630-3 Yhtomit
INTRODUCTION TO PART II
THREATS AND VULNERABILITIES
What are the practical, technical problems faced by security practitioners? Readers are introduced to what is known about the psychological profiles of computer crim- inals and employees who commit insider crime. The focus is then widened to look at national security issues involving information assurance—critical infrastructure protection in particular. After a systematic review of how criminals penetrate secu- rity perimeters—essential for developing proper defensive mechanisms—readers can study a variety of programmatic attacks (widely used by criminals) and methods of deception, such as social engineering. The section ends with a review of widespread problems such as spam, phishing, Trojans, Web server security problems, and physical facility vulnerabilities (an important concern for security specialists, but one that is often overlooked by computer-oriented personnel).
The chapter titles and topics in Part II include:
12. The Psychology of Computer Criminals. Psychological insights into motiva- tions and behavioral disorders of criminal hackers and virus writers
13. The Insider Threat. Identifying potential risks among employees and other authorized personnel
14. InformationWarfare.Cyberconflict and protection of national infrastructures in the face of a rising tide of state-sponsored and non-state-actor industrial espionage and sabotage
15. Penetrating Computer Systems and Networks.Widely used penetration tech- niques for breaching security perimeters
16. Malicious Code. Dangerous computer programs, including viruses and worms, increasingly used to create botnets of infected computers for spreading spam and causing denial of service
17. Mobile Code. Analysis of applets, controls, scripts, and other small programs, including those written in ActiveX, Java, and Javascript
18. Denial-of-Service Attacks.Resource saturation and outright sabotage that brings down availability of systems and that can be used as threats in extortion rackets by organized crime
II · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
II · 2 THREATS AND VULNERABILITIES
19. Social-Engineering and Low-Tech Attacks. Lying, cheating, impersonation, intimidation—and countermeasures to strengthen organizations against such at- tacks, which have increased drastically in recent years
20. Spam, Phishing, andTrojans: AttacksMeant to Fool.Fighting spam, phishing, and Trojans—trickery that puts uninformed victims at serious risk of fraud such as identity theft
21. Web-Based Vulnerabilities. Web servers, and how to strengthen their defenses 22. Physical Threats to the Information Infrastructure. Attacks against the infor-
mation infrastructure, including buildings and network media
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12CHAPTER
THE PSYCHOLOGY OF COMPUTER CRIMINALS
Q. Campbell and David M. Kennedy
12.1 INTRODUCTION 12 ·1
12.2 SELF-REPORTED MOTIVATIONS 12 ·3
12.3 PSYCHOLOGICAL PERSPECTIVES ON COMPUTER CRIME 12 ·4
12.4 SOCIAL DISTANCE, ANONYMITY, AGGRESSION, AND COMPUTER CRIME 12 ·4 12.4.1 Social Presence and
Computer Crime 12 ·6 12.4.2 Deindividuation and
Computer Crime 12 ·6 12.4.3 Social Identity Theory
and Computer Crime 12 ·7 12.4.4 Social Learning
Theory of Computer Crime 12 ·8
12.5 INDIVIDUAL DIFFERENCES AND COMPUTER CRIMINALS 12 ·9 12.5.1 Antisocial and
Narcissistic Personalities 12 ·9
12.5.2 Five-Factor Model of Personality and Computer Criminals 12 ·10
12.5.3 Asperger Syndrome and Computer Criminals 12 ·11
12.5.4 Internet Abuse and Computer Crime 12 ·12
12.6 ETHICS AND COMPUTER CRIME 12 ·14
12.7 CLASSIFICATIONS OF COMPUTER CRIMINALS 12 ·16 12.7.1 Early Classification
Theories of Computer Criminals 12 ·17
12.7.2 Rogers’s New Taxonomy of Computer Criminals 12 ·19
12.7.3 Hacktivists and Cyberterrorists: Hacking for a Cause 12 ·20
12.7.4 Dangerous/Malicious Insiders (DI/MI) 12 ·21
12.7.5 Virus Creators 12 ·22
12.8 RECOMMENDATIONS 12 ·24
12.9 FURTHER READING 12 ·26
12.10 NOTES 12 ·26
12.1 INTRODUCTION. Symantec’s Internet Security Threat Report for 2011 indicated an 81 percent increase in network attacks compared to 2010; this, coupled with a reported 187million identities that were exposed due to outsider attacks, sug- gests that the threat of computer crime is growing to unprecedented levels.1 For the most part, the industry has relied upon legal and technological solutions to reduce the risks to information security. An alternate approach is to target the human element;
12 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 2 THE PSYCHOLOGY OF COMPUTER CRIMINALS
to try to understand the psychological motivations behind those who would exploit these technologies and to design security system accordingly.2 The main drawback to this approach is that the information security field has traditionally relied on outdated stereotypes of computer criminals, which have lead to convoluted, overgeneralized, and inaccurate portrayals of these individuals. Contributing to this is the industry’s over- simplification of computer crime and its reliance on a generic, all-encompassing view of the computer criminal. The computer underground is a vast and varied landscape that comprises many different subgroups, some of which are infantile and benign, and others that are criminal and destructive. The purpose of this chapter is to identify the various subgroups of computer criminals and to examine their differing motivations from a psychological perspective. Using theoretical perspectives from social, person- ality, and clinical psychology, we will review current research on the various subsets of computer criminals, ranging from script kiddies to malicious insiders, and provide recommendations for addressing the problem of computer crime at its source.
The National Institute of Justice defines a computer criminal as any individual who uses computer or network technology to plan or perpetrate a violation of the law.3 Although the term computer hacker is often used interchangeably with computer criminal, they are not synonymous. The term hackerwas originally used as an umbrella term to refer to a computer programmer who changes or alters code (i.e., hacks) in a unique or unorthodox fashion to solve a problem or to enhance its use. Such interventions may be legal or illegal depending on the circumstances, intent, outcome, or use of the hacked program.
Although a computer criminal, or cracker, sometimes also referred to as amalicious or criminal hacker, may fall under this broad definition, these individuals typically alter or exploit technology for destructive purposes or financial gain rather than for benign or creative functions. Common examples of computer crimes includeWeb page defacements, creation and distribution of viruses, unauthorized access of technology, theft of information, distributed denials of service (DDoS), and so on.
In recent years, computer security analysts have reported that many computer crim- inals are moving away from the hacking-for-fun-and-notoriety mindset to hacking for profit.4 More recently, activist groups (hacktivists) have used the Internet as a way of spreading their messages of social and political discord by engaging in digital harass- ment of their targets. According to the 2012 “Verizon Data Breach Report,” hacktivist groups represent a significant threat to network security, accounting for the majority of data thefts occurring in 2011.5,6
Computer crime is an obvious financial and societal problem that shows no signs of slowing. Researchers suggest that computer attacks will continue to grow in frequency and sophistication as technology continues to evolve. More specialized threats to social networks, peer-to-peer networks (P2P), handheld mobile devices, and nontraditional hardware systems (e.g., networked gaming consoles and point of sale devices), have been identified in the wild with increasing regularity.7 Douglas Campbell, president of the Syneca Research Group Inc., states that “the dominant threat to the United States is not thermonuclear war, but the information war.”8,9
One solution that has been offered as an effort to slow this disturbing trend is to examine the motivations of computer criminals from a psychological perspective. Computer-crime researchers suggest that understanding the psychological motivations behind cyber criminals would aid in both cybercrime prevention and protection.10,11
Generating a psychological profile of the various subtypes of computer criminals would aid in creating preventive initiatives as well as more effective countermeasures in the fight against computer crime. Since computer crime is not solely a technological
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SELF-REPORTED MOTIVATIONS 12 · 3
issue but one involving human agents, psychological theories regarding anonymity, aggression, social learning, and individual difference factors may enable us to better understand the behaviors and motivations of the computer criminal.
Information security consultant Donn Parker asserts that the creation of an effective malicious hacker profile still remains an elusive goal in the information security field.12
Therefore, the goal of this chapter is to survey past and current literature surrounding the psychological motivations of computer criminals. Theories from criminology, as well as social, personality, and clinical psychology, will be presented in an attempt to explain some of the possible motivations behind computer criminals. Based on these psychological research studies, we will conclude by offering recommendations for attenuating computer crime from the perspective of the perpetrator.
12.2 SELF-REPORTED MOTIVATIONS. Perhaps the simplest approach to un- derstanding the mindset of computer criminals is having the perpetrators describe their motivations in their own words. Using various self-reporting measures, including surveys, open-ended questionnaires, and first-person interviews, researchers have con- sistently found a number of common accounts used by computer criminals to explain and justify their illicit and sometimes harmful behaviors.13,14,15,16
According to sociologist Paul Taylor, computer criminals report that they are mo- tivated by an interacting mix of six primary categories: addiction, curiosity, boredom, power, recognition, and politics.17 Using a phenomenological-interpretive interview approach that emphasizes the interviewee’s perception of reality, sociologist Orly Turgeman-Goldschmidt similarly found that computer criminals reported curiosity, thrill seeking, the need for power, and the ideological opposition to information restric- tions among the motivations for their behaviors.18 Taylor suggests that the extensive use of computers by these criminals may result from a combination of both compulsive behaviors and intellectual curiosity. From an outsider’s perspective, an advanced com- puter user’s need to meet the swiftly changing demands of the computer industry may appear to be an indicator of computer abuse, when in actuality the constant use of tech- nology is a consequence of the field. A relentless curiosity and desire for technological improvement is often used by computer criminals as a motivation for their behaviors.19
Anecdotal evidence has also suggested that the frustrations that result from restrictive computing environments (e.g., network or Internet filters), coupled with a lack of suf- ficient intellectual stimulation, contribute to some computer criminals’ unauthorized access attempts. Some reformed computer criminals have indicated that once they were provided with more liberal access to technology, they were able to focus their skills on practical and legal endeavors rather than illicit undertakings.20
In one of the most ambitious efforts to understand the mindset of criminal hack- ers, computer security consultant and reformed computer criminal Raoul Chiesa and colleagues created the Hacker’s Profiling Project (HPP).21 The aim of the HPP was to utilize criminal profiling techniques to develop a comprehensive profile of criminal hackers. Chiesa developed a questionnaire that was judiciously distributed to known criminal hackers and asked questions regarding personal demographics, technological skill, criminal history, and social relationships. The research revealed again that some of the main motivations of criminal hackers are curiosity, proving their self-worth to themselves and others, and feelings of adventure. These relatively benign motivations are also coupled with feelings of anger, frustration, and rebellion against authority. For many of these individuals, the Internet is viewed as the great equalizer. Because of the reduced social context cues that guide face-to-face interactions, Internet users are judged more on their technological skills rather than their social skills, gender, or
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 4 THE PSYCHOLOGY OF COMPUTER CRIMINALS
ethnicity. For a more comprehensive looked at the results of the HPP, see the recently published book Profiling Hackers.22
Contrary to their stereotypical portrayals in the news media and in fiction, computer criminals appear to havewide-ranging social networks that exist in both their online and offline environments.23,24 Taylor indicates that both the need for power and recognition by their peers may be motivating factors for some cybervandals. Computer criminals report feelings of enjoyment and satisfaction when they prove themselves better than system administrators and their peers. Communications researchers Hyung-jin Woo, Yeora Kim, and Joseph Dominick report in their analysis of Webpage defacements that 37 percent of the prank-related defacements contained messages that bragged or taunted the system administrators. Twenty-four percent of these types of defacements contained statements aimed at obtaining peer recognition and 8 percent contained boastful and self-aggrandizing verbiage.25
12.3 PSYCHOLOGICAL PERSPECTIVES ON COMPUTER CRIME. Al- though self-reporting analyses can give us some insight into the motivations behind computer criminals, these types of descriptivemethodologies typically yield incomplete and sometimes inaccurate results. Unless the causes for our behaviors are obvious, our explicit or consciously held explanations for our actions are often misguided. Research has found that our behaviors are frequently controlled by subtle situational variables and implicit attitudes of which we are not typically aware, and may be distinctly dif- ferent from the conscious mechanisms we use to explain our actions.26 Therefore, our conscious justifications for our actions may be inaccurate if we are unaware of more subtle cognitive processes. The next section examines more empirically based psychological theories of aggression and deviance to gain a further understanding of the factors that may be influencing the behaviors of computer criminals.
12.4 SOCIAL DISTANCE, ANONYMITY, AGGRESSION, AND COM- PUTER CRIME. Many acts of computer crime can be categorized as demonstra- tions of aggressive behaviors. For example, cracking into a company’s Web server and defacing a Web page, or launching a DDoS attack on an organization’s computer net- work, thereby crippling its Internet connection, are common malicious and aggressive acts engaged in by computer criminals. Social psychological theories on hostility and violence suggest that people are more likely to commit acts of aggression when the perpetrator of these acts is anonymous and the threat of retaliation is low.27 Since cy- bervandals frequently use nicknames (nicks or handles), stolen accounts, and spoofed Internet Protocol (IP) addresses when they engage in illegal activities, their behaviors may be more aggressive than when they are more easily identifiable. Computer crim- inals are overly confident that their crimes cannot and will not be traced back to their true identities. Computer criminals who deface Web pages are so confident that they are anonymous that they regularly tag the hacked Website by leaving their handles and the handles of their friends, and in some cases, even their Internet email addresses and Web page links.28
Due to the relative anonymity of the Internet and the technical abilities of cybercrim- inals, which enable them to further obfuscate their identities, the resulting emotional distance may be another factor that contributes to increased aggression online. For example, it is an extremely difficult and tedious task to identify computer criminals who launch DDoS attacks against computer networks. The attacker plants denial-of- service (DoS) programs into compromised shell accounts controlled by a master client. The master client will instruct every slave DoS program to cooperatively launch an
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SOCIAL DISTANCE, ANONYMITY, AGGRESSION, AND COMPUTER CRIME 12 · 5
attack at the victim’s host at a configurable time and date. Thus, the DoS attacks are not launched by the criminal’s own computer; rather, the attacks come from innocent networks that have been compromised by the cracker. This additional layer makes it all the more difficult for information-security professionals to locate the attack’s perpetra- tor. Much like the Website vandals, DDoS attackers are also confident that the attacks will not be traced back to their actual identities. Frequently, DDoS attackers will even brag on Internet Relay Chat (IRC) channels and Twitter about how many host nodes they have compromised and against which domain they are planning to launch new attacks.29
Situational influences on behaviors and attitudes work on the Internet much as they do in the real world. However, computer criminals who commit aggressive acts against their innocent victims do not see the immediate consequences of their actions. The computer screen and increased social distance that characterize interactions online can act as an electronic buffer between the attacker and victim. Like the participants in psychologist Stanley Milgram’s famous obedience experiment, computer criminals are physically and emotionally removed from their victims while they are committing their harmful actions.30 They do not witness firsthand the consequences of their computer- ized attacks. Automated cracking and DDoS scripts, coupled with the lack of social presence in computer-mediated interactions, may make it easier to attack an entity that is not only emotionally and physically distant, but also depersonalized (e.g., a system administrator working for a large corporation).
Consistent with social psychologist Albert Bandura’s theory of moral disengage- ment, individuals who engage in unscrupulous behaviors will often alter their thinking in order to justify their negative actions.31 According to Bandura, most individuals will not commit cruel or illicit behaviors without first engaging in a series of cognitive justification strategies that allow the person to view those actions as moral and just. Immoral behaviors can be justified by comparing them to more egregious acts, mini- mizing the consequences of the actions, displacing responsibility, and by blaming the victim themselves. Criminologist Marc Rogers posits that computer criminals may rely on a number of these disengagement strategies in an attempt to reduce the dissonance associated with their malicious activities.32
Studies conducted by sociologists Paul Taylor and Orly Turgeman-Goldschmidt suggest that many computer criminals are, in fact, engaging in forms of moral disengagement.33,34 Their interviewees report that computer crime is driven by a search for answers and spurs the development of new technologies. They further indicate that their electronic intrusions cause no real monetary harm or damage to the victims, and that larger corporations that can afford any financial losses that are incurred from their digital transgressions. Web page crackers will often criticize and publicly taunt the system administrators for not properly securing their computers, suggesting that the victims deserved to be attacked.35 Rogers suggests that this victim-blaming strategy is likely the most common form of moral disengagement that is employed by computer criminals.36
A study conducted by information technology researcher Randall Young and col- leagues confirmed that computer criminals have amorally distorted viewof their deviant activities, enabling them to socially justify their digital exploits.37 Self-identified com- puter criminals attending a computer conference reported significantly higher levels of moral disengagement than a control group of university students. The self-identified criminals strongly felt that their digital intrusions were actually helpful to the compa- nies that they invaded and that their friends and families would not think negatively of them if they were caught engaging in illegal computer hacking.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 6 THE PSYCHOLOGY OF COMPUTER CRIMINALS
12.4.1 Social Presence and Computer Crime. Social psychologist Sara Kiesler and colleagues found that during face-to-face (FTF) interactions, conversants implicitly attend to social context cues (e.g., facial expressions and intonations) and use them to guide their social behaviors. Since these social context cues are absent or reduced during computer-mediated interactions, digital communication may be more deregulated than FTF discussions.38,39 Kiesler and Lee Sproull suggest that the absence of social-context cues in computer-mediated communication hinders the perception of and adaptation to social roles, structures, and norms.40 The reduction of social-context cues in computer-mediated communication can lead to deregulated behavior, decreased social inhibitions, and reduced concern with social evaluation. The most common variables examined in their experiments were hostile language in the form of “flaming” (aggressive, rude, and often ad hominem attacks) and post hoc perceptions of group members (i.e., opinions formed after interacting with members). One empirical study found that group members communicating via computer-mediated communication were more hostile toward one another, took longer to reach decisions, and rated group members less favorably than comparable face-to-face groups.41 Another experiment reported that there were 102 instances of hostile communication during computer- mediated interactions, compared to only 12 instances of hostile commentary during comparable FTF discussions.42
Based on Kiesler’s findings, computer criminals may be engaging in hostile behav- iors partly due to this reduction of available context cues. Crackers who harass and victimize system administrators and Internet users may be engaging in these antisocial activities due to the reduced attention to and concern with social evaluations. There are numerous anecdotal accounts of computer criminals “taking over” IRC channels, harassing people online, deleting entire computer systems, and even taunting system ad- ministrators whose networks they have compromised.43 Their criminal and aggressive behaviors may be partially attributed to the reduced social context cues in computer- mediated communication and the resulting changes in their psychological states (i.e., deindividuation) while online.
12.4.2 Deindividuation and Computer Crime. Disinhibited behaviors have also been closely linked to the psychological state of deindividuation. Dein- dividuation is described as a loss of self-awareness that results in irrational, aggressive, antinormative, and antisocial behavior.44,45 The deindividuated state traditionally was used to describe the mentality of individuals who comprised large riotous and hostile crowds (e.g., European soccer riots, mob violence, etc.). Social psychologist Phillip Zimbardo suggested that a number of antecedent variables, often characteristic of large crowds, lead to the deindividuated state. The psychosocial factors associated with anonymity, arousal, sensory overload, loss of responsibility, and mind-altering sub- stances may lead to a loss of self-awareness, lessening of internal restraints, and a lack of concern for social or self-evaluation.46
The factors associated with deindividuation also appear to be present during some online activities. For instance, Internet users are relatively anonymous and often use handles to further obscure their true identities. Many of the Websites, software pro- grams, and multimedia files that typify the computing experience are sensory arousing and in some cases can be overstimulating. The Internet can be viewed as a large global crowd that individuals become submersed in when they go online. It is possible that the physical and psychological characteristics associated with the Internet that make it so appealing may also lead individuals to engage in antisocial and antinormative behaviors due to psychological feelings of immersion and deindividuation.47
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SOCIAL DISTANCE, ANONYMITY, AGGRESSION, AND COMPUTER CRIME 12 · 7
Deindividuation is brought about by an individual’s loss of self-awareness, and psychological immersion into a crowd due to the aforementioned antecedents.48 The aggressive, hostile, and antinormative actions of computer criminals may be linked to the denindividuated state. Zimbardo found that when participants were deindividuated, operationalized by anonymity, darkness, and loud music, they would administer higher levels of electric shocks to subjects, and for longer lengths of time, than individuated participants. Like Zimbardo’s participants, computer criminals may be engaging in hostile and aggressive behavior due to deindividuation—that is, as a direct result of anonymity, subjective feelings of immersion, and the arousing nature of computer and Internet use.49,50
12.4.3 Social Identity Theory and Computer Crime. Social psychol- ogists Martin Lea, Tom Postmes, and Russell Spears have recently developed a social identity model of deindividuation effects (SIDE) to explain the influence of deindividuating variables on behaviors and attitudes during computer-mediated communications.51,52,53 According to social identity theory, an individual’s self- concept resides on a continuum with a stable personal identity at one end and a social identity at the other. Depending on whether the social self, usually in group situations, or individual self is salient, the beliefs, norms, and actions associated with that particular self-concept will have the greatest influence on the individual’s actions and attitudes.54 When one of our social identities is salient, the norms associated with that group identity tend to guide and direct our behaviors.
According to the SIDE model, the isolation and visual anonymity that characterizes our online environment serves to enhance our social identities. This increase in social identification with a group may polarize our behaviors and attitudes toward the prevail- ing norms of that collective.55,56,57 Contrary to popular media stereotypes, computer criminals appear to have large social networks and frequently form groups and friend- ships with other like-minded individuals.58 The use of handles and pseudonyms by these individuals combined with their physical isolation from each other may increase their aggressive and criminal tendencies depending on the overall norms associated with their online social groups. If the criminal collective values electronic intrusions and defacements more than programming and coding, then these behaviors will be exhibited to a greater extent by members who strongly identify with that group.
According to Henri Tajfel and John Turner’s social identity theory (SIT), we tend to identify with ingroups, or those with whom we share common bonds and feelings of unity.59 We have a bias toward our own group members and contrast them with outgroups, whom we perceive as different from those in our ingroup. While this ingroup bias or favoritism may benefit and protect our self-concepts, it may cause us to dislike and unfairly treat outgroup members (e.g., network administrators).
Communications researcher Hyung-jin Woo and colleagues used SIT to explain the motivations behind some Web page defacements.60 SIT predicts that when groups are in competition for scarce resources, or feel threatened by outgroup members, there is a tendency for groups to respond aggressively toward each other. Ingroup members see improvements in collective self-esteem and enhanced feelings of group unity when they engage in attacks against outgroup members. Based on these predictions, Woo and colleagues hypothesized that computer criminalswho aremotivated by outgroup threats will express more aggressive and varied communication inWeb page defacements than nonthreatened defacers.61
A content analysis of 462 defaced Web pages indicated that the majority of the defacements (71 percent) were classified as nonmalicious pranks. The most common
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 8 THE PSYCHOLOGY OF COMPUTER CRIMINALS
motivations behind these prankster attacks were to beat the system or its administrator, to gain peer recognition, to brag about accomplishments, and for romantic purposes. Twenty-three percent of the defacements were classified as militant attacks. The mo- tivations behind these attacks were to promote groups associated with nationalism, ethnicity, religion, freedom of information, and anti-pornography.62 Consistent with the predictions made by SIT, the militant attacks were characterized by significantly more varied content, obscene language, insults, severe threats, and violent images. SIT may be useful in predicting the frequency and severity of attacks by computer crim- inals. Although only a minority (23 percent) of Web page defacements in this study resulted from intergroup conflict, those attacks were more severe in nature.63
12.4.4 Social Learning Theory of Computer Crime. Criminologist Marc Rogers suggests that social learning theory (SLT) may offer some insight into the be- havior of computer criminals.64 According to psychologist Albert Bandura, individuals learn behaviors by observing the actions of others and their associated consequences.65
SLT draws from B. F. Skinner’s operant-conditioning model of learning where behav- iors are learned or extinguished through schedules of reinforcement and punishment. However, Bandura’s theory suggests that social learning occurs when an individual simply observes others’ behaviors and reinforcements and forms a cognitive asso- ciation between the two actions. Once the behavior is acquired, the learned actions are subject to external reinforcement, as in operant conditioning or in self-directed reinforcement.66 According to the Social Structure and Social Learning model (SSSL), criminals learn deviant behaviors from their associations and subsequent imitations of deviant peers.67 Through these peer associations, individuals learn to rationalize crim- inal behaviors. As Bandura suggests, if these criminal activities are rewarded (e.g., money, increased status, etc.), then the behavior will be strengthened.
Recently, there has been a growing amount of social and media attention focused on information security and computer criminals. Newspapers, magazines, and electronic news sources have reported thousands of incidents, interviews, and commentary re- lated to computer crime. A number of these articles appear to glamorize hacking and the Internet underground.68 The articles compare computer criminals to rock-and-roll superstars, James Bond-like spies, and international freedom fighters. Motion pictures and television shows like The Matrix Trilogy, Mission Impossible, Hackers, Swordfish, and The X-Files have all bestowed mythical qualities on rebellious computer criminals, while media outlets report computer criminals being recruited for high-paying gov- ernment and industry jobs.69 The media’s glorification and glamorization of hacking and computer criminals, teaches some individuals that it pays to commit computer crime—at least, from a social learning perspective.
Many crimes involving computers are difficult to investigate and prosecute. The public learns via the media that computer criminals often are afforded fame and noto- riety among their peers, and in the information security field, for their illegal activities. There are very few instances of computer criminals’ being convicted and serving jail time as a consequence of their actions; usually the criminals are given light sentences. Their notoriety leads to media interviews, book and movie deals, even consulting and public speaking jobs.70 Once an action is learned, SLT states that the behavior will be maintained via self-directed and external reinforcement. If computer criminals are rewarded for their illegal activities via the acquisition of knowledge and their elevated status in the hacker community, and the popular media continues to glamorize and focus on the positive consequences associated with computer crime, then the cost and prevalence of these illicit actions will continue to grow. Lending empirical support
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
INDIVIDUAL DIFFERENCES AND COMPUTER CRIMINALS 12 · 9
to the social learning model, criminologist Thomas Holt found that the four tenets of the SSSL model reliably predicted cyberdeviance in a college population. Students who associated with cybercriminals, imitated cyberdeviants, held morally ambiguous definitions regarding cybercrime, and had their computer-based deviance reinforced, were more likely to engage in online criminal activities.71
SLT may offer one explanation for the illegal behaviors of computer criminals, especially the marked increase in recent years.72 Instead of focusing on the suppos- edly positive consequences of computer crime, media outlets should stress the negative repercussions of computer crime for both the victims and the perpetrators. Social learn- ing theorists would suggest modeling appropriate use of computers and the immediate negative ramifications of cyberdeviance as one element for fighting computer crime.
12.5 INDIVIDUAL DIFFERENCES AND COMPUTER CRIMINALS. Al- though situational factors can account for some of the behaviors of some computer criminals, one must not discount the impact of personality factors on their illicit activ- ities. Attitudes and behaviors are often the product of both situational influences and individual personality traits.73 It should be noted that there are few empirical studies that engage in a scientific examination of the personality traits of computer criminals, so without concrete evidence, the anecdotal claims regarding pathological traits of cybercriminals should be interpreted with caution. In addition, simply having traits that are consistent with a psychological disorder does not mean that one actually has the disorder.
12.5.1 Antisocial and Narcissistic Personalities. According to M. E. Kabay, some computer criminals exhibit insincerity and dishonesty in combination with superficial charm and an enhanced intellect, traits that are consistent with the Diagnostic and Statistical Manual of Mental Disorders IV (DSM-IV) criteria for anti- social personality disorder.74 He also notes that some computer criminals commit their illegal behavior for little or no visible rewards despite the threat of severe punishment.
Another central characteristic of antisocial personality disorder is lack of clear in- sight by perpetrators regarding their behaviors.75 Researchers have noted that computer criminals do not view their criminal actions as harmful or illegal.76,77 These criminals sometimes rationalize or externalize their behaviors by blaming the network adminis- trators and software designers for not properly securing their computers and programs.
Computer crime researchers Eric Shaw, Keven Ruby, and Jerrold Post also have sug- gested that some computer criminals demonstrate personality characteristics consistent with some elements of narcissistic personality disorder.78,79 According to DSM-IV criteria, narcissistic individuals are attention seekers with an exaggerated sense of entitlement.80 Entitlement is described as the belief that one is in some way privileged and owed special treatment or recognition.
Shaw and associates suggest that entitlement is characteristic of many “dangerous insiders,” or information technology specialists who commit electronic crimes against their own organizations.81 When corporate authority does not recognize the work or achievements of an employee to their satisfaction, the criminal insider seeks revenge via electronic criminal aggressions. Anecdotal evidence suggests that outside network intruders also may demonstrate an exaggerated sense of entitlement, as well as a lack of empathy for their victims, also characteristic of narcissistic personality disorder.
One self-identified computer criminal states, “we rise above the rest, and then pull everyone else up to the same new heights… We seek to innovate, to invent. We, quite seriously, seek to boldly go where no one has gone before.”82 Narcissistic individuals
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 10 THE PSYCHOLOGY OF COMPUTER CRIMINALS
also frequently engage in rationalization to justify and defend their behaviors.83 Com- puter criminal Toxic Shock writes, “We are misunderstood by the majority. We are misunderstood, misinterpreted, misrepresented. All because we simply want to learn. We simply want to increase the flow of knowledge, so that everyone can learn and benefit.”84 Although it would be a mistake to generalize these hypotheses to the entire population without any empirical support, certain subsets of computer criminals may demonstrate characteristics that are consistent with aspects of both narcissistic and antisocial personality disorders.
