Symantec has created a great video that demonstrates the use and function of Ghostnet.
You can also read Symantec's write-up about the Ghostnet backdoor here.
Saturday, April 4, 2009
Heading to Tallin
I'm headed to the Cooperative Cyber Defense Center of Excellence's Conference on Cyber Warfare in Tallin, Estonia. The Conference is in mid-June and boasts an outstanding line-up of speakers - you can visit the website for more detailed information.
I'll be giving a presentation on historical analogies for cyberspace. Specifically, my colleague and I will examine if there are other alternatives to the oft discussed digital Pearl Harbor and cyber Katrina analogies. I am concerned about the current narrative surrounding cyberspace in general and am in particular concerned that policy makers are narrowly driven by fear of a massive cyber attack. It is my concern that this fear will drive over regulation and cause more problems than the regulation attempts to solve.
If this argument sounds familiar it should. Jonathan Zittrain outlined this same concept of the 'generative dilemma' in his book the Future of the Internet.
I'll be giving a presentation on historical analogies for cyberspace. Specifically, my colleague and I will examine if there are other alternatives to the oft discussed digital Pearl Harbor and cyber Katrina analogies. I am concerned about the current narrative surrounding cyberspace in general and am in particular concerned that policy makers are narrowly driven by fear of a massive cyber attack. It is my concern that this fear will drive over regulation and cause more problems than the regulation attempts to solve.
If this argument sounds familiar it should. Jonathan Zittrain outlined this same concept of the 'generative dilemma' in his book the Future of the Internet.
Friday, April 3, 2009
Kreb's on Conficker
Lots of great reporting from Brian Kreb's on the threat from Conficker. Kreb's echoes a lot of points that we discussed in class and have previously made on this blog.
But whatever the number of infected machines, I think one important aspect of this and other date-based threats like Conficker is that they are in danger of being overlooked amid all the the I-told-you-sos and the nothing-to-see-here-move-along type sentiments.
One problem with over-hyped threats that fail to live up to expectations (as they invariably do) is that they tend to desensitize the average user to more insidious, stealthier threats.
All of that said, the truth is that the threat from Conficker is as real today as it was three days ago on April 1: The worm's author(s) could easily decide to wait until everyone's guard is down to instruct all infected systems to update themselves with additional malicious components, or to attack some target online or start blasting spam.
As stated earlier, we need to move past overhyped vulnerability analysis and embrace a more holistic risk analysis paradigm that encompases threat, vulnerability, and consequence.
Balancing Security and Privacy in Cyberspace
In the race to legislate solutions to our nation's vulnerabilities in cyberspace are we giving up more privacy protections? A recent piece in Mother Jones offers a good examination of the trade-offs between privacy and security in cyberspace in current legislation being proposed on Capitol Hill.
From Mother Jones,
a bill to establish the Office of the National Cybersecurity Advisor - an arm of the executive branch that would have vast power to monitor and control Internet traffic to protect against threats to critical cyber infrastructure. That broad power is rattling some civil libertarians.The Cybersecurity Act of 2009 gives the president the ability to "declare a cybersecurity emergency" and shut down or limit Internet traffic in any "critical" information network "in the interest of national security." The bill does not define a critical information network or a cybersecurity emergency. That definition would be left to the president.The bill does not only add to the power of the president. It also grants the Secretary of Commerce "access to all relevant data concerning [critical] networks without regard to any provision of law, regulation, rule, or policy restricting such access." This means he or she can monitor or access any data on private or public networks without regard to privacy laws.
Do you think the Executive Branch needs these kinds of authorities to protect cyberspace?
NSA and the Equities Dilemma
The equalities dilemma can best be described as weighing the pros and cons of exploiting or disclosing a vulnerability. For example, imagine that the National Security Agency (NSA) discovers a flaw in Microsoft Outlook that allows a remote attacker to read the entire contents of a target's email account. Does the NSA inform Microsoft of this vulnerability or does it use it to exploit the target's vulnerable email account for signals intelligence collection? Will keeping the vulnerability secret hurt the United States - as other hackers, cyber criminals, or nation-states may have discovered the same flaw and are using it to gather intelligence on US Government and private sector targets?
In a recent Wall Street Journal Op-Ed, Bruce Schneier nicely summarizes this dilemma stating,
what happens when both the good guys the NSA wants to protect, and the bad guys the NSA wants to eavesdrop on, use the same systems? They all use Microsoft Windows, Oracle databases, Internet email, and Skype. When the NSA finds a vulnerability in one of those systems, does it aler the manufacturer and fix it - making both the good and bad guys more secure? Or does it keep quiet about the vulnerability and not tell anyone - making it easier to spy on the bad guys but also keeping the good guys insecure?
Can this dilemma be resolved via a calculation regarding our exposure to a vulnerability compared to the potential value of intelligence gained through the vulnerability? Is it possible to calculate our total exposure to a vulnerability when many of the targets of cyber crime and cyber espionage are in the private sector?
Wednesday, April 1, 2009
GhostNet Breakdown
The Information Warfare Monitor (IWM) provides an excellent in-depth analysis of the design and function of GhostNet. As we discussed GhostNet was a botnet comprised of approximately 1,300 infected machines. The infected machines were located in 103 countries and appear to have been specifically targeted because they contained access to politically sensitive information.
The following graphic produced by the IWM provides a breakdown of where the infected computers were located.
I highly recommend that you read the IWM report.
The following graphic produced by the IWM provides a breakdown of where the infected computers were located.
I highly recommend that you read the IWM report.
Are you Infected by Conficker?
Security researcher Joe Stewart has developed a very simple and incredibly easy to use tool that will tell you if you have been infected by Conficker. Visit Joe's website here and follow the instructions to test your local computer.
Joe's tool tests whether or not your computer can access a series of websites that are blocked by Conficker. If you can get to these sites then you're clean, if you can't then you've been infected. If you find that you've been infected visit the SANS Internet Storm Center and consult the listed resources for removing Conficker from your computer.
Joe's tool tests whether or not your computer can access a series of websites that are blocked by Conficker. If you can get to these sites then you're clean, if you can't then you've been infected. If you find that you've been infected visit the SANS Internet Storm Center and consult the listed resources for removing Conficker from your computer.
Subscribe to:
Posts (Atom)