The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label kaspersky. Tampilkan semua postingan
Tampilkan postingan dengan label kaspersky. Tampilkan semua postingan

Minggu, 08 Desember 2013

If You Missed Suits and Spooks NY, Here It Is On Video


O'Reilly Media, the publisher of my book Inside Cyber Warfare, has produced a video compilation of our Suits and Spooks event. I'm proud to say that this is the first non-O'Reilly conference that they have produced for sale and it looks great. It doesn't include every speaker because some of the talks were under Chatham House rules, but here are the speakers that are included:
  • The Top 50 Non-state Hacker Groups in the World - Christopher Ahlberg (CEO of RecordedFuture)
  • Out of the Mountains: A Future of Feral Cities, Urban Systems Under Stress, and Increasing Overlaps Between the Real and Virtual Worlds - David Kilcullen (CEO of Caerus Associates)
  • Emerging Bad Actors in the Virtual and Physical Worlds (Jeffrey Carr, Moderator with Dr. David Kilcullen, Jonathan Hutson, Thomas Dzieran, Aaron Weisburd, Peter Mattis, and John Scott-Railton)
  • How to Survive a Surveillance-friendly Environment - Mike Janke (Co-founder, CEO of Silent Circle)
  • Should Defensive Strategies be Specific to the Threat Actor or Generalized for all Threat Actors? (Jeffrey Carr, Moderator with Pierre-Marc Bureau (ESET), Derek Manky (Fortinet), Roel Schouwenberg (Kaspersky), Chris Coleman (LookingGlass), Brian Carrier (Basis Technology))
  • Real-time Depiction of the Global Cyber Threat Landscape - Chris Coleman
  • Icefog: Mercenary Hackers Who Focus on Supply Chain Attacks in Asia - Roel Schouwenberg
  • Joseph Kony, the LRA and Elephant Poaching in Africa - Jonathan Hutson
The complete series is only $149. Here's where to order. We're going to be offering this again for Suits and Spooks DC so please let me know what you think.
Add to Cart View detail

Rabu, 16 Januari 2013

Has a Foreign Intelligence Service Been Targeting Russian Embassies?

Yesterday I posed the theory that the Russian Business Network (RBN) was behind the Red October attacks however in the interest of alternative analysis, I'd like to propose a different theory that also fits the facts contained in Kaspersky's report; that a Foreign Intelligence Service has been targeting Russian and CIS embassies.

Kaspersky's FAQ on ROCRA says that it was brought to their attention by a "partner" who prefers to remain anonymous. Considering that the primary target of ROCRA were Russian embassies and government agencies, that un-named partner was most likely the FSB. After all, Kaspersky Labs does significant business with the Russian government according to Noah Shachtman's Wired profile on Eugene Kaspersky:
One of GREAT’s frequent partners in fighting cybercrime, however, is the FSB. Kaspersky staffers serve as an outsourced, unofficial geek squad to Russia’s security service. They’ve trained FSB agents in digital forensic techniques, and they’re sometimes asked to assist on important cases.
The Red October report listed many embassies in multiple countries as victims but didn't identify whether those were Russian embassies or those of other nation states. Since the malware was looking for Cyrillic characters in documents, it makes sense to assume that the target was Russia's embassies in foreign countries. It would be nice if GREAT would confirm or deny whether that was the case.

Many of ROCRA's command and control servers were registered with Russian registrars. However, Russian law and regulations require the registrant to provide accurate contact information and to confirm that information with an authoritative document (something that we in the U.S. should also require, but don't).  Normally this would be a Russian citizen’s internal passport. So the perpetrator was either using compromised documents (Russian passport numbers and tax IDs have been posted on Runet) to obtain domain names or the websites themselves were compromised bots.

As far as which FIS might be responsible, there's no way to say but there's certainly no lack of suspects. The use of Acid Cryptofiler suggests that it might be a NATO or EU member country. 
Add to Cart View detail

Senin, 14 Januari 2013

RBN Connection to Kaspersky's Red October Espionage Network

Kaspersky made an astonishing announcement today with its discovery of a sophisticated cyber espionage network (most likely Russian) that has been operating since May 2007 and continues to this day. It has successfully infiltrated embassies, research organizations, military and government agencies, energy facilities (including nuclear power plants) predominantly in the Commonwealth of Independent States, India and countries in Central Asia, among many others.

