http://www.latimes.com/news/nationworld/nation/la-na-cyber-war-20110328,0,17
54694,full.story 


Virtual war a real threat


The U.S. is vulnerable to a cyber attack, with its electrical grids,
pipelines, chemical plants and other infrastructure designed without
security in mind. Some say not enough is being done to protect the country.


 

Marc Maiffret in 2009. He recently exposed weaknesses in a Southern
California water system. Such vulnerabilities exist in crucial facilities
nationwide, U.S. officials say. (Barbara Davidson / Los Angeles Times)

By Ken Dilanian, Washington Bureau 

March 28, 2011

Reporting from Washington- 

When a large Southern California water system wanted to probe the
vulnerabilities of its computer networks, it hired Los Angeles-based hacker
Marc Maiffret to test them. His team seized control of the equipment that
added chemical treatments to drinking water - in one day.

The weak link: County employees had been logging into the network through
their home computers, leaving a gaping security hole. Officials of the urban
water system told Maiffret that with a few mouse clicks, he could have
rendered the water undrinkable for millions of homes.

"There's always a way in," said Maiffret, who declined to identify the water
system for its own protection.

The weaknesses that he found in California exist in crucial facilities
nationwide, U.S. officials and private experts say.

The same industrial control systems Maiffret's team was able to commandeer
also run electrical grids, pipelines, chemical plants and other
infrastructure. Those systems, many designed without security in mind, are
vulnerable to cyber attacks that have the potential to blow up city blocks,
erase bank data, crash planes and cut power to large sections of the
country.

Terrorist groups such as Al Qaeda don't yet have the capability to mount
such attacks, experts say, but potential adversaries such as China
<http://www.latimes.com/topic/intl/china-PLGEO00000014.topic>  and Russia
do, as do organized crime and hacker groups that could sell their services
to rogue states or terrorists.

U.S. officials say China already has laced the U.S. power grid and other
systems with hidden malware that could be activated to devastating effect.

"If a sector of the country's power grid were taken down, it's not only
going to be damaging to our economy, but people are going to die," said Rep.
Jim Langevin (D-R.I.), who has played a lead role on cyber security as a
member of the House Intelligence Committee.

Some experts suspect that the U.S. and its allies also have been busy
developing offensive cyber capabilities. Last year, Stuxnet
<http://www.latimes.com/topic/crime-law-justice/crimes/computer-crime/stuxne
t-virus-EVSAT00002.topic> , a computer worm some believe was created by the
U.S. or Israel, is thought to have damaged many of Iran's
<http://www.latimes.com/topic/intl/iran-PLGEO0000011.topic>  uranium
centrifuges by causing them to spin at irregular speeds.

In the face of the growing threats, the Obama
<http://www.latimes.com/topic/politics/government/barack-obama-PEPLT007408.t
opic>  administration's response has received mixed reviews.

President Obama declared in a 2009 speech that protecting computer network
infrastructure "will be a national security priority." But the
follow-through has been scant.

Obama created the position of federal cyber-security "czar," and then took
seven months to fill a job that lacks much real authority. Several
cyber-security proposals are pending in Congress, but the administration
hasn't said publicly what it supports.

"I give the administration high marks for doing some things, but clearly not
enough," Langevin said.

The basic roadblocks are that the government lacks the authority to force
industry to secure its networks and industry doesn't have the incentive to
do so on its own.

Meanwhile, evidence mounts on the damage a cyber attack could inflict. In a
2006 U.S. government experiment, hackers were able to remotely destroy a
27-ton, $1-million electric generator similar to the kind commonly used on
the nation's power grid. A video shows it spinning out of control until it
shuts down.

In 2008, U.S. military
<http://www.latimes.com/topic/unrest-conflicts-war/defense/u.s.-military-ORG
OV000021106.topic>  officials discovered that classified networks at the
U.S. Central Command, which oversees military operations in the Middle East
and Central Asia, had been penetrated by a foreign intelligence service
using malware spread through thumb drives.

That attack led to the creation in 2009 of U.S. Cyber Command, a group of
1,000 spies and hackers charged with preventing such intrusions. They also
are responsible for mounting offensive cyber operations, about which the
government will say next to nothing.

The head of Cyber Command, Gen. Keith Alexander
<http://www.latimes.com/topic/sports/keith-alexander-PESPT000091.topic> ,
also leads the National Security Agency
<http://www.latimes.com/topic/politics/defense/security-measures/national-se
curity-agency-ORGOV0000104.topic> , the massive Ft. Meade
<http://www.latimes.com/topic/unrest-conflicts-war/fort-meade-%28military-ba
se%29-ORGOV000090.topic> , Md.-based spy agency in charge of listening to
communications and penetrating foreign computer networks.

