DefenseTech Military.com
  • Categories
  • Full Archives
  • Monthly Archives
  • About Defense Tech
Subscribe to RSS

About Defense Tech

Defense Tech examines the intersection of technology and defense from every angle and provides analysis on what’s ahead.

Tip Us Off

Tip for Defense Tech?

SEND IT!

It’s Confidential!

Categories

  • ‘Canes
  • Af-Cam
  • Afghan Update
  • Ammo and Munitions
  • Armor
  • Around the Globe
  • Av Week Extra
  • Axe in Iraq (and Elsewhere)
  • Bizarro
  • Blimps
  • Blog Bidness
  • Body Armor Blues
  • Bomb Squad
  • Brownshoes in Action
  • Bubbleheads, etc.
  • Cammo Green
  • Catch the “Buzz”
  • Chem-Bio
  • Civilian Apps
  • Cloak and Dagger
  • Commandos
  • Comms
  • Contingency Ops
  • Cops and Robbers
  • Crazy Ivan
  • Cyber-warfare
  • Data Diving
  • Defense Tech Poll
  • Defense Tech Radio
  • Dissent Tech
  • Door Kickers
  • Drones
  • DT Administrivia
  • Eat DT’s Dust
  • Extra! Extra!
  • Eye on China
  • F-35 Watch
  • Fast Movers
  • FCS Watch
  • Fire for Effect
  • FOS Files
  • Friday Funnies
  • Gadgets and Gear
  • Going Green
  • Grand Ole Osprey
  • Ground Vehicles
  • Guns
  • Homeland Security
  • In the Bubble with Joe Buff
  • In the Weeds with Eric
  • Info War
  • Iraq Diary
  • Jarhead Jazz
  • JSF Watch
  • Just War Theories
  • Lasers and Ray Guns
  • Less-lethal
  • Logistics
  • Los Alamos and Labs
  • M4 Monopoly
  • Medic!
  • Mercs
  • Missiles
  • Money Money Money
  • Most Wanted
  • MRAP Edge
  • Net-Centric
  • Nukes
  • Old Skool
  • Our Shrinking Planet
  • PEO Soldier
  • Planes, Copters, Blimps
  • Podcast
  • Politricks
  • Polmar’s Perspective
  • Popular Mechanics
  • Rapid Fire
  • Raptor Watch
  • Red Team
  • Retro-Futuro
  • Robots
  • Roll Your Own
  • Sabra Tech
  • Ships and Subs
  • Snipertech
  • Soldier Systems
  • Space
  • Special Ops
  • Star Wars
  • Strategery
  • Stray Trons
  • Tactical Development
  • Terror Tech
  • The Deadlies
  • The Defense Biz
  • The Peoples’ Site
  • The Sunday Paper
  • The Tanker Tango
  • The View from Av Week
  • Those Nutty Norks
  • Training and Sims
  • Trimble on the Case
  • Uncategorized
  • Video Lounge
  • War Update
  • Ward’z Wonderz
  • You can run…

Archives

  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003
  • August 2003
  • July 2003
  • June 2003
  • May 2003
  • April 2003
  • March 2003
  • February 2003
  • January 2003

Home » Cyber-warfare » Covering Up Cyber Assaults

Covering Up Cyber Assaults

cyber-map.jpg

Cyber attacks from individuals, organized crime, extremist groups, terrorists as well as nation states pose a significant threat to the national security of the United States. While many believe that this is a government issue, closer analysis of the problem suggests otherwise. Any computer that is not properly protected can be compromised and used as a weapon against the system owner, businesses and our economy, the nation’s infrastructure or in some rare cases our defenses. Personal, business and government systems are constantly under attack and the frequency and sophistication of the attacks is rapidly increasing.

The number of new computer systems threat skyrocketed nearly 570 percent from those identified in 2006. According to one 2007 computer security study, the average annual loss reported by U.S. companies increased by nearly 210 percent to $350,424 (per occurence) in 2007. The top three primary sources of loss were financial fraud, losses due to computer virus and system penetration by outsiders. About 20 percent of the companies reporting security incidents said they have fallen victim to targeted malware attacks. Nearly 1.2 million different pieces of malware have been identified and reside in the malware repository. Malware is software designed to infiltrate or damage a computer system without the owner’s informed consent. The term is a combination of the words malicious and software. The expression is a general term used by computer professionals to mean a variety of forms of hostile, destructive, intrusive, or annoying software. The bad news is malware is just one of the many threats to computers, systems and networks.