12.5.2 Five-Factor Model of Personality and Computer Criminals. In one of the rare empirical studies looking at computer criminals, criminologist Marc Rogers examined the relationship between the five-factor model of personality and self- reported “criminal computer activity.”85 The five-factor model formulated by psychol- ogists Robert McCrae and Paul Costa in 1990 suggests that an individual’s personality can be accurately described using five core dimensions: extraversion (e.g., sociable), neuroticism (e.g., anxious), agreeableness (e.g., cooperative), conscientiousness (e.g., ethical), and openness to experience (e.g., nonconforming).86
Rogers hypothesized that individuals engaging in computer crime would demon- strate higher levels of:
� exploitation, � hedonistic morality, � manipulation, � antagonism, � undirected behaviors, � introversion, � openness to experiences, and � neuroticism
than noncriminals would. Three hundred eighty-one psychology students from an in- troductory psychology class were administered the computer-crime index (CCI), which is a self-report measure of computer-crime activity, along with measures of exploita- tion, manipulation, moral decision making, and a five-factor personality inventory. Contrary to the researcher’s expectations, individuals who committed computer crimes did not significantly differ from the nonoffenders on any of the five-factor personality measures. However, students who reported engaging in illegal computer activities did demonstrate more exploitive and manipulative tendencies.87
In contrast, in a follow-up study Rogers did find that extraversion was a reliable predictor of computer crime behavior. The less extraverted an individual (i.e., more introverted), the more likely they were to engage in illicit computing activities. He suggests that the differences in populations between the two samples, the latter being a Canadian liberal arts college and the former being U.S. students from a technology program, may have contributed to the discrepant findings.88 It is clear that further research will need to be conducted in this area in order to clear up the discrepant findings. One possible limitation in both of these studies is that the questionnaires were administered using a pencil-and-paper format, which assesses attitudes and traits when the participants’ offline identities are salient.89 Internet researchers have long suggested that there is a distinct difference between our online and offline identities.90 Therefore,
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
INDIVIDUAL DIFFERENCES AND COMPUTER CRIMINALS 12 · 11
had the participants been administered measures in an electronic format, when their online identities were more salient, Rogers might have found differing results
12.5.3 Asperger Syndrome and Computer Criminals. Recently re- searchers have suggested a possible link between criminal hacking and a relatively new developmental disorder named Asperger syndrome (AS).91,92,93 AS is a disorder that resides at the mild end of the pervasive developmental disorder (PDD) spectrum, with classic autism at the more severe end. PDDs are characterized by primary de- velopmental impairments in language and communication, social relations and skills, as well as repetitive and intense interests or behaviors.94 Unlike autism, individuals who are diagnosed with AS have higher cognitive abilities and IQ scores ranging from normal to superior. Individuals with AS also have normal language and verbal skills, although there are noticeable deficits in social communication. Those diagnosed with AS typically have severe and systematic social skill impairment or underdevelopment, difficulties with interpersonal communication, and repetitive patterns of interests, be- haviors, and activities.95
According to clinical psychologist Kenneth Gergen, AS individuals must demon- strate social impairment. They may have a lack of desire or inability to interact with peers, and may engage in inappropriate or awkward social responses.96 These indi- viduals may have extremely limited or focused interests, and are prone to engage in repetitive routines. Although language development is often normal, these individuals may demonstrate unusual speech patterns (e.g., rate, volume, and intonation). Individ- uals with AS also may demonstrate clumsy motor behaviors and body language, as well as inappropriate facial expressions and gazing.97
One of the noted features ofAS that is anecdotally linked to computer criminals is the obsessive or extremely focused area of intellectual interest that the individuals demon- strate. Children with AS often show a preoccupation in areas such as math, science, technology, and machinery. They strive to learn and assimilate as much information as possible about their specialized interest. Researchers have indicated that their preoccu- pation may last well into adulthood, leading to careers associated with their intellectual interests.98 Much of their social communication is egocentric, revolving around their obsessive interests, often leading to strained and difficult social interactions. Although children with AS desire normal peer interaction, their egocentric preoccupations, lack of appropriate social behaviors, and difficulties empathizing with others often leave them frustrated, misunderstood, teased, and sometimes ostracized.99
Researchers have noticed similarities in the characteristics associated with AS and traits stereotypically associated with computer hackers.100 Tony Atwood, an Australian clinical psychologist, suggests that some computer hackers may have a number of characteristics that are associatedwithAS.101 He notes thatmany diagnosedASpatients are more proficient at computer programming languages than social language, and that the intellectual challenges that are presented by restricted computers and networks may override the illegal nature of their actions. AS has been used as a successful defense in at least one landmark U.K. court case.102
Based on over 200 personal interviews with computer criminals, cybercrime expert Donn Parker reports finding significant similarities between AS sufferers and criminal hackers. Many of the computer criminals that Parker interviewed demonstrated the social awkwardness, atypical prosody, and lack of social empathy during social in- teractions that are characteristic of AS.103 Anecdotal evidence suggests that computer hackers often have an obsessive interest in technology and computers, similar to that seen in individuals with AS, that forms a salient component of both their individual
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 12 THE PSYCHOLOGY OF COMPUTER CRIMINALS
and social identities. Due to their egocentric preoccupations, many computer hackers often feel misunderstood and frustrated in face-to-face social situations.
Although the Autism Diagnostic Interview is the most common assessment tool, a number of self-report instruments have been developed to assist in screening dis- orders on the autism spectrum. To date, sociologist Bernadette Schell has conducted the only empirical study examining Asperger syndrome in a self-identified hacker population.104 Schell administered the 50-item Autism-Spectrum Quotient (AQ) In- ventory to 136 attendees at various well-known hacker conferences (e.g., Defcon105) between 2005 and 2007. Previous research using the AQ found that diagnosed AS individuals’ mean scores were 35.8 compared to a mean score of 16.4 for a control population. Schell found that the mean score for conference attendees in her study was 19.7. However, 11 percent of males in her sample and 1.5 percent of females had mean AQ scores of 32 or higher. Although this study is limited by due to participants’ self-identification as hackers, it does suggest that proposed link between hacker culture and AS may be tenuous at best.106
To date there has been no clear empirical evidence to suggest a link between AS and computer crime. There is no evidence whatsoever to suggest that Asperger syndrome causes computer hacking. In fact, most sufferers of AS have been characterized as being extremely honest and lawful citizens.107 It would be a mistake to assume that all computer hackers are suffering from AS or that every AS sufferer is a computer hacker. Characteristics of AS appear more common in computer hackers (i.e., those who explore and tinker with computers and technology), rather than in crackers who break into computers or use them for illegal activities. At present, there is still no single all-encompassing personality profile that applies to all computer criminals. In fact, many feel that it is inappropriate to try to create a single personality profile that applies to all computer criminals.
12.5.4 Internet Abuse and Computer Crime. Although technological ad- diction is not a disorder recognized by the American Psychological Association (APA), researchers have suggested that some individuals appear to demonstrate disturbed com- puter use that is similar to other recognized disorders like compulsive gambling or impulse control disorders. Technological addiction is characterized by:
� Excessive use of a particular technology (usually in reference to computers and Internet usage)
� Preoccupation with the technology � Systematic increase in use � Failed attempts to curb one’s use � Feelings of malaise and irritation when not using the technology � Interference with social and professional pursuits due to excessive technology use108
Information security researchers Kent Anderson and Jerrold Post suggest that some computer criminals appear to have symptoms indicative of potentially pathological computer use.109,110 Research by sociologist Bernadette Schell found that hacker con- ference participants indicated that they spend on average 24 hours a week on hacker- related activities.111 Furthermore, Anderson reports that cybercriminals will work for 18 or more hours a day on their computers trying to gain unauthorized access to one
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
INDIVIDUAL DIFFERENCES AND COMPUTER CRIMINALS 12 · 13
single computer system with little or no external reward for doing so. He also mentions an instance where one U.S. judge even attempted to sentence a computer criminal to psychological treatment for his compulsive computer use.112
In their interviews with a number of self-identified computer criminals, sociologists Paul Taylor and Tim Jordan indicated that many of their interviewees report experi- encing a thrill or rush that isn’t comparable to anything that they experience in their real-world interactions when engaging in illegal activities.113 A number of their respon- dents reported feelings of depression, anxiety, and impaired social functioning when they are away from their computers. Taylor and Jordan suggest that these abuse-like characteristics may also be combined with feelings of compulsion regarding comput- ers and new technologies. However, the researchers indicated that these compulsive or obsessive-like characteristics may be as much a function of the information technology (IT) field as they are personality traits.114 Unlike most disciplines, the IT field is in a constant state of rapid change. To maintain a level of professional expertise and com- petence in this area, one must devote a good deal of time and resources to monitoring and adapting to this revolutionary field. This need to keep up with the rapidly changing discipline, combined with the euphoric feelings that some experience when committing illegal activities, may increase the likelihood of technological abuse.
Personality theorists state that for some computer criminals, committing electronic crimes produces an experience similar to that of a chemically induced high. Some computer criminals may commit illegal acts because of the euphoric rush they receive from their actions. Information security researcher August Bequai compares the actions of computer criminals to electronic joyriding.115 Gaining unauthorized access and usage to a computer network is, for these people, similar to that of taking a car on a joyride. One computer cracker interviewed by computer crime researcher Dorothy E. Denning described hacking as “the ultimate cerebral buzz.” Other crackers have commented that they received a rush from their illegal activities that felt as if their minds were working at accelerated rates. Some computer criminals have suggested that the euphoric high stems from the dangerous and illegal nature of their activities.116
Lending empirical support to this idea, criminologist Michael Bachmann found that self-identified computer criminals have a heightened propensity to engage in risk behaviors compared to the general population. Computer criminals have compared the feelings they receive from their illegal intrusions and attacks to the rush that is felt by participating in extreme sports like rock climbing and skydiving.117
Researchers have found that some experienced computer users also report some- times experiencing an altered psychological state known as flow while engaging in their technological pursuits. Flow is a psychological state that results in feelings of fulfillment and overall positive affect.118 When individuals becomes absorbed in a task that matches their skill set, at times they may not be consciously aware of the passage of time or of the differences between the undertaking and their identity. In their study looking at the experience of flow in self-identified computer criminals, psychologists Alexander Voiskounsky and Olga Smyslova found that both inexperienced and highly competent criminals report high levels of flow.119 For the inexperienced criminals, this flow experiencemy lead them to limit themselves to low-level challenges, and theymay remain in this novice stage for a significant amount of time. More experienced crackers who also experience flow may leave the hacking domain once they are no longer pre- sented with suitable challenges for their abilities. Conversely, they may systematically increase their illegal pursuits in attempts to reacquire the flow state, contributing to technological abuse.120
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 14 THE PSYCHOLOGY OF COMPUTER CRIMINALS
Physical and psychological tolerance can occur when increased amounts of a sub- stance or an activity are needed in order to obtain a high or euphoric rush. Tolerance is common in hard drug users who find themselves using increasing amounts of a substance to achieve their original euphoric states. Anecdotal evidence suggests that computer criminals may go through a similar stage of evolution, with each step leading to increased dangerous and riskier behaviors. Many cybercriminals begin by pirating and cracking the copy protection algorithms of software programs. When the warez (pirated software) scene loses its thrill, they migrate to chat-room or IRC harassment. The individuals may then begin launching damaging DoS attacks against servers and defacing Websites to obtain that initial rush that originated with simple warez trad- ing. As in a substance abuse, the initial euphoric psychological states and resulting tolerance associated with excessive computer use may explain why some computer criminals repeatedly engage in illicit activities, even after they have been caught and punished.
12.6 ETHICS AND COMPUTER CRIME. Researchers have suggested that com- puter criminalsmay have an underdeveloped sense of ethics—amoral immaturity—that contributes to their illegal activities.121,122,123,124 Because of this ethical immaturity, criminal hackers may think that many of their illegal actions are in fact ethical or beneficial to some degree. Many computer criminals feel that they are ethically entitled to have access to any and all information regardless of legal ownership. Most of these individuals also feel that it is morally right to use inactive computer processing power and time, regardless of who owns the computer system. Computer criminals do not feel that breaking into a computer network should be viewed in the same light as breaking into an individual’s house. Often, computer criminals rationalize their illegal activities and justify their behaviors by blaming the victims for not securing their computer networks properly.125
Most computer criminals are adolescents, which may account for the underdevel- oped sense of ethics in the community.126 Computer scientist Brian Harvey suggests that due to the relative lack of experience and guidance with the computing environ- ment compared to the real world, teenagers and adolescents may be operating at lower levels of moral functioning when online compared to their interactions and decisions in the real world.127 Similarly, information security specialist Ira Winkler suggests that computer hackers, because of their generally young age, do not fully understand the repercussions associated with their actions. They also may demonstrate an underde- veloped or complete lack of empathy for their victims.128 Computer criminals fail to fully realize the consequences of their electronic intrusions into computer networks. The adolescents do not fully comprehend that their mere presence on a computing network could potentially cost companies thousands of dollars, as well as cost systems administrators their jobs.129
Sociologist Orly Turgeman-Goldschmidt further suggests that computer criminals may view their behaviors as nothing more than a new form of social entertainment.130
They see their electronic intrusions as a game that provides them with excitement and thrills. The Internet serves an unlimited playground or social center where “netizens” are able to develop new games and forms of social activities. Computer criminals may view their illegal activity as nothing more than fun and thrill seeking, a new form of entertainment that is carried out on an electronic playground.131
According toWinkler,many criminal hackers learn and develop a sense of computing ethics from their online and offline peers.132 In other words, unlike most instruction on morality and ethics that stems from a responsible adult, computing ethics are socially
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
ETHICS AND COMPUTER CRIME 12 · 15
learned from other adolescents. Computer crackers learn the rules of hacking and computing from elder statesmen in the hacking community who may be no more than a few years older than themselves. Often, in today’s society, the younger generation is more knowledgeable about technology than older adults. When adolescents have problems or need guidance in ambiguous situations, many times their parents or other adult role models are unable to offer them the necessary guidance and assistance. Therefore, the youngsters may seek knowledge from their peers, who may or may not offer them the most ethical or wise advice.133 In support of this notion, Vincent Sacco and Elia Zureik found that students who viewed illicit computing behaviors as ethical increased the reported likelihood that they would engage in such actions. Computer crime was least reported when the behavior was seen as being more unethical.134
While using the Internet, children are constantly making sophisticated judgments without appropriate adult supervision. Adolescents do not have the same ethical ma- turity that adults have, yet while using the Internet they are given as much power, authority, and responsibility as ethically mature adults.135 Neil Patrick, the leader of one particularly malicious group of phone-system hackers known as the 414s, stated that he did not know that his hacking was illegal or unethical. In fact, asked when, if ever, he began to question the ethics of his actions, Patrick stated that ethics never came into his mind until the Federal Bureau of Investigation agents were knocking on his front door. Patrick and the other youngmembers of the 414s did not see anything wrong with their actions. To them, breaking into proprietary telecommunications networks was more of a game or challenges rather than a criminal act. They saw nothing ethically wrong with their actions.136
Psychologist Lawrence Kohlberg developed a three-level theory to explain normal human moral development.
� The first level deals with avoiding punishments and obtaining rewards. � The second level emphasizes social rules. � The third level emphasizes moral principles.
Each of his three levels contains two stages that an individual passes through during adolescence on the way to adult moral development.137 Computer criminals appear to be operating in the lower three phases of Kohlberg’s model: the two stages comprising level 1 and the first stage in level 2. The moral judgments of computer criminals appear to be determined by a need to satisfy their own needs and to avoid disapproval and rejection by others.
In his empirical research on moral development, Rogers found that self-identified computer criminals relied more on hedonistic decision making rather than internal or social morality-based choices, compared to a noncriminal student population. Com- puter criminals do not appear to be aware of or concerned with the third level of moral development, where moral judgments are motivated by civic respect and one’s own moral conscience.138 Computer criminals may be functioning at the third level of moral development in the physical world, a level appropriate for teens and adults, and may simultaneously be functioning at lower levels of moral development when their online identities are salient.139 Computer criminals acting at these lower levels of morality may be naively engaging in their illegal activities to satisfy their own curiosity and to gain the approval of their peers, without considering larger moral implications of their behaviors.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 16 THE PSYCHOLOGY OF COMPUTER CRIMINALS
According to Shaw and associates, there is a notable lack of ethical regulation and ed- ucation in organizations, schools, and homes regarding proper computing behavior.140
Computer criminals who lack ethical maturity fail to realize that their digital actions are sometimes just as damaging as physical aggression. Cybervandals do not see the immediate repercussions of their actions because of the physical distance and lack of social presence in computer-mediated interactions. This ethical immaturity is partially a result of the technology-enhanced knowledge gap between young computer users and their parents. A hacker whose handle was The Mentor wrote in the 1986 “Hacker Manifesto,”
This is our world now… the world of the electron and the switch, the beauty of the baud. We make use of a service already existing without paying for what could be dirt-cheap if it wasn’t run by profiteering gluttons, and you call us criminals. We explore… and you call us criminals. We seek after knowledge… and you call us criminals. We exist without skin color, without nationality, without religious bias… and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it’s for our own good, yet we’re the criminals.
Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for.141
In real-world situations, when parents and teachers strive to instill responsible ethics in adolescents, young adults become capable of making informed decisions regarding ethical dilemmas. However, the same adolescents who demonstrate ethical behavior in the physical world may be ethically bereft in cyberspace, partly due to the lack of adult guidance and instruction. Anecdotal evidence suggests that in today’s society, adolescents recreationally use, and are more familiar with, computers and the Internet than their parents. These young adults often learn the about Internet-related behaviors and attitudes on their own, or via peer-to-peer interaction. Adolescents are socialized on the Internet by other adolescents, which may lead to a Lord of the Flies scenario, where children construct social rules and guidelines to govern their behaviors.142
These socially constructed norms and guidelines may be both morally and ethically different from real-world norms. Kabay has argued that technological change can take two to three generations for integration of new moral codes into society; by this reasoning, young adults who are growing up with increased awareness of civil behavior in cyberspace will be teaching their own children more appropriate rules of behavior from the earliest ages of the next generation.143
12.7 CLASSIFICATIONS OF COMPUTER CRIMINALS. For both ordinary and abnormal behaviors, it is difficult to find one theoretical perspective that can ac- count for every behavior in a given situation. Attitudes and behaviors are the product of the combined influence of an individual’s personality and the current social situation. No single theory or theoretical perspective can account for the various types of com- puterized crimes and the criminals who engage in these activities. There are also many types of computerized crimes, ranging from trading pirated software to cyberterrorism, andmany types of computer criminals, ranging from the novice password cracker to the industrial spy. Any theory that would account for the behavior of computer criminals would have to consider, first, the type of illegal activity the person was engaged in and, second, the type of cybercriminal category that the individual falls into.144 Computer criminals are by nature paranoid and secretive agents who exist in a similar commu- nity. They use handles to conceal their true identities and, except for annual hacker
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
CLASSIFICATIONS OF COMPUTER CRIMINALS 12 · 17
conventions or local meetings, seldom interact with each other in the real world. There- fore, it is difficult for researchers to identify and categorized the various subgroups that exist.
The term computer hacker has been both overused and misused as a way of clas- sifying the entire spectrum of computer criminals.145 The motivations and actions of one subgroup of computer criminals may be entirely different from those of a sec- ond group; therefore, it is imperative that in any psychological analysis of computer criminals, the various subcategories be taken into consideration. Many theories have attempted to account for the motivations and behaviors of computer criminals as a whole when the theorists actually were referring to one specific subgroup in the un- derground culture.146 Computer criminals are a heterogeneous culture; therefore, one single theory or perspective cannot sufficiently explain all their actions. The fact that researchers traditionally have treated computer criminals as a homogeneous entity has limited the validity and generalizability of their findings. Even researchers who have taken into account the heterogeneous nature of the computing underground have had difficulty with experimental validity. Experimenters have allowed participants to use their own self-classification schemes or attempted to generalize the results of a single subgroup to the entire underground culture.147
12.7.1 Early Classification Theories of Computer Criminals. Over the past few decades, several researchers have attempted to develop a categorization sys- tem for individuals who engage in various forms of computer crime.148,149,150,151,152 A comprehensive review of this research is beyond the scope of this chapter. For an exten- sive review, see Rogers’s analysis and development of a new taxonomy for computer criminals.153 Bill Landreth, a reformed computer cracker, was one of the earliest theo- rists to develop a classification scheme for computer criminals.154 His system divided criminals into five categories based on their experience and illegal activities.
1. The novice criminals have the least experience with computers and cause the least amount of electronic disruption from their transgressions. They are considered to be tricksters and mischief-makers; for example, AOL users who annoy chat- room members with text floods and DoS-like punting programs that crash AOL sessions using specific font or control code strings.
2. The students are electronic voyeurs. They spend their time browsing and exploring unauthorized computer systems.
3. The tourists, according to Landreth, commit unauthorized intrusions for the emo- tional rush that results from their actions. This subgroup of computer criminals is similar to Bequai’s electronic joyriders.155 The tourists are thrill-seekers who receive a cerebral buzz from their illegal behaviors.
4. The crashers aremalicious computer criminals. This subgroup is composed of the darkside criminals that Kabay refers to.156 The crashers will crack into networks and intentionally delete and destroy data and cause denials of service.
5. Landreth’s final classification of computer criminal is the thieves. Criminals who fit into this category commit their illegal actions for monetary gain. These in- dividuals are equivalent to the dangerous insiders that Post, Shaw, and Ruby analyzed.157 Thieves may work alone, or they may be under contract from both foreign and domestic corporations and governments. Examples include the Rus- sian Business Network or RBN.158
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 18 THE PSYCHOLOGY OF COMPUTER CRIMINALS
Former Australian Army intelligence analyst Nicholas Chantler conducted one of the few empirical examinations of computer criminals and their culture.159 Published in 1995, this survey-based study attempted to gain a deeper understanding of the underground culture as well as to develop a categorization system for cybercrimi- nals. Chantler posted questionnaires to bulletin board systems (BBSs), Usenet news- groups, and chat rooms owned or frequented by computer criminals. An analysis of the data yielded five primary attributes—criminal activities, hacking prowess, moti- vations, overall knowledge, and length of time hacking—that Chantler used to create three categories of computer criminals: lamers, neophytes, and elites.160
1. Lamers have the least technical skill and they have been engaged in their illegal activities for the shortest period of time. This group of criminals is primarily motivated by revenge or theft of services and property.
2. Neophytes are more mature than lamers. They are more knowledgeable than the previous category and engage in illegal behaviors in pursuit of increased information.
3. Members of the elite group have the highest level of overall knowledge concerning computers and computer crime. They are internally motivated by a desire for knowledge and discovery. They engage in illegal activities for the intellectual challenge and for the thrill they receive from their criminal behaviors.
According to Chantler, the largest proportion of computer criminals at that time, 60 percent, fell into the neophyte category. Thirty percent of computer criminals fell into the elite category, while 10 percent were lamers.161
Information security analyst Donn Parker developed a seven-level categorization scheme for computer criminals.162,163 He formalized his scheme, through years of interaction and structured interviews with computer criminals, into the following cat- egories:
1. Pranksters are characterized by their mischievous nature. 2. Hacksters are motivated by curiosity and a quest for knowledge. Pranksters and
hacksters are the least malicious computer criminals.
3. Malicious hackers are motivated by a need for disruption and destruction. They receive pleasure from causing harm to computer systems and financial loss to individuals.
4. Personal problem solvers commit illegal activities for personal gain. Problem solvers, the most common type of computer criminal according to Parker, resort to crime after failing in legitimate attempts to resolve their difficulties.
5. Career criminals engage in their illegal cyberbehaviors purely for financial gain.
6. Extreme advocates have strong ties to religious, political, or social movements. Recently, these types of cybercriminals have been dubbed “hacktivists,” a com- bination of computer hackers and activists.
7. Malcontents, addicts, and irrational individuals comprise the final category in Parker’s scheme. Individuals in this category usually are suffering from some form of psychological disorder (e.g., antisocial personality disorder).
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
CLASSIFICATIONS OF COMPUTER CRIMINALS 12 · 19
12.7.2 Rogers’s New Taxonomy of Computer Criminals. After an ex- tensive review of past categorization theories, Rogers has advanced an updated con- tinuum of computer criminals based on his previous work.164 This continuum com- prises eight categories based primarily on the criminals’ motivations and technological prowess:
1. Novice (NV) criminals have the least amount of technical knowledge and skill. Members of this category are relatively new to the scene and use prewritten and precompiled scripts and tools to commit their computerized crimes. They are primarily motivated by the thrill of lawbreaking and making a name for themselves in the underground.
2. Cyber Punk (CP) is the group that most fits the traditional stereotype of hacker. Members of this category are slightly more advanced than the novices. These criminals have the ability to create basic attack scripts and programs. Cyber Punks’ typical behaviors include Web page defacements, DDoS attacks, card- ing, and telecommunication fraud. They are motivated by a need for attention, fame, and monetary gain, usually attained by parlaying their crimes into lucrative jobs and book deals. Winkler suggests that the majority of computer criminals fall into either the cyber punk or newbie categories. He estimates that between 35,000 and 50,000 computer criminals, well over 90 percent of their total esti- mated number, fall into these categories, whom he dubs clueless.165
3. Internals (IN) consist of disgruntled workers or former workers who hold in- formation technology positions in an organization. Members of this category have an advantage over external attackers due to their job and status within the corporation. Research indicates that internals are responsible for the majority of computer crimes and associated financial loss. Their motivation is typically based on revenge for some perceived wrong (e.g., termination, passed over for a promotion).166,167 These internal or malicious insiders are examined more fully later in Chapter 13 of this Handbook.
4. Petty Thieves (PT) are traditional criminals who have turned to technology as a way of keeping up with the times. These individuals are career criminals whose motivation is primarily financial gain from stealing from banks, corporations, and individuals.
5. OldGuard (OG) are computer criminalswith advanced technical knowledge and skill. These individuals are responsible for writing many of the exploit programs (e.g., stack overflows, rootkits, etc.) that are used by the less knowledgeable novice and cyberpunk crackers in their cyberattacks; however, they are not crim- inals in the traditional sense. This group has an underdeveloped sense of ethics regarding privacy and intellectual and personal property and engages in behav- iors consistent the traditional hacker ethic and ideology described by Levy.168
Their illegal behaviors are motivated by a quest for knowledge, curiosity, and intellectual stimulation.
6. VirusWriters (VW) do not fit neatly into Roger’s Taxonomy primarily due to the lack of research on this group of individuals. The demographics and motivations of virus writers are examined more fully later in this chapter.
7. Professional Criminals (PC) are traditionally older and more knowledgeable about technology than the previous categories. Members of these categories may be former government and intelligence operatives who are motivated by
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 20 THE PSYCHOLOGY OF COMPUTER CRIMINALS
financial gain. They may often have access to advanced technology and can be adept at industrial espionage. According to Rogers, PCs may be comprised of ex-intelligence agents and are one of the most dangerous types of computer criminals. Their motivation is primarily large-scale financial gain.
8. Information Warriors are highly skilled employees who conduct coordinated attacks against information systems in an attempt to cripple or destabilize the infrastructure. This group may be motivated by allegiance and patriotism. We examine this group more fully in the following section.
Based on these eight categories, Rogers has created a baseline circumplex model of computer criminals that aims to further classify computer criminals. Rogers’ cir- cumplex groups computer criminals in a circular diagram using two continua: techno- logical skill and motivation. Using this circumplex, the eight categories can be further subdivided, following future empirical work, to more accurately represent individual subgroups of the computer underground.
12.7.3 Hacktivists and Cyberterrorists: Hacking for a Cause. With the emerging protests against the economically advantaged 1 percent and the political upheaval in Middle East, new trends in cybercrime have emerged in the form of a revitalized hacktivist ethos. Hacktivism is defined as cause-based hacking for social, political, patriotic, or religious purposes. In general, the perpetrators engage in techno- logical dissent in order to promote freedom of speech and fair distribution of wealth and to combat censorship. Hactivists will often rally behind a symbol, logo, or flag, whether they are religious, political, or emblematic. The termwas first used by groups like Elec- tronic Disturbance Theatre (EDT) and the Cult of the Dead Cow (cDc) in themid-1990s to establish digital protests and hack-ins where the groups would launch coordinated DoS attacks and massWeb page defacements as a means of online protest.169,170,171,172
Paralleling the global “Occupy” protest movements, many of these modern hacktivist groups have no central leadership or core philosophy, making their actions and targets difficult to predict. They present an increased danger due to their tendency to single out and target high-profile people and organizations to achieve maximal exposure for their group, cause, and interests. Hacktivists are not motivated by financial gain, but instead prefer to publicize their cause through the harm and embarrassment of their victims.173
The methods employed by modern hacktivists have evolved from simple DoS attacks andWeb defacements to massive amounts of government, corporate, and personal data theft. The number of hacktivist attacks in 2011 surpassed all of the previous year’s attacks combined that were attributed to social and political motivations.174
According to Rogers, cyber-terrorists, along with professional criminals, may present the most danger to individuals and organizations. A cyber-terrorist is defined as, “an individual who uses computer or network technology to control, dominate, or coerce through the use of terror in furtherance of political or social objectives.”175 Fol- lowing the September 11, 2001, attacks in the United States, the term cyberterrorism has been frequently overused and misused by the media. An individual who stumbles upon a vulnerable .mil or .govWebsite and decides to deface it should not be considered a cyberterrorist unless there is a premeditated intent to cause panic and fear, with the object of obtaining some social end.
Although most of the Web page defacements and network attacks labeled by the media as cyberterrorism would not fit Rogers’s definition, that is not to say that the Internet will not be used as means for terrorist acts in the future.176 Spurred on by
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
CLASSIFICATIONS OF COMPUTER CRIMINALS 12 · 21
the specter of cyberterrorism and claims by hackers that they could cripple the Internet in 30minutes, governments and corporations are investing millions into research aimed at protecting the global computing infrastructure from cyberattacks. Rogers suggests that the relative anonymity of the perpetrator, and the multitude of potential targets that could be simultaneously attacked, makes the Internet a very appealing target for terrorists’ actions that will likely be exploited in the near future.177
Perhaps themost infamous case of cyberterrorismoccurred in 2010when researchers analyzed Stuxnet, one of the most sophisticated electronic worms ever discovered in the wild. Stuxnet was created with the singular goal of creating physical damage to centrifuges in one of Iran’s nuclear enrichment facilities. Although no one has taken credit for the Stuxnet worm, computer security researchers suggests that it may have been cyberwarriors working for the United States and/or Israeli governments.178
Theorists suggest that new breeds of computer criminals, dubbed cyberterrorists and hacktivists, are emerging and are motivated by political or social ideologies related information freedom, nationalism, ethnic pride, and warfare.179,180
12.7.4 Dangerous/Malicious Insiders (DI/MI). Dr. Eric Shaw and asso- ciates classify computer criminals into two categories: outside intruders and dangerous insiders.181,182,183 The researchers focus on the critical IT insiders who are typically programmers, technical support staff, networking operators, administrators, consul- tants, and temporary workers in organizations. Malicious insiders (MI) are a subgroup of such employees who are motivated by greed, revenge, problem resolution, and ego gratification. Shaw and colleagues estimate that the theft of trade secrets costs more than $250 billion annually for U.S. businesses alone.
Shaw’s research, based on corporate surveys and hundreds of investigations by the U.S. Secret Service and Carnegie Mellon University’s Computer Emergency Response Team Coordination Center (CERT-CC), has attempted to compile an initial profile of dangerous insiders. Their critical-pathway approach identifies psychological and situ- ational precursors that may predispose an employee to engage in insider espionage184:
1. Personal Predisposition: medical/psychiatric problems, reduced social skills, previous violations of the law or business ethics, social or professional ties with competitors or adversaries
2. Personal Life Stressors: financial burden, relationship problems, medical issues, legal issues
3. Professional Stressors: demotions, failed promotions, poor performance review, transfer, supervisor disagreements, looming layoffs
4. Concerning Behaviors: workplace violations, conflict, intellectual property (IP) disagreements
5. Maladaptive Organizational Responses: failure to detect, investigate, appreci- ate, and appropriately respond to concerning behaviors of employees
The generic profile for an MI is a male in his late thirties who has a job in a technology-related area within the company. The majority of thefts occur when an MI has accepted a job elsewhere and within a month of starting their new job. Moore, as cited by Shaw, classifies MIs into two categories, the Entitled Disgruntled Thief and the Machiavellian Leader.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 22 THE PSYCHOLOGY OF COMPUTER CRIMINALS
� The Entitled Disgruntled Thief typically engages in IP theft due to professional stressors. They steal information that they directly worked on or helped to develop. These individuals feel entitled to the information and typically will use it to help them acquire a new job or to enhance their performance at their already acquired position.
� The actions of the Machiavellian Leader are more premeditated. They are driven more by personal ambition rather than personal or professional stressors. These individuals may also recruit coworkers to assist them in their thefts.
According to Shaw and coauthors, these dangerous insiders typically have intro- verted personalities.185 They demonstrate a preference for solitary intellectual activi- ties over interpersonal interaction. Members of this subgroup may have had numerous personal and social frustrations that have hindered their interpersonal interactions and contributed to their antiauthoritarian attitudes.
The malicious subgroup of critical information technologists has been characterized as having a loose or immature sense of ethics regarding computers. The dangerous insiders rationalize their crimes by blaming their company or supervisors for bringing any negative consequences on themselves. They feel that any electronic damage they cause is the fault of the organization for treating them unfairly. The researchers also note that many insiders identify more with their profession than with the company for which they work. This heightened identification with the profession undermines an insider’s loyalty to an organization. This reduced loyalty is evidenced by the high turnover rates of jobs in the IT industry. According to Shaw and associates, the unstable bond between insiders and their organizations creates undue tension with regard to security practices and IP rights.186
Researchers also have suggested that dangerous insiders are characterized by an increased sense of entitlement and hostility toward organizational authority. According to Shaw and coauthors, when an unfulfilled sense of entitlement is combined with previous hostility toward authority, malicious acts or revenge against the organization are typical.187,188,189
12.7.5 Virus Creators. Unlike more traditional forms of computer crime, there has been very little research examining the motivations and behaviors of malware writers, usually referred to as virus writers.190 Despite the name, the group writes other forms of malware such as worms and Trojans. The limited number of research reports on this particular subgroup of computer criminal has relied primarily on one-on-one interviews and surveys, in an effort to understand the actions and motivations of virus creators.191,192,193,194
Using case studies and multiple interviews, researchers Andrew Bissett and Geral- dine Shipton examined the factors that influence and motivate virus writers.195 The researchers suggest that it is difficult to generalize their findings to all virus creators because of the limited published literature and research regarding virus writers. Virus creators appear to demonstrate conscious motivations for their potentially destruc- tive actions that are similar to the motivations of traditional computer criminals. The coders create and distribute their software for reasons of nonspecific malice, employee revenge, ideological motives, commercial sabotage, and information warfare.