The developers behind this campaign have built a toolkit similar to Flame but more sophisticated which Kaspersky researchers have named ROCRA (short for Red October). Some of the key functionalities which make this toolkit stand out as unique are:
  • The attackers have been active for at least five years, focusing on diplomatic and governmental agencies of various countries across the world. Information harvested from infected networks is reused in later attacks. For example, stolen credentials were compiled in a list and used when the attackers needed to guess passwords and network credentials in other locations. To control the network of infected machines, the attackers created more than 60 domain names and several server hosting locations in different countries (mainly Germany and Russia). The C&C infrastructure is actually a chain of servers working as proxies and hiding the location of the true -mothership- command and control server.
  • The attackers created a multi-functional framework which is capable of applying quick extension of the features that gather intelligence. The system is resistant to C&C server takeover and allows the attacker to recover access to infected machines using alternative communication channels.
  • Beside traditional attack targets (workstations), the system is capable of stealing data from mobile devices, such as smartphones (iPhone, Nokia, Windows Mobile); dumping enterprise network equipment configuration (Cisco); hijacking files from removable disk drives (including already deleted files via a custom file recovery procedure); stealing e-mail databases from local Outlook storage or remote POP/IMAP server; and siphoning files from local network FTP servers.
According to Kaspersky's report, the oldest domain name used in the Red October network was registered in November, 2007, and the newest in May, 2012. The November, 2007 date immediately rang a bell in my memory as the date that the Russian Business Network went dark (November 4, 2007) and temporarily moved operations to China. Then, after a few weeks, they disappeared again.

The developers behind ROCRA, who are Russian, are comfortable using Chinese malware and adapting it for their own use according to the Kaspersky report. This fits the RBN profile to a 't'. I ran 13 IPs listed in Kaspersky's report against the RBN list maintained by James McQuade and found matching IP blocks for five of them:

Malicious servers
178.63.208.49  matches to 178.63.
188.40.19.247 matches to 188.40.
78.46.173.15 matches to 78.46.
88.198.30.44 matches to 88.198.

Mini-motherships
91.226.31.40 matches to 91.226.

It has been my belief for many years that the RBN has a working relationship with the Russian government; that it disappeared from view when the FBI sought the assistance of the FSB to shut down their operations in 2007 (as detailed in chapter 8 of my book); and that it has continued operating below the radar all this time. It provides distance and deniability to the FSB for certain offensive cyber operations and, in exchange, the FSB allows the RBN to operate as a criminal enterprise; a portion of which involves selling the data that it steals to whomever is interested.

Red October is already the most significant find of the new year. If, in fact, Kaspersky has uncovered an RBN-controlled espionage ring, it's going to be one of the most important discoveries of the decade.


Add to Cart View detail

Rabu, 21 November 2012

France Throws Cyber Stones From Its Glass House

Source: L'Expansion.L'Express.fr 20 NOV 2012
The government of France shouldn't be so quick to charge the U.S. with being responsible for the Flame malware found on President Sarkozy's computer. Kaspersky Lab had remarkably little evidence to support their charge that it was created by the team that created Stuxnet and Duqu, and CrySys Labs said that it probably wasn't created by the Stuxnet/DuQu team.

Further, France is in no position to throw stones. It's use of cyber espionage operations is well-known inside the U.S. Intelligence Community as well as by the German gov't who consider them a more severe risk to intellectual property theft than Russia or China. France's state-owned energy firm EDF also conducted cyber espionage attacks against Greenpeace.

Related:

Report: French officials accuse US of hacking Sarkozy's computers
Votre Secrets, Monsieur? "The idea of the French using their intelligence service to obtain scientific, economic, and technological information from friendly countries is not new."
Add to Cart View detail

Jumat, 12 Oktober 2012

U.S. SECDEF on Attribution - A Little Too Optimistic?


