Friday, May 22, 2015

Public and Private Cyber Collaboration

With an increasing number of cyberattacks directed against the United States, the need for a national comprehensive cybersecurity policy is critical.  The extent of this effort has been the creation of guidance by the federal government often without Congressional approval or private sector mandates.  Given the fact that most of America’s critical infrastructure is in the hands of private entities, this must change.  Corporations have largely pushed back against any cybersecurity mandates and without official legislation, the “relationship between businesses and the government has been mostly all carrot and no stick” (Ravindranath, 2015).

As a result of this correlation, the federal government has become increasingly proficient at utilizing the carrot.  This comes in the form of government entities such as the National Cybersecurity Center of Excellence; an organization with the lofty goal of working with businesses to improve their cybersecurity posture, often by helping them find commercially available technology.  Similarly, the Commerce Department’s National Institute of Standards and Technology (NIST) has spent the last few years churning out reams of policy papers advising best practices for virtually every area of information technology.  These policies are increasingly seen as seminal works in the field of computer security with their guidance being implemented by a growing number of private organizations alongside their public counterparts. 

One of NIST’s most comprehensive and widely utilized guides, is 800-53 (Security and Privacy Controls for Federal Information Systems and Organizations).  In this 500 page publication, the Commerce Department’s regulatory agency details a framework for designing an organizational cyber policy. 


The publication goes further by discussing 17 security control categories and then detailing over 250 individual security controls that organizations should objectively consider implementing. 


All of this adds up to an impressive body of work that no one outside the federal government is required to abide by.  It would appear however that some private entities see the benefit in adopting a standard set of cybersecurity principles. 

“Last week, Department of Homeland Security’s cybersecurity and communications office’s chief technology officer, Peter Fonash, said businesses need to be able to exchange up-to-the-minute threat information with the government for instance.  Dodson said her team is working to hand over some projects to the private sector.  For instance, NIST’s Center for Excellence jump-started the Identity Management Ecosystem Steering Group, which aims to combat fraudulent online identities, beginning in 2012.  Today, the group is made up of commercial companies, including Microsoft and IBM.  That group is meant to serve as a forum in which members can discuss and implement better ways to conduct and verify online credentials and transactions” (Ravindranath, 2015).

References
NIST. (2013). Security and Privacy Controls for Federal Information Systems and Organizations. Retrieved from http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

Ravindranath, M. (2015). Nextgov. NIST official: Businesses need to take more responsibility for cybersecurity. Retrieved from http://www.nextgov.com/cybersecurity/2015/05/nist-official-businesses-need-take-responsibility-their-own-cybersecurity/113332/



Tuesday, April 28, 2015

Putin Hacks America...again

In early April, the White House announced that Russian hackers had penetrated the White House through a seemingly innocuous email account.  Their target was the "Executive Office of the President" network; an unclassified yet highly sensitive system that processes among other things, President Obama’s emails, schedule and policy notes.  The attack bears the same hallmarks of a similar intrusion last year at the State Department.  Based on the level of sophistication, U.S. officials believe the Russian government is the culprit (Sales, 2015).  If this incident wasn’t serious enough, a couple weeks after the White House disclosure, officials were forced to admit that Russian hackers had also accessed an unclassified Pentagon network in early 2015.  The breach which was only recently declassified illustrated another sophisticated cyberattack against the U.S. government most likely perpetrated by Moscow (Crawford, 2015).  These attacks targeted the same weak link in the cybersecurity chain: Us.

Much like the Sony Pictures attack, officials believe the White House incident was perpetrated through a successful spear-phishing campaign.  For the uninitiated, this type of attack entails the detailed targeting of a high-level official with a malware laden email.  Often times, the official mistakenly opens an infected attachment and the rest is history.  This type of attack is so successfully employed that Wired believes 91% of hacking attacks begin with a phishing email (Sales, 2015).  The Pentagon attack on the other hand appears to be a little less straight-forward.  Understanding that the Department of Defense has only recently declassified portions of the incident, it is unclear how exactly hackers gained access to a highly-guarded yet unclassified Pentagon network.  Initial reports point to an unpatched vulnerability, which indirectly leads us back to inadequate human involvement in the security chain.  Given the fact that the Office of the National Counterintelligence Executive has labeled Russia “a national long-term strategic threat to the United States,” it would seem to be a foregone conclusion that we as security professionals need to increase our training and awareness (Cilluffo & Cardash, 2015). 


