Showing posts with label Cyberattacks. Show all posts
Showing posts with label Cyberattacks. Show all posts

Saturday, June 6, 2015

With a series of major hacks, China builds a database on Americans

You can access an original translation of Unrestricted Warfare here: https://www.dropbox.com/s/llltfszyecpj6s6/UnrestrictedWarfare.pdf?dl=0

As you read about the Chinese hack of OPM and over 4 million government employees I think it is worth reflecting on these excerpts from the 1999 book by Chinese PLA Colonels, Unrestricted Warfare.  This is from the first FBIS translation of the book that I have saved over all these years.  Of course you can also buy a commercial copy of the book from Amazon.  I wonder how many people have read these prescient words.  Please pay attention to the highlighted words.  I know many have criticized this book and those who read it and in 2004 when I was a student at the National War College I asked the visiting Chinese Defense Minister if this book was being used to inform Chinese doctrine and strategic thinking he replied that the book had bene discredited in China and for me not to believe everything I read. (though I am violating the non-attribution rule - but I will take my lumps for that when compared to what the Chinese have done to us).  So while we applaud Snowden (and he applauds himself) for defending our privacy from the NSA who is protecting not only our privacy but our national security from the Chinese?


[FBIS Editor's Note: The following selections are taken from "Unrestricted Warfare," a book published in China in February 1999 which proposes tactics for developing countries, in particular China, to compensate for their military inferiority vis-à-vis the United States during a high-tech war. The selections include the table of contents, preface, afterword, and biographical information about the authors printed on the cover. The book was written by two PLA senior colonels from the younger generation of Chinese military officers and was published by the PLA Literature and Arts Publishing House in Beijing, suggesting that its release was endorsed by at least some elements of the PLA leadership. This impression was reinforced by an interview with Qiao and laudatory review of the book carried by the party youth league's official daily Zhongguo Qingnian Bao on 28 June. Published prior to the bombing of China's embassy in Belgrade, the book has recently drawn the attention of both the Chinese and Western press for its advocacy of a multitude of means, both military and particularly non-military, to strike at the United States during times of conflict. Hacking into websites, targeting financial institutions, terrorism, using the media, and conducting urban warfare are among the methods proposed. In the Zhongguo Qingnian Bao interview, Qiao was quoted as stating that "the first rule of unrestricted warfare is that there are no rules, with nothing forbidden." Elaborating on this idea, he asserted that strong countries would not use the same approach against weak countries because "strong countries make the rules while rising ones break them and exploit loopholes . . .The United States breaks [UN rules] and makes new ones when these rules don't suit [its purposes], but it has to observe its own rules or the whole world will not trust it." (see FBIS translation of the interview, OW2807114599) [End FBIS Editor's Note]


Everyone who has lived through the last decade of the 20th century will have a profound sense of the changes in the world. We don't believe that there is anyone who would claim that there has been any decade in history in which the changes have been greater than those of this decade. Naturally, the causes behind the enormous changes are too numerous to mention, but there are only a few reasons that people bring up repeatedly. One of those is the Gulf War. One war changed the world. Linking such a conclusion to a war which occurred one time in a limited area and which only lasted 42 days seems like something of an exaggeration. However, that is indeed what the facts are, and there is no need to enumerate one by one all the new words that began to appear after 17 January 1991. It is only necessary to cite the former Soviet Union, Bosnia-Herzegovina, Kosovo, cloning, Microsoft, hackers, the Internet, the Southeast Asian financial crisis, the euro, as well as the world's final and only superpower -- the United States. These are sufficient. They pretty much constitute the main subjects on this planet for the past decade