U.S. Secretary of Defense Leon Panetta gave a speech on Thursday, October 11, 2012 at the Business Executives for National Security (BENS) Eisenhower Award dinner in New York City where he made the following statement:
In addition to defending the Department’s networks, we also help deter attacks. Our cyber adversaries will be far less likely to hit us if they know we will be able to link them to the attack, or that their effort will fail against our strong defenses. The Department has made significant advances in solving a problem that makes deterring cyber adversaries more complex:the difficulty of identifying the origins of an attack. Over the last two years, the Department has made significant investments in forensics to address this problem of attribution, and we are seeing returns on those investments. Potential aggressors should be aware that the United States has the capacity to locate them and hold them accountable for actions that harm America or its interests.
With great respect for our former Director of Central Intelligence, now SECDEF, I don't believe that we're anywhere near being able to identify sophisticated adversaries in cyberspace that extends beyond being able to give code names to anonymous hacker groups or recognizing certain TTPs. For one thing, five seconds before Secretary Panetta made the above remarks he said "Moreover, DoD is already in an intense daily struggle against thousands of cyber actors who probe the Defense Department’s networks millions of times per day." So clearly if we have "made significant advances to link our cyber adversaries to an attack" and we're still fending off thousands of cyber actors probing DoD networks every day, then someone didn't get the memo!

In fairness, the Secretary didn't say that we are able today to solve the attribution problem. He said that we're making "significant advances" which is too nebulous a phrase to have a fact-based discussion about. The reason why I'm skeptical is because attribution is the kind of hard challenge that DOD farms out to private contractors, who sub-contract that work out to specialists at boutique security firms and I know a lot of those firms. They're all still focused on finding an answer by focusing on the forensics, and the answer won't ever be found through pure forensic research. Why? Because everything that we know about forensics is also known by our adversaries thanks to 900 security cons held worldwide annually and because our adversaries in cyberspace are highly skilled.

It's also ironic that while the SECDEF talks about our growing ability to deter through attribution, that it was the U.S. who was caught conducting a cyber-sabotage operation against Iran's Natanz nuclear fuel enrichment plant, and is suspected in two other high profile cyber attacks (DuQu and Flame). If anyone has demonstrated their ability to disguise their own cyber attacks while attributing the attacks of others, it would be Russia. Many of the U.S. security companies who promote their ability to identify bad guys to the DOD and IC never seem to catch Russia doing anything, yet Kaspersky Labs produces report after report post-Stuxnet on malware that seems to have originated with the U.S. Perhaps we could solve our attribution problem by hiring more Russian security engineers.


Add to Cart View detail

Rabu, 01 Agustus 2012

Russia's Kaspersky Labs to Develop a Secure O/S for Critical Infrastructure and Military Use

A Russian IT news service has reported that Kaspersky Labs is developing its own secure operating system for use in industrial control systems. One of Eugene Kaspersky's competitors, Renat Yusupov of Kraftway, predicts that Kaspersky is "most likely developing a process control operating system where security is vital. It will probably be used in production, aviation, transport, energy, and may be used for military purposes."

While Kaspersky Labs hasn't made an official announcement, it has advertised for a requirements analyst and a senior security system designer for SCADA automated control systems. The ad which was listed with a HeadHunter website also said that Kaspersky is developing a new secure operating system.

Kaspersky has been in the forefront of investigating the Stuxnet, DuQu, and Flame attacks against Iran so the announcement that it's developing a secure O/S for the same types of systems that Stuxnet was designed to attack makes a lot of sense. Further, the quality of their security research plus the fact that Russia produces some of the best software engineers in the world suggests to me that this product could be in high demand - especially by its Rosatom customers. However, Kaspersky's close relationship with Russia's security services should also be considered by its potential customers. Under Russian law, the FSB could ask Kaspersky to include a backdoor in its secure O/S and the company would be required to comply. In fact, I can't imagine the FSB missing out on such an opportunity for intelligence collection against potential customers among the Commonwealth of Independent States, India, China, South Africa and others.




