Showing posts with label CyberSecurity. Show all posts
Showing posts with label CyberSecurity. Show all posts

Sunday, April 21, 2013

Yet another JKB UPDATE: “AUTHORIZED” TAKEDOWN / HACKING of a Supposed Security Experts “UN-HACKABLE” WEBSITE! » GE Investigations Blog

“AUTHORIZED” TAKEDOWN / HACKING of a Supposed Security Experts “UN-HACKABLE” WEBSITE…

Joseph K. Black’s Companies LulzSec ‘Wins’ Black & Berg Hacking Prize

 

LulzSec Website Picture

 

Black & Berg Cybersecurity Consulting [linked website taken down] set up a competition for anyone who could change the image on their front page to win ‘$10K and a position working with Senior Cybersecurity Advisor, Joe Black.’ The hack was quickly completed by LulzSec who published an image on the front page and said ‘done, that was easy, keep your money we do it for the lulz’

 

@LulzSec Black & Berg Cybersecurity Consulting appreciate all the hard work that you’re putting in. Your Hacking = Clients for us. Thx ~Joe

The consultancy agency has regularly published tweets linking directly to LulzSec hacks. In one tweet, Joseph Black, writes ‘FBI username and passwords. Enjoy. (Hint: They use the same passwords for ALL their accounts!),’ attaching a link to a text file with the passwords.

The cybersecurity agency describe their business as the use of the ‘close relationship with the Federal Government to give our small business clients a Cybersecurity posture that equals or exceeds that of the NSA and Department of Defense,’ on their Facebook presence.

 

Direct Link: http://linearfix.wordpress.com/2011/06/08/lulzsec-wins-black-berg-hacking-prize/

 

INSIDE JOB.

@th3j35ter is more than a Newt Gingrich, he also violates Wounded Warriors | The Internet Chronicle

My dear j35t3r, you are a bottomless source of lulz.

When I helped ruin your Westboro Baptist Psy-Op, Topiary took all the glory and I stole all your troll food. You were a failure then, and you are a failure now. You may be pretty good at throwing packets around, but that doesn’t mean you have any valuable skills. I have all the insanely advanced Computer Science 101 it takes to do what you do, but I can get attention for my cause without the parlor tricks you pass for hacktivism. This site gets nearly as much traffic as yours without the need for that kind of childish behavior.

failtroll th3j35ter is more than a Newt Gingrich, he also violates Wounded Warriors

In June, th3j35t3r received a huge spike in traffic because Tyler Bass mentioned him in an interview with LulzSec.

Lately, no one’s been paying attention to you. That makes you a sad little troll, eh? Your recent confrontation with John Tiessen not only proves you are desperately in need of attention, but it also shows how fearful you are of engaging truly skilled trolls. Remember that hilarious, substantive troll about Hugo Carvalho I published on pastebin in your name? You denied it before I could even refresh the page to see the view count. I guess you were saving all your attention for this obstreperous John Tiessen nutjob. I guess it’s just natural that you’d pick the low hanging fruit. It’s okay, you know I’m a pro, and you know not to fuck with me.

John Tiessen is right though, you are a Newt Gingrich. The fact that Tiessen is a sex offender only strengthens his point. It takes one to know one, as they say. You’re an adult who believes that the childish DDoS of Jihadist web sites justifies the illegal possession of a bot-net. You rape the computers of children, old women, wounded soldiers, and the general public just so you can get the kind of attention that other writers at this site and I command with pure creativity. And then, most insulting of all, you use what you do as a platform to collect donations for Wounded Warriors and yourself. You sick Newt Gingrich.

I hope you enjoy your empty bitcoin purse and your dwindling traffic. Your 15 minutes of fame are up, loser. Tick-tock, tango down, stay frosty. Get the fuck off the internet forever, please.

Yours truly,

Someone much better than you

P.S. As a joke, I advertised my bitcoin address (18zJouAQAMzX5sJygZ4M2QV7yb8FzxSbdq) and begged for money to spend on Silk Road. Since then, I have received more donations than you ever will.

We tested this page and blocked content that comes from potentially dangerous or suspicious sites. Allow this content only if you’re sure it comes from safe sites.

Joseph K Black plagiarizes Gregory D Evans | The Internet Chronicle

Joseph K Black plagiarizes Gregory D Evans

Famous for books that are 99.3% plagiarized, security charlatan Gregory D Evans has, for once, had his work stolen out from under him. Joseph K Black has adopted Gregory D Evans’ methods. Black has cited his doubtful “expertise” as a reason for people to pay attention to him. Joseph K Black is unapologetic about his obvious intellectual theft from Gregory D Evans, just as Evans embraces his place as a plagiarist.

twittershot Joseph K Black plagiarizes Gregory D Evans

Twitterrific is a Mac-only Twitter client, final proof of Gregory D Evans' fraudulent computer expertise.

Gregory D Evans obviously doesn’t care that he’s a plagiarist, as long as he gets his attention. He’s made many contradictory and uninformed comments for reporters who think he’s an expert on Anonymous or computer security.

This is a challenge to Joseph K Black: Step up your game if you want to outdo Gregory D Evans.

We tested this page and blocked content that comes from potentially dangerous or suspicious sites. Allow this content only if you’re sure it comes from safe sites.

Saturday, April 20, 2013

Richard Clarke: China's Cyberassault on America - WSJ.com

In justifying U.S. involvement in Libya, the Obama administration cited the "responsibility to protect" citizens of other countries when their governments engage in widespread violence against them. But in the realm of cyberspace, the administration is ignoring its primary responsibility to protect its own citizens when they are targeted for harm by a foreign government.

Senior U.S. officials know well that the government of China is systematically attacking the computer networks of the U.S. government and American corporations. Beijing is successfully stealing research and development, software source code, manufacturing know-how and government plans. In a global competition among knowledge-based economies, Chinese cyberoperations are eroding America's advantage.

The Chinese government indignantly denies these charges, claiming that the attackers are nongovernmental Chinese hackers, or other governments pretending to be China, or that the attacks are fictions generated by anti-Chinese elements in the United States. Experts in the U.S. and allied governments find these denials hard to believe.

Three years ago, the head of the British Security Service wrote to hundreds of corporate chief executive officers in the U.K. to advise them that their companies had in all probability been hacked by the government of China. Neither the FBI nor the Department of Homeland Security has issued such a notice to U.S. executives, but most corporate leaders already know it.

David Gothard

Some, like Google, have the courage to admit that they have been the victims of Chinese hacking. We now know that the "Aurora" attack (so named by the U.S. government because the English word appears in the attack software) against Google in 2009 also hit dozens of other information technology companies—allegedly including Adobe, Juniper and Cisco—seeking their source code. Aurora wasn't an isolated event. This month Google renewed its charge against China, noting that the Gmail accounts of senior U.S. officials had been compromised from a server in China. The targeting of specific U.S. officials is not something that a mere hacker gang could do.

