Blog Feed Post

January Cyber War and Cyber Conflict Link Roundup


Wow, what a month. Two big stories to note: USCC is seeking to grow over 5x to 4900 people, and the NYTimes (and WSJ it seems) have been hacked, purportedly by the Chinese over their China coverage. In other news, a new discovery of the ‘Red October’ campaign filled the headlines, although by now these sorts of things feel standard issue. On a related note, DARPA is getting ready to issue a BAA for their CAT program, using big data to tackle targeted attacks.

An upcoming event to note in the DC area: Suits and Spooks, next week (February 8 and 9).


Israel launches cyber warfare training program

Israel is developing a national program that trains young people for cyber warfare to boost its ability to deal with the increasing number of online attacks.
According to The Jerusalem Post’s report Wednesday, the program named “Magshimim Le’umit” has been in development for the past three years and targets outstanding pupils aged between 16 and 18 to join up.
Israel Prime Minister Binyamin Netanyahu said the country’s computer systems are facing attacks from Iran and other countries, and such attacks are set to increase in the digital age. The goverment is also bolstering its ability to deal with these threats through the Israel National Cyber Bureau (INCB), he added.

Nations prepare for cyber war

In 2012, large-scale cyberattacks targeted at the Iranian government were uncovered, and in return, Iran is believed to have launched massive attacks aimed at U.S. banks and Saudi oil companies. At least 12 of the world’s 15 largest military powers are currently building cyberwarfare programs, according to James Lewis, a cybersecurity expert at the Center for Strategic and International Studies.

‘Red October’ cyber-attack found by Russian researchers

A major cyber-attack that may have been stealing confidential documents since 2007 has been discovered by Russian researchers.
Kaspersky Labs told the BBC the malware targeted government institutions such as embassies, nuclear research centres and oil and gas institutes.
It was designed to steal encrypted files – and was even able to recover files that had been deleted.

MPs Unsettled By Potentially ‘Fatal’ Government Cyber Warfare Strategy

MPs have complained about government ‘complacency’ in their assessment of when military forces should involve themselves in cyber warfare, pointing to a potentially fatal reliance on inadequately protected systems.
In a report released today, the Defence Committee said the government did not appear to have a fully-constructed plan for dealing with a major cyber attack. Meanwhile, the ever-changing threat landscape, coupled with a major reliance on IT, made for a potentially lethal brew for the UK military as it prepares for cyber warfare.

Cyber War Stakes Rising

U.S. intelligence officials have warned as nation-sponsored cyber warfare goes mainstream this year, attacks on U.S. installations and institutions could result not just in damage and theft but in fatalities.
They believe fatalities could occur and “that is the best estimate at this point,” said the former senior intelligence official.
Currently 12 of the world’s 15 largest military powers are building cyber warfare programs, these intelligence sources told ISSSource, adding the number of intrusions and attacks has increased dramatically over the last several years.


The Defense Department hopes to offload some of the work of analyzing network vulnerabilities to a machine, Pentagon officials said on Friday.
The Cyber Targeted Attack Analyzer is intended to reduce the workload for the department?s short-handed cyber forces by organizing information from ‘disparate network data sources’ to more easily see computer abnormalities, according to the Pentagon’s laboratory. Information technology development efforts will kick off with a briefing for prospective contractors on Jan. 30, Defense Advanced Research Projects Agency officials said. DARPA expects to release a solicitation for project proposals within a few weeks afterward.
The trick will be reeling in all that intelligence from devices that are not necessarily compatible.

DoD Proposes Cyber Targeted-Attack Analyzer (CAT) Program

The Pentagon has announced the initiation of a program to develop an integrated threat analysis system that will significantly improve the Defense Department?s ability to identify network security vulnerabilities by leveraging the power of Big Data analytics. The Defense Advanced Research Projects Agency (DARPA) Information Innovation Office (I2O) will host an informative briefing on January 30th in a run-up to a Broad Agency Announcement (BAA) in a few weeks that will include a Request for Information (RFI) that will officially commence the process for accepting proposals from vendors for the development of the Cyber Targeted-Attack Analyzer (CAT) Program, according to a Special Notice released by DARPA, the DoD’s research and development branch.

