Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Thursday, May 17, 2012

PIERLUIGI PAGANINI: Has Anonymous infiltrated US Government? The insider issue...

-RETURN to the BlackNET Intellignce Channel LIMITED DISSEMINATION
INTELLIGENCE & SECURITY-DG; SecurityAFFAIRS.com; US/1; ATTN: HST/2; US/12

So if that’s what controls our world, ask yourself who controls the 1s and the 0s? It’s the geeks and computer hackers of the world.” – ANONYMOUS Member

by paganinip on May 16th, 2012

In the last months we have a long discussed about the security status of US networks and infrastructures, we have described the American cyber strategies and the main action proposed to protect the principal assets of the nations. One story in particular struck us deeply, that relating to the vulnerability of U.S. Government networks for admission of senior government officials are routinely hacked. Difficult to accept a reality that is disconcerting, one of the major superpowers in the world forefront of the technology is vulnerable to attack by hacker groups animated by the most diverse motives.

Who is interested to US networks and why?

Consider that cyber infrastructures of a country are a mine of news that attracts foreign governments, independent hackers and also hacktivism, all this forces daily combine their actions against the same target. The success of the cyber attacks against US networks, according the declarations of the security experts, is due the US infrastructure status that are protected by obsolete defense systems unable to fight against continuous incursions. Speaking before the Senate Armed Services Subcommittee on Emerging Threats and Capabilities the experts told the assembled Senators that the U.S. government needed to abandon the notion that it could keep outsiders off its computer networks.

Very meaningful the worlds pronounced by Senator Rob Portman member of the Emerging Threats and Capabilities subcommittee:

“We can do things to make it more costly for them to hack into our systems…,”
“but you didn’t say we can stop them.”

A clear message that expresses the awareness of the threat and impossibility to defeat it in the short term This time the revelations on the status of US networks come from the famous group Anonymous, in a recent interview its component Christopher “Commander X” Doyon, who today lives in Canada, declared:

Right now we have access to every classified database in the U.S. government. It’s a matter of when we leak the contents of those databases, not if. You know how we got access? We didn’t hack them. The access was given to us by the people who run the systems…

The five-star general (and) the Secretary of Defense who sit in the cushy plush offices at the top of the Pentagon don’t run anything anymore. It’s the pimply-faced kid in the basement who controls the whole game, and Bradley Manning proved that.
According Doyon, the great force of the groups is made by insiders in government infrastructures that give the group an unimaginable power, the power of knowledge and information.

Doyon has admitted him participation in some of the most important attacks on websites last year from Sony to PayPal. He was arrested in September for a minor hack on the county website of Santa Cruz, Calif., where he was living, in retaliation for the town forcibly removing a homeless encampment on the courthouse steps.

For that, Doyon is facing 15 years in jail. But he crossed the border into Canada in February to avoid prosecution.  Doyon was the leader of the People’s Liberation Front , a group allied with Anonymous and is considered the most wanted hacktivist after Julian Assange.
 
The hacker has reiterated the concept saying

“The entire world right now is run by information,”

“Our entire world is being controlled and operated by tiny invisible 1s and 0s that are flashing through the air and flashing through the wires around us. So if that’s what controls our world, ask yourself who controls the 1s and the 0s? It’s the geeks and computer hackers of the world.”

What the hacker claims regarding today’s information society is correct, each date is related to its simple binary representation, a core of information expressed using 0s and 1s that can never be considered completely safe.

What do you think about the revelation of the exponent of the group? What is the truth behind these declarations?

We are now accustomed to sensational statement by Anonymous, we all recognize its great media capacity, but rather than believing the truth exposed the experts have the following interpretations:
  • Hackers are operating on psychological front, trying to instilling the culture of suspicion in the enemy lines. Everyone could be a spy, everyone could be Anonymous.
  •  
  • Just the statement “everyone could be Anonymous” is the base for a second hypothesis regarding the revelations of the hackers. Anonymous is sending a message to all those investigators who are employed by the government and for which collaborations are open.
I think both assumptions valid while acknowledging that Doyon has certainly exaggerated in his claims to more striking its declarations. The risk of insider close to the group is high and to face similar threats requires observations of procedures and protocols in order to prevent access to confidential information.

I’m still convinced that the group is in a phase of profound transformation, new inside tumultuous currents have born and they could degenerate to dangerous insurgents.
In my opinion, such statements must be taken into consideration but I also believe that the group has issued statements to pursue a clear strategy of media presenteeism.