War in the age of technological integration and globalization has eliminated the right of weapons to label war and, with regard to the new starting point, has realigned the relationship of weapons to war, while the appearance of weapons of new concepts, and particularly new concepts of weapons, has gradually blurred the face of war. Does a single "hacker" attack count as a hostile act or not? Can using financial instruments to destroy a country's economy be seen as a battle? Did CNN's broadcast of an exposed corpse of a U.S. soldier in the streets of Mogadishu shake the determination of the Americans to act as the world's policeman, thereby altering the world's strategic situation? And should an assessment of wartime actions look at the means or the results? Obviously, proceeding with the traditional definition of war in mind, there is no longer any way to answer the above questions. When we suddenly realize that all these non-war actions may be the new factors constituting future warfare, we have to come up with a new name for this new form of war: Warfare which transcends all boundaries and limits, in short: unrestricted warfare.

Mao Zedong's theory concerning "every citizen a soldier" has certainly not been in any way responsible for this tendency. The current trend does not demand extensive mobilization of the people. Quite the contrary, it merely indicates that a technological elite among the citizenry have broken down the door and barged in uninvited, making it impossible for professional soldiers with their concepts of professionalized warfare to ignore challenges that are somewhat embarrassing. Who is most likely to become the leading protagonist on the terra incognita of the next war? The first challenger to have appeared, and the most famous, is the computer "hacker." This chap, who generally has not received any military training or been engaged in any military profession, can easily impair the security of an army or a nation in a major way by simply relying on his personal technical expertise. A classic example is given in the U.S. FM100-6 Information Operations regulations. In 1994, a computer hacker in England attacked the U.S. military's Rome Air Development Center in New York State, compromising the security of 30 systems. He also hacked into more than 100 other 46 systems. The Korea Atomic Energy Research Institute (KAERI) and NASA suffered damage, among others. What astounded people was not only the scale of those affected by the attack and the magnitude of the damage, but also the fact that the hacker was actually a teenager who was merely 16 years old. Naturally, an intrusion by a teenager playing a game cannot be regarded as an act of war. The problem is, how does one know for certain which damage is the result of games and which damage is the result of warfare? Which acts are individual acts by citizens and which acts represent hostile actions by non-professional warriors, or perhaps even organized hacker warfare launched by a state? In 1994, there were 230,000 security-related intrusions into U.S. DOD networks. How many of these were organized destructive acts by non-professional warriors? Perhaps there will never be any way of knowing [see Endnote 7].

More murderous than hackers--and more of a threat in the real world--are the non-state organizations, whose very mention causes the Western world to shake in its boots. These organizations, which all have a certain military flavor to a greater or lesser degree, are generally driven by some extreme creed or cause, such as: the Islamic organizations pursuing a holy war; the Caucasian militias in the U.S.; the Japanese Aum Shinrikyo cult; and, most recently, terrorist groups like Osama bin Ladin's, which blew up the U.S. embassies in Kenya and Tanzania. The various and sundry monstrous and virtually insane destructive acts by these kinds of groups are undoubtedly more likely to be the new breeding ground for contemporary wars than is the behavior of the lone ranger hacker. Moreover, when a nation state or national armed force, (which adheres to certain rules and will only use limited force to obtain a limited goal), faces off with one of these types of organizations, (which never observe any rules and which are not afraid to fight an unlimited war using unlimited means), it will often prove very difficult for the nation state or national armed force to gain the upper hand.



