The Macrosite for News, Analysis and Opinion about the Future of the Internet
Mary E. Shacklett

Cyber-Terror: How Vulnerable Are We?

2/21/2008 9 comments
DISCUSS   Digg   Del.icio.us   Reddit   Email This   TWEET THIS

Cyber-threats are economically motivated and cyber-terror is politically driven. These attacks occur under a guise of virtual anonymity and are often not attributable to any one organization or individual. What risks do they present? And how vulnerable are we?

For terrorists, the psychological value of a sustained attack is that people lose confidence in their infrastructure. A disruption in the financial infrastructure creates insecurity in banks and in the stock market. A sustained disruption of a power system can create unrest in cities, disruption of telecommunications, and even food shortages. “A worst-case scenario would be a sustained failure of critical infrastructure like a power grid or a financial structure,” says Matthew DeVost, founding director of the Terrorism Research Center and president of Total Intelligence Solutions.

When it comes to cyberterror, most of us envision armies of invading botnets that compromise networks for nefarious purposes. But a cyber attack could well be physical. “Cable cutting is a key component of any cyber war,” says Paul Sop, CTO of Prolexic, which specializes in denial-of-service (DOS) attack mitigation services. “The U.S. has retrofitted submarines that can go down and snip undersea fiber cable, and other countries have this, too.” Sop says the commercial Internet has nothing built into it to work around major disruptions of hardware infrastructure.

DeVost points out that in 2000, the CIA told a congressional committee that more than 100 countries were developing cyberwarfare capability, but those at the forefront are the U.S., China, Russia, and Israel. “Russia and China both have hacking groups that specialize in bots, phishing, and spam, while Israel has concentrated in security,” says Sop. “Meanwhile, the U.S. has some of the top professionals in knowledge and hacking ability.”

In some ways, the “war” is already underway -- but it hasn’t been getting much attention. “I’ve supported probably 30 to 40 forensic investigations of cyber attacks, but only two were reported,” says DeVost. "Companies don’t like to engage law enforcement because of the unfavorable publicity that results.”

Mitigating cyber risks is a global and national security issue; however, companies can be proactive with security by adopting risk management programs.

“Companies should consider changing their architecture so their networks do not have single points of failure, because it’s very hard for cyber attackers to be effective when there is not a single point of attack,” says Sop. “Enterprises and service providers should have multiple data centers. If you have multiple servers deployed, do not link them all to a single database.”

Future cyber attacks will be more difficult to detect. They will hide behind the “noise” of the Internet, and you may never know your equipment is infected. “Companies should make sure they have the ability to do forensic analysis, and get law enforcement involved,” says DeVost. “The argument for law enforcement is: If no one is prosecuting the perpetrator of cyber threats, there is no criminal deterrent. These criminals need the fear of getting caught.”

Enterprises should also put their computing resources through the paces of real cyber-attacks, not just simulations. If you don’t subject your systems to the real thing, you have no way of knowing if your security measures are working. Due diligence is important in safeguarding our information. So are awareness and education.

— Mary E. Shacklett, President of Transworld Data

DISCUSS   Digg   Del.icio.us   Reddit   Email This
Current display:       newest comments first       display in chronological order
igorpecovnik
Rank: Cave Painter
Tuesday February 26, 2008 3:09:46 PM
no ratings
>These are the computers that are part of the ".mil" domain.

I know and I agree, but line between military and nonmilitary is hard to define. Internet revolution, let's say Net 2.0 is bringing more freedom and faster information exchange. With more speed there will be more problems to secure critical data. Business information value is depend from time.

>Attacking servers, deploying malicious virus attacks and stealing computer information are all criminal acts.  And when a nation such as China uses these attacks during peacetime against both military and civilian economic targets, it crosses the line of acceptable behavior.  This is state sponsored crime.

In this case I disagree. Spying (stealing information) is in human nature, everybody is spying to get better job, business, ... Attacking servers cannot be attached just to one nation. I am convinced that this is just propaganda against "bad" communistic regime and big economical power of China. Reality can and it is different.

Peacetime does not exists! We live in one world, we have war in Afganistan, Irak, some Africa states, we had 9/11 and that is state sponsored crime too ;)

Regards,
Igor


Mary E. Shacklett
Thinkernetter
Monday February 25, 2008 10:32:46 AM
no ratings

You're entirely right, Paul.

