Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Thursday, February 15, 2024

Justice Department Conducts Court-Authorized Disruption Of Botnet Controlled By The Russian Federation’s Main Intelligence Directorate Of The General Staff (GRU)


The U.S. Justice Department released the below information:

A January 2024 court-authorized operation has neutralized a network of hundreds of small office/home office (SOHO) routers that GRU Military Unit 26165, also known as APT 28, Sofacy Group, Forest Blizzard, Pawn Storm, Fancy Bear, and Sednit, used to conceal and otherwise enable a variety of crimes. 

These crimes included vast spearphishing and similar credential harvesting campaigns against targets of intelligence interest to the Russian government, such as U.S. and foreign governments and military, security, and corporate organizations. In recent months, allegations of Unit 26165 activity of this type has been the subject of a private sector cybersecurity advisory and a Ukrainian government warning

This botnet was distinct from prior GRU and Russian Federal Security Service (FSB) malware networks disrupted by the Department in that the GRU did not create it from scratch. Instead, the GRU relied on the “Moobot” malware, which is associated with a known criminal group. Non-GRU cybercriminals installed the Moobot malware on Ubiquiti Edge OS routers that still used publicly known default administrator passwords. GRU hackers then used the Moobot malware to install their own bespoke scripts and files that repurposed the botnet, turning it into a global cyber espionage platform.

The Department’s court-authorized operation leveraged the Moobot malware to copy and delete stolen and malicious data and files from compromised routers. Additionally, in order to neutralize the GRU’s access to the routers until victims can mitigate the compromise and reassert full control, the operation reversibly modified the routers’ firewall rules to block remote management access to the devices, and during the course of the operation, enabled temporary collection of non-content routing information that would expose GRU attempts to thwart the operation.

“The Justice Department is accelerating our efforts to disrupt the Russian government’s cyber campaigns against the United States and our allies, including Ukraine,” said Attorney General Merrick B. Garland. “In this case, Russian intelligence services turned to criminal groups to help them target home and office routers, but the Justice Department disabled their scheme. We will continue to disrupt and dismantle the Russian government’s malicious cyber tools that endanger the security of the United States and our allies.”

“For the second time in two months, we’ve disrupted state-sponsored hackers from launching cyber-attacks behind the cover of compromised U.S. routers,” said Deputy Attorney General Lisa Monaco. “We will continue to leverage all of our legal authorities to prevent harm and protect the public — whether the hackers are from Russia, China, or another global threat.” 

“Russia’s GRU continues to maliciously target the United States through their botnet campaigns,” said FBI Director Christopher Wray. “The FBI utilized its technical capabilities to disrupt Russia’s access to hundreds of routers belonging to individuals in addition to small and home offices. This type of criminal behavior is simply unacceptable, and the FBI, in coordination with our federal and international partners, will not allow for any of Russia’s services to negatively impact the American people and our allies.”  

“In this unique, two-for-one operation, the National Security Division and its partners disrupted a botnet used by both criminal and state-sponsored actors,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division. “Notably, this represents the third time since Russia’s unjustified invasion of Ukraine that the Department has stripped the Russian intelligence services of a key tool used to further the Kremlin’s acts of aggression and other malicious activities. We will continue to use our legal authorities and cutting-edge techniques, and to draw on the strength of our partnerships, to protect the public and our allies from such threats.”

“This is yet another case of Russian military intelligence weaponizing common devices and technologies for that government’s malicious aims,” said U.S. Attorney Jacqueline C. Romero for the Eastern District of Pennsylvania. “As long as our nation-state adversaries continue to threaten U.S. national security in this way, we and our partners will use every tool available to disrupt their cyber thugs — whomever and wherever they are.”

