Articles by "cyber"

Say what you will about cybercriminals, says Angela Sasse, “their victims rave about the customer service”.
Sasse is talking about ransomware: an extortion scheme in which hackers encrypt the data on a user's computer, then demand money for the digital key to unlock them. Victims get detailed, easy-to-follow instructions for the payment process (all major credit cards accepted), and how to use the key. If they run into technical difficulties, there are 24/7 call centres.
“It's better support than they get from their own Internet service providers,” says Sasse, a psychologist and computer scientist at University College London who heads the Research Institute in Science of Cyber Security. That, she adds, is today's cybersecurity challenge in a nutshell: “The attackers are so far ahead of the defenders, it worries me quite a lot.”
Long gone are the days when computer hacking was the domain of thrill-seeking teenagers and college students: since the mid-2000s, cyberattacks have become dramatically more sophisticated. Today, shadowy, state-sponsored groups launch exploits such as the 2014 hack of Sony Pictures Entertainment and the 2015 theft of millions of records from the US Office of Personnel Management, allegedly sponsored by North Korea and China, respectively. “Hacktivist” groups such as Anonymous carry out ideologically driven attacks on high-profile terrorists and celebrities. And a vast criminal underground traffics in everything from counterfeit Viagra to corporate espionage. By one estimate, cybercrime costs the global economy between US$375 billion and $575 billion each year.
Increasingly, researchers and security experts are realizing that they cannot meet this challenge just by building higher and stronger digital walls around everything. They have to look inside the walls, where human errors, such as choosing a weak password or clicking on a dodgy e-mail, are implicated in nearly one-quarter of all cybersecurity failures. They also have to look outwards, tracing the underground economy that supports the hackers and finding weak points that are vulnerable to counterattack.
“We've had too many computer scientists looking at cybersecurity, and not enough psychologists, economists and human-factors people,” says Douglas Maughan, head of cybersecurity research at the US Department of Homeland Security.
That is changing—fast. Maughan's agency and other US research funders have been increasing their spending on the human side of cybersecurity for the past five years or so. In February, as part of his fiscal-year 2017 budget request to Congress, US President Barack Obama proposed to spend more than $19 billion on federal cybersecurity funding — a 35% increase over the previous year — and included a research and development plan that, for the first time, makes human-factors research an explicit priority.
The same sort of thinking is taking root in other countries. In the United Kingdom, Sasse's institute has a multiyear, £3.8-million (US$5.5-million) grant from the UK government to study cybersecurity in businesses, governments and other organizations. Work from the social sciences is providing an unprecedented view of how cybercriminals organize their businesses—as well as better ways to help users to choose an uncrackable yet memorable password.
The fixes are not easy, says Sasse, but they're not impossible. “We've actually got good science on what does and doesn't work in changing habits,” she says. “Applying those ideas to cybersecurity is the frontier.”
Know your audience
Imagine that it is the peak of a harried work day, and a legitimate-looking e-mail lands in your inbox: the company's computer team has detected a security breach, it says, and everyone needs to run an immediate background scan for viruses on their machines. “There's a tendency to just click 'accept' without reading,” says Adam Joinson, a social psychologist who studies online behaviour at the University of Bath, UK. Yet the e-mail is a fake—and that hasty, exasperated click sends malware coursing through the company network to steal passwords and other data, and to convert everyone's computers into a zombie “botnet” that fires off more spam.
The attackers, it seems, have a much better grasp on user psychology than have the institutions meant to defend them. In the scenario above, the success of the attack relies on people's instinctive deference to authority and their lowered capacity for scepticism when they're busy and distracted. Companies, by contrast, tend to impose security rules that are disastrously out of sync with how people work. Take the ubiquitous password, by far the simplest and most common way for computer users to prove their identity. One study, released in 2014 by Sasse and others, found that employees of the US National Institute of Standards and Technology (NIST), headquartered in Gaithersburg, Maryland, averaged 23 “authentication events” per day—including repeated logins to their own computers, which locked them out after 15 minutes of inactivity.
Such demands represent a substantial drain on employees' time and mental energy—especially for those who try to follow the standard password guidelines. These insist that people use a different password for each application; avoid writing passwords down; change them regularly; and always use a hard-to-guess mix of symbols, numbers and uppercase and lowercase letters.
So people resort to subversion. In another systematic study of password use in the real world, Sasse and her colleagues documented the ways in which workers at a large multinational organization side-stepped the official security requirements without (they hoped) being totally reckless. The employees' methods—writing down a list of passwords, for example, or transferring files between computers using unencrypted flash drives—would be familiar in most offices, but essentially created a system of 'shadow security' that kept the work flowing. “Most people's goal is not to be secure, but to get the job done,” says Ben Laurie, who studies security compliance at Google Research in London. “And if they have to jump through too many hoops, they will say, 'To hell with it.'”
