Showing posts with label DHS. Show all posts
Showing posts with label DHS. Show all posts

Friday, May 18, 2012

Multi-Layered Counterterror Defenses Generally Work Well, Former NCTC Director Argues

- LIMITED DISSEMINATION

HSToday.us; US/1; ATTN:
 
Partners in Pre-ANTI-CRIMEBy: Mickey McCarter
05/17/2012 ( 8:30am)

Multi-layered counterterrorism defenses have safeguarded Americans more than generally acknowledged, particularly as they have deterred individual terrorists from carrying out catastrophic attacks on US soil, argued the former director of the National Counterterrorism Center (NCTC) Wednesday.

Speaking at the Counter Terror Expo in Washington, DC, Michael Leiter emphasized, "There is no silver bullet to counterterrorism," but insisted that US defenses nonetheless have been largely successful.

"What has in fact worked over and over again, not perfectly but well, is a multi-layered approach to counterterrorism and homeland security," Leiter stated.

Leiter cited the case of Najibullah Zazi, who purchased hydrogen peroxide for making a bomb in Denver, Colo., and drove to New York City with it before his arrest in September 2009.

US authorities relied upon foreign intelligence to track Zazi, who had been trained by Al Qaeda in Pakistan to carry out a terror plot. Federal intelligence agencies shared information with state and local authorities, and he was arrested in coordination with the New York Police Department, Leiter said.

In another case, multi-layered defenses worked well against Faisal Shahzad, the would-be Times Square bomber who attempted to detonate a fertilizer bomb in an SUV in May 2010.

The media portrayed Shahzad's attempt to detonate his bomb as an intelligence failure but US defenses ultimately frustrated Shahzad's plot to blow up Times Square, Leiter insisted.

Reading the headlines, people may ask, "How can we let this happen? How could the intelligence system not detect this guy who had gone back and forth from Pakistan and is now in the middle of Times Square? And the only thing that saved us was a hot dog vendor?" Leiter queried.

But the former counterterrorism director viewed the narrative differently.

First, public awareness is an important part of the multi-layered approach to defeating terrorism, he said. So an important element of defense is the identification of suspicious activity by members of the public, as envisioned by the "If You See Something, Say Something" campaign adopted by the Department of Homeland Security (DHS). Public awareness campaigns have worked well in other nations that have faced more persistent homegrown terrorist threats like Israel and the United Kingdom.

Although Shahzad did indeed travel to Pakistan for training on how to make a bomb, he limited those trips and thus limited his effectiveness because he was afraid of being discovered, Leiter said.

"He was worried that if he spent too much time in Pakistan then when he came back to the United States, he might be subject to additional screening and might become a suspect for the FBI or DHS to investigate," Leiter declared.

As Shahzad was discouraged from fully participating in terrorist training, one layer of US counterterrorism defenses worked, he argued.

Another layer also blocked Shahzad from being fully successful.

When he went to purchase fertilizer for his bomb, he bought fertilizer without nitrogen -- a lower grade of fertilizer that was not going to create the large explosion that he sought to create.

Shahzad purchased the lower grade fertilizer because he was aware of a tripwire system whereby people selling potentially dangerous bomb ingredients, such as the high-grade fertilizer, know to call local authorities of the FBI when they see suspicious purchases, Leiter said.

"So did the intelligence system find him among all of the noise beforehand? No. Did the intelligence or national security or homeland security system make it less likely that he was going to cause a catastrophic terrorist attack within the United States? Absolutely," he stated.

As such, the multi-layered defense system worked because it reduced the likelihood of a catastrophic terrorist attack, Leiter said.

He stressed that defenses could not stop every terrorist attack in the world, but US defenses still reduce the likelihood of catastrophic attacks and thus have generally been successful.

Follow me on Twitter at www.twitter.com/mickeymccarter


[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]
View W. Scott Malone's profile on LinkedIn
 

Wednesday, May 16, 2012

CS Monitor Exclusive: Potential China Link to Cyber-attacks on Gas Pipeline Companies

- LIMITED DISSEMINATION
IranianCyberWARFARE; US/1; ATTN: HST/2; US/12


Those analyzing the cyberspies who are trying to infiltrate natural-gas pipeline companies have found similarities with an attack on a cybersecurity firm a year ago. At least one US government official has blamed China for that earlier attack.

