DefenseTech Military.com
  • Categories
  • Full Archives
  • Monthly Archives
  • About Defense Tech
Subscribe to RSS

About Defense Tech

Defense Tech examines the intersection of technology and defense from every angle and provides analysis on what's ahead.

Tip Us Off

Tip for Defense Tech?

SEND IT!

It's Confidential!

Categories

  • 'Canes
  • Af-Cam
  • Afghan Update
  • Ammo and Munitions
  • Armor
  • Around the Globe
  • Av Week Extra
  • Axe in Iraq (and Elsewhere)
  • Bizarro
  • Blimps
  • Blog Bidness
  • Body Armor Blues
  • Bomb Squad
  • Brownshoes in Action
  • Bubbleheads, etc.
  • Cammo Green
  • Catch the "Buzz"
  • Chem-Bio
  • Civilian Apps
  • Cloak and Dagger
  • Commandos
  • Comms
  • Contingency Ops
  • Cops and Robbers
  • Crazy Ivan
  • Cyber-warfare
  • Data Diving
  • Defense Tech Poll
  • Defense Tech Radio
  • Dissent Tech
  • Door Kickers
  • Drones
  • DT Administrivia
  • Eat DT's Dust
  • Extra! Extra!
  • Eye on China
  • Fast Movers
  • FCS Watch
  • Fire for Effect
  • FOS Files
  • Friday Funnies
  • Gadgets and Gear
  • Going Green
  • Grand Ole Osprey
  • Ground Vehicles
  • Guns
  • Homeland Security
  • In the Bubble with Joe Buff
  • In the Weeds with Eric
  • Info War
  • Iraq Diary
  • Jarhead Jazz
  • JSF Watch
  • Just War Theories
  • Lasers and Ray Guns
  • Less-lethal
  • Logistics
  • Los Alamos and Labs
  • M4 Monopoly
  • Medic!
  • Mercs
  • Missiles
  • Money Money Money
  • Most Wanted
  • MRAP Edge
  • Net-Centric
  • Nukes
  • Old Skool
  • Our Shrinking Planet
  • PEO Soldier
  • Planes, Copters, Blimps
  • Podcast
  • Politricks
  • Polmar's Perspective
  • Popular Mechanics
  • Rapid Fire
  • Raptor Watch
  • Red Team
  • Retro-Futuro
  • Robots
  • Roll Your Own
  • Sabra Tech
  • Ships and Subs
  • Snipertech
  • Soldier Systems
  • Space
  • Special Ops
  • Star Wars
  • Strategery
  • Stray Trons
  • Tactical Development
  • Terror Tech
  • The Deadlies
  • The Defense Biz
  • The Peoples' Site
  • The Sunday Paper
  • The Tanker Tango
  • The View from Av Week
  • Those Nutty Norks
  • Training and Sims
  • Trimble on the Case
  • Uncategorized
  • Video Lounge
  • War Update
  • Ward'z Wonderz
  • You can run…

Archives

  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003
  • August 2003
  • July 2003
  • June 2003
  • May 2003
  • April 2003
  • March 2003
  • February 2003
  • January 2003

Home » Cyber-warfare » Peeking into Private Data

Peeking into Private Data

top-secret-files.jpg

Cyber espionage is a relatively new type of intelligence gathering capability with various strategies, tactics and tools.Cyber espionage is defined as the intentional use of computers or digital communications activities in an effort to gain access to sensitive information about an adversary or competitor for the purpose of gaining an advantage or selling the sensitive information for monetary reward. This widely accepted definition was originally crafted by Spy-Ops in their cyber warfare analysis program back in 2004.

Cyber espionage blasted on the scene in the mid 90s and has grown at a steady pace along side the adoption and use of the internet by business, government and industry. Even though cyber espionage is relatively new, countries like China have already invested a lot into building large and well trained cyber-espionage forces. By the first of 2009, Spy-Ops estimates about 140 countries and over 50 terrorist and criminal/extremist groups will be developing cyber weapons and espionage capabilities.

In conventional espionage you rely on deep cover covert operatives to conduct espionage and gain intelligence. In cyber espionage you use computer systems and data coupled with conventional techniques to gain intelligence and sensitive information. Events like the ones at ClearanceJobs and the Oakridge National Labs seem to indicate that the U.S. science and engineering community is being targeted. Let’s look at these two incidents a bit closer.

Incident #1 ClearanceJobs.com

ClearanceJobs.com is an online jobs board that specifically addresses the needs of individuals with security clearances and those who hire them. They only focus on active or current security clearances. As such those who apply to job postings on the ClearanceJobs site are ready to work on sensitive /classified projects.

