<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Advancements at the Monastery &#187; DDOS</title>
	<atom:link href="http://blog.securitymonks.com/category/ddos/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.securitymonks.com</link>
	<description>Information about developments at the Monastery</description>
	<lastBuildDate>Fri, 03 Sep 2010 05:41:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Unclear and Present Danger</title>
		<link>http://blog.securitymonks.com/2008/05/28/unclear-and-present-danger/</link>
		<comments>http://blog.securitymonks.com/2008/05/28/unclear-and-present-danger/#comments</comments>
		<pubDate>Thu, 29 May 2008 05:08:15 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[DDOS]]></category>
		<category><![CDATA[International]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/?p=159</guid>
		<description><![CDATA[Col. Charles W. Williamson III in his post &#8220;Carpet bombing in cyberspace: Why America needs a military botnet&#8221; ran into trouble with the security community when he stated, &#8220;America needs a network that can project power by building an af.mil robot network (botnet) that can direct such massive amounts of traffic to target computers that [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://aproposofnothing.files.wordpress.com/2007/11/deception.jpg" alt="Deception" align="left" width=275 />Col. Charles W. Williamson III in his post &#8220;<a href="http://www.armedforcesjournal.com/2008/05/3375884">Carpet bombing in cyberspace: Why America needs a military botnet</a>&#8221; ran into trouble with the security community when he stated, &#8220;<em>America needs a network that can project power by building an af.mil robot network (botnet) that can direct such massive amounts of traffic to target computers that they can no longer communicate and become no more useful to our adversaries than hunks of metal and plastic</em>.&#8221;  Richard Bejtlich&#8217;s post, &#8220;<a href="http://taosecurity.blogspot.com/2008/05/mutually-assured-ddos.html">Mutually Assured DDoS</a>&#8221; points out several of the problems with a af.mil robot network.  Sean Sullivan from F-Secure also did a thoughtful response titled &#8220;<a href="http://www.f-secure.com/weblog/archives/00001434.html">US Air Force Colonel Proposes Skynet</a>.&#8221;  I will leave it to the reader to head over to Williamson&#8217;s, Bejtlich&#8217;s, and Sullivan&#8217;s blogs and form their own opinions.</p>
<p>
In the end, an effective <a href="http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci557336,00.html">Distributed Denial of Service</a> (<strong>DDoS</strong>) attack will likely be done in a manner making it difficult to block the involved IPs without shutting down services to the victim&#8217;s customers.  In cyberspace, attackers do not wear uniforms, nor do they necessarily come from a particular domain.  It is not so easy to identifying the enemy.  The intelligent attacker makes all effort to blend into the population.
</p>
<p>
With that in mind, I wanted to post some sites that can help identify from where attacks might originate.  Please do remember that IPs used in an attack do not necessarily identify who is behind the attacks.  </p>
<h3>Overview</h3>
<p>I agree with Col. Charles W. Williamson III that that cyberspace is a dangerous place.  The idea of going on the offensive and striking back is appealing.  Since early childhood, I can remember my dad always saying, &#8220;<em>The best defense is  a good offense</em>.&#8221;  The problem with a offensive military botnet is that it will run into problems when it comes to locating the base of the enemy.  To understand why this is the case, we will start by defining some of the favorite cyberspace weapons used by the bad guys.  We will then examine the countries where attacks are occurring.  Sources of publish information will be examined, which should help the reader continuously monitor activities in their network.   We will end by discussing Carnegie Mellon&#8217;s attempt to establish international communication and coordination.</p>
<h3>Definitions</h3>
<p>Let us defines a few of the favorite tools being used in carrying out attacks in cyberspace.  </p>
<h4><strong>Malware</strong></h4>
<p>Malware is short for short for <strong>mal</strong>icious soft<strong>ware</strong>.  It is any software written for malicious reasons that infiltrates or damage a computer without authorization.  Some common malware types are <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521">trojans</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540">worms</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540474">viruses</a>, <a href="http://en.wikipedia.org/wiki/Internet_bot">bots</a>, <a href="http://en.wikipedia.org/wiki/Rootkit">rootkits</a>, and <a href="http://en.wikipedia.org/wiki/Spyware">spyware</a>/<a href="http://en.wikipedia.org/wiki/Adware">adware</a>.  Below are definitions taken from the links above.</p>
<ul>
