Showing posts with label anti-virus software. Show all posts
Showing posts with label anti-virus software. Show all posts

Monday, October 9, 2017

A Mysterious Virus Has Infiltrated America's Drone Program

There’s something deeply wrong at Creech Air Force Base, the notorious home of America’s drone program, where pilots remotely order US Reaper and Predator drones to unleash destructive missile strikes on unsuspecting villagers in Yemen, Libya, Iraq, Syria, Afghanistan and other war zones.


Less than a week after the Department of Homeland Security advised all federal agencies using anti-virus software created by Kaspersky Labs to remove the programs from their systems immediately, Ars Technica reports that two weeks ago the Defense Information Systems Agency detected mysterious spyware embedded in the drone “cockpits” – the control stations that pilots use to control the deadly machines.



Investigators have been unable to determine the virus’s provenance, or even if it was intentionally introduced to the drone systems, or the result of an accidental infection. But perhaps the virus’s most perplexing feature is its passivity. Instead of hastening away reams of classified information, it has simply logged keystrokes.


More curious still, the virus has resisted all attempts to remove it from the Air Force’s systems.





The virus, first detected nearly two weeks ago by the military’s Host-Based Security System, has not prevented pilots at Creech Air Force Base in Nevada from flying their missions overseas. Nor have there been any confirmed incidents of classified information being lost or sent to an outside source. But the virus has resisted multiple efforts to remove it from Creech’s computers, network security specialists say. And the infection underscores the ongoing security risks in what has become the US military’s most important weapons system.



“We keep wiping it off, and it keeps coming back,” says a source familiar with the network infection, one of three that told Danger Room about the virus. “We think it’s benign. But we just don’t know.”



Military network security specialists aren’t sure whether the virus and its so-called “keylogger” payload were introduced intentionally or by accident; it may be a common piece of malware that just happened to make its way into these sensitive networks. The specialists don’t know exactly how far the virus has spread. But they’re sure that the infection has hit both classified and unclassified machines at Creech. That raises the possibility, at least, that secret data may have been captured by the keylogger, and then transmitted over the public internet to someone outside the military chain of command.



As Ars notes, drones have become America’s weapon of choice for waging stealth warfare across the Middle East and Africa, a fact that was underlined by the killing of four US green berets in Niger earlier this week. The military advisers were serving at a waystation for American drones that were used to carry out attacks on nearby Al Qaeda affiliates.





Drones have become America’s tool of choice in both its conventional and shadow wars, allowing US forces to attack targets and spy on its foes without risking American lives. Since President Obama assumed office, a fleet of approximately 30 CIA-directed drones have hit targets in Pakistan more than 230 times; all told, these drones have killed more than 2,000 suspected militants and civilians, according to the Washington Post. More than 150 additional Predator and Reaper drones, under US Air Force control, watch over the fighting in Afghanistan and Iraq. American military drones struck 92 times in Libya between mid-April and late August. And late last month, an American drone killed top terrorist Anwar al-Awlaki — part of an escalating unmanned air assault in the Horn of Africa and southern Arabian peninsula.



And while they represent America’s most sophisticated weaponry in the never-ending war on terror, the drone program has well-known security flaws. Last fall, the US Air Force investigated a secure network outage in early September at Creech. Around the time of the outage, there were three incidences of drones striking three unintended targets. The Air Force said it was just a coincidence. 





But despite their widespread use, the drone systems are known to have security flaws. Many Reapers and Predators don’t encrypt the video they transmit to American troops on the ground. In the summer of 2009, US forces discovered “days and days and hours and hours” of the drone footage on the laptops of Iraqi insurgents. A $26 piece of software allowed the militants to capture the video.



Authorities believe the virus was spread by the use of remote drives used by technicians to upload maps and other data to the drone piloting systems, which are “air gapped” from the rest of the Air Force’s systems.





Use of the drives is now severely restricted throughout the military. But the base at Creech was one of the exceptions, until the virus hit. Predator and Reaper crews use removable hard drives to load map updates and transport mission videos from one computer to another. The virus is believed to have spread through these removable drives. Drone units at other Air Force bases worldwide have now been ordered to stop their use.



But given the hysteria surrounding Kaspersky’s software allegedly being used as a tool for espionage by the Russian government, how long until this breach is connected with a broader narrative about Russian hackers trying to destabilize American society?


Or, worse – how much longer until a malicious actor manages to seize control of America’s drone program and harness its destructive capabilities for its own ends?

Thursday, September 21, 2017

Ban On Kaspersky Software Exposes The Hypocrisy Of US' Internet Agenda

Authored by Andrei Akulov via The Strategic Culture Foundation,


On September 18, the US Senate voted to ban the use of products from the Moscow-based cyber security firm Kaspersky Lab by the federal government, citing national security risk. The vote was included as an amendment to an annual defense policy spending bill approved by the Senate on the same day. The measure pushed forward by New Hampshire Democrat Jeanne Shaheen has strong support in the House of Representatives, which also must vote on a defense spending bill. The legislation bars the use of Kaspersky Lab software in government civilian and military agencies.