Researchers have uncovered multiple ways to ease this impasse between workers and security managers. Lorrie Cranor directs the CyLab Usable Privacy and Security Laboratory at Carnegie Mellon University in Pittsburgh, Pennsylvania—one of several groups worldwide that are looking at ways to make password policies more human-compatible.
“We got started on this six or seven years ago, when Carnegie Mellon changed its password policy to something really complicated,” says Cranor, who is currently on leave from the university to serve as chief technologist at the US Federal Trade Commission in Washington DC. The university said that it was trying to conform to standard password guidelines from NIST. But when Cranor investigated, she found that these guidelines were based on educated guesses. There were no data to base them on, because no organization wanted to reveal its users' passwords, she says. “So we said, 'This is a research challenge.'”
Cranor and her colleagues put a wide range of password policies to the test by asking 470 computer users at Carnegie Mellon to generate new passwords based on different requirements for length and special symbols. Then they tested how strong the resulting passwords actually were, how much effort was required to create them, how easy they were to remember—and how annoyed at the system the participants became.
One key finding was that organizations should forget the standard advice that complex gobbledygook words such as 0s7G0*7j%x$a are safest. “It's easier for users to deal with password length than password complexity,” says Cranor. An example of a secure but user-friendly password might be a concatenation of four common but randomly chosen words—something like usingwoodensuccessfuloutline. At 28 characters, it is more than twice as long as the gibberish example, but much easier to remember. As long as the system guards against people making stupid choices such as passwordpassword, says Cranor, strings of words are quite hard for attackers to guess, and provide excellent security.
Time for a change
Another key finding, says Cranor, is that unless there is reason to think that the organization's security has been compromised, the standard practice of forcing users to change their passwords on a 30-, 60- or 90-day schedule ranks somewhere between useless and counterproductive (see go.nature.com/2vq6r4). For one thing, she says, studies show that most people respond to such demands by choosing a weaker password to begin with, so that they can remember it, and then making the smallest change that they can get away with. They might increase a final digit by one, for example, so that password2 becomes password3 and so on. “So if a hacker guesses your password once,” she says, “it won't take them many tries to guess it again.”
Besides, she says, one of the first that things hackers do when they break in is to install a key-logging program or some other bit of malware that allows them to steal the new password and get in whenever they want. So again, says Cranor, “changing the password doesn't help”.
Sasse sees encouraging signs that such critiques are being heard. “For me, the milestone was last year when GCHQ changed its advice on passwords,” she says, referring to the Government Communications Headquarters, a key UK intelligence agency. GCHQ issued a public document, containing several citations to the research literature, that gave up on long-established practices such as demanding regular password changes, and instead urged managers to be as considerate as possible towards the people who have to live with their policies. “Users have a whole suite of passwords to manage, not just yours,” goes one bit of advice. “Only use passwords where they are really needed.”
Attack on attackers
If research can uncover weak points in user behaviour, perhaps it can also find vulnerabilities among the attackers.
In 2010, Stefan Savage, a computer scientist at the University of California, San Diego, and his team set up a cluster of computers to act as what he calls “the most gullible consumer ever”. The machines went through reams of spam e-mails collected from several major antispam companies, and clicked on every link they could find. The researchers focused on illegal pills, counterfeit watches and handbags, and pirated software—three of the product lines most frequently advertised in spam—and bought more than 100 items. Then they used specially designed web-crawling software to track back through the spammers' supply network. If an illicit vendor registered a domain name, made payments to a supplier or used a bank to accept credit-card payments, the researchers could see it. The study exposed, for the first time, the entire business structure of computer criminals—and revealed how surprisingly sophisticated it was.
“It was the ultimate hothouse of weird new entrepreneurial ideas,” says Savage, “the purest form of small-business capitalism imaginable—because there is no regulation.” Yet there was order, even so. “Say you have a criminal activity you want to engage in,” Savage explains—for example, selling counterfeit drugs. You set up shop by creating the website and the databases, striking a deal with a bank to accept credit-card payments and creating a customer-service arm to deal with complaints—all the back-end parts of the business.

Executions, forced and arbitrary detentions, beatings, whipping, incarceration and hard labour — This is a common face of drug policy in many Asian nations, and one that is looking ever more archaic.
Half a million drug users are held annually in compulsory detention centers in China and Southeast Asia, according to estimates from the United Nations Office on Drugs and Crime (UNODC). Arduous physical exercises and military drills are often routine there, as is violence — former detainees described shocks with electric batons and whipping with electric wires to Human Rights Watch.
Roughly 50 to 70 percent of prisoners in Indonesia, Malaysia, Myanmar, the Philippines, and Thailand are in jail for drug-related crimes. In extreme cases, prisoners pay with their lives. Indonesia is currently preparing executions for drug trafficking.
The harsh, punitive approach to drug use in Asia stands in stark contrast with the health approach in many Western countries, where programs for “harm reduction” of drug use — such as access to clean needles and methadone substitution treatment — are the norm.
