By Jack M. Germain TechNewsWorld
04/29/08 4:00 AM PT
Computer network attacks are often perpetrated by gangs of criminal hackers attempting to break into a system for financial gain. However, cyber attacks for political purposes could just as easily be -- and sometimes are -- perpetrated. A country's national security could be severely threatened should a team of hackers successfully crack certain computer systems.
Tech Industry Paper - Finding Strength Through Customer Service Poised to capitalize on an upturn in the economy, technology companies are focused on retention & service. This paper, from Convergys, provides the latest research on customer experience for B2B & B2C technology customers. Learn more.
New-age warfare is here. Governments and Internet security firms are quietly gearing up for the potential onslaught. Don't think that cyber warfare is merely fuel for novel writers. Cyber attacks are being waged in increasing numbers.
Computer network attacks are often perpetrated by gangs of criminal hackers attempting to break into a system for financial gain. However, some criminal hacker groups are starting to test the same strategies on government agencies.
Though political attacks are not as common as those seeking personal and corporate information, cyber attacks for political purposes could just as easily be used as a weapon against governments. A country's national security could be severely threatened by a team of hackers successfully cracking certain computer systems run by government agencies.
Rumbles in Estonia
Perhaps the most notable example of cyber warfare threats was demonstrated last April in an apparent cyber attack on the nation of Estonia. Estonian officials pointed to Russian computers for much of the attacking traffic. But official accounts of the three-week attack stop short of directly blaming Moscow.
"Cyber warfare is not media hype," Tom Kellerman, vice president of security awareness at Core Security Technologies, told TechNewsWorld. "This dark secret is finally out of the bag. The Estonia attacks show what can happen. We've seen a 158 percent increase in cyber attacks. U.S. Department of Homeland Security statistics showed that 37,000 attempted breaches of government and private computer systems were reported in fiscal 2007, which ended Sept. 30, marking a dramatic increase from the 24,000 reported in 2006."
FBI reports from last year show that 108 countries have dedicated cyber attack capabilities, he added. Kellerman also serves on the Commission on Cyber Security for the 44th Presidency and is a former senior data risk management specialist for the World Bank Treasury Security Team.
Estonian Battleground
Beginning April 27, 2007, about 1 million computers worldwide were reportedly used to conduct denial-of-service attacks on Estonian government and corporate Web sites. Over a three-week period, the attacks swamped Estonia's computer network with so much traffic that the government there was forced to shut them down.
The Estonian government reportedly traced much of the attacking traffic to Russian computers and found instructions in Russian on the Internet on how to carry out the attack. The Russian government denied any involvement.
However, one prominent theory among security experts is that Russian hackers were protesting the Estonian government's decision to move a popular monument.
In the aftermath of the attacks, NATO provided the Estonian government with some help in restoring the computer systems and investigating the attacks. Meanwhile, Estonian Defense Ministry spokesperson Madis Mikko likened the cyber attack to more traditional missile assaults on banks or airports, which would clearly be seen as an act of war.
Estonia established independence from the Soviet Union in 1991 and has since become a member of both NATO and the European Union. Earlier this year, it became the first country to allow online voting in a parliamentary election.
Irregular Warfare
Regardless of the reasons behind the Estonian cyber attacks, the fact that it happened should raise the awareness of both enterprise and government officials. This incident is not an isolated matter, and it echoes a much-needed wake-up call.
"Cyber warfare attacks need to be seen in the broader context of increasing irregular warfare and terrorism," Tom Mullen, a member of PA Consulting Group's management team, told TechNewsWorld. He heads the firm's Federal and Defense Services practice. "Nations remain largely unprepared for asymmetric warfare, and the fact that so many recent attacks and campaigns have been successful adds to the need to prepare. The lessons of Iraq, Georgia, Lebanon and now Estonia are that asymmetric attacks work."
The challenge of irregular warfare in general is that it is adaptive, responsive and designed to strike an enemy where it is weak, he explained. Thus, a significant and sustained effort to protect against one tactic -- harden networks, for example -- would merely prompt one's adversary to pursue other tactics. These could include bombings, kidnappings and sabotage.