During the 1990's, and concurrent with the series of military actions launched by nonprofessional warriors and non-state organizations, we began to get an inkling of a non-military type of war which is prosecuted by yet another type of non-professional warrior. This person is not a hacker in the general sense of the term, and also is not a member of a quasi-military organization. Perhaps he or she is a systems analyst or a software engineer, or a financier with a 48 large amount of mobile capital or a stock speculator. He or she might even perhaps be a media mogul who controls a wide variety of media, a famous columnist or the host of a TV program. His or her philosophy of life is different from that of certain blind and inhuman terrorists. Frequently, he or she has a firmly held philosophy of life and his or her faith is by no means inferior to Osama bin Ladin's in terms of its fanaticism. Moreover, he or she does not lack the motivation or courage to enter a fight as necessary. Judging by this kind of standard, who can say that George Soros is not a financial terrorist? Precisely in the same way that modern technology is changing weapons and the battlefield, it is also at the same time blurring the concept of who the war participants are. From now on, soldiers no longer have a monopoly on war. Global terrorist activity is one of the by-products of the globalization trend that has been ushered in by technological integration. Non-professional warriors and non-state organizations are posing a greater and greater threat to sovereign nations, making these warriors and organizations more and more serious adversaries for every professional army. Compared to these adversaries, professional armies are like gigantic dinosaurs which lack strength commensurate to their size in this new age. Their adversaries, then, are rodents with great powers of survival, which can use their sharp teeth to torment the better part of the world.


With a series of major hacks, China builds a database on Americans


By Ellen Nakashima June 5 at 5:55 PM  
China is building massive databases of Americans’ personal information by hacking government agencies and U.S. health-care companies, using a high-tech tactic to achieve an age-old goal of espionage: recruiting spies or gaining more information on an adversary, U.S. officials and analysts say.
Groups of hackers working for the Chinese government have compromised the networks of the Office of Personnel Management, which holds data on millions of current and former federal employees, as well as the health insurance giant Anthem, among other targets, the officials and researchers said.
“They’re definitely going after quite a bit of personnel information,” said Rich Barger, chief intelligence officer of ThreatConnect, a Northern Virginia cybersecurity firm. “We suspect they’re using it to understand more about who to target [for espionage], whether electronically or via human ­recruitment.”
The targeting of large-scale data­bases is a relatively new tactic and is used by the Chinese government to further its ­intelligence-gathering, the officials and analysts say. It is government espionage, not commercial espionage, they say.
(Continued at the link below)



Saturday, October 19, 2013

In cyberarms race, North Korea emerging as a power, not a pushover


With all the distraction and damage caused by Snowden and Greenwald regarding the NSA it would be a real crime (which of course they have already committed) if Cyber Command was so neutered that the Chinese and north Koreans developed superior cyber capabilities that could do signification damage to us.  And I think Sasha is right here:

"Over the past four years the North has seriously intensified its cyberwarfare development efforts at South Korea's expense," says Alexandre Mansourov, a visiting scholar at the US-Korea Institute at Johns Hopkins University in Baltimore. "The [Korean People's Army] is basically planning for a future cyberwar and has been hacking to collect intelligence and prepare to disrupt information and communications, surveillance, and reconnaissance systems of its enemies: South Korea, the US, and Japan.

Just as an aside, what if the north's nuclear program is just a distraction and the real threats they are pursuing are in cyber space?  I bet theoretically at least, a comprehensive cyber attack that shuts down the US infrastructure, both utilities and financial ,might have far more devastating effects, particularly over time,  than the detonation of a nuclear device.  And I am very sure that the north has read the 1999 Chinese book on Unrestricted Warfare.
V/R
Dave

In cyberarms race, North Korea emerging as a power, not a pushover


A 4-year cyberattack-and-espionage campaign targeting key South Korean institutions suggests North Korean cyberwarfare capabilities are far more potent than previously believed.
Temp Headline Image
A Digital Forensic Investigation team entered the Cyber Terror Response Center in Seoul, South Korea in March. The team was responding to a cyberattack linked to North Korea.
(Lee Jin-man/AP)

By , Staff writer / October 19, 2013 at 11:40 am EDT

Often dismissed as a laggard in the global cyberarms race, North Korea has long been seen as a chronic cyber-superpower wannabe. Its poverty, minimal Internet access, and paucity of malicious software to its credit together have indicated that the "hermit kingdom" has just not yet arrived.