Bissett and Shipton’s review of anti-virus expert Sarah Gordon’s interview with Dark Avenger reveals some of the motivations behind one of the most notorious virus writers.196 They suggest that Dark Avenger consistently denies responsibility for his
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
CLASSIFICATIONS OF COMPUTER CRIMINALS 12 · 23
creations and, like traditional computer criminals, engages in victim blaming. Dark Avenger states that it is human stupidity, not the computer, that spreads viruses. The virus writer also appears to self-identify with his malicious code. Dark Avenger seems to project his persona onto viruses in a process called projective identification. During the interview, Dark Avenger stated that the United States could prevent him from entering the country, but it is unable to stop his viruses. Dark Avenger also attempted to justify creating destructive viruses by commenting that most personal computers did not store data of any value, and therefore his malicious programs were not doing any real harm. Similar to the motivations spurring dangerous insiders, the researchers suggest that Dark Avenger creates malicious viruses because he is envious of the work and achievements of other computing professionals. In the interview, Dark Avenger commented that he hates it when people have more powerful computing resources than he does, especially when the individuals do not use the resources for anything that he deems constructive.197
Sarah Gordon has also examined the ethical development of several virus writers using surveys and structured interviews.198,199,200 Her initial four case studies involved an adolescent virus writer, a college-age virus writer, a professionally employed virus writer, and an ex–virus writer. The interviews revealed that all four individuals appeared to demonstrate normal ethical maturity and development consistent with Kohlberg’s previously reviewed stage theory.201 Gordon suggests that there appear to be many different reasons why individuals create and distribute viruses, including boredom, exploration, recognition, peer pressure, and sheer malice.202
Gordon suggests that the virus underground in the mid and late 1990s was populated by a second generation or next generation of virus writers whose skill and ability at virus construction is comparable to that of the old school, original virus writers.203 On the surface, these second-generation creators maintain a public façade that suggests that they are extremely cruel, obnoxious, and more technologically advanced than the previous generation. The next-generation virus writers appear to be more aware of the ethical responsibilities surrounding virus creation and distribution; however, the exact definition of “responsible virus creation and distribution” varies from individual to individual.Many of these next-generation viruswriters have considerable technical skill and aremotivated by the challenge to defeat themalware countermeasures implemented by antivirus vendors.204
According to Gordon, another group of virus creators populating the virus under- ground in the 1990s was composed of “new-age” virus writers.205 These individuals are motivated by current trends, such as political activism, virus exchange, freedom of information, and challenges to write the most destructive or sophisticated virus, as opposed to technical exploration. These virus writers are motivated by boredom, intellectual curiosity, mixed messages surrounding the legality of virus creation, and increased access to ever-more-powerful technological resources. Gordon suggests that these new-age virus writers may be older and wiser than the second or next-generation creators. They are very selective as to who has access to their creations, and they do not share their findings or accomplishments with members outside their respective group. Unlike the next-generation creators, new-age virus writers will not stop or grow out of writing viruses, as they are most likely already adults. They will continue to write and distribute more sophisticated viruses in part due to the mixed messages concerning the ethical nature of virus creation propagated by the popular media, academia, and popular freedom of information zeitgiest.206
Researchers have stated that we must be careful not to view virus creators as a homogeneous group.207,208 Instead, we must monitor the virus-exchange community
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 24 THE PSYCHOLOGY OF COMPUTER CRIMINALS
while pursuing in-depth case histories that may aid in our understanding of virus writers. Education about the ethical nature of virus creation and distribution, and about the repercussions associated with malicious code, may attenuate these potentially destructive activities.
12.8 RECOMMENDATIONS. Psychological theories offer various explanations that may influence criminal activities on the Internet. These situational influences may interact with various individual personality traits to further contribute to illegal be- haviors. The current task for researchers is to untangle these personality and situation influences on electronic behavior. They must determine what situations and character- istics are influencing the various subgroups of computer criminals. There is no simple explanation as to why computer criminals engage in hostile and destructive acts. The answer lies in a complex mixture of factors that depends on the social environment and individual personality factors. There are numerous types of computer criminals ranging from script kids to the professional criminal, each with varying personalities and motivators. The interaction of personality variables and environmental factors will determine how a computer criminal reacts in any given situation.
One underlying theme in reducing the overall prevalence of computer crime has been to remove the tangible and psychological reward system that currently surrounds the culture of the Internet underground. Criminal law researchers A. S. Dalal and Raghav Sharma suggest that the information security field has established a pattern of rewarding criminal hackers for their exploits by offering them employment opportunities that further undermines law enforcement efforts to combat computer crime.209 Preventing cybercriminals from profiting from their transgressions via lucrative jobs and book deals may result in a socially learned deterrent to engaging in cybercrime. Thomas Holt and colleagues found strong support for the social learning model of cybercrime in their research: those who received reinforcement in the form of encouragement, praise, and resources from peers and authority figures were more likely to engage in cybercrime activities. This model suggests that removing this reinforcement would significantly reduce the amount and frequency of cyberdeviance, especially in the case of criminals that fall into Rogers’ novice and cyberpunk categories.210,211
Cautioning parents, teachers, and bosses about the dangers of praising adolescents for cyberdeviance and instead instituting consistent punishments should also help to mitigate computer crime for novices. Also, a more proactive strategy that parents and educators could take would be to engage in moral or ethics training on the use of computers and technology before children begin independently using technology on a regular basis. Then, when confronted with ambiguous decisions while using the com- puters, children would reflexively rely on adults’ moral advice and teachings instead of their peers’. Scholastic Incorporated demonstrated in a recent survey that 48 percent of elementary and middle school students did not consider computer hacking to be a crime.212 Recently, the U.S. Department of Justice (DoJ) formed a cybercitizen aware- ness program in an effort to educate parents, teachers, and children about ethical and unethical computing practices. The program seeks to educate individuals through ethics conferences, multimedia presentations, and speaking engagements at schools around the country. This program and others like it may aid to increase moral responsibility and ethical behaviors of adolescents on the Internet.213
Dalal and Sharma also suggest that punishments take into account themotivation and type of cybercrime that is committed, instead of using a rigid approach to sentencing that precludes adapting punishment to the nature of the criminal. For instance, longer jail terms may be a suitable deterrent for criminals who are motivated by financial
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
RECOMMENDATIONS 12 · 25
gain or malice (e.g., internals, petty thieves, and malicious insiders), but might not be warranted for those who are motivated by intellectual challenges and curiosity (e.g., old guard hackers).
Another problem may be the relatively light sentences that are typically handed down for computer crimes, and the perpetrators’ perceptions that they are unlikely to be caught or prosecuted for their transgressions. One study found that the perceived gains achieved by illegal hacking far outweighed the potential costs associated with digital crime. Furthermore, even though computer criminals feel that the punishments for their crimes are severe enough, their feelings that there is a very low probability that they’ll be caught minimizes the effects of punishment severity as a deterrent.214
Even still, the notoriety that a computer criminal gets from being handed a jail term can be parlayed into a lucrative job once the individual has paid the price for their criminal endeavors.
A more proactive approach to reducing the motivation to engage in illicit activities while using computers could be to establish legal hacking networks for novices to experiment with and explore. For novices and even cyberpunks, safe hacking spaces where they have unlimited access to networks and programs may reduce the psycho- logical reactance that results from strictly enforced computing access and resources. These legal hacking networks would also serve to redirect the users’ focus on the technical aspect of computing and traditional hacking endeavors rather than trying to crack open the system. By redirecting adolescents’ curiosity toward traditional hacking and technical pursuits into an open network, the users may be less inclined to engage in criminal pursuits.
To combat the threat of malicious insiders, Shaw suggests that businesses also adopt a proactive approach to threat mitigation.215 Developing more comprehensive employee-screening methods that include social-media reviews, background checks, substance abuse tests, honesty/ethical tests, and psychological screenings may serve to mitigate the risks of IP theft. Additionally, a more cost-effective and time-efficient method of reducing IP theft would be increasing employee awareness of IP nondis- closure agreements (NDAs) and ensuring that they are aware of the consequences of violating these agreements. Increasing employees’ and managers’ awareness of intellectual property rights and risk factors, as well as instituting a systematic re- porting system for potential violation could mitigate some of the risks of IP theft. Shaw reports that the majority of IP theft was detected by nontechnical means (e.g., employees noticing suspicious activity or similar products being marketed by competitors).216
This chapter summarized research on the psychological motivations of computer criminals. The cybercrime landscape is vast in scope and populated by subgroups of computer criminals with their own patterns of motivations, goals, attitudes, and behaviors. Psychological theory and research is one step in trying to generate effective countermeasures to combat the problem of cybercrime.
Although there is no shortage of theories and anecdotal evidence to account for why cybercriminals engage in network intrusions, there is a marked lack of empirical evidence that serves to test and validate these hypotheses. Information security profes- sionals, criminologists, and psychologists must find ways to begin jointly developing, testing, and examining these ideas in order to find concrete solutions for the problem of cybercrime. Such effort will be facilitated by government and private-sector funding to support research into the psychological and social dynamics of the Internet under- ground. The information security industry as a whole would do well to support these applied scientific efforts.217
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 26 THE PSYCHOLOGY OF COMPUTER CRIMINALS
12.9 FURTHER READING Jaishankar, K., ed. Cyber Criminology: Exploring Internet Crimes and Criminal Be-
havior. Boca Raton, FL: CRC Press, 2011. Kirwan, G., and A. Power, eds. The Psychology of Cyber Crime: Concepts and Prin-
ciples. Hershey, PA: IGI Global, 2011.
12.10 NOTES 1. Symantec, Internet Security Threat Report: 2011 Trends, Vol. 17, Syman-
tec Website, April 2012, www.symanteccloud.com/en/us/mlireport/b-istr main report 2011 21239364.en-us.pdf
2. Marc Rogers, “The Development of a Meaningful Hacker Taxonomy: A Two Dimensional Approach,” CERIAS Technical Report, 43 (2005): 1–9.
3. National Institute of Justice, “Electronic Crime Research and Development,” 2006, www.nij.gov/topics/crime/internet-electronic/
4. Symantec, Internet Security, 2012. 5. For more information about computer crimes, see Chapter 2 in this Handbook. 6. Verizon, “Data Breach Investigations Report,” Verizon Website, 2012, www.ve
rizonbusiness.com/resources/reports/rp data-breach-investigations-report-2012 en xg.pdf
7. Symantec, Internet Security, 2012. 8. For more information about information warfare, see Chapter 14 in this Hand- book.
9. Douglas Campbell, “A Detailed History of Terrorist and Hostile Intelligence Attacks Against Computer Resources,” 1992. Available at www.syneca.com/ publications.htm
10. Donn Parker, “How to Solve the Hacker Problem,” Journal of the National Com- puter Security Association, No. 5 (1994), pp. 4–8.
11. Jerrold Post, “The Dangerous Information Systems Insider: Psychological Per- spectives,” (1998). Available email: [email protected]
12. Parker, “Hacker Problem,” 1994 (pp. 4–8). 13. Paul Taylor, Hackers: Crime in the Digital Sublime, (London & New York:
Routledge, 1999). 14. Raoul Chiesa, Stefania Ducci, and Silvio Ciappi, Profiling Hackers: The Science
of Criminal Profiling as Applied to the World of Hacking (Boca Raton, FL: Auerbach Publications, 2008).
15. Orly Turgeman-Goldschmidt, “Hackers’ Accounts: Hacking as a Social Enter- tainment,” Social Science Computer Review, 23, no. 1 (2005): 8–23.
16. Tim Jordan and Paul Taylor, “A Sociology of Hackers,” Sociological Review, 46, no. 4 (1998): 757–780.
17. Taylor, Hackers, 1999. 18. Turgeman-Goldschmidt, “Hackers’ Accounts,” 2005. 19. Taylor, Hackers, 1999. 20. Taylor, Hackers, 1999. 21. Chiesa, Ducci, and Ciappi, Profiling Hackers, 2008. 22. Chiesa, Ducci, and Ciappi, Profiling Hackers, 2008.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 12 · 27
23. Chiesa, Ducci, and Ciappi, Profiling Hackers, 2008. 24. Jordan and Taylor, “A Sociology,” 1998. 25. Hyung-jin Woo, Yeora Kim, & Joseph Dominick, “Hackers: Militants or Merry
Pranksters? A Content Analysis of Defaced Web Pages,” Media Psychology, 6, no. 1 (2004): 63–83.
26. David G. Myers, Social Psychology, 8th ed. (New York: McGraw-Hill, 2005). 27. Myers, Social Psychology, 2005. 28. Woo, Kim, and Dominick, “Hackers: Militants or Merry Pranksters?” 2004. 29. For more information on denial-of-service attacks, see Chapter 18 in this Hand-
book. 30. Stanley Milgram, Obedience to Authority (New York: Harper & Row,
1974). 31. Albert Bandura, “Selective Activation and Disengagement of Moral Control,”
Journal of Social Issues, 46, (1990): 27–46. 32. Marc Rogers, “Modern-Day Robin Hood or Moral Disengagement?” 1999.
http://homes.cerias.purdue.edu/∼mkr/moral doc.pdf 33. Turgeman-Goldschmidt, “Hackers’ Accounts,” 2005. 34. Jordan and Taylor, “A Sociology,” 1998. 35. Woo, Kim, & Dominick, “Hackers: Militants or Merry Pranksters?” 2004. 36. Rogers, “Modern-Day Robin Hood,” 1999. 37. Randall Young, Lixuan Zhang, and Victor R. Prybutok, “Hacking into the Minds
of Hackers,” Information Systems Management, 24 (2007): 281–187. 38. Sara Kiesler, Jane Siegel, and Timothy McGuire, “Social Psychological Aspects
of Computer-mediated Communication,” American Psychologist, 39 (1984): 1123–1134.
39. Sara Kiesler and Lee Sproull, “Group Decision Making and Communica- tion Technology,” Organizational Behavior and Human Decision Processes, 52 (1992): 96–123.
40. Kiesler and Sproull, “Group Decision Making,” 1992. 41. Kiesler, Siegel, and McGuire, “Social Psychological Aspects,” 1984. 42. Kiesler and Sproull, “Group Decision Making,” 1992. 43. Turgeman-Goldschmidt, “Hackers’ Accounts,” 2005. 44. Phillip Zimbardo, “The Human Choice: Individuation, Reason, and Order Versus
Deindividuation, Impulse, and Chaos,” Nebraska Symposium onMotivation, No. 17 (1969): 237–307.
45. Edward Diener, “Deindividuation, Self-Awareness, and Disinhibition,” Journal of Personality and Social Psychology, 37 (1979): 1160–1171.
46. Zimbardo, “The Human Choice,” 1969. 47. Kiesler, Siegel, and McGuire, “Social Psychological Aspects,” 1984. 48. Zimbardo, “The Human Choice,” 1969. 49. Zimbardo, “The Human Choice,” 1969. 50. M. E. Kabay, “Anonymity and Pseudonymity in Cyberspace: Deindividuation,
Incivility and Lawlessness versus Freedom and Privacy,” Annual Conference of the European Institute for Computer Anti-virus Research (EICAR), 1998, revised 2001, www.mekabay.com/overviews/anonpseudo.pdf
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 28 THE PSYCHOLOGY OF COMPUTER CRIMINALS
51. Tom Postmes, Russell Spears, and Martin Lea, “Social Identity, Normative Con- tent, and ‘Deindividuation’ in Computer-Mediated Groups,” In Social Identity: Context, Commitment, Content, ed. N. Ellemers, R. Spears, and B. Doosje (Ox- ford: Blackwell, 1999), 164–183.
52. Tom Postmes, Russell Spears, and Martin Lea, “Breaching or Building Social Boundaries? SIDE-Effects of Computer Mediated Communication,” Communi- cation Research, 25 (1998): 689–715.
53. Stephen D. Reicher, Russell Spears, and Tom Postmes, “A Social Identity Model of Deindividuation Phenomena,” European Review of Social Psychology, 6 (1995): 161–198.
54. Henri Tajfel and John C. Turner, “The Social Identity Theory of Inter-Group Behavior,” In Psychology of Intergroup Relations, ed. S. Worchel and L. W. Austin (Chicago: Nelson-Hall, 1986), 2–24.
55. Postmes, Spears, and Lea, “Social Identity,” 1999. 56. Postmes, Spears, and Lea, “Breaching or Building,” 1998. 57. Reicher, Spears, and Postmes, “A Social Identity Model,” 1995. 58. Jordan and Taylor, “A Sociology,” 1998. 59. Tajfel and Turner, “The Social Identity Theory,” 1986. 60. Woo, Kim, & Dominick, “Hackers: Militants or Merry Pranksters?” 2004. 61. Woo, Kim, & Dominick, “Hackers: Militants or Merry Pranksters?” 2004. 62. Woo, Kim, & Dominick, “Hackers: Militants or Merry Pranksters?” 2004. 63. Woo, Kim, & Dominick, “Hackers: Militants or Merry Pranksters?” 2004. 64. Rogers, “Modern-Day Robin Hood,” 1999. 65. Albert Bandura, “The Social Learning Perspective: Mechanisms of Aggression.”
In Psychology of Crime and Criminal Justice, ed. H. Toch (New York: Holt, Rinehart & Winston, 1979).
66. Bandura, “Social Learning Perspective,” 1979. 67. Thomas J. Holt, George W. Burruss, & Adam M. Bossler, “Social Learning and
Cyber-Deviance: Examining the Importance of a Full Social Learning Model in the Virtual World,” Journal of Crime & Justice, 33, no. 2 (2010): 31–61.
68. M. E. Kabay, “Totem and Taboo in Cyberspace: Integrating Cyberspace into Our Moral Universe,” Journal of the National Computer Security Association (1996): 4–9. www.mekabay.com/ethics/totem taboo cyber.pdf
69. Chiesa, Ducci, and Ciappi, Profiling Hackers, 2008. 70. Kabay, “Totem and Taboo,” 1996. 71. Holt, Burruss, and Bossler, “Social Learning and Cyber-Deviance,” 2010. 72. Bandura, “Social Learning Perspective,” 1979. 73. Myers, Social Psychology, 2005. 74. American Psychiatric Association, Diagnostic and Statistical Manual of Mental
Disorders, 4th ed. (DSM-IV) (Washington, DC: American Psychiatric Associa- tion, 1994).
75. American Psychiatric Association, DSM-IV , 1994. 76. Kabay, “Totem and Taboo,” 1996. 77. Eric D. Shaw, Keven Ruby, and Jerrold Post, “The Insider Threat to Information
Systems: The Psychology of the Dangerous Insider,” Security Awareness Bulletin, 2 (1998): 1–10.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 12 · 29
78. Kabay, “Totem and Taboo,” 1996. 79. Shaw, Ruby, and Post, “Insider Threat,” 1998. 80. American Psychiatric Association, DSM-IV , 1994. 81. Shaw, Ruby, and Post, “Insider Threat,” 1998. 82. Toxic Shock, “Another View of Hacking: The Evil That Hackers Do,” Computer
Underground Digest, 2 (1990). Available: http://cu-digest.org/CUDS2/cud2.html 83. Shaw, Ruby, and Post, “Insider Threat,” 1998. 84. Toxic Shock, “Another View,” 1990. 85. Marc Rogers, “Understanding Criminal Computer Behavior: A Personality
Trait and Moral Choice Analysis,” 2003, Marc Rogers’s Website, http://homes. cerias.purdue.edu/∼mkr/CPA.doc
86. Robert R. McCrae and Paul T. Costa, Jr. “Personality Trait Structure as a Human Universal,” American Psychologist, 52. (1997): 509–516.
87. Rogers, “Criminal Computer Behavior,” 2003. 88. Marcus Rogers, Kathryn Seigfried, and Kirti Tidke, “Self-Reported Computer
Criminal Behavior: A Psychological Analysis,” Digital Investigation, 3S (2006): 116–120.
89. Postmes, Spears, & Lea, “Social Identity,” 1999 90. Sherry Turkle, “Identity Crisis,” in Life on the Screen: Identity in the Age of the
Internet (New York: Simon & Schuster, 1995): 255–269. 91. M. J. Zuckerman, “Hacker Reminds Some of Asperger Syndrome,” USA
Today, March 3, 2001, www.usatoday.com/news/health/2001-03-29-asperger .htm
92. Suelette Dreyfus, “Cracking the Hackers’ Code,” The Sydney Morning Herald, August 8, 2002, http://smh.com.au/articles/2002/08/20/1029114072039.html
93. Bernadette H. Schell and June Meluychuk, “Female and Male Hacker Con- ferences Attendees: Their Autism-Spectrum Quotient (AQ) Scores and Self- ReportedAdulthood Experiences,” inCorporate Hacking and Technology-Driven Crime: Social Dynamics and Implications, ed. Thomas J. Holt and Bernadette H. Schell (Hershey, PA: IGI Global, 2011): 144–166.
94. American Psychiatric Association, DSM-IV , 1994. 95. American Psychiatric Association, DSM-IV , 1994. 96. Stephen Bauer, “Asperger Syndrome,” 2001, http://aspergersyndrome.org/ 97. Bauer, “Asperger Syndrome,” 2001. 98. Peter Smith, “The Cybercitizen Partnership: Teaching Children Cyber Ethics,”
Cybercitizen Partnership, 2000, www.cybercitizenship.org/ethics/whitepaper. html
99. Bauer, “Asperger Syndrome,” 2001. 100. Zuckerman, “Hacker Reminds Some,” 2001. 101. Dreyfus, “Cracking the Hackers’ Code,” 2002. 102. Dreyfus, “Cracking the Hackers’ Code,” 2002. 103. Zuckerman, “Hacker Reminds Some,” 2001. 104. Schell and Meluychuk, “Female and Male Hacker AQ Scores,” 2011. 105. DEFCON Website, www.defcon.org 106. Schell and Meluychuk, “Female and Male Hacker AQ Scores,” 2011.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 30 THE PSYCHOLOGY OF COMPUTER CRIMINALS
107. Bauer, “Asperger Syndrome,” 2001. 108. Mark Griffiths, “Internet Addiction: Does It Really Exist?” In Psychology and
the Internet: Intrapersonal, Interpersonal and Transpersonal Applications, ed. J. Gackenbach, (New York: Academic Press, 1998): 61–75.
109. K. E. Anderson, “International Intrusion: Motives and Patterns,” 1994, www. aracnet.com/∼kea/Papers/paper.shtml
110. Jerrold Post, Eric Shaw, and Keven Ruby, “Information Terrorism and the Dan- gerous Insider,” Paper presented at the InfowarCon, 1998, Washington, D.C.
111. Schell and Meluychuk, “Female and Male Hacker AQ Scores,” 2011. 112. Schell and Meluychuk, “Female and Male Hacker AQ Scores,” 2011. 113. Jordan and Taylor, “A Sociology,” 1998. 114. Jordan and Taylor, “A Sociology,” 1998. 115. August Bequai, Technocrimes (Lexington, MA: Lexington Books, 1987). 116. Dorothy E. Denning, “Concerning Hackers Who Break into Computer Systems,”
CPSR (1990), http://cyber.eserver.org/hackers.txt 117. Michael Bachmann, “The Risk Propensity and Rationality of Computer Hackers,”
International Journal of Cyber Criminology, 4 (2010): 643–656. 118. Csikszentmihalyi, Mihaly, Flow (Harper Perennial Modern Classics, 2008). 119. Alexander E. Voiskounsky and Olga V. Smyslova, “Flow-Based Model of Com-
puter Hackers’ Motivation,” CyberPsychology & Behavior, 6, no. 2 (2003): 171–161.
120. Voiskounsky & Smyslova, “Flow-Based Model,” 2003. 121. Rogers, “Modern-Day Robin Hood,” 1999. 122. Post, Shaw, and Ruby, “Information Terrorism,” 1998. 123. Denning, “Concerning Hackers,” 1990. 124. Ira Winkler, “Why Hackers Do the Things They Do?” Journal of the National
Computer Security Association, 7 (1996): 12. 125. Woo, Kim, and Dominick, “Hackers: Militants or Merry Pranksters?” 2004. 126. Denning, “Concerning Hackers,” 1990. 127. Brian Harvey, “Computer Hacking and Ethics,” Brian Harvey’s Website, 1998,
www.cs.berkeley.edu/∼bh/hackers.html 128. Winkler, “Why Hackers Do,” 1996. 129. Harvey, “Computer Hacking and Ethics,” 1998. 130. Turgeman-Goldschmidt, “Hackers’ Accounts,” 2005. 131. Turgeman-Goldschmidt, “Hackers’ Accounts,” 2005. 132. Winkler, “Why Hackers Do,” 1996. 133. Winkler, “Why Hackers Do,” 1996. 134. Vincent Sacco and Elia Zureik, “Correlates of Computer Misuse: Data from
a Self-Reporting Sample,” Behavior & Information Technology, 9 (1990): 353–369.
135. Harvey, “Computer Hacking and Ethics,” 1998. 136. Harvey, “Computer Hacking and Ethics,” 1998. 137. Myers, Social Psychology, 2005. 138. Rogers, “Modern-Day Robin Hood,” 1999.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 12 · 31
139. Harvey, “Computer Hacking and Ethics,” 1998. 140. Shaw, Ruby, and Post, “Insider Threat,” 1998. 141. Mentor, “The Hacker Manifesto,” Phrack Magazine, January 8, 1986,
www.mithral.com/∼beberg/manifesto.html 142. William Golding, Lord of the Flies (London: Faber and Faber, 1954). 143. Kabay, “Totem and Taboo,” 1996. 144. Denning, “Concerning Hackers,” 1990. 145. Marc Rogers, “A New Hacker Taxonomy,” Marc Rogers’s Website, 2000,
http://homes.cerias.purdue.edu/∼mkr/hacker doc.pdf 146. Rogers, “A New Hacker Taxonomy,” 2000. 147. Rogers, “A New Hacker Taxonomy,” 2000. 148. Rogers, “Meaningful Hacker Taxonomy,” 2005. 149. A. N. Chantler, “Risk: The Profile of the Computer Hacker.” Ph.D. dissertation,
Curtin University of Technology, 1995. 150. Rogers, “A New Hacker Taxonomy,” 2000 151. Bill Landreth, Out of the Inner Circle (Redmond, WA: Microsoft Books, 1985). 152. Donn Parker, Fighting Computer Crime: A New Framework for Protecting Infor-
mation (New York: John Wiley & Sons, 1998). 153. Rogers, “Meaningful Hacker Taxonomy,” 2005. 154. Landreth, Out of the Inner Circle, 1985. 155. Bequai, Technocrimes, 1987. 156. Kabay, “Totem and Taboo,” 1996. 157. Post, Shaw, and Ruby, “Information Terrorism,” 1998. 158. See B. Guinen and M. E. Kabay, “The Russian Cybermafia: Beginnings,” 2011,
www.mekabay.com/nwss/866 russian cybercrime (guinen) part 1.pdf; M. E. Kabay and B. Guinen, “The Russian Cybermafia: Boa Factory & CarderPlanet,” 2011, www.mekabay.com/nwss/867 russian cybercrime (guinen) part 2.pdf; and B. Guinenand M. E. Kabay, “The Russian Cybermafia: RBN & the RBS WorldPay Attack,” 2011, www.mekabay.com/nwss/868 russian cyber crime (guinen) part 3.pdf
159. Chantler, “Risk,” 1995. 160. Chantler, “Risk,” 1995. 161. Chantler, “Risk,” 1995. 162. Rogers, “A New Hacker Taxonomy,” 2000. 163. Parker, Fighting Computer Crime, 1998. 164. Rogers, “Meaningful Hacker Taxonomy,” 2005. 165. Winkler, “Why Hackers Do,” 1996. 166. Eric D. Shaw, “The Role of Behavioral Research and Profiling inMalicious Cyber
Insider Investigations,” Digital Investigation, 3 (2006): 20–31. 167. Eric D. Shaw and Harley V. Stock, “Behavioral Risk Indicators of Mali-
cious Insider Theft of Intellectual Property: Misreading the Writing on the Wall,” Symantec White Paper, 2011, https://www4.symantec.com/mktginfo/ whitepaper/21220067 GA WP Malicious Insider 12 11 dai81510 cta56681.pdf
168. Steven Levy, Hackers (New York: Dell Publishing, 1984).
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
12 · 32 THE PSYCHOLOGY OF COMPUTER CRIMINALS
169. Samantha Murphy, “Culture Lab: Inside the Hacktivists Revolution,” Culture- Lab | New Scientist, April 12, 2012, www.newscientist.com/blogs/culturelab/ 2012/04/samantha-murphy-contributorit-is-the.html
170. Thomas J. Holt, “The Attack Dynamics of Political and Religiously Moti- vated Hackers,” In Cyber Infrastructure Protection, ed. Tarek Saadawi and Louis Jordan Jr., (Strategic Studies Institute, 2011): 159–180, www.strategic studiesinstitute.army.mil/pdffiles/PUB1067.pdf
171. Marc Rogers, “The Psychology of Cyber-Terrorism,” In Terrorists, Victims, and Society: Psychological Perspectives on Terrorism and its Consequences, ed. A. Silke (London: Wiley & Sons, 2003).
172. Alexander Gostev and Costin Raiu, “Kaspersky Security Bulletin. Malware Evolution 2011,” Securelist Website, 2012, www.securelist.com/en/analysis/ 204792217/Kaspersky Security Bulletin Malware Evolution 2011
173. Holt, “Attack Dynamics,” 2011. 174. Verizon, “Data Breach Investigations Report,” 2012. 175. Rogers, “Psychology of Cyber-Terrorism,” 2003. 176. Rogers, “Psychology of Cyber-Terrorism,” 2003. 177. Rogers, “Psychology of Cyber-Terrorism,” 2003. 178. Symantec, Internet Security, 2012. 179. Holt, “Attack Dynamics,” 2011. 180. Rogers, “Psychology of Cyber-Terrorism,” 2003. 181. Shaw, Ruby, and Post, “Insider Threat,” 1998. 182. Shaw, “Role of Behavioral Research,” 2006. 183. Shaw and Stock, “Behavioral Risk Indicators,” 2011. 184. Shaw and Stock, “Behavioral Risk Indicators,” 2011. 185. Shaw, Ruby, and Post, “Insider Threat,” 1998. 186. Shaw, Ruby, and Post, “Insider Threat,” 1998. 187. Shaw, Ruby, and Post, “Insider Threat,” 1998. 188. Shaw, “Role of Behavioral Research,” 2006. 189. Shaw and Stock, “Behavioral Risk Indicators,” 2011. 190. Rogers, “Meaningful Hacker Taxonomy,” 2005. 191. Andrew Bissett and Geraldine Shipton, “Some Human Dimensions of Computer
Virus Creation and Infection,” International Journal of HumanComputer Studies, 52, No. 5 (2000), pp. 1071–5819.