“Operation Dying Ember was an international effort led by FBI Boston to remediate over a thousand compromised routers belonging to unsuspecting victims here in the United States, and around the world that were targeted by malicious, nation state actors in Russia to facilitate their strategic intelligence collection,” said Special Agent in Charge Jodi Cohen of the FBI Boston Field Office. “The FBI’s strong partnerships with the private sector were critical to identifying and addressing this threat which targeted our national security interests here and abroad. This operation should make it crystal clear to our adversaries that we will not allow anyone to exploit our technology and networks.”

As described in court documents, the government extensively tested the operation on the relevant Ubiquiti Edge OS routers. Other than stymieing the GRU’s ability to access to the routers, the operation did not impact the routers’ normal functionality or collect legitimate user content information. Additionally, the court-authorized steps to disconnect the routers from the Moobot network are temporary in nature; users can roll back the firewall rule changes by undertaking factory resets of their routers or by accessing their routers through their local network (e.g., via the routers’ web-based user interface). However, a factory reset that is not also accompanied by a change of the default administrator password will return the router to its default administrator credentials, leaving the router open to reinfection or similar compromises.

The FBI Philadelphia and Boston Field Offices and Cyber Division, U.S. Attorney’s Office for the Eastern District of Pennsylvania, and the National Security Division’s National Security Cyber Section led the disruption effort. The Criminal Division’s Computer Crime and Intellectual Property Section and Office of International Affairs, Shadowserver Foundation, Microsoft Threat Intelligence, and other partners provided valuable assistance.

The FBI is working with internet service providers to provide notice of the operation to owners and operators of SOHO routers covered by the court’s authorization. If you believe you have a compromised router, please visit the FBI’s Internet Crime Complaint Center.

To better protect themselves, the FBI advises all victims to conduct the following remediation steps:

1.     Perform a hardware factory reset to flush the file systems of malicious files;

2.     Upgrade to the latest firmware version;

3.     Change any default usernames and passwords; and

4.     Implement strategic firewall rules to prevent the unwanted exposure of remote management services.

The FBI strongly encourages router owners to avoid exposing their devices to the internet until they change the default passwords.

Wednesday, March 23, 2016

Chinese National Pleads Guilty To Conspiring To Hack Into U.S. Defense Contractors’ Systems To Steal Sensitive Military Information


The U.S. Justice Department released the below information:

