Showing posts with label cyberwarfare. Show all posts
Showing posts with label cyberwarfare. Show all posts

2012/06/20

Cyberwar: paper-tiger or real threat?

Marcus Ranum, renowned IT Security expert, has interesting views on Cyberwar.
It's a lot more nuanced and subtle than "One Big Attack".

Where I diverge: a Big Event is a great distraction for really 'interesting', subtle actions - and can be just as simple as the First Worm by Morris. Oooops, it wasn't meant to do that...

Things you should read or view:



NBN, stuxnet and Security: It's worse than you can believe

What  did US Intelligence tell the Australian Government about Real Network Security when a chinese vendor was vetoed  as supplier of NBN (central?) switches?
Now that we have O'bama admitting "we did Stuxnet, with a little help", we know that they aren't just capable and active, but aware of higher level attacks and defences: you never admit to your highest-level capability.

Yesterday I read two pieces that gave me pause: the first, the US Navy replacing Windows with Linux for an armed drone was hopeful, the other should frighten anyone who understands Security: there's now a market in Zero-Day vulnerabilities.

The things the new-world of the NBN has to protect us against just got a lot worse than you can imagine.

2012/06/05

Cyberwar: Bush/O'Bama authorised Stuxnet

We've crossed a Internet Security Rubicon: the USA admits to combined cyber-attack operations with Israel against Iran's nuclear enrichment program.[NY Times]

The Washington Post's "Zero Day" series says a lot more.

It's a very important event when a government goes public with its most-secret security or intelligence programs: it took over 4-decades after WWII (and the 'Spycatcher' court case) for news of just part of the Allied SIGINT activities to become public.

The work of Bletchley Park, the home of Alan Turning's biggest contribution, was kept secret to the point of allowing mass casualties rather than give it away.

The only reason I can think of for O'Bama to publicise the USA's active, and successful, practice of cyber-attack is they think they've developed protections against it.


2012/04/27

The NBN and defending against Cyber warfare attacks.

CYBER-WARFARE and the Australian NBN.

We know from "Stuxnet" that Nation States are actively building and deploying Cyber warfare tools, applying them to National Security concerns and running them as Military, not technical, operations. This includes accurate reconnaissance and network topology and vulnerability mapping. The worst case is that attackers will gain access to the network control tools and infrastructure.

Recent coverage suggests that Obama denied a US Military request to launch a cyber attack on Syria's infrastructure during the recent 'troubles'.

From the "slammer" worm, we know that any Cyber warfare attack will be fully developed within 3 minutes, and any attack will be launched at the worst possible time for defenders, possibly accompanied by physical distractions.

Recovery from "munitions grade" worm/malware compromise will be long and expensive. Experience is that malware infections is as damaging to businesses as a fire: Within 12 months of a fire, 80-90% of small businesses fail.