References
Cilluffo, F. J. & Cardash, S. L. (2015). How to stop Putin hacking the White House. Newsweek. Retrieved from http://www.newsweek.com/how-stop-putin-hacking-white-house-321857

Crawford, J. (2015). Russians hacked Pentagon network, Carter says. CNN. Retrieved from http://www.cnn.com/2015/04/23/politics/russian-hackers-pentagon-network/


Sales, F. (2015). White House hack: By way of Russia with help from spear fishing. Tech Target. Retrieved from http://searchcio.techtarget.com/news/4500244197/White-House-hack-By-way-of-Russia-with-help-from-spear-phishing

Wednesday, March 25, 2015

Canada's Cyber Offensive

In yet another bombshell released from Edward Snowden’s cache of top secret documents, it turns out Canada has an ambitious and surprisingly advanced offensive cyber capability.  This revelation comes on the heels of an upcoming vote to authorize new powers for the nation’s cyber agencies.  Among the documents published was a confidential presentation by Canada’s intelligence agency Communications Security Establishment (CSE) in 2011.  The CSE, which is Canada’s version of the NSA outlines how by 2015, it “will seek the authority to conduct a wide spectrum of effects operations in support of our mandates” (False flags & cyber wars, 2015).  This authority comes in the form of the C-51 bill which is currently being pushed through the Canadian parliament by the nation’s conservative party.  The legislation has been proposed as a way to combat terrorism, but skeptics view this as another attack on personal privacy.  As a result, filibusters by opposition leaders and public demonstrations have been staged to oppose the bill.  Snowden’s leaked presentation details 32 techniques able to be employed by the CSE in both the defense and offensive arenas.  Some of the more notable weapons in the Canadian cyber-arsenal include:

Malware. The CSE has reportedly been building malware to bring down the networks of rival organizations. The malware was developed by the NSA as part of its QUANTUM hacking project. In fact, the NSA and the CSE have been collaborating for quite a while, gaining access and exploiting computer network targets in the Middle East, North Africa, Europe, and Mexico, say the documents. 

Deceiving attacks. The CSE used what are called “deception techniques” to attack networks while making it seem like they came from other organizations.  For instance, it directed victims to a fake site, then potentially used that site to “siphon classified information about computer networks.”  Additionally, the report says Canada launched attacks to block website traffic, redirect money transfers, and even delete emails.

Social engineering. The country also used a variety of social engineering methods to destroy other organizations' reputations.  Tactics included faking online poll results, posting fake Facebook messages, and even diffusing “negative information about targets online to damage their reputation.”

Network targeting. Lastly, the report indicates Canada's cyber-toolkit targeted specific networks to either garner foreign intelligence or inflict network damage.  Targets may have been aimed at "electricity, transportation or banking systems” (Weissman, 2015).

According to the leaked files, these capabilities have potentially already been employed against the Brazilian mining and energy ministry.  Leaked NSA documents in 2013 detail alleged CSE attacks against cellphones using specially crafted malware entitled WARRIORPRIDE.  Similarly, Canada is known to employ a government sponsored botnet to anonymously attack international targets.  These facts have prompted accusations of industrial espionage by at least one foreign nation against Canada and the United States (False flags & cyber wars, 2015).  As a security professional this level of public outrage is understandable but not new.  What I find more interesting about Snowden’s revelation is the level to which the Canadian government has risen in the field of attacks and espionage in the cyber realm.  I guess it shouldn’t come as a surprise that an advanced nation in the 21st century employs these tactics.  For whatever reason though, seeing overly polite Canada do it has been a real eye-opener.