A Chinese national pleaded guilty today to participating in a years-long conspiracy to hack into the computer networks of major U.S. defense contractors, steal sensitive military and export-controlled data and send the stolen data to China.
Su Bin, also known as Stephen Su and Stephen Subin, 50, a citizen and resident of the People’s Republic of China, pleaded guilty before U.S. District Judge Christina A. Snyder of the Central District of California.
The guilty plea was announced by Assistant Attorney General for National Security John P. Carlin, U.S. Attorney Eileen M. Decker of the Central District of California, Assistant Director Jim Trainor of the FBI’s Cyber Division and Assistant Director in Charge David Bowdich of the FBI’s Los Angeles Division.
A criminal complaint filed in 2014 and subsequent indictments filed in Los Angeles charged Su, a China-based businessman in the aviation and aerospace fields, for his role in the criminal conspiracy to steal military technical data, including data relating to the C-17 strategic transport aircraft and certain fighter jets produced for the U.S. military.  Su was initially arrested in Canada in July 2014 on a warrant issued in relation to this case.  Su ultimately waived extradition and consented to be conveyed to the United States in February 2016.
“Su Bin admitted to playing an important role in a conspiracy, originating in China, to illegally access sensitive military data, including data relating to military aircraft that are indispensable in keeping our military personnel safe,” said Assistant Attorney General Carlin.  “This plea sends a strong message that stealing from the United States and our companies has a significant cost; we can and will find these criminals and bring them to justice.  The National Security Division remains sharply focused on disrupting cyber threats to the national security, and we will continue to be relentless in our pursuit of those who seek to undermine our security.”
“Protecting our national security is the highest priority of the U.S. Attorney’s Office, and cybercrime represents one of the most serious threats to our national security,” said U.S. Attorney Decker.  “The innovative and tireless work of the prosecutors and investigators in this case is a testament to our collective commitment to protecting our nation’s security from all threats. Today’s guilty plea and conviction demonstrate that these criminals can be held accountable no matter where they are located in the world and that we are deeply committed to protecting our sensitive data in order to keep our nation safe.”
“Cyber security is a top priority not only for the FBI but the entire U.S. government,” said Assistant Director Trainor.  “Our greatest strength is when we harness our capabilities to work together, and today’s guilty plea demonstrates this.  Our adversaries’ capabilities are constantly evolving, and we will remain vigilant in combating the cyber threat.”
“This investigation demonstrates the FBI’s resolve in holding foreign cyber actors accountable regardless of where they reside,” said Assistant Director in Charge Bowdich.  “Cybercrime investigators in Los Angeles are among the finest and their efforts toward preserving America's national security in this case should be commended.”
In the plea agreement filed yesterday in the U.S. District Court of the Central District of California, Su admitted to conspiring with two persons in China from October 2008 to March 2014 to gain unauthorized access to protected computer networks in the United States, including computers belonging to the Boeing Company in Orange County, California, to obtain sensitive military information and to export that information illegally from the United States to China.
As part of the conspiracy, Su would e-mail the co-conspirators with guidance regarding what persons, companies and technologies to target during their computer intrusions.  One of Su’s co-conspirators would then gain access to information residing on computers of U.S. companies and email Su directory file listings and folders showing the data that the co-conspirator had been able to access.  Su then directed his co-conspirator as to which files and folders his co-conspirator should steal.  Once the co-conspirator stole the data, including by using techniques to avoid detection when hacking the victim computers, Su translated the contents of certain stolen data from English into Chinese.  In addition, Su and his co-conspirators each wrote, revised and emailed reports about the information and technology they had acquired by their hacking activities, including its value, to the final beneficiaries of their hacking activities.
Su’s plea agreement makes clear that the information he and his co-conspirators intentionally stole included data listed on the U.S. Munitions List contained in the International Traffic in Arms Regulations.  Su also admitted that he engaged in the crime for the purpose of financial gain and specifically sought to profit from selling the data the he and his co-conspirators illegally acquired. 
Su faces a maximum sentence of five years in prison and a fine of $250,000 or twice the gross gain or gross loss resulting from the offense, whichever is greatest.  Judge Snyder is scheduled to sentence Su on July 13, 2016.
The case is being investigated by the FBI Los Angeles Field Office’s Cyber Division with assistance from the U.S. Air Force’s Office of Special Investigations.
This case is being prosecuted by Assistant U.S. Attorney Anthony J. Lewis of the Central District of California and Trial Attorney Casey Arrowood and Senior Trial Attorney Robert E. Wallace of the National Security Division’s Counterintelligence and Export Control Section, with support from Lisa Roberts of the Justice Department’s Office of International Affairs. 

Tuesday, June 23, 2015

OPM Chief: Contractor's Credential Used To Breach System



The Philadelphia Inquirer offers a piece on the Office of Personnel Management (OPM) director explaining the massive computer security breach of the agency's files.

WASHINGTON (AP) - The head of the government agency that suffered two massive cyberattacks said Tuesday that a hacker gained access to its records with a credential used by a federal contractor.

Katherine Archuleta, director of the Office of Personnel Management, told a Senate hearing that an "adversary" somehow obtained a user credential used by KeyPoint Government Solutions, a contractor based in Loveland, Colorado.

She didn't say specifically when that occurred or if it was linked to the two cyberbreaches that exposed private information on nearly every federal employee and personal histories of millions with security clearances.

"I want to be very clear that while the adversary leveraged - compromised - a KeyPoint User credential to gain access to OPM's network, we don't have any evidence that would suggest that KeyPoint as a company was responsible or directly involved in the intrusion," she said.