Since Portugal successfully decriminalized drugs in 2001, whereby getting caught with drugs may result in a small fine and a referral to treatment, other countries have followed suit.
This dichotomy of approaches was evident at the United Nations General Assembly special session on drugs (UNGASS) last month. While Indonesia defended the use of the death penalty amid jeers, Canada and Mexico declared they would go their own way to legalize cannabis.
A public letter to the UN urging reform was signed by 1,000 prominent global leaders and activists, including many former world leaders, as well as Hillary Clinton, Bernie Sanders, and Richard Branson. Leading global public health bodies also urged reform in a report, arguing prevailing policies have had “serious detrimental effects” on health and human rights.
UNGASS proved disappointing for reform advocates, yet it was still significant. “The international consensus on drug prohibition came to an end” at UNGASS, said Dr. Alex Wodak, a leading drug reform advocate from Australia, said. “It cannot be revived.”
“We are in a transition from a predominantly criminal justice approach to a more health and social approach. Most of Western Europe has made that transition. North America has started… and many countries in Central and South America are on the way.”
Wodak, President of the Australian Drug Law Reform Foundation, said the case for relying on drug supply control had simply “collapsed” in Australia. “The evidence for cost effectiveness of harm reduction is now so compelling while the… severe unintended negative consequences and cost ineffectiveness of supply control is just as clear.  So it’s a very different discussion than in Asia where there is still much more acceptance of a drug-free world and punishment.”
A “drug-free world” was the 2015 goal of the Association of Southeast Asian Nations (ASEAN), a hopeless irony given the region’s flourishing drug trade. Between 2006 and 2013, opium poppy cultivation in the region’s “Golden Triangle” tripled, according to UNODC. Methamphetamine seizures in the region almost quadrupled from 2008 to 2013, to about 42 tons.
Governments have battled the rising trade by taking a hard stance on drugs, often directed at drug users, with police raids, forced urine testing and, in 11 countries, drug detention centers.
Drug users “face very serious human rights abuses” in these centers, Human Rights Watch associate director of health and human rights Diederik Lohman said, adding these centers violated international and often national law.
“Asia remains strongly invested in traditional law enforcement and justice approaches,” said Jeremy Douglas, UNODC’s Regional Representative for Southeast Asia and the Pacific. He called for a balance with these approaches and access to adequate health and social services. “I often comment that good public health equals good public security, but there is a distance to go before the balance is there [in Asia],” he said.
There is, however, “a significant move to align drug and public health policy,” he said. Skyrocketing HIV epidemics among injecting drug users — who number 3 to 5 million in Asia — have forced governments to change.
Take Malaysia. In the 1990s, drug users were all sent to prison or drug rehabilitation centers run by former army personnel, who enforced daily military drills and marching. More than 75 percent of reported HIV infections cases were among drug users.
It was a shocking situation for Dr. Adeeba Kamarulzaman who returned to Malaysia in 1997, after training and working in Melbourne, where it was rare to see injecting drug users acquiring HIV. “After seeing one patient after another with advanced HIV who was a drug user, I felt that something really needed to be done,” she said.
She put together a report with the help of Australian colleagues. “With that we went knocking on doors of agencies that had to do with either drug use or HIV…  Ultimately we went to the highest political leadership who gave us the go ahead to pilot a methadone program in 2005. The nod to do a needle exchange program came as a complete surprise,” said Adeeba, now the dean of University of Malaya’s Faculty of Medicine.
The scientific evidence helped make a case for harm reduction and maintain it. “We took great pains to ensure that we had a good monitoring and evaluation system in place,” she said.
The Cure and Care clinics which provide free, confidential, voluntary treatment such as methadone, have impressive results. One study found less than 40 percent of drug users attending the clinics relapse after a year — yet for compulsory detention centers, 50 percent relapse within a month, and 100 percent by a year. The clinics have been described as a model and have drawn visitors from across the region.
A recent return on investment study, done with World Bank support, found harm reduction had averted 12,600 new HIV infections.  “Hopefully this has gone some way in ensuring that the programs are continued,” Adeeba said.
Asia’s hard line on drugs is softening elsewhere too. Most countries now have some harm reduction programs, although not enough to meet needs, said Gloria Lai, senior policy officer for the International Drug Policy Consortium. Changes in Singapore and Vietnam may help limit the death penalty while public debate on drug decriminalisation has emerged in a few countries, she added.
Last year, representatives of nine Asian countries met in Manila with UNODC and other UN bodies and agreed to a transition towards voluntary, community-based services for drug users. “The discussion now needs to be taken up to the policy level with government ministers,” Douglas of the UNODC said.
He said the UN is also helping the Myanmar government prepare legislation on policy changes considered “quite progressive.”
Overall though, progress is still slow and piecemeal. In Malaysia, despite the success of harm reduction there, the country still maintains 28 drug rehabilitation centers and imprisons many drug users – 13,500 in 2014.
