Showing posts with label Terrorism. Show all posts
Showing posts with label Terrorism. Show all posts

Wednesday, March 31, 2010

Chechen rebel leader claims responsibility for attacks

As we discussed in class terrorist groups often use the Internet to distribute propaganda. A favorite type of propaganda of various groups is the video claiming responsibility for an attack.

As you all know Russia has fallen victim to a series of suicide bombings this week and according to the Washington Post "Doku Umarov, leader of a separatist insurgency in the North Caucasus, which seeks to establish a fundamentalist Caucasus Emirate in the region, claimed reponsibility for the Moscow attacks in a video posted on the kavkazcenter.com Web site. He said they were retaliation for a Russian attack on civilians in a village last month. He said the retribution would continue."

For those interested, the specific page on kavkazcenter.com can be found here. Additionally, the video of Doku Umarov can be found here on YouTube.



Sunday, March 28, 2010

There are Bad Neighborhoods Online Too

From the good netizens at the Zeus Tracker ...
I always check the ZeuS Tracker statistics to get some information about the trend of the active ZeuS Command&Control servers. This morning I was really surprised what I saw on the ZeuS Tracker statistic page:
As you can see in the chart above, on March 9th 2010, the number of active ZeuS C&C servers dropped from 249 to 181! The first thing I thought was: There has to be some problem with the ZeuS Tracker cron script. I checked the script – everything looked ok. So the massive drop of ZeuS C&C server is fact. I noticed that six of the worst ZeuS hosting ISP suddently dissapeared from the ZeuS Tracker.

I verified the subnets of the affected ISP and came to the conclusion that Troyak-as (AS50215), the upstream provider for the six worst ZeuS hosting ISPs, was cut from the internet on 2010-03-09. As a result, the following ISPs lost their internet connetivity which finally resulted in a massiv drop in the number of active ZeuS C&C servers.
In the physical world were attuned to sense danger. We all can instinctively recognize a bad neighborhood. When we see dilapidated buildings, broken street lights, liquor stores on every block, prostitutes working street corners, and a lack of police presence we all understand that we are not in a safe neighborhood.

However, we have not yet developed the same sensory perception for our digital lives online. The Internet is made up a series of neighborhood known as autonomous system (AS). Internet Service Providers "rent" space from these autonomous systems and provide hosting services for customers. Some criminal or indifferent hosting providers will work with likeminded autonomous systems to serve criminals and terrorists. These bad service providers foster bad neighborhoods online that allow for a good deal of the malicious activity that we see online today.

Internet making it easier to become a terrorist

From the LA Times ...
The abrupt transformation of Colleen R. LaRose from bored middle-aged matron to "JihadJane," her Internet alias, was unique in many ways, but a common thread ties the alleged Islamic militant to other recent cases of homegrown terrorism: the Internet.

From charismatic clerics who spout hate online, to thousands of extremist websites, chat rooms and social networking pages that raise money and spread radical propaganda, the Internet has become a crucial front in the ever-shifting war on terrorism.

"LaRose showed that you can become a terrorist in the comfort of your own bedroom," said Bruce Hoffman, professor of security studies at Georgetown University. "You couldn't do that 10 years ago."

"The new militancy is driven by the Web," agreed Fawaz A. Gerges, a terrorism expert at the London School of Economics. "The terror training camps in Afghanistan and Pakistan are being replaced by virtual camps on the Web."

From their side, law enforcement and intelligence agencies are scrambling to monitor the Internet and penetrate radical websites to track suspects, set up sting operations or unravel plots before they are carried out.

As we discussed last week in class terrorist groups across the world have embraced the Internet as a vital tool in their information warfare arsenal. Time permitting we will put our investigative hats on and explore the web in search of many of these digital hate safe havens in an effort to track those responsible for maintaining these sites.

Saturday, March 27, 2010

Dismantling of Saudi-CIA Web site illustrates need for clearer cyberwar policies

From the Washington Post,
By early 2008, top U.S. military officials had become convinced that extremists planning attacks on American forces in Iraq were making use of a Web site set up by the Saudi government and the CIA to uncover terrorist plots in the kingdom.

"We knew we were going to be forced to shut this thing down," recalled one former civilian official, describing tense internal discussions in which military commanders argued that the site was putting Americans at risk. "CIA resented that," the former official said.

