Postage Stamp Chat Board & Stamp Bulletin Board Forum
 

World's No#1 place to discuss STAMP COLLECTING and PHILATELY!
 

ZERO cost to ANYONE  -  NO annoying ads everywhere!

It is currently Thu May 23, 2013 09:05:30 am

All times are UTC + 10 hours [ DST ]




Post new topic Reply to topic  [ 15 posts ] 
Author Message
 Post subject: Future Cyberwar
PostPosted: Tue May 01, 2012 13:00:36 pm 
Offline
I was online for our Birthday Number 5!
I was online for our Birthday Number 5!
User avatar

Joined: Thu Jul 01, 2010 05:39:49 am
Posts: 2238
Location: Canada
Web War II: What a future cyberwar will look like

By Michael Gallagher

BBC World Service

How might the blitzkrieg of the future arrive? By air strike? An invading army? In a terrorist's suitcase? In fact it could be coming down the line to a computer near you.

Operation Locked Shields, an international military exercise held last month, was not exactly your usual game of soldiers. It involves no loud bangs or bullets, no tanks, aircraft or camouflage face-paint. Its troops rarely even left their control room, deep within a high security military base in Estonia.

These people represent a new kind of combatant - the cyber warrior.

One team of IT specialists taking part in Locked Shields, were detailed to attack nine other teams, located all over Europe. At their terminals in the Nato Co-operative Cyber Defence Centre of Excellence, they cooked up viruses, worms, Trojan Horses and other internet attacks, to hijack and extract data from the computers of their pretend enemies.

The idea was to learn valuable lessons in how to forestall such attacks on military and commercial networks. The cyber threat is one that the Western alliance is taking seriously.

It's no coincidence that Nato established its defence centre in Estonia. In 2007, the country's banking, media and government websites were bombarded with Distributed Denial of Service (DDOS) attacks over a three week period, in what's since become known as Web War I. The culprits are thought to have been pro-Russian hacktivists, angered by the removal of a Soviet-era statue from the centre of the capital, Tallinn.

DDOS attacks are quite straightforward. Networks of thousands of infected computers, known as botnets, simultaneously access the target website, which is overwhelmed by the volume of traffic, and so temporarily disabled. However, DDOS attacks are a mere blunderbuss by comparison with the latest digital weapons. Today, the fear is that Web War II - if and when it comes - could inflict physical damage, leading to massive disruption and even death.

"Sophisticated cyber attackers could do things like derail trains across the country," says Richard A Clarke, an adviser on counter-terrorism and cyber-security to presidents Clinton and Bush.

"They could cause power blackouts - not just by shutting off the power but by permanently damaging generators that would take months to replace. They could do things like cause [oil or gas] pipelines to explode. They could ground aircraft."

Clarke's worries are fuelled by the current tendency to put more of our lives online, and indeed, they appear to be borne out by experiments carried out in the United States.

At the heart of the problem are the interfaces between the digital and physical worlds known as Scada - or Supervisory Control And Data Acquisition - systems.

Today, these computerised controllers have taken over a myriad jobs once performed manually. They do everything from opening the valves on pipelines to monitoring traffic signals. Soon, they'll become commonplace in the home, controlling smart appliances like central heating.

And crucially, they use cyberspace to communicate with their masters, taking commands on what to do next, and reporting any problems back. Hack into these networks, and in theory you have control of national electricity grids, water supplies, distribution systems for manufacturers or supermarkets, and other critical infrastructure.

In 2007, the United States Department of Homeland Security (DHS) demonstrated the potential vulnerability of Scada systems. Using malicious software to feed in the wrong commands, they attacked a large diesel generator. Film of the experiment shows the machine shaking violently before black smoke engulfs the screen.

Although this took place under laboratory conditions, with the attackers given free rein to do their worst, the fear is that, one day, a belligerent state, terrorists, or even recreational hackers, might do the same in the real world.

"Over the past several months we've seen a variety of things," says Jenny Mena of the DHS. "There are now search engines that make it possible to find those devices that are vulnerable to an attack through the internet. In addition we've seen an increased interest in this area in the hacker and hacktivist community."

One reason why Scada systems may be prone to hacking is that engineers, rather than specialist programmers, are often likely to have designed their software. They are expert in their field, says German security consultant Ralph Langner, but not in cyber defence. "At some point they learned how to develop software," he adds, "but you can't compare them to professional software developers who probably spent a decade learning."

Moreover, critical infrastructure software can be surprisingly exposed. A power station, for example, might have less anti-virus protection than the average laptop. And when vulnerabilities are detected, it can be impossible to repair them immediately with a software patch. "It requires you to re-boot," Langner points out. "And a power plant has to run 24-7, with only a yearly power-down for maintenance." So until the power station has its annual stoppage, new software cannot be installed.

Langner is well-qualified to comment. In 2010 he, along with two employees, took it upon himself to investigate a mystery computer worm known as Stuxnet, that was puzzling the big anti-virus companies. What he discovered took his breath away.

Stuxnet appeared to target a specific type of Scada system doing a specific job, and it did little damage to any other applications it infected. It was clever enough to find its way from computer to computer, searching out its prey. And, containing over 15,000 lines of computer code, it exploited no fewer than four previously undiscovered software errors in Microsoft Windows. Such errors are extremely rare, suggesting that Stuxnet's creators were highly expert and very well-resourced.

It took Langner some six months to probe just a quarter of the virus. "If I'd wanted to do all of it I might have gone bust!" he jokes. But his research had already drawn startling results.

Stuxnet's target, it turned out, was the system controlling uranium centrifuges at Iran's Natanz nuclear facility. There is now widespread speculation that the attack was the work of American or Israeli agents, or both. Whatever the truth, Langner estimates that it delayed Iran's nuclear project by around two years - no less than any air strike was expected to achieve - at a relatively small cost of around $10 million. This success, he says, means cyber weapons are here to stay.

Optimists say Stuxnet does at least suggest a scrap of reassurance. Professor Peter Sommer, an international expert in cyber crime, points out that the amount of research and highly skilled programming it involved would put weapons of this calibre beyond anyone but an advanced nation state. And states, he point out, usually behave rationally, thus ruling out indiscriminate attacks on civilian targets.

"You don't necessarily want to cause total disruption. Because the results are likely to be unforeseen and uncontrollable. In other words, although one can conceive of attacks that might bring down the world financial system or bring down the internet, why would one want to do that? You would end up with something not that different from a nuclear winter."

But even this crumb of comfort is denied by Langner, who argues that, having now infected computers worldwide, Stuxnet's code is available to anyone clever enough to adapt it, including terrorists.

"The attack vectors and exploits used by Stuxnet - they can be copied and re-used reliably against completely different targets. Until a year ago no one was aware of such an aggressive and sophisticated threat. With Stuxnet that has changed. It is on the table. The technology is out there on the internet."

One thing is for sure, he adds: If cyber weapons do become widespread, their targets will lie mostly in the west, rather than in countries like Iran, which have relatively little internet dependence. This means that the old rules of military deterrence which favoured powerful, technologically advanced countries like the United States do not apply: Responding in kind to a cyber attack could be effectively impossible.

This asymmetry is likely to grow, as developed countries become ever more internet-dependent. So far, the Internet Protocol format allows only 4.3 billion IP addresses, most of which have now been used. But this year, a new version is rolling out, providing an inexhaustible supply of addresses and so allowing exponential growth in connectivity. Expect to see far more machines than people online in the future.

In the home, fridges will automatically replenish themselves by talking to food suppliers; ovens and heating systems will respond to commands from your smartphone. Cars may even drive themselves, sharing GPS data to find the best routes. For industry, commerce and infrastructure, there will be even more reliance on cyber networks that critics claim are potentially vulnerable to intrusion.

"There will be practically infinite number of IP addresses," says former hacker Jason Moon. "Everything can have an IP address. And everything will have one. Now, that's great. But think what that's going to do for the hacker!"

In fact, it has already become a challenge for even sensitive installations, let alone households, to remain offline. Although military and other critical networks are supposedly isolated from the public internet, attackers can target their contractors and suppliers, who plug into the "air-gapped" system at various times. Somewhere down the food chain, a vulnerable website or a rogue email will provide a way in.

According to Richard Clarke, the mighty American armed forces themselves are not immune, since their command & control, supplies, and even some weapons systems, also rely on digital systems.

"The US military ran headlong into the cyber age," he says. "And we became very dependent on cyber devices without thinking it through. Without thinking that if someone got control of our software, what would we be able to do? Do we have backup systems? Can we go back to the old days?"

The answer it seems is no. A new form of weapon appears to be emerging. And the world may have to learn to adapt.


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Wed May 02, 2012 00:42:28 am 
Offline
I was online for our Birthday Number 3!
I was online for our Birthday Number 3!
User avatar

Joined: Sat Oct 24, 2009 02:07:21 am
Posts: 4582
Location: ǝɔɐld ǝɥʇ ɹǝʌo llɐ
This is why NSA, CIA, etc. are all over DefCon every year trying to recruit people.

I am not sure about these "IT specialists" though...sound more like blue teams and red teams to me.

Yea, there is a lot that can be one with computer. I never understood why people were always so paranoid that there are missing bombs around and stuff. Really, what's one or two or a dozen big bombs floating around out there in unknown hands when anyone with the motivation and a keyboard can just launch thousands aimed anywhere with the stroke of an F5 key.

It's why some people want kill-switch legislation.

_________________
'The world is indeed comic, but the joke is on mankind.' -H. P. Lovecraft


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Fri May 04, 2012 15:15:46 pm 
Offline
Mauve Shooting Star Posting MANIAC!
Mauve Shooting Star Posting MANIAC!
User avatar

Joined: Fri Sep 10, 2010 07:31:03 am
Posts: 4257
Location: Alamo, CA USA
If you want the bejebbers scared out of you, watch this TED talk:

Avi Rubin - All Your Devices Can Be Hacked

http://www.youtube.com/watch?v=metkEeZvHTg

_________________
German, German State and Saar Revenues Wanted...


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Fri May 04, 2012 15:55:38 pm 
Offline
I was online for our Birthday Number 5!
I was online for our Birthday Number 5!
User avatar

Joined: Wed Dec 02, 2009 11:59:47 am
Posts: 8449
Location: Goulburn NSW Australia
Why do people think this is a future war? It's been going on for years and costs trillions to control. The world is already at war, not cold, not hot, just hi tech.

_________________
Greg - Looking for Goulburn Australia Cancels and Grangemouth Scotland Cancels and Covers
Member of the S.T.A.M.P Club for Slightly Twisted And Mad Philatelists - Motto: "Bring back the lick!"


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Tue May 08, 2012 00:02:58 am 
Offline
GOLD Star Super Posting Board Member
GOLD Star Super Posting Board Member
User avatar

Joined: Mon Oct 25, 2010 01:23:42 am
Posts: 336
Location: Scotland
The problem will come from nature in the end the suns activity could wipe it all away.Not to mention the loss of rare earths to make all these gizmos.The whole thing will become so clogged up it will just fail.
You only need to look at mobile phones they do everything but make a phone call.


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Tue May 08, 2012 23:33:03 pm 
Offline
I was online for our Birthday Number 3!
I was online for our Birthday Number 3!
User avatar

Joined: Sat Oct 24, 2009 02:07:21 am
Posts: 4582
Location: ǝɔɐld ǝɥʇ ɹǝʌo llɐ
http://security.blogs.cnn.com/2012/05/08/cyber-attack-targets-gas-pipeline-companies/?hpt=hp_t3

_________________
'The world is indeed comic, but the joke is on mankind.' -H. P. Lovecraft


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Tue May 29, 2012 06:37:53 am 
Offline
I was online for our Birthday Number 5!
I was online for our Birthday Number 5!
User avatar

Joined: Thu Jul 01, 2010 05:39:49 am
Posts: 2238
Location: Canada
Flame: Massive cyber-attack discovered, researchers say.
By Dave Lee

A complex targeted cyber-attack that collected private data from countries such as Israel and Iran has been uncovered, researchers have said.

Russian security firm Kaspersky Labs told the BBC they believed the malware, known as Flame, had been operating since August 2010.

The company said it believed the attack was state-sponsored, but could not be sure of its exact origins.

They described Flame as "one of the most complex threats ever discovered".

Research into the attack was carried out in conjunction with the UN's International Telecommunication Union.

They had been investigating another malware threat, known as Wiper, which was reportedly deleting data on machines in western Asia.

In the past, targeted malware - such as Stuxnet - has targeted nuclear infrastructure in Iran.

Others like Duqu have sought to infiltrate networks in order to steal data.

This new threat appears not to cause physical damage, but to collect huge amounts of sensitive information, said Kaspersky's chief malware expert Vitaly Kamluk.

"Once a system is infected, Flame begins a complex set of operations, including sniffing the network traffic, taking screenshots, recording audio conversations, intercepting the keyboard, and so on," he said.

More than 600 specific targets were hit, Mr Kamluk said, ranging from individuals, businesses, academic institutions and government systems.

Iran's National Computer Emergency Response Team posted a security alert stating that it believed Flame was responsible for "recent incidents of mass data loss" in the country.

The malware code itself is 20MB in size - making it some 20 times larger than the Stuxnet virus. The researchers said it could take several years to analyse.

Iran and Israel

Mr Kamluk said the size and sophistication of Flame suggested it was not the work of independent cybercriminals, and more likely to be government-backed.

He explained: "Currently there are three known classes of players who develop malware and spyware: hacktivists, cybercriminals and nation states.

"Flame is not designed to steal money from bank accounts. It is also different from rather simple hack tools and malware used by the hacktivists. So by excluding cybercriminals and hacktivists, we come to conclusion that it most likely belongs to the third group."

Among the countries affected by the attack are Iran, Israel, Sudan, Syria, Lebanon, Saudi Arabia and Egypt.

"The geography of the targets and also the complexity of the threat leaves no doubt about it being a nation-state that sponsored the research that went into it," Mr Kamluk said.

The malware is capable of recording audio via a microphone, before compressing it and sending it back to the attacker.

It is also able to take screenshots of on-screen activity, automatically detecting when "interesting" programs - such as email or instant messaging - were open.

'Industrial vacuum cleaner'

Kaspersky's first recorded instance of Flame is in August 2010, although it said it is highly likely to have been operating earlier.

Prof Alan Woodward, from the Department of Computing at the University of Surrey said the attack is very significant.

"This is basically an industrial vacuum cleaner for sensitive information," he told the BBC.

He explained that unlike Stuxnet, which was designed with one specific task in mind, Flame was much more sophisticated.

"Whereas Stuxnet just had one purpose in life, Flame is a toolkit, so they can go after just about everything they can get their hands on."

Once the initial Flame malware has infected a machine, additional modules can be added to perform specific tasks - almost in the same manner as adding apps to a smartphone.

Source: http://www.bbc.co.uk/news/technology-18238326


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Tue May 29, 2012 08:03:53 am 
Offline
I was online for our Birthday Number 5!
I was online for our Birthday Number 5!
User avatar

Joined: Wed Nov 18, 2009 00:41:10 am
Posts: 2612
Location: Ann Arbor & Paradise, Michigan, USA
Scary stuff, and Einstein believed WWIV would be fought with sticks and stones.