“Reform will be slow to come in the region because of the portrayal of drugs and any related activities as a security issue, in the minds of both government and the public, and the limited space for challenging those perspectives and policies,” said Lai.
She added some countries “will stay entrenched” in the tough, punitive approach “for a while to come,” in particular Singapore, Pakistan, Indonesia and China.
But with the international consensus on global drug prohibition in tatters, the push for reform will intensify. “The status quo countries can delay the inevitable but not prevent it. We can expect to see more Asian countries start moving to reform in the next few years,” said Wodak. But he added: “There will always be a Singapore or two or three that will champion the hard line approach for decades to come.”

The Bowman Avenue Dam, in Rye, New York, would seem an unlikely candidate for a new front in the cyber wars. Twenty-two feet tall, a hundred and twenty-two feet long, and sitting in the woods just up the street from Port Chester Middle School, the dam spans Blind Brook, a minor waterway that runs south through the city and empties into Long Island Sound.
Built in the early nineteen-hundreds, the dam was updated most recently in June of 2013, when local officials gathered to commemorate the addition of a two-million-dollar sluice gate, which would help manage flooding in the nearby neighborhood of Indian Village. Speeches were given, and novelty scissors were wielded to cut through red, white, and blue ribbon.
Then, late last week, top officials at the Justice Department held a press conference to announce that they were filing criminal charges against a group of seven veteran Iranian hackers, including one who was rooting around in the dam’s operating system. The hackers allegedly worked for private companies with ties to the Iranian government and intelligence world, and they were accused of conducting a “coordinated campaign of cyber attacks” against targets in the United States. “These were no ordinary crimes, but calculated attacks by groups with ties to Iran’s Islamic Revolutionary Guard and designed specifically to harm America and its people,” U.S. Attorney Preet Bharara, of the Southern District of New York, said. Among the hackers’ alleged targets were major banks, the Nasdaq, and the New York Stock Exchange.
What exactly the Iranians wanted with the dam remains unclear, at least publicly. The story told in the federal indictment is straightforward, if silent on possible motives. Evidently a single hacker, Hamid Firoozi, was responsible for the intrusion. Several times between August 28th and September 18th of 2013, Firoozi allegedly obtained “unauthorized remote access” to the computer, housed in a basement room in Rye’s city hall, that controlled the dam’s “supervisory control and data acquisition” system. That access allowed Firoozi to see information about water levels, water temperature, and the status of the recently installed gate, designed to control water levels and flow rates. What Firoozi didn’t know, the government says, is that the gate didn’t work.
Concerns about the dam hack apparently went all the way up the White House. Was the hacker trying to gain control of the Bowman Avenue Dam? Did he arrive there by accident, perhaps while hunting for a more impressive Bowman dam, such as the two-hundred-and-forty-foot-tall Arthur R. Bowman Dam, in Oregon? Over the weekend, the Wall Street Journal reported that Firoozi had “stumbled” onto the dam in Rye while using a publicly available search process called “Google dorking.” According to sources who spoke with the Journal, Firoozi had been using the technique for months, applying specific search parameters to “scour websites connected to U.S. infrastructure sites for vulnerable hardware systems.”
Paulo Shakarian, a cyber-security fellow at New America and the co-author of Introduction to Cyber-Warfare: A Multidisciplinary Approach, told me that the strategy made sense. Computer systems that control physical mechanisms run specialized software and are connected to specialized hardware. These devices are made by only a few manufacturers, Shakarian said, which means that they’re easier for hackers to locate, and that exposed systems stand out more readily. A tool like Google dorking can simplify the process further. “You can do searches through the Internet to find signatures of these industrial control systems,” Shakarian said. The real work for a modern-day hacker lies in the preliminary research; once that’s done, the hacker writes a program and lets it run automatically for a period of time before checking the results. “It’s not like in old hacker movies, where you see the hacker up all night trying to get into a computer,” Shakarian said.
That the hacker was able to access the dam’s computer suggests that he knew what he was looking for. Once a hacker finds a target, Shakarian said, he must successfully communicate with it. “You can try talking to it like it’s an Internet server, you can try talking to it like an e-mail server, or you can try talking to it like it’s a computer at a nuclear power plant.” Understanding the computer’s response becomes critical to understanding what the computer does. That’s where the preliminary research again becomes important.
“Why Rye?” Shakarian asked. “Here’s the likely answer: that was what was available.” But still the question remained: what did the hacker want? Shakarian offered a few theories. “If I want to understand better about how to mess up an industrial control system in a cyber-war scenario, what better way than to look for something that’s exposed, that I can easily gain access to,” he said. “Or it just might be a guy that wants to screw around with this for a random reason.” The bigger threat, Shakarian said, comes once a hacker finds him or herself inside a system and starts to figure out its inner workings. “I get a feel for the response,” he said. “I could then write malware that automates that. And, if I could get that malware on industrial control systems for thousands of floodgates throughout the U.S., now I have something that’s like a ticking time bomb or a precision weapon that I could launch at will.”
