Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

04 August 2011

CyBER-BlackSEC--Ex-CIA-DDO Cofer Black on Cybersecurity at BlackHAT

- OPEN SOURCE  US/1; ATTN:
US/30; CID/2; US/12; RT/66; TSP/2; JAG/5; US/17

Former CIA official cites rise in government cybersecurity awareness

Michael S. Mimoso, Editorial Director
Published: 3 Aug 2011

LAS VEGAS – Both white hat and black hat security researchers alike today received a sobering warning from the Central Intelligence Agency’s former director of operations: The opportunity has never been greater to foster government cybersecurity awareness, now that the threat paradigm at a national defense level has evolved to include cybersecurity.

Cyber is going to be a key component of future conflict against nations or terror groups.

Cofer Black, former director of operations, Central Intelligence Agency

During a keynote address at the Black Hat 2011 conference, Cofer Black urged the security community to influence and educate government decision makers, many of whom are ignorant of the threats posed by cybercriminals and nations carrying out online attacks that target major corporations, government agencies and the defense industry.

“The issues that you’re involved in are today are of great value to decision makers,” Black stressed. “That is huge.”

Black said cybersecurity is prominent among the different categories, alongside kinetic and bacteriological attacks, featured the government’s ongoing threat assessments. As a comparison, he said during the Cold War, intelligence agencies progressed from highlighting potential chemical attacks, to later emphasizing bacteriological, radiological and nuclear attacks.

Black spent 28 years working for the CIA and was appointed director of the agency’s Counterterrorist Center in 1999 and coordinator for counterterrorism for the Department of State. He’s seen the threat of the Cold War, the rise of terrorism and now threats to industry and national security from online attacks. He cautioned that the signs are present and discussions are being held that allow for the contingency that physical, kinetic attacks could accompany serious hacks.

“I am here to tell you the Stuxnet attack is the rubicon of our future,” Black said. “I can’t say I understand how it was executed, but the important point is this is expensive to pull off, which means a nation-state was involved. Another important point is, things happening in your world may lead to physical destruction of national resources. This is huge.”

Responses to cyberattacks, however, are tricky because of the difficulty in tracing the origin of attacks and the lack of international coordination in such cases.
 
“Cyber is going to be a key component of future conflict against nations or terror groups,” Black said. “The problem is decision makers don’t understand the threats completely because they have not personally experienced them. They may hear it, but they don’t believe it.”

Black’s keynote comes a little more than a month before the tenth anniversary of the September 11 attacks on New York and Washington. Black drew parallels between the intelligence gathered pre-9/11 and what is happening with cybersecurity today.

In the years and months leading up to September 11, Black recalls the dismissive attitude decision makers had about Al Qaeda and Osama Bin Laden, viewing the terror group and its leader as more a of financier of terror, and not an initiator. The threat from Al Qaeda was labeled overblown inside some government circles and by the press as well. This remained the case, even as attacks escalated against Americans overseas, including the 1998 U.S. embassy bombings in Tanzania and Kenya, and in October 2000 against the U.S.S. Cole.

Black Hat 2011
See all our news coverage and exclusive videos from Black Hat 2011.

Black recalls advising the Bush administration as the transference of power from the Clinton administration began, that terrorism would be its greatest threat. However, Black said, there was no personal experience, no validation of the threat, and it was downplayed. In the summer of 2001, as the volume of intelligence grew about a major impending attack on the U.S., decision makers were briefed and advised to go to a “war footing”, yet, Black said, there were delays in taking action because the threat had yet to be validated.

“Men’s minds have difficulty adapting to things they have not personally experienced,” Black said.

Black’s point is the lead-up to 9/11 may be analogous to what’s happening with targeted persistent attacks carried out against the defense industry and other high-profile targets.

“The validation of that threat will come into your world,” Black said. “There is an analogy to the tech world in all of this and the situation in your world is far more challenging than you may appreciate.”



[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]

15 July 2011

CyBER-BlackSEC--EPIC v. NSA; VC/JCS v. DepSECDEF--OS


VS/2; US/1; ATTN: US/12; JAG/1; HST/2; JAG/5
EPIC v. NSA: Agency Can "Neither Confirm Nor Deny" Google Ties

A federal judge has issued an opinion in EPIC v. NSA, and accepted the NSA's claim that it can "neither confirm nor deny" that it had entered into a relationship with Google following the China hacking incident in January 2010. EPIC had sought documents under the FOIA because such an agreement could reveal that the NSA is developing technical standards that would enable greater surveillance of Internet users.