You can read the rest of the piece via the below link:

http://www.philly.com/philly/news/nation_world/20150623_ap_eae3058fce70437e86f4e8c305089e5a.html


Saturday, March 14, 2015

Cyber Domain Presents Profound Challenges, Says Defense Secretary Carter At The U.S. Cyber Command


Claudette Roulo at the DoD News offers the below report:

WASHINGTON, March 13, 2015 - Defense Secretary Ash Carter gave his first domestic troop talk as secretary to the cyber warriors assigned to U.S. Cyber Command at Fort Meade, Maryland, today.

The mission of Cybercom is vital to the economic and physical security of not just the nation, but to Americans in their individual lives, Carter said.

"With all that's going on in the world, from Iraq to Ukraine, to the Asia-Pacific, the domain that you protect -- cyberspace -- is presenting us with some of the most profound challenges, both from a security perspective and from an economic perspective," he told the troops.

National leaders at every level are "seized with the need to get on top of this problem," the defense secretary said.

Building Bridges to Society

The Defense Department must be open to sources of good people and new technology to better position itself to defend the nation in cyberspace, he said.

"And that means we need to build bridges to society. Bridges that aren't as necessary in other fields of warfare that don't have a civilian or a commercial counterpart to the extent that this field does," Carter said.

Transparency is a difficult goal in cyber defense, the secretary acknowledged, but added that the department must always be open to new ideas and people.

"We can't always tell them what we are doing," the defense secretary said, "but we need to be open enough with our government so that it knows what it's doing."

The department must also be open to the ideas of new generations, he said.

"We need people who grew up with technology that was not available when I was growing up, and therefore have a sixth sense about it which I can never have," Carter said.

Nontraditional Warriors

The development of the cyber workforce can be a model for DoD, he told the troops.

"The freshness of approach, the constant effort to stay up [and] reinvent, that your field demands is actually something we can use everywhere in the department," the defense secretary said.

The cyber skill set and professional orientation doesn't have a good analog in the traditional armed services, Carter said.

"For the institutions that you join, be they military services or field agencies or new commands, they are trying to figure out how to welcome this new breed of warrior to their ranks," he said.

"We have to figure out how to get it to fit in, so that you all have a full opportunity to bring to bear on your careers the expertise that you gained here and that sense of mission that you felt here," the defense secretary said.

Challenges always accompany doing something new and exciting, Carter said, adding that he is determined to create a place where cyber warriors fit. "We'll find the path together," he said.

The relationship between Cybercom and the National Security Agency is also a work in progress, Carter said.

"My view is that we're doing the right thing in having the leadership of those two organizations in the same place," he said. "And one way of thinking about that is that we just don't have enough good people like you to spread around, and we need to cluster our hits."

Ensuring that cyber troops have the training, equipment and resources they need is a high priority for the department, he said.

Sequester 'Terrible, Stupid'

"If you read about sequester, which is a terrible, stupid thing that we are doing to ourselves -- I have nothing good to say about it," Carter said, referring to the across-the board government spending cuts the Budget Control Act of 2011 is set to impose in October. "But I think that even in the era of sequester, we understand that this mission area is one we cannot afford not to keep investing in."

The cyber mission force represents American ideals in cyberspace, he said. Keeping cyberspace open and free for everyone is its central focus, the defense secretary said.

"We're the ones who stand with those who create and innovate against those who would steal and destroy. That's the kind of country we are, and that's the kind of cyber force we are," he said.

"We're going to execute our mission while being as transparent as possible, because that's also who we are," Carter said.

"And that's why I wanted my remarks to you to be public," he told the troops. "That's an unusual thing for you, and I know that some of you can't be seen on television because of the nature of your work. And [that] it's rare that media come into the premises of this organization, but I wanted not only you to know how important we know what you do is for the country, but everyone else to hear that as well."

