Showing posts with label Cyber Espionage. Show all posts
Showing posts with label Cyber Espionage. Show all posts

Tuesday, October 4, 2011

Congressman lambastes Chinese cyber-espionage

From the Washington Post,

The chairman of the House intelligence committee on Tuesday launched a broadside against the Chinese government and its efforts to steal commercial data and other intellectual property online, saying that Beijing’s cyber-espionage campaign has “reached an intolerable level” and that the United States and its allies have an “obligation to confront Beijing and demand that they put a stop to this piracy.”

Rep. Mike Rogers (R-Mich.) noted that it might seem odd that a lawmaker charged with overseeing the U.S. intelligence community should lament spying by another government. But he said that China’s espionage activities now extend beyond the U.S. government and military to include scores of private American companies.


Continue reading here

Sunday, October 2, 2011

Homeland Security tries to shore up nation’s cyber defenses

From the Washington Post,

Screens glowed, mice clicked and lines of code scrolled on the laptop monitors of a hacker team hired by Barney Advanced Domestic Chemical Co. — or BAD Company — to break into a rival firm’s computer network.

In another room here at Idaho National Laboratory, a computer operator noticed something wrong. “They’re hitting one of our servers!” he said. The lights in the control room soon failed, and liquid gushed from a set of tanks as green and red lights flashed.

“We’ve got a spillover!” shouted the supervisor. “Call the hazmat team!”


Continue reading here.

2,700 hacking attempts on S.Korea military in year

From the AFP,

South Korea's military has seen more than 2,700 attempts to hack into its websites over the past year, a lawmaker said Wednesday, amid growing concern over North Korea's cyber warfare capability.

Kim Ok-Lee of the ruling Grand National Party said the military's websites had seen 2,772 hacking attempts from July 2010 to last month, according to data from the defence ministry.

The monthly average number of attacks has grown from some 170 last year to more than 200 in 2011, the ministry said in a report submitted to Kim.


Continue reading here

Sunday, September 25, 2011

'Lurid' malware hits Russia, CIS countries

Courtesy of ComputerWorld's Jeremy Kirk,

The latest espionage-related hacking campaign detailed by security vendor Trend Micro is most notable for the country it does not implicate: China.

Researchers from Trend Micro wrote on Thursday that they discovered a series of hacking attacks targeting space-related government agencies, diplomatic missions, research institutions and companies located mostly in Russia but also Vietnam and Commonwealth of Independent States countries. In total, the attacks targeted 1,465 computers in 61 countries.


Read more here

U.S. Expresses Concern About New Cyberattacks in Japan

Courtesy of Hiroko Tabuchi of the New York Times,

The United States gave a stern warning on Wednesday over recent cyberattacks on Japan’s biggest defense contractors, the latest in a series of security breaches that have fueled concern about Tokyo’s ability to handle delicate information.

An online assault on defense contractors including Mitsubishi Heavy Industries, which builds F-15 fighter jets and other American-designed weapons for Japan’s Self-Defense Forces, began in August, but only came to light this week, prompting rebukes from Japanese officials over the timing of the disclosure. The IHI Corporation, a military contractor that supplies engine parts for fighter jets, may have also been a target, the Nikkei business daily reported.


Read more here

Saturday, March 26, 2011

Hack Obtains 9 Bogus Certificates for Prominent Websites; Traced to Iran

From Kim Zetter at Wired's Threat Level Blog,

In a fresh blow to the fundamental integrity of the internet, a hacker last week obtained legitimate web certificates that would have allowed him to impersonate some of the top sites on the internet, including the login pages used by Google, Microsoft and Yahoo e-mail customers.

The hacker, whose March 15 attack was traced to an IP address in Iran, compromised a partner account at the respected certificate authority Comodo Group, which he used to request eight SSL certificates for six domains: mail.google.com, www.google.com, login.yahoo.com, login.skype.com, addons.mozilla.org and login.live.com.

The certificates would have allowed the attacker to craft fake pages that would have been accepted by browsers as the legitimate websites. The certificates would have been most useful as part of an attack that redirected traffic intended for Skype, Google and Yahoo to a machine under the attacker’s control. Such an attack can range from small-scale Wi-Fi spoofing at a coffee shop all the way to global hijacking of internet routes.