 

There will always be something new on the horizon, and we need to take it in stride.

 

Mary

awase149
Rank: Web master
Monday February 25, 2008 5:15:45 AM
no ratings

Hi Igor,

In answer to your question, "Military computer" networks refer to the US military intranet known as the unclassified IP router network (NIPRNET).  These are the computers that are part of the ".mil" domain.

Attacking servers, deploying malicious virus attacks and stealing computer information are all criminal acts.  And when a nation such as China uses these attacks during peacetime against both military and civilian economic targets, it crosses the line of acceptable behavior.  This is state sponsored crime.

~ Mike Bennett ~

 

Paul Whyte
Researcher
Sunday February 24, 2008 7:19:29 PM
no ratings

Hi Mary,

I've no intention to underestimate the gravity of cyberterror but i still believe we are carving to the culture of fear the terrorist want us to live in. I still hold the view that cybercrime should be more of a concern than cyberterror. The terrorist will always use their traditional way of killing and inflicting pain on innocent lives.

Experts: Cyber-crime bigger threat than cyber-terror

Whilst it's not wrong to prepare for such attacks in the future, we should be careful not to overblown this issue and put in on par with nuclear/chemical warfare.

 

Cyber terrorism 'overhyped'

 

 

Cyber-Terrorism: Propaganda or Probability?

igorpecovnik
Rank: Cave Painter
Sunday February 24, 2008 1:34:10 PM
no ratings

Regarding to this:

“America is under widespread attack in cyberspace”, testified General James Cartwright of the US Strategic Command to Congress in March 2007. There were more than 80,000 attempted attacks on military computer networks in 2007.

What is military computer?

Information war is nothing unusual ... trying to get as mouch information as possible is business politics driven, like it was pointed in the article. In politics there is no limit and attacking servers is just one small signal about what is going on.

On the other hand, behind computer, servers and in the network, there are people, operators, who have control over information by the nature and that is biggest risk and if you need to acchive almost secure informations, you have to isolate people on every hub of your information strucuture, which is expandalbe by nature.

Is it possible? No.

Regards,
Igor

awase149
Rank: Web master
Saturday February 23, 2008 2:48:27 AM

I believe that organized cyber warfare, funded and supported by nations pose a bigger threat to the Internet.  China is very active in the area of cyber warfare. A recent report by the Heritage Foundation entitled, “Trojan Dragons: China’s International Cyber Warriors” (http://www.heritage.org/Research/AsiaandthePacific/upload/wm_1735.pdf) describes the emphasis that China is placing on cyber warfare.  The Chinese People’s Liberation Army (PLA) has cyber warfare brigades that are already at work probing, hacking and stealing data from US and European computer systems.  The Chinese cyber attacks haven’t been limited to government systems.  In fact, their primary target is economic and industrial information systems.  China’s intelligence collection is the top intelligence threat to America’s science and technology secrets.

 

“America is under widespread attack in cyberspace”, testified General James Cartwright of the US Strategic Command to Congress in March 2007.  There were more than 80,000 attempted attacks on military computer networks in 2007.  These attacks were often successful in impacting US military operations.  Of concern to the government isn’t the high school hacker having fun, but the concerted Internet attacks that are coming out of China.  In the last three months, attacks against the US government from China have tripled.  The Chinese cyber warfare units have already penetrated the US military’s unclassified but sensitive IP router network (NIPRNET) and have designed software to disable it in time of conflict.

 

The Chinese have developed a very sophisticated and advanced capability to attack and degrade US and European computer networks and it is time that western nations recognize the threat.  This threat is not only to the military, but to commercial, financial and energy networks.  The actions of the Chinese cyber warriors in penetrating and stealing data from foreign nations have crossed the boundary of acceptable international behavior during peace time.