Monday, June 2, 2014

Operationalizing Cyber is New Commander's Biggest Challenge


Cheryl Pellerin at the American Forces Press Service officers the below piece:

WASHINGTON, June 2, 2014 - U.S. Cyber Command's greatest challenge is to operationalize cyberspace to turn the electro-digital network of networks into a command-and-control environment where warriors can see the adversary and whose operations defense leaders can integrate into options for commanders and policymakers, the new director of the National Security Agency and commander of U.S. Cyber Command said here last week.

Navy Adm. Michael S. Rogers was a keynote speaker May 28 at the Armed Forces Communications and Electronics Association 2014 Cyber Summit. The admiral told a large audience that he and his team are working to develop a set of five capabilities that will enable the teams of Cybercom to fight, if that becomes necessary, in cyberspace, which became a military domain in 2010 with the stand-up of Cybercom as a subunified command under U.S. Strategic Command.

Rogers also shared the early stages of an idea his team is working through to make part of the Defense Information Systems Agency, or DISA, a partner with Cybercom in defending DOD networks. "At U.S. Cyber Command, as the new guy, I've said we need to focus on what a subunified command should be doing and not doing. We've got to optimize, focus and prioritize, so let's ask ourselves what we're doing that we shouldn't be doing," Rogers said.

The admiral concluded that if Cybercom intimately focuses on tactical-level details of defending the network, it would not accomplish much more, and he turned to DISA. In its current role, he said, DISA is largely an acquisition and engineering organization. "I believe that for DISA to achieve what it needs to do with respect to how it's going to operate and help us defend the networks, a portion of DISA [must] become an operationalized entity focused on maneuvering and defending the networks," he said. "We have to give DISA the ability to come up with a command-and-control node that can coordinate with others in defending the DOD information networks."

The Cybercom commander said that in this role, DISA "could enable U.S. Cyber Command to function at the operational level of war. That's our niche and that's where I think we generate the best return and the best outcome." Cybercom teammates, including combatant commanders and service chiefs, eventually will discuss a more fleshed-out version of the idea, he added.

On Cybercom's greatest challenge, Rogers offered five capabilities that must exist if cyberspace is to become viable as a military domain. The first capability is a truly defensible network. "Today we are ... working with a series of networks in which redundancy, resiliency and defensibility were never core design characteristics," Rogers explained. "We often treat defensive capability as something that is literally bolted onto a system after we've done everything else."

The effort to create a defensible architecture is leading Cybercom to reduce its number of networks and to focus on areas where the networks have continuous public interfaces -- a source of particular vulnerability, Rogers added. OD's fledgling Joint Information Environment, or JIE, is a framework for modernizing DOD information technology systems and making them more secure. The system includes overarching architectures, standards and specifications; common ways of operating and defending DOD networks; and common engineered-solution designs.

"We've already created a JIE structure in Europe as a test. We're moving into the Pacific arena next and we'll continue to expand around the world," Rogers said. "We're trying to create a network in which defensibility, redundancy and resiliency are core design characteristics from the ground up." The second capability is common, shared situational awareness in cyberspace.

The admiral said that at every level of maritime operations, he's used to walking into a command center that gives him a common picture of a situation through the use of color, symbology and geography in a visual display that lets him quickly gain situational awareness and make decisions.

"We do not have that right now in the cyber arena," Rogers said. "As I used to kid my teammates, how do you defend something you can't see?" Cybercom is in the early stages of putting together such a capability, the admiral said, and it has proven to be a hard challenge. "We're certainly not as far along as I would like but it's not because of a lack of effort," Rogers said, adding that he's trying to bring together separate efforts to create the capability across the department. "In an era of declining resources we've ... got to do this together and we've got to divvy up who's going to do what," he added.

The third capability involves Cybercom's authorities and responsibilities to act. Within the Defense Department, Rogers said, he's comfortable with Cybercom's current authorities, "but when we start to go outside the department, it gets a little more complicated."