ClearanceJobs.com sent out an email to all those who registered at the web site on Monday, November 19th disclosing a security and systems breach. The hackers did not obtain resume information; however, they did gain access to names, emails and contact information according to the company. The company currently has approximately 3,700 job postings that attract a significant number of candidates seeking a new positions. To illustrate the sensitive nature of many of these posted opportunities, a search on Top Secret SCI resulted in a return of 2,660 listings with that as a requirement. Top Secret is applied to information or materials that the unauthorized disclosure of which would be expected to cause exceptionally grave damage to the national security. SCI is the abbreviation for Sensitive Compartmented Information, the term given to a method for handling specific types of classified information that relates to national security topics or programs whose existence is not publicly acknowledged.

The cyber attack used a SQL injection to gain access to information. This attack is thought to have originated in Russia.

Incident #2 Oakridge National Labs

Oak Ridge National Laboratory (ORNL) is a multi-program science and technology laboratory operated by the U.S. Department of Energy. Scientists and engineers at ORNL conduct basic and applied research and development to create scientific knowledge and technological solutions that strengthen the nation’s leadership in key areas of science; increase the availability of clean, abundant energy; restore and protect the environment; and contribute to national security.

A cyber attack targeted the lab by using phishing emails which opened the door for hackers to glean the sensitive information of up to 12,000 visitors to the facility. This was just one part of cyber battle plan that attempted to gain access to computer networks at numerous laboratories and other institutions across the country. A spokesperson for the lab publicly stated that it is possible the hackers may have gained access to a database of names, birth dates, and social security numbers of every lab visitor between 1990 and 2004. It is unknown how many of these individuals held security clearances and worked on classified programs. While ORNL’s management doesn’t believe that the attackers managed to get access to classified data on their system, there may be an arterial motive for accessing this data.

It should be noted that Oakridge was just one of multiple national labs that were targeted by this coordinated phishing attack, thought to originate in China. Additional reports that the 10 most prominent U.S. defense contractors that included Raytheon, Lockheed Martin, Boeing and Northrop Grumman have been the victims of the same sort of cyber espionage.

Scenario-Based Intelligence Analysis (SBIA)

SBIA is a technique pioneered by Technolytics, Intelomics and Spy-Ops. It creates a framework that allows scenarios to be examined and attempts to answer the “so what does this mean” with respect to events under analysis. Using this technique we looked at both of these events. The following was the result.

Specified target: Information about persons who have access to sensitive or proprietary information.

So how could this information be used? Think about this scenario. The foreign intelligence service contacts these individuals using the information they obtained. Armed with that data, they present a great job opportunity to a specific individual and set up a bogus phone interview for the made-up position. The potential target is wooed by the position, salary, benefits or other enticements. During the upfront interview process, the individual becomes comfortable and less guarded when discussing the details of the work they are doing or have previously done. Answering these seemingly harmless questions about strategies, plans, programs, practices, people or even technologies can lead to derivative intelligence. Derivative Intelligence (DI) is synthesized out of the lower level data, facts, timelines and events that may be disclosed during a casual conversation or on a professional’s resume. The information collected using this technique could compromise national security by unintentionally disclosing classified programs, projects or systems.

One recruiting professional, who asked not to be identified, said this tactic has been and still is used in Silicon Valley where the competitive environment is extremely intense among technology companies. One interesting fact is that the Defense Security Services did not identify this method in their latest Technology Collection Trends 2005 report.

An internet search turned up multiple resumes of individuals with Top Secret/SCI clearance that listed their home addresses and past and current projects for major defense contractors. One resume listed projects at Ft. Meade, home of the National Security Agency. While the information contained on the resume may or may not provide any useful intelligence, it at least creates a security risk for the individuals who provided their home address and a potential for recruitment by adversaries or worse.

Espionage is the act of obtaining non-public or secret information from rivals or enemies for military, political, or economic advantage. Espionage activities such as these are thought to be related to the theft of government secrets are a real threat to national security. Covert operations and espionage are often precursor events to conventional or in this case cyber conflicts. You would want to believe individuals who have security clearance and work in sensitive areas would not be doped by the common hacker practices. The reality is we are all susceptible to lapses in our security awareness. This is not just a problem for the security and defense industry, it can also be directed against corporations as well. Currently, corporate espionage alone is estimated at costing companies over $1.5 trillion annually.