<li><strong>Trojan</strong> &#8211; a package <u>disguised as something useful or popular</u>, but actually carrying a malicious payload that will damage the victim machines or threaten data integrity, or impair the functioning of the victim machine.  Trojans can be classified according to the actions which they carry out on victim machines: <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#back">backdoors</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#psw">PSW trojans</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#clickers">trojan clickers</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#downloaders">trojan downloaders</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#droppers">trojan droppers</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#proxies">trojan proxies</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#spies">trojan spies</a>, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#notifiers">trojan notifiers</a>, and <a href="http://www.viruslist.com/en/virusesdescribed?chapter=152540521#arch">arcbombs</a>.  </li>
<li><strong>Virus</strong> &#8211; will <u>attach itself to a program or file</u> so it can spread from one computer to another, leaving infections as it travels.  Viruses can be classified according to their environment and infection methods, such as <a href="http://www.viruslist.com/en/virusesdescribed?chapter=153313420">file</a> viruses, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=153313420">boot sector</a> viruses, <a href="http://www.viruslist.com/en/virusesdescribed?chapter=153313603">macro</a> viruses, and <a href="http://www.viruslist.com/en/virusesdescribed?chapter=153313914">script</a> viruses.</li>
<li><strong>Worm</strong> &#8211; are considered a <u>subclass of virus</u> and take advantage of file or information transport features on systems allowing it to <u>travel unaided</u>.  Worms includes programs that propagate via LANs or the Internet with the objective to penetrating remote machines, launching copies on victim machines, and spreading further to new machines.  The key difference to a trojan is that worms can propagate on their own.  They self-copy and infect other machines through penetrate and infect purely through vulnerabilities that are inherent to the system itself.  No human intervention is required.</li>
<li><strong>Rootkit</strong> &#8211; a program (or combination of several programs) designed to take fundamental control (in Unix terms &#8220;root&#8221; access, in Windows terms &#8220;Administrator&#8221; access) of a computer system, without authorization by the system&#8217;s owners and legitimate managers.</li>
<li><strong>Spyware</strong> &#8211; is computer software that is installed surreptitiously on a personal computer to intercept or take partial control over the user&#8217;s interaction with the computer, without the user&#8217;s informed consent.</li>
<li><strong>Adware </strong>- advertising-supported software is any software package which automatically plays, displays, or downloads advertising material to a computer after the software is installed on it or while the application is being used.  Generally, addware is classified as <a href="http://en.wikipedia.org/wiki/Privacy-invasive_software">privacy-invasive software</a>.</li>
</ul>
<h4><strong>Botnet</strong></h4>
<p>A <strong>botnet</strong> is a collection of Internet connected computers running autonomously and automatically in order to accomplish some distributed task.  <a href="http://en.wikipedia.org/wiki/Distributed_computing">Distributed computing</a> can be used for useful and constructive applications, while the term botnet typically refers a system designed and used for illegal purposes.  The individual compromised machines (<strong>drones</strong> or <strong>zombies</strong>) run malicious software (<strong>bot</strong>) and are assimilated and used without the owner&#8217;s knowledge.  The machines operate under the <a href="http://en.wikipedia.org/wiki/Command_and_control"><strong>Command and Control</strong></a> (<strong>C&#038;C</strong>) of the botnet owner (<strong>herder</strong>).  Botnets are used for (definitions taken from the accompanying links):</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Click_fraud">Click Fraud</a> &#8211; click fraud is a type of internet crime that occurs in pay per click online advertising when a person, automated script, or computer program imitates a legitimate user of a web browser clicking on an ad, for the purpose of generating a charge per click without having actual interest in the target of the ad&#8217;s link.</li>
<li><a href="http://www.cert.org/homeusers/ddos.html">DDoS</a> &#8211; one in which a multitude of compromised systems attack a single target, thereby causing denial of service for users of the targeted system. The flood of incoming messages to the target system essentially forces it to shut down, thereby denying service to the system to legitimate users.</li>
<li><a href="http://en.wikipedia.org/wiki/Keystroke_logging">Keylogging</a> &#8211; a method of capturing and recording user keystrokes. </li>
<li><a href="http://en.wikipedia.org/wiki/Warez">Warez</a> &#8211; refers primarily to copyrighted works traded in violation of copyright law. </li>
<li><a href="http://en.wikipedia.org/wiki/Spam_(electronic)">Spam</a> &#8211; is the abuse of electronic messaging systems to indiscriminately send unsolicited bulk messages.</li>
</ul>
<h4><strong>Phishing</strong></h4>
<p>Phishing is the practice of sending out fake emails, or spam for purpose of gathering personal information and/or identity theft.</p>
<h3>Source Countries</h3>
<p>Now that we know a few of the weapons used in cyberspace, we are ready to examine countries where these various attacks are occurring.  Once more, please remember that those behind the attacks might not be at the same location as the machines that are launching the attacks.
