The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label DOD. Tampilkan semua postingan
Tampilkan postingan dengan label DOD. Tampilkan semua postingan

Rabu, 01 Mei 2013

DOD Using Chinese satellites underscores the need to negotiate a cyber strategy with China

On March 15, 2013 I wrote an article for Slate magazine ("The U.S. response to Chinese cyberespionage is going to backfire") wherein I said:
The anti-China sentiment on the Hill, in the Pentagon, and at the White House clashes with the pro-China business policies of major U.S. companies, including those with very active in-house security operation centers. Beijing surely knows about this disconnect—and that makes the U.S. strategy look weak or inferior.
That was underscored in a big way with yesterday's announcement via the Danger Room blog that the U.S. Department of Defense's need for satellite bandwidth is so great that they have no alternative but to buy satellite time from the China Satellite Communications company.

Leaving aside DOD's justification for it and the steps that they're taking to protect their data from Chinese collection. And also leaving aside the fact that DOD data WILL be collected despite the encryption and that Chinese researchers have compromised 5 of the world's top ten encryption algorithms, the key take-away here is my original point; that sinophobic cold war rhetoric coming from some information security firm officials, western media, and Congress while U.S. businesses and now the Pentagon NEED to work with China makes the U.S look ridiculous and weak. As I wrote for Slate:
A better approach might be for the federal government to quietly encourage U.S. companies to take steps to harden their networks against low-level attacks (which will shrink the attack surface); identify, segregate, and monitor their crown jewels (which will make it harder for any adversary, including China, to steal them); and engage with China and Russia against a mutual enemy (mercenary hacker crews). This eliminates the rhetoric and focuses on collaboration—a requirement, since the U.S. is never going to make good on threats against the single biggest holder of U.S. debt and a vital market for U.S. multinationals.
Add to Cart View detail

Rabu, 17 Oktober 2012

Fact-checking Secretary Panetta's Speech Regarding a Preemptive Strike


In an important speech on Thursday night, Defense Secretary Leon Panetta spoke about how the Department of Defense has improved capabilities to protect the U.S. against the threat of a catastrophic cyber attack; that if such an attack were imminent, the U.S. would strike first. While this statement was clearly mean't to deliver a message to Iran which featured prominently in the Secretary's remarks, the U.S. lacks the technical ability to deliver on that threat.

According to the Law of Armed Conflict, a nation state must be under imminent threat of an attack which will cause grievous harm to its populace before it can launch a pre-emptive strike in self defense. Rather than a traditional kinetic attack, Secretary Panetta specifically referred to a cyber attack by "an aggressor nation or extremist group [who] could gain control of critical switches and derail passenger trains, or trains loaded with lethal chemicals". The Secretary went on to say that "If we detect an imminent threat of attack that will cause significant physical destruction or kill American citizens, we need to have the option to take action to defend the nation when directed by the President".

The fact is however that neither the NSA nor any other agency has the ability to identify a malicious program that was custom-written to target an industrial control system before the attack occurs. It cannot "see" such a program traveling across the Internet backbone assuming that were the delivery method. More likely, as in the case of Stuxnet, Shamoon, and other malware, it would be hand-carried onto the target's premises and inserted via removable media into a networked computer which bypasses the capabilities of any NSA-run signals intelligence program to identify it.

Even if we had the ability to discern the purpose and target of malware in-transit, we'd also have to know which nation state was behind it. Although Secretary Panetta claimed that DoD has made "significant advances" in determining attribution, there's ample reason to doubt that statement - the most obvious being the Secretary's own words that "DoD is already in an intense daily struggle against thousands of cyber actors who probe the Defense Department’s networks millions of times per day." Anonymity has provided much of the impetus for the increasing number of automated and targeted attacks against the U.S. and other countries. Those attacks are on the rise because anonymity remains intact.