The Aurora attacks were followed by systematic penetrations of one industry after another. In the so-called Night Dragon series, attackers apparently in China went after major oil and gas companies, not only in the U.S. but throughout the world. The German government claims that the personal computer of Chancellor Angela Merkel was hacked by the Chinese government. Australia has also claimed that its prime minister was targeted by Chinese hackers.

Recently the computer-security company RSA (a division of EMC) was penetrated by an intrusion which appears to have stolen the secret sauce behind the company's SecureID. That system is widely used to protect critical computer networks. And this month, the largest U.S. defense contractor, Lockheed, was subject to cyberespionage, apparently by someone using the stolen RSA data. Cyber criminals don't hack defense contractors—they go after banks and credit cards. Despite Beijing's public denials, this attack and many others have all the hallmarks of Chinese government operations.

In 2009, this newspaper reported that the control systems for the U.S. electric power grid had been hacked and secret openings created so that the attacker could get back in with ease. Far from denying the story, President Obama publicly stated that "cyber intruders have probed our electrical grid."

There is no money to steal on the electrical grid, nor is there any intelligence value that would justify cyber espionage: The only point to penetrating the grid's controls is to counter American military superiority by threatening to damage the underpinning of the U.S. economy. Chinese military strategists have written about how in this way a nation like China could gain an equal footing with the militarily superior United States.

What would we do if we discovered that Chinese explosives had been laid throughout our national electrical system? The public would demand a government response. If, however, the explosive is a digital bomb that could do even more damage, our response is apparently muted—especially from our government.

Congress hasn't passed a single piece of significant cybersecurity legislation. When the Chinese deny senior U.S. officials' claims (made in private) that Beijing is stealing terabytes of data in the U.S., Congress should not leave the American people in doubt. It should demand answers to basic questions:

What does the administration know about the role of the Chinese government in cyberattacks on public and private computer networks in the United States?

If there is widespread Chinese hacking of sensitive U.S. networks and critical infrastructure, what has the administration said about it to the Chinese government? Specifically, did President Obama raise concerns about these attacks with Chinese President Hu Jintao at the White House this spring?

Since defensive measures such as antivirus software and firewalls appear unable to stop the Chinese penetrations, does the administration have any plan to address these cyberattacks?

In private, U.S. officials admit that the government has no strategy to stop the Chinese cyberassault. Rather than defending American companies, the Pentagon seems focused on "active defense," by which it means offense. That cyberoffense might be employed if China were ever to launch a massive cyberwar on the U.S. But in the daily guerrilla cyberwar with China, our government is engaged in defending only its own networks. It is failing in its responsibility to protect the rest of America from Chinese cyberattack.

Mr. Clarke was a national security official in the White House for three presidents. He is chairman of Good Harbor Consulting, a security risk management consultancy for governments and corporations.

Tuesday, April 2, 2013

Apple iCloud Hack Raises Concerns Over Cloud Security - Security - News & Reviews - eWeek.com

The hack into a writer’s iCloud account puts a spotlight on steps consumers should take to protect their data and flaws in the policies of Apple, Amazon and other vendors.

The hack into a Gizmodo writer€™s Amazon and Apple accounts over the weekend is being used as a cautionary tale for consumers, a call to action for cloud providers regarding security policies and a sounding board for concerns about the rush to the cloud.

In a lengthy first-person account in Wired magazine, writer Mat Honan outlines how an attacker quickly found his way into Honan€™s iCloud account and wiped everything from his Mac, iPhone and iPad, all of which were linked to Apple€™s cloud service. The attacker also hacked into his Twitter and Gmail accounts. In the story, Honan admonishes himself for failing to follow basic security protocol€"his online accounts were linked together, and he had failed to back up his data, for example.

However, the larger concern was how quickly and easily the attacker€"who called himself €œPhobia€€"was able to get gain control of Honan€™s Apple iCloud account through just a couple of phones calls to Amazon and Apple, convincing customer service representatives at both places that he was Honan. The attack was less about hacking into the accounts via a computer and more about social engineering gleans the necessary personal information from Amazon and Apple.

According to Honan, the hacker was able to get a hold of his email address, and used that and the billing address to convince  Amazon customer service representatives that he was Honan to talk his way into seeing Honan€™s account. With that access, Phobia was able to see the last four digits of Honan€™s credit card number. With that in hand, he called Apple tech support and€"armed with the last four credit card numbers, email address and billing address€"convinced them that he was Honan and to reset the iCloud login. The hacker now had access to all the accounts and the devices Honan owned.

€œAmazon tech support gave them the ability to see a piece of information€"a partial credit card number€"that Apple used to release information,€ Honan wrote. €œIn short, the very four digits that Amazon considers unimportant enough to display in the clear on the Web are precisely the same ones that Apple considers secure enough to perform identity verification. The disconnect exposes flaws in data management policies endemic to the entire technology industry, and points to a looming nightmare as we enter the era of cloud computing and connected devices.€

He wrote that since his experience Aug. 3, he€™s learned of others who have been attacked in the same way. It also backs up comments made by Apple founder Steve Wozniak, who after a recent performance of €œThe Agony and the Ecstasy of Steve Jobs€ in Washington, told the audience in a discussion that he saw bad times coming as the world embraced cloud computing.

"I really worry about everything going to the cloud," Wozniak said, according to reports. "I think it's going to be horrendous. I think there are going to be a lot of horrible problems in the next five years. €¦ I want to feel that I own things. A lot of people feel, 'Oh, everything is really on my computer,' but I say the more we transfer everything onto the Web, onto the cloud, the less we're going to have control over it."

In the wake of Honan€™s article, computer security experts have talked about steps consumers need to take to retain as much control as possible over the data they are putting into the cloud. And it goes beyond passwords, according to Lisa Myers, a blogger on the Mac Security Blog site for Apple security software vendor Intego.

€œAs much as we like to trumpet the use of good passwords, this is one instance in which this would not have made a difference,€ Myers said. €œYou can use the best password in the world, but if someone can socially engineer you or someone from the site or service itself to reveal your password, it will make no difference. That isn€™t to say that strong passwords are not important; having a strong password will protect you against the majority of common attacks. But you should definitely not bet the farm on a password.€

There are steps consumers should take, she and others said. That includes encrypting as much of the online data as possible, making it more difficult for hackers to use data they gain access to. Reconsider linking accounts€"trading in convenience for security€"and using two-factor authentication when possible. Also, for such accounts, use an email that is unknown to others. In addition, according to Paul Ducklin, head of technology for Asia-Pacific for security software vendor Sophos Lab, consumers should make and keep backups outside of the cloud, and use an independent remote wipe service rather than one that is part of the cloud service.

As much as consumers have to take steps to protect themselves, vendors like Apple and Amazon, which hold so much personal information of their users, need to bulk up their policies. An Apple spokesperson told Honan that in his case, the company€™s internal policies were not followed. In addition, Wired reported that Amazon Aug. 6 changed its customer privacy policies, including no longer allowing people to call in and change account settings in their user accounts.

