Click here to close now.


Python Authors: XebiaLabs Blog, Hovhannes Avoyan, Carmen Gonzalez, Ignacio M. Llorente, Elizabeth White

Blog Feed Post

A Storify Dialog on Cyber Hurricane Katrina


Editor’s note: What follows is extracted from a storify post . This is a first post in this format for the CTOvision blog. Let us know what you think  on any aspect of this, including format in your browser, format in your newsletters and of course content- bg.

The Foreign Policy Research Institute recently held a webinar on Why “Cyber Pearl Harbor” Won’t Be Like Pearl Harbor At All…

I listened in.

First: I expressed some skepticism at the flashy premise of the webinar, as WWII metaphors are a tad overdone in security circles

The webinar opened with a lecture/powerpoint by Edward Turzanksi, whose name I finally got right on the 10th try. He started describing in some detail the different direct impacts of Pearl Harbor & 9/11, and of US immediate response…

…then immediately broke from the flashy title to point out that cyber is very different from conventional war.

The answer to why Cyber isn’t just signals intelligence? Cyber can directly attack infrastructure, not just communications.

a bit unfair of me here.^ Cyber attacks, as described for this presentation, have a political goal. Criminal networks don’t; disruptive though they may be, they are less about attacking states and instead focus on being left alone by them.

Using carpet bombing to describe cyber will always be a stretch, but the actual point of infrastructure being targeted at war holds.

the book described above? Unrestricted Warfare, published in 1999 but featuring a very misleading cover depicting the 9/11 attacks.

Of course, STUXNET itself played with gradual disruption, but the way this was described reminded me of nothing so much as this.

that clip? Children stomping bugs from Starship Troopers. Turzanski actually recommended stomping unknown flash drives as a way to stop them creating/exploiting vulnerabilities. I recommend we term this “boot-gapping.”

Shamoon was targeted specifically at Aramco, and was apparently the work of amateurs.

Husick addressed this later, noting that the invisible hand is really bad at addressing vulnerabilities present in the commons.

The actual problem here was not Windows software itself, which can update and be corrected, but that pirated/unlicensed Windows systems are paygapped from those updates despite those unauthorized copies being, according to Turzanski, 40% of operating systems. Here is a direct example of private sector poorly correcting a vulnerability opened up in the commons.

That above link is to a piece written for CTOVision, about how old-fashioned detective work, human intelligence, and boots on the ground caught a hacker who hid himself well online. Boots & detectives aren’t a quality we usually think of for countering cyber, but they absolutely should be.

The possibility of Estonia invoking NATO Article V for a cyber attack was brought up. Estonia has a stronger claim to this than most – incredibly tech-dependent and was clearly under a coordinated cyber attack. But incredibly unlikely anyone will start a shooting war over it, which calls into the question of cyberwar as a concept itself.

as a post-K New Orleans resident for four years, this metaphor seemed to match what I learned of people’s experience: misplaced investment, clear vulnerabilities shoved just a bit too hard, and then a long slow rebuilding in the directly-damaged area with unclear revision to response capability or actual resilience. A clear failure, but a contained failure.

That was not the actual answer. I paraphrased for space constraints, but the gist was the same.

Here an example was given of a 2003 rail failure, as one freight company linked it’s operational control computers to the internet proper and subsequently suffered a malware attack that left them blind, stranding all trains east of the Rockies for I believe he said 13 hours.

Redteaming: it works.

Maybe bootgapping is a viable strategy?Next we went to the Q & A, which was surprisingly infomative, despite it being a Q & A session.

Also mentioned in the response above was a modified nuke designed to EMP. Either would destroy solid-state drives, making it a destructive attack for which kinetics are a perfectly appropriate response, but also outside the realm of cyber security proper. This seems like the fundamental problem with terming Cyber things cyberwar – when they clearly cause war-like damage, that’s just war. When they don’t, they are crime or covert action. “Cyberwar” seems to be so thin a line that it is nonexistent.

Besides responding with overwhelming force, Farraday cages are a way to protect something from an EMP. Here’s instructions on a DIY version.

As a category, dark web is just what can’t be found conventionally online. In the above context, it refers to internet channels that won’t be effected if something like Google goes down.

The tragedy of the cyber commons was alluded to earlier – it makes little economic sense for anyone using the commons to devote resources to securing it from cyber attacks, and is especially unlikely for everyone to do so at once. (The second part of that tweet? Academia tangent: Mark Vail was a former professor of mine, whose work focused a lot on how European welfare states sought to solve the problems of the commons)

This lack of motivation to fix the problem is perhaps the best reason to start using “Cyber Hurricane Katrina” instead of “Cyber Pearl Harbor.”

It’s really, really hard to negotiate an arms treaty (of sorts) or a rule of battlefield ethics (which is what this would be) when the arms are rapidly evolving, can be designed and wielded by nonstate actors, and the actual battlespace is as broadly defined as any computer that could potentially be exposed to an attack. Compounding this are nations justifiably wanting to develop weapons in secret. My guess for a Cyber Geneva Convention? Only after a major problem reveals them to be both deadlier and less useful than anyone wants, like post-WWI chemical weapons.