But no amount of preliminary research can fully prepare a foreign cyber attacker for the workings of American small-city governance. The federal indictment notes that the hacker wasn’t able to actually control the Bowman Avenue Dam’s new sluice gate because the gate was manually disconnected at the time, for maintenance reasons. In fact, the gate was never fully operational. “There are still kinks, some monitoring issues,” a local official told the Westmore News at the time of the ribbon-cutting ceremony. But Marcus Serrano, the current city manager of Rye, told me that the software necessary to control the gate remotely hadn’t yet been installed when the ceremony was held, in 2013, and it still hasn’t. The system is supposed to automatically monitor the water upstream and downstream but “we’re nowhere near that,” Serrano said. “We need to hire a hydraulic engineer to determine where the sensors should be located, and then do the calculations and figure out, if a rainstorm is expected, should the gates open or close.”
Like other local officials, Serrano has his own theories about the hack. “I think they were fishing,” he said. “They went in a couple times, looked around, and then they left and never came back. I guess they realized we’re not significant enough to hack into anymore.”

In  February, the Pentagon revealed that it has begun an aggressive cyber campaign against the Islamic State.
The Associated Press reported that U.S. offensive cyber attacks are targeting the group’s ability to use social media and the internet to recruit fighters and inspire followers, including preventing the group from distributing propaganda, videos, or other types of recruiting and messaging on social media sites like Twitter.
Three days later, Secretary of Defense Ash Carter told reporters that cyber operations are underway to interrupt the Islamic State’s “command and control, to cause them to lose confidence in their networks, to overload their networks so that they can’t function,” particularly in Syria.
The Obama administration should be commended for any measure that disrupts IS’ ability to recruit foreign fighters, inspire “lone wolves,” conduct operations in Syria, or coordinate attacks abroad. Yet while there are numerous unanswered questions regarding this new cyber offensive — Secretary Carter, understandably, declined to provide specifics — the first one may be: “What took them so long”?
In his September 2014 address to the American people justifying military operations against IS, President Obama declared: “I have made it clear that we will hunt down terrorists who threaten our country, wherever they are. That means I will not hesitate to take action against [the Islamic State] in Syria, as well as Iraq.” Yet the history of the anti-IS campaign, dubbed Operation Inherent Resolve, is rife with examples of the Obama administration’s hesitance to take actions later deemed necessary to disrupt and degrade the terrorist network:
Despite declaring “Stopping [IS’] financing and funding,” one of the five mutually reinforcing lines of effort to degrade and defeat the group in September 2014, the administration chose not to target the massive convoys of fuel trucks smuggling its oil — generating up to $2 million in revenue per day for the terrorist proto-state — until last November, a full 15 months into the anti-IS air campaign;
The CIA and Joint Special Operations Command reportedly only began a drone campaign to hunt IS leaders in Syria last summer;
It was not until last October — 14 months into Operation Inherent Resolve — that President Obama ordered less than 50 special operations troops into Syria to advise local forces fighting IS.
This hesitance is especially puzzling in the case of cyber operations. The idea of conducting cyber operations against terror networks or in Syria is not exactly new. In 2013, U.S. intelligence operatives covertly sabotaged al Qaeda in the Arabian Peninsula’s propaganda efforts by hacking its online magazine Inspire. When airstrikes against the Assad regime in response to its use of chemical weapons against civilians appeared imminent in 2013,speculation was rampant that offensive cyber attacks would be a component of any military operation. Moreover, the administration clearly recognizes the threat posed by the Islamic State’s activity in cyberspace. Countering its propaganda and recruitment efforts was one of the original five lines of operation. Given that in November 2014 there were estimated to be roughly 46,000 IS-linked Twitter accounts, this line of operation would inevitably require a significant cyber component. Last August, after IS hackers posted the names, addresses, and photos of U.S. troops on Twitter, U.S. forces conducted a targeted drone strike in Raqaa, Syria, killing Junaid Hussain, a British citizen in his early 20s believed to be a leader of the Islamic State’s hacking division. Thus, the option of offensive cyber operations in Syria had been available for almost three years — and IS propaganda and cyber activity had been deemed a threat for 16 months — before the administration authorized their deployment.
There are three possible explanations for this delay:
The administration wanted to avoid establishing a precedent:
P.W. Singer of the New America Foundation noted that Carter’s admission “is the first public acknowledgment” the U.S. military is carrying out offensive cyber operations, and argued that this is “a big line to cross.” Given the conventional wisdom in some quarters that the alleged U.S.-Israeli cyber attack on Iran’s Natanz nuclear reprocessing facility triggered a cyber arms race, it is possible the administration wanted to avoid creating a new norm regarding offensive cyber operations. Yet there are several precedents of states conducting cyber attacks in coordination with military operations. Israel used a cyber attack to disable Syrian air defenses in 2007’s Operation Orchard, destroying the nuclear reactor under construction at Kibar. In 2008, Russian “patriotic hackers” crippled key portions of Georgia’s communications systems to facilitate their invasion of the country. In fact, this is not even the American use of offensive cyber operations as a force multiplier in a broader military campaign, as in 2007 U.S. forces hacked into al Qaeda in Iraq’s cellphone network to send fake texts directing insurgents to locations where they were subsequently targeted. Thus, although acknowledging such cyber operations may be unprecedented, there was certainly no precedent sufficient to deter the administration from actually deploying this capability against IS.