Add to Cart View detail

Selasa, 26 Juni 2012

2012 Russian Federation Information Security Reference

This book is an updated version of the 2011 Russian Federation Information Security Reference. It consists of original research conducted by Taia Global’s intelligence analysts who’ve recently retired from the U.S. intelligence community. The information was acquired through open sources on the Russian Internet (Runet) over a period of 8 months. Analysis was conducted by Taia Global’s veteran intelligence analysts who’ve recently retired from the U.S. intelligence community. This book is the culmination of many hundreds of hours of work. It contains findings that will be of use to corporate executives and their boards, law enforcement, intelligence agencies, and the military. It is unique in the marketplace and has been priced accordingly.
This book contains indepth reports on the following key agencies and one private company:
  • The Russia Federal Security Service (FSB) Center for Electronic Surveillance of Communications (TSRRSS) is responsible for the interception, decryption, and processing of electronic communications.  The Center—also known as the 16th Center (Directorate) FSB and Military Unit (Vch) 71330—is directly subordinate to the FSB Director.
  • Federal State Unitary Enterprises(FGUP) supervised by the Federal Security Service (FSB).  The list included the Orion Research and Development Center located in Moscow. Orion provides a range of information technology services including research, development, testing, consulting and certification of software and hardware.
  • FGUP STC Atlas is responsible for developing and certifying information technology (IT) security and cryptographic systems for the Russian government.
  • FGUP Center-Inform is the leading Russian state owned systems integration company for information technology (IT) and information security.
  • The Russian firm OOO Speech Technology Company (STC) provides surveillance and monitoring equipment.
  • Kaspersky Labs is licensed to provide classified work for the FSB and Defense Ministry.

To Order: US$159.00

Add to Cart View detail

Kamis, 31 Mei 2012

Flame, Russia and the ITU: A Geopolitical Agenda?

Both the ITU and the Russian government have been united in their interest to secure a global cyber warfare treaty since at least 2010. In recent weeks, Evgeniy (Eugene) Kaspersky has been increasing his rhetoric regarding a future cyber catastrophe and most recently his company was chosen by the ITU to investigate the Flame attack. That attack prompted today's press release by the ITU calling for "greater international collaboration" on cyber security matters at their upcoming conference in Dubai; a conference sponsored by Kaspersky Labs and where CEO Kaspersky will deliver the keynote:
Cybersecurity will be a major agenda theme at ITU Telecom World 2012 (Dubai, 14-18 October 2012), supported by key partners, one of whom is Kaspersky Lab. This agenda will explore issues such as mitigating risks posed by major coordinated cyber-attacks at the national level, the threats posed by malware such as Flame, and strengthening international cooperation. Kaspersky Lab CEO Eugene Kaspersky will deliver a Visionary Keynote speech at the event, outlining the magnitude and global nature of cyberthreats today.
 The Russian government has long been an advocate of an Information Warfare treaty limiting the use of cyber weapons and other acts of IW because it serves the interests of the Russian government (which has other means of conducting IW) while restricting cyber weapons development in the West. An excellent overview of the ramifications of such a treaty is Tom Gjelton's "Shadow Wars: Debating Cyber Disarmament".

Evgeniy Kaspersky, Kaspersky Labs, and the Russian Security Service

In November 2009, the Duma Committee on Security met on “the legislative, organizational and technical security aspects of the national info-communications infrastructure.”  The meeting included the Experts Council and several additional experts.  The invited experts were primarily senior government officials—including two from the FSB--with two from industry.  One was the President of MFI-Soft—the company that provides internet intercept systems to the FSB ISC—and the other was Evgeniy Kaspersky, Director of JSC Kaspersky Labs.

The President of MFI-Soft Alexander Ivanov is a former senior military communications officer.  MFI-Soft’s bread and butter are lawful intercept systems including SORM-1, SORM-2, and SORM-3.  MFI-Soft holds numerous licenses from the FSB and FSTEC for work on state secret information and encryption systems.  JSC Kaspersky Labs does as well.  While the Duma Security Committee did not post the meetings minutes, both companies are now involved in pushing Russian standards for the Commonwealth of Independent States (CIS).

