Welcome!

Python Authors: Donald Meyer, AppDynamics Blog, Elizabeth White, XebiaLabs Blog, Hovhannes Avoyan

Blog Feed Post

A Storify Dialog on Cyber Hurricane Katrina

By

Editor’s note: What follows is extracted from a storify post . This is a first post in this format for the CTOvision blog. Let us know what you think  on any aspect of this, including format in your browser, format in your newsletters and of course content- bg.

The Foreign Policy Research Institute recently held a webinar on Why “Cyber Pearl Harbor” Won’t Be Like Pearl Harbor At All…

I listened in.

First: I expressed some skepticism at the flashy premise of the webinar, as WWII metaphors are a tad overdone in security circles

The webinar opened with a lecture/powerpoint by Edward Turzanksi, whose name I finally got right on the 10th try. He started describing in some detail the different direct impacts of Pearl Harbor & 9/11, and of US immediate response…

…then immediately broke from the flashy title to point out that cyber is very different from conventional war.

The answer to why Cyber isn’t just signals intelligence? Cyber can directly attack infrastructure, not just communications.

a bit unfair of me here.^ Cyber attacks, as described for this presentation, have a political goal. Criminal networks don’t; disruptive though they may be, they are less about attacking states and instead focus on being left alone by them.

Using carpet bombing to describe cyber will always be a stretch, but the actual point of infrastructure being targeted at war holds.

the book described above? Unrestricted Warfare, published in 1999 but featuring a very misleading cover depicting the 9/11 attacks.

Of course, STUXNET itself played with gradual disruption, but the way this was described reminded me of nothing so much as this.

that clip? Children stomping bugs from Starship Troopers. Turzanski actually recommended stomping unknown flash drives as a way to stop them creating/exploiting vulnerabilities. I recommend we term this “boot-gapping.”

Shamoon was targeted specifically at Aramco, and was apparently the work of amateurs.

Husick addressed this later, noting that the invisible hand is really bad at addressing vulnerabilities present in the commons.

The actual problem here was not Windows software itself, which can update and be corrected, but that pirated/unlicensed Windows systems are paygapped from those updates despite those unauthorized copies being, according to Turzanski, 40% of operating systems. Here is a direct example of private sector poorly correcting a vulnerability opened up in the commons.

That above link is to a piece written for CTOVision, about how old-fashioned detective work, human intelligence, and boots on the ground caught a hacker who hid himself well online. Boots & detectives aren’t a quality we usually think of for countering cyber, but they absolutely should be.

The possibility of Estonia invoking NATO Article V for a cyber attack was brought up. Estonia has a stronger claim to this than most – incredibly tech-dependent and was clearly under a coordinated cyber attack. But incredibly unlikely anyone will start a shooting war over it, which calls into the question of cyberwar as a concept itself.

as a post-K New Orleans resident for four years, this metaphor seemed to match what I learned of people’s experience: misplaced investment, clear vulnerabilities shoved just a bit too hard, and then a long slow rebuilding in the directly-damaged area with unclear revision to response capability or actual resilience. A clear failure, but a contained failure.

That was not the actual answer. I paraphrased for space constraints, but the gist was the same.

Here an example was given of a 2003 rail failure, as one freight company linked it’s operational control computers to the internet proper and subsequently suffered a malware attack that left them blind, stranding all trains east of the Rockies for I believe he said 13 hours.

Redteaming: it works.

Maybe bootgapping is a viable strategy?Next we went to the Q & A, which was surprisingly infomative, despite it being a Q & A session.

Also mentioned in the response above was a modified nuke designed to EMP. Either would destroy solid-state drives, making it a destructive attack for which kinetics are a perfectly appropriate response, but also outside the realm of cyber security proper. This seems like the fundamental problem with terming Cyber things cyberwar – when they clearly cause war-like damage, that’s just war. When they don’t, they are crime or covert action. “Cyberwar” seems to be so thin a line that it is nonexistent.