192. Sarah Gordon, “The Generic Virus Writer,” 4th International Virus Bulletin Conference, Jersey, U.K. (September 1994). http://vxheaven.org/lib/static/vdat/ epgenvr2.htm
193. Sarah Gordon, “The Generic Virus Writer II,” 6th International Virus Bul- letin Conference, Brighton, U.K. (September 1996). www.research.ibm.com/ antivirus/SciPapers/Gordon/GVWII.html
194. Sarah Gordon, “Virus Writers: The End of Innocence?” Presented at the 10th In- ternational Virus Bulletin Conference (September 2000). http://vxheaven.org/lib/ asg12.htm
195. Bissett and Shipton, “Some Human Dimensions,” 2000. 196. Bissett and Shipton, “Some Human Dimensions,” 2000.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 12 · 33
197. Bissett and Shipton, “Some Human Dimensions,” 2000. 198. Gordon, “Generic Virus Writer,” 1994. 199. Gordon, “Generic Virus Writer II,” 1996. 200. Gordon, “Virus Writers,” 2000. 201. Myers, Social Psychology, 2005. 202. Gordon, “Generic Virus Writer II,” 1996. 203. Gordon, “Generic Virus Writer II,” 1996. 204. Gordon, “Generic Virus Writer II,” 1996. 205. Gordon, “Generic Virus Writer II,” 1996. 206. Gordon, “Generic Virus Writer II,” 1996. 207. Rogers, “Meaningful Hacker Taxonomy,” 2005. 208. Gordon, “Virus Writers,” 2000. 209. A. S. Dalal, & Raghav Sharma, “Peeping into a Hacker’s Mind: Can Criminolog-
ical Theories Explain Hacking?” ICFAI Journal of Cyber Law 6, no. 4 (2007): 34–47.
210. Rogers, “Meaningful Hacker Taxonomy,” 2005. 211. Holt, Burruss and Bossler, “Social Learning and Cyber-Deviance,” 2010. 212. Gordon, “Virus Writers,” 2000. 213. Gordon, “Virus Writers,” 2000. 214. Young, Zhang, and Prybutok, “Hacking into the Minds,” 2007. 215. Shaw and Stock, “Behavioral Risk Indicators,” 2011. 216. Shaw and Stock, “Behavioral Risk Indicators,” 2011. 217. M. E. Kabay, “Time for Industry to Support Academic INFOSEC,”M. E. Kabay’s
Website, 2004. www.mekabay.com/opinion/endowed chairs.pdf
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
13CHAPTER
THE INSIDER THREAT
Gary L. Tagg, CISSP
13.1 INTRODUCTION 13 ·1
13.2 THREATS FROM INSIDERS 13 ·2 13.2.1 How Common Are
Insider Attacks? 13 ·2 13.2.2 Examples of Insider
Attacks 13 ·3 13.2.3 Types of Insider
Threats 13 ·5 13.2.4 Internet-Based
Systems 13 ·6 13.2.5 Service Provider
Threats 13 ·7 13.2.6 System
Administration Threats 13 ·7
13.3 MITIGATING THE INSIDER THREAT 13 ·7 13.3.1 System and Asset
Inventories 13 ·8 13.3.2 Data Loss Prevention
(DLP) 13 ·8 13.3.3 Internal Honeypots 13 ·10
13.4 CONCLUDING REMARKS 13 ·10
13.5 FURTHER READING 13 ·11
13.6 NOTES 13 ·11
13.1 INTRODUCTION. An insider is someone who has been given a role within an organization and has access to premises and/or internal systems and information. There are many types of roles; some are core to the business and performed by em- ployees, while others are non-core and contracted out to service providers such as cleaning, maintenance, or information technology (IT). The categories of insiders may be classified as: Current staff work directly for and under the control of the organization’s manage-
ment. This category includes employees as well as temporary staff, contractors, and consultants. Most of these people are located on the organization’s premises and are connected to the internal network with access to internal information. Departing staff represent one of the highest risks to an organization. These people
consist of employees who have resigned or are planning to do so, temporary staff, contractors or consultants coming to the end of their contract, as well as all the people whose employment or services are being ended by the organization. These people still have access to internal information, and may be motivated to take that information with them when they leave, or to commit sabotage in revenge for perceived wrongs. Former staff are those who are no longer employed by or providing services to the
organization. This group still has insider knowledge, and without mitigating controls, they can do substantial damage long after they have left the organization. Former staff can be highly motivated to attack their former employers.
13 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
13 · 2 THE INSIDER THREAT
Service-providers: Organizations have many roles that are necessary for the smooth running of the business but that are not core to the company’s mission. Examples of these roles are cleaning services, maintenance, and IT. Over the last 20 years, service providers have steadily moved up the service stack to perform core functions as well. It is now common for service providers to perform business operations and even to be the first point of contact with customers. Although not all service providers will need access to premises or internal systems, there are many roles that do.
The key distinction between service providers and staff is that staff (who can be provided by service providers) are working under the control of the organization’s management and subject to its policies and procedures; in contrast, service providers are providing a specified service, and all personnel are the responsibility of the service provider. This situation increases risk to the organization, as it has little control over service-provider staff, but the threats are the same as from internal staff. Partners: Organizations are partners when they work together on a business venture.
Access to information goes up to senior business leaders within the partners. Partner- ships may be short or long term, and partners may be competitors at the same time as being partners. This situation creates risk for the organization, which has to share information relevant to the partnership but not other internal information.
The term partner is sometimes used where service providers are performing key functions for an organization and success of the service is essential. For these key contracts, it is good practice to treat the service provider more like a partner than a vendor, but for insider threat purposes they are service providers.
13.2 THREATS FROM INSIDERS. Successful organizations need to have peo- ple in many different roles, with the primary distinction between business roles (business management, sales, customer services, and product design) and sup- port/infrastructure roles (IT, finance, logistics, human resources, and the like).
The people in each role need access to information and systems to perform their role, and the key point to make at this stage is that the impact an insider attack makes on the organization is related to the insider role. A salesman leaving an organization to join a competitor will have had access to customer- and product-related information, whereas someone in product design is likely to have access to valuable intellectual property on current and future products. Customer service center staff are likely to have access to customers’ personally identifiable information (PII) that can be used to commit identity fraud.
IT is a high-risk area, and is essential to the efficient running of the business. Most of an organization’s information is stored in its IT systems, and without proper controls, IT administrators could have access to everything.
13.2.1 How Common Are Insider Attacks? According to the 2011 CyberSecurity Watch Survey,1 21 percent of electronic crime events were conducted by insiders, 58 percent by outsiders, and 21 percent unknown. Of the insider events, 76 percent were dealt with internally without legal action or law enforcement, which is likely a reason that external attacks are more often in the news.
The 2012 U.K. Information Security Breaches Survey2 provides some interesting statistics.
� 6 percent of the responding 447 organizations reported staff sabotage of systems, with some organizations experiencing incidents on a weekly basis
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
THREATS FROM INSIDERS 13 · 3
� 19 percent of large organizations reported that staff used systems to commit theft or fraud, and this figure had doubled since the survey in 2010
� With regard to other incidents caused by insiders, large organizations were more likely to experience incidents, with 82 percent reporting incidents versus 45 per- cent for small organizations
� 61 percent of large organizations reported unauthorized access to systems or data � 45 percent reported a breach of data protection laws or regulations � 36 percent reported misuse of confidential information � 47 percent reported loss or leakage of confidential information
The 2013 U.K. Information Security Breaches Survey3 includes the following rele- vant information for this chapter (quoting directly from the Executive Summary—note U.K. spelling):
� 36% of the worst security breaches in the year were caused by inadvertent human error (and a further 10% by deliberate misuse of systems by staff)
� 57% of small businesses suffered staff-related security breaches in the last year (up from 45% a year ago)
� 17% of small businesses know their staff broke data protection regulations in the last year (up from 11% [in the 2012 report])
� 14% of large organisations had a security or data breach in the last year relating to social networking sites
� 9% of large organisations had a security or data breach in the last year involving smartphones or tablets
� 4% of respondents had a security or data breach in the last year relating to one of their cloud computing services
� 4% of the worst security breaches were due to portable media bypassing defences
13.2.2 Examples of Insider Attacks. To get an understanding of the types of insider events, a number of organizations maintain databases and publish results. The FBI maintains an Insider Threat page on their Website4 containing a list of prosecuted insider theft cases. A short summary of these cases follows:
� Retired research scientist conspired with current and former employees to steal trade secrets from his former employer, and sell them to companies in China.
� Employee working for two different U.S. companies stole trade secrets from both companies which were used to benefit Chinese universities.
� A research scientist stole trade secrets from her employer andmade them available for sale through her own company.
� An employee stole customer and employee lists, contract information, and other trade secrets to provide to a foreign government, but instead gave them to an undercover FBI agent.
� A computer programmer working for a financial firm copied proprietary software during his last few days at the company.
� An employee who was fired had kept copies of trade secrets. These trade secrets were then sold to a rival company.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
13 · 4 THE INSIDER THREAT
� An employee stole and attempted to sell trade secrets that provided everything needed to start a competing business.
� Over a two-day period, an employee copied hundreds of technical documents from her employer, which were found in her luggage during a check at the airport.
� Spies working for U.S. defense companies stole internal information about the space shuttle, Delta IV rocket, the C-17military plane, and submarine propulsion systems, along with other information. This information was provided to the Chinese government.
In a summary of the “Top Five Insider Attacks of the Decade,” the Linux.com editorial board listed the following cases5:
� RogerDuroniowas convicted in 2006 to eight and a half years in federal prison6 for his actions in 2002when, apparently in a fit of pique at not receiving what he considered an adequate annual bonus, he sabotaged the computer systems of his employer, UBS PaineWebber. “UBS was hit on March 4, 2002, at 9:30 in the morning, just as the stock market opened for the day. Files were deleted from up to 2,000 servers in both the central data center in Weehawken, N.J., and in branch offices around the country. Company representatives never reported the cost of lost business but did say it cost the company more than $3.1million to get the system back up and running. Duronio worked at UBS as a systems administrator until he quit a few weeks before the attack. Witnesses testified that he quit because he was angry that he didn’t receive as large an annual bonus as he expected. Investigators found copies of the malicious code on two of his home computers and on a printout sitting on his bedroom dresser.”7
� In 2005, a sting operation by a The Sun reporter from Britain netted him confiden- tial details of more than a thousand “… accounts, passports, and credit cards…” from NatWest and Barclays banks. This led to investigations of call centers in India, when criminals “… boasted of being able to provide details of as many as 200,000 bank accounts in a month, which, he further said, came from more than one call center.”8
� The “Athens Affair” was discovered when investigators looked into the appar- ent suicide of an electrical engineer, Costas Tsalikidis, in his Athens apartment. The inside job by Tsalikidis, the head of network planning, and unknown oth- ers compromised the Vodafone-Panafon company (“Vodafone Greece”) using malware and may have resulted in monitoring and recording of conversations involving “… the prime minister, his defense and foreign affairs ministers, top military and law-enforcement officials, the Greek EU commissioner, activists, and journalists.”9
� San Francisco network administrator Terry Childs locked other employees out of the city’s network in July 2008 because he claimed that his supervisor was unqual- ified to have administrative control. He was sentenced to four years in California state prisons. “Prosecutors characterized the former network administrator as a power hungry control freak who couldn’t be managed.”10
� Bradley Manning, a 22-year-old U.S. Army intelligence analyst, was arrested in May 2010 and charged in July 2010with leaking nearly half a million classified U.S. videos and cables to the WikiLeaks project.11 He was charged with “aid- ing the enemy” in February 201212 and accused of aiding the terrorist group al
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
THREATS FROM INSIDERS 13 · 5
Qaida through his actions.13 In January 2013, the trial was rescheduled until June 201314 and Manning was denied the opportunity to justify his actions using a whistleblower defense.15
� The Sunday Times reported in 2012 that “Confidential personal data on hundreds of thousands of Britons is being touted by corrupt Indian call centre workers, an undercover investigation has discovered. Credit card information, medical and financial records are being offered for sale to criminals and marketing firms for as little as 2p.” Records of 500,000 Britons were apparently for sale, many of which were supposedly less than 72 hours old and included “… sensitive material about mortgages, loans, insurance, mobile phone contracts, and Sky Television subscriptions…”16
13.2.3 Types of Insider Threats. There are three main classifications of in- sider threats: accidental, malicious, and nonmalicious.
13.2.3.1 Accidental Threats. Accidental threats are generally caused by mis- takes; for example, staff may not follow operating procedures due to carelessness, disregard for policies, or a lack of training and awareness of the right thing to do. An example is a customer service representative who accidentally breaches client con- fidentiality by emailing client information to the wrong email address. Such errors may be caused by the use of email clients that have an auto-complete feature on the email address; staff under pressure to keep up with the volume of work may not notice the error before they send the data. This error is a particularly high risk for financial services organizations where in some jurisdictions a client confidentiality breach is a criminal offense.
Other typical examples include a database administrator who accidentally deletes a database table during maintenance, a systems administrator allowing a programmer to modify a production system without proper approvals, or an operator reformatting a disk drive without having two full, verified backups.
13.2.3.2 Malicious Threats. Malicious threats deliberately try to damage the organization or to benefit the attacker. Disgruntled IT administrators can sabotage IT systems, bringing an organization to a halt. There have been many incidents where both current and former administrators have deliberately caused system issues for various motives: enjoying the lifestyle of traveling around the world in luxury to fix the problems they created, extorting money from the organization, or simply causing as much damage as possible.
Some company information is highly valuable and specifically targeted by attackers. PII is one category that is sometimes illegally copied by staff to conduct identity theft and fraud, or to sell it to criminals. Another category is intellectual property (IP) such as trade secrets. Staff may take this information to help them with their next job or to sell to competing companies. This crime is thought to be common with IT developers who often seek to take their source code with them. Industrial espionage sponsored by rival companies or foreign governments is another common threat to IP (see Chapter 11 in this Handbook for examples).
Information can leave an organization by being copied to removable storage such as USB flash or hard drives and CD/DVD writers. Portable 3TB drives are now readily available, which means entire databases can be copied to a drive measuring less than 7 × 5 inches in size. With gigabit ethernet becoming standard, the time required to copy
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
13 · 6 THE INSIDER THREAT
this data is rapidly decreasing. Other common channels include emailing attachments to external email addresses, uploading files to external email services and to Internet Websites, and using cloud backup and cloud storage tools. To address these data-leakage channels, products known as data loss prevention (DLP) systems are increasingly being installed in organizations.17
There are also the common physical threats, such as taking printed information from people’s desks or from the office printers. Where logical access controls are strong, staff intent on stealing information can take photographs of documents or information on screen with the high-resolution cameras in today’s mobile phones.
There are some incidents where the motive may be conscience based as well as having a desire to damage an organization. Since the financial crisis in 2008, gov- ernments have increased their efforts to reduce tax avoidance, and are aggressively pursuing the use of foreign tax havens. There have been a number of publicized inci- dents where insiders have provided lists of offshore clients and accounts to country tax authorities.18,19
13.2.3.3 Nonmalicious Threats. Nonmalicious threats are actions taken de- liberately by people without intent to damage the organization. Often, the motive is to increase productivity, and the mistakes occur due to a lack of training or awareness of policies, procedures, and the risk. There have been many incidents in which staff loaded internal information onto Internet-based systems, some of which have no access controls. This error makes the information available to anyone who uses the sites and is often found and indexed by search engines.
One incident occurred in the early days of cloud computing. A drug researcher was given a lengthy lead time by his internal IT department for the delivery of infrastructure to conduct simulations. What he did instead was use his credit card to buy time on cloud-based systems and ran the simulations there instead. This would have put valuable intellectual property at risk had these Internet systems been compromised. This information was also sitting on the cloud provider’s storage systems; what if the cloud vendor were to fail to reinitialize the storage when reallocating released storage to another customer, and the next user of the storage were to understand the value of what came pre-loaded on their system—and be dishonest?
Another example that is often reported in the media is the loss of PII when staff copy information to laptop computers or to removable storage devices such as USB drives or CDs/DVDs, which are then lost or stolen.20
One common insider threat that can happen for both malicious and nonmalicious reasons is to email internal information to their home email address. Once on the staff member’s own computer, the information is vulnerable to theft, successful attack on the computer or email account, or recycling of the machine by donating it to charity, or giving it away to family or friends. There have been many media reports of people finding sensitive information on secondhand computer hard disks.21
The nonmalicious motive for this practice is often to enable the employee to work from home, or the information is needed for a business trip. The malicious motive is to take the information with them, for reasons covered earlier.
13.2.4 Internet-Based Systems. The growing trend to use outsourced appli- cations available over the Internet rather than internal systems can contribute to insider crime. With internal systems, when someone leaves an organization, they no longer have physical access to premises, and their network and application user-ids are sup- posed to be disabled immediately, removing access to corporate networks, computers,
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
MITIGATING THE INSIDER THREAT 13 · 7
and applications. Appropriate action makes it difficult for even maliciously motivated former staff to access confidential systems and their information.
But with Internet-based systems, the former staff member may still have access to confidential data via any Internet connection. It is very difficult to ensure all application accounts are promptly closed when someone leaves, creating a high risk of continued access to these systems. The people concerned may be deterred by the risk of being prosecuted for misusing their rights after leaving the organization, but their risk can be reduced if they use a former colleague’s log-on account.
Organizations don’t have to avoid using these external services; indeed, these ex- ternal services are often among the best available, and can be provided at a much lower cost than hosting internally. However, security officers must coordinate closely with their human resources departments and the IT people responsible for maintaining the lists of external providers to ensure that access by former employees to external services is shut down as quickly as access to internal systems.
13.2.5 Service Provider Threats. Even organizations with strong personnel controls that reduce the risk from internal staff may have no protection from external service-provider staff. Although organizations commonly include their policies, stan- dards, and procedures into contracts and treat this precaution as sufficient to address risk, the service provider may not consistently perform all the required controls, either through attempts to maximize profit or through poor management.
For example, a service provider faced with high staff turnover might bypass preem- ployment checks to get replacement staff quickly onto a service, particularly if there are service performance issues. Similarly, poor standards for handling termination of employment at the service provider could lead to compromise of client information.
In caseswhere an entire IT service is being provided by a service provider, the service provider’s staff and IT administrators may have access to all the client organization’s information. Email is a particular risk that may contain a great deal of an organization’s intellectual property and that has powerful search facilities to easily target individuals and specific information.
13.2.6 System Administration Threats. System administrators have priv- ileged access to an organization’s IT infrastructure and, in poorly managed systems, may have access to critical and sensitive information on the systems. System admin- istrators may deliberately attack the availability of an organization’s systems even if they cannot access the data themselves. Administrators may destroy individual data sets, applications, or entire systems and networks—and may be able to destroy system backups to make the organization’s recovery more difficult. This risk is most acute in smaller organizations, in which one person may manage the servers, applications, net- works, email, backups, and perhaps even user administration. In larger organizations, it is much easier to segregate these roles as they should be, thus limiting access and therefore the damage one person can cause.
Even in large organizations with thousands of servers with effective segregation im- plemented, an administrator may be able to submit a job that can be run simultaneously on every server to wipe every hard disk. This type of threat highlights the importance of controlling the access and scope of administrators and preventing unauthorized changes from being implemented.
13.3 MITIGATING THE INSIDER THREAT. This section describes at a high level a few of some specific mitigating controls and how they address the insider threat.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
13 · 8 THE INSIDER THREAT
For more details on the wider range of controls, refer to the detailed informa- tion in other chapters in this Handbook such as Chapter 15 (Penetrating Computer Systems and Networks), Chapter 28 (Identification and Authentication), Chapter 31 (Content Filtering and Web Monitoring), Chapter 45 (Employment Practices and Poli- cies), Chapter 52 (Application Controls), Chapter 53 (Monitoring and Control Sys- tems), Chapter 54 (Security Audits and Inspections), Chapter 55 (Cyber Investigation), Chapter 56 (Computer Incident Response Teams), and Chapter 68 (Outsourcing and Security).
13.3.1 System and Asset Inventories. If you don’t know what you have, you can’t manage it. Without an inventory of servers, you can’t ensure they are patched, enabling an insider to compromise them and use them for their own purposes. Without a list of applications running on each server, you may have unnecessary servers sitting on your network being used for unauthorized purposes. The active systems on the network also need to correlate to the inventory. An administrator who doesn’t remove a redundant system in your Internet DMZ could use it to bypass all of your network perimeter controls after he has left the organization.
In particular, one of the most dangerous tools for insider crime is the unauthorized and undetected wireless access point—easily purchased from any electronic store for at low cost and capable of transferring data from an internal network to unauthorized devices within the corporate facilities or even to external agents within a modest radius outside the building. See Chapter 33 in this Handbook for discussion of wireless network security.
13.3.2 Data Loss Prevention (DLP). There have been technology adoptions over the last 10 years which have made it much easier for staff to either accidentally or deliberately breach the confidentiality of organizational and client information. Data loss prevention (DLP) is a class of IT security system increasingly being implemented by organizations to help address these risks. A typical DLP system needs to address the following vulnerabilities at a minimum:
� Mobile storage devices/removable media, such as USB memory sticks and hard drives, mobile phones, memory cards, CD/DVD writers, along with infrared, Bluetooth, FireWire, and SCSI-connected storage.
� File uploads—including encrypted data—to external Websites via the standard protocols within Web browsers, such as ftp, http, and https. These controls may be enforced at both the Internet gateway as well as on the desktop.
� Detection of when laptops are not on the corporate network and preventing files being copied to noncorporate file shares.
For the majority of staff, the DLP system can be configured to block attempts to copy and upload data to these data-leakage channels. However, for most of these channels, there are going to be some people who have a genuine business need to copy and upload information, resulting in exceptions to the policy. The DLP system can help manage this risk by creating a log of what has been copied to support incident investigation or to enable a review of what a staff member has copied out of the organization. These facilities can be particularly useful when an employee hands in his resignation.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
MITIGATING THE INSIDER THREAT 13 · 9
13.3.2.1 Email Data Leakage. Once the low-hanging fruit of removable stor- age and file uploads are blocked, staff begin to export information via email. Themotive may not be malicious, but it still results in the organization’s losing control over the information. To address this risk, the DLP system can be configured to report on peo- ple sending attachments to home email addresses, which is the usual destination for information, or to any unauthorized email address. These reports can then be used to increase staff awareness about policy or to support disciplinary processes for deliberate data leakage.
However, the true benefit from DLP comes when the business areas are engaged, because DLP can drive a process of identifying and defining the critical information that has to be protected. For example, the IT development group could have a DLP rule that blocks emails containing source code, to prevent developers taking their work with them when they leave. Even if source code is placed in an encrypted zip file to try and avoid detection, the metadata (e.g., filenames and identifiers of file creators) may still be readable and can trigger the rule.
For other areas of the business, client information, business strategy, business results, intellectual property, and PII such as credit card numbers and Social Security numbers can be configured into the DLP system.
13.3.2.2 Data Leakage Using Cloud Storage. Widespread availability of external data storage facilities (e.g., Dropbox and Google Drive) adds to the complexity of DLP. Careful application of Web monitoring and blacklisting specific URLs may be helpful, but determined opponents of the regulations may circumvent such meth- ods using a variety of proxy avoidance Websites which mask the destination of the HTTP request. Security administrators should be on the lookout for new sites so they can add them to the corporate blacklists for outbound communications through their firewalls.
13.3.2.3 Difficulties with DLP. DLP is not a panacea. It is difficult if not impossible to prevent someone determined to leak data, but with a DLP system, one can make it difficult for them to do so without detection, and this barrier usually deters the majority of people.
With email DLP, it is very difficult to identify safe blocking rules that prevent data leakage. For example, if employees routinely send emails to customers, some of these customers are going to be using their home email addresses, which means that a hard block (blacklisting) of emails sent to home email addresses won’t be feasible.
13.3.2.4 Legal Issues with DLP. With the implementation of DLP, an orga- nization progresses from investigating reported incidents to actively monitoring for breaches of company policy. One of the major issues with implementing a global DLP system is that active monitoring may be subject to privacy and workplace laws, and failure to comply with these laws in some countries is a criminal offence.
Additionally, with customer and organization information being captured in DLP logs, consideration needs to be given as to where the log files are stored and who will be reviewing them. As an example from the financial services industry, some information is price sensitive and there are strict requirements on who can access it, to prevent insider dealing. Client information within the log files may be covered under banking secrecy laws and regulations. If the log files for one country are stored on a server in another country, then outsourcing regulations need to be complied with as well, and planners must identify the most stringent regulations to ensure efforts for
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
13 · 10 THE INSIDER THREAT
compliance. Data protection laws have been enacted in many countries that require data subjects to give their agreement to their information being processed and for defined purposes; therefore, monitoring of communications may need to be included in customer contracts and other data protection declarations.
Despite all of these hurdles, for most countries, it is possible to roll out a DLP sys- tem. As part of the project planning stage, the organization needs to commission a legal investigation for each country to understand whether it is lawful to actively monitor corporate email, but more importantly, the preconditions for anymonitoring to lawfully take place. For countries that forbid email monitoring or any form of workplace surveil- lance, it is usually possible to implement blocking controls on writing to removable storage along with uploads to external Websites, provided no log files are kept.
13.3.2.5 Remote Access Solution. A commonly implemented remote access solution is the provision of Webmail from home computers. With Webmail you need to configure the system to prevent staff opening attachments within local applications on the home computer. If this is not blocked, staff can copy corporate information by saving the open attachment to their local hard drive. In addition, any use of the Remote Desktop Protocol (RDP) also needs to be properly configured to prevent local USB resources being mapped to the remote computer.
13.3.3 Internal Honeypots. Honeypots are attractive systems or nodes that appear to have valuable confidential data. Roger Grimes, author of a textbook about honeypots,22 writes:
One of the best things you can do to get early warning of internal attackers is to implement honeypots.… because they’re low cost and low noise—and they work!
Because the internal attackers you seek could be trusted IT employees, the entire project must be kept secret. It should be known only to the sponsor, management, and the implementers. Often, we give the project a boring code name like Marketing Business Development, which is used in all documents and e-mails, avoiding terms having anything to do with honeypots. Don’t even tell the network security people about it, in so far as you can and still have an operational project. Then take a few computers that are destined for de-provisioning or the scrap heap and turn them into your honeypots.23
The point of such a honeypot is that there should be zero access to it: It serves no function and there is never a reference to it in any internal or external documentation. Thus, anyone who accesses it is either doing, so by pure accident or is violating policies governing unauthorized access to internal data (there is no one authorized to access the honeypot). Detailed logging should be in place at all times to provide forensic information immediately; however, administrators should ensure that they can actually visualize exactly what is being done in real time, not simply rely on the detailed log files for after-the-fact analysis. An early-warning system should immediately alert system administrators to the problem (preferably as the access is in progress) via screen messages, voice messages, and text messages.
13.4 CONCLUDING REMARKS. Fighting the insider threat need not be solely reactive. In addition to the entire spectrum of information assurance measures covered throughout this Handbook, maintaining an environment of security awareness and of encouragement, trust, fair-dealing, and long-term commitment to the welfare of employees must remain among the very best approaches to reducing the risk of insider crime.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 13 · 11
13.5 FURTHER READING Department of Defense. DoD Insider Threat Mitigation: Final Report of the In-
sider Threat Integrated Process Team. DoD. 2000. www.dtic.mil/cgi-bin/ GetTRDoc?AD = ADA39138
Noonan, T. & E. Archuleta. The National Infrastructure Advisory Council’s Fi- nal Report and Recommendations on the Insider Threat to Critical Infras- tructures.NIAC. 2008. www.dhs.gov/xlibrary/assets/niac/niac insider threat to critical infrastructures study.pdf
Silowash, G., D. Gappelli, A. Moore, R. Trzeciak, T. J. Shimeall, L. Flynn. Common Sense Guide to Mitigating Insider Threats, 4th ed. CMU/SEI. 2012. Technical Report CMU/SEI-20120TR-012. www.sei.cmu.edu/reports/12tr012.pdf
13.6 NOTES 1. CMU/SEI 2011 2. PwC 2012 3. PwC 2013 4. See www.fbi.gov/about-us/investigate/counterintelligence/the-insider-threat 5. Linux.com editorial staff, “Top Five Insider Attacks of the Decade,” LINUX.COM,
January 13, 2011, www.linux.com/news/technology-feature/security/397143-top- five-insider-attacks-of-the-decade
6. Sharon Gaudin, “Ex-UBS Systems Admin Sentenced To 97Months In Jail,” In- formationWeek, December 13, 2006, www.informationweek.com/ex-ubs-systems- admin-sentenced-to-97-mon/196603888
7. Sharon Gaudin, “Ex-UBS Sys Admin Found Guilty, Prosecutors To Seek Maxi- mum Sentence,” InformationWeek, July 19, 2006, www.informationweek.com/ex- ubs-sys-admin-found-guilty-prosecutor/190700064
8. SiliconIndia News, “Indian call centers selling U.K.’s secrets,” SiliconIn- dia News, June 23, 2005, www.siliconindia.com/shownews/Indian call centers selling UKs secrets-nid-28560-cid-2.html
9. Vassilis Prevelakis and Diomidis Spinellis, “The Athens Affair: How some ex- tremely smart hackers pulled off the most audacious cell-network break-in ever,” IEEE SPECTRUM, June 29, 2007, http://spectrum.ieee.org/telecom/security/the- athens-affair
10. Robert McMillan, “Network admin Terry Childs gets 4-year sentence,” Network- World, August 17, 2012, www.networkworld.com/news/2010/080710-network- admin-terry-childs-gets.html
11. Chris McGreal, “US private Bradley Manning charged with leaking Iraq killings video,” The Guardian, July 6, 2010, www.guardian.co.uk/world/2010/jul/06/ bradley-manning-charged-iraq-killings-video
12. Karen McVeigh, “Bradley Manning defers plea after being formally charged with aiding the enemy: No date set for WikiLeaks suspect’s trial but Man- ning’s lawyer says he would object to any delay in the trial beyond June,” The Guardian, February 23, 2012, www.guardian.co.uk/world/2012/feb/23/bradley- manning-defer-plea-charges
13. Associated Press, “Bradley Manning aided al-Qaida with WikiLeaks documents, military says: Manning, charged with aiding the enemy, accused of indirectly
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
13 · 12 THE INSIDER THREAT
aiding terrorist group by leaking thousands of documents,” The Guardian, March 3 2012, www.guardian.co.uk/world/2012/mar/15/bradley-manning-wikileaks
14. Adam Gabbatt and Ed Pilkington, “Bradley Manning trial delayed until June after sentence reduction granted: Judge reschedules US soldier’s trial to give more time for review of classified information related to WikiLeaks case,” The Guardian, January 9, 2013, www.guardian.co.uk/world/2013/jan/09/bradley-manning-trial- delayed
15. Ed Pilkington, “Bradley Manning denied chance to make whistleblower de- fence: Judge rules that Manning will not be allowed to present evidence about his motives for the leak—a key plank of his defence,” The Guardian, Jan- uary 17, 2013. www.guardian.co.uk/world/2013/jan/17/bradley-manning-denied- chance-whistleblower-defence
16. Tom Gardner, “Indian call centres selling YOUR credit card details and medical records for just 2p,” MailOnline, March 18, 2012, www.dailymail.co.uk/news/ar ticle-2116649/Indian-centres-selling-YOUR-credit-card-details-medical-records- just-2p.html
17. Eric Ouellet, “Magic Quadrant for Content-Aware Data Loss Prevention,” Gart- ner, Inc., January 3, 2013, https://www.ca.com/us/register/forms/collateral/Magic- Quadrant-for-Content-Aware-Data-Loss-Prevention-2013.aspx
18. BBC 2012 19. BBC 2011 20. BBC 2008 21. BBC 2009 22. Roger A. Grimes, Honeypots for Windows, Apress, 2005. 23. R. A. Grimes, “Honeypots: A sweet solution to the insider threat: A honeypot can
be a cheap, easy, and effective warning system against the trusted insider gone bad,” InfoWorld, May 1, 2009, www.infoworld.com/d/security-central/honeypots- sweet-solution-insider-threat-922?page=0,0
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14CHAPTER
INFORMATION WARFARE
Seymour Bosworth
14.1 INTRODUCTION 14 ·2
14.2 VULNERABILITIES 14 ·2 14.2.1 Critical
Infrastructure 14 ·2 14.2.2 Off-the-Shelf
Software 14 ·3 14.2.3 Dissenting Views 14 ·4 14.2.4 Rebuttal 14 ·4
14.3 GOALS AND OBJECTIVES 14 ·5 14.3.1 Infrastructure 14 ·5 14.3.2 Military 14 ·5 14.3.3 Military Offensives 14 ·8 14.3.4 Government 14 ·8 14.3.5 Energy Systems 14 ·9 14.3.6 Transportation 14 ·11 14.3.7 Commerce 14 ·12 14.3.8 Financial
Disruptions 14 ·13 14.3.9 Medical Security 14 ·14 14.3.10 Law Enforcement 14 ·15 14.3.11 International and
Corporate Espionage 14 ·15 14.3.12 Communications 14 ·16 14.3.13 Destabilization of
Economic Infrastructure 14 ·16
14.4 SOURCES OF THREATS AND ATTACKS 14 ·17 14.4.1 Nation-States 14 ·17 14.4.2 Cyberterrorists 14 ·19 14.4.3 Corporations 14 ·21
14.5 WEAPONS OF CYBERWAR 14 ·21 14.5.1 Denial of Service
and Distributed Denial of Service 14 ·21
14.5.2 Malicious Code 14 ·22 14.5.3 Cryptography 14 ·23 14.5.4 Psychological
Operations 14 ·23 14.5.5 Physical Attacks 14 ·24 14.5.6 Biological and
Chemical Weapons and Weapons of Mass Destruction 14 ·25
14.5.7 Weapons Inadvertently Provided 14 ·25
14.6 DEFENSES 14 ·25 14.6.1 Legal Defenses 14 ·25 14.6.2 Forceful Defenses 14 ·26 14.6.3 Technical Defenses 14 ·27 14.6.4 In-Kind
Counterattacks 14 ·27 14.6.5 Integration of
Cyberwarfare into Military Planning 14 ·27
14.6.6 Cooperative Efforts 14 ·28
14.7 SUMMARY 14 ·29
14.8 FURTHER READING 14 ·29
14.9 NOTES 14 ·30
14 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 2 INFORMATION WARFARE
Information warfare is the offensive and defensive use of information and infor- mation systems to deny, exploit, corrupt, or destroy, an adversary’s information, information-based processes, information systems, and computer-based networks while protecting one’s own. Such actions are designed to achieve advantages over military or business adversaries.
—Dr. Ivan Goldberg, Institute for Advanced Study of Information Warfare
14.1 INTRODUCTION. Until recently, warfare was conducted by armed forces representing adversarial nations, or by revolutionary elements opposing their own gov- ernments. Today, although such conflicts still exist around the world, the ubiquitous nature of computers and associated technology has created new forces, new threats, new targets, and an accompanying need for new offensive and defensive weapons. Information warfare (IW), also known as e-warfare or cyberwar, is actually, or po- tentially, waged by all U.S. armed forces and by those of other nations, as well as by commercial enterprises, by activist groups, and even by individuals acting alone.
Conventional wars, whether large or small, are regularly reported by the newsmedia. Information war, however, are largely ignored except by those with a professional interest in the field. One reason for this is that conventional warfare is a matter of life or death; photos and eyewitness accounts are dramatic reminders of human cruelty and mortality. In contrast, IW has so far been conducted bloodlessly, with only economic and political consequences. However, it is becoming increasingly evident that IW may soon be conducted in ways that could equal or exceed the death and destruction associated with conventional weapons.
Conventional wars are fought by known combatants with clearly defined allies and antagonists, but IW often is waged by unknown entities with uncertain allegiances and goals. IW may be conducted on many fronts simultaneously, with wars fought within wars, and with both civilian and military targets devastated.
Themotives for conventional warfare were almost always territorial, religious, polit- ical, or economic. These are still important, but to themmust be added the psychological motivations of groups and individuals—groups far more widely distributed and less easily overcome.
This chapter discusses information warfare in terms of the vulnerabilities of targets, participants’ objectives, sources of threats and attacks, weapons used, and defenses against those weapons.
14.2 VULNERABILITIES. Until recently, concerns over the security of the tech- nological infrastructure in technologically advanced nations have been viewed with skepticism. However, by the mid-1990s, opinion leaders in government, industry, and the security field were coming to grips with widespread vulnerabilities in the critical infrastructure.
14.2.1 Critical Infrastructure. In 1998, President Bill Clinton circulated Pres- idential Decision Directive 63, which outlined his administration’s policy on critical infrastructure protection:
Critical infrastructures are those physical and cyber-based systems essential to the mini- mum operations of the economy and the government.…They include, but are not limited to, telecommunications, energy, banking and finance, transportation, water systems and emer- gency services, both government and private.1
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
VULNERABILITIES 14 · 3
Having defined the very broad, vital areas that require protection, the paper went on to describe succinctly their vulnerability:
The United States possesses both the world’s strongest military and its largest national econ- omy. Those two aspects of our power are mutually reinforcing and dependent. They are also increasingly reliant upon certain critical infrastructures and upon cyber-based information systems.…
Because of our military strength, future enemies, whether nations, groups or individuals, may seek to harm us in non-traditional ways including attacks within the United States. Our economy is increasingly reliant upon interdependent and cyber-supported infrastructures and non-traditional attacks on our infrastructure and information systems may be capable of significantly harming both our military power and our economy.
A few examples of specific weaknesses were given by Jack L. Brock, Jr., director, Government-wide and Defense Information Systems, United States General Account- ing Office:
In May 1999 we reported that, as part of our tests of the National Aeronautics and Space Ad- ministration’s (NASA) computer-based controls, we successfully penetrated several mission- critical systems. Having obtained access, we could have disrupted NASA’s ongoing command and control operations and stolen, modified, or destroyed systems software and data.
In August 1999, we reported that serious weaknesses in Department of Defense (DOD) in- formation security continue to provide both hackers and hundreds of thousands of authorized users the opportunity to modify, steal, inappropriately disclose, and destroy sensitive DOD data.2
Although these “attacks”were carried out one at a time, andwithoutmalicious intent, it is apparent that they, and many others, could have been launched simultaneously and with intent to inflict the maximum possible damage to the most sensitive elements of the national infrastructure.
In a memorandum to its chairman, describing a report of the Defense Science Board Task Force on Defensive Information Operations, Larry Wright stated in 1999 that:
The threats to the DoD infrastructure are very real, non-traditional and highly diversi- fied.…The vulnerabilities of these United States are greater than ever before, andwe know that over twenty countries already have or are developing computer attack capabilities. Moreover, the Department of defense should consider existing viruses and “hacker” attacks to be real “Information Operations or Warfare,” what early aviation was to Air Power. In other words, we have not seen anything yet!3
The report concluded that “[i]t is the view of this task force that DoD cannot today defend itself from an Information Operations attack by a sophisticated nation state adversary.”
14.2.2 Off-the-Shelf Software. One characteristic of almost all military and civilian infrastructures is that they share, with more than 100 million computers, a sin- gle ubiquitous operating system, and many of the same applications programs, such as word processors, spreadsheets, and database software. These commercial off-the-shelf (COTS) products are available around theworld, to friend and foe alike, and they appear to be more intensively studied by malefactors than by their security-inadequate produc- ers. Each of these products presents entry points at which one common vulnerability may be exploited to damage or destroy huge portions of the national infrastructure.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 4 INFORMATION WARFARE
Until, and unless, this software is rendered significantly more resistant to attack, all of its users remain at risk.
14.2.3 Dissenting Views. Not every influential observer concurs in these pos- sible scenarios. Dr. Thomas P. M. Barnett, a professor and senior decision researcher at the Decision Support Department, Center for Naval Warfare Studies, U.S. Naval War College, voiced a fairly typical disagreement in 1999:
If absence makes the heart grow fonder, network-centric warfare is in for a lot of heartbreak, because I doubt we will ever encounter an enemy to match its grand assumptions regarding a revolution in military affairs. The United States currently spends more on its information technology than all but a couple of great powers spend on their entire militaries. In a world where rogue nations typically spend around $5 billion a year on defense, NCW is a path down which only the U.S. military can tread.4
14.2.4 Rebuttal. It may be of some benefit to have spokespersons for this un- worried viewpoint, but their opinions must be weighed against those, for example, of Scott Henderson, of the Navy-Marine Corps intranet, who said: “One of our critical capabilities will be how we are to defend our information and our information sys- tems from an adversary’s attack.”5 He stated that successful intrusions, or attacks, on Navy computer systems increased from 89 in 2000 to 125 by mid-2001, an annualized increase of 80 percent. Those figures did not include successful attacks that went un- detected or unsuccessful attempts that may have identified a weak point from which to launch future and probably more successful, attacks.
A highly significant factor in IW is its asymmetric nature. The barriers to entry for attackers are low; their weapons can be inexpensive, easily obtained, highly effective, easily automated, and used with negligible risk of personal harm. In contrast, defen- sive measures are extremely costly in time, money, and personnel and they may be ineffective against even unsophisticated attackers using obsolete computers.
The 2013Annual Report to Congress:Military and Security Developments Involving the People’s Republic of China from theU.S.Office of the Secretary ofDefense includes the following evaluation of China’s “Anti-Access/Area Denial (A2/AD)” capabilities:
An essential element, if not a fundamental prerequisite, of China’s emerging A2/AD regime is the ability to control and dominate the information spectrum in all dimensions of the mod- ern battlespace. PLA authors often cite the need in modern warfare to control information, sometimes termed “information blockade” or “information dominance,” and to seize the ini- tiative and gain an information advantage in the early phases of a campaign to achieve air and sea superiority. China is improving information and operational security to protect its own information structures, and is also developing electronic and information warfare capabilities, including denial and deception, to defeat those of its adversaries. China’s “information block- ade” likely envisions employment of military and non-military instruments of state power across the battlespace, including in cyberspace and outer space. China’s investments in ad- vanced electronic warfare systems, counter-space weapons, and computer network operations (CNO)—combined with more traditional forms of control historically associated with the PLA and CCP systems, such as propaganda and denial through opacity, reflect the emphasis and priority China’s leaders place on building capability for information advantage.6
Considering the nature and extent of already successful attacks against major ele- ments of U.S. military and civilian infrastructures, there appears to be no justification for discounting the views of those who believe that IW, in both its offensive and defen- sive roles, must be accorded the attention that surrounds any potentially cataclysmic force. This Handbook, especially Chapters 16, 17, 18, 20, and 21, contains many
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
GOALS AND OBJECTIVES 14 · 5
examples of viruses, worms, and other malware that have created massive disruptions in very large networks. The worst-case scenarios presented here should serve to awaken a measured response in those who may have been unaware or unconcerned.
14.3 GOALS AND OBJECTIVES. Attacking forces, in information warfare, will always have a variety of strategic and tactical motives behind their actions; de- fensive forces generally have only one tactical goal—to blunt the enemy’s attack and, if possible, to counterattack. Only after this is accomplished, and the nature of the attackers has been studied, can strategies for long-range operations be determined and effected.
14.3.1 Infrastructure. Depending on the target, an attacker’s goals may vary widely, but attackers generally want to damage, subvert, or destroy the infrastructure. In doing so, an attacker would hope to bring government, the economy, and military operations to a standstill or at least to reduce their efficiency and effectiveness to instill fear, uncertainty, and doubt (FUD), and ultimately to induce widespread chaos that could cost many lives.
Although this view is entirely appropriate to wars between nations or to campaigns by terrorists, it must be tempered when considering commercial warfare, whose main goal is competitive financial advantage.
14.3.2 Military. Today, information warfare is a vital concern of area comman- ders under battlefield conditions. They must obtain complete, accurate, and timely in- formation about their opponents’ actions, intentions, weaknesses, and resources while denying the same to their adversaries. The ultimate objective for all of these activities is to support the military tactics that will maximize the enemy’s body count, or at least to render its defenses ineffective, so that surrender becomes the only viable option. The other side of the coin, defensive tactics, are aimed at preventing enemies from accomplishing their objectives.
In the United States, the Joint Chiefs of Staff (for Army, Navy, Marine Corps, Coast Guard, and Air Force) have formulated the Joint Doctrine for Operations Security to be followed by all commanders of combatant commands in planning, preparation, and execution of joint operations. The publication states:
Operations Security (OPSEC) is a process of identifying critical information and subsequently analyzing friendly actions attendant to military operations and other activities, to: (a) identify those operations that can be observed by adversary intelligence systems; (b) determine what indicators adversary intelligence systems might obtain that could be interpreted or pieced together to derive critical information in time to be useful to adversaries; and (c) select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.7
OPSEC is a process that could be applied to every element of civilian infrastructure, as well as to the military, although all sources of information commonly used by the military are not available to the civilian sector. Other military code words for intelligence activities are:
� HUMINT (human intelligence) is the most widely used source of information, as it has always been for both the civilian and military sectors. HUMINT is often the only source capable of direct access to an opponent’s plans and intentions. Some
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 6 INFORMATION WARFARE
intelligence gathering is quite open, but covert or clandestine operations must be conducted in secrecy, so as to protect the sources of confidential information.
� SIGINT (signals intelligence) is obtained from communications (COMINT), elec- tronics (ELINT), and foreign instrumentation signals (FISINT).
� COMINT (communications intelligence) is information intended for others and intercepted without leaving a trace.
� ELINT (electronic intelligence) derives technical or geographic location data from an opponent’s electromagnetic radiations, other than those that arise from communications or from nuclear detonations or radioactive sources. The primary ELINT sources are radars (radio detection and ranging).
� FISINT (foreign instrumentation signals intelligence) is obtained from intercept- ing and analyzing metered performance parameters electronically transmitted from sources such as a ballistic missile.
� MASINT (measurement and signatures intelligence) is scientific and technical in nature. Its purpose is to identify distinctive features associated with a source, emitter, or sender so as to facilitate subsequent identification or measurement. These features include wavelength, modulation, time dependencies, and other unique characteristics derived from technical sensors.
� IMINT (imagery intelligence) is produced by photography, infrared sensors, lasers, radars, and electro-optical equipment. This equipment, operated from land, sea, air, or space platforms, provides strategic, tactical, and operational informa- tion.
� TECHINT (technical intelligence) is derived from the exploitation and analysis of captured or otherwise acquired foreign equipment.
� OSINT (open source intelligence) is available to the general public from news media, unclassified government publications, public hearings, contracts, journals, seminars, and conferences. The World Wide Web has become an important tool of OSINT.
The Joint Doctrine for Operations Security lists several generic military activities with some of their associated critical information. It must be the objective of all information warfare to acquire this critical information about their opponents while denying such information to them:
� Diplomatic negotiations include military capabilities, intelligence verification, and minimum negotiating positions.
� Political-military crisis management includes target selection, timing considera- tions, and logistic capabilities and limitations.
� Military intervention requires information about intentions, military capabilities, forces assigned and in reserve, targets, and logistic capabilities and constraints.
� Counterterrorism involves forces, targets, timing, strategic locations, tactics, and ingress and egress methods.
� Open hostilities information involves force composition and disposition, attrition and reinforcement, targets, timing, logistic constraints, and location of command and control (C2) nodes.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
GOALS AND OBJECTIVES 14 · 7
� Mobilization requires information about an intent to mobilize before public an- nouncement, impact on military industrial base, impact on civilian economy, and transportation capabilities and limitations.
� Intelligence, reconnaissance, and surveillance information includes purpose and targets of collection, timing, capabilities of collection assets, and processing capabilities.
In addition to the Joint Chiefs’ doctrines, the Department of Defense and each individual branch of service have been charged with the responsibility for establishing task forces, advisory groups, training and awareness programs, and virtual information networks to mobilize IW forces and to bring into being a strong defense against enemy attack.
Further evidence of the importance of military information and the vulnerabilities that exist at this time is contained in the 2001 report of the Secretary of Defense to the President and the Congress:
Information superiority is all about getting the right information to the right people at the right time in the right format while denying adversaries the same advantages. The United States enjoys a competitive advantage in many of the technical components of informa- tion superiority, but the U.S. also has vulnerabilities stemming from its increasing depen- dence on high technology. Experiences from Somalia to the Balkans have shown that low technology adversaries also can wage effective information campaigns, especially in urban environments.
In the Information Age, the opportunities and obstacles to achieving national security ob- jectives often are informational in nature. Information superiority is a principal component of the transformation of the Department. The results of research, analyses, and experiments, reinforced by experiences in Kosovo, demonstrate that the availability of information and the ability to share it significantly enhances mission effectiveness and improves efficiencies. Benefits include: increased speed of command, a higher tempo of operations, greater lethality, less fratricide and collateral damage, increased survivability, streamlined combat support, and more effective force synchronization. Kosovo also highlighted the shortage of assets for intel- ligence, surveillance, and reconnaissance, as well as the need for more secure interoperability and information protection, especially within coalitions.
To ensure that the above prerequisites are in place, DoD is developing appropriate policy and oversight initiatives, actively pursuing opportunities to improve international cooperation in the areas of Command, Control, Communication, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR) and space-related activities, partnering with industry, and working to anticipate and understand the implications of emerging information technologies.
The quality of DoD’s infostructure will be a pacing item on the journey to the future. The ability to conceive of, experiment with, and implement new ways of doing business to harness the power of Information Age concepts and technologies depends upon what information can be collected, how it can be processed, and the extent to which it can be distributed. The ability to bring this capability to war will depend upon how well it can be secured and its reliability. DoD envisions an infostructure that is seamless with security built-in, one that can support the need for increased combined, joint, and coalition interoperability, leverages commercial technology, and accommodates evolution.87
Although not as well publicized as are the U.S. defensive efforts, equal attention, time, and resources are being expended on actual and possible offensive operations. Every objective, every tactic, and every recommendation just mentioned, and some too sensitive to discuss here, are subjects for study and implementation of offensive strategies and tactics aimed at enemies, present and future.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 8 INFORMATION WARFARE
14.3.3 Military Offensives. The nature of U.S. offensive planning has been described in detail in a top-secret presidential memo published by The Guardian (U.K.) on June 7, 2013.
The memo states that:
The United States has an abiding interest in developing and maintaining use of cyberspace as an integral part of U.S. national capabilities to collect intelligence, and to deter, deny, or defeat any adversary that seeks to harm U.S. national interests in peace, crisis, or war.…The United States Government shall conduct DCEO [Defensive Cyber Effects Operations] and OCEO [Offensive Cyber Effects Operations] under this directive consistent with its obligations under international law, including with regard to matters of sovereignty and neutrality, and as applicable, the laws of armed conflict. This directive pertains to cyber operations, including those that support or enable kinetic, information, or other types of operation.9
In this context, “kinetic operations” are a recognized euphemism for warfare, and thismemo provides theU.S. Governmentwith a broadmandate to protect U.S. interests, as it sees them, with any means available to it without a declaration of war.
At the time of this writing (July 2013), the full implications of this serious secu- rity breach cannot be evaluated. At the very least, it will provide the critics of U.S. policy with reinforcement for their view of the United States as a militaristic, even terrorist force in international relations. For defenders of U.S. policies, it will repre- sent an ordered, rational, response to threats that must be contemplated and guarded against.
14.3.4 Government. The objectives of government, at every level, must be to protect the lives and welfare of its constituencies. Any breakdown in an essential gov- ernment function may produce marked unrest, rioting, vandalism, civil disobedience, and possibly much bloodshed.
Just as in themilitary, governmentmust be able to defend itself against an information attack waged by any enemy of the established order. Although not every element of government is perceived by all to perform a useful function, there are agencies without which it would be virtually impossible to sustain a developed nation’s day-to-day activities.
At the federal level, civil servants’ salaries, Social Security payments, tax collec- tions and disbursements, military expenditures, lawmaking, and a myriad of other functions and activities can be carried out only with the active and pervasive use of computers and computer networks. In the past, some of these computer operations have been penetrated by hackers, crackers, and political dissidents, but only one at a time. It does not require a science fiction writer to imagine what the effect would be if simultaneous attacks were successfully launched against major federal government agencies.
At state levels, although the effects would be more constrained geographically, a great deal of damage could be done to emergency response units, to police and judiciary functions, and to health and welfare services. All of these depend on computerized functions that are protected even less than those of federal agencies.
For municipalities and even smaller governments, zoning enforcements and other local functions can be suspended without serious consequences, but police radio and computer networks are easily penetrated, and their ability to maintain law and order compromised.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
GOALS AND OBJECTIVES 14 · 9
As demonstrated by many previous incidents, government functions at any level are susceptible to information warfare. Natural events, Murphy’s law (what can go wrong will go wrong), poorly configured systems, flawed operating systems and application programs, together with inadequate security measures underlie the vulnerability of government systems.
14.3.5 Energy Systems.10 Oil, coal, and hydroelectric systems are critical elements of the national infrastructure. Supervisory control and data acquisition (SCADA) security in the electric power industry suffers from widespread misconcep- tions and a breakdown in communications between administrators and security experts. In brief,
� Attacks on electric power plants and the distribution grid may not result in the catastrophic scenarios painted by the promoters of panic, but any interruption in electric power delivery can cause widespread infrastructure disruption.
� SCADA systems controlling electric generators and distribution systems are not, in fact, isolated by air gaps from the Internet.
� On the contrary, vulnerability analysis teams have systematically and repeatedly demonstrated that power companies are unaware of the reality of their intercon- nectedness and vulnerabilities.
� There are documented cases of industrial espionage, sabotage, denial of service, and malware attacks on electric power grid SCADA systems.
� SCADA systems have been considered too stable to bother updating with current patches; as a result, they are consistently vulnerable to exploits of current (and even ancient) vulnerabilities.
� Many SCADA systems were developed without consideration of security, secure coding, or integration of security dimensions of software quality assurance.
� Government and academia have significant projects in place to advance SCADA security, but acceptance by industry is modest at best. Academics engaged in SCADA security research are doing a good job of reaching other academics through peer-reviewed presentations at academic conferences; they are less suc- cessful in reaching managers at power companies.
� Pressure is rising in the public sphere, in government circles, among security practitioners, and within the electric power industry to come to grips with the need for improved cybersecurity.
� The electric power industry must coordinate its efforts to implement well- established standards for protecting computer systems and networks in all its SCADA systems and related networks. In addition, the industry should implement cyber situational awareness solutions to integrate multiple inputs from SCADA and network sensors that will permit intelligent, agile response to attacks and effective forensic analysis of those attacks.
The electric power industry has become a fundamental underpinning of twenty-first century life. In a landmark report on “The Electricity Economy,” author Jesse Berst and colleagues describe the convergence of growing demand, an increasing dependence on computerized SCADA systems, and the inevitable complexity of interactions among elements controlled by diverse entities with limited coordination.11 To illustrate the
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 10 INFORMATION WARFARE
growth in electricity demands, the report’s Table 1 shows global electricity demands of 2.06 terawatts (TW) in 1950 versus 3.8 TW in 2000 and a predicted 6.99 TW in 2050. The proportion of electricity as a percentage of global energy utilization was 10.4 percent in 1950 and 25.3 percent in 2000; by 2050 it may reach 33.7 percent. The authors add,
Today we depend on electricity for basic needs such as food, water, shelter, communication, employment, and health care. Those needs are served by infrastructures for food preserva- tion, water treatment, heat and light, phone service, Internet, offices, factories, hospitals and emergency response, to name a few. Yet all of those essentials degrade or disappear without electricity.12
In October 1997, the President’s Commission on Critical Infrastructure Protection (the “Marsh Report” named after Commission Chairman Robert T. Marsh) included the following warning:
Prolonged disruption in the flow of energy would seriously affect every infrastructure.
The significant physical vulnerabilities for electric power are related to substations, generation facilities, and transmission lines. Large oil refineries are also attractive targets. The increase in transportation of oil via pipelines over the last decade provides a huge, attractive, and largely unprotected target array. Oil and gas vulnerabilities include lines at river crossings; interconnects; valves, pumps, and compressors; and natural gas city gates. Large metropolitan areas could be deprived of critical fuel for an extended period by a properly executed attack.
The widespread and increasing use of Supervisory Control and Data Acquisition (SCADA) systems for control of energy systems provides increasing ability to cause serious damage and disruption by cyber means. The exponential growth of information system networks that interconnect the business, administrative, and operational systems contributes to system vulnerability.13
Electrical power systems have been harmed through data leakage, industrial espi- onage, insider threats and sabotage.14 Incidents described in the reference include
� 2006 Japan’s Power Plant Security Info Leaked Onto Internet � 2007 Egypt Accuses Nuclear Employee of Spying � 2007 Former Nuclear Plant Engineer Allegedly Took Data to Iran � 2007 Saboteur of California Power Grid Gained Access Despite Warning � 2009 Fired Nuclear-Power-Plant Employee Arrested for Hacking Systems � 2009 (Former) IT Consultant Confesses to SCADA Tampering
Hackers and malware writers and distributors have also attached power systems.15
Cases summarized in the reference include
� 2000 Hacker Shocks Electric Company � 2003 Slammer Worm Crashes Ohio Nuclear Plant Network � 2006 National Nuclear Security Administration Computers Hacked; Info on
1500 Taken � 2010 Stuxnet Worm Attacks SCADA Vulnerabilities
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
GOALS AND OBJECTIVES 14 · 11
The Stuxnet incident is a significant development in information warfare. The Euro- pean Network and Information Security Agency (ENISA) published a detailed analysis of the case in 2010:
Stuxnet is a specialised malware targeting SCADA systems running Siemens SIMATIC R©
WinCC or SIMATIC R© Siemens STEP 7 software for process visualisation and system control. SCADA in general refers to computer systems that monitor and control industrial processes, such as, e.g., those in nuclear power plants, or in facilities for water treatment.
This highly sophisticated malware uses several vulnerabilities in the underlying Windows R©
operating system for infection and propagation. Infection works via USB-drives or open network shares. A root kit component hides the content of the malware on infected WinCC systems. An infected system can usually be controlled remotely by the attacker. In the end this means that the attacker has full control of the respective facility.16
ENISA also published a report on securing computer-controlled energy-distribution systems (smart grids) in December 2012.17
14.3.6 Transportation. Airplanes, trains, trucks, and ships are all likely targets for physical and information warfare. Because all of them are necessary to support the infrastructure by transporting personnel and materials, any disruption can cause severe problems. Because all of these transportation systems increasingly rely on sophisticated telecommunications and computing resources, they are subject to information warfare.
14.3.6.1 Aviation. The most visible, and potentially the most vulnerable, com- ponent of the transportation infrastructure is the aviation industry. Unlike the fly- by-the-seat-of-your-pants technology of aviation’s early days, today’s airplanes and the systems that dispatch and control them in flight are almost totally dependent on electronic communications and instruments, both analog and digital.
To a great extent, almost every airplane depends on its global positioning system (GPS) to determine its position in space, its course, speed, bearing to an airfield, and other important functions. Airplanes generally are required to fly at certain altitudes, in specific corridors, avoiding restricted areas, bad weather, and other aircraft. These requirements are met by a combination of GPS, ground and airborne radar, internal instruments, and communications from ground controllers. In the original design of these types of equipment, little or no consideration was given to security; as a result, all of them are susceptible to information warfare attacks.
The accuracy and reliability of GPS and airborne radar, however, has led federal aviation authorities to consider implementing a system wherein ground controllers and published restrictions would no longer determine altitude, speed, clearance distances, and other flight parameters. Instead, pilots would have the option to choose any flight parameter that they believed to be safe. This new system is intended to increase the number of flights that can safely traverse the limited airspace. It is undoubtedly capable of doing so, but at the same time, it will greatly increase the dangers of flight should information warfare be waged against airplanes and the aviation infrastructure.
14.3.6.2 Railroads. Less so than airplanes, but not to a negligible degree, trains are possible targets of IW. Train movements; switch settings, communications between engineers, trainmen, and control centers are all carried on by insecure radio commu- nications and wired lines. Attacks against any or all of these can prevent the railroads from carrying out their important functions, possibly by causing disastrous wrecks.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 12 INFORMATION WARFARE
14.3.6.3 Trucking. The great majority of domestic goods shipments are carried by tractor-trailer trucks. Foodstuffs, especially, depend on this relatively fast, reliable means of transportation. If even a short disruption were to be caused by IW, untold quantities of foodstuffs would rot in the fields, as would additional stockpiles awaiting distribution from central warehouses. Data for scheduling, routing, locating trucks, setting times and locations of pickup and delivery, and performing maintenance could be prevented from reaching their destinations.
14.3.6.4 Shipping. Ships are indispensable means for transporting vast quanti- ties of materials over long distances. Navigational data, such as position, speed, course to steer, and estimated time of arrival, are a few of the parameters determined by com- puters and GPS on virtually every ship afloat. Conventional radar and communications by VHF and high-frequency radio are in common use, with satellite communications becoming more prevalent, despite an early start that met with technical and economic difficulties.
Radar and communications jamming are old established weapons of IW, as is inter- ception of critical information. Little attention has been paid to security in designing or operating this equipment, and that places ships at great risk, as does the threat of physical attacks.
14.3.6.5 Other Transportation Vulnerabilities. Recognizing the impor- tance of transportation to a nation’s infrastructure, IW attackers could create wide- ranging disruptions if they were to intercept and successfully prevent receipt of critical information within the transportation industry. Recently, as a leader in new technology, the Port Authority of New York and New Jersey has begun converting to a wireless infrastructure at its many airports, train stations, bus terminals, tunnels, bridges, and shipping facilities. It requires no stretch of the imagination to predict what a determined attacker might accomplish in damaging or destroying such an infrastructure. The dan- ger is especially great in light of the general lack of security from which wireless transmissions suffer.
When the World Trade Center (WTC) was destroyed by terrorist action, the Port Authority’s offices in the WTC were completely destroyed, and more than 70 of its employees were officially listed as deceased or missing. Although that catastrophe pointed up the need for greater physical security, it also demonstrated how the Internet can be used in emergency situations. The Port Authority site, www.panynj.gov, was used to convey operational messages to the public as well as information for tenants, employees and prospective employees, vendors, suppliers, contractors, and the media.
14.3.7 Commerce. In 1924, in an address to the American Society of News- paper Editors, President Calvin Coolidge said: “After all, the chief business of the American people is business. They are profoundly concerned with producing, buying, selling, investing, and prospering in the world. I am strongly of the opinion that the great majority of people will always find these are moving impulses of our life.…”18
Now, 90 years later at the time of writing, these statements are no less true. Produc- ing, buying, selling, and investing are the commercial means by which U.S. citizens and guest workers can hope to achieve prosperity. Although not recognized earlier, infrastructure is the glue that ties these functions together and permits them to operate efficiently and economically.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
GOALS AND OBJECTIVES 14 · 13
If these bonds were to be broken, American business would come to a virtual standstill; it is that reality which makes the commercial infrastructure so inviting a target. Without complete, accurate, and current information, no investors would put their money at risk, and no transactions would take place among producers, buyers, and sellers.
In a populace lacking food, utilities, prescription drugs, money, and other necessi- ties, civil disorder would be widespread. With the breakdown of commerce and the citizenry’s unwillingness or inability to perform their customary functions, government at every level might cease to operate. This, in turn, would make military defensive ac- tions highly problematic, and an enemy that combined IW with conventional force attacks would be difficult to resist.
On a less catastrophic level, there have been several cases of deliberate stock ma- nipulation by means of insertion of false information into various news channels; an enemy could cause significant disruption in the stock market by forcing a few key stocks into unwarranted declines. In addition, the widespread use of automated trading tools that respond to significant drops in specific shares or in particular aggregate stock indexes could precipitate major economic problems in the developed world.