Kaspersky Labs holds numerous security clearances authorizing work on projects involving state secret information (current list is posted at http://www.kaspersky.ru/license). The FSB only licenses two antivirus companies for work with state secret information; JSC Kaspersky Labs and Dr. Web. The licensing requirements effectively give JSC Kaspersky Labs and Dr. Web a monopoly on the Russian market since the IT market is dominated by the Russian Government and large industry closely aligned with the government.  Indeed, in 2009, the Russian Federal Antimonopoly Service (FAS) initiated proceedings against Kaspersky for possible violations of Russian antitrust laws, but no action appears to have been taken. Russian government tenders posted at zakpuki.gov.ru frequently specify JSC Kaspersky Labs products as required based on their FSB/FSTEC licenses.  The licenses are almost certainly critical to Kaspersky’s future.  According to Interfax, Kaspersky sales totaled $538 million in 2010 (last year for full data).  However, the revenue breakdown was stated in such a way that it is impossible to identify specific sources.

Summary
Kaspersky's elevation of Flame to a status that it doesn't deserve (a "highly sophisticated cyber weapon") takes on a new meaning when you examine the close relationship between Kaspersky Labs and the Russian government along with their relationship with the ITU and their parallel interests in promoting international cyber security agreements and cyber warfare treaties. Is Flame a means to a geopolitical end that favors those players interests? I think it is.

RELATED:
"Kaspersky's Problematic Flame Analysis"


Add to Cart View detail

Senin, 28 Mei 2012

Kaspersky's Problematic "Flame" Analysis

Countries infected by Flame (SecureList 28MAY12)
I'm beginning to wonder what's going on over at Kaspersky Labs. Eugene Kaspersky has begun sounding like Richard Clarke with his warning about mega-cyber disasters during his keynote address at the AUSCERT IT security conference. Then there's his repeating of the Russian government mantra that a cyber weapons treaty is needed (it's not). Now Kaspersky Labs has called a virus whose only purpose is to steal data a "cyber weapon". Come on, guys. You've done some terrific research in the past with DuQu. Now all of a sudden, it seems like you've become evangelists for a Russian government strategy to raise the stakes in cyber war rhetoric. Espionage is not warfare and never has been. Hence a tool created solely to conduct cyber espionage cannot also be legitimately called a cyber weapon.

You've also wrongly simplified the scope of cyber actors out there to three when it has never been that cut and dried:
Currently there are three known classes of players who develop malware and spyware: hacktivists, cybercriminals and nation states. Flame is not designed to steal money from bank accounts. It is also different from rather simple hack tools and malware used by the hacktivists. So by excluding cybercriminals and hacktivists, we come to conclusion that it most likely belongs to the third group.
You've conveniently failed to mention an important fourth category: mercenary hacker crews - principally from Russia and the Commonwealth of Independent States - who steal IP and sell it to both corporations and governments. Crews that would love a tool like Flame and who, in my opinion, are the most likely actors involved in using such a tool. If you'd be forthcoming with more information - such as Flame's Command and Control server URLs - a lot more could be learned about who may be behind this virus.

UPDATE (31 MAY 2012): See my related article "Flame, Russia and the ITU: A Geopolitical Agenda?"
Add to Cart View detail

Senin, 10 Oktober 2011

Cybersecurity Issues with Predators, Reapers, and Unmanned Aerial Systems

Creech Air Force Base UAV hangars
According to Wired, Creech Air Force Base has been struggling to clean its Reaper and Predator Ground Control Stations (GCS) of a persistent virus of unknown origin; perhaps something like TDL-4 which loads before the operating system, right at the beginning of the computer's boot-up sequence. This type of virus is almost impossible to get rid of. Whether its TDL-4 or something with similar behaviors, I spent the last few days researching Unmanned Aerial Systems (UAVs plus their ground control stations) and there are a few serious cybersecurity issues besides the 2009 unencrypted video feed controversy and the one Noah Shachtman reported about last Friday. Before we get to those, I think it's important to note that while there are only a few countries (U.S., Israel, Britain, France) who are using drones operationally in Afghanistan, there are over 50 who have built or bought them. I wouldn't be surprised to see this technology near the top of someone's list for targeted cyber-espionage.

Unencrypted mission control data feeds
On 20 Dec 2009, shortly after the news broke about unencrypted Predator video feeds, a security engineer using the alias "kingcope" posted an article to the Full Disclosure list entitled "Reading Mission Control Data Out Of Predator Drone Video Feeds". He pointed out that not only was the line of sight transmission unencrypted, but so was the Ku-Band satellite transmission which extends the range of interception far beyond just line-of-sight and that if the MPEG stream wasn't encrypted, then the metadata inside the stream was probably being transmitted in the clear as well. Both the mission control data and the video stream data are part of the MPEG stream and could be read using a free tool called LEADTOOLS.