In recent weeks, in several articles I predicted the possibility that law enforcement and intelligence agencies were infiltrating the group, today according hacktivist’s declaration we are assisting to a reverse of the scenario. The reality is that both factions fear the event and are working so that the damage could be minimal in case of external conditions.

Meanwhile we have few info on how Anonymous is approaching the problem, on the opposite site we have perception of how major government agencies are facing the threat. I note that the FBI in more than one occasion pointed out the need to detect insider providing valuable guidance and insights on the topic.

Regard the topic I suggest to read the guidance provided by FBI “The Insider Threat An introduction to detecting and deterring an insider spy.” an introduction for security personnel on how to detect an insider threat and provides tips on how to safeguard your company’s trade secrets. Cyber espionage and theft of intellectual property are increasing threats to organizations and government institutions that can go unnoticed for months or even years.

The message is:

“We must remain on guard, we don’t wait for the day when Doyon’s words will come true”

Pierluigi Paganini

[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]
View W. Scott Malone's profile on LinkedIn

Wednesday, May 16, 2012

CS Monitor Exclusive: Potential China Link to Cyber-attacks on Gas Pipeline Companies

- LIMITED DISSEMINATION
IranianCyberWARFARE; US/1; ATTN: HST/2; US/12


Those analyzing the cyberspies who are trying to infiltrate natural-gas pipeline companies have found similarities with an attack on a cybersecurity firm a year ago. At least one US government official has blamed China for that earlier attack.

By Mark Clayton, Staff writer / May 10, 2012

Investigators hot on the trail of cyberspies trying to infiltrate the computer networks of US natural-gas pipeline companies say that the same spies were very likely involved in a major cyberespionage attack a year ago on RSA Inc., a cybersecurity company. And the RSA attack, testified the chief of the National Security Agency (NSA) before Congress recently, is tied to one nation: China.

Three confidential alerts since March and a public report on May 4 by the Department of Homeland Security warn of a "gas pipeline sector cyber intrusion campaign," which apparently began in December. That campaign, against an undisclosed number of companies, is continuing, DHS said in the alerts, which were first reported by the Monitor.

"Analysis of the malware and artifacts associated with these cyber attacks has positively identified this activity as related to a single campaign," DHS said in its public statement May 4. It also described a sophisticated "spear-phishing" campaign – in which seemingly benign e-mails that are actually linked to malicious software are sent to specific company personnel in hopes of gaining access to corporate networks.


Along with the alerts, DHS supplied the pipeline industry and its security experts with digital signatures, or "indicators of compromise" (IOCs). Those indicators included computer file names, computer IP addresses, domain names, and other key information associated with the cyberspies, which companies could use to check their networks for signs they’ve been infiltrated.

Two independent analyses have found that the IOCs identified by DHS are identical to many IOCs in the attack on RSA, the Monitor has learned. RSA is the computer security division of EMC, a Hopkinton, Mass., data storage company.

Discovery of the apparent link between the gas-pipeline and RSA hackers was first made last month by Critical Intelligence, a cybersecurity firm in Idaho Falls, Idaho. The unpublished findings were separately confirmed this week by Red Tiger Security, based in Houston. Both companies specialize in securing computerized industrial control systems used to throw switches, close valves, and operate factory machinery.

"The indicators DHS provided to hunt for the gas-pipeline attackers included several that, when we checked them, turned out to be related to those used by the perpetrators of the RSA attack," says Robert Huber, co-founder of Critical Intelligence. "While this isn't conclusive proof of a connection, it makes it highly likely that the same actor was involved in both intrusions."

Mr. Huber would not release details about the indicators, because access is restricted by DHS.

Jonathan Pollet, founder of Red Tiger Security, has arrived at similar conclusions.
"The indicators from each source are a match," says Mr. Pollet, whose company has extensive experience in the oil and gas industry. "This does not directly attribute them to the same threat actor, but it shows that the signatures of the attack were extremely similar. This is either the same threat actor, or the two threat actors are using the same ‘command and control' servers that control and manage the infected machines."

Among several DHS indicators with links to the RSA campaign, Huber says, is an Internet "domain name" – a humanly recognizable name for a computer or network of computers connected to the Internet. Scores of computer-server "hosts" associated with that domain were already known to have participated in the RSA attack, Critical Intelligence found.

Alone, the domain-name finding was strongly suggestive. But along with many other indicators he's checked, a link between the RSA and pipeline-company attacks is clear, Huber says.

"I don't think there's much question that the attackers going after the pipelines are somehow connected to the group that went after RSA," he says.