The "Glomar response," to neither confirm nor deny, is a controversial legal doctrine that allows agencies to conceal the existence of records that might otherwise be subject to public disclosure. EPIC plans to appeal this decision. EPIC is also litigating to obtain the National Security Presidential Directive that sets out the NSA's cyber security authority. And EPIC is seeking from the NSA information about Internet vulnerability assessments, the Director's classified views on how the NSA's practices impact Internet privacy, and the NSA's "Perfect Citizen" program. 

Tags: Google NSA NSPD54 Privacy
- OPEN SOURCE
-------------------------------------------------------|
CBS News Exclusive on US Cyber-WAR Center:





U.S. cyber approach ‘too predictable’ for one top general

By Ellen Nakashima, Published: July 14, 2011

The nation’s second-ranking military official said Thursday that the U.S. approach to protecting its computer systems was “too predictable” and failed to penalize attackers, comments that preceded the release of a Pentagon cyber strategy that emphasized defense over retaliation.

“We’re on a path that is too predictable, way too predictable,” Gen. James Cartwright, vice chairman of the Joint Chiefs of Staff, told defense reporters Thursday. “It’s purely defensive. There is no penalty for attacking us now. We have to figure out a way to change that.” 

Hours later, Deputy Defense Secretary William J. Lynn III presented a strategy whose thrust, he said, is defensive and focused on “denying the benefit of an attack.”

To illustrate the growing threat, Lynn disclosed that in March, the Defense Department discovered that a foreign intelligence service had hacked into a defense contractor’s system and stolen 24,000 computer files related to a weapons system under development, one of the largest known cyberattacks targeting the U.S. military.

Lynn did not name the contractor or the government behind the intrusion but said the Pentagon was reviewing whether the weapons system needed to be redesigned.
The Defense Department’s newly unveiled strategy relies on deploying sensors, software and special signatures, or lines of code, that detect and stop intrusions before they affect operations.

“If an attack will not have its intended effect, those who wish us harm will have less reason to target us through cyberspace in the first place,” Lynn said.
Defining an act of CyBER-WAR, VC/JCS Gen. James Cartwright said during a recent press conference on the subject: “it’s in the eye of the beholder.”
Cartwright, in his remarks to defense reporters, suggested that stronger deterrents would be needed. “We are supposed to be offshore convincing people if they attack, it won’t be free,” he said, adding that adversaries should know that the United States has “the capability and capacity to do something about it.”

Cartwright, who appeared with Lynn at a news conference after the strategy rollout, described the cyber plan as a first step. “This starts us down the path of building out both our defenses and our awareness skills,” he said. Eventually, he added, more aggressive cyber tactics, as well as legal and diplomatic measures, would be needed to “raise the price” of attacking. 

Over the past year, President Obama had asked Cartwright several times whether he would be willing to become chairman of the Joint Chiefs of Staff, The Washington Post reported in May, but Obama later turned to another candidate. Cartwright is leaving office this summer.

Stewart A. Baker, a former National Security Agency general counsel, in a blog post likened the Pentagon’s new cyber plan to a nuclear deterrent strategy of building more fallout shelters. “This is at best a partial strategy,” he wrote. “The plan as described fails to engage on the hard issues, such as offense and attribution and, well, winning.”

Rep. Jim Langevin (D-R.I.), co-founder of the Congressional Cybersecurity Caucus, said that the plan was a good start but that key areas were missing. “What are acceptable red lines for actions in cyberspace? . . . Does data theft or disruption rise to the level of warfare, or do we have to see a physical event, such as an attack on our power grid, before we respond militarily?”

Lynn said that the United States has not yet been hit by an act of cyber war and that there was deterrent value in remaining ambiguous about what would constitute one. But ultimately, he said, it is the president and Congress that would decide that the human or economic damage is severe enough to consider a cyber event an act of war. He said the Pentagon would take the lead only if, in the “judgment of the leadership of the country, it required a military response.”

Cartwright, at the news conference, said the disabling of computerized patient records at a hospital such that the patients cannot be treated would be a violation of the law of armed conflict. “Then you have proportional responses” that can be undertaken, he said, without specifying which or by whom.

But when it comes to an act of war, he said, “it’s in the eye of the beholder.”

Staff writer Jason Ukman contributed to this report.
© The Washington Post Company

 CONTINUE Reading FULL STORY HERE...

05 June 2011

FP: Why Missiles Won’t Scare Cyber-Terrorists--OS

- OPEN SOURCE  US/1; ATTN:
US/121; US/12; VADM/2



Why Missiles Won’t Scare Cyber-Terrorists

 Pentagon planners are dusting off the Cold War deterrence playbook to plan for cyberattacks, but Iraq and Afghanistan would be better models.