14.3.8 Financial Disruptions. Money is the lifeblood of every developed na- tion. For an economy to be healthy, its money supply, like the body’s blood supply, must be strong, healthy, and free flowing. For an IW attacker, disruptions in the en- emy’s money supply and in its free flow are important objectives. Likely targets in the financial infrastructure include payment systems, investment mechanisms, and banking facilities.
14.3.8.1 Payment Systems. Every government employee, every member of the armed forces, every officeworker, factory hand, serviceworker, engineer, and retired person—in fact, almost every individual in the United States—depends on regular re- ceipt of funds necessary for survival. Paychecks, dividends, welfare and unemployment benefits, commissions, payments for products, and fees for services comprise most of the hundreds of millions of daily checks, direct deposits, and wire transfers without which most people would be unable to purchase their essential needs—assuming that products and services were available to meet those needs.
The great majority of payroll systems are computerized. Many of them, including those of the federal and state governments, depend on a few centralized computer payroll services. Even if those services were not damaged by infrastructure attacks, the banks on which payroll funds are drawn might be. This would halt, or at least impede, the cutting of physical checks, the direct deposits, cash withdrawals, wire transfers, and any other means by which payments are made. Such a situation has never occurred within the United States except in small local areas and for only brief periods of time. No one can predict what the consequences would be for a widespread attack, and surely no one would want to find out.
For more on banking payment systems, see Section 14.3.8.3.
14.3.8.2 Investment Mechanisms. Various stock, bond, and commodity ex- changes provide the principal means by which individual, institutional, and corporate entities easily and expeditiously can invest in financial instruments and commodity goods.
With few exceptions, each exchange has all of its computers and communications located within a single facility, with connections to tens of thousands of terminals
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 14 INFORMATION WARFARE
worldwide. Disruption in these systems would not have as disastrous an effect as would a payment system disruption, but it would not be long before a breakdown in investment mechanisms would produce a commercial meltdown.
Because of the vast sums of money involved, exchange systems largely have been hardened against intrusion, and some have remote, redundant facilities, but there have been instances where hardware and software problems as well as physical exploits have brought down an exchange infrastructure.
14.3.8.3 Banking. The banking industry is the foundation of the modern fi- nancial system and, by extension, both American and foreign capitalist economies. At some point, every important financial transaction is conducted through the banking system. As such it is vital to economic health. With the advent of information warfare, the electronic, interdependent nature of banking—and finance in general—combined with its critical nature, makes the banking system a likely target for a strategic attack against a country. This is a new viewpoint for an industry focused on crime, traditional financial crises, and the more recent phenomenon of low-level hacking. It is critical, however, that we master this viewpoint and adapt our banking industry to it, for the threats information warfare poses are different from traditional bank security threats and will increase as the age of information warfare develops. Focused correctly, a well-prepared attack could cause chaos throughout the international system.19
The ubiquitous banking system is as highly automated and as security conscious as any element of the world’s infrastructure. With ATMs, online banking, funds-transfer networks, and check clearing, banks are integral to virtually every commercial transaction.
As an example of the scope of banking operations involving money transfers, FED- WIRE, operated by the Federal Reserve Board, serves approximately 9,000 depository institutions as of January 2012, providing transfers that are immediate, final, and irrevocable.20 In 2011, it processed 127 million transactions with a total value in ex- cess of $663 trillion. The average daily volume in 2011 was over 506,000 transactions valued at more than $2.6 trillion.21
The Clearing House Interbank Payment System (CHIPS) “is responsible for over 95%ofUSDcross-border transactions, and nearly half of all domesticwire transactions, totaling $1.5 trillion daily [in 2012].”22
The Society forWorldwide Interbank Funds Transfer (SWIFT) “is a member-owned cooperative through which the financial world conducts its business operations with speed, certainty, and confidence. More than 10,000 financial institutions and corpora- tions in 212 countries trust us every day to exchange millions of standardized financial messages. This activity involves the secure exchange of proprietary data while ensuring its confidentiality and integrity.”23 Information about dollar value is not made public, but the amounts are known to be huge and the traffic enormous. For example, by the end of September 2012, the annualized number of messages transferred for the year was over 339 million and the annualized volume of files transferred among institutions was over 22 million.24
If any of these systems were to be attacked successfully, the consequences for the financial well-being of many nations would be disastrous. Despite intensive efforts to safeguard the networks, attacks could be launched against the central computers, the computers of each user, and the networks that connect them.
14.3.9 Medical Security. In hospitals, as in group and private medical prac- tice, the primary functions are carried out in a decentralized mode, making large-scale
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
GOALS AND OBJECTIVES 14 · 15
attacks impracticable. However, ancillary functions, such as sending invoices to the government, to health maintenance organizations, and to individuals, for services pro- vided, and placing orders for drugs and supplies, all require interconnections with centralized computers.
Although the medical profession is often slow to adopt new infrastructure elements, network-connected computers have been mandated at least for payments, and they are becoming increasingly popular for maintaining patient data, for research, and for other functions. There have been reports that hospital systems have been penetrated, with prescriptions switched and HIV-negative patients advised that their test results were positive.
See Chapter 71 of thisHandbook for more detail about medical information security.
14.3.10 Law Enforcement. The objectives of law enforcement are to facilitate the apprehension of criminals andwrongdoers. To accomplish this, facilities in common use include computers in every squad car connected to precinct headquarters and networks that interconnect local, state, federal, and international databases. With local law enforcement, it is clear that jamming, or noise interference on emergency channels, or denial of computer services would greatly exacerbate the effects of physical attacks. At worst, a state of panic and chaos might ensue.
Another attack on law enforcement could be flash crowds—groups of people gath- ered into a single physical location through instructions sent electronically.25 One commentator wrote in 2004,
… [T]raining people to assemble on command in large numbers at, say, shoe stores, piano showrooms or restaurants for no good reason other than the fun of being part of a huge crowd is a perfect setup for creating an army of willing, mindless drones who will congregate on command at the site of a terrorist attack or at places where their presence will interfere with response to criminal or terrorist activities. Want to rob a bank in peace and quiet? Set up a conflict between two instant crowds to draw the police to an instant riot.26
14.3.11 International and Corporate Espionage. Espionage has been a recognized military activity since at least the biblical story of Joshua, one of 12 spies sent to explore the land of Canaan.27 However, its application to civilian commerce dates only from the Industrial Revolution. Since then, industries and indeed nations have prospered to the extent that they could devise and retain trade secrets. In the United States, the unauthorized appropriation of military secrets has been legally proscribed since the country’s inception, with penalties as severe as death, during wartime.
Only recently have economic espionage and the theft of trade secrets become the subjects of law, with severe penalties whether the law is broken within or outside of the United States or even via the Internet.
The Economic Espionage Act of 1996 was signed into law by President Clinton on October 11, 1996. Section 1832 provides that:
(A) Whoever, with intent to convert a trade secret, that is related to or included in a product that is produced for or placed in interstate or foreign commerce, to the economic benefit of anyone other than the owner thereof, and intending or knowing that the offense will injure any owner of that trade secret, knowingly—
(1) Steals, or without authorization appropriates, takes, carries away, or conceals, or by fraud, artifice, or deception obtains such information;
(2) Without authorization copies, duplicates, sketches, draws, photographs, downloads, uploads, alters, destroys, photocopies, replicates, transmits, delivers, sends, mails, communicates, or conveys such information;
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 16 INFORMATION WARFARE
(3) Receives, buys, or possesses such information, knowing the same to have been stolen or appropriated, obtained, or converted without authorization;
(4) Attempts to commit any offense described in any of paragraphs (1) through (3); or
(5) Conspires with one or more other persons to commit any offense described in any of paragraphs (1) through (3), and one or more of such persons do any act to effect the object of the conspiracy,
Shall, except as provided in subsection (b), be fined under this title or imprisoned not more than 10 years, or both. (b) Any organization that commits any offense described in subsection (a) shall be fined not more than $5,000,000.28
Although the foregoing lists all of the actions that are proscribed, it is not specific as towhich assets are to be protected as trade secrets. For this, see theDefense Security Ser- vice paper, “What AreWe Protecting?”29 There, the five basic categories of People, Ac- tivities/Operations, Information, Facilities, and Equipment/Materials are expanded into 42 specific assets, with the admonition that every company official must clearly iden- tify to employees what classified or proprietary information requires protection. Only if the owner has taken reasonable measures to keep such information secret, and the information derives actual or potential economic value from not being generally known to or readily obtainable through proper means, will the courts view it as a trade secret.
For further information on intellectual property, including trade secrets, see Chap- ters 11 and 42 in this Handbook.
14.3.12 Communications. Communications are the means by which all ele- ments of a civilization are tied together. Any significant destruction of communications media would disrupt the most important segments of society. Without adequate com- munications, transactions and services would come to a complete halt. In the United States, communications have been disrupted frequently, but fortunately, the infrastruc- ture has been so vast and so diverse that the consequences have rarely been more than temporary. Even after the World Trade Center disaster of September 11, 2001, when Verizon’s downtown telephone facilities centers were heavily damaged, service was restored within four days to the NewYork Stock Exchange and to other important users in the area.
Contrary to popular belief, the Internet is so widely used and concentrated in so few backbone points that a coordinated attack actually could destroy its functioning. For many years, backup facilities have included redundant computers and all of their associated peripherals, often in remote locations. Too often, however, alternate com- munications facilities are not provided. Unless this is rectified, the same disaster that brings down one installation could disable all.
14.3.13 Destabilization of Economic Infrastructure. A major difference between wealthy, developed nations and poor, undeveloped countries lies in the strength of their economic infrastructures. The existence of strong capital markets, stable banking and lending facilities, and efficient payment processes, all tied together by fast, technically advanced communications capabilities, is essential to healthy, growing economies.
At opposite ends of this spectrum lie Afghanistan and the United States. The perpe- trators of the attacks on the World Trade Center and the Pentagon, identified as Osama bin Laden and his Al-Qaeda organization, operating out of Afghanistan, chose as their targets the symbols and the operating centers of America’s military operations and of its economic infrastructure.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SOURCES OF THREATS AND ATTACKS 14 · 17
The recession of the late 2000s and early 2010s has illustrated the vulnerability of global economic systems to disruption. With hundreds of thousands thrown out of work and with investment capital drying up, the entire economic infrastructure of the world has already suffered a great blow without direct cyberattacks. Every effort must be bent toward preventing attacks that imperil the economic infrastructure of the world. Security can no longer be the duty of a few technical people; it has become everyone’s responsibility.
14.4 SOURCES OF THREATS AND ATTACKS. The actual and potential orig- inators of information warfare are numerous and powerful. One need not be paranoid to feel that an attack may come from any direction. This section lists sources that have already proven their capabilities for conducting cyberwar.
14.4.1 Nation-States. U.S. military preparations for cyberwar have been described in Section 14.3.2. This section details some of the measures that another great power—China—is effecting toward the same ends. Most of the material is from a paper entitled “Like Adding Wings to the Tiger: Chinese Information War Theory and Practice.”30
14.4.1.1 China and Information Warfare. Although China is a nuclear power, it does not yet have the arsenal necessary to threaten a superpower like the United States. However, it can do so with its IW forces; adding wings to the tiger makes it more combat worthy. Nor is Chinese IW entirely theoretical. On August 3, 2000, the Washington Times reported that hackers suspected of working for a Chinese government institute took large amounts of unclassified but sensitive information from a Los Alamos computer system. A spokesman stated that “an enormous amount of Chinese activity hitting our green, open sites” occurs continuously.31
According to an article in the Chinese Armed Forces newspaper, the Liberation Army Daily, their first attack objectives will be the computer networking systems that link a country’s political, economic, and military installations, as well as their general society.32 A further objective will be to control the enemy’s decision-making capability in order to hinder coordinated actions.
Expanding on Mao Zedung’s theory of a People’s War, IW can be “carried out by hundreds of millions of people using open-type modern information system.”33 In this war, combatants can be soldiers or teenagers, or anyone who has a computer as a weapon.34 Ironically, China, with its long-standing fear of outside information as a possible spur to counterrevolutionary action, now views arming large numbers of intelligent people with computers and access to the Internet as a necessary survival measure. It remains to be seen just howmany personal computerswill bemade available and how China will ensure that they will be used only as the government intends.
The “Annual Report to Congress on the Military Power of the People’s Republic of China” from the U.S. Department of Defense has been issued every year since 2002. Reading through all the reports provides valuable perspective on the DoD view of information warfare capabilities of the People’s Republic of China (PRC) and the People’s Liberation Army (PLA). The 2011 edition included the following analysis:
� Cyberwarfare Capabilities. In 2010, numerous computer systems around theworld, including those owned by the U.S. Government, were the target of intrusions, some of which appear to have originated within the PRC. These intrusions were focused on exfiltrating information. Although this alone is a serious concern, the accesses and skills required for these intrusions are similar to those necessary to conduct computer network attacks. China’s 2010 Defense
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 18 INFORMATION WARFARE
White Paper notes China’s own concern over foreign cyberwarfare efforts and highlighted the importance of cybersecurity in China’s national defense.
� Cyberwarfare capabilities could serve PRC military operations in three key areas. First and foremost, they allow data collection through exfiltration. Second, they can be employed to constrain an adversary’s actions or slow response time by targeting network-based logistics, communications, and commercial activities. Third, they can serve as a force multiplier when coupled with kinetic attacks during times of crisis or conflict.
� Developing capabilities for cyberwarfare is consistent with authoritative PLA military writ- ings. Twomilitary doctrinal writings, Science of Strategy and Science of Campaigns, identify information warfare (IW) as integral to achieving information superiority and an effective means for countering a stronger foe. Although neither document identifies the specific crite- ria for employing computer network attack against an adversary, both advocate developing capabilities to compete in this medium.
� The Science of Strategy and Science of Campaigns detail the effectiveness of IW and computer network operations in conflicts and advocate targeting adversary command and control and logistics networks to impact their ability to operate during the early stages of conflict. As the Science of Strategy explains,
–In the information war, the command and control system is the heart of informa- tion collection, control, and application on the battlefield. It is also the nerve center of the entire battlefield. [Emphasis ours.]35
In parallel with itsmilitary preparations, China has increased diplomatic engagement and advocacy in multilateral and international forums where cyberissues are discussed and debated. Beijing’s agenda is frequently in line with the Russian Federation’s efforts to promote more international control over cyberactivities. China has not yet agreed with the U.S. position that existing mechanisms, such as International Humanitarian Law and the Law of Armed Conflict, apply in cyberspace. China’s thinking in this area is evolving as it becomes more engaged.”
14.4.1.2 Strategies. The People’s Liberation Army (PLA) with 1.5 million re- serve troops has been carrying out IW exercises on a wide scale. One such exercise, in Xian Province, concentrated on conducting information reconnaissance, changing net- work data, releasing information bombs, dumping information garbage, disseminating propaganda, applying information deception, releasing clone information, organizing information defense, and establishing spy stations.36 The antecedents of these tactics can be found in a book of unknown authorship, first mentioned about 1,500 years ago, entitled The Secret Art of War: The 36 Stratagems. Strategy 25 advises:
Replace the Beams with Rotten Timbers. Disrupt the enemy’s formations, interfere with their methods of operations, change the rules which they are used to following, and go contrary to their standard training. In this way you remove the supporting pillar, the common link that makes a group of men an effective fighting force.37
The 36 stratagems deserve close study; many of them are obviously in use even today by China and others. For example, strategy 3 says:
Kill with a Borrowed Sword.When you do not have the means to attack your enemy directly, then attack using the strength of another.
Lacking the weapons to attack the United States directly, the perpetrators of the WTC attack used the airliners belonging to their targets.
Strategy 5 says:
Loot a Burning House.When a country is beset by internal conflicts, when disease and famine ravage the population, when corruption and crime are rampant, then it will be unable to deal with an outside threat. This is the time to attack.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SOURCES OF THREATS AND ATTACKS 14 · 19
Some of the strategies might well be employed by the United States. For example, strategy 33 advises:
The Strategy of Sowing Discord. Undermine your enemy’s ability to fight by secretly causing discord between him and his friends, allies, advisors, family, commanders, soldiers, and pop- ulation. While he is preoccupied settling internal disputes his ability to attack or defend, is compromised.
To accomplish this, IW may prove to be an effective weapon.
14.4.1.3 Training. Several high-level academies and universities have been es- tablished to conduct IW instruction for the PLA. In addition, training is planned for large numbers of individuals to include:
� Basic theory, including computer basics and application, communications network technology, the information highway, and digitized units
� Electronic countermeasures, radar technology � IW rules and regulations � IW strategy and tactics � Theater and strategic IW � Information systems, including gathering, handling, disseminating, and using information
� Combat command, monitoring, decision making, and control systems � Information weapons, including concepts, principles of soft and hard destruction, and how to apply these weapons
� Simulated IW, protection of information systems, computer virus attacks and counterattacks, and jamming and counterjamming of communications networks38
It is doubtful that all of these training objectives have been accomplished, but there seems to be a major commitment to do so, and sooner rather than later.
China and the United States are only two of the nations that are openly preparing for, and actually engaged in, information warfare. It is obvious that many others are similarly involved and that these measures, combined with conventional weapons or weapons of mass destruction, have the potential to elevate warfare to a destructive level never before possible and hardly conceivable.
14.4.2 Cyberterrorists
“Cyberterrorism” means intentional use or threat of use, without legally recognized authority, of violence, disruption, or interference against cybersystems, when it is likely that such use would result in death or injury of a person or persons, substantial damage to physical property, civil disorder, or significant economic harm.39
Cyberterrorists, those who engage in cyberterrorism, generally are able to carry out the same sort of cyberwar as nation-states; in fact, they may be state-sponsored. The major difference is that terrorist attacks are usually hit-and-run, where nations are capable of sustained and continuous operations. Although conventional warfare always was carried out in an overt fashion, it is the nature of IW that it can be engaged in without a declaration of war and without any clear indication of who the attacker actually is. In fact, it may not be recognized that a war is being conducted; it may
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 20 INFORMATION WARFARE
seem only that a series of unfortunate, unconnected natural failures of computers and communications are disrupting an economy.
Terrorists, especially when state-sponsored, would be very likely to conceal their IW activities in this manner, so as to avoid the retribution that would inevitably follow. However, some terrorists would publicly take credit for their actions, in order to bolster their apparent strength and to gather added support from like-minded individuals and organizations.
The seriousness of terrorist threats after 9/11 resulted in Executive Order 13228 of October 8, 2001, establishing the Office of Homeland Security and the Homeland Security Council.40 The mission of the Office was to “develop and coordinate the implementation of a comprehensive national strategy to secure the United States from terrorist threats or attacks.” Its function was “to coordinate the executive branch’s efforts to detect, prepare for, prevent, protect against, respond to, and recover from terrorist attacks within the United States.”
The Department of Homeland Security was mandated by Congress on January 24, 2003, and was fully formed on March 1, 2003. Celebrating its tenth anniversary in 2013, the department employs more than 200,000 people dedicated to fulfilling its mission.
On February 15, 2005, Michael Chertoff was sworn in as the second secretary. His five goals:
1. Protect our Nation from Dangerous People
2. Protect our Nation from Dangerous Goods
3. Protect Critical Infrastructure
4. Strengthen our Nation’s Preparedness and Emergency Response Capabilities
5. Strengthen and Unify Operations and Management4126
On April 30, 2008, Secretary Chertoff, recognizing new realities, said:
[T]he technology of the 21st Century is changing so rapidly that many of our rules and procedures, which were built at a time that we had a certain kind of communication system and a certain kind of analog set of processes, that legal structure seems woefully inadequate to a digital age when the movement of communications is not rooted in any one place and when it’s very difficult to take the concepts which made a lot of sense in the days of the rotary telephone and apply them in the world of voice over internet protocols.42
In March 2010, a report on comments by FBI Director Robert Mueller and former White House “terrorism czar” Richard Clarke included this summary:
“As you well know, a cyber-attack could have the same impact as a well-placed bomb,”Mueller said. “In the past 10 years, Al-Qaeda’s online presence has become as potent as its in-world presence.”
Al-Qaeda uses for the Internet range from recruiting members and inciting violence to posting ways to make bio-weapons and forming social-networks for aspiring terrorists, according to Mueller. “The cyber-terrorism threat is real and rapidly expanding,” Mueller said. “Terrorists have shown a clear interest in hacking skills and combining real attacks with cyber attacks.”
Threats are also rising from online espionage, with hackers out for source code, money, trade, and government secrets, according to the FBI. “Every major company in the U.S. and Europe has been penetrated—it’s industrial warfare,” said Richard Clarke, who was a White House adviser under three prior U.S. presidents. “All the little cyber-devices that the companies here sell have been unable to stop them. China and Russia are stealing petabytes of information.”
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
WEAPONS OF CYBERWAR 14 · 21
Clarke, now a partner at Good Harbor Consulting firm, was among the RSA panelists dis- cussing cyber-warfare. “Nation states have created cyber-warfare units. They are preparing the battlefield,” Clarke said. “We have the governments of China and Russia engaging in daily activities successfully that the U.S. government and private industry are not stopping and they are stealing anything worth stealing.…
Mueller urged computer security professionals to join in a united, international alliance with law enforcement agencies to battle enemies in cyberspace. He credited such teamwork with resulting in the recent arrest of three men in Spain suspected of running a network of nearly 13 million computers secretly infected with malicious software and used for nefarious deeds.
Mueller called on victims of cyber-attacks to break the pattern of remaining silent out of fear that reporting crimes would hurt their positions in the marketplace. “Maintaining the code of silence will not benefit you or your clients in the long run,” Mueller said. “We must continue to do everything we can together to minimize and stop these attacks.”43
The challenges faced by the Department of Homeland Security are multitudinous and complex. Whether it proves effective in reducing or eliminating terrorism within the United States will depend on solving the problems of overlapping authorities, inertia, incompatible databases, turf wars, funding, management, the predictability of terrorist actions, and a host of political and technological issues.
14.4.3 Corporations. The threats aimed at or directed by corporations are far less deadly than those of the military or of terrorists, but they are no less pervasive. Thefts of data, denial of service, viruses, and natural disasters traditionally have been at the heart of individual corporate security concerns. These concerns have not abated, but to them have been added fears that attacks on large segments of the information infrastructure are more likely to create damage than is an attack against any single en- terprise. To guard against this, every installation should operate behind strong firewalls and effective access controls.
In the wake of the September 11 attacks, Richard Clarke, who had been National Coordinator for Security, Infrastructure Protection, and Counterterrorism since May 1998, was appointed to a new post. As special advisor to the president for cyberspace security, Mr. Clarke warned that terrorists are out to hurt our economy and that they can use viruses in massive, coordinated attacks against corporate IT systems. He recommended, at a minimum, that disaster recovery plans include near-online, offsite backup facilities and redundant communications paths.
14.5 WEAPONS OF CYBERWAR. The weapons used in information warfare have existed for many years, but newer and more malevolent versions are produced with increasing frequency. For this reason, system security cannot be considered as static, but rather as part of an ongoing process that must be continuously monitored and strengthened. This section briefly describes the most common and most dangerous IW weapons, with references to other chapters where more detailed information is available.
14.5.1 Denial of Service and Distributed Denial of Service. Denial of service (DoS) and distributed denial of service (DDoS) are means by which comput- ers, network servers, and telecommunications circuits can be partially or completely prevented from performing their designated functions. Any computer element that has been designed for a specific maximum capacity, if flooded by messages or data inputs that greatly exceed that number, can be slowed or even brought to a complete halt.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 22 INFORMATION WARFARE
A DoS attack is carried out by a single computer that has been programmed to overwhelm the target system’s capacity, usually by generating, automatically, a very large number of messages. A DDoS attack is implemented by planting a small program on hundreds or thousands of unaware computers. At a signal from the attacker, all of the agents (sometimes called zombies or daemons) are caused to send many messages simultaneously, thus flooding the victim’s system or preempting all of its bandwidth capacity.
On April 26, 2007, a page-one article in the New York Times reported on what some Estonian authorities described as the first war in cyberspace. It was precipitated by the removal from a park in Tallinn of a bronze memorial to the Soviet soldiers of World War II. It was believed, but not proven, that the Russian government, or individual activists, had used DDoS attacks to bring down computers propagating the Websites of the Estonian president, prime minister, and Parliament as well as of banks and newspapers. The attacks were finally brought under control with the help of experts from NATO, the European Union, the United States, Finland, Germany, Slovenia, and Israel. Details of many DoS and DDos attacks and the recommended defenses are contained in Chapter 18 of this Handbook.
14.5.2 Malicious Code. Malicious code includes viruses, worms, and Trojan horses, as described in Chapter 16. Mobile code, such as Java, ActiveX, and VBScript, was developed to increase the functionality of Websites, but all three, as described in Chapter 17, also can be used maliciously.
There have been innumerable instances where malicious code has been used to damage or deface Websites, both civilian and military. Apparently, all of these exploits have been perpetrated by single individuals or by very small groups of unaffiliated crackers. However, in the event of actual cyberwar, it seems certain that large groups of coordinated, technically knowledgeable attackers will attempt to wreak havoc on their opponents’ infrastructures through the use of malicious code.
In 2012, news reports indicated that Flame, malware with a relationship to Stuxnet, may, similarly, have been developed byU.S. and Israeli cyberwarfare specialists. Flame was not used for sabotage but rather for data theft.44 It was held to be responsible for stealing Iranian passwords, network descriptors, and even data files. Armed with this information, Stuxnet was allegedly used to destroy Iranian centrifuges enriching uranium as a component of atomic weapons. It accomplished this by controlling the controllers that set the speed of the centrifuges. When the speeds were set excessively high, they damaged or destroyed the centrifuges.
Becausemost of the hardware elements of these systems are commercially available, and because the software is readily duplicated, the threats to military and commercial applications are imminently capable of extensive and costly attacks. Just asU.S.military and governmental agencies, and most of their allies, are engaged in large-scale oper- ations to develop defensive capabilities, it is essential that all commercial enterprises exert major efforts to do the same. Initiatives have begun to form close working rela- tionships between government and the private sector. Also, industry groups have begun advocating relaxation of those laws that prohibit close cooperation between competi- tors. This will be necessary before information can be shared as required to strengthen the infrastructure. Similarly, groups are requesting that shared information be protected from those who would use the Freedom of Information Act to force disclosure.
Every prudent organization will support these initiatives and will work with ap- propriate government agencies and industry groups to ensure its own survival and the welfare of the country itself.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
WEAPONS OF CYBERWAR 14 · 23
14.5.3 Cryptography. Military operations, since the earliest recorded times, have utilized cryptography to prevent critical information from falling into enemy hands. Today, information is a vastly more important resource than ever before, and the need for cryptography has increased almost beyond measure. Not only the military, but indeed every financial institution, every competitive commercial enterprise, and even many individuals feel impelled to safeguard their own vital information. At the same time, access to the secret information of enemies and opponents would provide inestimable advantages.
Recognizing this, powerful supercomputers, directed bymathematicians, theoretical scientists, and cryptographers, are being applied to improving the processes of encryp- tion and decryption. The most notable achievement in the recent past was the British construction of a computerized device to break the German Enigma code. The infor- mation thus obtained has been widely credited with a significant role in the outcome of World War II.
The development of effective mechanisms for spreading computations over millions of personal computers has greatly reduced the time required for brute force cracking of specific encrypted messages; for example, messages encrypted using the 56-bit Digital Encryption Standard (DES) were decrypted in four months using 10,000 computers in 1997, 56 hours using 1,500 special-purpose processors in 1998, and 22 hours using 100,000 processors in 1999.45
A major issue, yet to be resolved, is the strength of cryptographic tools that may be sold domestically or exported overseas. The contending forces include producers of cryptographic tools who believe that if the strength of their product is in any way restricted, they will lose their markets to producers in other countries with more liberal policies. Similarly, proponents of privacy rights believe that unbreakable cryptographic tools should be freely available.
The countervailing view is that virtually unbreakable cryptographic tools shipped overseas will inevitably find their way into the hands of unfriendly governments, which may use them in conducting cyberwars against us. Domestically, law enforcement agen- cies believe that they should have “back-door” entry into all cryptographic algorithms, so that they may prevent crimes as wide-ranging as embezzlement, drug trafficking, and terrorism.
As domestic crimes and terrorist attacks grow in number and intensity, it seems certain that at least a few civil liberties, including privacy rights, may be infringed. The hope is that an optimum balance will be struck between the need for security and the core values of our democracy.
For more on privacy in cyberspace, see Chapter 69 in this Handbook.
14.5.4 Psychological Operations. Psychological operations (PSYOP) may be defined as planned psychological activities directed to enemy, friendly, and neutral audiences in order to influence their emotions, motives, attitudes, objec- tive reasoning, and behaviors in ways favorable to the originator. The target audi- ences include governments, organizations, groups, and individuals, both military and civilian.
One of the most potent weapons in information warfare, PSYOP attempts to:
� Reduce morale and combat efficiency within the enemy’s ranks � Promote mass dissension within, and defections from, enemy combat units and/or revolutionary cadres
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 24 INFORMATION WARFARE
� Support our own and allied forces cover and deception operations � Promote cooperation, unity, and morale within one’s own and allied units, as well as within friendly resistance forces behind enemy lines46
The information that accomplishes these ends is conveyed via any media: by printed material such as pamphlets, posters, newspapers, books, and magazines, and by radio, television, personal contact, public address systems, and of increasing importance, through the Internet.
A classic example of successful PSYOP application was the deception practiced prior to the Allied invasion of the European mainland. Through clever “leaks,” false information reached Germany that General Patton, America’s most celebrated combat commander, was to lead an army group across the English Channel at Pas de Calais. As a consequence, German defensive forces were concentrated in that area. For weeks after the Normandy invasion was mounted, Hitler was convinced that it was just a feint, and he refused to permit the forces at Calais to be redeployed. Had this PSYOP failed, and had more of Germany’s defensive forces been concentrated in Normandy, the Allied landing forces might well have been thrown back into the sea.
Although generally considered not to involve a PSYOP action, the September 11 at- tacks and the subsequent spread of anthrax spores made clear that a physical action can have the greatest and most far-reaching psychological effects. Beyond mourning the death of almost 3,000 innocent civilians, the new sense of vulnerability and powerless- ness caused great psychological trauma throughout the nation and much of theWestern world. The full consequences to the travel, entertainment, and hospitality industries, as well as to every segment of the world economy, are likely to be both disastrous and long-lasting.
Amajor, integrated, expert PSYOPmission to restoremorale and encourage behavior can halt or reverse a downward spiral, but worldwide recessions and acts of nature, such as cyclones, hurricanes, and earthquakes, can do more than PSYOP actions to demoralize a nation.
14.5.5 Physical Attacks. Prior to September 11, 2001, physical attacks, as a part of cyberwar, were generally considered in the same light as attacks against any military objective, and defensive measures were instituted accordingly. In the civilian sector, starting with student attacks against academic computers in the 1960s and 1970s, there have been occasional reported physical attacks against information processing resources. Although access controls have been almost universally in place, their enforcement often has been less than strict.
Another indication of the susceptibility of the information infrastructure to physical attack is the prevalence of “backhoe attacks” in which construction crews accidentally slice through high-capacity optic cables used for telecommunications and as part of the Internet backbones.47 The signs indicating where not to dig can serve as markers for those targeting single points of failure.
A related vulnerability is undersea telecommunications cables, which are unpro- tected against accidental—or deliberate—damage from ship anchors and from other objects or tools. Breaks in these cables can interrupt the Internet and telephone networks on a global scale.48
The destruction of theWTC and a portion of the Pentagon have brought the possibil- ity of additional physical attacks very much into the forefront of cyberwar thinking, for both the military and the civilian infrastructures. Car bombings and packaged bombs
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
DEFENSES 14 · 25
had become almost commonplace, especially in the Mideast. Successful attacks had been launched against U.S. embassies and troop barracks, as well as against Israel, England, Spain, and France. To guard against such actions, perimeter defenses were widened, and in some areas personal searches at strategic points were instituted.