A security strategy must include an ongoing effort to educate users and developers about these common exploits and to achieve a high level of awareness. P. Cordaro a security training specialist at Spy-Ops said, “The dynamics of cyber warfare and system security are such that we all need a continuous update of our skills and knowledge.” With nearly 6,500 cyber attacks being reported in the last minute, we can not afford to let down our guard for one second.

– Kevin Coleman

Share |

January 9th, 2009 | Cyber-warfare | 42744 Comments »http://defensetech.org/2009/01/09/peeking-into-private-data/Peeking+into+Private+Data2009-01-09+13%3A34%3A43Ward You can skip to the end and leave a response. Pinging is currently not allowed.

« « Vehicle Makers Work on Weight Reduction | Fire for Effect — Friday » »

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

  1. Marcello says:
    January 12, 2009 at 2:53 am

    About ClearanceJobs.com incident: if the attackers actually used SQL injection to gain access to their database it probably means that site security policy is/was seriously flawed.
    Is it really acceptable that a website handling top-secret level “stuff” (as in not the actual classified information, but something strictly related) could be vulnerable to this kind of attacks?
    What happens in these cases? Are the people actually responsible for securing the database subject to inquiry? Punished?
    Cyber espionage could be a problem, but as long as important information is left out in the open there’s little that can be done…

    Reply
  2. gsak says:
    January 13, 2009 at 3:45 pm

    Is it really possible that a United States *nuclear* submarine crew could ever carelessly-sink a Japanese fishing boat? Come on, these people are who we rely on to defend our nation from….
    Suck it up.

    Reply

Leave a Reply

Click here to cancel reply.

Spam Protection by WP-SpamFree

NOTE: Comments are limited to 2500 characters and spaces.

By commenting on this topic you agree to the terms and conditions of our User Agreement

    Recent Hot Topics
    • Bye Bye HUMVEE
    • Corps Keeps Buying Growlers (The Jeep Kind)
    • Russian F-22 (PAK-FA) First Test Flight Revealed
    • Sea Drones in the Works
    • Air Force Loses 12 Reaper/Predators, Buys WASPs
    • Bayonets Hit the Mark
    • REPLACEMENT ARM, GOOD AS NEW
    • Bushmaster Adaptive Combat Rifle
    • FBI Stings SHOT Show
    • Oodles of Grenade Guns for Joes in 2011
    Recent Comments
    • Sea Drones in the Works
      I respectfully remind anyone with contract or signature authority that...
      Mark
    • Sea Drones in the Works
      I remember a story I read a while back where mankind had built...
      Kirk
    • UPDATE: Shot Detection for the Individual
      I am at a total loss for words at the moment but I...
      btdt68
    • Murtha Dead at 77
      more crickets and whats up with the guy next to him (letting his nails...
      Brandon
    • Murtha Dead at 77
      Haditha
      /sea/
    • Sea Drones in the Works
      How about a drone sub-ship? With the ability to cruise the world and...
      roland
    • Bushmaster Adaptive Combat Rifle
      I agree with Brett…M16 or AR-15 jamming? Clean it and...
      Mike
    • Secret Program Works to Field SEAL Plane
      The COIN plane must work tactically if the rumors of...
      Jared
    • Our Oscar Vote
      The main scientific issue to me is the fact that the Na’vi...
      Thomas L. Nielsen
    • Murtha Dead at 77
      The circumstances behind his death is so murky. He had gallbladder...
      Roy Smith
    Recent Articles
    • Murtha Dead at 77
    • Sea Drones in the Works
    • The Keating Report (Where is it?)
    • COP Keating Report Complete
    • Asia-Pacific Recapitalizes its Fighter Fleets
    • Air Force Loses 12 Reaper/Predators, Buys WASPs
    • Our Oscar Vote
    • JSF Chief’s Career Crashes, Another Plane Takes Off
    • Corps Keeps Buying Growlers (The Jeep Kind)
    • COIN Attack Plane Not Til Next Year
  • Channels: Military.com | Military Benefits | Military News | Off Duty | Join the Military | Military Education | Veteran Jobs | Military Money | Military Deals | Military Family | Military Community
  • Military.com Network: Military.com | MilBlogging | Defense Tech | DoD Buzz | SpouseBuzz | Fred's Place | GI Bill Express
  • Services: Army | Navy | Air Force | Marine Corps | Coast Guard | National Guard | Military Spouse
  • About Military.com About Us | Advertise With Us | Press | Affiliate Program | Monster Network | Help | Feedback | Privacy Policy | User Agreement | © 2010 Military Advantage