Hacker hits on U.S. power and nuclear targets spiked in 2012

The number of attacks reported to a U.S. Department of Homeland Security cybersecurity response team grew by 52% in 2012, according to a recent report from the team. There were 198 attacks brought to the agency’s attention last year, several of which resulted in successful break-ins.
An earlier report from DHS sketched in details on some of those successes. An unidentified group of hackers targeting natural gas pipeline companies gained access to the corporate systems of several of their targets and “exfiltrated” — that’s security-speak for “stole” — data on how their control systems work.

DoD Looking to ‘Jump the Gap’ Into Adversaries’ Closed Networks

The Army’s Intelligence and Information Warfare Directorate, known as I2WD, hosted a classified planning day Nov. 28. Representatives from 60 companies and labs attended to discuss what can be done in the realm of electronic warfare and cyber, according to a source familiar with the program.
The roughly half-dozen objectives of the Tactical Electromagnetic Cyber Warfare Demonstrator program are classified. (The TECWD program is pronounced ‘techwood’ by participants.) The source said the program is designed to demonstrate ready-made systems, dubbed ‘boxes,’ that can perform a variety of tasks. Some are somewhat typical fare, like systems aimed at the improvised explosive device threat.
But among the objectives are these: inserting and extracting data from sealed, wired networks.

Air Force’s cyber commander says Iran is next big ‘Net menace

General William Shelton, commander of the US Air Force Space Command, told reporters in a press briefing for the Defense Writers Group that he believes Iran’s growing “cyber” capabilities will be a “force to be reckoned with,” thanks in part to Iran’s response to the Stuxnet attacks on its nuclear facilities in 2010.

In Syria, the Cyberwar Intensifies

The front pages have been dominated for more than a year by photos of young Syrian rebel fighters, armed and proud, battling an increasingly isolated Syrian military.
But amid the shooting, the atrocities and the bombings, there is a parallel war – a sophisticated cyber insurgency battling a shadowy team working on behalf of the Assad regime. The Syrians’ online conflict may be the most active cyberwar in recent memory, with extraordinary efforts by both sides to sabotage, disrupt and destroy. It may even foreshadow the way cyber battles will play out in future conflicts.

Iran cyber police uncovers hacking of US bank: Report

The Head of FETA (Iran’s cyber police) says the police has identified the source of attack to US Citibank, and denies that Iranians have a role in attack, Mehr News Agency reported from Tehran on Sunday.
“The attack sources have not been located inside Iran and even Iranian users have been victimized,” says Brigadier General Seyed Kamal Hadianfar, the head of Iranian Cyber Police in an interview to Mehr News.

John Kerry: Foreign Hackers Are ’21st Century Nuclear Weapons’

Sen. John Kerry (D-Mass.) on Thursday likened the threat posed by foreign hackers to “modern-day, 21st century nuclear weapons” and pledged to use diplomacy to avert cyber attacks against the nation?s power grid, transportation system and financial networks.

FSB’s Cyber Silver Bullet

President Vladimir Putin recently ordered the Federal Security Service to create a system to allow the state to detect, prevent and disable cyberattacks in Russia and at diplomatic stations abroad. It is an ambitious goal and one that the FSB is well-equipped to tackle with the help of its Information Security Center and Communications Security Center. But the FSB might very well go beyond its immediate mandate to neutralize hacker attacks against Russia and expand its cyberspace presence among members of the Commonwealth of Independent States, or CIS, perhaps even gaining access to information on hacker attacks waged around the world.

Pentagon to boost cybersecurity force

The Pentagon has approved a major expansion of its cybersecurity force over the next several years, increasing its size more than fivefold to bolster the nation’s ability to defend critical computer systems and conduct offensive computer operations against foreign adversaries, according to U.S. officials.

Hackers in China Attacked The Times for Last 4 Months

SAN FRANCISCO — For the last four months, Chinese hackers have persistently attacked The New York Times, infiltrating its computer systems and getting passwords for its reporters and other employees.
After surreptitiously tracking the intruders to study their movements and help erect better defenses to block them, The Times and computer security experts have expelled the attackers and kept them from breaking back in.

