Slashdot Log In
Inside the Secret War Against Internet Spies
Posted by
Soulskill
on Thu Apr 10, 2008 07:07 PM
from the war-on-malware dept.
from the war-on-malware dept.
ahess247 brings us a lengthy BusinessWeek story on the increasing amount of attacks against the US government's online presence as well as its contacts in the private sector. Hackers are gaining a greater awareness of where valuable data might reside, and that awareness is leading to more precise, more sophisticated attacks. Quoting:
"The U.S. government, and its sprawl of defense contractors, have been the victims of an unprecedented rash of similar cyber attacks over the last two years, say current and former U.S. government officials. 'It's espionage on a massive scale,' says Paul B. Kurtz, a former high-ranking national security official. Government agencies reported 12,986 cyber security incidents to the U.S. Homeland Security Dept. last fiscal year, triple the number from two years earlier. Incursions on the military's networks were up 55% last year, says Lieutenant General Charles E. Croom, head of the Pentagon's Joint Task Force for Global Network Operations. Private targets like Booz Allen are just as vulnerable and pose just as much potential security risk. 'They have our information on their networks. They're building our weapon systems. You wouldn't want that in enemy hands,' Croom says. Cyber attackers 'are not denying, disrupting, or destroying operations--yet. But that doesn't mean they don't have the capability.'"
Related Stories
[+]
Your Rights Online: US Government to Have Only 50 Gateways 150 comments
Narrative Fallacy brings us a story about the US government's plan to reduce the roughly 4,000 active internet connections used by its civilian agencies to a mere 50 highly secure gateways. This comes as part of the government's response to a rise in attacks on its networks.
"Most security professionals agreed that the TIC security improvements and similar measures are long overdue. 'We should have done this five years ago, but there wasn't the heart or the will then like there is now,' said Howard Schmidt, a former White House cyber security adviser. 'The timetable is aggressive,' he said, but now there is a sense of urgency behind the program. Small agencies that won't qualify for their own connections under TIC must subcontract their Internet services to larger agencies."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
You PWN3D my Empire! (Score:5, Interesting)
Northrop-Grumman or General Dynamics or any D.o'D. approved private contractor can post anything they like about future combat systems on their websites, and even sell secret weapons systems to Saudis or the UAE or anyone else who can buy, but for anyone else to do it is an infringement of national security.
Also, the private contractors can preferentially hire non-nationals, who work diligently and are key to the development of these systems, instead of American citizens who might be disturbed at the nature of what the private contractors are doing in the name of national security, but that's the free market.
So, if I remember correctly, didn't something happen in Germany in the 1930s that caused its brightest physiscists to flee? And didn't the same imperial hubris that caused Germany to persecute the people who might have made it an economic power after WWI really cause it to enter- and lose- WWII?
Just askin'. I just wondered what the Party line was these days.
Re: (Score:3, Insightful)
Is there anyone dumb enough to still believe the romantic portrayal of the young valiant American heros defending liberty and freedom from the vicious hordes that everyone else refers to as "the rest of the world" ?
Re:You PWN3D my Empire! (Score:5, Insightful)
Yes. Products of the American "education" system.
Parent
Re: (Score:2, Insightful)
[citation needed]
I read the article quickly, and I did see that it describes attempts to penetrate US systems, from a US point of view. But I didn't happen to notice any editorializing about US nobility, or any suggestion of a lack of a US cyber warfare program.
Sure it wasn't in your head? Go ahead and criticize US policy. Criticize the article too, if you think it's poorly written. But you're criticizing the article based
Re: (Score:3, Insightful)
The FoxNews demographic. Earnest, well-intentioned, poorly-informed, misguided and wrong.
Re:You PWN3D my Empire! (Score:5, Insightful)
Parent
Re: (Score:3, Interesting)
Re: (Score:3, Insightful)
Oh, and the tone of your message is basically "Sure we killed millions of innocents and plundered natural wealth to which we had no legal or moral claim. But hey, at least our heart was in the right place!".
Re: (Score:3, Insightful)
Billions of dollars to buy their feudal allegiance - with goodwill as the PR story to sell Empire back home.
Um.....I think you are a bit confused about how feudalism works. You see the idea is the underling gives money and tribute to his feudal Lord. You don't buy feudal allegiance with money, you get it by promising not to destroy the country.
Maybe this is not what you meant. Maybe you picked the wrong words; but you will get a lot farther using words that represent what you actually mean rather than picking words that sound sensationalistic and are clearly an exaggeration.
America isn't perfect by any s
Re: (Score:3, Informative)
http://www.afcyber.af.mil/
You were being sarcastic, right?