One mission set Cybercom anticipates receiving is in the event of attempts to disrupt critical infrastructure in the United States, the admiral said. "It is our expectation that we are training and working toward the ability to respond," he added, "and it is my expectation that potentially the president and the secretary of defense will turn to U.S. Cyber Command and say, ... 'We're seeing activity X, and need you to be part of the federal government's response to this.'" As a department, the admiral said, DOD routinely provides support to civil authorities in a multitude of mission areas, including hurricanes and wildfires. "I don't think cyber is going to be any different in that regard," Rogers said, "and I look for us to partner incredibly closely with our friends at the Department of Homeland Security, DHS, which is the lead for protecting federal networks" and for responding to cyber concerns outside the federal government. The FBI also plays an important role, he said.

DOD is measured in what it does within the United States versus what it does overseas, Rogers said, "and we've got to be mindful of [the Posse Comitatus Act] and this thing we call the law. We are not going to violate that." Under the Posse Comitatus Act, service members and National Guardsmen who are under federal authority can't perform in a law-enforcement capacity in the United States, unless the Constitution or Congress specifically authorizes it. "We've got to make sure the constructs we build enable us to work within the U.S. legal [system]," Rogers said, so he and his Cybercom team are discussing with officials at U.S. Northern Command, which has a primary mission of homeland defense, how best to work with federal government partners.

"But clearly," he added, "to work with other federal partners, we'll need some measure of authority and direction that we don't enjoy day to day." The fourth capability for operationalizing cyberspace, Rogers said, is to develop operational concepts and a command-and-control structure that takes operating in cyberspace from dream to reality.

As U.S. Cyber Command generates teams of warfighters to operate in cyberspace, its questions will include: Who will operate in cyberspace? How will command and control work there? How will cyber operations be prioritized? Who will make critical decisions about what Cybercom teams will and won't do in the cyber environment? What authorities are granted to which individuals? How will Cybercom make the chain of command clear to everyone operating in cyberspace?

None of this is unique to cyber, and for the military services, it's nothing new, but one thing that does make cyber especially challenging is a lack of physical geography, Rogers said. "In the DOD framework, we often use geography as a way to define responsibilities, carving the world up as regional combatant commands, ... and yet cyber doesn't recognize the geographic boundary thing," the admiral explained. "If I'm looking at potential attack strategies against critical infrastructure or ... DOD networks, I'm watching a path that bounces from a nation state, individual or group to infrastructure spread out in countries that aren't [our] particularly close friends or allies, then bounces into U.S. infrastructure, bounces out again, and then comes back in directly at the final target," Rogers said. U.S. Cyber Command must develop operational concepts and a command-and-control structure that recognizes this reality, he added. "Like any other military endeavor," Rogers said, "we tend to use intellectual thought, exercises and a variety of means in U.S. Cyber Command and among the broader partner teams ... to work our way through this."

The admiral added, "I tell the team, don't fixate on cyber as something unique that nobody understands. Ask yourself how we can translate [into the cyber arena] the operational concepts all of us have spent our lives in uniform learning and understanding as warfighters."

The fifth area critical to operationalizing cyber is to generate trained and ready forces, Rogers said, adding that generating such forces and deploying them to operational commanders is a service mission.

To accomplish the mission, Rogers has mandated the following three priorities:

-- Train everyone to the same set of standards. -- Conform to a team structure that divides 6,000 people into 133 teams that range in size from more than 60 individuals to about 20.

At U.S. Cyber Command, Rogers said, the goal is to have the 6,000 people trained and certified by the end of 2016. -- Generate capacities in the teams focused on defending the networks -- combatant commander networks, service networks, DISA networks, DOD enterprise networks, the DOD backbone, and, if needed, critical-infrastructure networks.

"This is hardest in some ways, because to truly defend a network takes a host of partners," Rogers said, "[and] ... synchronizing all areas of defense at one time is master's-level command and control in the cyber environment." The admiral said network defense may be Cybercom's most complicated task, "but I would argue it's the most important in some ways because we'll be tested every day on our ability to defend the department's networks and, if directed, defend other networks." 