By Mark Clayton, Staff writer / May 10, 2012

Investigators hot on the trail of cyberspies trying to infiltrate the computer networks of US natural-gas pipeline companies say that the same spies were very likely involved in a major cyberespionage attack a year ago on RSA Inc., a cybersecurity company. And the RSA attack, testified the chief of the National Security Agency (NSA) before Congress recently, is tied to one nation: China.

Three confidential alerts since March and a public report on May 4 by the Department of Homeland Security warn of a "gas pipeline sector cyber intrusion campaign," which apparently began in December. That campaign, against an undisclosed number of companies, is continuing, DHS said in the alerts, which were first reported by the Monitor.

"Analysis of the malware and artifacts associated with these cyber attacks has positively identified this activity as related to a single campaign," DHS said in its public statement May 4. It also described a sophisticated "spear-phishing" campaign – in which seemingly benign e-mails that are actually linked to malicious software are sent to specific company personnel in hopes of gaining access to corporate networks.


Along with the alerts, DHS supplied the pipeline industry and its security experts with digital signatures, or "indicators of compromise" (IOCs). Those indicators included computer file names, computer IP addresses, domain names, and other key information associated with the cyberspies, which companies could use to check their networks for signs they’ve been infiltrated.

Two independent analyses have found that the IOCs identified by DHS are identical to many IOCs in the attack on RSA, the Monitor has learned. RSA is the computer security division of EMC, a Hopkinton, Mass., data storage company.

Discovery of the apparent link between the gas-pipeline and RSA hackers was first made last month by Critical Intelligence, a cybersecurity firm in Idaho Falls, Idaho. The unpublished findings were separately confirmed this week by Red Tiger Security, based in Houston. Both companies specialize in securing computerized industrial control systems used to throw switches, close valves, and operate factory machinery.

"The indicators DHS provided to hunt for the gas-pipeline attackers included several that, when we checked them, turned out to be related to those used by the perpetrators of the RSA attack," says Robert Huber, co-founder of Critical Intelligence. "While this isn't conclusive proof of a connection, it makes it highly likely that the same actor was involved in both intrusions."

Mr. Huber would not release details about the indicators, because access is restricted by DHS.

Jonathan Pollet, founder of Red Tiger Security, has arrived at similar conclusions.
"The indicators from each source are a match," says Mr. Pollet, whose company has extensive experience in the oil and gas industry. "This does not directly attribute them to the same threat actor, but it shows that the signatures of the attack were extremely similar. This is either the same threat actor, or the two threat actors are using the same ‘command and control' servers that control and manage the infected machines."

Among several DHS indicators with links to the RSA campaign, Huber says, is an Internet "domain name" – a humanly recognizable name for a computer or network of computers connected to the Internet. Scores of computer-server "hosts" associated with that domain were already known to have participated in the RSA attack, Critical Intelligence found.

Alone, the domain-name finding was strongly suggestive. But along with many other indicators he's checked, a link between the RSA and pipeline-company attacks is clear, Huber says.

"I don't think there's much question that the attackers going after the pipelines are somehow connected to the group that went after RSA," he says.

So who went after RSA?

Gen. Keith Alexander, chief of US Cyber Command, who also heads the NSA, told a Senate committee in March that China was to blame for the RSA hack in March 2011.

The infiltration of RSA by cyberspies is widely considered one of the most serious cyberespionage attacks to date on a non-defense industry company. Its SecurID system helps to secure many defense companies, government agencies, and banks. Information stolen from RSA has since been reported to have been used in attacks against defense companies Lockheed Martin, Northrop Grumman, and L-3 Communications.

Cyberspies attacked RSA using a spear-phishing e-mail that contained an Excel spreadsheet with an embedded malicious insert. Similarly, the gas-pipeline attacks have seen spear-phishing e-mails with an attachment or tainted link.

Nothing in cyberespionage is for sure, Huber and Pollet say – especially since identifying perpetrators is difficult or sometimes impossible because of the layers of digital obfuscation that’s possible for attackers. But as other security firms check and confirm the findings, it could reveal important things, the two experts agree.

First, it would show that the same group hacking the gas-pipeline companies is also interested in high-tech companies that have a focus on cryptography and cybersecurity.