A reader of the blog asked me “Why with all the U.S. technological expertise are we so vulnerable to these threats?” That is a great question. Considering a recent report suggested that around 90 percent of breaches could have been prevented, why are our computer systems so at risk?

After giving this a fair amount of thought I came to the following realization. It is our attitude! For some reason there is an abundance of “I know more than they do” types in information security. If that is not bad enough, the second most prominent attitude is “It can’t happen here” followed closely by “I will address it when it happens to me.”

Example 1 — A $13 billion publically traded corporation has five full time staff assigned to information security. When I asked the Director how he spent his time he said by far most was in the Human Resources Department and with corporate lawyers.

Example 2 — A systems design and development organization that services part of our nation’s infrastructure was briefed on the issues and threats of cyber attack. Numerous examples were provided to that organization that showed their industry had already experienced cyber attacks. In addition, a high level overview of their operational procedures resulted in the identification of two critical vulnerabilities that exposed the systems to compromise. The organization addressed one of those issues and decided to take a wait and see approach to addressing the other.

Example 3 — A security consulting firm contacted me as an advisor. They were brought in to review security and recommend changes of a publically traded company. During their work they discovered the company had been breached. They had found a “bot” attached to an Oracle database. The “bot” collected information about the manufacturing cost of the company’s products. They approached the CIO with the facts and the Sarbanes-Oxley issues, he refused to communicate the issue to the senior executives and then cancelled their contract.

Well, we don’t know more than all the hackers do. This is a highly dynamic threat environment that even the top security professional say is “challenging.” The “it can’t happen here” attitude is insane. One veteran US Special Agent in cybercrime investigation publically stated how companies do their best to cover up corporate espionage and insider theft. He went on to say he had seen entire corporate networks of over 100,000 systems completely compromised and hundreds of thousands of files exfiltrated and not disclosed. The fact is, if all system breaches were reported the security metrics would be much worse that the ones reported earlier here. So it not only can happen here, it probably already did and got covered up.

– Kevin Coleman

Share |

June 30th, 2008 | Cyber-warfare | 392916 Comments »http://defensetech.org/2008/06/30/covering-up-cyber-assaults/Covering+Up+Cyber+Assaults2008-06-30+12%3A40%3A46Ward You can skip to the end and leave a response. Pinging is currently not allowed.

« « The Sunday Paper (Imminent Threat Edition) | Development For B-52 Jammer Continues » »

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

  1. Ali says:
    June 30, 2008 at 10:12 am

    maybe interesting for you !! i am a security admin for one of the IRANIAN biggest comapny (yes your old enemy !!! ha ha ha). one of our servers was under attack for 2 day , someone tried to extract info about company activity that is publicly accessible but not contain sensitive information.the attack was not DOS , that was some kind of unauthorized access.the interesting thinngs was attack was sourced from almost 30 counrty in different region.hard to find who is really behind the attack but we find the proper way to block the attack.i belive the most threat against iranian computer system come from US.pretending that you are at high risk more than the countries you named them adversaries is like a joke.while most high-tech especially computer related technology come from US , most threats come from US.for etc what china can do while Windows code owned by MS and the most important , sophisticated linux kernel security , SELinux come from NSA !!! (i always disable it when i build my own linux kernel.who read the source code of SELinux entirely ? ) . but as your all time reader i awlays love your website.i think being enemy in cyber world is more better than reall war.who know , maybe we , in near future become friends.thks

    Reply
  2. pau says:
    June 30, 2008 at 3:12 pm

    Places such as military.com,navyseals.com,myspace.com are
    heavily hacked already…I’ve been dealing with it on my ids etc…It’s usually VOIP Virtual etc.

    Reply
  3. pau says:
    June 30, 2008 at 3:14 pm

    Ali! Re-read your post,it doesn’t have a core!

    Reply
  4. Mongo says:
    June 30, 2008 at 10:16 pm

    That picture is from the game Uplink. It’s a good game if anyone is interested.