So who went after RSA?

Gen. Keith Alexander, chief of US Cyber Command, who also heads the NSA, told a Senate committee in March that China was to blame for the RSA hack in March 2011.

The infiltration of RSA by cyberspies is widely considered one of the most serious cyberespionage attacks to date on a non-defense industry company. Its SecurID system helps to secure many defense companies, government agencies, and banks. Information stolen from RSA has since been reported to have been used in attacks against defense companies Lockheed Martin, Northrop Grumman, and L-3 Communications.

Cyberspies attacked RSA using a spear-phishing e-mail that contained an Excel spreadsheet with an embedded malicious insert. Similarly, the gas-pipeline attacks have seen spear-phishing e-mails with an attachment or tainted link.

Nothing in cyberespionage is for sure, Huber and Pollet say – especially since identifying perpetrators is difficult or sometimes impossible because of the layers of digital obfuscation that’s possible for attackers. But as other security firms check and confirm the findings, it could reveal important things, the two experts agree.

First, it would show that the same group hacking the gas-pipeline companies is also interested in high-tech companies that have a focus on cryptography and cybersecurity.

Second, the question arises: Why did DHS provide the indicators to the industry, but didn’t identify the apparent link between the gas-pipeline and RSA attacks?

Finally, there's also the question of why DHS officials, in their alerts, requested companies that detected the intruders to only observe them and report back to DHS – but not act to remove or block them from their networks. Some speculate that blocking the intruders would have short-circuited intelligence gathering. (A DHS spokesman refused comment on the issue.)

This last point has raised consternation among security personnel at some pipeline companies. For a year now, big cybersecurity companies like McAfee have had digital defenses that could be deployed against the RSA hack. In fact, they might have been at least partially effective against the new pipeline hack, Huber says.

Has DHS’s advice to only observe the intruders come at the expense of allowing the cyberspies to become more deeply embedded on company networks?

Marty Edwards, director of the DHS Control Systems Security Program, which issued the alerts, referred questions to public-affairs officials.

“DHS’s Industrial Control Systems Cyber Emergency Response Team [ICS-CERT] has been working since March 2012 with critical infrastructure owners and operators in the oil and natural gas sector to address a series of cyber intrusions targeting natural gas pipeline companies," Peter Boogaard, a DHS spokesman, said in an e-mailed statement.

"The cyber intrusion involves sophisticated spear-phishing activities targeting personnel within the private companies," he continued. "DHS is coordinating with the FBI and appropriate federal agencies, and ICS-CERT is working with affected organizations to prepare mitigation plans customized to their current network and security configurations to detect, mitigate and prevent such threats.”

But if anything, questions are growing about China's role either directly or through its cyber militia in vacuuming up proprietary, competitive data on US corporate networks – as well as possibly mapping critical infrastructure networks.

Sen. Carl Levin (D) of Michigan queried Alexander about "China's aggressive and relentless industrial espionage campaign through cyberspace" and asked him to provide some unclassified examples. Alexander's first named example was RSA.

"We are seeing a great deal of DOD-related equipment stolen by the Chinese," he replied. "I can't go into the specifics here, but we do see that from defense industrial companies throughout. There are some very public ones, though, that give you a good idea of what's going on. The most recent one, I think, was the RSA exploits."

"The exploiters," he continued, "took many of those certifications and underlying software" from RSA, rendering the security system insecure until updated.

Chinese officials regularly pour cold water on such accusations. A Pentagon press conference on Monday with Defense Secretary Leon Panetta and Chinese Defense Minister Gen. Liang Guanglie was intended to show US-Chinese cooperation on cybersecurity. But Liang took the opportunity to condemn claims that Chinese cyberspies are the predominant actors in cyberspying on US networks.

"I can hardly agree with [that] proposition," said Liang, as reported by The Hill's DefCon blog. "During the meeting, Secretary Panetta also agreed on my point that we cannot attribute all the cyberattacks in the United States to China."

Related stories

CONTINUE Reading Full Story HERE...

[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]
View W. Scott Malone's profile on LinkedIn

Follow The Money. in HAWALA - EdgeHEDGE

Follow The Money. in HAWALA - EdgeHEDGE
NEW - Muslim who financed Times Square jihad bomber pleads guilty

FLASH - DigitalBLACK: GERONIMO ACQUIRED - FLASH - NavySEALs Capture UBL...

BlackNET Member James Bamford: Inside the NSA's Largest Secret Domestic Spy Center