</p>
<p>
The <a href="http://www.shadowserver.org/">Shadowserver Foundation</a> (see below) collects and provides some very interesting statistics.  The below map shows the locations of infected machines (drones) that Shadowserver has observed in the past 24 hours.  Please note that this information is not complete.  It cannot be.  If we knew all infected computers and C&#038;C machines, we could shut them down easily.  The challenge is in the <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Stats.GeoLocations">ever changing landscape</a>.  The Shadowserver Foundation does a commendable job continuously monitoring this dynamic landscape.</p>
<h1 ALIGN=center><a href="http://www.shadowserver.org/wiki/uploads/Stats/drones.jpg"><img src="http://www.shadowserver.org/wiki/uploads/Stats/drones.jpg" alt="Drones" height=300 /></a></h1>
<p>The below map shows the last 24-hours worth of tracked C&#038;C servers.</p>
<h1 ALIGN=center><a href="http://www.shadowserver.org/wiki/uploads/Stats/ccip.jpg"><img src="http://www.shadowserver.org/wiki/uploads/Stats/ccip.jpg" alt="CC IPs" height=300 /></a></h1>
<p>The below graph shows the count of all the network scans into routed CIDR blocks that occur from the botnets that Shadowserver is aware of:</p>
<h1 ALIGN=center><a href="http://www.shadowserver.org/wiki/uploads/Stats/scan-year.png"><img src="http://www.shadowserver.org/wiki/uploads/Stats/scan-year.png" alt="Scans for Year" width=500 /></a></h1>
<p>The below map shows the last 24-hours worth of tracked existing C&#038;C and the target of scan attacks.</p>
<h1 ALIGN=center><img src="http://www.shadowserver.org/wiki/uploads/Stats/scan.jpg" alt="Scans Past 24hrs" height=300 /></h1>
<p>The below graph shows the count of all the DDoS attacks that occurred from the botnets that Shadowserver is aware of:</p>
<h1 ALIGN=center><img src="http://www.shadowserver.org/wiki/uploads/Stats/ddos-year.png" alt="DDoS" width=500 /></h1>
<p>The below most recent 24 hour period map shows the C&#038;C and the target of the DDoS attack.</p>
<h1 ALIGN=center><img src="http://www.shadowserver.org/wiki/uploads/Stats/ddos.jpg" alt="DDoS Past 24hrs" height=300 /></h1>
<p>The below map shows the machines suffering DDoS attacks and the C&#038;C sources in 2007.</p>
<h1 ALIGN=center><img src="http://www.shadowserver.org/wiki/uploads/Stats/ddos2-2007.jpg" alt="C&#038;C 2007" height=300 /></h1>
<p>The PhishTank (see below) provides <a href="http://www.phishtank.com/stats.php">daily verified phishing attempts</a>.  Below is a map of the countries generating the most reported verified Phishing attempts for April 2008.</p>
<h1 ALIGN=center><img src="http://www.phishtank.com/images/phish_world_map_200804.gif" alt="Phishing 2008" width=500 /></h1>
<h3>Sources for Information</h3>
<p>As previously mentioned, the <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Shadowserver.Mission"><strong>Shadowserver Foundation</strong></a> gathers, tracks, and reports on malware, botnet activity, and electronic fraud. It is a great source of information concerning cybercrime. <a href="http://conference.auscert.org.au/conf2008/presenter.php?presenter_id=R_P">Richard Perlotto</a>, the gentleman who runs the technology and operational side of the Shadowserver Foundation, <a href="http://itradio.com.au/auscert08/?p=75">presented</a> last week at the <a href="http://conference.auscert.org.au/conf2008/">Asia Pacific Information Security conference</a> (AusCERT2008).
</p>
<p>
<a href="http://www.phishtank.com"><strong>PhishTank</strong></a> provides information on phishing attacks.  While <a href="http://www.opendns.com">OpenDNS</a> created and operate the site, PhishTank is a community effort with the information being provided by companies and people submitting phishing e-mails and Web sites.  The data is totally open and a free API exist.  The <a href="http://www.phishtank.com/api_documentation.php">API documentation</a> is available for developers wanting to use PhishTank&#8217;s community data to integrate anti-phishing elements into their applications.
</p>
<p>
If you have anything in your security arsenal that is monitoring for certain IPs or domains, the <a href="http://malwaredomains.com/"><strong>DNS-DB Malware Domain Blocklist</strong></a> and the <a href="http://watchlist.security.org.my/watchlist"><strong>Global Watchlist</strong></a> provide invaluable up-to-date information.  The DNS-DB Malware Domain Blocklist site maintains a <a href="http://www.malwaredomains.com/files/domains.txt">list of domains</a>, pulled from various sources, that are known to be used to propagate malware and spyware.  The Global Watchlist was created after a discussion between <a href="http://www.blogger.com/profile/10778262436985693992">C.S. Lee</a> and <a href="http://mel.icious.net/">Spoonfork</a>.  C.S. Lee describes the purpose of this list in his posting &#8220;<a href="http://geek00l.blogspot.com/2008/02/harimau-watchlist.html">The Harimau Watchlist</a>&#8221;  What they have done, in their own words is to &#8220;<em>pull the list of suspected malicous IPs/Net ranges from different sources such as Sans dshield, Arbor atlas and so forth, then putting all of them in one place</em>.&#8221;  You can search through a web interface or set up processes to search automatically via URL.  They have also made all the <a href="http://watchlist.security.org.my/all.txt">IPs and data available</a> in one file.  Helping detect and possibly prevent access from these IPs and domains through Snort, Dragon, and other IDS/IPS <a href="http://www.emergingthreats.net/content/view/16/38/">signatures</a> is the <a href="http://www.emergingthreats.net/"><strong>Emerging Threats</strong></a> site.