For every defense... (Score:3, Insightful)
For every threat there is funding (Score:3, Insightful)
The end of the Cold War was a huge threat to careers and funding in the CIA, military and govt contractors. Need those Iraq wars, terrorists and hackers to keep the whole war machine going.
The military industry is not the only one that works this way. The medical industry is catching on too (bird flu) and now the whole greenwashing industry (global warming etc).
Spy vs. Spy (Score:5, Insightful)
Also, spies would rather have infrastructure INTACT, so they can exploit it easily. They are lazy humans, like you.
Re:Spy vs. Spy (Score:5, Funny)
Parent
Re:Spy vs. Spy (Score:5, Funny)
I could see him thinking about spies, and birds being like spies, and then screwing it up. What I find funnier is how many people will skim over that sentence really quickly and find it smart and intelligent sounding, while never really understanding what ornithology or ontology really is.
Parent
Re:Spy vs. Spy (Score:5, Interesting)
And just because we're worried about "internet spies" let's not forget that there are plenty of the old-fashioned variety out there, too.
For example, how many of us know that 15 Bush Administration officials, including Sec'y of State Condi Rice, have just been subpoenaed in the oft-delayed Franklin/AIPAC/Israel Lobby spy case. Even though it's common enough to come up in Google search auto-complete, it hasn't been mentioned on any US media.
The difference is now the people that are spying on us are employed by the ones that are supposed to be working to protect us.
And even if we caught every single spy, who among us feels we could trust our Department of Justice to prosecute them with any integrity? Hell, if there were any justice, the top law enforcement appointees (John Yoo, Alberto Gonzalez, Michael Mukasey, etc) not to mention their bosses, would be the ones facing trial.
Parent
Re: (Score:3, Interesting)
Not much of a secret anymore now is it? (Score:4, Insightful)
You shouldn't have military plans on the Net (Score:5, Informative)
The problem is that they're not even following their own rules - Win boxen have never been approved for holding Net-connected data - only in a stand-alone environment are they even considered, and even then in a secure room with full security protocols enforced.
We used to lock down our drives too. In locked cabinets. When we went home.
Re:You shouldn't have military plans on the Net (Score:4, Informative)
If the military was as susceptible as they might lead you to believe, they'd still be trying to stop spam emails from pouring out of the RNC servers. Holy shit man, if they were hackable someone on the NYT would already be posting the 'lost RNC emails' if you know what I mean... geez
Parent
So feed them some bum plans. (Score:5, Interesting)
Connection to other malware. (Score:4, Insightful)
We have a multibillion-dollar industry based on corrupting computers and stealing selected information from them, which the governments have virtually ignored while its techniques were honed. Now their own military secrets are the target of a similar attack. Any bets on whether it is built on the same code base.
Too late now, guys. The enemies' cyber-warfare departments now have the technology.
But I bet that, if you start finding and closing the barn doors even after most of the horses are gone, you'll find enough fingerprints and tire-tracks to trace down who did it. Hunt them down and take them out, and you'll eliminate a bunch of the talent that would otherwise be developing the technology further.
Color me underwhelmed. (Score:4, Insightful)
Western civilization was saved from the abyss.
Who doesn't think these things happen all of the time. I would be upset (in a general way) if our enemies didn't try that sort of stuff. And sneaking in via the side door. And the hot secretary. And countless other bits of espionage craft. Keep up the firewalls men! Loose lips sink ships. Watch them commies, you never know what to expect. Let's have another iPhone article, shall we. It's been maybe 24 hours since the last one. I'm getting bored.
Can anyone explain... (Score:2, Insightful)
Logistics is key, even in the cyber age (Score:3, Insightful)
Wasn't "The military marches on its stomach." some historical quote that was attributed to Napolean? Anyhow, where I'd keep an eye out for cyber vulnerabilities is in the logisitics chain. All it'd take is someone to get into the requisitions, inventory, and procurement channels and they could make all hell break loose. Frozen fish in the place of ammo, livestock sent to some other place, 100 screwdrivers and bomb fuses to an office that only does paperwork, etc. Not only can such things waste resources or man hours to correct, but it can cause negative economic consequences for contract vendors. Stupid shit like that could get old really fast.
Hopefully the military brass has enough sense to ensure strong verification when dealing with civilian contractors in the supply chain (and via internal supply channels). Also there should be some means to ensure the trustworthiness of supply contractors, as some purchase orders might have the possibility of indicating potential for action, etc.
On the other hand, this would potentially be a great way for the U.S. to attack any adversaries too. The more bureaucratic, thick, and mundane an organization is - the more opportunities for logistics data mayhem. False requests will tend to look more "reasonable" under such systems.