Showing posts with label cyberattacks. Show all posts
Showing posts with label cyberattacks. Show all posts

Thursday, July 27, 2017

CIA On Chinese Cyberspying


Veteran national security reporter Bill Gertz offers a piece in the Washington Times on Communist Chinese cyberespionage and other national security items.

A senior CIA analyst said China is continuing to conduct aggressive cyberespionage operations against the U.S., contrary to claims by security experts who say Beijing curbed cyberattacks in the past few years.

“We know the Chinese are very active in targeting our government, U.S. industry and those of our partners through cyberespionage,” said Michael Collins, deputy assistant CIA director and head of the agency’s East Asia Mission Center.

“It’s a very real, big problem, and we need to do more about it,” Mr. Collins told a recent security conference in Aspen, Colorado.

Mr. Collins said solving the problem of Chinese cyberattacks will require an “all-of-government, all-of-country approach to pushing back against it.”

The comments contradict a number of cybersecurity experts who have said Beijing’s digital spying and information theft decreased sharply as a result of the 2015 agreement between President Obama and Chinese President Xi Jinping.

The two leaders announced the cyber deal with great fanfare and said both countries had agreed to curtail cyberespionage against businesses.

You can read the rest of the piece via the below link:



Thursday, May 25, 2017

Cybercom: Pace of Cyberattacks Have Consequences For Military, Nation


Cheryl Pellerin at the DoD News offers the below report:

WASHINGTON, May 24, 2017 — The intensifying pace of international conflict and cyber events has consequences for the U.S. military and for the nation at large, Navy Adm. Michael S. Rogers (seen in the below photo), commander of U.S. Cyber Command, told a House panel yesterday.

Rogers, also director of the National Security Agency, testified before the House Armed Services Emerging Threats and Capabilities Subcommittee on the fiscal year 2018 Defense Department budget request for Cybercom and its Cyber Mission Force support for defense operations.


Facing Advanced Cyber Threats

“Hardly a day has gone by during my tenure at Cyber Command that we have not seen at least one significant cybersecurity event occurring somewhere in the world,” said Rogers, adding, “We face a growing variety of advanced threats from actors who operate with ever-more sophistication and precision.”

In his written testimony, the admiral said that cyber-enabled destructive and disruptive attacks now have the potential to affect the property, rights and daily lives of Americans.

“We are particularly concerned as adversaries probe and even exploit systems used by government, law enforcement, military, intelligence and critical infrastructure in the United States and abroad,” Rogers said.

“We have seen states seeking to shape the policies and attitudes of democratic peoples,” he added, “and we are convinced such behavior will continue for as long as autocratic regimes believe they have more to gain than to lose by challenging their opponents in cyberspace.”

Lines of Operation

Cybercom tracks state and nonstate adversaries as they expand their capabilities to advance their interests in cyberspace and try to undermine U.S. national interests and those of the nation’s allies, the admiral said.

Conflict in the cyber domain is unfolding according to its own logic, he added, “which we continue to better understand. And we're using this understanding to enhance the department's and the nation's situational awareness and to manage risk in the cyber arena.”

Cybercom forces conduct full-spectrum military cyberspace operations to enable actions in all domains, he told the panel.

The command’s three lines of operation are to provide mission assurance for DoD operations and defend the DoD information environment, called the DoDIN, to support joint force commander objectives globally and deter or defeat strategic threats to U.S. interests and critical infrastructure, Rogers said.

Enhanced Authorities

Rogers requested a budget of about $647 million for Cybercom for fiscal 2018, a nearly 16 percent increase from fiscal 2017 to fund Cybercom's elevation from a subcommand of U.S. Strategic Command to a full unified combatant command, as directed by the 2017 NDAA.

The enhanced budget will be used, in part, to continue building out the cyber mission force and adding cyber-specific capabilities and tools, and funding Joint Task Force Ares and the Cyber Combat Mission Force to support the fight against the Islamic State of Iraq and Syria.

Rogers created JTF-Ares after receiving an execute order in 2016 from then-Defense Secretary Ash Carter authorizing Cybercom to "task organize" for specific missions that could last to last weeks, months or longer, the admiral said in written testimony.

He established the new organization to coordinate cyberspace operations against ISIS, providing unity of command and effort for Cybercom and coalition forces working to counter ISIS in cyberspace.

Rogers said the JTF-model has helped Cybercom direct operations in support of Centcom operations, and “marks an evolution in the command-and-control structure in response to urgent operational needs.”

He told the panel that all cyber mission force teams are scheduled to be fully operational by the end of fiscal 2018, and named some of the enhancement of command responsibilities and authorities Cybercom expects in 2018.

These include increasing cyber manpower, enhancing professionalization of the cyber workforce, building defensive and offensive capability and capacity, and streamlining what Rogers called “cyber-operations-peculiar” acquisition capabilities.

“These are critical enablers for cyber space operations in a dynamically changing global environment,” the admiral said, “and most or all of these particulars have been directed in recent National Defense Authorization Acts.”

Operational Successes

Rogers told the panel that Cybercom’s operational successes have validated concepts for creating cyber effects on the battlefield and beyond.

