60-day Cyberspace Policy Review Released and the Crowd Falls Silent

Posted by Brett Hardin on 29th May 2009

Reading time: 2 – 3 minutes

60 day Cyberspace Policy Review Released and the Crowd Falls Silent

Image: Thomas Hawk

Today, the 60-day cyberspace policy review has been publicly released. Melissa Hathaway, the Cybersecurity Chief at the National Security Council, was in charge of leading the effort and was one of the keynote speakers at RSA.

Here are some of the main points of the document:

  • Establish a person in the White House who’s responsibility it is to report to the president on matters of cyber security (cyber czar position)
  • Review the laws and policies that are currently in place and issue more by tying the position into congress.
  • Increase public awareness about the risks of the Internet
  • Increase public education about how to be secure when conducting Internet activities.
  • Expand federal IT workforce (A.K.A. The government needs to pay more)
  • Executives need to be more aware of cybersecurity.
  • Government and Private Sector need to work together.
  • Laws regarding “collusion” need to be relaxed so that companies can work together more. (Scary Thought)
  • Work with International Governments to form jurisdiction lines.
  • Build a framework for incident response.
  • Enhance information sharing across government bodies for better incident response handling.
  • Improve Cybersecurity across all infrastructures

The policy review should upset anyone in security field. It points things out the obvious. I expect much more from our National Security Council. Metaphorically, this paper is like taking your car to a mechanic and asking for a full diagnostic for the health of your vehicle. After 2 weeks, you come back and the mechanic gives you a piece of paper with the phrase, “Your Car is Black.”

This review is a complete miss from a security standpoint. Hopefully, it will bring awareness to multiple parties on what needs to get done, but it doesn’t help to fix anything.

Government was designed to move slow. The founders of this country did not want the government to make any hasty decisions, hence bureaucratic red-tape. The Internet on the other hand is designed to move very fast. As soon as something becomes popular on the Internet, the next thing is being developed.

It is hard to comprehend a government body that would be able to keep pace with the Internet. In fact, as soon as the policy review was completed, the Internet has already changed.

29May

What Motivates Hackers?

Posted by Brett Hardin on 27th May 2009

Reading time: 4 – 6 minutes

Photo: Kristin Bradley

Photo: Kristin Bradley

Attackers are motivated by multiple factors. Previously, “experts” believed most attackers were social outcasts who were writing malicious software out of their parent’s basement. These attackers were not driven by any particular motive. They were more driven by the problem-solving aspect. They wanted to know if they could do it. This idea that attackers are socially inept kids based in the United States is quickly becoming inaccurate.

Most security articles are focused on the means of the attack. They don’t address what attackers are actually after.

The four motivating factors for attackers that have been identified are:

  1. Financial Gain
  2. Notoriety
  3. Political
  4. Vengeance

Financial Gain
Hacking, Malware, and Worm Creation is a money making opportunity. Worms, such as Conficker, are being tied to organized crime based in Soviet republics.

The tightly managed criminal organizations behind such scams—often based in Russia and former Soviet republics—treat malware like a business. They buy advanced code on the Internet’s black market, customize it, then sell or rent the resulting botnet to the highest bidders. They extend the worm’s life span as long as possible by investing in updates—maintenance by another name. This assembly line–style approach to crime works: of all the viruses that Symantec has tracked over the past 20 years, 60 percent of them have been introduced in the past 12 months.

This shouldn’t be surprising. If criminals have no problem killing another human and taking their wallet, why would they have problems stealing massive amounts of money electronically?

However, organized criminals aren’t the only attackers driven by financial gain. There is also evidence of financially driven attackers being petty criminals. These are the types that don’t have a great understanding of what they are doing. They can be found on websites specifically setup for trading credit card numbers or other Personally Identifiable Information (PII). Some researchers, such as Rios and Dhanjani, have done research into this subgroup. What Motivates Hackers?

Notoriety

There is still evidence of hacking for notoriety. Most of these attackers are the “13-19″ year old kids described above. The reason these individuals attack systems is driven by their want to become famous.

A recent example is the Mikeyy worm created by Michael Mooney of StalkDaily. This sub-group usually will justify their attacks by stating, “I wanted to bring awareness to the problem.” This is a constructed answer but demonstrates their want to become famous. They are clearly stating, they were the ones who wanted to bring awareness to the issue. These attackers typically have a Robin Hood type mentality of bringing knowledge to the uninformed.

Political
These attackers are politically focused or driven by political means. This group includes “hacktivists” and foreign nationals driven to cause damage to an enemy country. Examples of these attacks are the Titan Rain and more recently Power Grid hacking.

Political motivation is frightening. Many countries will not deter attackers from hacking a foreign country. In addition, law enforcement has a hard time tracking down or arresting these type of attackers due to the lack of cooperation of foreign countries.What Motivates Hackers?

Vengeance

These attackers are the most dangerous. They will attack people who have somehow made them upset. Their driving factor is causing as much pain as possible for their victim.

These attacks typically target an ex-girlfriend or a celebrity. These are the electronic equivalent of breaking someones windshield. There is nothing that can really be done to prevent it other than to stop using the Internet.

27May

How to Hack: Hacking by Numbers?!

Posted by Brett Hardin on 26th May 2009

Reading time: 1 – 2 minutes

Photo: stuartpilbrow

Photo: stuartpilbrow

A course will be offered this year at Black Hat entitled, “Hacking by Numbers: PCI Edition.” A quote from the appropriate literature:

The PCI Data Security Standard (DSS) has had a huge impact on the information security industry. One effect that it has had is to make annual penetration testing mandatory in some segments, and thereby spawn a whole new class of off-the-shelf penetration testers.

The term “off-the-shelf penetration testers” makes my stomach churn. It is my belief that hacking is more of an art than a science. Hacking is methodical, but takes a specific type of person to do it. Typical hackers are very methodical and analytic. In addition, ever hacker that I have ever met has a never-give-up mentality about them. This attribute is used as a feedback loop into the problem they are working on.

Sure some security work and/or security methodologies can be taught, but to be a “breaker” you have to have a certain personality type.

What are your thoughts on this? Feel free to tweet me about the topic. @miscsecurity

26May