Neither Apple nor Amazon have commented publicly about Honan€™s case.

Sophos€™ Ducklin said in an Aug. 6 post on his company€™s Naked Security blog that Apple recently bolstered its security policies by asking users to provide a number of security questions for further authentication. However, he said that in Honan€™s case, because the hacker used social engineering and talked an Apple representative into giving him the information, the tighter security policies wouldn€™t have mattered.

Apple, Amazon and others are in a difficult spot, Ducklin said. Companies can enforce €œutterly inflexible procedures for password reset,€ he said, but that is done more to save money by reducing the workforce rather than security. It also leads to situations where legitimate consumers can€™t solve password reset issues.

€œOr you can keep humans in the loop, and run the risk that their occasional helpfulness will occasionally be off the mark,€ he wrote. €œThat's what happened with Honan.€

iCloud hack shows the serious problem with living la vida Apple - CSMonitor.com

You run to your laptop, and catch it erasing all its own data. You get online, but both of your email addresses have been hijacked, your online storage has been emptied, and someone else is using your Twitter account.

This nightmare scenario happened in real life Friday afternoon for Mat Honan, a technology journalist based in San Francisco.

Someone took over Honan's Apple account, which let him remotely wipe Honan's iPhone, iPad, and MacBook, then leverage that power to take over Honan's Google and Twitter accounts as well, plus the Twitter account of Gizmodo, the tech blog Honan sometimes writes for.

Yet Honan's enemy wasn't an elite hacker who used advanced techniques to crack Honan's password. Instead, the attacker simply placed a call to Apple tech support and convinced Apple to give him control of Honan's Apple account.

Tale of the tape

"At 4:50 PM, someone got into my iCloud account, reset the password and sent the confirmation message about the reset to the trash," Honan wrote on his Tumblr account, which was spared. "At 4:52 PM, they sent a Gmail password recovery email to the .mac account. Two minutes later, an email arrived notifying me that my Google Account password had changed.

"At 5:00 PM, they remote wiped my iPhone. At 5:01 PM, they remote wiped my iPad. At 5:05, they remote wiped my MacBook Air. A few minutes after that, they took over my Twitter." (Honan posted a screen grab of the notifications his Gmail account received.)

The attacker, identifying himself as part of a hacker group calling itself "Clan Vv3," used Honan's Twitter account, "@mat," to post, "@gizmodo Tell this dumbass employee mat he's an idiot for using insecure email services, having a 3-letter Twitter, and having access to [Gizmodo]."

Then he or she took over Gizmodo's Twitter account and posted offensive messages for about 15 minutes.

Clan Vv3 has been hijacking the Twitter accounts of minor celebrities for several months, for example one belonging to comedian and TV star Whitney Cummings in June.

After a distressing couple of days, Honan has now regained control of his Twitter and Google accounts and has an appointment with an Apple Store Genius Bar [on Aug. 6] to try to recover the data on his Macbook.
Related stories

10 great Siri tricks that iPhone owners probably don't know
13 Tips to Keep Your Devices Safe While Traveling (SecurityNewsDaily)
French T-Shirt Maker Defends Stealing Anonymous' Identity (SecurityNewsDaily)
10 Best Mac Anti-Virus Software Products (SecurityNewsDaily)
As hacking victim's story spreads, Apple and Amazon tighten security
Apple tightens account security with two-factor authentication

Technology is smart, but people are dumb

The entire episode should serve as a warning to others about two issues.

First, Honan was overly reliant on one company's services — in this case, Apple's. Honan backed up his MacBook, his iPhone and his iPad, but he did so only to iCloud, Apple's own cloud-storage service. All of that was destroyed with one password.

Cloud storage is great, as long as you have reliable Internet access, but it's best to have backups you physically control — for example, on an external hard drive.

Honan's ".mac" email address was the emergency confirmation address that Honan had instructed Google to notify if anything went wrong with his Google account.

So when the attacker, posing as Honan, pretended he'd forgotten his Google password, the confirmation email went to the .mac address, which the attacker already controlled.

Once the attacker had control of the Google account and the Gmail service, he used that to take over Honan's Twitter feed.

Honan could have used Google's two-factor authentication service, which upon a password-reset attempt sends a text message to a designated cellphone as well as an email to a non-Google email address for confirmation. But that wouldn't have prevented the wholesale wiping of all his Apple products.

Second, no matter how good security technology gets, it will never be able to stop "social engineering" attacks, or what your grandparents would have called a good con job.

In the early '90s, famed hacker Kevin Mitnick found that the best way to get into any secure system was to simply telephone the system's administrators and convince them you were an employee who'd forgotten his password.

Twenty years and thousands of successful hacks later, the same method still works on the world's most valuable and most high-profile technology company.

It's not clear exactly what the attacker said to the tech-support person who answered the phone, but as some experts have pointed out, Apple should not give frontline tech-support staffers the ability to reset user passwords.

Most online-account hijacks are the result of weak passwords — the passwords are too short, too obvious, used in too many places or limited to lower-case letters.

Honan's password was rather short, but it was unique and used mixed characters. "My password was a 7-digit alphanumeric that I didn’t use elsewhere," he wrote on his Tumblr page.

But it didn't matter. As Sascha Segan of PC Magazine tweeted, "The strongest password in the world wouldn't have saved @mat."

RECOMMENDED: 10 great Siri tricks that iPhone owners probably don't know
Related stories

10 great Siri tricks that iPhone owners probably don't know
13 Tips to Keep Your Devices Safe While Traveling (SecurityNewsDaily)
French T-Shirt Maker Defends Stealing Anonymous' Identity (SecurityNewsDaily)
10 Best Mac Anti-Virus Software Products (SecurityNewsDaily)
As hacking victim's story spreads, Apple and Amazon tighten security
Apple tightens account security with two-factor authentication

FBI: 'Swatting' Cases Across The Country May Be Copycats - ABC News

At 9:18 p.m. on Aug. 3, the San Francisco Police Department received a call from a man reporting that his brother was being held hostage in his own home. After three hours of trying to reach the victims, SWAT teams burst into the house.

Once inside, they found a husband and wife in their mid-thirties with their two small children, spending a quiet evening at home.

"There was no merit to any kidnapping or actual hostage situation," said Sgt. Michael Andraychak, a public information officer for the San Francisco Police.

The SFPD had been the victim of "swatting": placing prank phone calls to police to lure them to mobilize SWAT teams to respond to fake hostage situations.

Courtesy of Myles Ma/Patch.com
On July 23, the Bergen County Police... View Full Size
New Jersey Swat Team Called in Response to 'Prank' Watch Video
Mom Calls 911, Pleads With Robber Watch Video
Say What? Bizarre 911 Calls Watch Video

Swatting has spread throughout the United States and Canada in recent months.

"Once you catch a swatter or a group that is committing these crimes, they are usually responsible for multiple swatting incidents," said Kevin Kolbye, the assistant special agent in charge of the FBI's Dallas office, which headed the first federal swatting case in 2007. Kolbye has been piecing together what appeared to be isolated swatting cases around the country since 2004.