Husick specifically mentioned that Saudi would label Pat Robertson’s website itself a work of cyber war. Layer that on top of the problems already expounded above, and Cyber Geneva Convention seems nigh-impossible.

Here we should be looking at cyber as covert action/spycraft/crime, where the channels of communication are important to maintain. The follow-up to this was that the US might expect cyber attacks on our allies, as China is less worried about severing economic ties with them. And, yes, the continued ability to steal US intellectual property was given as a reason for why China would not cyber-attack the US.

This led really well into the next point – STUXNET was able to disrupt Iranian centrifuges in a way that made Iran question it’s own equipment until they figured out, months and months and months later and after actually sitting around watching the centrifuges, that it was a virus at work.

Point referenced here is one from Gartenstein-Ross’s book Bin Laden’s Legacy, and very subtly illustrated by the burning dollar bill on the cover. An attack that yields a massively disproportionate expenditure in response is one that has succeeded in causing economic harm, whatever else it’s objective.

Read the original blog entry...

More Stories By Bob Gourley

Bob Gourley, former CTO of the Defense Intelligence Agency (DIA), is Founder and CTO of Crucial Point LLC, a technology research and advisory firm providing fact based technology reviews in support of venture capital, private equity and emerging technology firms. He has extensive industry experience in intelligence and security and was awarded an intelligence community meritorious achievement award by AFCEA in 2008, and has also been recognized as an Infoworld Top 25 CTO and as one of the most fascinating communicators in Government IT by GovFresh.