 

~ Mike Bennett ~

 

 

drihsan
Researcher
Saturday February 23, 2008 12:53:47 AM
no ratings
In my opinion the cyber terror threat may involve two aspects; the vulnerability and the risk of a diffuse attack against resources classified critical. These include financial system, internet backbone and power system resources etc. The good news is that according to a recent analysis by the IBMs Internet Security Systems X-Force, vulnerabilities actually decreased by 3.3% in the second half of 2007 as compared to last year. However according to a  Business Rountable's assessment in 2006 experts do not agree about the actual risk of a diffuse cyber attack.
Viewed from this perspective, some would argue that potential cyber attack risk against critical infrastructure is actually lower than the other known risks like breach of privacy, crime against minors, throttling of internet traffic and anti-trust violations. 
Mr. Roques
Researcher
Friday February 22, 2008 4:25:30 PM
no ratings

Each second that passes we are creating a bigger dependancy towards the internet, and networks in general. It's not a bad thing, but it does come with some issues. Cyber-terror being one of the worst.

Everything in history has came with a price, it's the job of the decision makers to decide if the risk is acceptable, compared to the benefits it draws.

lpricci49
IQ Crew
Thursday February 21, 2008 9:08:37 PM
no ratings
You ask if our systems are vulnerable?  You bet we are! And the most critical systems- those that manage our water, power and fuel are perhaps the most easily penetrated and the hardest to reclaim. If somebody gets your credit card info, get a new one.  If a keystroke logger has been installed on your PC, go off line and scrub it out.  But what if a hack has penetrated your thermostat?  Your water meter?  Or the systems that distribute your gas, electric or water.  And what about the critical  systems to maintain societal trust- voting machines.  Plenty said  about those. 

Lawrence Ricci

www.EmbeddedInsider.com

The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Mary E. Shacklett
Mary E. Shacklett
SIP (Session Initiation Protocol) is an increasingly important Internet integration technology, but there are still areas where critical interoperability work remains to be done -- including on IP PBXs, on SIP-enabled service provider connections, and on fax-over-IP (FoIP) solutions.
Mary E. Shacklett
It started as a living room conversation in 1998 and grew into a worldwide movement of software developers believing in the principle of creating and circulating software for free. It was a turn-of-the-century counter-movement to the established world of proprietary software that had characterized the 20th century, and which major companies had used to maintain market dominance.
Mary E. Shacklett
By its very nature, interoperability engages the efforts of many, and this past May’s SIPit 26 testing event for the Session Initiation Protocol (SIP) was no exception. Sixty-seven attendees from 28 companies from 15 different countries attended the five-day event in Kista, Sweden, which tested interoperability among SIP applications, IP (Internet protocol) communications equipment, consumer and enterprise fixed and mobile technology networks, and both edge and end devices.
Mary E. Shacklett
There was a time when the use of radio telescopes to scour space for signs of life was reserved for scientists and university students, but extraterrestrial life-seeker SetiQuest is expanding its search corps to "citizen scientists" by using Internet-inspired technologies and social innovations like global communities, open-source, and collaboration.
Mary E. Shacklett
IT continues to cope with internal security issues.
5
of
IETV: the thinkerNet on film
5
of
2pm EDT
Thu
Sep 2nd
2pm EDT
Thu
Sep 30th
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   7/29/2010   Post a comment
IBM announced today it has entered into a definitive agreement to acquire Storwize, a privately held company based in Marlborough, Mass.
white papers & case studies
an IBM information resource
sponsored content
Getting to Work on Smart Work: How IT Is Transforming the Implementation of the 'Internet of Things'
Organizations in all industry sectors are becoming more instrumented, interconnected, and intelligent -- and that's changing the way they approach virtually every facet of their operations. It's up to IT to help organizations adopt a "Three I's" approach that leverages the emerging Internet of Things and enables them to work smarter.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Not Dr. Phil
Comparison Shopping for Broadband – Or Not

12|4|09   |   02:36   |   26 comments


Comparing Internet services is tough because service providers price and market their services based on a best-case scenario connection that most consumers will never enjoy.
Not Dr. Phil
Content Could Complicate Internet Caps

3|3|10   |   2:15   |   6 comments


Comcast and other broadband providers just might exempt content they own from counting against consumer Internet usage caps. Would that make their broadband services more desirable?
Second Shooter
Collaboration & Spherical Stupidity

2|24|10   |   2:12   |   18 comments


A recent scandal involving a school's use of remotely activated Webcams to locate lost or stolen laptops may portend, not only legal action against the school, but also a loss of trust in video that is critical to developing video collaboration over the Internet.
Eurotrash
High & Dry in Barcelona