At a minimum, the attacker would then be able to steal login credentials from anyone who entered a username and password into the fake page, or perform a “man in the middle” attack to eavesdrop on the user’s session.

Comodo CEO Melih Abdulhayoglu calls the breach the certificate authority’s version of the Sept. 11 terror attacks.

“Our own planes are being used against us in the C.A. [certificate authority] world,” Abdulhayoglu told Threat Level in an interview. “We have to up the bar and react to these new threat models. This untrusted DNS infrastructure cannot be what drives the internet going forward. If DNS was trusted, none of this would have been an issue.”

Comodo says the attacker was well prepared, and appeared to have a list of targets at the ready when he logged into the company’s system and began requesting certificates.

In addition to the bogus certificates, the attacker created a ninth certificate for a domain of his own under the name “Global Trustee,” according to Abdulhayoglu.

Abdulhayoglu says the attack has all the markings of a state-sponsored intrusion rather than a criminal attack.

“We deal with [cybercriminals] all day long,” he said. But “there are zero footprints of cybercriminals here.”

“If you look at all these domains, every single one of them are communications-related,” he continued. “My personal opinion is that someone is trying to read people’s e-mail communications. [But] the only way for this attack to work [on a large scale] is if you have access to the DNS infrastructure. The certificates on their own are no use, unless they have access to the DNS infrastructure itself, which a state would.”

Though he acknowledges that the attack could have originated anywhere, and been routed through Iranian servers as a proxy, he says Iranian president Mahmoud Ahmadinejad’s regime is the obvious suspect.

Out of the nine fraudulent certificates the hacker requested, only one — for Yahoo — was found to be active. Abdulhayoglu said Comodo tracked it, because the attackers had tried to test the certificate using a second Iranian IP address.

All of the fraudulent certificates have since been revoked, and Mozilla, Google and Microsoft have issued updates to their Firefox, Chrome and Internet Explorer browsers to block any websites from using the fraudulent certificates.

Comodo came clean about the breach this week, after security researcher Jacob Appelbaum noticed the updates to Chrome and Firefox and began poking around. Mozilla persuaded Appelbaum to withhold public disclosure of the information until the situation with the certificates could be resolved, which he agreed to do.

Abdulhayoglu told Threat Level that his company first learned of the breach from the partner that was compromised.

The attacker had compromised the username and password of a registration authority, or R.A., in southern Europe that had been a Comodo Trusted Partner for five or six years, he said. Registration authorities are entities that are authorized to issue certificates after conducting a due-diligence check to determine that the person or entity seeking the certificate is legitimate.

“We have certain checks and balances that alerted the R.A. [about the breach], which brought it to our attention,” he said. “Within hours we were alerted to it, and within hours we revoked everything.”

It’s not the first time that the integrity of web certificates has come into question.

Security researcher Moxie Marlinspike showed in 2009 how a vulnerability in the way that web certificates are issued by authorities and authenticated by web browsers would allow an attacker to impersonate any trusted website with a legitimately issued certificate
.

Thursday, February 3, 2011

Facebook treads carefully after its vital role in Egypt's anti-Mubarak protests

A fascinating look at Facebook's role in helping anti-government protesters in Egypt and around the world by the Washington Post's Cecilia Kang and Ian Shapira:

In Egypt, the tried-and-true tool for opponents of President Hosni Mubarak in recent years has been Facebook. Most recently, it was on Facebook - which boasts 5 million users in Egypt, the most in the Arab world - where youthful outrage over the killing of a prominent activist spread, leading to the protests in Cairo's Tahrir Square and Mubarak's promise to step down this year.

But Facebook, which celebrates its seventh birthday Friday and has more than a half-billion users worldwide, is not eagerly embracing its role as the insurrectionists' instrument of choice. Its strategy contrasts with rivals Google and Twitter, which actively helped opposition leaders communicate after the Egyptian government shut down Internet access.

The Silicon Valley giant, whether it likes it or not, has been thrust like never before into a sensitive global political moment that pits the company's need for an open Internet against concerns that autocratic regimes could limit use of the site or shut it down altogether.