Second, the question arises: Why did DHS provide the indicators to the industry, but didn’t identify the apparent link between the gas-pipeline and RSA attacks?

Finally, there's also the question of why DHS officials, in their alerts, requested companies that detected the intruders to only observe them and report back to DHS – but not act to remove or block them from their networks. Some speculate that blocking the intruders would have short-circuited intelligence gathering. (A DHS spokesman refused comment on the issue.)

This last point has raised consternation among security personnel at some pipeline companies. For a year now, big cybersecurity companies like McAfee have had digital defenses that could be deployed against the RSA hack. In fact, they might have been at least partially effective against the new pipeline hack, Huber says.

Has DHS’s advice to only observe the intruders come at the expense of allowing the cyberspies to become more deeply embedded on company networks?

Marty Edwards, director of the DHS Control Systems Security Program, which issued the alerts, referred questions to public-affairs officials.

“DHS’s Industrial Control Systems Cyber Emergency Response Team [ICS-CERT] has been working since March 2012 with critical infrastructure owners and operators in the oil and natural gas sector to address a series of cyber intrusions targeting natural gas pipeline companies," Peter Boogaard, a DHS spokesman, said in an e-mailed statement.

"The cyber intrusion involves sophisticated spear-phishing activities targeting personnel within the private companies," he continued. "DHS is coordinating with the FBI and appropriate federal agencies, and ICS-CERT is working with affected organizations to prepare mitigation plans customized to their current network and security configurations to detect, mitigate and prevent such threats.”

But if anything, questions are growing about China's role either directly or through its cyber militia in vacuuming up proprietary, competitive data on US corporate networks – as well as possibly mapping critical infrastructure networks.

Sen. Carl Levin (D) of Michigan queried Alexander about "China's aggressive and relentless industrial espionage campaign through cyberspace" and asked him to provide some unclassified examples. Alexander's first named example was RSA.

"We are seeing a great deal of DOD-related equipment stolen by the Chinese," he replied. "I can't go into the specifics here, but we do see that from defense industrial companies throughout. There are some very public ones, though, that give you a good idea of what's going on. The most recent one, I think, was the RSA exploits."

"The exploiters," he continued, "took many of those certifications and underlying software" from RSA, rendering the security system insecure until updated.

Chinese officials regularly pour cold water on such accusations. A Pentagon press conference on Monday with Defense Secretary Leon Panetta and Chinese Defense Minister Gen. Liang Guanglie was intended to show US-Chinese cooperation on cybersecurity. But Liang took the opportunity to condemn claims that Chinese cyberspies are the predominant actors in cyberspying on US networks.

"I can hardly agree with [that] proposition," said Liang, as reported by The Hill's DefCon blog. "During the meeting, Secretary Panetta also agreed on my point that we cannot attribute all the cyberattacks in the United States to China."

Related stories

CONTINUE Reading Full Story HERE...

[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]
View W. Scott Malone's profile on LinkedIn

Wednesday, May 2, 2012

FLASH--CyBER-BlackSEC- BBC - Web War II: What a future cyberwar will look like

- LIMITED DISSEMINATION
Magazine
FLASH-CyBER-BlackSEC 
CyberIntelligenceNETWORK; US/1; ATTN: ALL

The first episode of the three part documentary series Danger in the Download presented by Ed Butler will be broadcast on BBC World Service on Tuesday 1 May at 00:06GMT and will be available afterwards on i-player.

30 April 2012 Last updated at 04:21 ET 

By Michael Gallagher BBC World Service
 
How might the blitzkrieg of the future arrive? By air strike? An invading army? In a terrorist's suitcase? In fact it could be coming down the line to a computer near you.
Operation Locked Shields, an international military exercise held last month, was not exactly your usual game of soldiers. It involves no loud bangs or bullets, no tanks, aircraft or camouflage face-paint. Its troops rarely even left their control room, deep within a high security military base in Estonia

These people represent a new kind of combatant - the cyber warrior

One team of IT specialists taking part in Locked Shields, were detailed to attack nine other teams, located all over Europe. At their terminals in the Nato Co-operative Cyber Defence Centre of Excellence, they cooked up viruses, worms, Trojan Horses and other internet attacks, to hijack and extract data from the computers of their pretend enemies. 