Elite U.S. military computer specialists, over the objections of the CIA, mounted a cyberattack that dismantled the online forum. Although some Saudi officials had been informed in advance about the Pentagon's plan, several key princes were "absolutely furious" at the loss of an intelligence-gathering tool, according to another former U.S. official.
This case study highlights one of the dilemmas we discussed in last weeks class. Should we leave potentially dangerous websites online in order to exploit them for actionable intelligence, or should we shut them down and deny terrorists an online safe haven?

Read the whole article here ...

Sunday, September 27, 2009

FBI Targets Online Extremists

The recent spate of arrests of terror suspects is based in part on excellent investigative work done by the Federal Bureau of Investigation. According to media reports, the FBI is doing an excellent job of monitoring online extremists message boards and chat rooms for signs of pending terrorist attacks.

The arrest of Hosam Maher Husein Smadi, a 19-year-old Jordanian citizen who planned on bombing the 60-story Fountain Place building in Dallas, Texas. According to reports,
Smadi stood out to federal authorities in an online group for extremists because of his repeated remarks that he wanted to commit a violent jihad, or a holy war, against the United States.
Federal officials began speaking with Smadi in March after finding him on an online group for extremist.

Posing as al-Qaida members and speaking Arabic, undercover agents began to probe Smadi for more details of his plans. Slowly, he began to provide them details and ideas to carry out his plan.
We will discuss this case and others later in the semester as we analyze how terrorist groups or using the Internet to communicate and coordinate their activities to like minded extremists. We will also discuss how to conduct online investigations of terrorist suspects.

Wednesday, September 16, 2009

Digital Safe Havens

Georgetown Professor Paul Pillar writes in today's Washington Post

How important to terrorist groups is any physical haven? More to the point: How much does a haven affect the danger of terrorist attacks against U.S. interests, especially the U.S. homeland? The answer to the second question is: not nearly as much as unstated assumptions underlying the current debate seem to suppose. When a group has a haven, it will use it for such purposes as basic training of recruits. But the operations most important to future terrorist attacks do not need such a home, and few recruits are required for even very deadly terrorism. Consider: The preparations most important to the Sept. 11, 2001, attacks took place not in training camps in Afghanistan but, rather, in apartments in Germany, hotel rooms in Spain and flight schools in the United States.



In the past couple of decades, international terrorist groups have thrived by exploiting globalization and information technology, which has lessened their dependence on physical havens.



The central question asked by Professor Pillar is whether the Obama administration's assumption that abandoning Afghanistan will create a needed safe haven for al-Qaeda is correct? Many policy makers believe that should we pull out of Afghanistan the Karzai government will fall and the Taliban will take over or the country will disintegrate into a failed state. According to this argument, either condition will provide al-Qaeda with a safe have to re-group and plan additional attacks against US interest at home and abroad.

Professor Pillar questions this assumption by pointing out that al-Qaeda and other al-Qaeda inspired groups have used the Internet to communicate, coordinate, recruit, and train and therefore do not rely on a physical safe haven for success.

What are your thoughts? Can a terrorist cell rely solely on the Internet to plan, coordinate and successfully execute an attack? We will discuss this question in more detail later in the semester.


Thursday, April 9, 2009

Extremist Web Sites Are Using U.S. Hosts

Today's Washington Post reports on the Taliban's use of U.S. Internet Service Providers (ISP). The article states,

On March 25, a Taliban Web site claiming to be the voice of the "Islamic Emirate of Afghanistan" boasted of a deadly new attack on coalition forces in that country. Four soldiers were killed in an ambush, the site claimed, and the "mujahideen took the weapons and ammunition as booty."

Most remarkable about the message was how it was delivered. The words were the Taliban's, but they were flashed around the globe by an American-owned firm located in a leafy corner of downtown Houston.

For those writing their final paper on how terrorist groups use the Internet, I recommend that you read it in full. Despite the articles implication that the use of U.S. ISPs is a "new" trend, it is important to understand that terrorist groups, specifically al-Qaeda, have long made use of U.S. ISPs to deliver their message. Ive seen groups use U.S. ISPs for the last five years. Ive also seen terrorist ulilize other American online services such as YouTube!, the US Government funded Internet Archive, and WordPress to name a few.

Thursday, March 19, 2009

Grey Goose Phase II Report

While you were slaving away on your mid-terms and then lounging around on Spring Break I was busy working away with my colleagues on Project Grey Goose. We just released the public version of our Phase II report. The report covers the ongoing Israeli-Palestinian cyber war and Russia's cyber war capabilities. You can view the report here - http://greylogic.us/?page_id=85. Our guest speaker for this Monday's class, Rebecca Givner-Forbes, also participated in this report.