While some response to hardening computer networks is warranted, it is important to look holistically at risk and not overreact to one tactic, Mullen cautioned. Getting better at understanding the motivation and mindset is as important as strengthening individual areas.
New Attack Fronts
Whether a cyber attack is lodged against a business or a government, the attackers generally use the same methods. The only difference is the intended payload delivery to a targeted system. For instance, hackers can use customized Trojans aimed at government targets.
"We are seeing many cases of government and political Web sites being hacked," Derek Manky, lead cyber threat researcher for Internet security firm Fortinet, told TechNewsWorld. "Top-level domains are being targeted by criminal organizations. We are entering an age where this is a real serious threat."
Manky is concerned about the safety of critical infrastructures within countries. Financial institutions and utility grids are now prime targets of cyber warfare and cyber espionage, said Manky.
He is particularly concerned about the ability of SCADA (Supervisory Control and Data Acquisition) networks to withstand attacks. SCADA is a system used to control and monitor critical infrastructure, such as power, utility and transportation networks.
"Everything today is being integrated to Web 2.0. SCADA is supposed to be isolated from the Internet. But cost efficiencies are allowing WiFi and Web 2.0 applications to expose this grid through remote access," said Manky. "Attackers can use existing methods with inside connections to wage a cyber warfare attack."
March of the Botnets
Two factors that make cyber attacks so potentially dangerous are government sponsorship and the millions of available compromised computers throughout the world.
Some very large criminal hacking groups reside inside Russia. China continues to be the subject of allegations about political cyber activities.
"China is well known to provide safe haven for hacker groups and political activists. Nothing is stopping nations from developing cyber bullets," said Manky.
Security firms that track cyber threat activity see increasing signs of compromised computers being used to remotely wage attacks on a variety of targets. The role of botnets is a keen interest to Phyllis Schneck, vice president of research integration for Secure Computing Corporation.
"My biggest concern is how to protect from deliberate attack to critical infrastructure. We are making some progress, but it is an ever-present threat," Schneck told TechNewsWorld.
She described the role of botnets in waging attacks against governments or specific groups as nothing more than an abuse of the Internet through malware. Every unprotected computer is a potential new botnet member in the attacking cyber army, she concluded.
In part 2 of Cyber Warfare: The Digital Battlefield, TechNewsWorld explores more of the threats posed by cyber attacks and what security experts are doing to protect the nation from cyber assaults.
Mass SQL Attack a Wake-Up Call for Developers April 28, 2008
A novel hacker attack on Web servers that rely on Microsoft SQL database technology has the security community in something of a dither. There seems general agreement that the mass SQL injection approach is highly sophisticated, that it could work against any database, and that developers need to stick to best practices to keep their systems safe.
Related Stories
Cyber-Attacks and Cyber-Disasters: Are You Prepared? April 25, 2008
In 2007, a denial-of-service attack was launched every 53 minutes. Earlier this year, the loss of an undersea cable resulted to the loss of Internet service for entire regions. Businesses that rely to any measure on the Web must secure their businesses against the possibility of large-scale cyber-attacks and disasters, writes strategic management consultant Kevin Coleman.
Yahoo Scrambles, Scrabble Scraps, Chertoff Coaxes April 11, 2008
In this episode: Yahoo has a few tricks up its sleeve; Homeland Security chief seeks help preventing cyberattacks; applicants outnumber available H-1B visas; cybercrime cost hits record levels; Google, UN highlight refugee issue; smaller, cheaper laptops enter the market; e-commerce outperforms the rest of the economy; Verizon, Time Warner duke it out in court; Motorola names former AT&T chief as chairman.
MS Squashes Outlook, SharePoint Bugs in Patch Tuesday Fixfest October 10, 2007
Four critical fixes were on the menu as Microsoft deployed its monthly Patch Tuesday set of security fixes. Affected applications included patches for Kodak Image Viewer and Outlook Express. SharePoint Services 3.0 and Server 2007 were also given a fix, something that had been pulled for September's Patch Tuesday.
Related News Alerts
More by Jack M. Germain
Microsoft FOSSifies .Net Micro Framework November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.