The idea was to learn valuable lessons in how to forestall such attacks on military and commercial networks. The cyber threat is one that the Western alliance is taking seriously. 

It's no coincidence that Nato established its defence centre in Estonia. In 2007, the country's banking, media and government websites were bombarded with Distributed Denial of Service (DDOS) attacks over a three week period, in what's since become known as Web War I. The culprits are thought to have been pro-Russian hacktivists, angered by the removal of a Soviet-era statue from the centre of the capital, Tallinn. 

DDOS attacks are quite straightforward. Networks of thousands of infected computers, known as botnets, simultaneously access the target website, which is overwhelmed by the volume of traffic, and so temporarily disabled. However, DDOS attacks are a mere blunderbuss by comparison with the latest digital weapons. Today, the fear is that Web War II - if and when it comes - could inflict physical damage, leading to massive disruption and even death.

"Sophisticated cyber attackers could do things like derail trains across the country," says Richard A Clarke, an adviser on counter-terrorism and cyber-security to presidents Clinton and Bush. 

"They could cause power blackouts - not just by shutting off the power but by permanently damaging generators that would take months to replace. They could do things like cause [oil or gas] pipelines to explode. They could ground aircraft.

Clarke's worries are fuelled by the current tendency to put more of our lives online, and indeed, they appear to be borne out by experiments carried out in the United States.
At the heart of the problem are the interfaces between the digital and physical worlds known as Scada - or Supervisory Control And Data Acquisition - systems.
Today, these computerised controllers have taken over a myriad jobs once performed manually. They do everything from opening the valves on pipelines to monitoring traffic signals. Soon, they'll become commonplace in the home, controlling smart appliances like central heating.

And crucially, they use cyberspace to communicate with their masters, taking commands on what to do next, and reporting any problems back. Hack into these networks, and in theory you have control of national electricity grids, water supplies, distribution systems for manufacturers or supermarkets, and other critical infrastructure. 

In 2007, the United States Department of Homeland Security (DHS) demonstrated the potential vulnerability of Scada systems. Using malicious software to feed in the wrong commands, they attacked a large diesel generator. Film of the experiment shows the machine shaking violently before black smoke engulfs the screen. 

Although this took place under laboratory conditions, with the attackers given free rein to do their worst, the fear is that, one day, a belligerent state, terrorists, or even recreational hackers, might do the same in the real world. 

"Over the past several months we've seen a variety of things," says Jenny Mena of the DHS. "There are now search engines that make it possible to find those devices that are vulnerable to an attack through the internet. In addition we've seen an increased interest in this area in the hacker and hacktivist community."

One reason why Scada systems may be prone to hacking is that engineers, rather than specialist programmers, are often likely to have designed their software. They are expert in their field, says German security consultant Ralph Langner, but not in cyber defence. "At some point they learned how to develop software," he adds, "but you can't compare them to professional software developers who probably spent a decade learning." 

Moreover, critical infrastructure software can be surprisingly exposed. A power station, for example, might have less anti-virus protection than the average laptop. And when vulnerabilities are detected, it can be impossible to repair them immediately with a software patch. "It requires you to re-boot," Langner points out. "And a power plant has to run 24-7, with only a yearly power-down for maintenance." So until the power station has its annual stoppage, new software cannot be installed. 

Langner is well-qualified to comment. In 2010 he, along with two employees, took it upon himself to investigate a mystery computer worm known as Stuxnet, that was puzzling the big anti-virus companies. What he discovered took his breath away.
Stuxnet appeared to target a specific type of Scada system doing a specific job, and it did little damage to any other applications it infected. It was clever enough to find its way from computer to computer, searching out its prey.

And, containing over 15,000 lines of computer code, it exploited no fewer than four previously undiscovered software errors in Microsoft Windows. Such errors are extremely rare, suggesting that Stuxnet's creators were highly expert and very well-resourced. 

It took Langner some six months to probe just a quarter of the virus. "If I'd wanted to do all of it I might have gone bust!" he jokes. But his research had already drawn startling results. 

Stuxnet's target, it turned out, was the system controlling uranium centrifuges at Iran's Natanz nuclear facility. There is now widespread speculation that the attack was the work of American or Israeli agents, or both. Whatever the truth, Langner estimates that it delayed Iran's nuclear project by around two years - no less than any air strike was expected to achieve - at a relatively small cost of around $10 million. This success, he says, means cyber weapons are here to stay. 