In the past, offenders have solicited private information about their intended victims from phone companies and slipped the victims' numbers into the caller ID of the 911 emergency system -- a method called spoofing.

But according to Kolbye, it doesn't take an experienced hacker to trigger a fake hostage situation and mobilize SWAT teams.

"It's not like it's a hard crime," he said. "It just takes somebody who has a little bit of savvy about computers and telephone systems."

Recent swatting incidents may be copycats of earlier crimes, Kolbye said, instigated by past offenders who brag about their methods on blogs.

"I think you find a lot of copycat violations," Kolbye said. "Same as you find when a highly publicized serial killer is around, you find a lot of copycatting. So when crimes receive national attention, you find people who are intrigued with this type of crime and they emulate it."

Swatting perpetrators tend to be males between in their 20s and 30s -- social misfits who mobilize SWAT teams for nothing more than "bragging rights," Kolbye said.

Swatting in Canada and the U.S.

In Canada, local media report that SWAT teams were prank called to family homes in North Toronto and British Columbia last month.

In Florida, the Hialeah Police Department received a teletype on Aug. 2 with information that a shooter, armed with an AR-15 rifle, was holding a victim hostage in a local home. Public information officer Det. Eddy Rodriguez said that after five hours of evacuating surrounding buildings and attempting contact with victims inside the home, the SWAT team broached the house. Nobody was home.

Forty members of the Bergen County Police Department SWAT team burst into the home of cyber expert Perry Aftab in Wyckoff, N.J., on July 23, responding to a caller who reported that he had already killed four people and taken several others hostage. When SWAT members entered the home fighting tear gas from four bombs they thrown through the windows, they were greeted only by a cat.

"I'm not laughing," said Wyckoff Police Chief Benjamin Fox, who was in lead command of the SWAT team.

Fox said that swatting drains local law enforcement of their already scarce resources and poses a danger to innocent victims who may accidentally get hurt.

"You've got police officers running around with high powered weapons acting under belief of a potential threat against them," he said. "What's if there's an accident? What if somebody innocently comes out of their house because of the hoax and it's perceived by officers of scene as someone else? After the fact, we would have to sort out that whole tragic situation which now has been elevated to another level."

All three recent U.S. swatting incidents are federal offenses that are under investigation. Perpetrators could face charges of conspiracy and fraud, which carry maximum penalties of five and 20 years in prison respectively.

"Each time they call, they leave an investigative trail: a piece of evidence," Kolbye said. "It's just a matter of time for us to continue to put all the pieces together and come knocking on their door."

FBI — The Cyber Threat: Planning for the Way Ahead

The Cyber Threat
Planning for the Way Ahead

02/28/13

Denial of service attacks, network intrusions, state-sponsored hackers bent on compromising our national security: The cyber threat is growing, and in response, said FBI Director Robert S. Mueller, the Bureau must continue to strengthen its partnerships with other government agencies and private industry—and take the fight to the criminals.

“Network intrusions pose urgent threats to our national security and to our economy,” Mueller told a group of cyber security professionals in San Francisco today. “If we are to confront these threats successfully,” he explained, “we must adopt a unified approach” that promotes partnerships and intelligence sharing—in the same way we responded to terrorism after the 9/11 attacks.


Padlocks graphic

 Focus on Hackers and Intrusions

The FBI over the past year has put in place an initiative to uncover and investigate web-based intrusion attacks and develop a cadre of specially trained computer scientists able to extract hackers’ digital signatures from mountains of malicious code. Learn more 


The FBI learned after 9/11 that “our mission was to use our skills and resources to identify terrorist threats and to find ways of disrupting those threats,” Mueller said. “This has been the mindset at the heart of every terrorism investigation since then, and it must be true of every case in the cyber arena as well.”

Partnerships that ensure the seamless flow of intelligence are critical in the fight against cyber crime, he explained. Within government, the National Cyber Investigative Joint Task Force, which comprises 19 separate agencies, serves as a focal point for cyber threat information. But private industry—a major victim of cyber intrusions—must also be “an essential partner,” Mueller said, pointing to several successful initiatives.

The National Cyber Forensics and Training Alliance, for example, is a model for collaboration between private industry and law enforcement. The Pittsburgh-based organization includes more than 80 industry partners—from financial services, telecommunications, retail, and manufacturing, among other fields—who work with federal and international partners to provide real-time threat intelligence.

Another example is the Enduring Security Framework, a group that includes leaders from the private sector and the federal government who analyze current—and potential—threats related to denial of service attacks, malware, and emerging software and hardware vulnerabilities.

Mueller also noted the Bureau’s cyber outreach efforts to private industry. The Domestic Security Alliance Council, for instance, includes chief security officers from more than 200 companies, representing every critical infrastructure and business sector. InfraGard, an alliance between the FBI and industry, has grown from a single chapter in 1996 to 88 chapters today with nearly 55,000 members nationwide. And just last week, the FBI held the first session of the National Cyber Executive Institute, a three-day seminar to train leading industry executives on cyber threat awareness and information sharing.

“As noteworthy as these outreach programs may be, we must do more,” Mueller said. “We must build on these initiatives to expand the channels of information sharing and collaboration.”

He added, “For two decades, corporate cyber security has focused principally on reducing vulnerabilities. These are worthwhile efforts, but they cannot fully eliminate our vulnerabilities. We must identify and deter the persons behind those computer keyboards. And once we identify them—be they state actors, organized criminal groups, or 18-year-old hackers—we must devise a response that is effective, not just against that specific attack, but for all similar illegal activity.”

“We need to abandon the belief that better defenses alone will be sufficient,” Mueller said. “Instead of just building better defenses, we must build better relationships. If we do these things, and if we bring to these tasks the sense of urgency that this threat demands,” he added, “I am confident that we can and will defeat cyber threats, now and in the years to come.”

Resources:
- Read Director Mueller’s remarks
- Cyber Crime page
- National Cyber Investigative Joint Task Force

- National Cyber Forensics and Training Alliance
- Infragard

FBI — The New Phenomenon of Swatting

Don’t Make the Call
The New Phenomenon of ‘Swatting’

02/04/08

phonecord020408.jpg

Remember the “phone phreakers?” The term hit our national consciousness in the 1970s, when a magazine reported on a small group of techie troublemakers who were hacking into phone companies’ computers and making free long-distance calls.

Today, there’s a new, much more serious twist on this old crime. It’s called “swatting,” and it involves calling 9-1-1 and faking an emergency that draws a response from law enforcement—usually a SWAT team.

Needless to say, these calls are dangerous to first responders and to the victims. The callers often tell tales of hostages about to be executed or bombs about to go off. The community is placed in danger as responders rush to the scene, taking them away from real emergencies. And the officers are placed in danger as unsuspecting residents may try to defend themselves.