“Innovations are constantly emerging out of operational necessity and real-world experiences,” he said, “and meeting the requirements of national decision makers and joint force commanders continues to mature our operational approaches and effectiveness over time.”

Cybersecurity is a national security issue requiring a whole-of-nation approach that brings together public and private sectors of U.S. society, Rogers said, noting that the Cybercom Point of Partnership program in Silicon Valley, California, and Boston has proven successful.

The initiative, he told the panel, “link[s] our command to some of the most innovative minds from industry, working together on cybersecurity as we face 21st Century threats together in the private and public sectors.”

This, Rogers added, “combined with agile policies, decision-making processes, capabilities and command-and-control structures will ensure that Cyber Command attains its potential to counter our adversaries.”

Friday, October 21, 2016

Authorities Monitoring Cyberattacks That Knocked Major Websites Offline


Andrea Noble at the Washington Times offers a piece on the cyberattacks that occurred today.

You can read the piece via the below link:

http://www.washingtontimes.com/news/2016/oct/21/authorities-monitoring-cyberattacks-major-websites/

Tuesday, March 12, 2013

U.S. National Intelligence Director Places Cyber Threats At The Top Of Transnational Threat List


Jim Garamone at the American Forces Press Service offers the below piece:

WASHINGTON, March 12, 2013 - Ten years ago, the idea that cyber posed a leading threat against the United States would be laughed at. But no one is laughing any more.

James R. Clapper, the director of national intelligence, testified before the Senate Select Committee on Intelligence today, and cyber led off his presentation of transnational threats.

Threats are more diverse, interconnected and viral than at any time in American history, the director said.

"Attacks, which might involve cyber and financial weapons, can be deniable and unattributable," he said in his prepared testimony. "Destruction can be invisible, latent and progressive."

In such a world, the role of intelligence grows, and finding ways to increase the efficiency of the intelligence community becomes paramount, Clapper said. "In this threat environment, the importance and urgency of intelligence integration cannot be overstated," he added. "Our progress cannot stop. The intelligence community must continue to promote collaboration among experts in every field, from the political and social sciences to natural sciences, medicine, military issues and space."

Clapper explained that cyber threats are broken into two terms: cyberattacks and cyberespionage. Cyberattacks aim at creating physical effects or to manipulate, disrupt or delete data. "It might range from a denial-of-service operation that temporarily prevents access to a website to an attack on a power turbine that causes physical damage and an outage lasting for days," he said. Cyber espionage refers to stealing data from a variety of sources.

The threat is growing, Clapper said, but is not here just yet. "We judge that there is a remote chance of a major cyberattack against U.S. critical infrastructure systems during the next two years that would result in long-term, wide-scale disruption of services, such as a regional power outage," Clapper said.

State actors with the skills to do this, such as Russia and China, are unlikely to launch such an attack, he said, and other states or organizations do not have these skills.

"However, isolated state or nonstate actors might deploy less sophisticated cyberattacks as a form of retaliation or provocation," he added. "These less advanced but highly motivated actors could access some poorly protected U.S. networks that control core functions, such as power generation, during the next two years, although their ability to leverage that access to cause high-impact, systemic disruptions will probably be limited."

A number of attacks already have taken place, including numerous denial-of-service attacks against U.S. banks. In August, someone attacked the Saudi oil company Aramco, rendering 30,000 computers unusable.

A more insidious cyber threat comes from foreign intelligence and security services that have penetrated numerous computer networks of U.S. government, business, academic and private-sector entities, Clapper said. "Most detected activity has targeted unclassified networks connected to the Internet, but foreign cyber actors are also targeting classified networks," he said. "Importantly, much of the nation's critical proprietary data are on sensitive, but unclassified, networks -- and the same is true for most of our closest allies."

Cyber thieves and spies are targeting and collecting sensitive U.S. national security and economic data, almost certainly allowing adversaries to close the military technological gap, Clapper said.

"It is very difficult to quantify the value of proprietary technologies and sensitive business information and, therefore, the impact of economic cyber espionage activities," he acknowledged. "However, we assess that economic cyber espionage will probably allow the actors who take this information to reap unfair gains in some industries."

U.S, intelligence agencies track cyber developments among terrorist groups, activist hackers and cyber criminals, the intelligence director said. "We have seen indications that some terrorist organizations have heightened interest in developing offensive cyber capabilities," he added, "but they will probably be constrained by inherent resource and organizational limitations and competing priorities."

Activist hackers -- known as "hacktivists," -- target a wide range of companies and organizations in denial-of-service attacks, but intelligence professionals have not observed a significant change in their capabilities or intentions during the last year, Clapper said.

"Most hacktivists use short-term denial-of-service operations or expose personally identifiable information held by target companies, as forms of political protest," he said, adding that this could change.

Cyber criminals also threaten U.S. economic interests. "They are selling tools, via a growing black market, that might enable access to critical infrastructure systems or get into the hands of state and non-state actors," the director said. Some companies abet these groups, he told the panel, selling computer intrusion kits to all comers.