Besides responding with overwhelming force, Farraday cages are a way to protect something from an EMP. Here’s instructions on a DIY version.

As a category, dark web is just what can’t be found conventionally online. In the above context, it refers to internet channels that won’t be effected if something like Google goes down.

The tragedy of the cyber commons was alluded to earlier – it makes little economic sense for anyone using the commons to devote resources to securing it from cyber attacks, and is especially unlikely for everyone to do so at once. (The second part of that tweet? Academia tangent: Mark Vail was a former professor of mine, whose work focused a lot on how European welfare states sought to solve the problems of the commons)

This lack of motivation to fix the problem is perhaps the best reason to start using “Cyber Hurricane Katrina” instead of “Cyber Pearl Harbor.”

It’s really, really hard to negotiate an arms treaty (of sorts) or a rule of battlefield ethics (which is what this would be) when the arms are rapidly evolving, can be designed and wielded by nonstate actors, and the actual battlespace is as broadly defined as any computer that could potentially be exposed to an attack. Compounding this are nations justifiably wanting to develop weapons in secret. My guess for a Cyber Geneva Convention? Only after a major problem reveals them to be both deadlier and less useful than anyone wants, like post-WWI chemical weapons.

Husick specifically mentioned that Saudi would label Pat Robertson’s website itself a work of cyber war. Layer that on top of the problems already expounded above, and Cyber Geneva Convention seems nigh-impossible.

Here we should be looking at cyber as covert action/spycraft/crime, where the channels of communication are important to maintain. The follow-up to this was that the US might expect cyber attacks on our allies, as China is less worried about severing economic ties with them. And, yes, the continued ability to steal US intellectual property was given as a reason for why China would not cyber-attack the US.

This led really well into the next point – STUXNET was able to disrupt Iranian centrifuges in a way that made Iran question it’s own equipment until they figured out, months and months and months later and after actually sitting around watching the centrifuges, that it was a virus at work.

Point referenced here is one from Gartenstein-Ross’s book Bin Laden’s Legacy, and very subtly illustrated by the burning dollar bill on the cover. An attack that yields a massively disproportionate expenditure in response is one that has succeeded in causing economic harm, whatever else it’s objective.

Read the original blog entry...

More Stories By Bob Gourley

Bob Gourley writes on enterprise IT. He is a founder and partner at Cognitio Corp and publsher of CTOvision.com