Blogs & Opinion Pieces

Cyber and Drone Attacks May Change Warfare More Than the Machine Gun

But information warfare, warfare pursued with information technologies, distorts concepts like “necessity” and “civilian” in ways that challenge these ethical frameworks. An attack on another nation’s information infrastructure, for instance, would surely count as an act of war. But what if it reduced the risk of future bloodshed? Should we really only consider it as a last resort? The use of robots further complicates things. It’s not yet clear who should be held responsible if and when an autonomous military robot kills a civilian.

My Infosec Wish for 2013: A Balanced Cyberwarfare Debate

I can already hear the chuckling. ‘Cyber warfare’ Balanced? And I’d like partisanship in Washington to end, a double date with Mila Kunis and Scarlett Johansson, and some fries with that!? Yes, my desire is utopian, but the fact that I would have to qualify it with a self-deprecating remark suggests the distance that we have yet to travel before we can get more value out of our present conversation on the topic of cyber warfare.

Industry’s Vital Role in National Cyber Security
by James P. Farwell

Yet, 90 percent of US critical cyber infrastructure is owned by the private sector. Melissa Hathaway, who served as the cyber coordination executive for the Director of National Intelligence (DNI), has rightly pointed out that corporate and political leaders “appear to be paralyzed about meeting the needs for our cyber infrastructures and enterprises.” This current deadlock undercuts American security interests, and Congress must strike a balance between competing policy perspectives for cyber security. The dilemma is that earning a profit motivates industry, while protecting national security motivates the USG. Although often complementary, these agendas do compete. What is required is a confluent approach that removes legislative obstacles to stronger cyber security, forges robust partnerships between the public and private sectors, and better manages risk in the global supply chain. A review of current US strategy and the threat matrix is instructive in framing a new approach.

Towards a coherent international cyberspace policy for the EU
Global Cyber Security Conference
SPEECH/13/82 by Neelie Kroes in Brussels, 30 January 2013
Vice-President of the European Commission responsible for the Digital Agenda

As more people come to rely on the Internet, they rely on it to be secure. And as the online world becomes a part of everything we do, securing that world is essential to ensuring a society that remains secure, prosperous and free.


Suits and Spooks DC 2013

Some of the most important discussions that will take place in 2013 will be around the need for the private sector to become more aggressive in the defense of their systems. These questions and more will be examined and debated at Suits and Spooks DC to be held at the Waterview Conference Center in Arlington, VA on February 8-9, 2013. We?ll be inviting industry veterans, government officials, hackers, lawyers, Special Operations Forces personnel, and security researchers to join in the discussion along with our registered attendees.

Read the original blog entry...

More Stories By Bob Gourley

Bob Gourley writes on enterprise IT. He is a founder and partner at Cognitio Corp and publsher of CTOvision.com