Last year, for example, a 19-year-old Washington state man was charged by California authorities after pretending to be calling from the home of a married California couple, saying he had just shot and murdered someone. A local SWAT team arrived on the scene, and the husband, who had been asleep in his home with his wife and two young children, heard something and went outside to investigate—after first stopping in the kitchen to pick up a knife. What he found was a group of SWAT assault rifles aimed directly at him. Fortunately, the situation didn’t escalate, and no one was injured.

The schemes can also be fairly sophisticated. Consider the following case investigated by our Dallas office recently in concert with a range of partners:

  • Five swatters in several states targeted people who were using online telephone party chat lines (or their family or friends).
  • The swatters found personal details on the victims by accessing telecommunication company information stored on protected computers.
  • Then, by manipulating computer and phone equipment, they called 9-1-1 operators around the country. By using “spoofing technology,” the swatters even made it look like the calls were actually coming from the victims!
  • Between 2002 and 2006, the five swatters called 9-1-1 lines in more than 60 cities nationwide, impacting more than 100 victims, causing a disruption of services for telecommunications providers and emergency responders, and resulting in up to $250,000 in losses.
  • “Swats” that the group committed included using bomb threats at sporting events, causing the events to be delayed; claiming that hotel visitors were armed and dangerous, causing an evacuation of the entire hotel; and making threats against public parks and officials.

Case work. The swatters were tracked down through the cooperative efforts of local, state, and federal agencies and the assistance of telecommunications providers and first responders. In all, the case involved more than 40 state and local jurisdictions in about a dozen states. All five subjects have pled guilty to various charges and are scheduled to be sentenced in 2008.

Why did they do it? Said Kevin Kolbye, Assistant Special Agent in Charge of our Dallas office: “Individuals did it for the bragging rights and ego, versus any monetary gain.” Basically, they did it because they could.

Law enforcement agencies at all levels are currently working with telecommunications providers around the country to help them address swatting activity.

You can help, too—if you believe you’ve been a victim of a “swat” please contact your local FBI office.

Swatting | Law Enforcement Today

Swatter’s Rights?

11:18 am in Featured, Future Crime Trends, Posts, SWAT, Training by James P Gaffney

Swatting is the new rage, growing in frequency throughout the United States and is now an emerging trend in Canada as well. Both countries are experiencing bogus 911 calls requiring an immediate police response. Often a SWAT response is initiated to overcome dire circumstances based on information falsely reported.

A SWAT response requires effective coordination of effort and incident management.  The Incident Commander deploys personnel and resources when a purported critical incident is in progress. SWAT deploys if needed. The swatting is complete once personnel recognize after the fact that no crisis actually exists. Once the hoax is realized, the “swatter” disappears without leaving behind witnesses, fingerprints, DNA, or a traditional crime scene.

No one has been killed yet by a “swatting” incident.  However, innocent people have been forced to the ground, handcuffed, and temporarily detained following the swift action of a SWAT Team. Clearly, the potential for citizen and officer deaths as well as serious injury is simply a matter of time.

SWAT officers need to act quickly. Precise control of the scene is required. The very technical expertise and precision of SWAT teams are being used against law enforcement in swatting incidents.

Kevin Kolbye is the assistant special agent in charge of the Dallas office of the FBI. In 2007, the Dallas office initiated the first swatting case. Kolbye stated that it would be easy for an individual with knowledge of computers, telephone systems, and the desire to do so to create a false hostage situation to initiate a SWAT response.   Successful “swatting” incidents tend to draw national media attention. This in turn generates copycat incidents. Each swatter desires to surpass what others accomplished previously.

There is no exact formula to create a “swatting” incident. In the past, law enforcement had to deal with false alarms and prank calls for service.  However, these incidents pale in comparison to what today’s “swatter” dreams up.  The greater the expenditure of time, effort, manpower, funds, equipment, and disruption of everyday services, the more a swatter is rewarded.  Once swatters experience the adrenalin rush from experiencing such power and control, they need to create similar incidents.   Kollbye advised that swatters do these things simply because they can.

Swatting incidents are criminal acts. The brazenness of the acts has grown with the passing of time. Generally, as information is first received by 911, an immediate police response is initiated. The severity of the circumstances requires an additional response of support personnel and equipment to the scene.

The caller and 911 dispatcher have ongoing communication. As false information is provided to field intelligence, incident commanders are hard-pressed to contact the people they believe need assistance.

From my perspective, swatting has reached a new level. It is more involved.   Just initiating the SWAT action is no longer is the sole goal of a swatter.   Swatters realize success when they can initiate a massive SWAT response with one or more agencies focused on saving lives…for nothing.

Following are recent examples of swatting incidents:

- As of June 27, 2012, four cases of swatting have occurred in the City of Rye, NY. Each incident called for an emergency response. Police believe that a group may be involved. A 14-year-old Rye youth was charged for allegedly making a false report of a home invasion. This investigation is ongoing. Rye Police requested FBI assistance.

- June 11, 2012 the Coast Guard received a report a yacht had exploded off the coast of New Jersey. The caller communicated updates on the situation. An immediate response was required because authorities believed that the boat was sinking.

Information provided by the Coast Guard indicates that the caller claimed three people were dead, 9 injured, and 20 in the water. The caller also advised the Coast Guard that individuals made their way to life rafts. The Coast Guard and New York City police helicopters conducted a search and rescue response of the area for approximately four hours. No sign was ever found suggesting a sinking vessel due to an explosion.

- June 11, 2011 the Coast Guard was advised via their National Distress System that a 33-foot sailboat was sinking. An hour later, a second contact indicated that the boat was almost completely submerged. The Coast Guard was advised the four boaters were changing over to a small gray boat.  They were also advised that the boat was not equipped with flares or a handheld radio. A 10-hour search and rescue operation did not turn up signs of the boaters or the sailboat under water.

- Last year (2011) the Coast Guard, with the assistance of state and local agency marine responded to more than 60 suspected prank calls in the Northern New Jersey, New York City, and Hudson River region.

- On August 3, 2011, a caller reported to the San Francisco Police Department that his brother was being held hostage in his own home. After failing to make contact, SWAT Team entered the home. There was no merit to the call. A couple was at home with their two children. This detail was in place for more than three hours.

In Canada, the same kinds of events are being staged as in United States.  This situation represents an extremely dangerous trend.  Law enforcement agencies MUST respond to any request for help.  However, response to false incidents represents a totally unnecessary expenditure of time and resources in an era of diminishing public budgets.

Assistance from federal agencies will be needed to address this new crime trend, which represents not only an unnecessary risk to personnel and expense, but also has frightening terror implications.  Terror cells could deploy similar swatting incidents as a decoy to a real terror event staged while emergency resources are deployed elsewhere.

Jim Gaffney, MPA is LET’s risk management /police administration contributor.  He has served with a metro-New York police department for over 25 years in varying capacities, including patrol officer, sergeant, lieutenant, and executive officer. He is a member of  ILEETA, IACP, and  the IACSP.  Jim mentors the next generation of LEOs by teaching university-level criminal-justice courses as an adjunct professor in the New York City area.