But that equation is changing. While the North's nuclear ambitions and maltreatment of its citizens absorb diplomatic bandwidth, a four-year cyberattack-and-espionage campaign targeting South Korean banks, news media, telecoms, and military think tanks has revealed North Korean cyberwarfare capabilities to be far more potent than previously believed, US experts say and new analyses show.
What's more, say American cyberwarfare and North Korea experts, the North's advancing capabilities show a dangerous potential to slide into real-world conflict.

"Over the past four years the North has seriously intensified its cyberwarfare development efforts at South Korea's expense," says Alexandre Mansourov, a visiting scholar at the US-Korea Institute at Johns Hopkins University in Baltimore. "The [Korean People's Army] is basically planning for a future cyberwar and has been hacking to collect intelligence and prepare to disrupt information and communications, surveillance, and reconnaissance systems of its enemies: South Korea, the US, and Japan."

Analyses of these attacks, while falling short of "smoking gun" proof, leave little doubt North Korea is not only behind major attacks against the South – but that its capabilities are much broader than previously believed, Dr. Mansourov and others say. As a result, these experts are boosting their estimates of the sophistication and pace of the North's cybermilitary development – and of its threat to the United States.

Most revealing is the new linkage between the North and four years of increasingly threatening attacks on South Korea, analyzed by leading cybersecurity firms in the past five months. The attacks have cost the South more than $750 million, South Korean lawmakers said this month, citing Defense Ministry data.


The first major attack, on July 4, 2009, began with a modest distributed denial-of-service (DDoS) bombardment – with millions of requests per second (tiny compared with today's attacks) clogging Korean and US government and financial websites for days. The attacks appeared to emanate from 435 different servers in 61 countries around the world – including in South Korea itself.
But a second attack on March 4, 2011, went beyond basic DDoS by launching malicious software that wiped hard drives on systems at one of the South's biggest banks, leaving 30 million customers without ATM services for days.

The picture clears

Initial investigations suggested that the North was responsible, but were ultimately inconclusive.
Clarity began to emerge this past spring following the biggest attack. It began at 2 p.m. on March 20 with several South Korean banks and media outlets hammered by a massive malware attack erupting from inside their own networks. In minutes, a cyberweapon dubbed "DarkSeoul" infected and wiped clean the critical master boot records of 32,000 computers, wrecking them and crippling those organizations for days – one of the most costly and destructive cyberattacks the world has seen.
The digital trail initially led to a cybergang called the "WhoIs Team" – its skull calling card digitally tattooed on the computer hard drives of South Korean banks. Adding to the confusion, another group – the "New Romantic Cyber Army Team" – also claimed responsibility.

But US cybersecurity company McAfee saw something else. "Operation Troy," as McAfee dubbed the attack in a June report, was actually the culmination of a "secret, long-term," and "sophisticated" four-year campaign by just one cyberattacker – not the two cybergangs.

"Operation Troy had a focus from the beginning to gather intelligence on South Korean military targets," McAfee investigators reported. "We have also linked other high-profile public campaigns conducted over the years against South Korea to Operation Troy, suggesting that a single group is responsible."

Which group? South Korean fingers jabbed at North Korea. While McAfee never publicly named a culprit, its officials said privately that Pyongyang was behind the four years of increasingly sophisticated attacks.

The McAfee analysis was not the last to track the attacks back to North Korea's doorstep. The same month, cybersecurity giant Symantec issued its own report linking the four years of cyberattacks to a single actor amid not-so-veiled references – "regardless of whether the gang is working on behalf of North Korea or not."