Optimists say Stuxnet does at least suggest a scrap of reassurance. Professor Peter Sommer, an international expert in cyber crime, points out that the amount of research and highly skilled programming it involved would put weapons of this calibre beyond anyone but an advanced nation state. And states, he point out, usually behave rationally, thus ruling out indiscriminate attacks on civilian targets. 

"You don't necessarily want to cause total disruption. Because the results are likely to be unforeseen and uncontrollable. In other words, although one can conceive of attacks that might bring down the world financial system or bring down the internet, why would one want to do that? You would end up with something not that different from a nuclear winter."

But even this crumb of comfort is denied by Langner, who argues that, having now infected computers worldwide, Stuxnet's code is available to anyone clever enough to adapt it, including terrorists.

"The attack vectors and exploits used by Stuxnet - they can be copied and re-used reliably against completely different targets. Until a year ago no one was aware of such an aggressive and sophisticated threat. With Stuxnet that has changed. It is on the table. The technology is out there on the internet."

One thing is for sure, he adds: If cyber weapons do become widespread, their targets will lie mostly in the west, rather than in countries like Iran, which have relatively little internet dependence. This means that the old rules of military deterrence which favoured powerful, technologically advanced countries like the United States do not apply: Responding in kind to a cyber attack could be effectively impossible. 

This asymmetry is likely to grow, as developed countries become ever more internet-dependent. So far, the Internet Protocol format allows only 4.3 billion IP addresses, most of which have now been used. But this year, a new version is rolling out, providing an inexhaustible supply of addresses and so allowing exponential growth in connectivity. Expect to see far more machines than people online in the future

In the home, fridges will automatically replenish themselves by talking to food suppliers; ovens and heating systems will respond to commands from your smartphone. Cars may even drive themselves, sharing GPS data to find the best routes. For industry, commerce and infrastructure, there will be even more reliance on cyber networks that critics claim are potentially vulnerable to intrusion. 

"There will be practically infinite number of IP addresses," says former hacker Jason Moon. "Everything can have an IP address. And everything will have one. Now, that's great. But think what that's going to do for the hacker!" 

In fact, it has already become a challenge for even sensitive installations, let alone households, to remain offline. Although military and other critical networks are supposedly isolated from the public internet, attackers can target their contractors and suppliers, who plug into the "air-gapped" system at various times. Somewhere down the food chain, a vulnerable website or a rogue email will provide a way in.
According to Richard Clarke, the mighty American armed forces themselves are not immune, since their command & control, supplies, and even some weapons systems, also rely on digital systems.

"The US military ran headlong into the cyber age," he says. "And we became very dependent on cyber devices without thinking it through. Without thinking that if someone got control of our software, what would we be able to do? Do we have backup systems? Can we go back to the old days?"

The answer it seems is no. A new form of weapon appears to be emerging. And the world may have to learn to adapt.

The first episode of the three part documentary series Danger in the Download presented by Ed Butler will be broadcast on BBC World Service on Tuesday 1 May at 00:06GMT and will be available afterwards on i-player.

_________________________________________________________________________


[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]
View W. Scott Malone's profile on LinkedIn

Friday, August 19, 2011

Anthony Kimery: 'LoneWolf' Terrorists Pose Growing Threat

- LIMITED DISSEMINATION
US/1


'Lone Wolf' Terrorists, Extremists Pose Growing Homeland Threat, Administration Believes
 
By: Anthony Kimery
08/18/2011 ( 9:22am)

This past week, the Obama administration launched a full court press to alert citizens, law enforcement and other federal, state and local authorities to be on the lookout for activities that could be indicative of potential terrorist plotting and extremist behavior.

Tuesday, President Barack Obama said in an interview with CNN that a "lone wolf" terror attack in the United States is much more likely today than a coordinated attack like the attack on Sept. 11, 2001.

Conceding that the federal government is in a state of heightened awareness in the run-up to the tenth anniversary of the 9/11 attack, Obama said “the biggest concern we have right now is not the launching of a major terrorist operation, although that risk is always there.”