"The movement [in Egypt] was very dependent on Facebook," said Alaa Abd El Fattah, an Egyptian blogger and activist in South Africa who has a strong following in Egypt. "It started with anger then turned into a legitimate uprising."

The recent unrest in Egypt and Tunisia is forcing Facebook officials to grapple with the prospect that other governments will grow more cautious of permitting the company to operate in their countries without restrictions or close monitoring, according to David Kirkpatrick, author of "The Facebook Effect," an authorized biography of the company's history. Facebook is also looking at whether it should allow activists to have a measure of anonymity on the site, he said.

"I have talked to people inside Facebook in the last week, and they are debating this internally," Kirkpatrick said. "Many countries where Facebook is popular have autocracies or dictatorships, and most of the countries have passively tolerated their popularity. But what's happened in Egypt or Tunisia is likely to change other countries' attitudes, and they'll be more wary of Facebook operating there."

A Facebook spokesman, Andrew Noyes, declined to make anyone at the company available to discuss its role in the Egypt protests or its strategy in politically fraught environments. In a short statement, Noyes said: "Although the turmoil in Egypt is a matter for the Egyptian people and their government to resolve, limiting Internet access for millions of people is a matter of concern for the global community. It is essential to communication and to commerce. No one should be denied access to the Internet."

(Washington Post Co. Chairman Donald E. Graham sits on Facebook's board.)

Even when Facebook has actively helped protesters work around government intrusions, the company casts its moves as mere technical solutions. Last month, after Tunisian security officials used a virus to secretly collect local Facebook user IDs and passwords, the Internet giant took action. It rerouted Tunisia's Facebook traffic to a site where local Internet service providers couldn't gobble up user information.

In a statement released to The Post, the company said it viewed the predicament as just a "security problem" in need of a fix.

"Certainly there's a political context to the particular circumstance in Tunisia, but from Facebook's perspective, what happened was a security problem that required a technological solution: we prevented an exploit that was making Facebook accounts vulnerable and restored the integrity of the compromised accounts," wrote Joe Sullivan, Facebook's chief security officer. "We would have taken the same approach in any situation where we saw a systematic exploit."

Yet Facebook seems to be veering in a different direction than Google, which has battled China over censorship, or Twitter, the microblogging site that earned renown during the Iranian protests of 2009 for delaying a scheduled shutdown and facilitating civil protest in Tehran. This week, Twitter, Google and SayNow, a voice-based social media platform, launched a service that provides Egyptians with phone numbers to call and leave messages, which are recorded and posted on the Internet. It's called Tweet2Speak.

In early 2010, in the wake of Google's censorship clashes with China, Facebook was one of a handful of companies blasted by Congress for refusing to participate in Senate committee hearings that examined how Silicon Valley companies were operating with foreign governments. Facebook responded at the time by saying it had no employees in China and that it was a different kind of business than Google.

Facebook's director of public policy, Tim Sparapani, wrote in a letter to Sen. Richard J. Durbin. (D-Ill.): "These conflicting approaches presents challenges for companies, particularly ones such as Facebook that are small and growing, to navigate new markets around the world without strong support from national governments and multinational institutions."

Facebook hasn't joined the Global Network Initiative, a nonprofit coalition of communications companies - including Microsoft, Google and Yahoo - established to create anti-censorship standards around the world. (Twitter hasn't joined, either.)

Some advocates of online free speech say Facebook can no longer linger on the sidelines.

"The good news for Twitter and Facebook is how important they are, and one should congratulate them for being critical tools," said John Palfrey, the co-director of Harvard University's Berkman Center for Internet & Society. "But also, there is an obligation that comes with that level of adoption."

Even though Facebook has refrained from taking overtly political stances on Egypt, the social network remains a vital tool for conveying anti-government news about Egypt.

Riyaad Minty, al-Jazeera's social-media head, said the news agency has been live-streaming its coverage of the protests on its Facebook fan pages in the United States and Arab world, boosting its fan volume by 30 to 50 percent; its half-dozen status updates about the crisis have reaped 10 million views a day, up from the 2 million daily views the pages had previously, Minty said.