According to the Air Force, they've known about the unencrypted video feeds for over 10 years, and that it'll be 2014 before that vulnerability is fixed. Presumably that'll include the unencrypted mission control data feed as well.


Internet Access
There shouldn't be any connection between the UAS network and public-facing Internet however at least one GCS that I looked at did utilize an Internet connection as part of its architecture: the Network Centric Ground System.

I assume that the above network architecture was not deployed at Creech AFB since the GCS stations would be handling classified data however it would be worth a look at how Creech AFB has connected its Ground Control Stations to the Global Information Grid. The volume of data handled is growing at an extremely rapid pace as are the number of analysts who are viewing it according to the New York Times. With the deployment of "Gorgon Stare", an incredible 1.8 gigapixel camera offering 12 simultaneous views of the target environment, the UAV firehouse must be more massive than ever. Whatever has infected the Creech GCSs could theoretically spread beyond Creech AFB via the GIG. Let's assume that the point of entry was one of the portable hard drives used to load map updates and transport mission videos. Once in the network, its infection path could include printer servers and other shared resources regardless of geography. In other words, other Air Force bases who are conducting analysis on this data may be exposed to the same virus that the Creech technicians are struggling with.  This could include Britain's Royal Air Force whose 39 Squadron use Creech AFB as ground control for their own fleet of UAVs. I assume that the Brits are conducting their own analysis of the video feeds which would stream from Creech's GCS, thus providing a means for the virus to possibly infect British networks.

Why Kaspersky?
One of the nagging questions that I had after reading Noah's article was why would the Creech AFB technicians go to Kaspersky? DISA's Host-Based Security System website references McAfee as a supporting vendor, not Kaspersky. One of my Twitter followers suggested that they might be dealing with TDL-4, a particularly nasty TDSS variant that was originally detected by Kaspersky and which they've dubbed the "most sophisticated threat today". That might explain why the technicians turned felt they needed to visit the Russian company's site even though no one has a patch for this; not even Kaspersky. Based upon its description and functionality, a TLD-4 infection would be a worst-case scenario for the U.S. Air Force because it means that their data is being exfiltrated to cybercriminals in a way that's extremely hard to detect:
TDSS uses a range of methods to evade signature, heuristic, and proactive detection, and uses encryption to facilitate communication between its bots and the botnet command and control center. TDSS also has a powerful rootkit component, which allows it to conceal the presence of any other types of malware in the system.
If it is TDL-4, no one has a way to remove it short of shit-canning the old hard drives and buying new ones. And speaking frankly, the Air Force appears to me to be a bit too relaxed about its vulnerabilities in cyberspace. It let its UAS data stream remain unencrypted for over 10 years because someone thought the enemy was too unsophisticated to know how to read it. Someone else apparently thought it was OK to make an exception on its removable media rule for UAV data transfer. And as far as its public response to this breaking story goes, a standard CYA response like the one Lt. Col. Tadd Sholtis gave - "We invest a lot in protecting and monitoring our systems to counter threats and ensure security, which includes a comprehensive response to viruses, worms, and other malware we discover" - is pretty meaningless in light of past events. Then there's the remarks of an unidentified senior Air Force official for Fox News who claimed that Wired's entire story was over-blown:
"The planes were never in any jeopardy of 'going stupid'," the source said, and the virus "is not affecting operations in any way ... it showed up on a Microsoft-based Windows system. We have a closed-loop system and heavily protected cockpits -- the planes were never in jeopardy."
I have no idea who this un-named source is or what article he thinks he read but it wasn't the article in Wired. There's not a single mention of planes being in jeopardy or "going stupid" in Noah Shachtman's article. If he can't get his facts straight about what the article said, why should anyone believe his assessment of the malware? Having met and spoken with many USAF officers involved in cyber including some General officers, I know that the Air Force is capable of better cybersecurity management. Hopefully this breach will spur some positive changes before any more damage is done.
Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID