Showing posts with label cyber attacks. Show all posts
Showing posts with label cyber attacks. Show all posts

Friday, January 18, 2008

CIA Confirms Cyber Attack Caused Multi-City Power Outage

From SANS.org:
On Wednesday, in New Orleans, US Central Intelligence Agency (CIA) senior analyst Tom Donohue told a gathering of 300 US, UK, Swedish, and Dutch government officials and engineers and security managers from electric, water, oil & gas and other critical industry asset owners from all across North America, that

"We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge. We have information that cyber attacks have been used to disrupt power equipment in several regions outside the United States. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet."
According to Mr. Donohue, the CIA actively and thoroughly considered the benefits and risks of making this information public, and came down on the side of disclosure.

Thursday, June 14, 2007

Fed's 'Operation Bot Roast' Reveals 1 Million Victims

As the FBI and the DOJ investigated botnet operators, they began amassing a list of the alleged botnet victims -- with most of them here in the U.S.

Article by Sharon Gaudin, InformationWeek
In the Department of Justice and the FBI's attack on 'botherders', the government has identified more than one million botnet victims. The agencies announced Wednesday the results of an ongoing cybercrime initiative to disrupt and dismantle botherders, a term used for the people creating and operating an increasing number of botnets around the world. The FBI reported in an online advisory that its agents are working with the U.S.-CERT Coordination Center at Carnegie Mellon University to notify the owners of the compromised computers.

Government investigators tracked down the million victims while working on five different cybercrime cases, according to Richard Kolko, a special agent with the FBI. Charges already have been handed down in three of those cases. James C. Brewer of Arlington, Texas, is charged with operating a botnet that infected Chicago area hospitals. His botnet allegedly infected tens of thousands of computers worldwide. The government charged Jason Michael Downey of Covington, Kentucky, with using botnets to launch denial-of-service attacks. Robert Alan Soloway of Seattle was also charged this month with using a large botnet network to spam tens of millions of messages to advertise his Web site.

Kolko told InformationWeek that as agents delved into these three cases, along with two others that are under investigation, they uncovered the botnet victims. "There are hundreds of cybercrime cases at any given time but we put the botnet cases together for this initiative," he said. "We're trying to get people to take care of their computers. They're unaware participants in this criminal activity. We need them to take the proper precautions so we can put a dent in this crime." He also said most of the one million victims they found are in the United States. The government, he added, will continue to try to find more victims so they can notify them and get the compromised machines cleaned up.

Hackers and malware writers conspire to infect computers around the world with viruses and Trojans that allow them to remotely control the victim machines. Then, they amass thousands or hundreds of thousands of these zombie computers, creating great armies -- or botnets -- of them. In recent months, botnets have been increasing in number and in size, as they launch massive waves of spam, malware and even denial-of-service attacks. Most of the owners of the zombie machines don't even know they have been infected or that their machine is being controlled by someone else.

According to the FBI's advisory, because of their widely distributed capabilities, the government considers botnets a growing threat to national security, the national information infrastructure, and the economy. "They were a problem and they're emerging as a greater problem as people use them to get around security measures and cause greater damages," said Assistant U.S. Attorney Erez Liebermann, chief of the computer hacking and intellectual property unit in New Jersey. "The fact that they can do so much damage with the press of a button is a huge problem." A large number of the botnets are controlled by hackers and botherders outside of the U.S., with a growing number being set up in China. Dealing with cybercriminals outside the country's borders has been an issue -- but it's one the U.S. government is working on.

"Generally speaking, international aspects of these cases do have extra hurdles, but more and more countries are cooperating," said Liebermann. "There are efforts to get [cooperation] from China, and they're paying off." In recent months, rival online gangs have even begun a virtual turf war for bragging rights to the largest botnets. Two or three online criminal gangs have been waging an all-out battle for control of the largest botnets, sending out waves of malware aimed at stealing zombie computers from rival gangs to build up their own army. Each online gang is trying to build up the biggest botnet because the bigger the army of infected computers they control, the more money spammers and hackers will pay to use them, said Shane Coursen, a senior technical consultant forKaspersky Lab, in a previous interview.

Thursday, December 14, 2006

The Ten Most Important Security Trends of the Coming Year

Experts Predict the Future
The Ten Most Important Security Trends of the Coming Year

Mobile Devices
1. Laptop encryption will be made mandatory at many government agencies and other organizations that store customer/patient data and will be preinstalled on new equipment. Senior executives, concerned about potential public ridicule, will demand that sensitive mobile data be protected.

2. Theft of PDA smart phones will grow significantly. Both the value of the devices for resale and their content will draw large numbers of thieves.

Government Action
3. Congress and state governments will pass more legislation governing the protection of customer information. If Congress, as expected, reduces the state-imposed data breach notification requirements significantly, state attorneys general and state legislatures will find ways to enact harsh penalties for organizations that lose sensitive personal information.

Attack Targets
4. Targeted attacks will be more prevalent, in particular on government agencies. Targeted cyber attacks by nation states against US government systems over the past three years have been enormously successful, demonstrating the failure of federal cyber security activities. Other antagonistic nations and terrorist groups, aware of the vulnerabilities, will radically expand the number of attacks. Targeted attacks on commercial organizations will target military contractors and businesses with valuable customer information.

5. Cell phone worms will infect at least 100,000 phones, jumping from phone to phone over wireless data networks. Cell phones are becoming more powerful with full-featured operating systems and readily available software development environments. That makes them fertile territory for attackers fueled by cell-phone adware profitability.

6. Voice over IP (VoIP) systems will be the target of cyber attacks.
VoIP technology was deployed hastily without fully understanding security.

Attack Techniques
7. Spyware will continue to be a huge and growing issue. The spyware developers can make money so many ways that development and distribution centers will be developed throughout the developed and developing world.

8. Zero-day vulnerabilities will result in major outbreaks resulting in many thousands of PCs being infected worldwide. Security vulnerability researchers often exploit the holes they discover before they sell them to vendors or vulnerability buyers like TippingPoint.

9. The majority of bots will be bundled with rootkits. The rootkits will change the operating system to hide the attack's presence and make uninstalling the malware almost impossible without reinstalling a clean operating system.

Defensive Strategies
10. Network Access Control will become common and will grow in sophistication. As defending laptops becomes increasingly difficult, large organizations will try to protect their internal networks and users by testing computers that want to connect to the internal network. Tests will grow from today's simple configuration checks and virus signature validation to deeper analysis searching for traces of malicious code.

How these trends were determined
Twenty of the most respected leaders in cyber security developed this list. First each proposed the three developments that they each felt were most important. Then they compiled the list of more than 40 trends and voted on which were most likely to happen and which would have the greatest impact if they did happen. That resulted in a prioritized list. To validate their prioritization, they asked the 960 delegates at SANSFire in Washington to each prioritize the 40 trends. More than 340 did so. The SANSFire delegates' input reinforced the experts' prioritization and helped target the Top Ten.