    Reply
  5. Anjar Priandoyo says:
    July 1, 2008 at 2:05 am

    Nice information thanks, quite surprise see the number increased doubled even triple every year

    Reply
  6. Kevin says:
    July 1, 2008 at 8:03 am

    Ali
    I think you took a great first step on the path to friendship.
    As for your attack. Based on what you said in the post, it looks like a botnet was used in the assault on your servers. That is becomming more common now days. There are an estimated 150 million computers around the world that have been compromised and have bots implanted in them. Sourcing the attack has become nearly impossible given the use of botnets.

    Reply
  7. Kevin says:
    July 1, 2008 at 10:16 am

    Who is to blame you ask WE ALL AHARE IN THIS ONE.

    Reply
  8. JE says:
    July 1, 2008 at 1:25 pm

    US technological expertise? Something like 60% of our engineers are foreign born — young Americans just want to smoke pot, skateboard, become marketing or psychology majors etc..
    Whatever technological edge we still have is due to the fact that we were until recently (perhaps still are, but less so) a nice place to move too..

    Reply
  9. Archchancellor says:
    July 1, 2008 at 6:55 pm

    As Mongo mentioned, the photo is from the computer game Uplink. For anyone who wants a crash course in how rudimentary hacking works, try playing the game for just 30 minutes and you’ll have a solid idea.

    Reply
  10. J.Noose says:
    July 3, 2008 at 7:49 pm

    I disagree. Playing the game Uplink for half an hour is *not* a crash course in how hacking works. One might learn a little about concealing one’s physical location by “bouncing” a signal from Moscow to Tokyo to Seoul before attacking a target in Dallas. Thus the techs in Dallas would look for suspects in Korea or Japan when they should be looking in Russia.
    There is a standard CISSP course. Tell your boss to pay for it. Take it and pass. Then you will have a basic knowledge of hacking.

    Reply

Leave a Reply

Click here to cancel reply.

Spam Protection by WP-SpamFree

NOTE: Comments are limited to 2500 characters and spaces.

By commenting on this topic you agree to the terms and conditions of our User Agreement

    Recent Articles
    • Blog Note
    • JSF Price Tag Jumps to $135 Million
    • EADS Tanker, Not Dead Yet
    • JFCOM’s Mattis Pushes Light IW Aircraft
    • And, the Vertical Landing
    • NLOS-LS Missile Fail Could Impact Navy’s LCS
    • JFCOM’s JOE Whacks Defense Industry
    • New F-35B Hover Video
    • China’s Shipbuilding in a Regional Context
    • Debating the Pros and Cons of LCS
    Recent Comments
    • JFCOM’s Mattis Pushes Light IW Aircraft
      The real issue is not what type of plane but trying...
      Bill
    • Paris Hilton: Patriot
      Omg! You can find her pictures and video here...
      WebWarez
    • JFCOM’s Mattis Pushes Light IW Aircraft
      Marine Air Light? Wait…don't they...
      LtCol Ben
    • JSF Price Tag Jumps to $135 Million
      Except its really not that stealthy… The...
      chaos0xomega
    • JSF Price Tag Jumps to $135 Million
      Is an F-22 capable of landing even on a big deck carrier,...
      joe
    • EADS Tanker, Not Dead Yet
      From a national security perspective we should do all we can to keep...
      mike
    • EADS Tanker, Not Dead Yet
      Please define what is "best". Boeings plane is cheaper and...
      Curt
    • JSF Price Tag Jumps to $135 Million
      F4 was origionally a Navy Fighter, so coming up with a...
      Curt
    • JSF Price Tag Jumps to $135 Million
      The US Navy was right to bypass congress and develop the...
      Tony C
    • JSF Price Tag Jumps to $135 Million
      The fly-away cost of a F-22 is between 130 and...
      The Norwegian
  • Channels:Military.com | Military Benefits | Military News | Off Duty |Join the Military | Military Education | Veteran Jobs | Military Money |Military Deals | Military Family | Military Community
  • Military.com Network:Military.com | MilBlogging | Defense Tech | DoD Buzz |SpouseBuzz | Fred's Place | GI Bill Express
  • Services: Army | Navy | Air Force | Marine Corps |Coast Guard | National Guard | Military Spouse
  • About Military.com About Us | Advertise With Us | Press | Affiliate Program |Monster Network | Help | Feedback | Privacy Policy |User Agreement| © 2010 Military Advantage