Showing posts with label Cyber attack. Show all posts
Showing posts with label Cyber attack. Show all posts

Wednesday, 29 May 2013

Information Warfare - China Cannot Handle The Truth

China’s efforts to control the Internet often backfire. The most recent example can be seen in how China was forced, by Internet based public opinion in China, to lean on North Korea. The West had long been urging China to pressure the North Korean leaders to cut out the warlike rhetoric and pay more attention to their economic problems. North Korea has refused and even defied the Chinese government by trying to steal Chinese assets (railroad cars used to send aid into North Korea and Chinese businesses set up in North Korea at the invitation of the North Korean government).
The Chinese government was unable to keep all of this away from the people using the heavily censored and managed Chinese Internet. The popular response was intensely anti-North Korea and critical of how the Chinese government was handling things. This anger was in part created by Chinese officials backing Chinese nationalism over the last decade. This was especially the case with calls for other nations to show some long overdue respect for China. The continued defiance of China by North Korea, especially after the billions in aid China has provided, has sparked growing popular anger in China. For most Chinese, Korea is one of those neighbors (like Vietnam, Japan, and Mongolia) that have benefitted from Chinese culture and trade but managed (most of the time) to avoid being absorbed into China. Thus these nations are expected to show some respect. While Korea usually has done so over the centuries, the current North Korean government has been increasingly obnoxious. This is also in sharp contrast to the much wealthier and better behaved South Korea.
 
It’s not just North Korean news that the Chinese government has had a hard time managing. Last year China's efforts to control the Internet went into overdrive when a senior government official, who was also outspoken and popular with the military, was removed from office for corruption. The Chinese Internet immediately lit up with rumors and speculation about what would happen next. This speculation alarmed the government more than anything that was happening (not much, in fact). The government sought to shut down web sites (especially microbloggers, who substitute for Twitter, which is banned in China) and arrested a few people. This did not slow down the spread of rumor and criticism. The government censors were caught short once more as microbloggers adopted code words to defeat the automatic filtering software the government used. As quickly as the government figured out the code a new one was in use. It's not that the government didn't know about this, it was widely used in the 1990s when most Chinese were texting (more than talking) on their cell phones. 

But no solution was ever found. While the government efforts can keep many Chinese in the dark, too many find out what is really going on and the word spreads. The government censors are constantly going back to the drawing board to try and come up with a solution. One solution, judging from the response to the popular anger at North Korea, is to listen to the people and act accordingly.
China needs the Internet for economic reasons and because it is a major form of communication and entertainment for most people. But the downside is that the Internet is also a major source of news, and the communist government in China has long depended on a news monopoly to keep dissent under control. The Internet has proven difficult to censor and control. While the government has imposed more control over the Internet than any other country, that has not been enough to control embarrassing or troublesome news from getting out of control. The government is not giving up, especially since it is losing.

Tuesday, 7 May 2013

Pentagon Points Finger at Chinese Army Over Computer Attacks

For years now security companies have described that attacks originating in China routinely infiltrate and steal data from U.S. corporate networks, and that similar activity targets U.S. government systems, too. But even as politicians and government officials have begun to speak more freely about the issue (see “U.S. Power Grids, Water Plants a Hacking Target”), they have stopped short of making specific accusations about who is responsible. In April, President Obama’s national security adviser Tom Donilon talked vaguely of attacks “emanating from China.”

A new report from the Department of Defense (PDF) uses much firmer language, singling out the Chinese military:
“China is using its computer network exploitation (CNE) capability to support intelligence collection against the U.S. diplomatic, economic, and defense industrial base sectors that support U.S. national defense programs.”
That information could be used to help out Chinese defense companies, technology industry military planners, political leaders, says the report, which adds:
“Although this alone is a serious concern, the accesses and skills required for these intrusions are similar to those necessary to conduct computer network attacks.”
That seems to refer to the fact that an intruder on a computer network could also use their access to shut it down and disrupt communications or other – perhaps physical – systems connected to it.