Obama said “the risk that we're especially concerned [about] right now is the lone wolf terrorist, somebody with a single weapon being able to carry out wide-scale massacres of the sort that we saw in Norway recently. You know, when you've got one person who is deranged or driven by a hateful ideology, they can do a lot of damage, and it's a lot harder to trace those lone wolf operators."

These so-called lone wolves can be both Islamist jihadists or homegrown extremists like the Tampa, Florida student arrested this week on charges of plotting what officials said was potentially “catastrophic” bombing at his high school.

Echoing Obama, Department of Homeland Security (DHS) Secretary Janet Napolitano said Wednesday that “lone wolf" terror attacks are increasing and "much more difficult to intercept" than 9/11 magnitude plots.

In a speech at a Chamber of Commerce event, Napolitano said the US has a "layered system of security that would give us multiple ways to deter" an attack like the one on 9/11.

"What we see now is smaller plots," Napolitano stressed, adding, “we are also seeing a rise of activities by individuals who are actually in the country, and they are acting by themselves and that kind of attack is the most difficult to prevent because there is nothing to intercept."

Rep. Peter King (R-NY), chairman of the House Committee on Homeland Security, told WCBS 880 that when you have no “chatter” indicating a large plot, “then you [have to start looking for things like]  weapons sales. You look for, for instance, purchase of explosives. So, you try to track that down [to] see any type of unusual activity.”

Napolitano and the President’s comments coincided with DHS’ launch of public service announcements about the department’s “See Something, Say Something” initiative, and the “For Official Use Only” (FOUO) Joint Intelligence Bulletin on lone wolves issued Tuesday by the FBI Counterterrorism Analysis Section and DHS’ Intelligence & Analysis Production Branch.

Obtained by Homeland Security Today, this new intelligence bulletin, Use of Small Arms: Examining Lone Shooters and Small-Unit Tactics, updated a September 3, 2010 DHS-FBI joint analytic product of the same title that “is intended to provide warning and perspective regarding the scope of the potential terrorist threats to the United States, specifically towards US persons,” the bulletin stated.

The alert is intended “to support the activities of DHS and FBI and to help federal, state and local government counterterrorism and law enforcement officials deter, prevent, preempt or respond to terrorist attacks directed against the United States,” it stated.

The “Key Findings” of the bulletin are:

  • “The current evolving and diversified homeland threat environment and recent incidents involving small-arms operations in the United States and abroad demonstrate the need for continued vigilance and awareness. Small-arms operations could be employed through a range of tactics from a lone offender - as illustrated by the recent 22 July 2011 lone shooter attack that took place in Norway - to a coordinated small-unit attack involving several operatives;” and
  •  
  • “We continue to assess that the scale and complexity of any attack of this type is dependent on a variety of factors, to include the sophistication and training of the attackers, the parameters of their targets, and the local security environment.”

Continuing, the alert warned that “recent lone offender attacks and plots in the United States and abroad illustrate the effectiveness of the small-arms tactic and the need for continued vigilance and awareness of this tactic. Attacks by lone offenders - which by definition lack  co-conspirators, and therefore provide fewer opportunities for detection - may be more difficult for law enforcement and homeland security authorities to disrupt.”

Additionally, the bulletin warned, “incidents involving lone gunmen in the United States and abroad demonstrate the potential danger, lethality, and effectiveness of an unrehearsed small-arms attack by a single individual with little or no training, and underscore the potentially higher consequences of an assault-style attack involving multiple operatives.”

The bulletin stressed that “terrorist and violent insurgent groups overseas - in many cases operating in nations battling violent civil unrest - have long favored small-unit assault tactics, in which small teams of operatives storm a target using small arms to defeat security. The frequency of these attacks is likely attributable to perceptions of their effectiveness, the prevalence of small-arms instruction at terrorist and militant training camps, and the widespread availability of assault weapons …”

Regarding the homeland threat posed by small-unit tactics, the joint DHS-FBI bulletin issued Tuesday stated that, “given recent events demonstrating the success of small-arms tactics and the evolving, diversified threat faced by the United States from Al Qaeda and those inspired by its ideology, we assess that transnational terrorist groups and homegrown violent extremists (HVEs) could employ small-unit assault tactics in the United States.”

