Showing posts with label cyber-warfare. Show all posts
Showing posts with label cyber-warfare. Show all posts

December 19, 2010

Stuxnet: A serious global problem

Writing for both RAND and The Bulletin of the Atomic Scientists, Isaac Porche is raising the alarm on Stuxnet, claiming that it is now a global concern. He argues that the cyberworm may foreshadow the evolution of "bad seed cybercousins" that could threaten banking, commerce, and national defense and that it could breach boundaries between public and private sectors--a path US defenders cannot easily follow. The time is now, says Porche, for serious discussions on whether information laws should be reformed for the sake of national security:
The highly sophisticated Stuxnet computer worm suspected of sending Iran's nuclear centrifuges into self-destruction mode forces a difficult debate on whether longstanding firewalls in our country's democracy should be breached for the sake of national security.

Stuxnet is a malicious, complicated program, which has been detected on computers in Iran, India, Indonesia, and other countries. It allows an outside force to take control of a certain industrial computer system made by Siemens and "sabotages normal operations by speeding up industrial control processes," according to Eric Chien, a researcher at the Symantec computer security company. Stuxnet's embrace and destruction of computer codes can suddenly cause centrifuges to blow apart. That effect, as recently detected on computers in Iran's Natanz nuclear facility and Bushehr nuclear power plant, has terrifying implications for any country, including the US, whose gas pipelines, chemical plants, and nuclear centrifuges, among other important computerized platforms, depend on similar equipment.

Though Stuxnet may have been targeted to disrupt Iran's nuclear program, the fact that worms like Stuxnet now exist raises the specter of still other worms that could evolve and interfere with electrical grids, causing loss of power to millions; or interrupt transmissions from the Global Positioning System (GPS), affecting motorists, emergency responders, and the military's guidance of precision weapons; or foil electronic fund transfers, causing a banking meltdown.
More.

September 27, 2010

Stuxnet worm allows hackers to control industrial machinery

Well, it finally happened: A worm has been developed that can break into computers which control machinery at the heart of industry. Such a security breach could allow attackers to assume control of critical systems like pumps, motors, alarms and valves in an industrial plant. Worse, safety systems could be switched off at a nuclear power plant; fresh water contaminated with effluent at a sewage treatment plant, or the valves in an oil pipeline opened, contaminating the land or sea.

The worm is called Stuxnet and it's about 600-kilobytes in size. It was professionally written, an indication that a nation-state or organized crime outfit is likely behind it.

This worm will prove particularly problematic for legacy systems, but it's also a wake-up call for new distributed systems such as smart grids. Security will have to be embedded in the architecture right from the start to avoid such vulnerabilities.

Source.

August 22, 2010

Mind Wars: Brain Research and National Defense [book]

Along the lines of my previous post on neurosecurity and information warfare, check out this book by Jonathan D. Moreno: Mind Wars: Brain Research and National Defense (2006). Synopsis:
Imagine a future conflict in which one side can scan from a distance the brains of soldiers on the other side and learn what they may be planning or whether they are confident or fearful. In a crisply written book, University of Virginia ethicist Moreno notes that military contractors have been researching this possibility, as well as the use of electrodes embedded in soldiers' and pilots' brains to enhance their fighting ability. Moreno (Is There an Ethicist in the House?) details the Pentagon's interest in such matters, including studies of paranormal phenomena like ESP, going back several decades. Readers learn that techniques like hypersonic sound and targeted energetic pulses to disable soldiers are close to being used in the field, and even have everyday applications that make "targeted advertising" an understatement. Despite the book's title, Moreno doesn't limit his discussion to brain-related research; he explains the military's investigation of how to enhance soldiers' endurance and reaction time in combat as well as various nonlethal disabling technologies. The ethical implications are addressed throughout the book, but the author leaves substantive discussion to his praiseworthy last chapter.
I really don't know what to make of these claims that the US military is delving into the paranormal. Almost sounds like deliberate disinformation. Or that the higher-ups can't distinguish between sound scientific principles and the work of quacks.

Neurosecurity: The mind has no firewall

Neurosecurity and the potential for so-called 'mind hacking' has interested me for quite some time now, so I was surprised to discover that this topic was covered back in 1997 by Timothy. L Thomas. Writing in Parameters, the US army war college journal, Thomas warned that the American military risked falling behind in the burgeoning field of information warfare.

His particular concern was that military systems operators could be exploited as 'open systems.' "We need to spend more time researching how to protect the humans in our data management structures," he writes, "Nothing in those structures can be sustained if our operators have been debilitated by potential adversaries or terrorists who--right now--may be designing the means to disrupt the human component of our carefully constructed notion of a system of systems."