_________________
Mike
Why do we need perforations? Scissors are cheap!


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Tue May 29, 2012 22:20:32 pm 
Offline
GOLD Star Super Posting Board Member
GOLD Star Super Posting Board Member
User avatar

Joined: Mon Oct 25, 2010 01:23:42 am
Posts: 336
Location: Scotland
The answer is that we have become too reliant on gagets. computers phones etc have never been a safe bet from day one.
Nature may decide faster than any government.
There is enough junk in space for it to collide.
As we live in a very rural area we know how to cope without electricity, the internet is hit and miss and as for mobile phone forget it round here no signal.
So I suggest a nice log fire some candles and a good book you cant beat it Oh and a nice pheasant for tea.


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Wed May 30, 2012 05:47:58 am 
Offline
I was online for our Birthday Number 5!
I was online for our Birthday Number 5!
User avatar

Joined: Thu Jul 01, 2010 05:39:49 am
Posts: 2238
Location: Canada
A link to questions and answers about Flame.

http://www.securelist.com/en/blog?weblogid=208193522


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Wed May 30, 2012 09:35:48 am 
Offline
I was online for our Birthday Number 3!
I was online for our Birthday Number 3!
User avatar

Joined: Mon Jun 23, 2008 11:21:02 am
Posts: 1433
Location: Montreal Canada
Kaspersky Labs are a bunch of hype artists.

About 2% of what they say might be true.

But they do appeal to the 'Oh my God, we're all going to die' types.

And they do make lots of money from it.


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Wed May 30, 2012 10:34:01 am 
Offline
I was online for our Birthday Number 5!
I was online for our Birthday Number 5!
User avatar

Joined: Wed Nov 18, 2009 00:41:10 am
Posts: 2612
Location: Ann Arbor & Paradise, Michigan, USA
Big story about "Flame" on NPR this evening. Scary, but not at the same time. Speculation is that the US or Israel might be behind the virus since it is limited to Middle Eastern targets. Seems to be mostly a data gathering "tool" for spies and the like.

_________________
Mike
Why do we need perforations? Scissors are cheap!


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Thu May 31, 2012 00:01:34 am 
Offline
I was online for our Birthday Number 3!
I was online for our Birthday Number 3!
User avatar

Joined: Sat Oct 24, 2009 02:07:21 am
Posts: 4582
Location: ǝɔɐld ǝɥʇ ɹǝʌo llɐ
makielb wrote:
Big story about "Flame" on NPR this evening. Scary, but not at the same time. Speculation is that the US or Israel might be behind the virus since it is limited to Middle Eastern targets. Seems to be mostly a data gathering "tool" for spies and the like.

I'm going with it being a group of greyhats behind it. Just a whole lot of reasons that it feels that way.

_________________
'The world is indeed comic, but the joke is on mankind.' -H. P. Lovecraft


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Fri Jun 01, 2012 10:51:02 am 
Offline
I was online for our Birthday Number 3!
I was online for our Birthday Number 3!
User avatar

Joined: Mon Jun 23, 2008 11:21:02 am
Posts: 1433
Location: Montreal Canada
Looking past the hype on Flame :shock:

http://www.theregister.co.uk/2012/05/31 ... _analysis/


Top
 Profile  
 
 Post subject: Re: Future Cyberwar
PostPosted: Sat Jun 09, 2012 07:38:06 am 
Offline
I was online for our Birthday Number 5!
I was online for our Birthday Number 5!
User avatar

Joined: Thu Jul 01, 2010 05:39:49 am
Posts: 2238
Location: Canada
More news about Flame.

The security firm Symantec, while watching Flame, has noticed that some Flame command and control computers have sent a command to completely remove Flame from the compromised computers.

More to the story at the link below.

http://www.bbc.co.uk/news/technology-18365844


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 15 posts ] 

All times are UTC + 10 hours [ DST ]


Who is online

Users browsing this forum: WEIRD AL and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  


A powerful Google Custom Search Engine for JUST This Site

 

 

Loading
 
          

Click For Our Newest Issues

Click for our Current Auction

Internet Auctions-Buy & Sell Stamps

Melbourne 2013 - May 10-15

        

 
Powered by phpBB® Forum Software © phpBB Group
[ Time : 0.198s | 15 Queries | GZIP : On ]