And “although we have no information indicating transnational terrorists have attempted to execute a small-unit assault operation in the homeland,” the bulletin stated, “we note that disrupted HVE plots … planned to employ small arms-based assault tactics.”

The bulletin noted that because of terrorists’ failure to successfully pull-off homeland attacks using improved explosive devices, or IEDs, small-unit assault tactics “may increase [their] attractiveness.”

“While terrorist organizations almost certainly will continue to attempt future homeland attacks using IEDs, it is also possible that operational planners will incorporate small-arms attacks that do not require mastery of IED construction or risk the failure of a complex bomb design,” the FBI and DHS warned.

The intelligence bulletin emphasized the importance of suspicious activity reporting, which is the cornerstone of DHS’ aggressive promotion of its “See Something, Say Something” public awareness campaign.

“We face an increased challenge in detecting terrorist plots underway by individuals or small groups acting independently or with only tenuous ties to foreign handlers,” the DHS-FBI bulletin said, noting that “recent events have illustrated that state, local, tribal and private sector partners play a critical role in identifying suspicious activities - such as unusual purchases of or inquiries about firearms, gunpowder, or ammunition - and raising the awareness of federal counterterrorism officials.”

Similarly, DHS is funding the Information Collection on Patrol (InCOP) training program to enhance the capacity of the line police officer to be able to identify and report suspicious or criminal behavior. InCOP has been adopted by major police departments across the nation.

The training is provided by the Oklahoma City-based Memorial Institute for the Prevention of Terrorism (MIPT), whose executive director, David Cid, is a retired career FBI official.


[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]

Wednesday, August 3, 2011

BKNT-FLASH--DOCTOR JONES & THE MISSING ASHES OF BLASPHEMY

- LIMITED DISSEMINATION
FROM: Scott Malone, Editor 

 YIKES!

[ed.note: Posted below is what we here at the BlackNET Intelligence Channel are wont to call "RAW INTELLIGENCE," as once noted in the March 19th  2003 United Press International profile of the BlackNET on the day we accurately predicted the commencement of the SECOND US and allied invasion of IRAQ.

What will the intrepid Florida evangelist think up next? His threat to immolate the Holy Koran last September 11th almost set of a FURTHER WORLD CONFLAGRATION.

Hard to top that.

But then the good Dr. Jones actually did BURN the Holy Koran after a rather pedantic "show trial." That landed the Christian Fundamentalist in the TARGET SIGHTS of various AL QAEDA internet forums, as first and exclusively reported by the BlackNET Intelligence Channel

The "U/FOUO - Law Enforcement SENSITIVE" Al Qaeda HIT_LIST the Office of the SECDEF Bob Gates wanted removed from the BlackNET Intelligence Channel Website.

We first got to meet Dr. Jones via cell when BlackNET investigator Scott Malone was the FIRST to inform him that he was now on the Al QAEDA's lastest HIT-LIST, which was considered serious enough to warrant FOUR separate SECURITY ALERTS Worldwide.

These included the "Law Enforcement Sensitive" Bulletins from the FBI, the Department of Homeland Security (DHS), and the Office of Secretary of Defense (OSD) Protective Intelligence Investigations branch of the DoD’s Coordinator for Threat Mitigation Office. 

"I heard from you first," Dr. Jones told us. "Then the FBI called." 

And that was TWO WEEKS after the SECURITY Bulletin had been issued.

And then LAST WEEK:

BKNT--US Pastor, on Al Qaeda ‘Hit List’ for Burning Koran, Alleged Victim of Hit-and-Run Assault


Controversial Florida Pastor Terry Jones, who achieved notoriety earlier this year when he enraged Muslims by burning a copy of the Koran following a mock trial by his church that found the Islamic holy book quilty of crimes against humanity, says he was the victim of a mysterious hit-and-run assault Saturday afternoon.

Jones received scores of death threats in response to his burning of the Koran, and more recently his name appeared on a so-called "hit list" of infidels who should be killed that was drawn up by members of an Al Qaeda-linked Internet chat room for jihadists.

So it would appear yet again that there truly is no rest for wicked, whatever their WAR COLORS.

But we here at the BlackNET Intelligence Channel believe that Members should be able to judge for themselves...]
 





FOR IMMEDIATE RELEASE:
August 3, 2011

MEDIA CONTACT: 

What should Dr. Terry Jones and Stand Up America Now! do with the charred remains of the Koran that was burned in March during International Judge the Koran Day?