References
False flags & cyber wars: New Snowden leaks reveal Canada spy agency’s deception toolbox. (2015). RT.com. Retrieved from http://rt.com/news/243397-canada-cyber-spying-snowden/

Weissman, C. G. (2015). Here’s how Canada tapped into computers and phones around the world. Business Insider. Retrieved from http://www.businessinsider.com/canada-tapped-into-computers-and-phones-around-the-world-2015-3


Tuesday, February 10, 2015

Mark Burnett and the Ethics of Hacking

In 2015, a security consultant named Mark Burnett published 10 million passwords along with their corresponding usernames.  His rationale was that doing so is necessary to ensure the continued access to hacking-related information. Until recently, cybersecurity researchers have only been given access to passwords without usernames, which Burnett argues provides a serious detriment to the field of computer security.  Passwords are ubiquitous in the IT industry and only through an examination of how individuals choose them can researchers craft better countermeasures against hackers.  Or so the rationale goes.

The major problem with Burnett’s justification is the illegality of what he did.  Given the recent five-year sentence handed down to Anonymous hacker Barrett Brown for a similar activity, it is understandable why Burnett might question his future as a free man.  To help clarify Burnett’s position as well as that of the federal government, it is critical to establish a few key points in what I can only imagine is an upcoming criminal case.  The passwords in question appear to have been collected from other notable hacks leaked online.  Advertised as a security consultant, Burnett argues that he collected this data with the white-hat hacker intent of helping to strengthen the concept of passwords for the collective good.  That being said, many researchers shy away from publishing passwords with their corresponding usernames because these pieces of data combined create an authentication feature.

In the case of Anonymous’ Barrett Brown, his five year sentence was predicated upon the fact that he trafficked in stolen goods (aka, the passwords) similar to Mark Burnett.  It should be noted however that this charge was later dropped with the government opting to go after Brown for his association with Anonymous.  Additionally, the Obama administration has proposed changes to the Computer Fraud and Abuse Act which would further outlaw the “publication of links to public password dumps even if the person making the link had no intent to defraud” (Goodin, 2015).

According to Burnett, these recent developments in the field of cybersecurity law has forced researchers and journalists alike to stop reporting on hacks entirely for fear of federal retribution.  If posting links to publicly available hacked data lands you in prison, then why would you take the risk?  According to Burnett,

“Including usernames alongside passwords could help advance what's known about passwords in important ways. Researchers, for instance, could use the data to determine how often users include all or part of their usernames in their passwords. Besides citing the benefit to researchers, Burnett also defended the move by noting that most of the leaked passwords were "dead," meaning they had been changed already, and that all of the data was already available online.”


References
Goodin, D. (2015). Fearing an FBI raid, researcher publishes 10 million passwords/usernames. ArsTechnica. Retrieved from http://arstechnica.com/security/2015/02/fearing-an-fbi-raid-researcher-publishes-10-million-passwordsusernames/




Tuesday, December 23, 2014

North Korea-The Newest Cyber Threat in Town

Certainly by now, the world has heard about the infamous cyberattack against Sony purportedly carried out by North Korea.  Although numerous denials have been given, the attack appears to have been perpetrated by a despotic regime in retaliation for the simple act of making a satirical movie.  I’ll let the ridiculousness of that statement sink in for a minute.  Now onto the practical matter at hand; how can the world’s most isolated nation pull off such a technologically advanced attack?  To put this in perspective, consider the following.  If you do a web search for “North Korea at night”, you can plainly see the lack of electricity or at least visible lighting as compared to its southern neighbor.  I remember standing on the DMZ looking into North Korea.  The normally wooded area was clear cut by the residents and soldiers not to provide a defensive line of sight, but for a fuel source....because there was nothing else.  Despite these limitations, North Korea actually has a fairly well developed cyber warfare capability. 

