take away some of the services’ authority to “train, equip, and organize” cybersecurity personnel and give it to the interservice Cyber Command. That step would raise CYBERCOM to a status currently enjoyed only by Special Operations Command (SOCOM), halfway to being a full-scale independent service.
  2. Drones, aka “unmanned aircraft systems” (UAS). “Currently,” they write, “the four services are developing 15 separate UAS platforms of varying weights, speeds and altitudes” (see exhibits 123, and 4), as well as “42 separate UAS payload development programs… [and] 13 ground control stations.” While they stop short of a specific recommendation here, the co-authors do note regretfully  that the current UAS Task Force lacks “authority over the services for programmatic consolidation or termination.” (Hint, hint?) They also speak approvingly of the much-derided 1947 Key West agreement, which among other things defined what kind of (manned) aircraft each service could fly.
(Continued at the link below)

Friday, October 25, 2013

People, Cyber & Dirt: Army & SOCOM’s ‘Strategic Landpower’

Excerpts:

“People have to live somewhere and that somewhere to them is important[:] The land has historical and cultural significance, strategic value,” McRaven said. “If we forget that, then geography will have its revenge.”
But Odierno’s full argument, which was backed up forcefully by McRaven, is considerably subtler and more interesting. “There are three things that I think intersect,” Odierno said. “I’m not sure quite how they intersect yet – what it means tactically, operationally, and strategically,” he added with his typical frankness, “but I know they are intersecting”: human beings, the online world in which humans increasingly interact with one another, and the physical terrain on which they live.

I think if you add GEN Odierno's comments on cyber to this definition of MIlitary Geography perhaps people would see the relevance of geography and would spend some more time studying military geography as part of professional military education.

Military Geography is the study of the linkages between humans and the natural and cultural landscape insofar as it pertains to the employment of military force.”
--Peltier and Pearcy, 1966

Or you can turn to John Collins' book Military Geography for a more detailed description:

WEBSTER'S THIRD NEW INTERNATIONAL DICTIONARY DEFINES GEOGRAPHY AS "A SCIENCE THAT DEALS WITH 

the Earth and its life; especially the description of land, sea, air, and the distribution of plant and animal life including man and his industries with reference to the mutual relations of these diverse elements." The next edition likely will add space to the list. Geography consequently embraces a spectrum of physical and social sciences from agronomy to zoology. In simple terms, it describes what the environment is like at any given place and time. 

MILITARY CONSIDERATIONS 

Military geography, one of several subsets within those broad confines, concentrates on the influence of physical and cultural environments over political-military policies, plans, programs, and combat/support operations of all types in global, regional, and local contexts. Key factors displayed in table 1 directly (sometimes decisively) affect the full range of military  activities: strategies, tactics, and doctrines; command, control, and organizational structures; the optimum mix of land, sea, air, and space forces; intelligence collection; targeting; research and development; the procurement and allocation of weapons, equipment, and clothing; plus supply, maintenance, construction, medical support, education, and training.

I wish the Admiral had clarified this statement with the fact that SOF (and most specifically ROK SOF with US assistance) will have a major role in north Korea during war or regime collapse.  There will be a huge need for that connective tissue that SOF can provide in north Korea:

“I see SOF as the connective tissue between the populations and the conventional forces,” McRaven went on. It’s the regular Army and Marine Corps units that have the numbers, firepower, and logistics to seize and defend terrain. “SOF’s never going to stop the North Koreans from going south,” McRaven said. “We can’t keep the Strait of Hormuz open. We can’t conduct an opposed landing. We can’t bring a nation to its knees; but we can shape the outcome of the fight well before the battle begins by knowing and influencing the populations in Phase 1, and, once the fight starts, we can provide insights that will place the right force in the right place at the right time.”

But the Admiral does give the right cautionary note to policy makers and strategists who would place too much emphasis on SOF as the silver bullet because it is not.

But also important is this statement from a friend and former director of SAMS:
And, if you really think it through human, cyber, land translates into moral, mental, physical, which backs us into the Clausewitzian Trinity. Funny how everything ties up into a nice little package

People, Cyber & Dirt: Army & SOCOM’s ‘Strategic Landpower’

By  on October 24, 2013 at 6:42 PM
army-cybersecurity-fort-dix
AUSA: The word “cyber” is everywhere these days. It’s an all-purpose adjective slapped onto any concept to attract money and make it sound sexier, from cyberwar tocyberschoolbus to, well, cybersex. (We are not making that last term a link). Cyber and SOF – the Special Operations Forces – are the only parts of the Pentagon budget that keep growing while everything else shrinks. But there’s a dirty little secret about cyber, one that the leaders of the Army, the Marine Corps, and special operators have seized on as essential to keeping old-fashioned ground troops relevant in the information age.
So what’s the secret? We all know that more and more of our lives – from banking to buying books, from sharing recipes to managing the electrical grid – now happen in cyberspace. But what most people don’t realize is that cyberspace itself isn’t in cyberspace. Everything “cyber” – every email, every online bank account, every 90th level Tauren Druid, every streaming video from PornTube or a Predator drone – is composed of zeroes and ones that physically exist somewhere: as radio waves rippling invisibly through the air over a wireless network, as pulses of light in a fiber optic cable running under the sea, or, most often, as electrical impulses in a tiny transistor in a computer.
Guess where most of those components are physically located? On land. Guess where all the human beings who use cyberspace, from hackers to housewives, actually live? They’re on land.
“The enemy’s will, that ultimate center of gravity, remains tied to the ground upon which he sits, upon which he blogs, and to the dirt under his feet,” said Adm. William McRaven, the Navy SEAL who heads Special Operations Command (SOCOM), speaking Wednesday at the Association of the Army’s annual conference here. “We can launch a hundred TLAMs [Tomahawk Land Attack Missiles], a thousand TLAMS, and I’m not sure that’s going to fundamentally change the enemy’s will,” McRaven said.
Cyberspace operations don’t eliminate the need for ground troops any more than precision-guided missiles do, the admiral went on. In a whirlwind tour of Robert Kaplan’s book The Revenge of Geography – as well as Carl von Clausewitz, Alfred Thayer Mahan, and Giulio Douhet, the three seminal theorists of land, sea, and air warfare respectively – McRaven warned: “Some of the strategists, some of the futurists, want to point to the importance of the social media and the blogosphere and the self-synchronizing organizations” – for example, the Twitter-coordinated protests of the Arab Spring –  ”but the fact is geography, terrain, matters.”
“People have to live somewhere and that somewhere to them is important[:] The land has historical and cultural significance, strategic value,” McRaven said. “If we forget that, then geography will have its revenge.”
The Navy admiral was speaking to an Army conference because SOCOM has joined a tri-service initiative called “Strategic Landpower.” Alongside him on the panel were the relatively quiet assistant Commandant of the Marine Corps, Gen. John Paxton (the Commandant, Gen. James Amos, was at a 30th anniversary memorial of the 1983 bombing of the Marine barracks in Beirut) and the Army’s passionately voluble Chief of Staff, Gen. Ray Odierno.
Most of the limited media coverage of the event, including the official Army News Service story, emphasized Odierno’s shot across the bow of those who would slash old-fashioned ground forces to free up funds for air, sea, space, and cyber. “There are a lot of intellectuals out there who believe land power is obsolete,” he said. “It is naïve and in fact, in my mind, it is a dangerous thought.” US News even headlined its story “Army Chief Chafes at New Reliance on Technology.”
But Odierno’s full argument, which was backed up forcefully by McRaven, is considerably subtler and more interesting. “There are three things that I think intersect,” Odierno said. “I’m not sure quite how they intersect yet – what it means tactically, operationally, and strategically,” he added with his typical frankness, “but I know they are intersecting”: human beings, the online world in which humans increasingly interact with one another, and the physical terrain on which they live.
“The intersection of land domain, the human domain, and the cyber domain in the future is really important for us to be successful in the future security environment,” Odierno lamented, “and yet nobody wants to talk about it.”
Information technology is changing that security environment in ways that go far beyond precision-guided missiles and command-and-control networks. When I first went into Iraq [in 2003], I don’t know the exact number, but there was like a thousand cell phones in Iraq, and that was all in the leadership of Iraq,” Odierno said. “When we left [in 2011], there was millions and millions.”
(Continued at the link below)