Together, the NSA and Cyber Command have the world's most advanced
capabilities, analysts say, and could wreak havoc on the networks of any
country that attacked the U.S. - if they could be sure who was responsible.

It's easy to hide the source of a cyber attack by sending the malware on
circuitous routes through computers and servers in third countries. So
deterrence of the sort relied upon to prevent nuclear war - the threat of
massive retaliation - is not an effective strategy to prevent a cyber
attack.

Asked in a recent interview whether the U.S. could win a cyber war,
Alexander responded, "I believe that we would suffer tremendously if a cyber
war were conducted today, as would our adversaries."

Alexander also is quick to point out that his cyber warriors and experts are
legally authorized to protect only military networks. The Department of
Homeland Security
<http://www.latimes.com/topic/unrest-conflicts-war/defense/u.s.-department-o
f-homeland-security-ORGOV0000136.topic>  is charged with helping secure
crucial civilian infrastructure, but in practice, the job mostly falls to
the companies themselves.

That would've been akin to telling the head of U.S. Steel in the 1950s to
develop his own air defenses against Soviet bombers, writes Richard Clarke,
who was President George W. Bush
<http://www.latimes.com/topic/politics/government/presidents-of-the-united-s
tates/george-bush-PEPLT000857.topic> 's cyber-security advisor, in his 2010
book, "Cyber War: The Next Threat to National Security and What to Do About
It."

The comparison underscores the extent to which the U.S. lacks the laws,
strategies and policies needed to secure its cyber infrastructure, experts
say.

"If we don't get our act together, the consequences could be dire," said
Scott Borg, who heads the U.S. Cyber Consequences Unit, which analyzes the
potential damage from various scenarios.

The problem, though, is "there's nothing that everyone agrees on," said
James Lewis
<http://www.latimes.com/topic/politics/james-lewis-PEPLT003909.topic> ,
cyber-security expert at the Center for Strategic and International Studies
in Washington.

For example, Lewis and other experts believe the government should mandate
cyber-security standards for water systems, electric utilities and other
crucial infrastructure. Some contend that major U.S. Internet service
providers should be required to monitor patterns in Internet traffic and
stop malware as it transits their servers.

But both ideas are viewed with suspicion by a technology industry that wants
the government out of its business, and by an Internet culture that sees
such moves as undermining privacy.

"There are a whole lot of things that can't be legislated," said Bob Dix,
vice president of government affairs for Sunnyvale, Calif.-based Juniper
Networks Inc.
<http://www.latimes.com/topic/economy-business-finance/juniper-networks-inco
rporated-ORCRP008517.topic> , which makes routers and switches.

Yet Washington may be reaching a moment when the seriousness of the threat
trumps political resistance. Sources familiar with the negotiations say the
White House
<http://www.latimes.com/topic/politics/government/executive-branch/white-hou
se-PLCUL000110.topic>  has promised Senate leaders that it will offer its
own cyber-security legislation in a month. But any proposal that calls for
far-reaching regulations would face an uphill battle.

CIA
<http://www.latimes.com/topic/politics/espionage-intelligence/cia-ORGOV00000
9.topic>  Director Leon E. Panetta told Congress recently that he worried
about a cyber Pearl Harbor. Yet many who follow the issue believe that's
what it will take to force Americans to awaken to the threat.

"The odds are we'll wait for a catastrophic event," said Mike McConnell,
former director of National Intelligence and cyber-security specialist, "and
then overreact."

[email protected] 

 

 
<http://www.latimes.com/news/nationworld/nation/la-na-cyber-war-20110328,0,1
754694,full.story> 


 

 



[Non-text portions of this message have been removed]



------------------------------------

--------------------------
Want to discuss this topic?  Head on over to our discussion list, 
[email protected].
--------------------------
Brooks Isoldi, editor
[email protected]

http://www.intellnet.org

  Post message: [email protected]
  Subscribe:    [email protected]
  Unsubscribe:  [email protected]


*** FAIR USE NOTICE. This message contains copyrighted material whose use has 
not been specifically authorized by the copyright owner. OSINT, as a part of 
The Intelligence Network, is making it available without profit to OSINT 
YahooGroups members who have expressed a prior interest in receiving the 
included information in their efforts to advance the understanding of 
intelligence and law enforcement organizations, their activities, methods, 
techniques, human rights, civil liberties, social justice and other 
intelligence related issues, for non-profit research and educational purposes 
only. We believe that this constitutes a 'fair use' of the copyrighted material 
as provided for in section 107 of the U.S. Copyright Law. If you wish to use 
this copyrighted material for purposes of your own that go beyond 'fair use,' 
you must obtain permission from the copyright owner.
For more information go to:
http://www.law.cornell.edu/uscode/17/107.shtmlYahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/osint/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/osint/join
    (Yahoo! ID required)

<*> To change settings via email:
    [email protected] 
    [email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/

Reply via email to