"I do think governments see Facebook as a political tool, which is why Egypt has shut off the Internet," said Minty, adding that he prefers Facebook's more objective approach so it does not unnecessarily rattle conservative foreign leaders.

Additionally, Facebook ad sales teams have been helping al-Jazeera capitalize on Egypt's crisis to attract more eyeballs in the United States and build up a new, loyal audience.

"They've been giving us strategic advice," he said. "We're targeting people over 18, and our big push has been toward the U.S. audience."

Some Internet experts say Facebook needs to determine how to protect its users in countries with restrictive regimes, but the company's terms of use - which require members to use real identities - make protesters vulnerable to government spying. Facebook chief executive Mark Zuckerberg has insisted on the policy, saying the site would lose integrity if people hid behind phony identities.

"People at Facebook have been asking themselves in the wake of Egypt or Tunisia whether there might be a way they can allow political activities in these spontaneous revolts to acquire a little bit of anonymity," said Kirkpatrick, the company's biographer. "The problem is, if they start making it easier for political activists to use Facebook in places like Egypt or Tunisia, those same capabilities are likely to be used by people we don't admire or pro-government thugs."

Kirkpatrick added that these choices all come down to the company's famously private CEO.

"Inside Facebook," he said, "there's really only one person who makes these decisions. He has to decide."


Pay particular attention to the offense vs defense battle between nation-states and opposition movements. Specifically, how nation-states try to use platforms like Facebook to gather information on its opponents, while opposition parties attempt to use Facebook and other tools to rally dissent. This piece provides a fascinating perspective on the emerging battleground in cyberspace and how privacy and security are intertwined.

Sunday, November 14, 2010

Nobel Peace Prize, Amnesty HK and Malware

From Nart Villeneuve at SecDev.cyber ...

There have been two recent attacks involving human rights and malware. First, on November 7, 2010, contagiodump.blogspot.com posted an analysis of a malware attack that masqueraded as an invitation to attend an event put on by the Oslo Freedom Forum for Nobel Peace Prize winner Liu Xiaobo. The malware exploited a known vulnerability (CVE-2010-2883) in Adobe Reader/Acrobat. The Committee to Protect Journalists was hit by the same attack.

On November 10, 2010 Websense reported that website of Amnesty Hong Kong was compromised and was delivering an Internet Explorer 0day exploit (CVE-2010-3962) to visitors. In addition, Websense reports that the same malicious server was serving three additional exploits: a Flash exploit (CVE-2010-2884), a QuickTime exploit (CVE-2010-1799) and a Shockwave exploit (CVE-2010-3653).

The malicious domain name hosting the exploits mailexp.org (74.82.168.10) has been serving malware since Sept. 2010. The domain mailexp.org was registered in May 2010 to y_yum22@yahoo.com. mailexp.org was formerly hosted on 74.82.172.221 which now hosts the Zhejiang University Alumni Association website.

The malware dropped from the Internet Explorer exploit (CVE-2010-3962)
scvhost.txt
MD5: ca80564d93fbe6327ba6b094ae3c0445 VT: 2 /43

The malware dropped from the Flash exploit (CVE-2010-2884)
hha.exe
MD5: 0da04df8166e2c492e444e88ab052e9c VT: 2 /43

The malware dropped from the QuickTime exploit (CVE-2010-1799)
qq.exe
MD5: 3e54f1d3d56d3dbbfe6554547a99e97e VT: 16 /43

The malware dropped from the Shockwave exploit (CVE-2010-3653)
pdf.exe
MD5: 3a459ff98f070828059e415047e8d58c VT: 0/43

Both ca80564d93fbe6327ba6b094ae3c0445 and 3a459ff98f070828059e415047e8d58c perform a DNS lookup for ns.dns3-domain.com, which is an alias for centralserver.gicp.net which resolves to 221.218.165.24 (China Unicom Beijing province network).

The domain name “ns.dns3-domain.com” has been associated with a variety of malware going back to May 2010. This domain name, dns3-domain.com is registered to zhanglei@netthief.net, the developer of the NetThief RAT.