</p>
<p>
<a href="http://www.spamhaus.org"><strong>The Spamhaus Project</strong></a> attempts to &#8220;<em>track the Internet&#8217;s Spam Gangs, to provide dependable realtime anti-spam protection for Internet networks, to work with Law Enforcement Agencies to identify and pursue spammers worldwide, and to lobby governments for effective anti-spam legislation</em>.&#8221;  The project offers a realtime database of IP addresses consisting of a combination of the Spamhaus Block List (<strong>SBL</strong>), the Exploits Block List (<strong>XBL</strong>) and the Policy Block List (<strong>PBL</strong>).  If you desire a <a href="http://www.spamhaus.org/datafeed/">data feed</a>, the service is not free.  You can try it out for 30 days free.  They do operate DNSBL servers spread across 18 countries.  You may qualify for <a href="http://www.spamhaus.org/organization/dnsblusage.html">free access</a> via DNS queries.
</p>
<p>
The <a href="http://isc.sans.org/"><strong>SANS Internet Storm Center</strong></a> (<strong>ISC</strong>) provides a free analysis and warning service to fight back against the malicious attackers.  The ISC gathers millions of intrusion detection log entries every day, from sensors covering over 500,000 IP addresses in over 50 countries.  It is a a free service to the Internet community.  After removing identifying information, the ISC sends send intrusion detection and firewall logs to the <a href="http://www.dshield.org">DShield</a> distributed intrusion detection system.
</p>
<p>
The <a href="http://nvd.nist.gov/"><strong>National Vulnerability Database</strong></a> (<strong>NVD</strong>) is a fantastic source of free information enabling automation of vulnerability management, security measurement, and compliance.  While it might not help with filtering of IPs, the data can be used in combination when automating your security.  To quote the site, &#8220;<em>NVD includes databases of security checklists, security related software flaws, misconfigurations, product names, and impact metrics</em>.&#8221;  NVD is the repository for <a href="http://nvd.nist.gov/scap/docs/ISAP.doc">Information Security Automation Program</a> (<strong>ISAP</strong>) and the <a href="http://nvd.nist.gov/validation.cfm">Security Content Automation Protocol</a> (<strong>SCAP</strong>).  Here are a few of the major sources of information NVD provides:
<ol>
<li><a href="http://cve.mitre.org/">CVE Vulnerabilities</a> &#8211; a dictionary of publicly known information security vulnerabilities and exposures.  Allows you to <a href="http://cve.mitre.org/cve/cve.html">download</a> the entire CVE List in various formats.</li>
<li><a href="http://nvd.nist.gov/ncp.cfm">Checklists</a> &#8211; repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications. </li>
<li><a href="http://www.us-cert.gov/cas/techalerts">US-CERT Alerts</a> &#8211; provide timely information about current security issues, vulnerabilities, and exploits.</li>
<li><a href="http://www.kb.cert.org/vuls/byupdate?open&#038;start=1&#038;count=10">US-CERT Vuln Notes</a> &#8211; include technical descriptions of the vulnerability, as well as the impact, solutions and workarounds, and lists of affected vendors.</li>
<li><a href="http://oval.mitre.org/">OVAL Queries</a> &#8211; an international, information security, community standard to promote open and publicly available security content, and to standardize the transfer of this information across the entire spectrum of security tools and services.  <a href="http://oval.mitre.org/rep-data/index.html">OVAL Repositoty downloads</a> include Data Files of all vulnerability, compliance, inventory, and patch definitions for supported platforms.</li>
</ol>
<p>
There are a few good sources for security statistics in the form of a reports.  The <a href="http://www.antiphishing.org/">Anti-Phishing Working Group</a> (APWG) is the global pan-industrial with over 3000 members in over 1700 companies and agencies worldwide.  The group&#8217;s purpose is eliminating the fraud and identity theft that result from phishing, pharming and email spoofing of all types.  They produce an interesting <a href="http://www.antiphishing.org/reports/apwg_report_jan_2008.pdf">Phishing Activity Trends report</a> which was last updated in January 2008.
</p>
<p>
<strong>WhiteHat</strong> produces a <a href="http://www.whitehatsec.com/home/resource/stats.html">Security Statistics Report</a>.  The report presents a statistical picture of current website vulnerabilities focused solely on previously unknown vulnerabilities on public websites.  The report also contains expert analysis and recommendations.   <a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a>, founder and CTO, does maintain a very informative blog where additional information can be found.  You can hear Jeremiah on a <a href="http://itradio.com.au/security/?p=68">recent episode of Risky Business</a> where he discussed with host Patrick Gray Cross Site Request Forgery attacks.