In September, researchers at Kaspersky Lab announced discovery of an extensive cyberespionage campaign against six South Korean military think tanks. Far from being a primitive hack, the "Kimsuky" campaign, named after a snippet of malicious code, was "extraordinary in its execution and logistics," wrote Dmitry Tarakanov, a researcher at the Moscow-based firm, who said digital tracks led to the North.
(Continued at the link below)



Sunday, July 14, 2013

Nations Buying as Hackers Sell Flaws in Computer Code

We live in a (brave?) New World and we are going to have to learn to live with the full realization that we are all vulnerable (as a nation, as businesses, as individuals).  Although I think we do have to worry about our 4th Amendment Rights in our country (and our political process needs to properly work out what needs to evolve with the great American experiment in Democracy based on the conditions as the exist today) I think we face far greater threats from outside entities (organizations and nation-states) than we do from our own government.  As those who take up Snowden's and Greenwlad's cause and will focus on the US government, all these other countries and organizations that are developing cyber capabilities are being given a free pass and enjoying the show as American feeds on the Snowden and Greenwald case with the possible result that the US will neuter its security capabilities.  At the same time others will continue to develop the capabilities to exploit Americans economically and financially, influence American opinion, and develop the capability to attack US infrastructure that is undefended or under defended.  Yes, I know I sound like Chicken Little and I will be very happy to be proven wrong and  learn that the sky is not falling but from an enemy perspective the best way to attack America is to create the conditions for America to attack itself from within and I believe that Snowden has contributed to that attack.

(note:  of course not every country listed below is hostile to the US and obviously some are allies.  What I think may be different is that all these nations are taking steps to develop offensive and defensive capabilities to survive and even thrive in this New World while the US succumbs to internal controversy and stifles its own ability to operate in the New World.  Again, I think we need to work out the 4th Amendment issues but that should be done through our political process and not have the debate controlled by the likes of Snowden and Greenwald – And from now on I intend to use Snowden and Greenwald in tandem in all my comments because Greenwald has chosen to make him part of the story and he is aiding and abetting Snowden particular through his communication of threats against the US).
V/R
Dave

July 13, 2013

Nations Buying as Hackers Sell Flaws in Computer Code



On the tiny Mediterranean island of Malta, two Italian hackers have been searching for bugs — not the island’s many beetle varieties, but secret flaws in computer code that governments pay hundreds of thousands of dollars to learn about and exploit.

The hackers, Luigi Auriemma, 32, and Donato Ferrante, 28, sell technical details of such vulnerabilities to countries that want to break into the computer systems of foreign adversaries. The two will not reveal the clients of their company, ReVuln, but big buyers of services like theirs include the National Security Agency — which seeks the flaws for America’s growing arsenal of cyberweapons — and American adversaries like the Revolutionary Guards of Iran.

All over the world, from South Africa to South Korea, business is booming in what hackers call “zero days,” the coding flaws in software like Microsoft Windows that can give a buyer unfettered access to a computer and any business, agency or individual dependent on one.

Just a few years ago, hackers like Mr. Auriemma and Mr. Ferrante would have sold the knowledge of coding flaws to companies like Microsoft and Apple, which would fix them. Last month, Microsoft sharply increased the amount it was willing to pay for such flaws, raising its top offer to $150,000.
But increasingly the businesses are being outbid by countries with the goal of exploiting the flaws in pursuit of the kind of success, albeit temporary, that the United States and Israel achieved three summers ago when they attacked Iran’s nuclear enrichment program with a computer worm that became known as “Stuxnet.”

The flaws get their name from the fact that once discovered, “zero days” exist for the user of the computer system to fix them before hackers can take advantage of the vulnerability. A “zero-day exploit” occurs when hackers or governments strike by using the flaw before anyone else knows it exists, like a burglar who finds, after months of probing, that there is a previously undiscovered way to break into a house without sounding an alarm.

“Governments are starting to say, ‘In order to best protect my country, I need to find vulnerabilities in other countries,’ ” said Howard Schmidt, a former White House cybersecurity coordinator. “The problem is that we all fundamentally become less secure.”

A zero-day bug could be as simple as a hacker’s discovering an online account that asks for a password but does not actually require typing one to get in. Bypassing the system by hitting the “Enter” key becomes a zero-day exploit. The average attack persists for almost a year — 312 days — before it is detected, according to Symantec, the maker of antivirus software. Until then it can be exploited or “weaponized” by both criminals and governments to spy on, steal from or attack their target.