These defenses have proven to be of limited value, and suicide bombers seem to be increasing in numbers and in the effectiveness of their weapons. The use of com- mercial aircraft, fully loaded with fuel, as manned, guided missiles was apparently never considered prior to 11 September. After that date, there has been widespread recognition that protective measures must be taken that will prevent a recurrence of those tragic events. Airport security has become a direct federal responsibility, under a new Transportation Security Administration in the Department of Transportation. On November 11, 2001, President Bush signed a bill that requires all airport baggage screeners to be U.S. citizens and to undergo criminal background checks before becom- ing federal employees. At many airports, security is provided by private contractors. The protective measures in common use are considered to be pointless, inconvenient, and ineffective by many travelers. Although even minimal safeguards against known weapons are being debated, there appears to be little thinking directed toward other types of attacks that might even now be in the planning stage.
14.5.6 Biological and Chemical Weapons and Weapons of Mass De- struction. Although the use of these weapons can affect every element of society, they have a particular potency in destroying the infrastructure of a targeted nation. The WTC attacks have had long-lasting psychological effects, but the results of the anthrax dissemination may be even more deeply traumatic. Already, the presence of anthrax spores has interfered with the functioning of the Congress, the Supreme Court, the U.S. Postal Service, hospitals, and other institutions. Although the furor over these attacks, as well as their incidence, has dissipated, there may be even more such attacks in the future. Unless any future culprit is apprehended quickly, and countermeasures taken immediately, damage to the infrastructure could be extensive.
14.5.7 Weapons Inadvertently Provided. There aremanywidespread vul- nerabilities to computer systems that are not created as weapons, but whose presence makes the targets of cyberwar highly vulnerable. Poor software designs and inadequate quality control create opportunities for attackers to damage or destroy information, and the information systems themselves. Chapters 38 to 40 of thisHandbook are especially useful in identifying and eliminating these sources of security vulnerabilities.
14.6 DEFENSES. A variety of defenses may be employed both to prevent attacks and to mitigate their effects. Because each of these defenses may have only limited utility, it is evident that new and more effective defenses must be developed.
14.6.1 Legal Defenses. As a defense against IW attacks or as a framework for apprehending and prosecuting attackers, the international legal system has been generally ineffective. The reasons for this include:
� Information warfare is not prohibited under the United Nations (UN) Charter, unless it directly results in death or property damage.
� Laws that are not recognized and enforced lose their power to compel actions. � There is little or no police power to enforce those few laws that do exist.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 26 INFORMATION WARFARE
� The issue of sovereignty as it relates to transborder communications is unresolved. � Neither the United States nor any other major power has pressed for interna- tional laws to govern information warfare. This may be attributed to the fact that such laws, while desirable for defense, would impair the nation’s own offensive operations.
� Many nations do not recognize cyberwar attacks as criminal actions. � In many lands, political considerations determine judicial outcomes. � Few countries support extradition of their citizens even when indicted for terrorist or criminal activities.
� Terrorists, drug cartels, the international mafia, and even individual hackers have every reason to circumvent the law, and usually possess the resources that enable them to do so.
� Identifying attackers may be difficult or even impossible. � New technologies arrive at a rate much faster than appropriate legislation.
Further acting to constrain law as a deterrent is the fact that there has been no univer- sal acceptance of definitions for IW-relevant terminology: Attacks, acts of war, aggres- sion, hostilities, combatants, crimes, criminals—all remain vague concepts. Until such terms, as applied to IW, are clearly defined, there can be no legal strictures against them.
The difference between acceptable and unacceptable targets is obscured by the dual- use, civilian and military, characteristics of infosystems and infrastructures. Similarly, it is difficult to condemn denial of service, when peacetime boycotts and economic sanctions are widely applied to further economic or political ends.
Clearly, legal defenses against cyberwar are inadequate at this time. Whether the United States will pursue effective international legislation remains doubtful, until the question of building adequate defenses, without hobbling offensive operations, is resolved.
14.6.2 Forceful Defenses. If IW attacks are accepted as acts of war, the use of retaliatory military force would be highly likely. The strategic and tactical decisions that would follow are well beyond the scope of this chapter, but six considerations are relevant.
1. TheUnited States is growing reluctant to engage in combatwithout the sanction of the United Nations and without the concurrence of major allies. If the provocation is limited to an IW attack, it may be difficult to build a coalition or even to avoid UN condemnation.
2. The identity of the attacker may be unclear. Even after the September 11 attacks, the United States had no enemy that admitted culpability. As a consequence, the United States could not declare war on any nation or state but could only declare a war on “terrorism.”
3. The attacker may be misidentified. Through the use of “spoofing” and routing an attack through unaware nations, the anonymous culprit may escape detection, while blame falls on an innocent victim.
4. There may be difficulty in determining whether a particular event is an act of information warfare or simply the result of errors, accidents, or malfunctions.
5. The attackers may not be a foreign government, against whom war can be de- clared, but a criminal organization, a disaffected group, activists, commercial competitors, or even individuals bent on mischief.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
DEFENSES 14 · 27
6. The United Nations, and international sentiment in general, requires that military force only be used in response to armed attack and, further, that the response be proportional to the attack that provoked it.
In light of these considerations, it seems unlikely that information warfare, unless it results in catastrophic injuries and deaths, will be met by a forceful reaction. The top secret Presidentialmemo leaked on June 7, 2013, and discussed in Section 14.3.3 clearly indicates that armed actions may now be initiated without the impetus of injuries and deaths.
14.6.3 Technical Defenses. The technical defenses against IW are many and varied. Almost the entire contents of this volume are applicable to safeguarding against cyberwar attacks. These samemeasures can prove equally effective in defending against IW, criminals, activists, competitors, and hackers.
14.6.4 In-Kind Counterattacks. A cyberwar defense that has been used often is an in-kind counterattack, where flaming is met by flaming, DDoS by DDoS, site defacement by site defacement, and propaganda by propaganda. Recent examples include exchanges between Israelis and Arabs, Kashmiris and Indians, Serbs and Albanians, Indians andPakistanis, Taiwanese andChinese, andChinese andAmericans.
Although there may be personal satisfaction in originating or responding to such attacks, the net effect is usually a draw, and, therefore, in-kind attacks generally have been short-lived. In the future, such attacks may no longer be the output of only a few individuals, but may be mounted by large numbers of similarly minded cyberwarriors, organized into coordinated groups, with sophisticated tools and with covert or overt state sponsorship.
In that event, the asymmetric nature of the adversaries’ infrastructures would be telling. Clearly, if the Taliban, for example, were to mount another full-scale cyber- terrorist attack against the United States with the help of their supporters through- out the world, the effects could be devastating. Although the United States might mount a highly sophisticated in-kind response, it probably would have no effect on the Taliban’s organization, its economy, its military effectiveness, or its ability to carry out suicide missions, biological warfare, or other physical attacks. A great and pow- erful nation may lack the ability to destroy a small, primitive, almost nonexistent infrastructure.
A serious problem with any kind of counterattack is that the origins of cyberattacks through the Internet using Internet Protocol version 4 (IPv4) are easily masked, or spoofed, because of the lack ofmandatory, verifiable source authentication. It is possible that poorly analyzed data about the supposed attackers could lead to a counterattack against innocent victims.
14.6.5 Integration of Cyberwarfare into Military Planning. The United States Cyber Command (USCYBERCOM) was initiated in 2009 as a subset of the United States Strategic Command and became fully operational in its Fort Meade headquarters in 2010.49 Its mission and focus are defined as follows:
� Mission: USCYBERCOM is responsible for planning, coordinating, integrating, synchro- nizing, and directing activities to operate and defend the Department of Defense information networks and when directed, conducts full-spectrum military cyberspace operations (in ac- cordance with all applicable laws and regulations) in order to ensure U.S. and allied freedom of action in cyberspace, while denying the same to our adversaries.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 28 INFORMATION WARFARE
� Focus: The command is chargedwith pulling together existing cyberspace resources, creating synergy that did not previously exist and synchronizing war-fighting effects to defend the information security environment.
� The Command centralizes direction of cyberspace operations, strengthens DoD cyberspace capabilities, and integrates and bolsters DoD’s cyberexpertise. USCYBERCOM improves DoD’s capabilities to ensure resilient, reliable information and communication networks, counter cyberspace threats, and assure access to cyberspace. The command works closely with interagency and international partners in executing the cybermission.
USCYBERCOM has initiated training exercises for U.S. military forces. The first Cyber Flag exercise was held in 2011 at Nellis Air Force Base; the second was in 2012.50 The 2012 “… exercise saw approximately 700 participants, up from last year’s 300, and doubled the network size. All participants had a specific role to play, playing the part of a U.S. team or role-playing an adversary.”
In January 2013, plans surfaced for a major investment by the Pentagon in cyberse- curity:
The expansion would increase the Defense Department’s Cyber Command by more than 4,000 people, up from the current 900, an American official said. Defense officials acknowledged that a formidable challenge in the growth of the command would be finding, training, and holding onto such a large number of qualified people.
The Pentagon “is constantly looking to recruit, train and retain world class cyberpersonnel,” a defense official said Sunday.
“The threat is real and we need to react to it,” said William J. Lynn III, a former deputy defense secretary who worked on the Pentagon’s cybersecurity strategy.
As part of the expansion, officials said the Pentagon was planning three different forces un- der Cyber Command: “national mission forces” to protect computer systems that support the nation’s power grid and critical infrastructure; “combat mission forces” to plan and exe- cute attacks on adversaries; and “cyberprotection forces” to secure the Pentagon’s computer systems.51
14.6.6 Cooperative Efforts. Although the United States has been moderately successful in building coalitions in support of military operations, it has shown little inclination to build an international consensus dealing with information warfare. This may be so because of the legal difficulties outlined in Section 14.6.1 or because any prohibitions against offensive cyberwar will limit United States options. Nevertheless, whether by treaty, convention, agreement, or UN directive, technical people, diplo- mats, and statesmen of all well-intentioned countries should work together to define unacceptable and harmful actions and to devise means for detecting, identifying, and punishing those who transgress.
In June 2013, the North Atlantic Treaty Organization (NATO) representatives par- ticipated in a discussion of “how best to defend against cyber threats.”52 NATO posted this summary of its stance:
Against the background of rapidly developing technology, NATO is advancing its efforts to confront the wide range of cyber threats targeting the Alliance’s networks on a daily basis. NATO’s Strategic Concept and the 2012 Chicago Summit Declaration recognise that the growing sophistication of cyber attacks makes the protection of the Alliance’s information and communications systems an urgent task for NATO, and one on which its security now depends.
In June 2011, NATO adopted a new cyber defence policy and the associated Action Plan, which sets out a clear vision of how the Alliance plans to bolster its cyber efforts. This policy
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
FURTHER READING 14 · 29
reiterates that any collective defence response is subject to decisions of the North Atlantic Council, NATO’s principal political decision-making body.
The revised policy offers a coordinated approach to cyber defence across the Alliance. It focuses on the prevention of cyber attacks and building resilience. All NATO structures will be brought under centralised protection and NATO will enhance its capabilities to deal with the vast array of cyber threats it currently faces, including through integrating them into the NATO Defence Planning Process. This way Allies will ensure that appropriate cyber defence capabilities are included as part of their planning to protect information infrastructures that are critical for core Alliance tasks. The revised cyber defence policy also stipulates NATO’s principles on cyber defence cooperation with partner countries, international organisations, the private sector and academia.53
14.7 SUMMARY. The potential for information warfare to damage or destroy the infrastructure of any nation, any corporation, or, in fact, any civilian, governmental, or military entity is unquestionable. Until now, the only incidents have been isolated and sporadic, but the possibility of sustained, coordinated, simultaneous attacks is strong. If these attacks are combined with physical, chemical, or biological warfare, the effects are certain to be devastating.
Although the types of potential attackers, and the probable weapons they will use, are well known, the available defenses do not at this time offer any great assurance that they will be effective. The United States and many of its allies are engaged in great efforts to remedy this situation, but formidable obstacles are yet to be overcome. The military is generally better prepared than the civilian sector, but much of the military’s infrastructure is woven into and dependent on transportation, communications, utilities, food production and distribution, and other vital necessities that are owned by private enterprises.
Recent terrorist attacks and the probability of future offensives should serve as an immediate impetus to devote whatever resources are needed to combat the threats to our way of life and, in fact, to our very existence.
14.8 FURTHER READING Armistead, E. L. Information Operations: Warfare and the Hard Reality of Soft Power.
Potomac Books, 2004. Armistead, E. L. Information Warfare: Separating Hype from Reality. Potomac Books,
2007. Armistead, E. L. Information Operations Matters: Best Practices. Potomac Books,
2010. Arquilla, J., and D. Ronfeldt, eds. In Athena’s Camp: Preparing for Conflict in the
Information Age. RAND Corporation, 1997. Available free in parts as PDF files from http://rand.org/pubs/monograph reports/MR880/
Campen, A. D., and D. H. Dearth, eds. Cyberwar 3.0: Human Factors in Information Operations and Future Conflict. Fairfax, VA: AFCEA International Press, 2000.
Clarke, R. A. Cyber War: The Next Threat to National Security and What to Do About It. Ecco, 2010.
Cohen, F. World War 3: We Are Losing It and Most of Us Didn’t Even Know We Were Fighting in It—Information Warfare Basics. Fred Cohen & Associates, 2006.
Denning, D. E. Information Warfare and Security. Addison-Wesley, 1998. Erbschloe, M., and J. Vacca. Information Warfare. McGraw-Hill, 2001. Greenberg, L., S. E. Goodman, and K. J. Soo Hoo. Information Warfare and Interna-
tional Law. National Defense University Press, 1998.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 30 INFORMATION WARFARE
Hall, W. M. Stray Voltage: War in the Information Age. U.S. Naval Institute Press, 2003.
Henry, R., and C. E. Peartree, eds. The Information Revolution and International Security. Center for Strategic and International Studies, 1998.
Kahn, D. The Codebreakers. Scribner, 1996. Kramer, F. D., S. H. Starr, and L. Wentz, eds. Cyberpower and National Security.
Potomac Books, 2009. Lesser, I. O., B. Hoffman, J. Arquilla, D. Ronfeldt, and M. Zanini. Countering the New
Terrorism. RAND Project Air Force, 1999. Available free in parts as PDF files from http://rand.org/pubs/monograph reports/MR989/
Macdonald, S. Propaganda and Information Warfare in the Twenty-First Century: Altered Images and Deception Operations. Routledge, 2007.
Marsh, R. T., chair. Critical Foundations: Protecting America’s Infrastructures. The Report of the President’s Commission onCritical Infrastructure Protection. 1997; www.fas.org/sgp/library/pccip.pdf
Price, A., andC.A.Horner.War in the FourthDimension:U.S. ElectronicWarfare, from the VietnamWar to the Present. London, UK: Greenhill Books/Lionel Leventhal, 2001.
Rattray, G. J. Strategic Warfare in Cyberspace. MIT Press, 2001. Reveron, D. S. Cyberspace and National Security: Threats, Opportunities, and Power
in a Virtual World. Georgetown University Press, 2012. Rid, T. Cyber War Will Not Take Place. Oxford University Press, 2013. Rosenzweig, P.CyberWarfare: HowConflicts in Cyberspace Are Challenging America
and Changing the World. Praeger, 2013. Schwartau, W. Information Warfare: Chaos on the Electronic Superhighway, 2nd ed.
Thunder’s Mouth Press/Perseus Publishing Group, 1996. Zalmay,K., and J. P.White, eds. Strategic Appraisal: TheChangingRole of Information
in Warfare. McGraw-Hill, 1999.
14.9 NOTES 1. W. J. Clinton, “Critical Infrastructure Protection,” Presidential Decision Directive
63, May 22, 1998, www.fas.org/irp/offdocs/pdd/pdd-63.htm 2. J. L. Brock, “Critical Infrastructure Protection: Fundamental Improvements
Needed to Assure Security of Federal Operations,” GAO/T-AIMD-00-7, Testi- mony before the Subcommittee on Technology, Terrorism and Government Infor- mation, Committee on the Judiciary, U.S. Senate, October 6, 1999, www.gao.gov/ archive/2000/ai00007t.pdf
3. L. Wright, “Protecting the Homeland: Report of the Defense Science Board Task Force on Defensive Information Operations 2000 Summer Study, Vol. II.” Office of the Undersecretary of Defense for Acquisition, Technology, and Logistics (March 2001), www.acq.osd.mil/dsb/reports/dio.pdf (URL inactive)
4. T. P. M. Barnett, “The Seven Deadly Sins of Network-Centric Warfare,” United States Naval Institute Proceedings 125, No. 1 (January 1999): 36–39, www.usni. org/magazines/proceedings/1999-01/seven-deadly-sins-network-centric-warfare
5. G. G. Gilmore, “Navy-Marine Corps Intranet Girds for Cyber-Attacks,” Armed Forces Press Service, July 6, 2001, www.defenselink.mil/news/newsarticle. aspx?id=44745
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 14 · 31
6. U.S. Office of the Secretary of Defense, “Annual Report to Congress: Military and Security Developments Involving the People’s Republic of China 2013,” www.defense.gov/pubs/2013 China Report FINAL.pdf
7. Joint Chiefs of Staff, “Joint Doctrine for InformationOperations,” Joint Publication 3-13, 2006, www.dtic.mil/doctrine/jel/new pubs/jp3 13.pdf (URL inactive)
8. W. S. Cohen, Annual Report to the President and the Congress: Secretary of De- fense, 2001, www.dod.mil/execsec/adr2001/index.html, Chapter 8: “Information Superiority and Space,” www.dod.mil/execsec/adr2001/Chapter08.pdf (URL inactive)
9. “Obama tells intelligence chiefs to draw up cyber target list—full document text: Eighteen-page presidential memo reveals howBarackObama has ordered intelligence officials to draw up a list of potential overseas targets for US cyber attacks.” The Guardian, June 7, 2013, www.guardian.co.uk/world/interactive/2013/jun/07/ obama-cyber-directive-full-text
10. This section uses verbatim extracts of articles published by M. E. Kabay originally published in Network World Security Strategies. Used with permission.
11. Jesse Berst, “The Electricity Economy: New Opportunities from the Transforma- tion of theElectric Power Sector,”White Paper,Global Environment Fund&Global SmartEnergy, August 2008, 55, www.terrawatts.com/electricity-economy.pdf p. 12.
12. Berst, “The Electricity Economy,” p. 19. 13. Robert T. Marsh, Critical Foundations: Protecting America’s Infrastructures, U.S.
Government, Washington, DC: President’s Commission on Critical Infrastructure Protection, 1997, 192. www.fas.org/sgp/library/pccip.pdf
14. M. E. Kabay, “Attacks on Power Systems: Data Leakage, Espionage, Insider Threats, Sabotage,” Network World Security Strategies, September 13, 2010, www.mekabay.com/nwss/828c attacks on power systems (2).pdf
15. M. E. Kabay, “Attacks on Power Systems: Hackers, Malware,” Network World Se- curity Strategies, September 8, 2010, www.mekabay.com/nwss/828c attacks on power systems (1).pdf
16. ENISA, “Stuxnet Analysis,” Press Release, July 10, 2010, www.enisa.europa.eu/ media/press-releases/stuxnet-analysis
17. ENISA, “New Report on Smart Grids Cyber Security Measures; A Risk- Based Approach Is Key To Secure Implementation, According to EU Agency ENISA,” Press Release, December 19, 2012, www.enisa.europa.eu/media/press- releases/smart-grids-cyber-security-measures-a-risk-based-approach-is-key-to- secure-implementation
18. See www.presidency.ucsb.edu/ws/?pid=24180 19. S. M. Parker, “Information and Finance: A Strategic Target,” CommSec, 1997,
http://all.net/books/iw/iwarstuff/www.commsec.com/security/infowarfare.htm 20. Federal Reserve Financial Services, “All Fedwire Participants,” 2012, https://
www.fededirectory.frb.org/fpddir.txt 21. Federal Reserve Board, “Fedwire Funds Sevice 2011 Annual Summary,” 2011,
www.federalreserve.gov/paymentsystems/fedfunds ann.htm 22. Clearing House Interbank Payments System, “About CHIPS,” www.chips.org/
about/pages/033738.php 23. SWIFT “Company Information,” www.swift.com/about swift/company informa
tion/index.page
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
14 · 32 INFORMATION WARFARE
24. SWIFT, “SWIFT in Figures—FIN Traffic,” 2012, www.swift.com/about swift/ company information/swift in figures/archive/2012/SIF 2012 09.pdf (URL inactive)
25. Ann Zimmerman and Miguel Bustillo, “‘Flash Robs’ Vex Retailers.” Wall Street Journal, October 21, 2011, http://online.wsj.com/article/SB1000142405297 0203752604576643422390552158.html
26. M. E. Kabay, “Critical Thinking and Disintermediation,” 2007, www.mekabay. com/opinion/critical thinking.pdf
27. Numbers 13:16, 17 28. Public Law 104-294, “Economic Espionage Act of 1996”; www.law.cornell.edu/
usc-cgi/get external.cgi?type=pubL&target=104-294 29. “Counterintelligence: What Are We Protecting?” Defense Security Service, 1998,
www.dss.mil/portal/ShowBinary/BEA%20Repository/new dss internet/isp/ count intell/what protecting.html or http://tinyurl.com/5fwafb
30. T. L. Thomas, “Like Adding Wings to the Tiger: Chinese Information War The- ory and Practice,” Foreign Military Studies Office, Fort Leavenworth, KS, 2000; www.iwar.org.uk/iwar/resources/china/iw/chinaiw.htm
31. B. Gertz, “Hackers Linked to China Stole Documents from Los Alamos,” Wash- ington Times, August 3, 2000, p. 1
32. Shen Weiguang, “Checking Information Warfare Epoch Mission of Intellectual Military,” Jiefangjun Bao, February 2, 1999, p. 6, as translated and downloaded from the Foreign Broadcast Information System (FBIS) Web site on February 17, 1999; www.opensource.gov (registration restricted to U.S. federal, state and local government employees and contractors).
33. Wei Jencheng, “New Form of People’s Warfare,” Jiefangjun Bao, June 11, 1996, p. 6, as translated and reported in FBIS-CHI-96-159, August 16, 1996.
34. Shen Weiguang (1995). “Focus of Contemporary World Military Revolution— Introduction to Research in IW,” Jiefangjun Bao, November 7, 1995, p. 6, as translated and reported in FBIS-CHI-95-239, December 13, 1995, pp. 22–27.
35. M. E. Kabay, “US DoD Annual Estimates of Information Warfare Capabilities and Commitment of the PRC 2002-2011,” 2013, www.mekabay.com/overviews/ dod prc iw.pdf
36. Qianjin Bao, December 10, 1999, provided by William Belk via email to Timothy L. Thomas. According to Mr. Thomas, Mr. Belk is the head of a skilled U.S. reservist group that studies China.
37. Quotation from S. H. Verstappen, The Thirty-Six Strategies of Ancient China (Books and Periodicals, 2000). As described at www.chinastrategies.com/ home36.htm
38. Zhang Zhenzhong and Chang Jianguo, “Train Talented People at Different Levels for Information Warfare,” Jiefangjun Bao, February 2, 1999, as translated and downloaded from FBIS Website on February 10, 1999.
39. A. D. Sofaer et al., “A Proposal for an International Convention on Cyber Crime and Terrorism,” 2000, www.iwar.org.uk/law/resources/cybercrime/stanford/cisac- draft.htm
40. G. W. Bush, Executive Order Establishing Office of Homeland Security, 2001, http://georgewbush-whitehouse.archives.gov/news/releases/2001/10/20011008-2 .html
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 14 · 33
41. U.S. Department of Homeland Security, “The Secretary’s Five Goals,” 2008, www.dhs.gov/xabout/gc 1207339653379.shtm (URL inactive)
42. M. Chertoff, “Remarks by Secretary Michael Chertoff and President of the Supreme Court of Israel Dorit Beinisch to the Heritage Foundation’s Civil Rights and the War on Terror: Dilemmas and Challenges Event,” April 30, 2008, www.dhs.gov/xnews/speeches/sp 1209741455799.shtm (URL inactive)
43. “FBI: Cyber-Terrorism a Real and Growing Threat to U.S.” Homeland Secu- rity News Wire, March 5, 2010, www.homelandsecuritynewswire.com/fbi-cyber- terrorism-real-and-growing-threat-us
44. Lucian Constantin, “Report: Flame Part of US-Israeli Cyberattack Campaign against Iran.”Network World, June 20, 2012, www.networkworld.com/news/2012/ 062012-report-flame-part-of-us-israeli-260353.html
45. M. Curtin and J. Dolske, “A Brute-Force Search of DES Keyspace,” 1998, www.interhack.net/pubs/des-key-crack; “Cracking DES: Secrets of Encryption Research, Wiretap Politics & Chip Design—How Federal Agencies Subvert Privacy: Frequently Asked Questions (FAQ) About the Electronic Frontier Foundation’s ‘DES Cracker’ Machine,” Electronic Frontier Foundation, 1998, http://w2.eff.org/Privacy/Crypto/Crypto misc/DESCracker/19980716 eff des.faq or http://tinyurl.com/68thws; and “RSA Code-Breaking Contest Again Won by Distributed.Net and Electronic Frontier Foundation (EFF): DES Chal- lenge III Broken in Record 22 Hours,” Electronic Frontier Foundation, 1999, http://w2.eff.org/Privacy/Crypto/Crypto misc/DESCracker/HTML/19990119 deschallenge3.html or http://tinyurl.com/5n3gqf
46. E. Rouse, “Psychological Operations/Warfare,” date unknown; www.psywarrior. com/psyhist.html
47. K. Poulson, “The Backhoe: A Real Cyberthreat,” Wired, January 19, 2006, www. wired.com/science/discoveries/news/2006/01/70040; also CGA “CGA DIRT Analysis and Recommendations for Calendar Year 2005,” Common Ground Al- liance Damage Information Reporting Tool, 2005, www.commongroundalliance. com/TemplateRedirect.cfm?Template=/ContentManagement/ContentDisplay. cfm&ContentFileID=3269 or http://tinyurl.com/43obmo
48. K. Kratovac, “Ship’s Anchor Caused Cut in Internet Cable: Unusual Cuts Led to Disruptions in Services, Slowed Down Businesses,” MSNBC Technology and Science/Internet, February 8, 2008, www.msnbc.msn.com/id/23068571/
49. United States Strategic Command, “U. S. Cyber Command,” Fact Sheet, 2012, www.stratcom.mil/factsheets/Cyber Command/
50. Scott McNabb, “AFCYBER Takes Part in Second USCYBERCOM Cyber Flag Exercise.” U.S. Air Force Space Command press release, November 21, 2012, updated November 29, 2012, www.afspc.af.mil/news/story.asp?id=123327388
51. E. Bumiller, “Pentagon Expanding Cybersecurity Force to Protect Networks Against Attacks,” TheNewYork Times, January 27, 2013, www.nytimes.com/2013/ 01/28/us/pentagon-to-beef-up-cybersecurity-force-to-counter-attacks.html
52. NATO, “Collaborating against Cyber Threats,” in the Web page “Defending against Cyber Attacks,” NATO Website, June 4, 2013, www.nato.int/cps/en/ natolive/75747.htm
53. NATO, “NATO and Cyber Defence,” NATO Website, www.nato.int/cps/en/SID- BB17E53B-F3456C51/natolive/topics 78170.htm
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15CHAPTER
PENETRATING COMPUTER SYSTEMS AND NETWORKS
Chey Cobb, Stephen Cobb, M. E. Kabay, and Tim Crothers
15.1 MULTIPLE FACTORS INVOLVED IN SYSTEM PENETRATION 15 ·1 15.1.1 System Security: More
than a Technical Issue 15 ·2 15.1.2 Organizational Culture 15 ·2 15.1.3 Chapter Organization 15 ·3
15.2 NONTECHNICAL PENETRATION TECHNIQUES 15 ·3 15.2.1 Misrepresentation
(Social Engineering) 15 ·3 15.2.2 Incremental
Information Leveraging 15 ·6
15.3 TECHNICAL PENETRATION TECHNIQUES 15 ·7 15.3.1 Data Leakage: A
Fundamental Problem 15 ·7 15.3.2 Intercepting
Communications 15 ·8 15.3.3 Breaching Access
Controls 15 ·15
15.3.4 Spying 15 ·20 15.3.5 Penetration Testing,
Toolkits, and Techniques 15 ·20
15.3.6 Penetration via Websites 15 ·27
15.3.7 Role of Malware and Botnets 15 ·31
15.3.8 Sophisticated Attackers 15 ·32
15.4 POLITICAL AND LEGAL ISSUES 15 ·36 15.4.1 Exchange of System
Penetration Information 15 ·36
15.4.2 Full Disclosure 15 ·36 15.4.3 Sources 15 ·38 15.4.4 Future of Penetration 15 ·39
15.5 SUMMARY 15 ·40
15.6 FURTHER READING 15 ·41
15.7 NOTES 15 ·42
15.1 MULTIPLE FACTORS INVOLVED IN SYSTEM PENETRATION. Al- though penetrating computer systems and networks may sound like a technical chal- lenge, most information security professionals are aware that systems security has both technical and nontechnical aspects. Both aspects come into play when people attempt to penetrate systems. Both aspects are addressed in this chapter, which is not an in- struction guide on how to penetrate systems, but rather a review of the methods and means by which systems penetrations are accomplished.
15 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 2 PENETRATING COMPUTER SYSTEMS AND NETWORKS
15.1.1 System Security: More than a Technical Issue. The primary non- technical factor in system security and resistance to system penetration is human be- havior, which can defeat just about any technical security measure. More than anything else, security depends on human beings to understand and carry out security proce- dures. Consequently, information system (IS) security must be integral to the culture of any organization employing an information system. Without security, systems and networks will not be able resist attempts at penetration.
Often security is represented as a structure of concentric circles. Protection of the central, secured element is then dependent on the barriers imposed by each successive ring. These barriers can be physical or figurative, but the goal of IS security is to protect the integrity, confidentiality, and availability of information processed by the system. This goal is reached using identification, authentication, and authorization. Identification is a prerequisite, with each user required to proffer an identifier (ID) that is included in the authorization lists of the system to be accessed. Authentication consists of proving that the user really is the person to whom the ID has been assigned. Authorization consists of defining what a specific user ID, running specified programs, can legally do on the system. The security perimeter can be penetrated by compromising any of these functions. Chapters 28 and 29 in this Handbook discuss identification and authentication in detail.
The trend toward distributed and mobile computers, often utilizing the global net- working capability of the Internet, makes it hard to knowwhere to draw these concentric circles of protection. Indeed, the barriers to penetration need to be extended along lines of communication, encompassing end points of the network, which may be geograph- ically dispersed.
15.1.2 Organizational Culture. An organization’s general attitude toward security is the key to an effective defense against attack. Security is difficult to sell, especially to an organization that has never experienced a significant problem. (Ironi- cally, the better the defenses, the less evidence there is of their utility.) A basic principle of security is that practitioners must act as if they are paranoid, continuously on guard against attacks from any direction. Many organizations view security precautions as an attack on the integrity of employees. Wearing badges, for example, sometimes is viewed as dehumanizing and offensive. This attitude leads to absurdities, such as hav- ing only visitors wear badges. If only visitors wear badges, then taking off the badge automatically reduces the likelihood that a dishonest intruder will be challenged.
Some individual employees also consider security precautions as personally of- fensive. For example, locking a terminal or workstation when leaving it for a few minutes may be seen as evidence of distrust of other employees. Refusing to allow piggybacking—that is, permitting several colleagues to enter a restricted area on one access card—may be seen as insufferably rude. Where employees are taught to be open and collegial, securing removable computer media and paperwork at night can seem insulting.