</p>
<p>
<strong>Microsoft</strong> produces a &#8220;<a href="http://www.microsoft.com/sir">Security Intelligence Report</a>.&#8221;  Currently the fourth volume is available covering July through December 2007.  You can also <a href="http://go.microsoft.com/fwlink/?LinkId=119213&#038;clcid=0x409">watch the video cast</a> of <a href="http://pipl.com/directory/people/Bret/Arsenault">Bret Arsenault</a>, GM US National Security Team and <a href="http://pipl.com/directory/people/Vinny/Gullotto">Vinny Gullotto</a>, GM Microsoft Malware Protection Center, discuss the trends and findings in the latest SIR.
</p>
<p>
There are a few final additional sources of information that I have found useful when trying to understand security trends.  <a href="http://en.wikipedia.org/wiki/Dan_Geer"><strong>Dan Geer</strong></a> did a presentation, &#8220;<a href="http://geer.tinho.net/trends.pdf">A Quant Look at the Future Extrapolation via Trend Analysis</a>.&#8221;   The <a href="http://iac.dtic.mil/iatac/download/security.pdf">state-of-the-art report</a> (<strong>SOAR</strong>) published by the Information Assurance Technology Analysis Center (<a href="http://iac.dtic.mil/iatac/">IATAC</a>) provides observations about noteworthy trends in software security assurance as a discipline.  The <a href="http://www.gocsi.com/forms/csi_survey.jhtml"><strong>Computer Crime and Security Survey</strong></a> is conducted by CSI annually. The aim of this effort is to raise the level of security awareness, as well as help determine the scope of computer crime in the United States.  They use to issue the report with the FBI.  Registration is required.
</p>
<p>
Blogs can also be a valuable source of information, and may occasionally post IPs to be concerned about.  <strong>SunBelt Software</strong> just did a posting titled &#8220;<a href="http://sunbeltblog.blogspot.com/2008/05/fresh-new-rogue-antispyware-programs.html">Fresh new rogue antispyware programs</a>.&#8221;  Dancho Danchev recently posted &#8220;<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a>.&#8221;  The <a href="http://www.f-secure.com/weblog"><strong>F-Secure</strong></a> folks maintain a very informative site concerning the latest news from their labs.  There are many excellent sites for information on malware, botnets, and phishing.  For example, <a href="www.kaspersky.com">Kaspersky Lab</a> maintains the blog <a href="http://www.viruslist.com/en/weblog"><strong>VirusList</strong></a> and the <a href="http://kasperskyav.blogspot.com/"><strong>AVDefender</strong></a>.  SANS ISC has the <a href="http://isc.sans.org/diary.html"><strong>Handler&#8217;s Diary</strong></a>.<br />
<script type="text/javascript" src="http://www.cert.org/cert/js/scripts.js"></script></p>
<h3>International Incident Coordination</h3>
<p>Security on international projects is complicated.  Take a look at my previous post, &#8220;<a href="http://blog.securitymonks.com/2007/10/10/information-security-and-the-law/">Information Security and the Law</a>.&#8221;  Different countries have different laws impacting what can and cannot be done.  Many CEOs may not know a great deal about information technology, but they know they have no desire to break the laws of other countries.  This can pressure managers to prefer to implement light security.  Heavy on the data protection, but light on the detection.  We have established cyberspace can be a dangerous place, especially when you are playing in international waters.  Defenses will fail.  If an organization cannot detect nefarious  activities in a high risk environment, that is a bad combination.  Even when you have fully supportive management, it is easy to run into a road block when dealing with other countries.
</p>
<p>
Carnegie Mellon University <a href="http://www.sei.cmu.edu/">Software Engineering Institute</a> (<strong>SEI</strong>) is trying to help establish some coordination between the white hats working in international security.  First, a little history in order to understand the players involved.  SEI  was charged by the <a href="http://www.darpa.mil/">Defense Advanced Research Projects Agency</a> (<strong>DARPA</strong>) with setting up center to &#8220;<em>coordinate communication among experts during security emergencies and to help prevent future incidents</em>.&#8221; This center was named the <a href="http://www.cert.org/">CERT Coordination Center</a> (<strong>CERT/CC</strong>) and is an amazing source for cutting edge security research and information.
</p>
<p>
<a href="http://www.first.org/members/map/"><img src="http://www.first.org/_images/wmap.png" alt="FIRST" align="right" /></a>With the establishment of incident response team both within the United Stated and Internationally, soon difficulties developed due to differences in language, timezone, and international standards or conventions.  It became apparent that better communication and coordination between teams were needed.  The <a href="http://www.first.org">Forum of Incident Response and Security Teams</a> (<strong>FIRST</strong>) was established.   Membership consists of teams from a wide variety of organizations including educational, commercial, vendor, goverment and military.