Thursday, June 13, 2013

FBI On Preparing For And Responding To The Cyber Threat


Richard A. McFeely, the FBI's Executive Assistant Director, Criminal, Cyber, Response, and Services Branch (seen in the above FBI official photo), testified before the Senate Appropriations Committee on cyber security on June 12, 2013.

Good afternoon Chairwoman Mikulski, Vice Chairman Shelby, and members of the committee. I appreciate the opportunity to appear before you today to discuss the cyber threat, how the FBI has responded to it, and how we are marshaling our resources and strengthening our partnerships to more effectively combat the increasingly sophisticated adversaries we face in cyberspace.

As the committee is well aware, the frequency and impact of cyber attacks on our nation’s private sector and government networks have increased dramatically in the past decade, and are expected to continue to grow. Since 2002, the FBI has seen an 84 percent increase in the number of computer intrusion investigations.

Our adversaries in the cyber realm include spies from nation-states who seek our secrets and intellectual property; organized criminals who want to steal our identities and money; terrorists who aspire to attack our power grid, water supply, or other infrastructure; and hacktivist groups who are trying to make a political or social statement. It is difficult to overstate the potential impact these threats pose to our economy, our national security, and the critical infrastructure upon which our country relies. The bottom line is we are losing data, money, ideas, and innovation to a wide range of cyber adversaries and much more is at stake.

Director Mueller has said he expects the cyber threat to surpass the terrorism threat to our nation in the years to come. That is why we are strengthening our cyber capabilities in the same way we enhanced our intelligence and national security capabilities in the wake of the September 11th attacks.

You can read the rest of his statement via the below link:

http://www.fbi.gov/news/testimony/cyber-security-preparing-for-and-responding-to-the-enduring-threat?utm_campaign=email-Daily&utm_medium=email&utm_source=congressional-testimony&utm_content=232918

Thursday, May 9, 2013

FBI Responding To The Cyber Threat

 
John D. Memarest, the FBI's Assistant Director in charge of the Cyber Division, spoke before the Senate Judiciary Committee, Subcommittee on Crime and Terrorism, on May 8th.
 
The 21st century brings with it entirely new challenges, in which criminal and national security threats strike from afar through computer networks, with potentially devastating consequences. These intrusions into our corporate networks, personal computers, and government systems are occurring every single day by the thousands. Such attacks pose an urgent threat to the nation’s security and economy. The threat has reached the point that, given enough time, motivation, and funding, a determined adversary will likely be able to penetrate any system accessible from the Internet.
We see four primary malicious actors in the cyber world: foreign intelligence services, terrorist groups, organized criminal enterprises, and hacktivists.

Dozens of countries have sophisticated cyber espionage capabilities, and these foreign cyber spies have become increasingly adept at exploiting weaknesses in our computer networks. Once inside, they can exfiltrate government and military secrets, as well as valuable intellectual property—information that can improve the competitive advantage of state-owned entities and foreign companies.

Terrorist groups would like nothing better than to digitally sabotage our power grid or water supply. Although most such groups currently lack the capability to conduct sabotage operations over the Internet themselves, the tools and expertise to perpetrate a cyber attack with physical effects are readily available for purchase or hire.

Organized criminal groups, meanwhile, are increasingly migrating their traditional criminal activity from the physical world to the online world. They no longer need guns to rob a bank; they use a computer to breach corporate and financial institution networks to steal credentials, account numbers, and personal information they can use to make money.

These criminal syndicates, often made up of individuals living in disparate places around the world, have stolen billions of dollars from the financial services sector and its customers. Their crimes increase the cost of doing business, put companies at a competitive disadvantage, and create a significant drain on our economy.

Hacktivist groups are pioneering their own forms of digital anarchy, posing novel cybersecurity threats by repeatedly illegally accessing computers or networks for a variety of reasons, including politically or socially motivated goals.