Learn more about this article here:

http://abcnews.go.com/Technology/fbi-swatting-cases-country-copycats/story?id=14257526

http://www.dailymail.co.uk/news/article-2023415/Armed-police-raiding-homes-Canada-dangerous-swatting-trend-makes-way-north.html

http://www.lohud.com/apps/pbcs.dll/article?AID=2012307040038

http://www.ems1.com/search-rescue/articles/1303020-Hoax-yacht-explosion-part-of-growing-trend-SWAT-ting

http://www.ems1.com/communications-dispatch/articles/1303776-Swatting-pranks-Not-so-funny-to-EMS/

http://www.fbi.gov/news/stories/2008/february/swatting020408

http://www.military.com/daily-news/2012/06/21/hoax-yacht-explosion-may-be-tied-to-swatting.html

http://www.networkworld.com/community/node/24714

SCADA Security: Welcome to the Patching Treadmill | Tofino Industrial Security Solution

As regular readers of this blog know, after Stuxnet, security researchers and hackers on the prowl for new targets to exploit shifted their efforts to critical industrial infrastructure.

 

Unfortunately, the Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) applications they are now focusing on are sitting ducks.

 

Up until recently SCADA and ICS systems have been designed with reliability and safety in mind; security has been a minor consideration. Products that have never faced security tests are now under attack from sophisticated vulnerability discovery tools, and major control system security flaws are being continuously exposed.

 

SCADA/ICS applications are easy targets for security researchers and hackers.

Image Credit: Active Rain Caption

 

In recent years, we have seen a staggering growth in government security alerts for these systems, and have witnessed some of the most sophisticated cyber-attacks on record.

 

The US government’s ICS-Computer Emergency Response Team (ICS-CERT) tracks and publishes Security Advisories for known security vulnerabilities found in industrial products. In the entire decade prior to the discovery of Stuxnet (July 2010), ICS-CERT published 5 security advisories involving 3 vendors.

 

Compare this to 2011, when there were:

 

• 215 publicly disclosed vulnerabilities

• 104 security advisories

• 39 vendors involved in those security advisories

 

By late 2012, the total publically disclosed vulnerabilities topped 569.

 

And remember that these vulnerabilities are typically disclosed to the world prior to ICS vendors having patches available.

 

Furthermore, 40% of disclosed vulnerabilities include working attack code. This means that individuals can download exploit tools and run them against a target with little understanding of control systems or the consequences of their actions. And download and attack they do - ICS-CERT reported over 20,000 reports of unauthorized internet access to control systems in the last half of 2012.

Welcome to the Industrial Security Patching Treadmill!

Since security researchers, hackers, and issues have essentially migrated from the IT environment, it’s not surprising that we look to that world for a solution. There, security vulnerabilities are addressed by applying software patches - a constant cycle involving multiple patches over the life of a product. In fact, the typical IT computer needs patching (with a full reboot) at least once per week.

 

You don’t need to be a SCADA/ICS expert to realize that shutdowns of that frequency just aren’t feasible for critical infrastructure control systems.

On and on and on it goes... Image Credit: Learning to Fly

So How Many Patches Does a Control System Need?

One might argue that a control system requires fewer patches than an IT system…or that the software footprint is smaller, the code quality better… If so, then maybe the patching cycle could be synchronized with annual maintenance shutdowns. In this scenario, patching could be a workable solution to address software vulnerabilities.

 

To determine if this was an option, in 2008 I participated in the analysis of a U.S. refinery process control network (PCN). There were 85 computers on the refinery PCN, and a similar number of industrial controllers. Although we could only gather reliable data for 78 of the computers, we determined that they were running 272 distinct processes/applications.

 

A search of the National Vulnerability Database (NVD) found that 48 of these processes had one or more serious security vulnerabilities. Across the refinery PCN, there were 5,455 publically known vulnerabilities, an average of 70 per machine. An aggressive Windows OS patch program reduced this number by almost 50%, but that still left 2,284 published vulnerabilities remaining. Why? Because the applications involved did not have a means of automated patching.

Latent PLC Vulnerabilities Are Not All Disclosed at Once

And let’s not forget the latent vulnerabilities lurking in the control system. Academic research tells us that most commercial software contains 3 - 10 defects for every thousand lines of code (KLOC), and that 1% to 5% of these result in vulnerabilities. That works out to between 0.03 and 0.5 vulnerabilities per KLOC.

 

So what does that mean in real life?

 

Take Windows XP, for example…it contains about 40 million lines of code (40,000 KLOC). As of October 2012, about 1106 moderate or severe vulnerabilities have been listed in the NVD for Windows XP - that’s a Vulnerability/KLOC ratio of about 0.0276.

 

Whatever your experience using Windows XP, seems it’s on the low end of vulnerabilities and pretty good from a security point of view!

 

Looking back at the history of Windows XP vulnerabilities, we have to assume that SCADA/ICS vulnerabilities won’t all be disclosed at one time. We’ll likely see a relatively small number of disclosures in the first few years, as researchers begin to investigate the products in the industrial space. Then, after SCADA/ICS products have been exposed to widespread security scrutiny, a virtual avalanche of vulnerabilities may occur, resulting in the need to install control system patches on a weekly basis.

 

 Prepare for an avalanche of vulnerabilities once SCADA/ICS products have been exposed to security scrutiny. Image Credit: The Alaska Avalanche Information Center

We Can’t Ignore SCADA/ICS Firmware

It’s also obvious that the firmware in PLC and DCS controllers will also have vulnerabilities and will require patching. Controllers typically contain between 1,000 KLOC and 5,000 KLOC of firmware. Based on the analysis used above, this means that each is likely to contain between 30 and 150 vulnerabilities. If the vulnerability disclosure curves are similar to those we’ve seen in the IT sector, we can expect a low number of patches in the immediate future, followed by an epidemic in a few years.

 

The above analysis clearly indicates that the frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers is likely to exceed the tolerance of most SCADA/ICS operators for system shutdowns.

 

Tune in to next week’s blog and learn about the impact of patches, what happens when there are no patches, and why many SCADA/ICS customers simply don’t want to patch...

 

Do you think that patching is a workable solution for securing SCADA/ICS control systems? Do you have any patching success or horror stories to share? Let me know your thoughts.

Related Content to Download

Presentation - "Patching for Control Systems - A Broken Model?"

 

Download this presentation and learn about:

 

•    The challenges of patching for control systems

 

•    Vendor data on patching deployment rates on ICS products and what can be achieved in the    future

•    Compensating control-based solutions for security vulnerabilities

 

This document is vendor neutral and is ideal for serious consideration of the topic.
 