</p>
<p>
<a href="http://www.cert.org/csirts/csirt-map.html"><img src="http://www.cert.org/images/csirtmap_sm.jpg" alt="CSIRT" align="left"/></a>CERT/CC also began a program to help <a href="http://www.cert.org/csirts/">Computer Security Incident Response Team (<strong>CSIRT</strong>) development</a> and establish CSIRTs around the world.  National CSIRTs deal with security at the macro level.  Large-scale incidents can affect the economy, critical infrastructure, government operations, and/or national security.  If the incident ends up being a worldwide event, National CSIRTs can coordinate with CSIRTs in other countries to establish communications and cooperation among those countries.  </p>
<p>
To hear more about CSIRT, in August <a href="http://www.cert.org/podcast/bios.html#carpenter">Jeff Carpenter</a> talked with <a href="http://www.cert.org/podcast/bios.html#allen">Julia Allen</a> on the CERT podcast titled, &#8220;<a href="http://www.cert.org/podcast/show/20070821carpenter.html">Tackling Security at the National Level: A Resource for Leaders</a>.&#8221;   Jeffrey J. Carpenter is the technical manager of the CERT/CC and has assisted with the formation and development of CSIRTs.  Julia Allen is a senior researcher within the CERT Program and is engaged in developing and transitioning executive outreach programs in enterprise security and governance, and works extensively with the IT operations and audit communities.  She is one of my favorite sources for enterprise security information.
</p>
<p>
Below is an interactive map to locate CSIRTs with national responsibility around the world.  From the map, additional information can be pulled up on the individual sites.  </p>
<table border="0" cellspacing="0" cellpadding="3">
<tr>
<td width="50%">
<a href="#" onclick="javascript:window.open('http://www.cert.org/cert/map_open.html','mywin','left=20,top=20,width=1000,height=492,toolbar=0,scrollbars=no,resizable=no');"></p>
<h1 ALIGN=center><img src="http://www.cert.org/cert/images/flash_map_icn.jpg" alt="map" border="0" width=300 /></h1>
<p></a></td>
</tr>
</table>
<h3>Final Words</h3>
<p>I understand the frustration Col. Charles W. Williamson III feels.  The problem is that in cyberspace, the enemy is all around us.  It is within us.  If we lash out, our first target must be ourselves.  In the end, we are fighting blind.  <a href="http://en.wikipedia.org/wiki/Edmund_Burke">Edmund Burke</a> once said, &#8220;<em>All that is necessary for evil to succeed is that good men do nothing</em>.&#8221;  I do not think good men attacking each other was the something Edmund had in mind.  That is what will occur if we fight blind.  We can&#8217;t even withdraw into the safety of our own silos for the perimeters are being continuously breached.  Retreat is not an option.  The delusion that isolationism will bring safety has been shattered.  The only solution is for the good guys to band together.  There is strength in unity.  Only when working together will we be strong enough to take on those who bring destruction.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2008/05/28/unclear-and-present-danger/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://go.microsoft.com/fwlink/?LinkId=119213&amp;clcid=0x409" length="78326190" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>From Cyberspace with Love</title>
		<link>http://blog.securitymonks.com/2008/05/23/from-cyber-space-with-love/</link>
		<comments>http://blog.securitymonks.com/2008/05/23/from-cyber-space-with-love/#comments</comments>
		<pubDate>Sat, 24 May 2008 00:49:35 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[Censorship]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[Estonia]]></category>
		<category><![CDATA[International]]></category>
		<category><![CDATA[Myanmar]]></category>
		<category><![CDATA[OpenNet]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Pakistan]]></category>
		<category><![CDATA[Russia]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/2008/05/23/from-cyber-space-with-love/</guid>
		<description><![CDATA[April 26 was the 22nd anniversary of the meltdown at the Russian Chornobyl reactor.  On this day, Radio Free Europe / Radio Liberty (RFE/RL) began its live Web report covering a rally of thousands of people, organized by the Belarusian opposition.  The demonstration was to protest the government&#8217;s decision to build a new [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hackerstock.890m.com/"><img src="/images/logo.GIF" alt="Hacking" align="left" width=150 /></a>April 26 was the 22nd anniversary of the meltdown at the Russian <a href="http://en.wikipedia.org/wiki/Chernobyl_disaster">Chornobyl</a> reactor.  On this day, <a href="http://www.rferl.org">Radio Free Europe / Radio Liberty</a> (RFE/RL) began its live Web report covering a rally of thousands of people, organized by the Belarusian opposition.  The demonstration was to protest the government&#8217;s decision to build a new nuclear power station and the plight of uncompensated <a href="http://http://www.usnews.com/articles/news/world/2008/04/24/chernobyl-victims-struggle-with-consequences-of-radiation-exposure.html">Chornobyl victims</a>.  What followed was a <a href="http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci557336,00.html">Distributed Denial of Service</a> (DDoS) attack, flooding the Belarusian RFE/RL Web sites with up to 50,000 hits every second.  Eight RFE/RL websites (Belarus, Kosovo, Azerbaijan, Tatar-Bashkir, Radio Farda, South Slavic, Russian, and Tajik) were knocked out or otherwise affected for almost two days.  This effectively silenced the coverage.  Two other Web sites were targeted in the same attack, belonging to the opposition groups <a href="http://www.charter97.org/">Charter 97</a> and <a href="http://www.belaruspartisan.org">Belarus Partisan</a>.  </p>
<p>