Malware attacks leveraging human rights issues are not new. I have been documenting them for some time (see, Human Rights and Malware Attacks, Targeted Malware Attack on Foreign Correspondent’s based in China, “0day”: Civil Society and Cyber Security). However, one of the issues that Greg Walton and I raised last year, is a trend toward using the real web sites of human rights organizations compromised and as vehicles to deliver 0day exploits to the visitors of the sites – many of whom may be staff and supporters of the specific organization. Unfortunately, we can expect this to continue.

Wednesday, September 29, 2010

FBI Drive for Encryption Backdoors Is Déjà Vu for Security Experts

From Wired Magazine via the New York Times,

The FBI now wants to require all encrypted communications systems to have back doors for surveillance, according to a New York Times report, and to the nation’s top crypto experts it sounds like a battle they’ve fought before.

Back in the 1990s, in what’s remembered as the crypto wars, the FBI and NSA argued that national security would be endangered if they did not have a way to spy on encrypted e-mails, IMs and phone calls. After a long protracted battle, the security community prevailed after mustering detailed technical studies and research that concluded that national security was actually strengthened by wide use of encryption to secure computers and sensitive business and government communications.

Now the FBI is proposing a similar requirement that would require online service providers, perhaps even software makers, to only offer encrypted communication unless the companies have a way to unlock the communications.

In the New York Times story that unveiled the drive, the FBI cited a case where a mobster was using encrypted communication, and the FBI had to sneak into his office to plant a bug. One of the named problems was RIM, the maker of BlackBerrys, which provides encrypted e-mail communications for companies and governments, and which has come under pressure from India and the United Arab Emirates to locate its severs in its countries.

According to the proposal, any company doing business in the States could not create an encrypted communication system without having a way for the government to order the company to decrypt it, and those who currently do offer that service would have to re-tool it. It’s the equivalent of outlawing whispering in real life.


Read the full article here.

Friday, April 16, 2010

Almost all Fortune 500 companies show Zeus botnet activity

From Ars Technica ...
Up to 88% of Fortune 500 companies may have been affected by the Zeus trojan, according to research by RSA's FraudAction Anti-Trojan division, part of EMC. The trojan installs keystroke loggers to steal login credentials to banking, social networking, and e-mail accounts.

The botnet was first identified in 2007 and is still around today. The malware tends to be difficult to detect and remove, and several million machines worldwide are believed to be infected. The Zeus server-side components, used to collect the stolen data, surprisingly mimic techniques more commonly seen in the world of commercial software; the software is licensed (with fees ranging from several hundred to a few thousand dollars), and each installation is tied to the hardware it's installed on in a system reminiscent of Microsoft's software activation. The malware itself predominantly attacks Windows XP machines, though Windows Vista and Windows 7 variants are available for sale too.
Read the full article here.

Tuesday, April 6, 2010

Researchers Trace Data Theft to Intruders in China

From the New York Times ...
Turning the tables on a China-based computer espionage gang, Canadian and United States computer security researchers have monitored a spying operation for the past eight months, observing while the intruders pilfered classified and restricted documents from the highest levels of the Indian Defense Ministry.

In a report issued Monday night, the researchers, based at the Munk School of Global Affairs at the University of Toronto, provide a detailed account of how a spy operation it called the Shadow Network systematically hacked into personal computers in government offices on several continents.

The Toronto spy hunters not only learned what kinds of material had been stolen, but were able to see some of the documents, including classified assessments about security in several Indian states, and confidential embassy documents about India’s relationships in West Africa, Russia and the Middle East. The intruders breached the systems of independent analysts, taking reports on several Indian missile systems. They also obtained a year’s worth of the Dalai Lama’s personal e-mail messages.
I had the pleasure of meeting one of the Citizen Lab's lead researchers Nart Villeneuve at a NATO conference last year and working with others including Greg Walton and Rafal Rohozinski while a member of Project Grey Goose. These guys do incredible work and have excellent insights into how nation-states and non-state actors use the Internet as a weapon.