The potential costs of cyber operations against IS outweighed the potential gains.
Even as IS has perfected the use of social media for propaganda and recruitment purposes, the U.S. intelligence community has used extremists’ Twitter feeds to monitor their messaging for strategies, tactics, and policies.As one former National Security Agency official noted: “Twitter is an incredible source to learn what these groups are doing. The FBI, CIA, and NSA not only get a lot of intelligence from Twitter, but there is also a lot of manipulation going on.” Thus, the administration may have foregone attacking IS in cyberspace over concerns that blocking its internet access could hurt intelligence gathering. Alternatively, cyber attacks frequently have unintended consequences. In 2008, for example, the U.S. military’s dismantling of a Saudi website that U.S. officials suspected of facilitating suicide bombers in Iraq also inadvertently disrupted more than 300 serversin Saudi Arabia, Germany, and Texas. Fear of similar negative second-order effects may have inhibited the administration.
While such concerns are legitimate, they are also manageable. Secretary Carter reportedly ordered that cyber operations be conducted without diminishing the indications or warning U.S. intelligence officers can glean about IS activities, suggesting this risk can be assessed and mitigated. In fact, Carter went a step further and suggested the hacking campaign could force IS to communicate via more easily interceptable methods. Moreover, although the risk of blowback is endemic to cyber warfare, it may be outweighed by the operational value of the targeted network. In discrete operations such as the jamming of IS online communications networks during the four-day battle for Shaddada in mid-February, which helped U.S.-backed Syrian rebels retake the town and nearby oil fields, the operational objective attained was worth the risk of spillover to untargeted networks.
Either way, the Pentagon clearly believes these risks can be evaluated on a case-by-case basis, and should not have precluded the use of all cyber operations against IS.
The administration is not actually trying to defeat IS.
According to the Los Angeles Times, the cyber offensive against IS was not launched until last December after the IS-inspired attack in San Bernardino, California, that killed 14 Americans. Consequently, in a White House meeting, administration officials directed senior Pentagon officials to prepare options for more aggressive cyber operations. If true, this merely represented the latest in a series of entirely reactive escalations by the Obama administration in Syria and Iraq. President Obama initially dismissed IS as the jayvee team of terrorism, and only signed off on military operations against the group in response to its conquest of Mosul in June 2014 and the subsequent threat of genocide against Iraq’s Yazidi population. The announcement of a drone campaign against IS leadership followed the fall of Ramadi last summer. The deployment of U.S. special operations advisers to aid Syrian rebels only came after Russia began combat operations in Syria last October. Similarly, the decision to accept a greater risk of civilian casualties while bombing IS fuel convoys was only taken after November’s IS-sponsored attack in Paris that killed 130 people.
None of these assets were committed to the anti-IS campaign as part of a comprehensive strategy for defeating the group, but rather as defensive measures in response to successful Islamic State operations or expansion. In a sense, the administration’s incremental deployments are reminiscent of Leslie Gelb and Richard Betts’ famous conclusion in The Irony of Vietnam regarding the Kennedy and Johnson administration’s decision-making: “Each time they turned the ratchet of escalation up another notch they did not believe that the increase would provide victory [in Vietnam].” Similarly, the Obama administration’s incrementalism projects the appearance of fighting not to lose in Syria and Iraq.
Why does the administration appear to have eschewed victory against IS as a strategic objective? Some analysts speculate that President Obama does not want to risk empowering anti-IS groups that also oppose Bashar al-Assad — or even provide Syrian civilians with a modicum of protection from his forces — in order to avoid jeopardizing its pursuit of detente with Iran. Alternatively, it is possible that President Obama does not perceive IS to be a significant threat to U.S. national security. He told Jeffrey Goldberg that the Islamic State “is not an existential threat to the United States,” especially when compared to climate change, and reiterated this sentiment in his remarks from Argentina on the Brussels suicide bombings that killed at least 31 people and wounded 270. Alternatively, President Obama may view the struggle against IS as unwinnable. When asked “Why don’t you just go get the bastards [ISIL]?” the President’s reponse is that “we just don’t have the tools in our toolkit to have a huge impact.”
Although it can plausibly be argued that the costs of an intervention capable of defeating IS — or at least eliminating its manifestation as a proto-state in Syria and Iraq — outweigh the threat it represents, the president certainly seems to find these “tools” effective enough each time his policy appears broken.