According to a 2014 report published by Hewlett-Packard researchers North Korea is seriously committed to the cyber aspect of their national defense.  The hermit kingdom’s Unit 121 is considered to be one of the world’s premier cyber organizations, third in size only behind the United States and Russia.  South Korea estimates this team is comprised of anywhere between 3000 and 6000 staff.  According to the HP report, some of the more notable hacks North Korea has managed to pull off include:

(2004) Gained access to 33 of 80 South Korean military wireless communication networks. 

(2004) Hacked into the US State Department, US Defense Department, and South Korean defense networks during discussions over nuclear missile testing.

(2007)  Tested a logic bomb which led to the UN ban of certain pieces of hardware to North Korea.

(2009)  DarkSeoul DDoS targeted South Korean and U.S. government, media outlets, and financial websites.

(2011) North Korea disrupted South Korean GPS signals, attempted a DDoS attack against Incheon airport and Nonghyup bank.

(2013)  DarkSeoul DDoS attacked South Korean government’s DNS server and South Korean financial institutions. (Osborne, 2014)

The Sony attack however appears to be the metaphorical straw.  Shortly after the hack and Sony’s subsequent decision to pull “The Interview” from release, North Korea’s limited access to the Internet was cut off for approximately 10 hours.  It is unknown whether this was a deliberate cyberattack against the regime or simply technical difficulties with the nation’s four official networks (Robertson & Strohm. 2014).  Researchers point out however that this occurrence is definitely out of the norm.  And while the U.S. State Department won’t comment on the reports, there appears to be no lack of likely actors willing to target the regime.  Anonymous made headlines in 2013 for its #OpNorthKorea campaign which targeted various North Korean websites.  In the end, the Sony hack illustrates the larger issue at hand; the next battlefield will undoubtedly occur in cyberspace.

References
HP Security Research. (2014). Profiling an enigma: The mystery of North Korea’s cyber threat landscape. Retrieved from http://h30499.www3.hp.com/hpeb/attachments/hpeb/off-by-on-software-security-blog/388/2/HPSR%20SecurityBriefing_Episode16_NorthKorea.pdf

Osborne, C. (2014). North Korea cyber warfare capabilities exposed. ZD Net. Retrieved from http://www.zdnet.com/article/north-korea-cyber-warfare-capabilities-exposed/

Robertson, J. & Strohm, C. (2014). North Korean internet access restored after hours long outage. Bloomberg. Retrieved from http://www.bloomberg.com/news/2014-12-22/north-korea-undergoing-internet-outage-network-researcher-says.html

Friday, November 28, 2014

China and the Cybersecurity Myth

In the wake of emerging cyberattacks against the National Oceanic and Atmospheric Administration (NOAA) and the U.S. Postal Service (USPS), China yet again emerges as the prime suspect.  Given this latest round of hacks against the United States, it should come as no surprise then that “the U.S.–China cybersecurity talks at the Asia–Pacific Economic Cooperation (APEC) largely failed” (Inserra, 2014).  The failure could also have something to do with the United States’ indictment of five Chinese PLA military members; which further chilled the relationship between the two super-powers. 

In the most recent hacks, the USPS announced that “800,000 employees had their personal data stolen including names, addresses, and Social Security numbers while the NOAA reported that four websites were compromised, but it is unknown if any data was stolen.”  To further illustrate the situation Robert Anderson, executive assistant director of the Criminal, Cyber, Response, and Services Branch of the FBI told the Senate Homeland Security Committee in September 2014 that “it’s likely that every federal department has been hacked”  (Inserra, 2014).  In the wake of an apparently never-ending cyberattack most likely purported by China, it would seem direct negotiations would be the place to start.  Alas, the U.S. and China made little progress when President Obama and Chinese President Xi Jinping met at APEC this year.  While China emphasized the desire to coordinate on matters of cyberterrorism, the United States was more concerned with “the importance of protecting intellectual property as well as trade secrets, especially against cyber threats” (Bennett, 2014).  Unfortunately, as Assistant Secretary for Policy at the Department of Homeland Security Stewart A. Baker noted, “China has been unapologetic about its activities when confronted by U.S. officials” (Inserra, 2014).  I would take this diplomatic statement one step further to say that the theft of intellectual property, especially property involving defense related materials, is a national strategy for China.  Whether the target is the F-35 stealth fighter (Gertz 2014) or a myriad of other civilian and commercial technologies (Frizell, 2014), the outcome is the same.  China will not stop.  I have long held the belief that in a world where a cyberattack costing thousands can net technologies representing billions, why would any nation stop?