There most recent report SHADOWS IN THE CLOUD: Investigating Cyber Espionage 2.0 is well worth the read and many of the reports key findings apply directly to our class discussions. In the report's forward the author's state,
Governments around the world are engaged in a rapid race to militarize cyber space, to develop tools and methods to fight and win wars in this domain. This arms race creates an opportunity structure ripe for crime and espionage to flourish. In the absence of norms, principles and rules of mutual restraint at a global level, a vacuum exists for subterranean exploits to fill.
There is a real risk of a perfect storm in cyberspace erupting out of this vacuum that threatens to subvert cyberspace itself, either through over-reaction, a spiraling arms race, the imposition of heavy-handed controls, or through gradual irrelevance as people disconnect out of fear of insecurity.

For those of you considering examining how nation-states are using cyber weapons to achieve political goals the SHADOW IN THE CLOUD report is a must read.

Wednesday, January 27, 2010

US oil industry hit by cyberattacks: Was China involved?

On January 25, The Christian Science Monitor published an article detailing cyber attacks against three Oil & Gas companies. According to the article,
At least three US oil companies were the target of a series of previously undisclosed cyberattacks that may have originated in China and that experts say highlight a new level of sophistication in the growing global war of Internet espionage. The oil and gas industry breaches, the mere existence of which has been a closely guarded secret of oil companies and federal authorities, were focused on one of the crown jewels of the industry: valuable “bid data” detailing the quantity, value, and location of oil discoveries worldwide, sources familiar with the attacks say and documents obtained by the Monitor show.

The companies – Marathon Oil, ExxonMobil, and ConocoPhillips – didn’t realize the full extent of the attacks, which occurred in 2008, until the FBI alerted them that year and in early 2009. Federal officials told the companies proprietary information had been flowing out, including to computers overseas, a source familiar with the attacks says and documents show.

The data included e-mail passwords, messages, and other information tied to executives with access to proprietary exploration and discovery information, the source says.

The attackers appear to have gained access to their targets by patiently researching which key personnel to target with phishing attacks designed to downloaded malware into the victim's networks.

The oil and gas industry breaches, the mere existence of which has been a closely guarded secret of oil companies and federal authorities, were focused on one of the crown jewels of the industry: valuable “bid data” detailing the quantity, value, and location of oil discoveries worldwide, sources familiar with the attacks say and documents obtained by the Monitor show.

The companies – Marathon Oil, ExxonMobil, and ConocoPhillips – didn’t realize the full extent of the attacks, which occurred in 2008, until the FBI alerted them that year and in early 2009. Federal officials told the companies proprietary information had been flowing out, including to computers overseas, a source familiar with the attacks says and documents show.

The data included e-mail passwords, messages, and other information tied to executives with access to proprietary exploration and discovery information, the source says.

But, according to the source and documents obtained by the Monitor, her response was too late. The fake had already been forwarded to other people – and someone had clicked on the link it contained. Instantly, an unseen spy program started spreading stealthily across Marathon’s global computer network.

Nearly identical fake e-mails that appeared to come from senior executives were also sent to colleagues in key posts at ExxonMobil and ConocoPhillips – all containing a request for them to analyze the Economic Stabilization Act noted on the subject line, a source familiar with the attacks says.

The entire article is worth the read. It highlights the systemic nature of the cyber threat to US economic and national security.

Tuesday, January 26, 2010

Social Engineering via Social Networks

The Financial Times reports that the hackers responsible for attacking Google used social networking sites to infiltrate the search engine's network. According to the Financial Times,
The most significant discovery is that the attackers had selected employees at the companies with access to proprietary data, then learnt who their friends were. The hackers compromised the social network accounts of those friends, hoping to enhance the probability that their final targets would click on the links they sent.“We’re seeing a lot more up-front reconnaissance, understanding who the players are at the company and how to reach them,” said George Kurtz, chief technology officer at security firm McAfee.“Someone went to the trouble to backtrack: ‘Let me look at their friends, who I can target as a secondary person’.”
This article highlights how our personal information can be exploited in unexpected ways and provides a real-world example to many of concepts we discussed in class.

Monday, January 18, 2010

More Targeted Attacks

The same tools, techniques, and procedures used to attack Google and other private sector companies are also used to actively attack the US military in cyberspace. F-Secure highlights this recent attack against US military contractors.