Sunday, July 14, 2013

Nations Buying as Hackers Sell Flaws in Computer Code

We live in a (brave?) New World and we are going to have to learn to live with the full realization that we are all vulnerable (as a nation, as businesses, as individuals).  Although I think we do have to worry about our 4th Amendment Rights in our country (and our political process needs to properly work out what needs to evolve with the great American experiment in Democracy based on the conditions as the exist today) I think we face far greater threats from outside entities (organizations and nation-states) than we do from our own government.  As those who take up Snowden's and Greenwlad's cause and will focus on the US government, all these other countries and organizations that are developing cyber capabilities are being given a free pass and enjoying the show as American feeds on the Snowden and Greenwald case with the possible result that the US will neuter its security capabilities.  At the same time others will continue to develop the capabilities to exploit Americans economically and financially, influence American opinion, and develop the capability to attack US infrastructure that is undefended or under defended.  Yes, I know I sound like Chicken Little and I will be very happy to be proven wrong and  learn that the sky is not falling but from an enemy perspective the best way to attack America is to create the conditions for America to attack itself from within and I believe that Snowden has contributed to that attack.

(note:  of course not every country listed below is hostile to the US and obviously some are allies.  What I think may be different is that all these nations are taking steps to develop offensive and defensive capabilities to survive and even thrive in this New World while the US succumbs to internal controversy and stifles its own ability to operate in the New World.  Again, I think we need to work out the 4th Amendment issues but that should be done through our political process and not have the debate controlled by the likes of Snowden and Greenwald – And from now on I intend to use Snowden and Greenwald in tandem in all my comments because Greenwald has chosen to make him part of the story and he is aiding and abetting Snowden particular through his communication of threats against the US).
V/R
Dave

July 13, 2013

Nations Buying as Hackers Sell Flaws in Computer Code



On the tiny Mediterranean island of Malta, two Italian hackers have been searching for bugs — not the island’s many beetle varieties, but secret flaws in computer code that governments pay hundreds of thousands of dollars to learn about and exploit.

The hackers, Luigi Auriemma, 32, and Donato Ferrante, 28, sell technical details of such vulnerabilities to countries that want to break into the computer systems of foreign adversaries. The two will not reveal the clients of their company, ReVuln, but big buyers of services like theirs include the National Security Agency — which seeks the flaws for America’s growing arsenal of cyberweapons — and American adversaries like the Revolutionary Guards of Iran.

All over the world, from South Africa to South Korea, business is booming in what hackers call “zero days,” the coding flaws in software like Microsoft Windows that can give a buyer unfettered access to a computer and any business, agency or individual dependent on one.

Just a few years ago, hackers like Mr. Auriemma and Mr. Ferrante would have sold the knowledge of coding flaws to companies like Microsoft and Apple, which would fix them. Last month, Microsoft sharply increased the amount it was willing to pay for such flaws, raising its top offer to $150,000.
But increasingly the businesses are being outbid by countries with the goal of exploiting the flaws in pursuit of the kind of success, albeit temporary, that the United States and Israel achieved three summers ago when they attacked Iran’s nuclear enrichment program with a computer worm that became known as “Stuxnet.”

The flaws get their name from the fact that once discovered, “zero days” exist for the user of the computer system to fix them before hackers can take advantage of the vulnerability. A “zero-day exploit” occurs when hackers or governments strike by using the flaw before anyone else knows it exists, like a burglar who finds, after months of probing, that there is a previously undiscovered way to break into a house without sounding an alarm.

“Governments are starting to say, ‘In order to best protect my country, I need to find vulnerabilities in other countries,’ ” said Howard Schmidt, a former White House cybersecurity coordinator. “The problem is that we all fundamentally become less secure.”

A zero-day bug could be as simple as a hacker’s discovering an online account that asks for a password but does not actually require typing one to get in. Bypassing the system by hitting the “Enter” key becomes a zero-day exploit. The average attack persists for almost a year — 312 days — before it is detected, according to Symantec, the maker of antivirus software. Until then it can be exploited or “weaponized” by both criminals and governments to spy on, steal from or attack their target.