2|3|10   |   1:08   |   1 comment


Ray’s heading to Barcelona for the Mobile World Congress, and he’s not happy about it, the miserable git.
Second Shooter
80/20, 40/3, Shovel/Snow

12|14|09   |   2:09   |   No comments


The iPhone has created a new form of the 80/20 rule, according to AT&T, which claims only 3% of iPhone users generate 40% of wireless traffic. But is that really a justification for usage caps and pricing tiers? What did AT&T think was going to happen with the iPhone pricing plan, and are they shoveling something else at us now that we're hooked?
TeleGraham
China's Broadband Revolution

10|13|09   |   2:36   |   1 comment


China is investing heavily in fiber to the premises to propel itself into the world broadband Internet first division. What's it deploying, and what's it going to do with all that bandwidth?
Second Shooter
All Spectrum Is Not Created Equal

7|2|10   |   1:59   |   No comments


Doubling wireless broadband spectrum does no good if you run the wrong applications over it. Listen up, Mr. President!
TeleGraham
Lies, Damned Lies & Broadband Speeds

6|24|10   |   3:08   |   2 comments


Sites like Speedtest.net, which use data from users to construct a new picture of what the Net looks like, are making it harder and harder for service provider spin merchants to mislead the public about how much broadband capacity they are really getting.
Second Shooter
Seduced & Abandoned in Broadband Pricing

6|23|10   |   2:08   |   6 comments


Telecom operators say they are adding new high-speed broadband wireless technology to their networks to improve services for users, but they are also introducing tiered pricing which punishes us for taking advantage of the new speed. No fair, says Tom Nolle.
Reiter's Block
Don't Count on Cheap 4G Data

6|1|10   |   2:37   |   14 comments


Reiter explores 4G data pricing and doesn’t like what he sees.
Sweeney Blog
Tweets Show West Is Best

7|30|10   |   2:47   |   No comments


Hey, Eastern Timezoners: Lighten up! Or at least Tweet happier thoughts.
Reiter's Block
Inside RIM’s Tablet Survey

7|29|10   |   2:50   |   2 comments


Research in Motion recently emailed a survey about smartphone use and tablet computer preferences. Could it be a prelude to a RIM tablet? Of course!
Second Shooter
Let’s Make Up Our Minds on Copyright

7|29|10   |   2:07   |   2 comments


There's a public-policy war on copyright that nobody is winning, and inconsistencies in viewpoint and interpretation seem to be multiplying. We need to step back and think our policies over again, or we risk having a strategy that fails everyone.
The Sole Man
Cloud-Based Video Sharing: Not Promising

7|28|10   |   2:49   |   1 comment


Ultraviolet is an industry-wide attempt to standardize video content delivery across multiple platforms. Apart from the fact that it’s based in the cloud, relies on the DRM system, and isn’t backed by Apple… it sounds great!
Wisdom of the Big Chair
Using the Web to Clean the Gulf

7|28|10   |   2:12   |   3 comments


The Internet played a key role in disseminating information and helping with the Gulf cleanup. Bravo, Internet!
Second Shooter
The Third Way or the Highway

7|27|10   |   2:09   |   4 comments


The FCC's Sixth Broadband Report has a hidden secret. But here’s a hint: The regulatory body plans to regulate broadband as a telecommunications service.
Singer at C-Level
I Predict You Will Watch This Video

7|27|10   |   1:59   |   No comments


Wouldn’t it be great to be able to predict what your customers want before they know they want it? Check our our latest tutorial about Predictive Analytics to find out how: www.internetevolution.com/tutorial-predictive-analytics.asp
The Sole Man
Shiver Me Timbers

7|26|10   |   2:21   |   No comments


Digital pirates find easy pickings in the open waters of the Internet. Aaarrrrrr!
Cirque Du Solez
Spontaneity Gives New Meaning to 'On the Road'

7|26|10   |   1:46   |   6 comments


Once defined by epic journeys, planning, and maps, the phrase "on the road" takes on new meaning in a digital age, where we can make all our decisions using our connected devices en route.
what.the.ferraro
Facebook the Movie... Awful

7|23|10   |   2:39   |   6 comments


Nothing quite says jumping the gun like making a movie about a six-year-old company.

Enabling People and Organizations to Harness the Transformative Power of Technology