Saturday, January 16, 2010

Google's Counter Attack

Two interesting articles, one in the New York Times and one in the San Jose Mercury News, discuss how Google officials investigated the cyber attacks against Google's infrastructure and users of the company's services.

According to the New York Times Google
managed to gain access to a computer in Taiwan that it suspected of being the source of the attacks. Peering inside that machine, company engineers actually saw evidence of the aftermath of the attacks, not only at Google, but also at at least 33 other companies, including Adobe Systems, Northrop Grumman and Juniper Networks, according to a government consultant who has spoken with the investigators. Seeing the breadth of the problem, they alerted American intelligence and law enforcement officials and worked with them to assemble powerful evidence that the masterminds of the attacks were not in Taiwan, but on the Chinese mainland.
The San Jose Mercury News writes
When Tenzin Seldon, a 20-year-old sophomore at Stanford, logged onto her Gmail account from New York over winter break, she may have helped Google understand the widespread penetration of its network by unidentified hackers in China.Unknown to Seldon, a regional coordinator of Students for a Free Tibet, at the same moment she was reading her e-mail in Queens, someone in China was logged into her account as well. Top Google officials, including chief legal officer David Drummond, later told Seldon that the suspicious situation alerted them that she was one of the human rights activists whose electronic mail was routinely being spied upon by someone in China.
The San Jose Mercury News article continues,
According to Google officials, her black Hewlett-Packard laptop with the red Stanford "S" sticker on the outside was one of perhaps two machines Google examined for signs of malicious software, or "malware," that would have allowed cyberspies entry to her Gmail account. Despite spending six days going through her laptop in early January, Google was unable to find any signs of malware on it. An industry source familiar with the case said her laptop may have been infected with a sophisticated form of malware programmed to harvest and relay back Gmail passwords, before erasing itself from her hard drive.
These accounts raise two interesting questions. First, should private companies like Google be empowered to respond to cyber attacks with attacks of their own? In many cases, the attacking system may belong to a private citizen or company that has no idea their system has been compromised and is participating in an attack. Further, a counter strike, even one that is designed only to gather information and not destroy the attacking machine, may cause unintentional damage and have unintended consequences.

For example, there have been previous cases of computers in hospitals hosting malicious bots. Breaking into these computers, without consultation with the system owner, may break the machine. In the case of the infected hospital computer this may adversely affect the doctors and patients that rely on the computer. Remember just because a computer is infected doesnt mean that it cant perform its other programmed functions.

Second, even though Google broke into a server participating in the attack against it, Google officials could not say with certainty who was responsible for the attack. The New York Times noted,
But while much of the evidence, including the sophistication of the attacks, strongly suggested an operation run by Chinese government agencies, or at least approved by them, company engineers could not definitively prove their case. In interviews in which they disclosed new details of their efforts to solve the mystery, Google engineers said they doubted that a nongovernmental actor could pull off something this broad and well organized, but they conceded that even their counterintelligence operation, taking over the Taiwan server, could not provide the kind of airtight evidence needed to prove the case.

Thursday, January 14, 2010

Timeline of Chiese Cyber Espionage

This image is from a Northrop Grumman report published by United States-China Economic and Security Review Commission that we will read later in the semester. It provides great context for Google's recent announcement about cyber attacks on its network.