With these diverse actors, we face significant challenges in our efforts to address and investigate cyber threats. While the FBI has already made great strides in developing its capability to address the cyber threat, we are currently prioritizing our immediate and long-term areas for strategic development in order to best position ourselves for the future. 

You can read the rest of the statement via the below link:

http://www.fbi.gov/news/testimony/responding-to-the-cyber-threat?utm_campaign=email-Daily&utm_medium=email&utm_source=congressional-testimony&utm_content=222787

Tuesday, October 18, 2011

My On Crime & Security Column: Thinking About Cyber Security

 
The web site AllBusiness.com published my latest On Crime & Security column this week.

The piece dealt with the threats to cyber security.

Speaking last April before the Senate Judiciary Committee's Subcommittee on Crime and Terrorism, FBI Assistant Director Gordon M. Snow stated that the number and sophistication of cyber attacks has increased dramatically over the past five years and he expected this trend to continue to grow.

"The threat has reached the point that given enough time, motivation, and funding, a determined adversary will likely be able to penetrate any system that is accessible directly from the Internet," Snow said. "It is difficult to state with confidence that our critical infrastructure - the backbone of our country's economic prosperity, national security, and public health - will remain unscathed and always be available when needed."

You can read the rest of the piece via the below link:

http://www.allbusiness.com/technology/security/16706741-1.html

Friday, June 3, 2011

Defense Department, Homeland Security Collaborate In Cyber Realm


By Donna Miles, American Forces Press Service

WASHINGTON, June 3, 2011 - Recognizing the huge national security implications of compromised U.S. computer networks, a senior Pentagon official said the Defense Department is working hand in hand with the Department of Homeland Security and others to shore up vulnerabilities against an increasingly sophisticated threat.

"Our focus is to ensure we can operate effectively in cyberspace, especially in areas of command and control" and other network-centric operations, Robert J. Butler, deputy assistant secretary of defense for cyber policy, told a Center for a New American Security forum yesterday.

Kristin M. Lord, coeditor of the center's new report, "America's Cyber Future: Security and Prosperity in the Information Age," told attendees that cyber threats endanger the enormous economic, social and military advances cyberspace enables for the United States and the world.

This can have severe implications across the board, including on the U.S. military, which depends on cyberspace to operate its communications, weapons, logistics and navigation systems. In a worst-case scenario, Lord noted, cyber attacks could disable critical equipment and even turn it against its users.

The Defense Department stood up U.S. Cyber Command under U.S. Strategic Command to focus directly on the challenges as well as opportunities in what DOD now recognizes as a fifth domain of warfare. The military services have aligned their capabilities as well, with 24th Air Force, U.S. Fleet Cyber Command, Marine Forces Cyber Command and Army Cyber Command/2nd Army all leading their respective services' efforts.

Butler (seen in the above DoD photo) cited a memorandum of understanding signed last fall that enables the Defense Department and Department of Homeland Security to better share information, expertise and capabilities.

The plan retains Homeland Security's lead responsibility for protecting the U.S. government's civilian networks and critical infrastructure. The Defense Department is responsible for protecting some 15,000 military networks in the so-called "dot-mil" domain. Under the agreement, the two agencies will collaborate to better safeguard cyberspace against state as well as nonstate actors.

Butler said this sharing arrangement will expand as Cyber Command grows and matures. He said he envisions more personnel-sharing between the two departments, and more collocating of employees to they can better conduct planning and share talents.

Rand Beers, undersecretary of Homeland Security's national protection and programs directorate, said his department, a relative newcomer to the cyber arena, gains tremendously through the whole-of-government approach to cyberspace, particularly its partnership with DOD.

"The bottom line is we couldn't do it without DOD because it is a team effort," he said.

A recent cyber attack on a network at Lockheed Martin Corp., a major U.S. defense contractor, had only a minimal impact, Butler said. The FBI is leading the investigation into the incident, which reportedly occurred May 2.