@ThingsExpo Stories
SYS-CON Events announced today that MobiDev will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex software systems for startups and enterprises. Since 2009 it has grown from a small group of passionate engineers and business managers to a full-scale mobile software company with over 200 develope...
SoftLayer operates a global cloud infrastructure platform built for Internet scale. With a global footprint of data centers and network points of presence, SoftLayer provides infrastructure as a service to leading-edge customers ranging from Web startups to global enterprises. SoftLayer's modular architecture, full-featured API, and sophisticated automation provide unparalleled performance and control. Its flexible unified platform seamlessly spans physical and virtual devices linked via a world...
SYS-CON Events announced today that Alert Logic, Inc., the leading provider of Security-as-a-Service solutions for the cloud, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Alert Logic, Inc., provides Security-as-a-Service for on-premises, cloud, and hybrid infrastructures, delivering deep security insight and continuous protection for customers at a lower cost than traditional security solutions. Ful...
Companies can harness IoT and predictive analytics to sustain business continuity; predict and manage site performance during emergencies; minimize expensive reactive maintenance; and forecast equipment and maintenance budgets and expenditures. Providing cost-effective, uninterrupted service is challenging, particularly for organizations with geographically dispersed operations.
As cloud and storage projections continue to rise, the number of organizations moving to the cloud is escalating and it is clear cloud storage is here to stay. However, is it secure? Data is the lifeblood for government entities, countries, cloud service providers and enterprises alike and losing or exposing that data can have disastrous results. There are new concepts for data storage on the horizon that will deliver secure solutions for storing and moving sensitive data around the world. ...
SYS-CON Events announced today TechTarget has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. TechTarget is the Web’s leading destination for serious technology buyers researching and making enterprise technology decisions. Its extensive global networ...
The IoTs will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, will demonstrate how to move beyond today's coding paradigm and share the must-have mindsets for removing complexity from the development proc...
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management...
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. MangoApps provides modern company intranets and team collaboration software, allowing workers to stay connected and productive from anywhere in the world and from any device. For more information, please visit https://www.mangoapps.com/.
The essence of data analysis involves setting up data pipelines that consist of several operations that are chained together – starting from data collection, data quality checks, data integration, data analysis and data visualization (including the setting up of interaction paths in that visualization). In our opinion, the challenges stem from the technology diversity at each stage of the data pipeline as well as the lack of process around the analysis.
Designing IoT applications is complex, but deploying them in a scalable fashion is even more complex. A scalable, API first IaaS cloud is a good start, but in order to understand the various components specific to deploying IoT applications, one needs to understand the architecture of these applications and figure out how to scale these components independently. In his session at @ThingsExpo, Nara Rajagopalan is CEO of Accelerite, will discuss the fundamental architecture of IoT applications, ...
SYS-CON Events announced today that Tintri Inc., a leading producer of VM-aware storage (VAS) for virtualization and cloud environments, will exhibit at the 18th International CloudExpo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, New York, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
In his session at 18th Cloud Expo, Bruce Swann, Senior Product Marketing Manager at Adobe, will discuss how the Adobe Marketing Cloud can help marketers embrace opportunities for personalized, relevant and real-time customer engagement across offline (direct mail, point of sale, call center) and digital (email, website, SMS, mobile apps, social networks, connected objects). Bruce Swann has more than 15 years of experience working with digital marketing disciplines like web analytics, social med...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, wh...
SYS-CON Events announced today that EastBanc Technologies will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. EastBanc Technologies has been working at the frontier of technology since 1999. Today, the firm provides full-lifecycle software development delivering flexible technology solutions that seamlessly integrate with existing systems – whether on premise or cloud. EastBanc Technologies partners with p...
SYS-CON Events announced today BZ Media LLC has been named “Media Sponsor” of SYS-CON's 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. BZ Media LLC is a high-tech media company that produces technical conferences and expositions, and publishes a magazine, newsletters and websites in the software development, SharePoint, mobile development and Commercial Drone markets.
SYS-CON Events announced today that ContentMX, the marketing technology and services company with a singular mission to increase engagement and drive more conversations for enterprise, channel and SMB technology marketers, has been named “Sponsor & Exhibitor Lounge Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York City, New York. “CloudExpo is a great opportunity to start a conversation with new prospects, but what happens after the...
WebRTC is bringing significant change to the communications landscape that will bridge the worlds of web and telephony, making the Internet the new standard for communications. Cloud9 took the road less traveled and used WebRTC to create a downloadable enterprise-grade communications platform that is changing the communication dynamic in the financial sector. In his session at @ThingsExpo, Leo Papadopoulos, CTO of Cloud9, will discuss the importance of WebRTC and how it enables companies to fo...
The IoT is changing the way enterprises conduct business. In his session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, discuss how businesses can gain an edge over competitors by empowering consumers to take control through IoT. We'll cite examples such as a Washington, D.C.-based sports club that leveraged IoT and the cloud to develop a comprehensive booking system. He'll also highlight how IoT can revitalize and restore outdated business models, making them profitable...
IoT generates lots of temporal data. But how do you unlock its value? How do you coordinate the diverse moving parts that must come together when developing your IoT product? What are the key challenges addressed by Data as a Service? How does cloud computing underlie and connect the notions of Digital and DevOps What is the impact of the API economy? What is the business imperative for Cognitive Computing? Get all these questions and hundreds more like them answered at the 18th Cloud Expo...