Related Links

•    Press Release: Belden Research Shows that Patching for Industrial Cyber Security is a Broken Model

•    ICS-CERT.US-CERT.gov, Webpage: The Industrial Control Systems Cyber Emergency Response Team
•    Automation.com, Webpage: Cyber Attacks on Industrial Systems Increasing Rapidly
•    National Vulnerability Database (NVD), Webpage: Database search page
•    Blog: SCADA Security Basics: Why are PLCS so Insecure?
•    Blog: S4 Security Symposium Takeaway: Time for a Revolution
•    Blog: Tofino provides an Alternative to Patching
 

Belden Research Shows that Patching for Industrial Cyber Security is a Broken Model | Tofino Industrial Security Solution

St. Louis, Missouri – March 14, 2013 – Belden Inc. (NYSE: BDC), a global leader in signal transmission solutions for mission-critical applications, announces that its Tofino Security brand has published new research showing that patching is often ineffective in providing protection from the multitude of vulnerability disclosures and malware targeting critical infrastructure systems today. While patching such systems is important as part of an overall Defense in Depth strategy, the difficulties of patching for industrial systems mean that compensating controls such as Tofino Security Profiles are often a better method of providing immediate protection.

 

Since the discovery of the Stuxnet malware in 2010, industrial infrastructure has become a key target for security researchers, hackers, and government agents. Designed years ago with a focus on reliability and safety, rather than security, Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) products are often easy to exploit. As a result, there has been exponential growth in government security alerts for these systems in the past two years. In addition, they have attracted some of the most sophisticated (Stuxnet, Night Dragon, Flame) and damaging (Shamoon) cyberattacks on record.

 

Eric Byres, CTO and vice president of engineering at Tofino Security, investigated the effectiveness of patching for protecting control systems from vulnerability exploits and malware. His work revealed that:

 

• The number of vulnerabilities existing in SCADA/ICS applications is high, with as many as 1,805 yet to be discovered vulnerabilities existing on some control system computers.

• The frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers likely exceeds the tolerance of most SCADA/ICS operators for system shutdowns. Unlike IT systems, most industrial processes operate 24x7 and demand high uptime. Weekly shutdowns for patching are unacceptable.

• Even when patches can be installed, they can be problematic. There is a 1 in 12 chance that any patch will affect the safety or reliability of a control system, and there is a 60% failure rate in patches fixing the reported vulnerability in control system products. In addition, patches often require staff with special skills to be present. In many cases, such experts are often not certified for access to safety regulated industrial sites.

• Patches are available for less than 50% of publically disclosed vulnerabilities.

• Many critical infrastructure operators are reluctant to patch as it may degrade service and increase downtime.

 

When patching is not possible, or while waiting for a semi-annual or annual shutdown to install patches, an alternative is to deploy a workaround, also known as a ‘compensating control’. Compensating controls do not correct the underlying vulnerability; instead, they help block known attack vectors. Examples of compensating controls include product reconfigurations, applying suggested firewall rules, or installing signatures that recognize and block malware.

 

Another compensating control is Tofino Security Profiles, available in Belden’s Tofino Security product line. Tofino Security Profiles are rule and protocol definitions that address newly disclosed vulnerabilities. They provide a simple way for automation system vendors to create and securely distribute malware protection. Operators benefit from a single, easy-to-deploy package of tailored rules that can be installed without impacting operations. The result is that critical industrial infrastructure facilities can quickly and effectively defend themselves against new threats.

 

“My research highlights the multiple challenges with patching for SCADA and ICS systems,” remarked Eric Byres. “To secure facilities, critical infrastructure operators should pursue a Defense in Depth strategy that includes patching when possible, and use compensating controls for protection when patching is not possible.”

 

Starting today, Belden is publishing a series of blog articles on its patching research and is accompanying them with useful documents. These documents include:

 

• “Patching for Control System Security - A Broken Model?”; a presentation that summarizes its patching research,

• “Patching for Control System Security - A Broken Model?“ a peer reviewed published paper,

• and “Solving the SCADA/ICS Security Patch Problem”, a White Paper.

 

Visit: http://www.tofinosecurity.com/blog/scada-security-welcome-patching-treadmill for the first blog article.

 

Tofino Security provides practical and effective industrial network security and SCADA security products that are simple to implement and that do not require plant shutdowns. Its products include configurable security appliances with a range of loadable security modules plus fixed function security appliances made for specific automation vendor applications. Tofino Security products protect zones of equipment on the plant floor, and are complementary to Belden’s Hirschmann brand, which leads industrial networking solutions. Both groups service and secure industrial networks in the oil and gas, utilities, transportation and automation industries.

www.tofinosecurity.com

 

About Belden

St. Louis-based Belden Inc. designs, manufactures, and sells connectivity solutions for markets including industrial, enterprise, and broadcast. It has approximately 6,700 employees, and has manufacturing capabilities in North America, South America, Europe, and Asia, and a market presence in nearly every region of the world. Belden was founded in 1902, and today is a leader with some of the strongest brands in the signal transmission industry. For more information, visit www.belden.com.

 

###

For more information, contact:

 

Joann Byres

VP and General Manager

Tofino Security
+1 250 984 4105
joann.byres@belden.com

Michelle Foster

Corporate Communications

Belden Inc.

314-854-8006

michelle.foster@belden.com

 

Belden, Belden Sending All The Right Signals, Tofino, Plug-n-Protect and the Belden logo are trademarks or registered trademarks of Belden Inc. or its affiliated companies in the United States and other jurisdictions. Belden and other parties may also have trademark rights in other terms used herein.

Related Links

Blog: SCADA Security: Welcome to the Patching Treadmill

SCADA honeypots attract swarm of international hackers

Vulnerable internet-facing industrial systems controlling crucial equipment used by power plants, airports, factories and other critical systems are subjected to sustained attacks within hours of appearing online, according to new honeypot-based research by Trend Micro.

The security weaknesses of SCADA (supervisory control and data acquisition) industrial control systems have been a major focus of interest in information security circles for the last three years or so thanks to Stuxnet, Duqu, and other similar noteworthy attacks.

Trend Micro threat researcher and SCADA security expert Kyle Wilhoit set out to look into this phenomenon in greater depth by setting up a internet-facing honeypot and record attempted attacks [1]. The honeypot architecture developed by Wilhoit directly mimics those of real industrial control systems and SCADA devices.

The researcher, who was once the lead incident handler and reverse engineer at a large energy company, focusing on ICS/SCADA security and persistent threats, created a total of three honeypots.

All three were internet-facing and used three different static IP addresses in different subnets scattered across the US. One honeypot featured a programmable logic controller (PLC) system running on a virtual instance of Ubuntu hosted on Amazon EC2, and configured as a web page that mimics that of a water pressure station. Another honeypot featured a web server that mimicked a control interface connected to a PLC production system. The final honeypot was an actual PLC device set up to mimic temperature controller systems in a factory.

All three honeypots included traditional vulnerabilities found across the same or similar systems. Steps were taken to make sure the honeypots were easily discovered. The sites were optimised for searches and published on Google.

The researchers also made sure that that honeypot settings would be seeded on devices that were part of HD Moore’s Shodan Project, which indexes vulnerable routers, printers, servers and internet-accessible industrial control systems. Once a search latches onto a vulnerable embedded device, then Metasploit provides a library of possible attacks, which - as security strategist Josh Corman points out [2] - can be run without any detailed knowledge or skill.