Whatever the cause, there are significant dangers to the Obama administration’s incrementalism. First, by deploying new assets solely as a reactionary measure, the White House is ceding the initiative in Syria and Iraq to a web of actors — IS, Iran, and Russia — who are pursuing goals in direct opposition to U.S. interests and will shape conditions in the region accordingly. Second, by failing to make clear that it has settled for a policy of containing IS, the Obama administration has created a disconnect between its rhetoric and the resources deployed by its ad hoc escalations. This exacerbates the appearance of American inconstancy evidenced by President Obama’s refusal to enforce the 2013 “red lines” over Assad’s use of chemical weapons, further undermines U.S. credibility in the region, and may lead regional allies to seek help from other great powers. Finally, by repeatedly deploying the minimum resources necessary to prevent the Islamic State’s expansion rather than committing them in a decisive and deliberate fashion, the administration risks prolonging the conflict. Beyond the devastating humanitarian toll in terms of civilian deaths and refugees, this has enabled the self-declared caliphate to serve as an inspiration to “lone wolves” and homegrown jihadists, as well as plan terrorist attacks abroad.
By failing to deploy all relevant assets to the anti-IS campaign at the outset in a deliberate and decisive fashion, the administration has increased the probability that the horrors of Paris, Brussels, and San Bernardino will be repeated. President Obama may be right that such attacks do not threaten the “existence of our nation”, but they certainly pose an existential threat to the lives of U.S. citizens and those of our allies.


A few years ago cyberattacks were on the margins of news stories. But after a series of high-profile attacks against major financial institutions, retailers and healthcare providers, people realize that cyberattacks aren’t going away.
The need to address increasingly sophisticated threats against U.S. businesses has rapidly gone from an IT issue to a top priority for the C-suite and the boardroom.
Cybercrime is among the most urgent threats to U.S. national and economic security, and these threats are increasing in scale, sophistication and frequency. Bad actors from criminals to nation-states use cyberattacks because they are cheap, easy and lucrative. Here in the state of Michigan, hackers attempt millions of attacks every day. According to a McAfee report, the global impact of cybercrime tops $375 billion annually, and the estimated cost to U.S. businesses is 200,000 jobs lost annually. It’s not surprising that a Gallup poll found that people are more concerned about cyber theft and hacking than any other kind of crime.
U.S. businesses are responsible for protecting their cyber networks. This includes not only their intellectual property and trade secrets but also the personal information of their employees and customers. There isn’t a silver bullet to create a more secure and resilient network. However, there are numerous tools available to industry to reduce vulnerabilities and mitigate cyber risk.
One tool that offers an important first line of defense is timely, actionable cyber threat data. This is something the government and private sector agree on, and following a bipartisan push in the House of Representatives and the Senate last year, President Obama signed the Cybersecurity Information Sharing Act into law. This landmark legislation gives businesses the legal protection they need to feel safe when voluntarily sharing or receiving threat data with industry peers and the government.
Yet we’ve still got work to do. In a recent IBM survey of CEOs, 55 percent of respondents said that information sharing is necessary in fighting cybercrime, but only 32 percent said they are willing to share their organizations’ cyber-threat data.
One example of positive, proactive data sharing can be found by looking at an industry pivotal to Detroit. Members of the Alliance of Automobile Manufacturers and the Association of Global Automakers established an auto-specific information sharing and analysis center with Homeland Security to facilitate sharing existing or potential threats to motor vehicle cybersecurity among members of the industry. In addition, members of the two associations have recently released a Framework for Automotive Cybersecurity Best Practices. Building on the auto framework, the industry plans to begin developing automotive cybersecurity best practices and continue collaborating with external stakeholders and cybersecurity experts as appropriate.
Since its founding, the Internet has fundamentally changed how we connect with others, the nature of our work, and how we discover and share news and new ideas. Industry and government are building a strong foundation to preserve our competitive advantage in the global economy and protect the privacy of American people.
But, one thing is certain — protecting America’s critical cyber infrastructure is a team sport.


Cyber extortion emerged as a strong trend in 2015, and is expected to continue in 2016, according to the latest threat report by security firm F-Secure.
The most common form of cyber extortion in recent months is the use of malware to encrypt organizations’ files and demand ransom payment in return for the decryption keys.
2015 saw the rise in popularity of several families of so-called ransomware, especially Cryptowall, Crowti and Teslacrypt, the report said.
While the Angler exploit kit delivered Alpha Crypt, Reveton and ransomware, the Nuclear exploit kit delivered CTB-Locker and Troldesh. However, Cryptowall and TeslaCryp was delivered by both, with Cryptowall also delivered by the Magnitude and Fiesta exploit kits.
In the first quarter of 2016, F-Secure said several large organizations had been hit by consumer-type ransomware, including some hospitals and local government authorities, causing “a considerable amount of pain” for those organizations.
Exposing data
However, cyber extortion is being increasingly conducted using the threat of distributed denial-of-service (DDoS) attacks and the threat of exposing sensitive commercial data.