References
Bennett, C. (2014). US, China see little progress on cybersecurity. The Hill. Retrieved from http://thehill.com/policy/cybersecurity/223865-us-china-see-little-progress-on-cybersecurity

Frizell, S. (2014). Here’s what Chinese hackers actually stole from U.S. companies. Time. Retrieved from http://time.com/106319/heres-what-chinese-hackers-actually-stole-from-u-s-companies/

Gertz, B. (2014). Top Gun takeover: Stolen F-35 secrets showing up in China’s stealth fighter. The Washington Times. Retrieved from http://www.washingtontimes.com/news/2014/mar/13/f-35-secrets-now-showing-chinas-stealth-fighter/?page=all

Inserra, D. (2014). Cybersecurity: Time for the U.S. to Stop Negotiating with China and Start Acting. The Daily Signal. Retrieved from http://dailysignal.com/2014/11/24/cybersecurity-time-u-s-stop-negotiating-china-start-acting/

Tuesday, October 21, 2014

Anonabox and the Growing Demand for Privacy


I have a few colleagues that are aficionados of the crowd-funding site "Kickstarter." Fascinated by the concept for both its ability to fund new technologies as well as from a pure business standpoint, I was intrigued.  So I began looking for a project I could invest in and eventually came across the Anonabox. 

Billed as a “$45 router that would run all a user’s online traffic over the anonymity network Tor,” the project advertised an easy-to-use solution to today’s increasing privacy concerns (Greenberg, 2014).  With a modest funding goal of only $7,500, many were surprised that Anonabox raised over half a million dollars in less than a week.  The project’s founder August Germar seemed to have tapped into a growing desire for discretion in an increasingly prying world.  I took a look at the Kickstarter site and watched the fairly compelling sales video and I was intrigued.  Although I’ve spent 50 bucks on more frivalous purchases, my hesitation in automatically hitting the “back this project” button was the obvious lack of technical specs about the device.  After all Germar claimed the project would be open-sourced, where were the details? 

Apparently, I was not the only potential investor with these questions.  A few days after the project was launched, funders began to unravel Germar’s claims.  What started out as a custom hardware/software solution was eventually determined to be somewhat of  scam.  As it happens the hardware was actually an off-the-shelf Chinese router (roughly $20) and the open-source software was determined to be full of potential security vulnerabilities including a hardcoded root password and default settings.  The project was eventually scrapped with the following explanation provided by Germar:

“In an email to the project’s investors, Kickstarter told backers only that ‘a review of the project uncovered evidence that it broke Kickstarter’s rules.’  Those rules, the email continued, prohibit ‘offering purchased items and claiming to have made them yourself,’ ‘presenting someone else’s work as your own’ and ‘misrepresenting or failing to disclose relevant facts about the project or its creator’ (Greenberg, 2014).

The Anonabox Kickstarter campaign illustrated a number of interesting facts.  With increasingly intrusive governments across the globe, people are craving privacy more than ever.  This desire can even transcend to the dillusional in some cases.  Even after the project was shown to be riddled with inconsistencies, a lot of people still sought to fund the technology.  The one positive take-away from this is that even if you’re not paranoid about your government, securing your web traffic is just plain smart.  Whether you’re shopping online while sitting in a Starbucks or connecting to your hotel’s Wi-Fi while on the road, you should never feel digitally secure.  As the need and demand for this type of security will only increase in the digital future, rest assured more projects like this will arise.

And I’m still on the lookout for my first Kickstarter investment. 

References
Greenberg, A. (2014). Kickstarter Freezes Anonabox Privacy Router Project For Misleading Funders. Wired. Retrieved from http://www.wired.com/2014/10/kickstarter-suspends-anonabox/