The Trend Micro security researchers excluded simple port scans and focused on recording anything that might pose a threat to internet-facing ICS/SCADA systems. This includes unauthorised access to secure areas of sites, attempted modifications of controllers, or any attack against a protocol specific to SCADA devices, such as Modbus/TCP.

They also logged any targeted attempt to gain access or take out servers running the system. Various tools including popular open-source intrusion detection package Snort, honeyd (modified to mimic common SCADA protocols), tcpdump and analysis of server log files were used to monitor and record the attacks the honeypots attracted.

Less than 24 hours later...

The researchers waited less than a day before the attacks began, as Wilhoit explains in a research paper Who’s Really Attacking Your ICS Equipment? (PDF [3]).

It took only 18 hours to find the first signs of attack on one of the honeypots. While the honeypots ran and continued to collect attack statistics, the findings concerning the deployments proved disturbing. The statistics of this report contain data for 28 days with a total of 39 attacks from 14 different countries. Out of these 39 attacks, 12 were unique and could be classified as “targeted” while 13 were repeated by several of the same actors over a period of several days and could be considered “targeted” and/or “automated.” All of these attacks were prefaced by port scans performed by the same IP address or an IP address in the same netback.

The attacks included attempts to spear-phish a site administrator, bids to exploit fundamental ICS protocols and malware exploitation attempts on the servers running the honeypot environment. Other hacks included bids to change the CPU fan speed on systems supposedly controlling a water pump and attempts to harvest systems information.

Four samples were collected over the four-week testing period, two of which have not been seen in the wild. Trend Micro is currently analysing these pieces of malware to determine their functionality. As well as looking at the type of attack getting thrown against the honeypot system, researchers at Trend Micro also looked at the origin of attempted attacks.

A third of attacks against the industrial control system honeypot (35 per cent) originated in China but one in five (19 per cent) originated in the US. Security researchers also found that a surprisingly high 12 per cent of attacks against a honeypot control system they had established came from the southeast Asian nation of Laos.


These systems used to be run from a single computer next to a conveyor belt

Wilhoit, presented his research at the BlackHat Europe conference in Amsterdam, the Netherlands last Friday.

“This Trend Micro research shows that attackers have enough knowledge to analyse and affect industrial control devices' infrastructures,” said Raimund Genes, CTO at Trend Micro. “This is a wake-up call for operators of these infrastructures to check the security of these systems and ensure they are properly separated from the internet/open networks. The research also shows that it is not only usual suspects attacking, but that these attacks also happen in your own backyard.”

SCADA systems control everything from escalators in metro stations in Madrid to milk-processing factories in Mali and uranium enrichment centrifuges in Iran.

"Security in an ICS/SCADA network is often considered 'bolt-on' or thought of 'after the fact'. When these systems were first brought into service more than 20 or so years ago, security was typically not a concern," Wilhoit explains.

"However, as things changed over time, most of these systems’ purposes have been reestablished, along with the way they were configured. A system that used to only be accessible to a single computer next to a conveyor belt became accessible via the internet, with very little hindrance."

Wilhoit called for further research into motives, sources and delivery techniques of the increasingly sophisticated attackers who target industrial control systems. "Internet-facing ICS are readily targeted," Wilhoit warns. "Until proper ICS security is implemented, these types of attack will likely become more prevalent and advanced or destructive in the coming years."

A recent study [4] by InfraCritical discovered that 500,000 SCADA (supervisory control and data acquisition) networks were susceptible to attack, highlighting the wide-scale vulnerability of systems that control the operations of power and water plants, among other critical facilities. According to recent research conducted by ICS-CERT, 171 unique vulnerabilities affecting 55 different ICS vendors were found last year alone (PDF [5]).

And patching of industrial control systems creates its own problems, according to a study [6] by Tofino Security published last week.

Eric Byres, CTO and vice president of engineering at Tofino Security, reckons there are as many as 1,805 as-yet-undiscovered vulnerabilities existing on control system computers.

IC systems need FREQUENT patches... but if they're buggy, it ALL falls apart

The frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers likely exceeds the tolerance of most SCADA operators for system shutdowns. Unlike IT systems, most industrial processes operate around the clock and demand high uptime. Weekly shutdowns for patching are unacceptable.

But even when patches can be installed, they can be problematic. According to Tofino Security, there is a one in 12 chance that any patch will affect the safety or reliability of a control system, and there is a 60 per cent failure rate in patches fixing the reported vulnerability in control system products. In addition, patches often require staff with special skills to be present. In many cases, such experts are often not certified for access to safety regulated industrial sites.

Tofino Security markets industrial network security and SCADA security products that protect industrial control systems from potential attack, even if they aren't patched, so it has a vested interest in talking up the problems of patching. However the overall picture of exposed and vulnerable industrial control systems is constant with findings from experts at Trend Micro and elsewhere.

A SCADA network ought to be segregated from a corporate intranet and air-gapped from the internet - or at least firewalled - but even rudimentary protections are often absent.

Sean McGurk, former head of cybersecurity for the US Department of Homeland Security turned managing principal for investigative response on Verizon’s RISK Team, told El Reg that attacks against the enterprise systems behind utilities are a bigger risk than Stuxnet-style attacks. The networks of both Saudi Aramco and Rasgas in Qatar were both hobbled by conventional malware attacks last year, for example. Both attacks were later linked [7] to the Shamoon data wiper.

Part of the problem is that industrial control systems have a far longer timeline than enterprise servers, computers and routers - typically up to 20 years instead of three to five years. And industrial control kit works with different ports and protocols than conventional enterprise networks, so simply adding a firewall or network segmentation is adequate as a defensive strategy. In addition, industrial control systems often have to work in real time, with low latency and high availability.

"Patching of legacy system is ongoing," McGurk said. "But patching is difficult for five-9s high-availability systems. Secure connectivity can be enhanced with layers of security but you can't gold-plate everything."

Despite the difficulties, McGurk suggested many in the sector are being slow to react to the security threat. The UK energy sector has been particularly slow to adopt security measures that match new technological developments, such as smart grids - potentially leaving them exposed to large-scale cyber-attacks as a result.

However he acknowledged that the technology was certainly not without its issues, such as potentially making it easier to disconnect the vulnerable or elderly, and no panacea.

"Introduce smart-grid technology is a double edged sword," McGurk explained. "Although you enhance interoperability, you can't just throw it in there.

"There's a greater security focus and it's not just about interoperability anymore," he concluded. McGurk said that government and industry need to work together to improve both the security and interoperability of the industrial control systems that monitor and manage power generation and distribution systems.

McGurk, who has more than 30 years of experience in ICS cybersecurity and critical infrastructure protection, traveled to London last week to speak at the European Smart Grid Cyber and SCADA Security Conference [8], a closed event restricted to industry participants and vendors. ®

Related stories