The next day, April 27th, marked the one year anniversary of the <a href="http://en.wikipedia.org/wiki/Cyberattacks_on_Estonia_2007">cyber attack on Estonia</a>.  The incident began when Estonian government moved a war memorial honoring Russian-Estonians who died fighting the Nazis.  <a href="http://www.truveo.com/Gadi-Evron-Estonia-Information-Warfare-and/id/1585334160">Gadi Evron</a>, the former Israeli Government CERT manager who was in Estonia at the time of the attacks, has published an article titled, &#8220;<a href="http://www.ciaonet.org/journals/gjia/v9i1/0000699.pdf">Battling Botnets and Online Mobs</a>&#8221; in the <a href="http://journal.georgetown.edu">Georgetown Journal of International Affairs</a>.  Evan explains the attack:<br />
<blockquote>Once bloggers started reporting their small-scale attacks, more experienced players became involved. Before long, botnets were being used. The involvement of the Russian government in the affair cannot be confirmed. What raised speculation, however, is the failure&#8211;or unwillingness&#8211;of the Russian authorities to stop the cyber riot against Estonia for over three weeks after the initial attack.</p></blockquote>
<p>In an attempt to deal with future attacks, seven NATO countries are backing the establishment of the <a href="www.nato.int/docu/update/2008/05-may/e0514a.html ">Cooperative Cyber Defence (CCD) Centre of Excellence (COE)</a> in Estonia.  <a href="http://www.jfcom.mil/about/mattis.htm">General James Mattis</a>, NATO’s  Supreme Allied Commander Transformation/Commander, at the signing ceremony stated, &#8220;<em>The need for a cyber defense center to be opened today is compelling&#8230;It will help NATO defy and successfully counter the threats in this area</em>.&#8221;  The center will be tasked with conducting research and training on cyber warfare.  The US showed its backing by agreeing to send an observer.
</p>
<p>
Cyber attacks are occurring in every country.  Last month Chinese hackers called for a DDoS against <a href="http://CNN.com">CNN.com</a> in retaliation for news coverage of <a href="http://search.cnn.com/search.jsp?query=Tibetan%20protests&#038;type=news&#038;sortBy=date&#038;intl=false">Tibet protesters</a>.  The organizers felt the news coverage was skewed against China.  The attack was reported called off because the amount of coverage of the approaching attack expected to limit its effectiveness.  Still, on the day of the planned attack, CNN was knocked offline for <a href="http://www.zdnet.com.au/news/security/soa/Chinese-hackers-disable-CNN-com-for-three-hours/0,130061744,339288382,00.htm?omnRef=http://www.google.com/search?q=Chinese%20hackers%20called%20on%20a%20DDOS%20against%20CNN.com">three hours</a>.  The Internet research website <a href="http://news.netcraft.com/archives/2008/04/22/cnn_site_bears_the_brunt_of_chinese_attackers.html">Netcraft reported</a>, &#8220;<em>CNN&#8217;s website suffered downtime within a three hour period on Sunday morning, followed by other anomalous activity on Monday morning, where response times were greatly inflated</em>.&#8221;
</p>
<p>
Providing information on scale of compromised servers, malicious attackers, and the spread of malware is the <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Shadowserver.Mission">Shadowserver Foundation</a>.  The organization gathers, tracks, and reports on malware, botnet activity, and electronic fraud.  It is a great source of information concerning cybercrime.  <a href="http://conference.auscert.org.au/conf2008/presenter.php?presenter_id=R_P">Richard Perlotto</a>, the gentleman who runs the technology and operational side of the Shadowserver Foundation, <a href="http://itradio.com.au/auscert08/?p=75">spoke</a> last week at the Asia Pacific Information Security conference (<a href="http://conference.auscert.org.au/conf2008/">AusCERT2008</a>).  Additional presentations and interviews from the conference can be accessed through <a href="http://itradio.com.au/auscert08/">ITRadio</a>.  Below is a sample map showing DDoS attacks in 2007. </p>
<h1 ALIGN=center><a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Stats.DDoSHistorical"><img src="http://www.shadowserver.org/wiki/uploads/Stats/ddos2-2007.jpg" alt="DDoS 2007" height =300 /></a></h1>
<p>In the old days, countries controlled information through clamping down on the press and shutting down television stations.  Pakistan meant to exercise country wide censorship February, when the the telecommunications ministry order <a href="http://www.youtube.com/watch?v=jKCZfnpU1uc&#038;feature=related">access to YouTube blocked</a>.  According to Danny McPherson, Arbor Networks’ Chief Research Officer, in his posting &#8220;<a href="http://asert.arbornetworks.com/2008/02/internet-routing-insecuritypakistan-nukes-youtube/">Internet Routing Insecurity::Pakistan Nukes YouTube?</a>&#8221; Pakistan Telecom had three options:
<ol>
<li>deploy access-control lists (ACLs) on all your router interfaces dropping packets to or from these IPs</li>
<li>statically route the three IPs, or perhaps the covering prefix (208.65.153.0/24), to a null or discard interface on all the routers in your network</li>
<li>employ something akin to a BGP blackhole routing function that results in all packets destined to those three specific IPs, or the covering prefixes, being discarded as a result of null or discard next hop packet forwarding policies, as discussed <a href="http://asert.arbornetworks.com/2006/04/effectively-completing-the-attack-and-this-posting/">here</a></li>
</ol>
<p>Pakistan Telecom selected option three.  Because Pakistan’s BGP traffic was offering very precise routes to what it declared were YouTube’s Internet servers, routers took it to be more accurate than YouTube’s own information about itself.  That data was supposedly accidentally shared with Hong Kong&#8217;s PCCW, who failed to validate the BGP data.  PCWW then shared the data with other ISPs throughout the Internet.  Believing Pakistan Telecom had faster routes to YouTube, service provides started sending their YouTube traffic requests to Pakistan.