Thomas continues,
This "systems" approach to the study of information warfare emphasizes the use of data, referred to as information, to penetrate an adversary's physical defenses that protect data (information) in order to obtain operational or strategic advantage. It has tended to ignore the role of the human body as an information- or data-processor in this quest for dominance except in those cases where an individual's logic or rational thought may be upset via disinformation or deception. As a consequence little attention is directed toward protecting the mind and body with a firewall as we have done with hardware systems. Nor have any techniques for doing so been prescribed. Yet the body is capable not only of being deceived, manipulated, or misinformed but also shut down or destroyed--just as any other data-processing system. The "data" the body receives from external sources--such as electromagnetic, vortex, or acoustic energy waves--or creates through its own electrical or chemical stimuli can be manipulated or changed just as the data (information) in any hardware system can be altered.
---
Others, however, look beyond simple PSYOP ties to consider other aspects of the body's data-processing capability. One of the principal open source researchers on the relationship of information warfare to the body's data-processing capability is Russian Dr. Victor Solntsev of the Baumann Technical Institute in Moscow. Solntsev is a young, well-intentioned researcher striving to point out to the world the potential dangers of the computer operator interface. Supported by a network of institutes and academies, Solntsev has produced some interesting concepts. He insists that man must be viewed as an open system instead of simply as an organism or closed system. As an open system, man communicates with his environment through information flows and communications media. One's physical environment, whether through electromagnetic, gravitational, acoustic, or other effects, can cause a change in the psycho-physiological condition of an organism, in Solntsev's opinion. Change of this sort could directly affect the mental state and consciousness of a computer operator. This would not be electronic war or information warfare in the traditional sense, but rather in a nontraditional and non-US sense. It might encompass, for example, a computer modified to become a weapon by using its energy output to emit acoustics that debilitate the operator. It also might encompass, as indicated below, futuristic weapons aimed against man's "open system."
There's some great food for thought here, but as an important aside, it's worth noting that this article has a high bullshit to reality ratio. Overly enamored by the pseudoscientific areas of inquiry explored by his Russian colleagues, Thomas, quite bizarrely, placed as much credence on the development of viable alternative weapons (such as energy-based and psychotronic weapons) as he did on paranormal weapons. Consequently, the credibility of the entire article has to be thrown into question; I advise you to read this essay with a considerable grain of salt.

Link: "The Mind Has No Firewall"

H/T: JD

July 10, 2010

Economist: War in the Fifth Domain

The latest cover article of The Economist poses the question: are the mouse and keyboard the new weapons of conflict?
Important thinking about the tactical and legal concepts of cyber-warfare is taking place in a former Soviet barracks in Estonia, now home to NATO’s “centre of excellence” for cyber-defence. It was established in response to what has become known as “Web War 1”, a concerted denial-of-service attack on Estonian government, media and bank web servers that was precipitated by the decision to move a Soviet-era war memorial in central Tallinn in 2007. This was more a cyber-riot than a war, but it forced Estonia more or less to cut itself off from the internet.

Similar attacks during Russia’s war with Georgia the next year looked more ominous, because they seemed to be co-ordinated with the advance of Russian military columns. Government and media websites went down and telephone lines were jammed, crippling Georgia’s ability to present its case abroad. President Mikheil Saakashvili’s website had to be moved to an American server better able to fight off the attack. Estonian experts were dispatched to Georgia to help out.

Many assume that both these attacks were instigated by the Kremlin. But investigations traced them only to Russian “hacktivists” and criminal botnets; many of the attacking computers were in Western countries. There are wider issues: did the cyber-attack on Estonia, a member of NATO, count as an armed attack, and should the alliance have defended it? And did Estonia’s assistance to Georgia, which is not in NATO, risk drawing Estonia into the war, and NATO along with it?

Such questions permeate discussions of NATO’s new “strategic concept”, to be adopted later this year. A panel of experts headed by Madeleine Albright, a former American secretary of state, reported in May that cyber-attacks are among the three most likely threats to the alliance. The next significant attack, it said, “may well come down a fibre-optic cable” and may be serious enough to merit a response under the mutual-defence provisions of Article 5.
Link.

October 7, 2007

Cyber-warfare? Martin C. Libicki says don't believe the hype

Martin C. Libicki of the RAND Corporation has written a report about the potential for conquest in cyberspace. Libicki argues that many fears about cyber-warfare are overstated, but he also considers the threat of social engineering and the use of computers to persuade. Here's the abstract:
The global Internet has served primarily as an arena for peaceful commerce. Some analysts have become concerned that cyberspace could be used as a potential domain of warfare, however. Martin C. Libicki argues that the possibilities of hostile conquest are less threatening than these analysts suppose. It is in fact difficult to take control of other people’s information systems, corrupt their data, and shut those systems down. Conversely, there is considerable untapped potential to influence other people’s use of cyberspace, as computer systems are employed and linked in new ways over time. The author explores both the potential for and limitations to information warfare, including its use in weapons systems and in command-and-control operations as well as in the generation of “noise.” He also investigates how far “friendly conquest” in cyberspace extends, such as the power to persuade users to adopt new points of view. Libicki observes that friendly conquests can in some instances make hostile conquests easier or at least prompt distrust among network partners. He discusses the role of public policy in managing the conquest and defense of cyberspace and shows how cyberspace is becoming more ubiquitous and complex.