On September 13, a binding directive issued by Acting Secretary of Homeland Security Elaine Duke, ordered federal agencies to remove Kaspersky Lab products from government computers over concerns the Russia-based cybersecurity software company might be vulnerable to Russian government influence. All federal departments and agencies were given 30 days to identify any Kaspersky products in use on their networks. The departments have another 60 days to begin removal of the software. The statement says, «The department is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks». The Russian law does not mention American networks, nevertheless it is used as a pretext to explain the concern.


Similar bans against US government use of Kaspersky products have been suggested before. In 2015, Bloomberg News reported that the company has «close ties to Russian spies».


According to US News, scrutiny of the company mounted in 2017, fueled by U.S. intelligence assessments and high-profile federal investigations of Russian interference in the 2016 election. This summer, the General Service Administration, which oversees purchasing by the federal government, removed Kaspersky from its list of approved vendors. In June, a proposal prohibiting the US military from using the company"s products was reportedly included in the Senate"s draft of the Department of Defense"s budget rules. US intelligence leaders said earlier this year that Kaspersky Lab was already generally not allowed on military networks.


Kaspersky Lab has been producing widely lauded anti-virus software for 20 years. Today, it boasts 400 million customers around the world. Suspected of being involved in cyber espionage, the leading antivirus programs producer concluded that it was «caught in the middle of a geopolitical fight» and is being «treated unfairly even though the company has never helped, nor will help, any government in the world with its cyberespionage or offensive cyber efforts». Eugene Kaspersky, co-founder and CEO of Kaspersky Lab, has repeatedly denounced the allegations against his company as false and lacking credible or public evidence. He accepted the invitation to testify before the US House of Representatives Committee on Science, Space, and Technology. The testimony is scheduled on Sept. 27. Too late! Even if he proves that his company is innocent, the ban will be in force. It has been introduced without giving him a chance to speak on the issue and dissipate the fears.


Kaspersky highlighted that more than 85% of its revenue comes from outside Russia. The US measure will inevitably damage the company’s image and undermine the competitive position of the Russian company internationally. Best Buy has already said it will no longer sell software made by the Russian company.


All the decisions have been taken without giving the company a chance to openly address or mitigate the concerns. There has been no thorough investigation of its activities on US soil. No credible evidence has been presented to support the accusations. It all smacks of unfair competition. The Kaspersky Lab software is quite popular in the United States, and the company’s competitors will no doubt look to capitalize on this opportunity.


The move is part of anti-Russian hysteria that hit the United States. Kaspersky Lab has come under a politically-charged attack simply because it is Russian. Can anybody imagine Russia’s authorities saying that Apple and Microsoft were working hand in glove with the CIA and, therefore, their products were considered a security threat and should be banned?


A few months ago the authorities of New Hampshire, the state Jeanne Shaheen is from, were seriously considering a ban on Russian vodka imports and sales! Meanwhile, the US energy exporters use the Countering America"s Adversaries Through Sanctions Act to vie for the European energy market.


On August 14, President Trump signed a memorandum that directs US Trade Representative Robert Lighthizer to determine whether an investigation is needed into alleged unfair Chinese trade practices. The move represents the first step in a process that could allow the president to impose tariffs on Chinese imports or other punishing trade actions. The struggle for «fair trade practices» takes place against flagrant violations of international competition rules by the United States as illustrated by the unfair treatment of Kaspersky Lab.


At the same time, the US takes no measures against Microsoft, which is abusing its dominance in the PC operating system market, creating obstacles for independent software security vendors by distributing its own Defender anti-virus software with the ubiquitous Windows operating system.


The message has been sent. Hypocrisy at the core of US internet agenda is becoming untenable. It cannot continue to advocate for an open web, while at the same time using the tactics of unfair competition. The narrative that United States is the defender of free Internet appears to be dead.

Tuesday, May 2, 2017

Cyber Security (Better Than Musk)

By Chris at www.CapitalistExploits.at


I still remember my brother coming home with a cell phone.


It looked like a brick and weighed as much. But hell, was it cool. That was in the late 90"s.


The world today is almost unrecognisable in comparison.


Today, people are hyper connected all the time - streaming Kim Kardashian bending over in her yoga pants or listening to Justin Bieber (why, I cannot fathom). Using some app to help park the car, another to book a hotel, yet another to organise flight schedules, and - when the novelty of all of those has worn off - an app to organise getting laid. Revolutionary stuff!


And if that weren"t enough, while all this is going on you can wear a Fitbit which will record every minuscule thing you do and feed this information back to any device of your choosing in order for you to quantify just exactly how fat and appallingly lazy you actually are.


Not only that but we"ve not even begun to discuss the homes, shopping centres, airports, etc. all regulated with sensors controlling climate, security systems, and so on.


Now, I"ll readily admit to having almost none of these gadgets, partly because I"m mean and partly because I like to keep my life simple. 90% of this stuff doesn"t do that for me.