</p>
<p>
McPherson spoke with ITRadio on the topic, &#8220;<a href="http://itradio.com.au/auscert08/?p=86">How to destroy the Internet</a>.&#8221;  In the interview, McPherson discusses what occurred in Pakistan and how, &#8220;<em>the control path, in general, on the Internet (DNS and routing, in particular) are two of the most fragile pieces of the Internet infrastructure</em>.&#8221;
</p>
<p>
<a href="http://www.linkedin.com/in/kimberlyzenz">Kimberly Zenz</a>, Senior Threat Analyst at VeriSign <a href="http://labs.idefense.com/">iDefense</a>, pointed out that times have changed and blocking a site from an ISP is an increasingly unreliable way of censoring the Internet.  Bringing down a site with a DDoS or shutting down the Internet completely are more effective options.  For example, faced with a major protest movement for the first time since 1990, the government of Myanmar <a href="http://www.nytimes.com/2007/10/04/world/asia/04info.html?_r=1&#038;oref=slogin">cut off the country&#8217;s Internet access</a> completely.  The actions of the Myanmar government are not unique.  The <a href="http://opennet.net/">OpenNet Initiative</a> (ONI) tracks Internet censorship with the aim &#8220;<em>to investigate, expose and analyze Internet filtering and surveillance practices in a credible and non-partisan fashion</em>.&#8221;  The site has a intriguing <a href="http://map.opennet.net/filtering-pol.html">global filtering map</a> and can provide valuable non-partisan information on Internet censorship throughout the world.
</p>
<p>
RFE/RL President <a href="http://en.wikipedia.org/wiki/Jeffrey_Gedmin">Jeffrey Gedmin</a> raises the concern that the number of cyberattacks will only increase, when he stated:<br />
<blockquote>The Belarusians, the Iranians &#8212; they all have basically the same objective. They see free information &#8212; flowing information of ideas and so forth &#8212; as the oxygen of civil society. They&#8217;ll do anything they can to cut it off. If it means jamming, if it means cyberattacks, that&#8217;s what they&#8217;ll do.</p></blockquote>
<p>Providing additional insight into the conditions that are helping foster hacking, Zenz was <a href="http://itradio.com.au/auscert08/?p=81">interviewed</a> and <a href="http://itradio.com.au/auscert08/?p=80">presented</a> at AusCERT2008.  For additional information, Zenz co-authored with <a href="http://labs.idefense.com/about/leadership.php">Eli Jellenc</a> the fascinating report &#8220;<a href="http://www.verisign.com/static/042139.pdf ">Global Threat Research Report: Russia</a>.&#8221;  While the report is focused on Russia, the conditions exist in may countries.
</p>
</p>
<p>Remember the good old days when our view of <a href="http://research.corsaire.com/articles/040524-hacker.html">hacking</a> was mostly based on the movie <a href="http://en.wikipedia.org/wiki/WarGames">War Games</a>?  Hackers where misunderstood high school kids who might break into a government site just for the thrill of it, or maybe to play games.  Who can forget the famous lines, &#8220;<a href="http://www.youtube.com/watch?v=ecPeSmF_ikc&#038;feature=related">Greetings Professor Falken, Shall We Play a Game?</a>&#8221;  If you don&#8217;t recall the movie, or that line, you really need to work on your <a href="http://www.geekculture.com/ultimatebb/Forum12/HTML/000483.html">geek culture</a>. While life and hacking may have appeared simple in those days, one cannot deny that today&#8217;s Internet offers the most interesting challenges.  It is an exciting time to be a security monk.  In the end, what&#8217;s not to love?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2008/05/23/from-cyber-space-with-love/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