More Details on China's Cyber Espionage Campaign

The Washington Post provides some additional insight into the recent the attack series traced to China. According to the article the attacks,
originated in China were part of a concerted political and corporate espionage effort that exploited security flaws in e-mail attachments to sneak into the networks of major financial, defense and technology companies and research institutions in the United States, security experts said. At least 34 companies -- including Yahoo, Symantec, Adobe, Northrop Grumman and Dow Chemical were attacked, according to congressional and industry sources.
Further, the article points out that
the recent attacks seem to have targeted companies in strategic industries in which China is lagging, industry experts said. The attacks on defense companies were aimed at gaining information on weapons systems, experts said, while those on tech firms sought valuable source code that powers software applications -- the firms' bread and butter. The attacks also focused on obtaining information about political dissidents.
James Lewis, from the Center for Strategic and International Studies, provides insight into the Chinese government's motivations in sponsoring or allowing this espionage program to continue. Lewis states,
This is a big espionage program aimed at getting high-tech information and politically sensitive information -- the high-tech information to jump-start China's economy and the political information to ensure the survival of the regime.
The article also provides insight into the modus operandi used by the attackers.
The attackers, experts said, followed the familiar "phishing" ruse: A recipient opens an e-mail that purports to be from someone he knows and, not suspecting malicious intent, opens an attachment containing a "sleeper" program that embeds in his computer. That program can be controlled remotely, allowing the attacker to access e-mail, send confidential documents to a specific address -- even turn on a Web camera or microphone to record what is going on in the room.
Its interesting to note the responses provided by the other companies identified as targets of the espionage attacks in the Article.
Adobe, a software maker, confirmed on Wednesday that it learned of the attacks on Jan. 2 but said there was "no evidence to indicate that any sensitive information . . . has been compromised," while Symantec, which makes security software, said it is investigating to "ensure we are providing appropriate protection to our customers."Dow Chemical said that it has "no reason to believe that the safety, security and intellectual property of our operations are in jeopardy." Yahoo and defense contractor Northrop Grumman declined to comment on the attack.
These denials are standard fare for corporate America and provide a stark contrast to Google's admission. Google's candidness is an exciting development for the cyber security industry which is in dire need of a shake up and finding new approaches to dealing with a decades old problem.

Tuesday, January 12, 2010

Google's New Approach to China

I am truly amazed and impressed with Google today. Their candid account of Chinese cyber espionage activities on their network is significant simply because they are the rare company willing to disclose this type of activity. Additionally, Google's willingness to reassess their business operations in China shows that they are willing to move beyond mere rhetorical protestrations. Google appears to be the first Internet company willing to stand up to China and protect Internet free speech. Great job Google!

UPDATE (1/13/10): It could just be a coincidence that on the same day that Google announced targeted attacks on its infrastructure at GMail users they also announced that GMail will use HTTPS by default. No matter the reason this also good news for GMail users. Free security for everyone! Yeah!

Wednesday, November 11, 2009

China proves to be an aggressive foe in cyberspace

The Washington Post checks in with a re-hash of China's cyber espionage and cyber warfare capabilities. Theres not much new information here but for those new to the field its worth the read.

From the article ...

China is significantly boosting its capabilities in cyberspace as a way to gather intelligence and, in the event of war, hit the U.S. government in a weak spot, U.S. officials and experts say. Outgunned and outspent in terms of traditional military hardware, China apparently hopes that by concentrating on holes in the U.S. security architecture -- its communications and spy satellites and its vast computer networks -- it will collect intelligence that could help it counter the imbalance.

Thursday, October 22, 2009

Cyberespionage Overview

An article in today's Wall Street Journal outlines evidence of a cyberespionage attack against a US technology company. According to the article,
The Chinese government is ratcheting up its cyberspying operations against the U.S., a congressional advisory panel found, citing an example of a carefully orchestrated campaign against one U.S. company that appears to have been sponsored by Beijing.The unnamed company was just one of several successfully penetrated by a campaign of cyberespionage, according to the U.S.-China Economic and Security Review Commission report to be released Thursday. Chinese espionage operations are "straining the U.S. capacity to respond," the report concludes.
The report also details the techniques, tactics, and procedures of the cyberspies.
In the months leading up to the 2007 operation, cyberspies did extensive reconnaissance, identifying which employee computer accounts they wanted to hijack and which files they wanted to steal. They obtained credentials for dozens of employee accounts, which they accessed nearly 150 times.The cyberspies then reached into the company's networks using the same type of program help-desk administrators use to remotely access computers.The hackers copied and transferred files to seven servers hosting the company's email system, which were capable of processing large amounts of data quickly. Once they moved the data to the email servers, the intruders renamed the stolen files to blend in with the other files on the system and compressed and encrypted the files for export.Before exporting the data, the collection team used employee accounts to take over four desktop computers to direct the final stage of the operation.They selected at least eight U.S. computers outside the company, including two at unidentified universities, as a drop point for the stolen data before sending it overseas. The high Internet traffic volume on university networks provides excellent cover.



We will discuss the specifics of these kind of targeted cyberespionage attacks in class in the coming weeks.