Latest Stories
For basic one-to-one voice or video calling solutions, WebRTC has proven to be a very powerful technology. Although WebRTC’s core functionality is to provide secure, real-time p2p media streaming, leveraging native platform features and server-side components brings up new communication capabilities for web and native mobile applications, allowing for advanced multi-user use cases such as video broadcasting, conferencing, and media recording.
Without lifecycle traceability and visibility across the tool chain, stakeholders from Planning-to-Ops have limited insight and answers to who, what, when, why and how across the DevOps lifecycle. This impacts the ability to deliver high quality software at the needed velocity to drive positive business outcomes. In his general session at @DevOpsSummit at 19th Cloud Expo, Eric Robertson, General Manager at CollabNet, will discuss how customers are able to achieve a level of transparency that e...
DevOps is speeding towards the IT world like a freight train and the hype around it is deafening. There is no reason to be afraid of this change as it is the natural reaction to the agile movement that revolutionized development just a few years ago. By definition, DevOps is the natural alignment of IT performance to business profitability. The relevance of this has yet to be quantified but it has been suggested that the route to the CEO’s chair will come from the IT leaders that successfully ma...
Fifty billion connected devices and still no winning protocols standards. HTTP, WebSockets, MQTT, and CoAP seem to be leading in the IoT protocol race at the moment but many more protocols are getting introduced on a regular basis. Each protocol has its pros and cons depending on the nature of the communications. Does there really need to be only one protocol to rule them all? Of course not. In his session at @ThingsExpo, Chris Matthieu, co-founder and CTO of Octoblu, walk you through how Oct...
Major trends and emerging technologies – from virtual reality and IoT, to Big Data and algorithms – are helping organizations innovate in the digital era. However, to create real business value, IT must think beyond the ‘what’ of digital transformation to the ‘how’ to harness emerging trends, innovation and disruption. Architecture is the key that underpins and ties all these efforts together. In the digital age, it’s important to invest in architecture, extend the enterprise footprint to the cl...
Almost everyone sees the potential of Internet of Things but how can businesses truly unlock that potential. The key will be in the ability to discover business insight in the midst of an ocean of Big Data generated from billions of embedded devices via Systems of Discover. Businesses will also need to ensure that they can sustain that insight by leveraging the cloud for global reach, scale and elasticity.
@DevOpsSummit has been named the ‘Top DevOps Influencer' by iTrend. iTrend processes millions of conversations, tweets, interactions, news articles, press releases, blog posts - and extract meaning form them and analyzes mobile and desktop software platforms used to communicate, various metadata (such as geo location), and automation tools. In overall placement, @DevOpsSummit ranked as the number one ‘DevOps Influencer' followed by @CloudExpo at third, and @MicroservicesE at 24th.
A critical component of any IoT project is what to do with all the data being generated. This data needs to be captured, processed, structured, and stored in a way to facilitate different kinds of queries. Traditional data warehouse and analytical systems are mature technologies that can be used to handle certain kinds of queries, but they are not always well suited to many problems, particularly when there is a need for real-time insights.
One of biggest questions about Big Data is “How do we harness all that information for business use quickly and effectively?” Geographic Information Systems (GIS) or spatial technology is about more than making maps, but adding critical context and meaning to data of all types, coming from all different channels – even sensors. In his session at @ThingsExpo, William (Bill) Meehan, director of utility solutions for Esri, will take a closer look at the current state of spatial technology and ar...
Without lifecycle traceability and visibility across the tool chain, stakeholders from Planning-to-Ops have limited insight and answers to who, what, when, why and how across the DevOps lifecycle. This impacts the ability to deliver high quality software at the needed velocity to drive positive business outcomes. In his session at @DevOpsSummit 19th Cloud Expo, Eric Robertson, General Manager at CollabNet, will show how customers are able to achieve a level of transparency that enables everyon...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at @ThingsExpo, James Kirkland, Red Hat's Chief Arch...
SYS-CON Events announced today that Interface Masters Technologies, a leader in Network Visibility and Uptime Solutions, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Interface Masters Technologies is a leading vendor in the network monitoring and high speed networking markets. Based in the heart of Silicon Valley, Interface Masters' expertise lies in Gigabit, 10 Gigabit and 40 Gigabit Eth...
The IoT industry is now at a crossroads, between the fast-paced innovation of technologies and the pending mass adoption by global enterprises. The complexity of combining rapidly evolving technologies and the need to establish practices for market acceleration pose a strong challenge to global enterprises as well as IoT vendors. In his session at @ThingsExpo, Clark Smith, senior product manager for Numerex, will discuss how Numerex, as an experienced, established IoT provider, has embraced a ...
As software becomes more and more complex, we, as software developers, have been splitting up our code into smaller and smaller components. This is also true for the environment in which we run our code: going from bare metal, to VMs to the modern-day Cloud Native world of containers, schedulers and microservices. While we have figured out how to run containerized applications in the cloud using schedulers, we've yet to come up with a good solution to bridge the gap between getting your conta...
Everyone knows that truly innovative companies learn as they go along, pushing boundaries in response to market changes and demands. What's more of a mystery is how to balance innovation on a fresh platform built from scratch with the legacy tech stack, product suite and customers that continue to serve as the business' foundation. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, will discuss why and how ReadyTalk diverted from healthy revenue an...