The other reason is experience has taught me that when the new iAnything comes out it costs $1.8bn new and within 24 months you can get it for a few hundred bucks - Moore"s law being what it is. And by then, I"ve determined I don"t really want it anyway. Problem solved.


Twenty years ago, we all thought we"d be in flying cars by now. Instead we got the smartphone, exquisitely designed to build the next generation of hunchbacks.



There is a beacon of light at the end of this tunnel, though.


Two things:


  1. Turn off the meaningless junk and recapture your life, and

  2. Realise nobody else will, which means that we"re dealing with a growth industry. Excellent!

Tell me, how dependent are you on technology?


Think about it seriously and remember that almost EVERYTHING is connected. Look around you and you"ll realise that EVERYONE is connected.


Take a look at this:



Did you know the IOT was this large? I didn"t.


Think about those 50+ billion connected devices - each of them a vulnerability point for breach of data.


As I"ve written recently, security is an area where nowhere near enough money is being spent. This will change.


I wrote about a private company I"ve invested in in the IOT sector of security, where I mentioned the following:





"The real bang for your buck will lie in artificial intelligence, machine learning, drones, and the integration of existing data sources."



It"s going to change because the risks are exponential.


Consider recent data hacks in the corporate sector:


  • eBay (NASDAQ:EBAY): 150 million passwords

  • JPMorgan Chase (NYSE:JPM): 73 million emails

  • Target (NYSE:TGT): 40 million credit card numbers

  • Yahoo (NASDAQ:YHOO): 1 billion accounts

Ok, so that"s the corporate sector. And remember for many companies simply admitting to hacks taking place renders them less trustworthy in the eyes of the consumer. Most CEOs would sooner admit to genital warts than admit to data breaches. Industry experts suggest the actual number of hacks taking place are far higher than being reported. I don"t doubt them.


Government


Chairman Trump isn"t the only guy to see that cyber security is important. Certainly Hillary figured that one out. It may have even contributed to her losing the election. Here"s what Trump says about cyber security:





"I will make certain that our military is the best in the world in both cyber offense and defense. I will also ask my Secretary of Defense and Joint Chiefs to present recommendations for strengthening and augmenting our Cyber Command."



He goes on to say:





"To enhance the defense of the other agencies of government, including our law enforcement agencies, we will put together a team of the best military, civilian and private sector cybersecurity experts to comprehensively review all of our cybersecurity systems and technology."



What Can We Do?


On a personal level we should be protecting ourselves. Get rid of the crap that brings no value to your life. Simply not using something reduces personal risk.


If you don"t know what I"m talking about, then I strongly suggest watching Snowden and Citizenfour, and jumping online to watch videos given by hackers. You"ll quickly realise how vulnerable we all are.


The simple stuff like using a firewall, anti-virus software, never using public Wi-Fi, and always using a VPN should be mandatory for any device we use. It"s just so easy to use public Wi-Fi, neglect using a VPN, but the risks are asymmetric to the downside. Like wearing a seatbelt, it doesn"t matter until, well, until it does.


Will this protect you from being hacked or your history being recorded and archived? No, but it"ll substantially decrease the risks.


Out of those listed topics above, the only one I"ve had some issues with over the years has been the use of VPNs. I"ve used a number of different ones and, like anything, some work better than others, often depending on your location. I recently found what is I think the best I"ve used so far, but whatever you use, I think using a firewall, anti-virus software, and then neglecting a VPN is silly.


How to Invest


While I"m not sure this qualifies as asymmetric in nature I do think that we"re looking at a growth industry.


Here is a good resource with a host of forecasts and trends in the IOT industry.


Estimates of the current size of the IOT market range from $600 billion to $900 billion. Even if we"re working at the low end of that range, consider that the two largest ETFs in the cyber security space total a combined $870 million. That"s it.


That"s nothing!


Heck, Enron On Wheels" market cap is now north of $50 billion and they make cars (barely) with other peoples" parts. I"d gladly pair trade these over the next decade. Long HACK and CIBR and short TSLA.


In any event, here"s HACK:



And CIBR:



There are pros and cons to them. HACK has more liquidity, is larger in size but charges a higher expense ratio than CIBR.


Why look at ETFs?


Remember Betamax? Killed by VHS which DVDs then sent to the grave.


You want to be involved in the growth of the sector but unless you are going to dedicate your time to really understanding all the movers and shakers in that sector, diligencing balance sheets, earnings statements, competing technologies, and the like, then you"re better off making a sector bet.


If you want a set and forget play, then buying the ETF means you"re just making a sectorial bet not betting on Betamax in 1977 just as VHS was being released.


Either way, cyber security is likely to do really well over the coming years. It"s a war hedge, an innovation play, and, as long as the IOT space continues to grow cyber security, will become an increasingly required service sector.


- Chris


"There are only two types of companies. Those that have been hacked and those that will be." — Robert Mueller, FBI Director 2012


--------------------------------------


Liked this article? Don"t miss our future missives and podcasts, and


get access to free subscriber-only content here.


--------------------------------------