This data typically includes intellectual property and information relating to legal cases or mergers and acquisitions, according to Sean Sullivan, security advisor at F-Secure Labs.
“We expect 2016 to be the year of cyber extortion, with big company database breaches followed up by demands for payment not to publish the data,” he told Computer Weekly.
In the past ten years, said Sullivan, malware as a service has become entrenched as a business model in the hands of organized professionals, moving beyond commoditized malware to hacks of corporate databases.
“If corporations have not started segregating and segmenting their data into isolated zones on the network, that is tantamount to negligence,” he said.
Far too many organizations are keeping mission-critical documents and intellectual property on network shares, said Sullivan. These can be accessed by hackers and even commoditized malware. “Just by moving laterally across a network, sensitive data is often easily accessible to attackers because there are no barriers or controls,” he said.
In 2015, Sullivan said there was plenty of evidence that organizations are not able to prevent intrusions by commoditised malware. “If organizations were not prepared for commoditized malware and dumb bots in the past year, they are unlikely to be prepared for human hackers following the bot in 2016,” he said.
Cyber extortion
F-Secure researchers predict there will be a shift towards intelligent, targeted attacks aimed mainly at extorting money from organizations.
Sullivan believes the attack on Sony Pictures Entertainment in November 2014 fell into this category. It was the first of this kind of attack to make headlines.
Although the attack has been linked to North Korea’s anger over the film The Interview, Sullivan said the initial emails relating to the attack demanded money, which means cyber extortion was more likely the prime motive for the attack.
Similarly, he said the attacker behind the Ashley Madison breach may have disapproved of the company’s business, but the prime motive was extortion and data was dumped only when the company failed to give into demands.
Sullivan suspects there may have been several other similar cases that have not made the headlines because targeted companies elected to pay off the cyber extortionists.
“In 2016, I think we will see an example of a large corporation dealing with customer data facing threats of that data being dumped onto the internet if they fail to make a certain payment,” he said.
Exploit kits
Another key finding of the report is that exploit kits face a disruptive future in the light of the fact that prominent exploit kits such as Angler, Nuclear and others mostly took advantage of vulnerabilities in Adobe Flash.
Sullivan predicts that Google Chrome will kill Flash support in early 2017, and Mozilla Firefox and Microsoft Edge will follow. This could mean that, by early 2017, Flash will no longer bear fruit for exploit kit makers.
Exploits, which have become one of the most common vehicles for malware in the past decade, need out-of-date software to accomplish their goal of getting through security holes. However, that software will become increasingly difficult to find, according to Sullivan.
For example, with HTML 5’s capability to “do it all”, the need for third-party browser plugins has mostly been eliminated. Today’s browsers themselves are auto-updated, without the need for the user to intervene, so users always have the latest version.
Hopefully exploits will die, said Sullivan, with Microsoft’s software being much more secure than it used to be; with Adobe’s other software becoming increasingly cloud based; and with browser developers forcing Java into a restricted place.
Macro malware makes a comeback
However, he said, cyber attackers will move onto something else. This will most probably be, for the short term, falling back on email attachment-based malware schemes. One such scheme is macro malware, which re-emerged in 2015 after lying low since the early 2000s.
Malware authors use the macro feature in Microsoft Office to implant malicious code to documents they email as attachments.
With Office 2003, Microsoft changed default settings to no longer run macros automatically, making attacks much more difficult. But now macro malware attempts to get around Microsoft’s default settings by displaying text in the open document that claims it is a “protected” document that requires the user to enable macros.
“In the past, we have seen attackers revert to older methods, such as when the Blackhole exploit kit was shut down, the attackers behind the GameoverZeus Trojan switched to using zip files and macro documents to distribute the malware,” said Sullivan.
As attackers are less able to exploit browser plugins to install malware on the disk, F-Secure also expects attackers to turn to malware that is resident only in memory and does not require installation on disk. “Cyber extortion through encrypting critical files does not necessarily require persistence, it only has to life long enough to locate and encrypt the targeted data,” said Sullivan.

Greater focus on browsers
As third-party plugins are phased out, F-Secure expects greater focus on using browsers as a way to infect computers.
“Even though there has been a concerted effort to harden browsers, there are probably tricks up attackers’ sleeves that they haven’t used yet,” said Sullivan.
To defend against these tactics, he said organizations should ensure they have usable backups that are not cloud based or connected to the corporate network in any way.
“In 2016, organizations should really be focusing on protecting their data, because that is what attackers are going after more than ever,” said Sullivan.

MKRdezign

{facebook#https://www.facebook.com/newssort} {twitter#https://twitter.com/meher_imran} {google#https://plus.google.com/u/0/111617136549267753043} {pinterest#https://www.pinterest.com/newssort/} {tumblr#http://newssort.tumblr.com/}

Contact Form

Name

Email *

Message *

Weekly News sort. Powered by Blogger.
Javascript DisablePlease Enable Javascript To See All Widget