Ten years ago, hackers would hand knowledge of such flaws to Microsoft and Google free, in exchange for a T-shirt or perhaps for an honorable mention on a company’s Web site. Even today, so-called patriotic hackers in China regularly hand over the information to the government.
(Continued at the link below)

Wednesday, March 20, 2013

North Korea suspected of mounting cyberattack that shuts down South Korean banks, TV stations


Just to remind ourselves of the north Korea provocation pattern, below this article I have pasted the AP article from four days ago in which the north accused the South and US of conducting cyber attacks against it.  They have constructed their self defense rationale and are now "justified" (in their minds) conducting their own cyberattacks because they can "prove" the South attacked them first.  And as an aside if we pay attention to the north's actions and rhetoric we can see that they sometimes do telegraph their punches but too often we can only see that in hindsight.
V/R
Dave

Freya PetersenMarch 20, 2013 05:56

Follow


North Korea suspected of mounting cyberattack that shuts down South Korean banks, TV stations

South Korean police are investigating a possible hacking incident from North Korea on Wednesday as banks and TV stations experience power outages.


A possible cyberattack has shut down South Korean banks and TV stations with suspicions falling on North Korea after an escalation of rhetoric between Seoul and Pyongyang.

Screens went blank at 2 p.m. local time and skulls popped up on the screens, indicating a breach by hackers, the Associated Press wrote, citing the state-run Korea Information Security Agency.
TV stations KBS and MBC and cable channel YTN and two major banks, Shinhan Bank and Nonghyup, were paralyzed, according to reports.

The government, military and nuclear power plants appear to have been spared,The New York Times wrote.

South Korea's Defense Minister Kim Kwan-jin called an emergency security meeting to review the military's five-tier threat level system, designed to defend against a cyberattack, from Level 4 to Level 3, Yonhap wrote.

A ministry spokesman said:

"Currently, the military network is operating normally. There were no [hacking] attempts from outside."
While the National Intelligence Service was still investigating the outage and was yet to find any evidence of external attacks, speculation in local media was that North Korea had fired the last salvo in a tit-for-tat exchange in a cyber war.

North Korea recently accused South Korea and the US of attacking its state websites.
The Korean Central News Agency (KCNA) claimed last week that several official websites, including its own and those of state newspaper the Rodong Sinmun and national airline Air Koryo, had suffered disruption.
Continued at the link below)

North Korea accuses US, South Korea of waging cyberattack; expert says China is likely culprit

By Associated PressPublished: March 15
SEOUL, South Korea — North Korea on Friday blamed South Korea and the United States for cyberattacks that temporarily shut down websites this week at a time of elevated tensions over the North’s nuclear ambitions. Experts, however, indicated it could take months to determine what happened and one analyst suggested hackers in China were a more likely culprit.

Internet access in Pyongyang was intermittent on Wednesday and Thursday, and Loxley Pacific Co., the broadband Internet provider for North Korea, said it was investigating an online attack that took down Pyongyang servers. A spokesman for the Bangkok-based company said Friday that it was not clear where the attack originated.


North Korea’s official Korean Central News Agency blamed the shutdown on the United States and South Korea, accusing the allies of expanding an aggressive stance against Pyongyang into cyberspace with “intensive and persistent virus attacks.”

South Korea denied the allegation and the U.S. military declined to comment.

Loxley Pacific, which has provided broadband Internet service in North Korea through a joint venture with the government since 2010, said the Internet was back to normal Friday. AP journalists in Pyongyang also were able to access the Internet again Friday after two days of disruptions. Most North Koreans do not have access to the Internet, which remains restricted to a select group.
(Continued at the link below)

Giving Tuesday Recommendations

  Dear Friends,  I do not normally do this (except I did this last year and for the last few years now, too) and I certainly do not mean to ...