Ten years ago, hackers would hand knowledge of such flaws to Microsoft and Google free, in exchange for a T-shirt or perhaps for an honorable mention on a company’s Web site. Even today, so-called patriotic hackers in China regularly hand over the information to the government.
(Continued at the link below)

Friday, June 21, 2013

The New Triad (SOF, UAS, Cyber)

For all SSP Students:  There are probably more thesis research topics in this short article than you will find on any topic list.

V/R
Dave


It's time to found a U.S. Cyber Force.

BY JAMES STAVRIDIS | JUNE 20, 2013

Throughout the long decades of my military career, the backbone of U.S. national security was the "strategic triad" of delivery systems for nuclear weapons: ballistic-missile submarines and their associated nuclear-tipped missiles, land-based intercontinental ballistic missiles operated from silos deep in the earth, and long-range manned bombers, which could deliver nuclear bombs and eventually nuclear-tipped cruise missiles.

America's reliance on this Cold War triad continues through the present day, though the systems have changed somewhat as a result of both advances in technology and changes in treaty limits, most recently reflected in the New START treaty.

As we sail more deeply into the turbulent 21st century, however, there is another triad that bears considering that will be a critical part of U.S. security in the decades to come. This new triad will be far less abstract and hidden-away than the Cold War strategic triad and much more frequently employed -- often in kinetic ways.

This "New Triad" consists of special operations forces, unmanned vehicles, and cybercapabilities. Each has an important individual role to play, but taken together, the sum of their impacts will be far greater than that of each of the parts when used alone.

First, consider special operations forces, or SOF. They have become a tool of choice in a wide variety of actions in today's world, from the spectacular mission that finally killed Osama bin Laden to training African partners to thwart the brutal Lord's Resistance Army in Africa, and from helping Colombian forces fight the FARC insurgency in Latin America to providing security for disaster relief operations in Pakistan.

Today's SOF are capable of operating across the entire spectrum of operations, from soft power and training to the ultimate "red dots on foreheads" missions epitomized by the killing of bin Laden and popularized by film and television.

Because they are trained in languages, cultural mores, high-tech communications, medicine, concealment, and many other discrete skills, they can operate in the widest imaginable variety of geographical settings. They are also small in number, highly motivated, and relatively cost-effective. They are generally precision-guided in their approach, can limit collateral damage, and blend in when needed.

The second capability in the New Triad is unmanned vehicles and sensors.
(Continued at the link below)


Monday, January 14, 2013

Cybersleuths Uncover 5-Year Spy Operation Targeting Governments, Others



I think one of the interesting things about the graphic in the article are the countries that were supposedly not attacked (not just the obvious one of China).
V/R
Dave

Cybersleuths Uncover 5-Year Spy Operation Targeting Governments, Others
Map showing the location and industry of victims in 69 countries hit by the spy operation. Courtesy of Kaspersky Lab

An advanced and well-orchestrated computer spy operation that targeted diplomats, governments and research institutions for at least five years has been uncovered by security researchers in Russia.
The highly targeted campaign, which focuses primarily on victims in Eastern Europe and Central Asia based on existing data, is still live, harvesting documents and data from computers, smartphones and removable storage devices, such as USB sticks, according to Kaspersky Lab, the Moscow-based antivirus firm that uncovered the campaign. Kaspersky has dubbed the operation “Red October.”

While most of the victims documented are in Eastern Europe or Central Asia, targets have been hit in 69 countries in total, including the U.S., Australia, Ireland, Switzerland, Belgium, Brazil, Spain, South Africa, Japan and the United Arab Emirates. Kaspersky calls the victims “high profile,” but declined to identify them other than to note that they’re government agencies and embassies, institutions involved in nuclear and energy research and companies in the oil and gas and aerospace industries.

“The main purpose of the operation appears to be the gathering of classified information and geopolitical intelligence, although it seems that the information-gathering scope is quite wide,” Kaspersky notes in a report released Monday. “During the past five years, the attackers collected information from hundreds of high-profile victims, although it’s unknown how the information was used.”
(Continued at the link below)

Giving Tuesday Recommendations

  Dear Friends,  I do not normally do this (except I did this last year and for the last few years now, too) and I certainly do not mean to ...