It’s not within the scope of the Pentagon report to mention that the U.S. has expanding computer-based espionage and attacks capabilities of its own (see “Welcome to the Malware Industrial Complex”), that China isn’t the only nation targeting the U.S. (see “Which Four Countries Most Actively Attack the U.S.?”), or to discuss the state of defenses against such actions.

From a technical perspective, the prevalence of successful infiltration of U.S. companies – even defense and security companies such as Lockheed Martin and RSA – suggests they are slim. Recent research has shown that a determined adversary could likely find many opportunities to access physical industrial systems (see “What Happened When One Man Pinged the Whole Internet”).

However, how far China might be willing to test any computer espionage and attack capabilities will be determined by traditional political and strategic concerns more than technical questions. President Obama, secretary of state John Kerry and other senior U.S. officials are all known to have raised the question of computer-based industrial espionage with China in recent months and presumably they are also raising the matter of the actions against Pentagon and government networks described in the new report out today.

For now, China’s government is publicly sticking to its previous line that it does not condone or support any such activity, with a spokesperson telling the New York Times today that:
 “China has repeatedly said that we resolutely oppose all forms of hacker attacks…we are firmly opposed to any groundless accusations and speculations.”

Friday, 26 April 2013

Chinese Counter-Intelligence On The Internet

A recent worldwide survey of Internet based hacking attacks discovered that about a fifth of them are directed at stealing data. That’s espionage and over 90 percent of these attacks are from China. Most of the criminal Internet activity is still all about making money (via spam or outright theft).
 
What is interesting about the data stealing activity is that more and more of it is counter-intelligence (attacking enemy intelligence collecting) work. For example, more and more Chinese hacking is an effort to find out how Western media is finding out details of corruption inside China. Western media has published some very embarrassing data about corruption by the families of senior Chinese leaders. Chinese hackers are trying to find out who the sources in China are, so they can be silenced. The Chinese are also trying to find information about informants working for Western intelligence agencies. 
 
While military organizations are usually very careful about guarding the identities of these informants, if you can grab enough lower-level communications within military intelligence agencies you can probably figure out who the sources within China are. The Chinese also use these techniques to discover key people in Western corporations who are developing new products or markets for existing products. Chinese firms have a big advantage knowing this sort of thing. It’s all about information and who has it. If you know what the enemy knows and they don’t know what you are all about you have a major advantage in war and peace

Wednesday, 24 April 2013

US Navy’s newest warship vulnerable to cyber attack

The computer network on the US Navy's newest class of coastal warships has been found vulnerable to hacking.

Navy cybersecurity tests uncovered vulnerabilities, but the issues were not severe enough to prevent an eight-month deployment to Singapore, a Navy official said on Tuesday on condition of anonymity.
A Navy team of computer hacking experts found some deficiencies when assigned to try to penetrate the network of the USS Freedom, the lead vessel in the $37 billion Littoral Combat Ship program, said the official.

The Freedom arrived in Singapore last week for an eight-month stay, which its builder, Lockheed Martin, hopes will stimulate Asian demand for the fast, agile and stealthy ships.

"We do these types of inspections across the fleet to find individual vulnerabilities, as well as fleet-wide trends," said the official.

Cyber-security is a major priority for the Navy, which relies heavily on communications and satellite networks for its weapons systems and situational awareness.

Defense Department spokeswoman Jennifer Elzea said the Pentagon's chief weapons test agency addressed "information assurance vulnerabilities" for the Littoral Combat Ship in an assessment provided to the Navy.

"The details of that assessment are classified," Elzea said.

Lockheed spokesman Keith Little said the company was working with the Navy to ensure that USS Freedom's networks were secure during the deployment.
The Navy plans to buy 52 of the new LCS warships in coming y
ears, including some of Lockheed's steel monohull design and some of an aluminium-hulled LCS trimaran design built by Australia's Austal. The ships are designed for combat and other missions in shallower waters close to shore.

Freedom's first operational deployment was in the Caribbean Sea in 2010, where the ship participated in four drug transport busts and captured a total of five tons of cocaine.