U.S. offensive cyber warfare capabilities are second to none, but in the words of General Peter Pace, the former Chairman of the Joint Chiefs of Staff, we cannot defend against what we send out, and since what we have sent out (like Stuxnet) is being reverse-engineered, we should re-think whether our being in a weak defensive state is really the best time to be running offensive cyber operations in the first place.
Add to Cart View detail

Rabu, 14 Maret 2012

A History of Google's Government Sales

After reading Noah Shachtman's article at Danger Room "Google Adds (Even More) Links to the Pentagon", I was curious about the scope of Google's (NASDAQ:GOOG) government sales so I used the FFATA Search Portal and plugged Google's name into the search field. The results were surprising. The largest number of sales by far is with the Department of Defense (264); which is about two and a half times more than NASA who's in 2nd place with 104 sales. Here's the Top Ten search results:
  • Defense, Dept of (264)
  • NASA (104)
  • Justice, Dept of (75)
  • State, Dept of (68)
  • Treasury, Dept of the (44)
  • Health and Human Services, Dept of (43)
  • Interior, Dept of (42)
  • Agriculture, Dept of (41)
  • Commerce, Dept of (40)
  • Transportation, Dept of (37)
Sales within the Department of Defense are to:
  • Army (130)
  • Air Force (50)
  • Navy (44)
  • Defense Information Systems Agency (10)
  • Defense Logistics Agency (8)
  • U.S. Special Operations Command (6)
  • Defense Contract Management Agency (5)
  • Uniformed Services: University of the Health Sciences (3)
  • Defense Threat Reduction Agency (3)
  • Defense Media Center (2)
Sales with the Department of Justice are to:
  • Drug Enforcement Administration (45)
  • Federal Bureau of Investigation (8)
  • Offices, Boards, and Divisions (7)
  • Office of Justice Programs (6)
  • Federal Prison System (6)
  • U.S. Marshalls Service (2)
  • ATF Acquisition and Property Management Div (1)
To be fair, every technology company sells to the government and compared to Microsoft and Apple the above numbers are pretty low, but since Google is more intimately connected with our search habits and email content (for advertising) than anyone else, these statistics still make me a little uncomfortable.

Related:
The Google-Clinton-China Martini with a Cyber War Twist

Add to Cart View detail

Kamis, 19 Januari 2012

Inconclusive Attribution Is Worse Than No Attribution

A China expert friend of mine just sent me a link to a Defense News article by Andrew Tilghman "Chinese Virus Targets DoD Common Access Card". Jaime Blasco, lab manager for AlienVault, said "the virus is linked to a “command and control server” that appears to be based in China; some flaws buried deep in the code revealed Chinese language characters, suggesting that only a Chinese speaker would be able to launch it." Tilghman's headline doesn't accurately reflect Blasco's findings. Instead, he chose a sensationalistic headline that would attract readers. Unfortunately, it also attracts researchers, pundits and U.S. government employees who harbor an anti-China slant and who collect stories like this to add fuel to an already hot anti-China sentiment on the Hill.

As I've said many times before, the geolocation of IP addresses mean absolutely nothing since IP addresses are easily obtainable by anyone - both legally and illegally. Chinese characters in the code only mean that a Chinese engineer was involved at some point. How many Chinese engineers work for Western companies or are naturalized citizens outside of the PRC? I shouldn't have to state the obvious fact that because you write using Chinese characters doesn't mean that you work for the Chinese government. That's beyond simple ignorance; bordering on Xenophobia.

Related:
Why I Oppose the 12 Chinese Hacker Groups Claim
Rep. Mike Rogers Needs To Re-Think His China Tactics
The Case Against The Case Against China


Add to Cart View detail

Selasa, 11 Oktober 2011

U.S. Defense Dept.'s Organizational Chart for Cyber Operations

In light of today's Wired.com article about how Creech AFB failed to report its virus attack to the 24th Air Force, I thought it might be helpful to see exactly how DoD has structured its cyber operations. The above graphic is best viewed as a Prezi.

Organizations with responsibility in this case could have included USSTRATCOM which directs DOD's Global Information Grid's operations and defense, USCYBERCOM which is a dual-hatted command with the NSA who has direct responsibility for protecting the .MIL domains. And then there's the 24th Air Force which is responsible for the Air Force Enterprise Network GIG and three Wings which report to it.