@ThingsExpo Stories
WebRTC converts the entire network into a ubiquitous communications cloud thereby connecting anytime, anywhere through any point. In his session at WebRTC Summit,, Mark Castleman, EIR at Bell Labs and Head of Future X Labs, will discuss how the transformational nature of communications is achieved through the democratizing force of WebRTC. WebRTC is doing for voice what HTML did for web content.
The buzz continues for cloud, data analytics and the Internet of Things (IoT) and their collective impact across all industries. But a new conversation is emerging - how do companies use industry disruption and technology enablers to lead in markets undergoing change, uncertainty and ambiguity? Organizations of all sizes need to evolve and transform, often under massive pressure, as industry lines blur and merge and traditional business models are assaulted and turned upside down. In this new data-driven world, marketplaces reign supreme while interoperability, APIs and applications deliver un...
Too often with compelling new technologies market participants become overly enamored with that attractiveness of the technology and neglect underlying business drivers. This tendency, what some call the “newest shiny object syndrome,” is understandable given that virtually all of us are heavily engaged in technology. But it is also mistaken. Without concrete business cases driving its deployment, IoT, like many other technologies before it, will fade into obscurity.
The IoT is upon us, but today’s databases, built on 30-year-old math, require multiple platforms to create a single solution. Data demands of the IoT require Big Data systems that can handle ingest, transactions and analytics concurrently adapting to varied situations as they occur, with speed at scale. In his session at @ThingsExpo, Chad Jones, chief strategy officer at Deep Information Sciences, will look differently at IoT data so enterprises can fully leverage their IoT potential. He’ll share tips on how to speed up business initiatives, harness Big Data and remain one step ahead by apply...
Today air travel is a minefield of delays, hassles and customer disappointment. Airlines struggle to revitalize the experience. GE and M2Mi will demonstrate practical examples of how IoT solutions are helping airlines bring back personalization, reduce trip time and improve reliability. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Dr. Sarah Cooper, M2Mi's VP Business Development and Engineering, will explore the IoT cloud-based platform technologies driving this change including privacy controls, data transparency and integration of real time context w...
The broad selection of hardware, the rapid evolution of operating systems and the time-to-market for mobile apps has been so rapid that new challenges for developers and engineers arise every day. Security, testing, hosting, and other metrics have to be considered through the process. In his session at Big Data Expo, Walter Maguire, Chief Field Technologist, HP Big Data Group, at Hewlett-Packard, will discuss the challenges faced by developers and a composite Big Data applications builder, focusing on how to help solve the problems that developers are continuously battling.
Nowadays, a large number of sensors and devices are connected to the network. Leading-edge IoT technologies integrate various types of sensor data to create a new value for several business decision scenarios. The transparent cloud is a model of a new IoT emergence service platform. Many service providers store and access various types of sensor data in order to create and find out new business values by integrating such data.
WebRTC services have already permeated corporate communications in the form of videoconferencing solutions. However, WebRTC has the potential of going beyond and catalyzing a new class of services providing more than calls with capabilities such as mass-scale real-time media broadcasting, enriched and augmented video, person-to-machine and machine-to-machine communications. In his session at @ThingsExpo, Luis Lopez, CEO of Kurento, will introduce the technologies required for implementing these ideas and some early experiments performed in the Kurento open source software community in areas ...
There are so many tools and techniques for data analytics that even for a data scientist the choices, possible systems, and even the types of data can be daunting. In his session at @ThingsExpo, Chris Harrold, Global CTO for Big Data Solutions for EMC Corporation, will show how to perform a simple, but meaningful analysis of social sentiment data using freely available tools that take only minutes to download and install. Participants will get the download information, scripts, and complete end-to-end walkthrough of the analysis from start to finish. Participants will also be given the pract...
The Internet of Things (IoT) is growing rapidly by extending current technologies, products and networks. By 2020, Cisco estimates there will be 50 billion connected devices. Gartner has forecast revenues of over $300 billion, just to IoT suppliers. Now is the time to figure out how you’ll make money – not just create innovative products. With hundreds of new products and companies jumping into the IoT fray every month, there’s no shortage of innovation. Despite this, McKinsey/VisionMobile data shows "less than 10 percent of IoT developers are making enough to support a reasonably sized team....
Internet of Things (IoT) will be a hybrid ecosystem of diverse devices and sensors collaborating with operational and enterprise systems to create the next big application. In their session at @ThingsExpo, Bramh Gupta, founder and CEO of, and Fred Yatzeck, principal architect leading product development at, discussed how choosing the right middleware and integration strategy from the get-go will enable IoT solution developers to adapt and grow with the industry, while at the same time reduce Time to Market (TTM) by using plug and play capabilities offered by a robust IoT ...
Today’s connected world is moving from devices towards things, what this means is that by using increasingly low cost sensors embedded in devices we can create many new use cases. These span across use cases in cities, vehicles, home, offices, factories, retail environments, worksites, health, logistics, and health. These use cases rely on ubiquitous connectivity and generate massive amounts of data at scale. These technologies enable new business opportunities, ways to optimize and automate, along with new ways to engage with users.
“In the past year we've seen a lot of stabilization of WebRTC. You can now use it in production with a far greater degree of certainty. A lot of the real developments in the past year have been in things like the data channel, which will enable a whole new type of application," explained Peter Dunkley, Technical Director at Acision, in this interview at @ThingsExpo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
Through WebRTC, audio and video communications are being embedded more easily than ever into applications, helping carriers, enterprises and independent software vendors deliver greater functionality to their end users. With today’s business world increasingly focused on outcomes, users’ growing calls for ease of use, and businesses craving smarter, tighter integration, what’s the next step in delivering a richer, more immersive experience? That richer, more fully integrated experience comes about through a Communications Platform as a Service which allows for messaging, screen sharing, video...
SYS-CON Events announced today that Dyn, the worldwide leader in Internet Performance, will exhibit at SYS-CON's 17th International Cloud Expo®, which will take place on November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Dyn is a cloud-based Internet Performance company. Dyn helps companies monitor, control, and optimize online infrastructure for an exceptional end-user experience. Through a world-class network and unrivaled, objective intelligence into Internet conditions, Dyn ensures traffic gets delivered faster, safer, and more reliably than ever.
The IoT market is on track to hit $7.1 trillion in 2020. The reality is that only a handful of companies are ready for this massive demand. There are a lot of barriers, paint points, traps, and hidden roadblocks. How can we deal with these issues and challenges? The paradigm has changed. Old-style ad-hoc trial-and-error ways will certainly lead you to the dead end. What is mandatory is an overarching and adaptive approach to effectively handle the rapid changes and exponential growth.
Mobile messaging has been a popular communication channel for more than 20 years. Finnish engineer Matti Makkonen invented the idea for SMS (Short Message Service) in 1984, making his vision a reality on December 3, 1992 by sending the first message ("Happy Christmas") from a PC to a cell phone. Since then, the technology has evolved immensely, from both a technology standpoint, and in our everyday uses for it. Originally used for person-to-person (P2P) communication, i.e., Sally sends a text message to Betty – mobile messaging now offers tremendous value to businesses for customer and empl...
Can call centers hang up the phones for good? Intuitive Solutions did. WebRTC enabled this contact center provider to eliminate antiquated telephony and desktop phone infrastructure with a pure web-based solution, allowing them to expand beyond brick-and-mortar confines to a home-based agent model. It also ensured scalability and better service for customers, including MUY! Companies, one of the country's largest franchise restaurant companies with 232 Pizza Hut locations. This is one example of WebRTC adoption today, but the potential is limitless when powered by IoT.
You have your devices and your data, but what about the rest of your Internet of Things story? Two popular classes of technologies that nicely handle the Big Data analytics for Internet of Things are Apache Hadoop and NoSQL. Hadoop is designed for parallelizing analytical work across many servers and is ideal for the massive data volumes you create with IoT devices. NoSQL databases such as Apache HBase are ideal for storing and retrieving IoT data as “time series data.”
Clearly the way forward is to move to cloud be it bare metal, VMs or containers. One aspect of the current public clouds that is slowing this cloud migration is cloud lock-in. Every cloud vendor is trying to make it very difficult to move out once a customer has chosen their cloud. In his session at 17th Cloud Expo, Naveen Nimmu, CEO of Clouber, Inc., will advocate that making the inter-cloud migration as simple as changing airlines would help the entire industry to quickly adopt the cloud without worrying about any lock-in fears. In fact by having standard APIs for IaaS would help PaaS expl...