Friday, February 20, 2009

Weekly Roundup

Tuesday, January 13, 2009

The YouTube Battlespace

On January 12, 2009, I noted an entry on the Google Public Policy blog today entitled 'Congress Comes to YouTube'. According to the blog,

As the 111th Congress kicks into gear, many Members of Congress are starting their own YouTube channels. They're posting videos direct from their Washington offices, as well as clips of floor speeches and committee hearings alongside additional behind-the-scenes footage from Capitol Hill. And in conjunction with both the House and Senate, today we're launching two new platforms that will help you access your Senator and Representatives' YouTube channels: The Senate Hub (youtube.com/senatehub) and The House Hub (youtube.com/househub).
The Google Public Policy blog concludes that Congress's YouTube presence has "the potential to make Congress more transparent and accessible than ever before."

I personally think this is a good move for Congress because it has the potential to engage and create a more politically active electorate. Frankly, Im somewhat surprised that it has take Congress this long to use online services like YouTube.

In a somewhat ironic twist, CBS News released a story on the same day reporting on a new YouTube channel launched by Hamas's military wing the Al Qassam Brigades. CBS News reports, "Seven videos have been added to the channel since its launch on December 31st, two days after the Israeli military set up a Youtube channel to show videos of IAF strikes on Gaza."

I discovered a YouTube channel maintained by the Al Qassam Brigades which appears to have been established on November 2, 2008 and currently hosts 29 videos here. Im not sure which channel CBS News is referring to, but its clear that Hamas and other Jihadists groups have leveraged the propaganda value of YouTube and other social media sites for a long time. In fact, in May 2008 Senator Joe Lieberman pressured Google to remove Jihadist propaganda hosted on YouTube.

We will discuss how terrorist use the Internet later in the semester, but I thought it would be good to get some exposure to this issue as early as possible. Questions that we will discuss include whether or not we should censor sites like YouTube, or if we should allows terrorist to continue to use these sites and turn their use of these sites against them by gathering as much intelligence as possible about the producers and consumers of terrorist propaganda.

Thursday, December 4, 2008

Terrorist on YouTube

According to a recent article published by Reuters, "Islamic extremists are being instructed on how to use the popular video-sharing site YouTube as a way to disseminate propaganda videos." Specifically, online jihadist are being encouraged to participate in a "YouTube Invasion" and have been provided "several screenshots showing step by step instructions on how to create a YouTube account and to upload material."

Im not really sure why this story is "news" as we have known for quite some time that jihadist and other terrorist groups upload propaganda videos to YouTube and other video sharing websites.

It's possible that this latest effort to create a "YouTube Invasion" is a direct response to the increasing inability of Internet jihadists to keep their primary online forums operational.

The Mumbai Attacks

Many commentators have stated that the recent terrorist attacks in Mumbai were a "low-tech" affair. On the surface this description seems apt as the gunmen relied on automatic weapons and grenades to carry out their assualt. However, an article in the Washington Post describes how the attackers made clever use of technology to aid in the execution of their attack. Specifically the article writes,
The heavily armed attackers who set out for Mumbai by sea last week navigated with Global Positioning System equipment, according to Indian investigators and police. They carried BlackBerrys, CDs holding high-resolution satellite images like those used for Google Earth maps, and multiple cellphones with switchable SIM cards that would be hard to track. They spoke by satellite telephone.
An obvious reaction this information is to condemn technology for enabling terrorist to increase their deadly efficiently. Many politicians have called for restrictions on technology in an effort to impede terrorists from gaining a tactical advantage. For example, Indian government officials previously worked out a deal with Google to degrade satellite imagery of select sensitive locations in India.


I have no problem with targeted and specific efforts to restrain technology out of fear that it can be abused by terrorist and other malicious actors. However, I worry that politicians may only focus on the malevolent uses of technology causing them to overreach in an effort to regulate against potential and in many cases unrealistic abuses of technology.

It is important to remember that technology is neither inherently good or evil. It is what people make out of it and it can be used to achieve the goals of its users - both good and bad. Interestingly, the Mumbai attacks demonstrated both the positive and the negatives uses of technology. While the terrorists used technology to aid in their attack, the citizens of Mumbai also used to technology to disseminate information about the attack in real-time. These unfilitered first hand accounts of the attacks, posted to sites like Twitter and Flickr, may have served to reduce panic as people were able to connect with friends and family in a timely fashion.

As a result, lets remember not to blame technology and blindly seek to regulate it.