24th Air Force
  • Plans and conducts cyberspace operations in support of combatant commands.
  • Maintains and defends the Air Force Enterprise Network GIG.
67th Network Warfare Wing
  • Organizes, trains, and equips cyberspace forces to conduct network defense, attack, and exploitation.
  • Executes air force network operations, training, tactics, and management for the 24th Air Force and combatant commands.
688th Information Operations Wing
  • Aims to deliver proven IO and engineering infrastructure capabilities integrated across air, space, and cyberspace domains.
689th Combat Communications Wing
  • Trains, deploys and delivers expeditionary and specialized communications, air traffic control, and landing systems for Humanitarian Relief Operations and dominant combat operations.
  • Conducts tactical operations in austere, deployed, and joint/coalition environments.
We prepared the above graphic along with a full explanation of DOD's Cyber Operations with the help of the U.S. Government Accountability Office for use in the 2nd edition of my book Inside Cyber Warfare: Mapping the Cyber Underworld (O'Reilly Media) when it's published later this year or early 2012.
    Add to Cart View detail

    Senin, 06 Juni 2011

    Was The RSA-Lockheed-L-3 Breach Over A $2.6B DHS Contract?

    Site Plan New DHS Building
    Since my original post on the Lockheed Martin / Prime contractors breach which I and other security researchers connected to the EMC RSA breach (a fact that EMC has now conceded to), I've been investigating possible motives for this multi-faceted attack. Its always been my belief that RSA's technology was not the primary target but a means to an end. And that "end" apparently involved breaching the networks of multiple Department of Defense contractors: Lockheed Martin, L-3 Communications, and allegedly Northrop Grumman. Other primes mentioned as possibilities by Reuters included General Dynamics, Boeing, and Raytheon.

    If RSA was stage one of a multi-stage operation, that would suggest that Lockheed, L-3, and Northrup Grumman as the targets would have something else in common besides just being DOD contractors. Since it's my belief that the EMC RSA attack started earlier than March, 2011 and took some planning prior to its launch, I began looking for contract awards in mid to late 2010 that involved the three victim companies. I found a couple of possibilities that warranted further consideration but then I came across this news item from November 8, 2010: 4 competitors protest award of $2.6 billion IT contract to Northrop Grumman

    The award, which is now up for re-bidding (GSA solicitation GST0011AJ0021) is for the crown jewels of the new Department of Homeland Security headquarters - building the infrastructure which will support information technology, telecommunications, security, and building management systems. The contractors who filed protests with GAO are Lockheed Martin, General Dynamics, Serco and L-3 Communications. Of the five companies involved, Lockheed and L-3 are confirmed attack targets, Northrop is an alleged target and General Dynamics is a possible target. Serco hasn't been named by any sources familiar with this attack but they also don't use RSA SecurID tokens; opting instead for Signify, one of RSA's competitors for two factor authentication. 

    In order to compete for an award, companies must submit detailed technical proposals in written and oral form with an accompanying slide deck. DHS' acquisition schedule for the competing vendors corresponds with the known dates of the attacks:
    DHS TIP Industry Day Deck: (Slide 39)
    According to the schedule on slide #39, vendor written proposals were due in April and Orals were due in May. L-3 Communications announced active targeting with penetration attacks on April 6, 2011 while Lockheed reported that its breach commenced on May 21.  Late May was also the time of the alleged attack against Northrop Grumman. 

    The information and communications infrastructure of the new DHS headquarters would certainly be a target of interest for foreign intelligence services like the FSB. Even the technical proposals from competing DOD contractors would contain valuable information. The level of detail asked for by DHS is fairly intensive as evidenced by the following slide which breaks out one of the eight required tasks: 
    Task 2: Requirements Analysis and Design (slide 26)
    If the November, 2010 article in the Washington Post triggered the planning stage of the operation, it offered sufficient time for an adversary to discover that the vendors shared the same two factor authentication technology; perform social engineering research on the target companies' employees, probe company websites for vulnerabilities, and craft customized attacks if needed. This doesn't require the resources of a nation state. Any experienced Eastern European hacker crew could pull it off with a relatively low budget. The upside however is huge. The information contained in those DHS technical proposals could be sold to multiple foreign governments and net the crew a seven figure or eight figure payday. And considering the scope of the DHS HQ project (the largest federal construction job since the Pentagon was built in the 1940's according to the Washington Post), this probably isn't the end of it. Whichever prime contractor wins the TIP contract, along with its sub-contractors, will almost certainly become the next targets to be compromised.


    Add to Cart View detail

    Most View Product

    Contact Online

    Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
    Template Clone Script ID