1)  Auction off the remains to support the fight against radical Islam and Sharia in America?

2)  Present the remains to Imam Feisal Abdul Rauf as a rejection to the building of the Ground Zero mosque?

3)  Spread the ashes at Ground Zero?

4)  Present the burned remains to President Obama?

If you have ideas or suggestions, please send them in an e-mail to Stand Up America Now! at info@standupamericanow.org

United States
[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]


- flash- LIMITED DISSEMINATION
ATTN: HST/2; NSW/1&2

FROM: Scott Malone, Editor

[NO DISSEMINATION [Lifted]  [ed.note:  Dr. Terry Jones is famous the word over for not only inflammatory rhetoric, but for being just plain inflammatory, particularly when it comes to the holy Koran.

What is NOT publicly known is that he earned a prominent place the Al Qaeda CyBER-JIHAD ‘Hit-List,’ according to the U/FOUO Terror Alert Bulletins put out by the FBI, DHS, DoD and CFIX in early JUNE. He and his flock were first to learn of this serious Al Qaeda death threat from BlackNET Investigators. 
  
Only then did the FBI call him, more than TWO weeks post-THREAT Bulletin issuance. Our Member joint article for BlackNET Intelligence Channel and Homeland Security Today,

W. Scott Malone and Anthony L. Kimery: NEW DETAILS - Al Qaeda HIT LIST Names NAMED... http://blacknetintel.blogspot.com/2011/06/w-scott-malone-and-anthony-l-kimery-new.html


…specifically did NOT mention Dr. Jones by name. And the actual documents, though appropriately sanitized as regards Dr. Jones, were taken down from the BlackNET site in response to early morning phone calls from several Members on behalf of the SECDEF and  OSD.

We have been planning for several weeks to do an EXCLUSIVE Interview on this very subject with Dr. Jones via Skype (as soon as US/1 learns how—apologies to certain Florida Members).

Dr. Jones was the only “civilian” on the 58-name assassination list, in that he was neither a Pentagon official, military commander, Member of Congress or defense contractor.

[edit]

We pray for his speedy recovery and implore him to ALWAYS travel safely…
NO DISSEMINATION, ABOVE [Lifted]. OPEN SOURCE below.] 


July 23, 2011


Dr. Terry Jones, Founder and President of Stand Up America Now was the victim of a hit-and-run attack Saturday afternoon, July 23, around 1:45pm ET. 

Dr. Jones suffered minor injuries in the attack.
A black SUV sped around him hitting his leg and running over his foot as he was stopped at an intersection while on his motorcycle.  The SUV, with Georgia plates, then sped away quickly.  Dr. Jones, noticed the SUV following him for a few miles before the attack.

Dr. Terry Jones' account of the hit-and-run incident:
As we left the church, we turned right and came straight down as we went through the wooded area and came to the stop sign where you must turn left or right. I noticed that there was a black SUV behind us. Of course because of our situation, we always are aware of things and people who are following us.  


“As we turned left, they turned left. They were a little bit suspicious as they kept speeding up and backing off, speeding up and backing off. We continued on down the road a few miles. As we approached the next intersection, the next stop light, and as I was slowing down, they passed me slowly on the right hand side literally only inches away from my motorcycle. I kept it straight and yelled at them. This was done on purpose as there was absolutely no need for this.

It was a black SUV with a Georgia license plate. As I stopped, they ran over my leg, my foot. I yelled out at them. They gave it no absolutely no attention. Although no window was down, they knew very well that they had hit me. They proceeded to turn to the right and to speed up very, very fast. It was a definite attempt of some form on my life, either to give us a warning, a scare, or to actually do bodily harm which they did by running over my leg. We will [sic] reported this to the Florida Highway Patrol and to the FBI.”

[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]

Follow The Money. in HAWALA - EdgeHEDGE

Follow The Money. in HAWALA - EdgeHEDGE
NEW - Muslim who financed Times Square jihad bomber pleads guilty

FLASH - DigitalBLACK: GERONIMO ACQUIRED - FLASH - NavySEALs Capture UBL...

BlackNET Member James Bamford: Inside the NSA's Largest Secret Domestic Spy Center