BY ROBERT HADDICK | JUNE 3, 2011 

The Pentagon's cyberwarfare doctrine begins to emerge

 
This week, the Wall Street Journal revealed that Pentagon strategists are completing a document that outlines the government's cyberwarfare strategy. The Pentagon is expected to publish an unclassified version next month. According to the Journal, Pentagon strategists are prepared to declare that a sufficiently damaging cyberattack against the United States could be viewed as an "act of war," warranting equivalent retaliation. 

And that retaliation would not necessarily be a U.S. cyber-counterstrike. As one official put it, "If you shut down our power grid, maybe we will put a missile down one of your smokestacks." It is good that the government is finally establishing a doctrine for dealing with cyberwarfare. But strategists still must grapple with a challenging form of warfare that combines elements of Cold War-era deterrence theory and modern counterinsurgency doctrine.

According to the Washington Post, the Pentagon has developed a list of cyberweapons, including various worms and viruses, for use either in support of an existing military campaign or for use, with presidential approval, at the strategic level. According to the emerging doctrine, U.S. military commanders in existing war zones would have the authority to use cyberweapons to collect intelligence from adversary networks and support tactical operations in a broader military campaign. At the strategic level, presidential approval would be required for attacks against an adversary's industrial infrastructure like the Stuxnet worm against Iran's nuclear complex. 

It is not so simple to find a neat divide between strategic cyberattacks requiring presidential approval and tactical attacks delegated to field commanders. The doctrine appears to reserve to the president the decision to attack portions of an adversary's civilian infrastructure. But in an ongoing military campaign, adversary military forces will use portions of the civilian infrastructure -- for example, the telecommunications system -- for tactical military purposes. This will certainly be true if the adversary is a nonstate actor. A local commander's tactical use of cyberweapons could have wider strategic effects. As with all doctrine, the emerging cyberwarfare doctrine will undergo many changes after decision-makers encounter practical experience. 

The Journal article highlighted the threat to use traditional military power in retaliation for a cyberattack that cripples U.S. infrastructure. Reserving the right to expand the boundaries of retaliation should not come as a surprise. Earlier this year, Gregory Schulte, deputy assistant secretary of defense for space policy, discussed a similar retaliatory policy when he rolled out the National Security Space Strategy. As I discussed in a column at that time, that strategy seeks to use diplomacy and soft power to protect U.S. assets and interests in space. But if it became necessary, Schulte asserted a broad retaliatory policy to deter attacks on U.S. space interests. The emerging cyberwarfare doctrine appears to follow the same principle. 

Announcing such a policy is one thing. Implementing it in a crisis won't be easy, as Cold War policymakers discovered to their discomfort. Recently, anonymous hackers attempted to penetrate Lockheed Martin's networks and apparently did succeed in cracking into Google's Gmail service. Having caused no deaths or widespread economic calamity, such attacks wouldn't seem to rise to the level requiring the kind of punitive retaliation discussed in the Wall Street Journal piece. 

But these incidents expose some of the dilemmas cyberwarfare strategists will face. Who exactly were the attackers? The problem of attribution remains unsolved, at least to the degree necessary to convince world opinion that punitive and deadly U.S. retaliation would be legally and morally justified. The emerging U.S. cyberwarfare doctrine will presumably seek to hold governments responsible for the cyberattacks that originate from their territory. Such a policy is designed to elicit cooperative behavior from governments. But it creates opportunities for mischief by nonstate actors and will set up an agonizing test of the U.S. government's retaliatory credibility. 

Policymakers are tempted to view cyber warfare through the lens of deterrence theory. But as long as the attackers remain anonymous, cyberwarfare more closely resembles counterinsurgency -- a form of warfare where the U.S. government is still struggling to crack the code…

Robert Haddick is managing editor of Small Wars Journal.

CONTINUE FULL Story at:


[Information contained in BKNT E-mail is considered Attorney-Client and Attorney Work Product privileged, copyrighted and confidential. Views that may be expressed are those of the author(s) and do not necessarily reflect those of any government, agency, or news organization.]

CyBER-BlackSEC Debate

BlackNIGHT Target Practice

SEAL Team SIX - Iron Will from CBS News

The Devil's Advocate?

In 1991, [the late former Secretary of State Lawrence 'Just call me George'] Eagleburger explained to The Post why all of his sons were named Lawrence.

“First of all, it was ego,” he said. “And secondly, I wanted to screw up the Social Security system.”