These conflicts occur because years of socialization, starting in infancy, are diamet- rically opposed to the tenets of information security. Politeness in a social context is a disaster in a secure area; for instance, piggybacking into a computer room impairs the accuracy of audit trails kept by the access-control computers. Lending someone a car is kind and generous, but lending someone a user ID and a personal password is a gross violation of responsibility. Chapters 49 and 50 in this Handbook discuss psychological aspects of changing corporate culture to support information security.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NONTECHNICAL PENETRATION TECHNIQUES 15 · 3
Carrying out effective security policies and procedures must resolve these conflicts between normal standards of politeness and the standards required in a secure envi- ronment. Organizations must foster open discussion of the appropriateness of security procedures, so that employees can voluntarily create a corporate culture conducive to protection of corporate information. Chapters 44, 45, 48, and 51 in this Handbook specifically discuss policy issues.
Beyond this, organizations need to be aware of the security posture and attitudes of those with whom they network. These days it is quite possible for one organization’s system to be operated, or even owned, by another. And people from many different organizations may be using the same network. A culture of security must permeate all of the organizations that have access to a system, otherwise points of weakness will exist, thus increasing the probability that attempts to penetrate the system will succeed.
15.1.3 Chapter Organization. Section 15.2 looks at methods of tricking peo- ple into allowing unauthorized access to systems (Chapter 19 in this Handbook ex- plores social engineering in more depth). Section 15.3 examines technical measures for overcoming security barriers and specific techniques (exploits) for penetration, while Section 15.4 describes legal and political aspects of system penetration.
15.2 NONTECHNICAL PENETRATION TECHNIQUES. Although the pene- tration of information systems is often portrayed as the work of the technically adept, many successful penetrations have relied on human factors, such as gullibility and venality. Both are exploited by would-be system penetrators.
15.2.1 Misrepresentation (Social Engineering). Social engineering relies on falsehood. Lies, bribes, and seduction can trick honest or marginally dishonest employees into facilitating a penetration. An attacker might trick an employee into revealing login and authentication codes or even into granting physical access to an otherwise secure site. System penetration can then be accomplished by numerous means, from walking up to an unsecured workstation, to installing Trojan code or a network packet-sniffing device. (Both of these technologies are discussed in more detail later in this chapter.)
15.2.1.1 Lying. Telling lies is a technique often used by persons intent on ob- taining unauthorized access to a system. One can obtain valuable information about a system and its defenses by telling lies. Many lies work by playing on the natural human tendency to interpret the world by our internal model of what is most likely. So- cial psychologists call this model the schema.Well-dressed businesspeople who walk briskly and talk assertively are probably what they seem. In a phone conversation, a person who sounds exasperated, impatient, and rude when demanding a new password is probably an exasperated, impatient, and rude employee who has forgotten a pass- word. Unfortunately, many criminals know, sometimes instinctively, how to exploit these interpretations to help get them into secured systems.
Another technique, often used in concert with lying, is to escape notice and avoid suspicion by simply blending in. The way we perceive, or fail to perceive, details are referred to by social psychologists as the figure-ground problem. The normal becomes the background, and the objects of our attention become figures standing out from the ground. The schema influences what is noticed; only deviations from expectation spark figure-ground discrimination. Criminal hackers take advantage of this effect by fading into the background while penetrating security perimeters.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 4 PENETRATING COMPUTER SYSTEMS AND NETWORKS
15.2.1.2 Impersonating Authorized Personnel. Criminal hackers and unscrupulous employees call security personnel, operators, programmers, and admin- istrators to request user IDs, privileges, and even passwords. (This is one reason that the telephone is a poor medium for granting security privileges; if staff members were trained to refuse requests made over the phone, many attempts to penetrate systems could be thwarted.) In sites where employees wear ID badges, intruders have a hard time penetrating physical security by posing as employees. However, physical security in these cases depends on the cooperation of all authorized personnel to challenge everyone who fails to wear a badge. This policy is critically important at entry points. To penetrate such sites physically, criminals must steal or forge badges or work with confederates to obtain real but unauthorized badges.
Sites where physical security includes physical tokens, such as cards for electronic access control, are harder for criminals to penetrate. They must obtain a real token, per- haps by theft or by collusion with an employee. Perimeter security depends on keeping the access codes up to date so that cards belonging to ex-employees are inactivated. Security staff must immediately inactivate all cards reported lost. In addition, it is essential that employees not permit piggybacking, the act of allowing another person, possibly unauthorized, to enter a restricted zone along with an authorized person. Too often, an employee, in an act of politeness, will permit others to enter a normally locked door as he or she exits. Once inside a building, criminals can steal valuable information that will allow later penetration of the computer systems from remote locations. This is often accomplished by impersonating third-party personnel.
Even if employees are willing to challenge visitors in business suits, it may not occur to them to interfere with people who look as if they are employees of an authorized support firm. For example, thieves often have succeeded in entering a secured zone by dressing like third-party computer technicians or office cleaners. Few employees will think of checking the credentials of a weary technician wearing grimy overalls, an authentic-looking company badge, a colorful ID card, and a tool belt. When a suitable- looking individual claims to have been called to run diagnostics on a workstation, many nontechnical employees will acquiesce at once, seizing the opportunity to grab a cup of coffee or to chat with colleagues. Minutes later, the thief may have copied sensitive files or installed a sniffing device (e.g., a keystroke recorder or a network packet sniffer). In one case known to one of the authors (MK), a criminal was given a workspace and a network connection in a large bank and allowed to work unmolested and unchallenged for several months on a “secret project.” It was only when an alert security guard realized that no on one in the office knew who this person was that she challenged the intruder and broke the scam.
15.2.1.3 Intimidation. A technique related to impersonation of authorized or third-party personnel is intimidation. Someone claiming to be a person in a position of authority displays irritation or anger at delays in granting an unauthorized deviation from policy, such as communicating a password over the phone to a person of unau- thenticated identity. The attackers indirectly or directly threaten alarming consequences (e.g., delays of critical repairs, financial losses, disciplinary actions) unless they are granted restricted information or access to secured equipment or facilities.
15.2.1.4 Subversion. People make moral choices constantly. There is always a conscious or unconscious balancing of alternatives. Criminal hackers try to reach
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NONTECHNICAL PENETRATION TECHNIQUES 15 · 5
their goals by changing the rules so that dishonesty becomes more acceptable to the victim than honesty.
15.2.1.5 Bribery. A lot of industrial and commercial information has a black market value. The same is true of personally identifiable information that can be used to commit fraud and identity theft. The price of a competitor’s engineering plans or customer database may be a year’s salary for a computer operator responsible for making backups. There is little likelihood that anyone would notice the subverted operator copying a backup at 3:00 a.m. or a secretary taking an extra compact disc out of the office. Many organizations have failed to install software to prevent a manager sending electronic mail with confidential files to a future employer.
That industrial espionage, with or without state sponsorship, is a thriving business is a fact that is now widely—and sometimes quite openly—acknowledged.1 Building a corporate environment in which employees legitimately feel themselves to be part of a community is a bulwark against espionage. When respect and a sense of exchange for mutual benefits inform the corporate culture, employees will rebuff spies or even entrap them, but the disgruntled employee whose needs are not addressed is a potential enemy.
15.2.1.6 Seduction. Sometimes criminal hackers and spies have obtained con- fidential information, including access codes, by tricking employees into believing that they are loved. This lie works well enough to allow access to personal effects, sometimes after false passion or drugs have driven the victim into insensibility. It is not unknown for prostitutes to seduce men from organizations that they and their con- federates are seeking to crack. Rifling through customers’ wallets can often uncover telltale slips bearing user IDs and passwords.
No one can prevent all such abuse. People who are enthralled by expert manipulators will rarely suspect that they are being used as a wedge through a security perimeter. Along with a general increase in security consciousness, staff members with sensitive codes must become aware of these techniques so that they may be less vulnerable. Perhaps then they will automatically reject a request for confidential information or access codes.
15.2.1.7 Extortion. Criminals can threaten harm if their demands are not met. Threaten someone’s family or hold a gun to their head and few will, or should, resist a demand for entry to a secured facility or for a login sequence into a network. Some physical access-control systems include a duress signal that can be used to trigger a silent alarm at the monitoring stations. The duress signal requires a predetermined, deliberate action on the part of the person being coerced into admitting unauthorized personnel. This actionmay be adding an extra number to the normal pass code, pressing the pound sign (#) twice after entering the code, or entering 4357 (H-E-L-P) into the keypad. The duress signal covertly notifies security that an employee is being forced to do something unwillingly. Security can then take appropriate action.
15.2.1.8 Blackmail. Blackmail is extortion based on the threat of revealing se- crets. An employee may be entrapped into revealing confidential data, for example, using techniques just described. Classic blackmail includes seduction followed by pic- tures in flagrante delicto, which the criminals then threaten to reveal. Sometimes a person can be framed by fabricated evidence; a plausible but rigged image of venality can ruin a career as easily as truth. Healthy respect for individuals and social bonds
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 6 PENETRATING COMPUTER SYSTEMS AND NETWORKS
among employees, supervisors, and management can make it difficult for blackmailers to succeed. If employees who are victims of a blackmail attempt feel they can inform management without suffering inappropriately negative consequences, the threat may be mitigated to a certain degree. Perhaps the last, best defense against blackmail is honesty. The exceptionally honest person will reject opportunities that lead to victim- ization through blackmail and will laugh at fabrications, trusting friends and colleagues to recognize lies when they hear them.
15.2.1.9 Insiders. Many of the world’s largest and most daring robberies have, upon examination, turned out to be inside jobs. The same is true of system penetrations. Although many of the just-described techniques can be used to obtain help from the inside, some aremade possible by people on the insidewho decide, for whatever reason, to aid and abet criminal hackers. For example, a dishonest employee may actively seek to sell access for personal gain. Organizations should try to be alert to this eventuality, but there is very little defense against thoroughly dishonest employees when the only overt act needed to open the gates from the inside is to pass system credentials to an outsider. Chapter 13 in this Handbook specifically addresses insider crime.
15.2.1.10 Human Target Range. Organizations should not underestimate the range of targets at which the described techniques may be directed. Although the terms employees, authorized personnel, and third-party personnel are used in the preceding paragraphs, the target range includes all manner of vendors, suppliers, and contractors as well as all levels of employees—from software and hardware vendors, through contract programmers, to soft-drink vendors and cleaning staff. It may even include clients and customers, some of whom possess detailed knowledge of the organization’s operations. Employees at every level are likely to be computer literate, although with varying degrees of skill. For example, it is quite possible that someone working as a janitor today knows how to operate a computer skillfully and may even know how to surf hacking sites on the Web and download penetration tools. Indeed, a janitor may have obtained the job specifically with the intent of engaging in industrial espionage, data theft, or sabotage.
In short, anyone who comes into contact with the organization has the potential to provide an attacker with information useful in the preparation and execution of an attack. The human targets of a social engineering attack may not, on an individual basis, possess or divulge critical information, but eachmay provide clues—pieces of the puzzle—an aggregation of which can lead to successful penetration and compromise of valuable data and resources. Use of this process is a hallmark of some of the most successful criminal hackers. The term incremental information leveraging was coined for this use of less valuable data to obtain more valuable data.2
15.2.2 Incremental Information Leveraging. By gathering and shrewdly utilizing small and seemingly insignificant pieces of information, it is possible to gain access to much more valuable information. This technique of incremental information leveraging is a favorite tool of hackers, both criminal and noncriminal. One important benefit of the tool that is particularly appreciated by criminal hackers is the low profile it presents to most forms of detection. By accumulating seemingly innocuous pieces of information over a period of time, and by making intelligent deductions from them, it is possible to penetrate systems to the highest level.
A prime example of this approach is seen in the exploits of Kevin Mitnick, who served almost five years behind bars for breaking into computers, stealing data, and
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 7
abusing electronic communication systems. Illegal acts committed by Mitnick include the 1981 penetration of Computer System for Mainframe Operations (COSMOS), a Pacific Bell facility in downtown Los Angeles. COSMOS was a centralized database used by many U.S. phone companies for controlling basic recordkeeping functions. Mitnick and others talked their way past a security guard and located the COSMOS computer room. They stole lists of computer passwords, operating manuals for the COSMOS system, and combinations to the door locks on nine Pacific Bell central offices. Mitnick later employed knowledge of phone systems and phone company operations to penetrate systems at Digital Equipment Corp. (DEC).
Since his release in January 2000, Mitnick has spoken about information security before Congress and at other public venues. He described social engineering as such a powerful tool that he “rarely had to resort to a technical attack.”3 As to technique, he stated, “I used to do a lot of improvising . . . I would try to learn their internal lingo and tidbits of information that only an employee would know.” In other words, by building up knowledge of the target, using a lot of information that is neither protected nor proprietary, it is possible to gain access to that which is both proprietary and protected. The power of incremental information leveraging is the equivalent of converting a foot in the door into an invitation to come inside.
Protection against incremental information leveraging and all other aspects of social engineering begins with employee awareness. Employees who maintain a healthy skepticism toward any and all requests for information provide a strong line of defense. Another powerful defense mechanism, highlighted by Mitnick, is the use of telephone recording messages, such as “This message may be monitored or recorded for training purposes and quality assurance.” An attacker who hears a message like this may think twice about proceeding with attempts to use voice calls to social engineer information from the target.
15.3 TECHNICAL PENETRATION TECHNIQUES. Technical penetration at- tacks may build on data obtained from social engineering, or they may be executed on a purely technical basis. Techniques used include eavesdropping, either by listening in on conversations or by trapping data during transmissions, and breaches of access controls (e.g., trying all possible passwords for a user ID or guessing at passwords). Weaknesses in the design and implementation of information systems, such as program bugs and lack of input validation, also may be exploited in technical attacks. Unfortu- nately, weaknesses of this nature abound in the realm of the Internet, even as more and more organizations increase their Internet connectivity, thus creating more and more potential penetration points.
15.3.1 Data Leakage: A Fundamental Problem. Unfortunately, for in- formation security (INFOSEC) specialists, it is impossible, even in theory, to prevent the unauthorized flow of information from a secured region into an unsecured region. The imperceptible transfer of data without authorization is known as data leakage. Technical means alone cannot suppress data leakage.
Consider a tightly secured operating system or security monitor that prevents con- fidential data from being copied into unsecured files. Workstations are diskless, there are no printers, employees do not take disks into or out of the secured facility, and there are strict restrictions on taking printouts out of the building. These mechanisms should suffice to prevent data leakage.
Not really.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 8 PENETRATING COMPUTER SYSTEMS AND NETWORKS
Anyone with a penchant for mnemonics or with a photographic memory could simply remember information and write it down after leaving the facility. And it is extremely difficult to prevent employees from writing notes on paper and concealing them in their clothing or personal possessions when they leave work. Unless employees are strip-searched, no guard can stop people with crib sheets full of confidential data from walking out of the building. Indeed, this is how Vasili Mitrokhin, head archivist of the KGB’s First Chief Directorate, perpetrated the largest breach of KGB security ever, by smuggling thousands of handwritten copies of secret documents out of the KGB headquarters in Moscow in his shoes, socks, and other garments.4
Another means of data leakage is steganography, hiding valuable information in plain sight among large quantities of unexceptional information. For example, a corrupt employee determined to send a confederate information about a chemical formula could encode text as numerical equivalents and print these values as, say, the fourth and fifth digits of a set of engineering figures. No one is likely to notice that these numbers contained anything special. Themore digitally inclined can use steganography software, freely available on the Internet, to hide data in image files.
The unauthorized transfer of information cannot be absolutely prevented because information can be communicated by anything that can fluctuate. Theoretically, one could transfer data to a confederate by changing the position of a window shade (slow but possible). Or one could send ones and zeroes by the direction of oscillation of a tape reel; or one could send coded information by the choice of music. Even if a building were completely sealed, it would still leak heat outward or transfer heat inward—and that would be enough to carry information. In practical terms, system managers can best meet the problem of data leakage by a combination of technical protection and effective management strategies.
It is also important to realize that a significant amount of data leakage occurs through innocuous intending communications from employees. It is common for employees to discuss small aspects of their jobs and work information without realizing the implica- tions and ability of others to collate this information into far more substantial amounts. This has become particularly prevalent with the modern advent of social media. Sig- nificant amounts of information about an organization and its internal workings can be derived from employee social media pages. Consequently, social media has become a rich source of data for attackers wishing to target an organization. This approach is particularly common among attackers that target an organization through its employees using techniques such as spear-phishing.
Data loss prevention (DLP), discussed briefly in Chapter 13 in thisHandbook, is now an established set of techniques, with numerous tools available to enforce restrictions on unauthorized data transfers to storage devices and external sites. Nonetheless, vigilance over human behavior and the effective configuration and real-time or at least frequent analysis of log records remain essential components of effective DLP.
15.3.2 Intercepting Communications. Criminal hackers and dishonest or disgruntled employees can glean access codes and other information useful to their system penetration efforts by monitoring communications. These might be between two workstations on a local area or wide area network, between a remote terminal and a host such as a mainframe, or between a client and a server on the Internet. Attackers can exploit various vulnerabilities of communications technologies. The shift to Trans- mission Control Protocol/Internet Protocol (TCP/IP)–based Internet communications over the last decade has brought many more communications streams into the target
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 9
range of would-be penetrators. For basic information about data communications, see Chapter 5 in this Handbook.
15.3.2.1 Wiretapping. Wiretapping consists of intercepting the data stream on a communications channel (even if that channel is not wire; e.g., fiber optic cable can also be tapped, as can wireless communications, although the latter sometimes are said to be sniffed rather than tapped).
15.3.2.2 Asynchronous Connections. Point-to-point data connections (e.g., using telephone modems or serial devices) have all but disappeared, but they are rela- tively easy to tap. Physical connection at any point on twisted pair or multiwire cables allows eavesdropping on conversations; if the line is being used for data communica- tions, a monitor is easily attached to display and record all information passing between a node and its host. Asynchronous lines in large installations often pass through patch panels, where taps may not be noticed by busy support staff, as they manage hundreds of legitimate connections. Such communications usually use phone lines for distances beyond a few hundred meters (or about 1,000 feet).
Wiretappers must use modems configured for the correct communications param- eters, including speed, parity, number of data bits, and number of stop bits, but these parameters are easy to find out by trial and error.
Countermeasures include:
� Physical shielding of cables and patch panels � Multiplexing data streams on the same wires � Encryption of data flowing between nodes and hosts
15.3.2.3 Synchronous Communications. Because synchronous modems are more complex than asynchronous models and because their bandwidths (maxi- mum transmission speeds) are higher, they are less susceptible to attack, but they are not risk-free.
15.3.2.4 Dial-up Phone Lines. Used for both data and voice communica- tions, dial-up lines supplied by local telephone companies and long-distance carriers are vulnerable to wiretapping. Law enforcement authorities and telephone company employees can install taps at central switching. Criminals can tap phone lines within a building at patch panels, within cabling manifolds running in dropped ceilings, below raised floors, or even in drywall. They also can tap at junction boxes where lines join the telephone company’s external cables.
The same countermeasures apply to phone lines as to asynchronous or synchronous data communications cables.
15.3.2.5 Leased Lines. Leased lines use the same technology as dial-up (switched) lines, except that the phone company supplies a fixed sequence of con- nections rather than random switching from one central station to another. There is nothing inherently more secure about a leased line than a switched line; on the con- trary, it is easier to tap a leased line at the central switching station because its path is fixed. However, leased lines usually carry high-volume transmissions. The higher the volume of multiplexed data, the more difficult it is for amateur hackers to disentangle the data streams and make sense of them. At the high end of leased line bandwidth
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 10 PENETRATING COMPUTER SYSTEMS AND NETWORKS
(e.g., carriers such as T1, T2, etc.), the cost of multiplexing equipment makes intercep- tion prohibitively expensive for all but professional or government wiretappers.
Data encryption provides the best defense against wiretapping on leased lines.
15.3.2.6 Long-Distance Transmissions. Dial-up and leased lines carry both short-haul and long-distance transmissions. The latter introduce additional points of vulnerability. Microwave relay towers carry much of the long-distance voice and data communications within a continent. The towers are spaced about 40 kilometers (25 miles) apart; signals spread out noticeably over such distances. Radio receivers at ground level can intercept the signals relayed through a nearby tower, and because microwaves travel in straight lines, rather than following the curvature of the earth, they eventually end up in space, where satellite receivers can collect them. The difficulty for the eavesdropper is that there may be thousands of such signals, including voice and data, at any tower. Sorting out the interesting ones is the challenge. However, given sufficient computing power, such sorting is possible, as is targeting of specific message streams. Spread-spectrum transmission, or frequency hopping, is an effective countermeasure.
15.3.2.7 Packet-Switching Networks. Packet-switching networks, includ- ing historical X.25 carriers such as Telenet, Tymnet, and Datapac, used packet assembler-disassemblers (PADs) to group data into packets addressed from a source to a destination. If data traveled over ordinary phone lines to reach the network, in- terception could occur anywhere along these segments of the communications link. However, once the data were broken up into packets (whether at the customer side or at the network side), wiretappers had a difficult time making sense of the data stream.
15.3.2.8 Internet Connections. TCP/IP connections are no harder to tap than any others, and they carry an ever-increasing array of data, from e-commerce traffic to television broadcasts and voice communications, the latter using Voice over Internet Protocol (VoIP). (See Chapter 34 in this Handbook.) Unless the data stream is en- crypted, there are no special impediments to wiretappers. Although the tapping of fiber optic cable requires more specialized equipment than the tapping of copper cables, it is possible.
15.3.2.9 LAN Packet Capture. Local area networks (LANs) are similar to packet-switching networks: both network protocols send information in discrete pack- ages, either over cables or radio waves. Each package has a header containing the address of its sender and of its intended recipient. Packets are transmitted to all nodes on a segment of a LAN. For more information about LANs, see Chapter 25 in this Handbook.
Normally a node is restricted to interpreting only those packets that are intended for it alone. However, it is possible to place devices in “promiscuous mode,” overriding this restriction. This can be done with software that surreptitiously converts a device, such as an end user workstation, into a listening device, capturing all packets that reach that node. Of course, network administrators can intentionally create a packet-capturing workstation for legitimate purposes, such as diagnosing network bottlenecks. It is also possible to connect specialized hardware called LAN monitors to the network, either with or without permission, for legitimate or illegitimate purposes. Sometimes called network sniffers, these devices and programs range from basic freeware to expensive commercial packages that can cost tens of thousands of dollars for a network with
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 11
hundreds of nodes. (The term sniffer, although in commonuse, is a registered trademark, as Sniffer R© , of Network General Corporation.)
The more sophisticated packet-sniffing programs allow the user to configure profiles for capture; for example, the operator can select packets passing between a host and a system manager’s workstation. Such programs allow an observer to view and record everything seen and done on a workstation, including logins or encryption keys sent to a server.
Packet sniffing poses a serious threat to confidentiality of data transmissions through LANs. Most sniffing programs do not announce their presence on the network. Al- though it may not be apparent to the casual observer that a workstation is performing sniffing, it is possible, as a countermeasure, to scan the network for sniffing devices. Stealthier packet-sniffing technology is constantly improving, and tight physical secu- rity may be the best overall deterrence.
LAN users concerned about confidentiality should use LAN protocols that provide end-to-end encryption of the data stream or third-party products to encrypt sensitive files before they are sent through the LAN. Routers that isolate segments of an LAN or WAN (wide area network) can help limit exposure to the threat of sniffers.
15.3.2.10 Optical Fiber. Although optical fibers were once thought to be se- cure against interception, new developments quickly abolished that hope. An attacker can strip an optical fiber of its outer casing and bend it into a hairpin with a radius of a few millimeters (1/8 inch); from the bend, enough light leaks out to duplicate the data stream. Bryan Betts, writing in PCWorld, quoted
Thomas Meier, the CEO of Swiss company Infoguard. . . . [who] demonstrated the technique on a fibre carrying a VOIP phone call over Gigabit Ethernet. A section of fibre from inside a junction box was looped into a photodetector called a bend coupler, and the call was recorded and then played back on a laptop.
“People claim optical fibre is harder to tap than copper, but the opposite is true—you don’t even have to break the insulation, as you would with copper,” Meier said. “You can read through the fibre’s cladding with as little as half a dB signal loss.”
He claimed that suitable bend couplers can be bought off the shelf—or from eBay—for a few hundred dollars, and connected to the extra fibre that is typically left coiled up in junctions boxes for future splicing needs.
He added that the risk is not imaginary or theoretical—optical taps have been found on police networks in the Netherlands and Germany, and the FBI investigated one discovered on Verizon’s network in the United States. Networks used by U.K. and French pharmaceutical companies have also been attacked, probably for industrial espionage, he said.5
Luckily, most optical trunk cables carry hundreds or thousands of fibers, making it almost impossible to locate any specific communications channel. (The same is not true of fiber cables used to deliver network connectivity to individual homes and offices.) Equipment for converting optical signals into usable data remains costly, discouraging its use by casual criminal hackers.
15.3.2.11 Wireless Communications. Cable-based communications have the advantage of restricting channel access to at least theoretically visible connec- tions. However, the rapid increase in wireless telecommunications in the last decade of the twentieth century and the first years of the twenty-first has routed increasing
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 12 PENETRATING COMPUTER SYSTEMS AND NETWORKS
amounts of information through a broadcast medium in which access—even unautho- rized access—may be invisible to users and system administrators.
15.3.2.12 Wireless Phones. Also referred to as cordless phones, conventional wireless phones broadcast their signals, and the traffic they carry can be detected from a distance. Older cordless phones were analog and susceptible to eavesdropping from such basic devices as walkie-talkies and baby monitors. Children sometimes walked around their suburban neighborhoods with a handset from such a phone turned on; once they walked far enough away from their home to lose the signal, any new dial tone belonged to a neighbor, who might be puzzled to discover a call to the Antipodes on the next phone bill. Today’s wireless phone models typically use a different set of frequencies, such as 2.4 gigahertz (GHz). These phones generally use frequency- hopping spread spectrum (FHSS) technology to make unauthorized use more difficult, and to impede eavesdropping. FHSSmeans the signals hop from frequency to frequency across the entire 2.4-GHz spectrum, making tapping their signals harder but by no means impossible. Wireless phones should not be used for confidential voice or data traffic unless encryption is enabled and activated. An added danger lies in hanging up a cordless phone during a conversation, since the cordless phone’s base continues to transmit until switched off.
15.3.2.13 Cellular (Mobile) Phones. Early analog cellular (mobile) phone systems had an expectation of privacy equivalent to that of shouting a message through a megaphone from a rooftop. Calls on such phones were easily intercepted using scanners purchased from local electronics stores. Although encryption is possible on the newer digital cell phones that are now widely used, the encryption is not always turned on due to the burden it imposes on the cell company switching equipment. Check with the carrier before assuming that cell calls are encrypted. Also, bear in mind that, although digital cell phone calls are harder to intercept than analog ones, there is a thriving black market in devices that make such interception possible.
As a rule, confidential information should never be conveyed through cellular phones without encrypting the line or the messages first.
Phil Zimmermann, creator of Pretty Good Privacy (PGP, later GPG) in the early 1990s, created a new service in 2012 called Silent Circle to provide encrypted telephony and Internet access to its subscribers.6
15.3.2.14 Wireless Networks. The increasingly popular means of network- ing computers to networks known asWiFi presents many opportunities for interception of communications. In this context, “wireless network” usually means a data network using the 802.11 standard, which comes in a variety of flavors, such as 802.11b, 802.11g (often collectively referred to as WiFi, which stands for “Wireless Fidelity” and is ac- tually a brand name owned by the trade group WiFi Alliance). Typically, this is the sort of local area network created by plugging a wireless access point into an Ethernet network and aWiFi card or adapter into each computer. Most notebook computers now come with a built-in WiFi adapter.
These WLANs, or wireless local area networks, are relatively cheap and easy to create since they do not require network cabling. That helps to explain why more than 200 million WiFi devices were sold in 2006 and more than half of all U.S. companies have been usingWLANs to some degree or other since 2002. But cheapWLANs come with hidden costs, namely security. EveryWLAN operates, by its very nature, in loose- lips mode. In a sense, the ease of use comes with ease of abuse. They all broadcast
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 13
their traffic into the air, whence it may be overheard by someone with the right set of ears, a legitimate user or a criminal hacker, someone looking for free bandwidth or a war driver. War driving, the practice of driving around town to find wireless access points, is a hobby to some people, and probably not illegal unless done with malicious intent—many notebook computers try to find wireless access points whenever turned on—but bear in mind that laws vary from one country to another. (Those contemplating war driving should check the legal status in their jurisdictions.)
To be a war driver, all that is needed is an old laptop, the right WiFi card, some free software (NetStumbler, e.g.), and an empty Pringles R© potato-chip can wired to the WiFi card as an external antenna to boost reception. (The Pringles R© can is optional, as is a global positioning system device to mark the location of WiFi access points.) If you drive around with this equipment activated, you will doubtless discover numerous access points in both residential and business districts. If the names of the access points are things like “Linksys” or “netgear,” this is an indication that the owner of the network has not changed the default service set identifier (SSID), which tends to be the brand of the wireless access point, broadcast for the world to see, unless the network owner turns off this feature. The name could also be a person, or place, or company, which helps war drivers figure out whose network they are picking up. (One of the authors detected SCHS near the offices of Sample County Health Services.) A program like NetStumbler will also tell you whether the network is using encryption. There has been a steady rise in the percentage of wireless networks using encryption, but it is far less than 10 percent. According to a survey conducted by AT&T in late 2007, one in six small businesses in America that use wireless technology has taken no precautions against wireless threats, and one-third of small businesses indicated that they were unconcerned about wireless data security.7
There is more about wireless network security in Chapter 33 in this Handbook, but the point is the relative ease with which networks can be tapped. This means WiFi, whether at home, in the office, or at a hot spot, represents a significant category of data leakage and thus a major avenue for systems penetration.
15.3.2.15 Van Eck Phreaking. This attack is named for Wim Van Eck, a Dutch electronics researcher who in 1985 proved to a number of banks that it was possible to read information from their cathode ray tubes (CRTs) at distances of almost a mile away, using relatively simple technology.8 Because many types of electronic equipment emit radio-frequency signals, receivers that capture these signals can be used to reconstruct keystrokes, video displays, and print streams. Using simple, inexpensive wide-band receivers, criminals can detect and use such emissions at distances of tens or hundreds of meters (yards).
Since radio-frequency signals leak easily through single-pane windows, PCs should never be placed in full view of ground-floor windows (and certainly not facing the windows!). Attenuators that tap the window at irregular intervals can be installed to defeat such leakage. A special double-pane window with inert gas between the panes also can lessen the amount of signals leakage.
Other countermeasures include special cladding of hardware, such as computers and printers, to attenuate broadcast signals. This protection often is referred to by the name of the classified government standard for protection of sensitive military systems, TEMPEST. Although TEMPEST was allegedly a classified code word to begin with, it is now sometimes expanded as Transient ElectroMagnetic Pulse Emission Stan- dard or Telecommunications Electronics Material Protected from Emanating Spurious Transmissions.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 14 PENETRATING COMPUTER SYSTEMS AND NETWORKS
TEMPEST-certified equipment costs many times more than the same equipment without TEMPEST cladding.9 A less expensive alternative is to use a special device that emits electromagnetic noise that masks meaningful signals. Yet another approach to protection against this threat is to locate systems within buildings, or rooms within buildings, that have been constructed to TEMPEST standards. There are federal reg- ulations concerning the methods of building sensitive compartmented information facilities (SCIFs), and the testing to obtain a TEMPEST rating is quite stringent. These measures include such things as cladding of all walls and ceilings, cladding of all electrical and network cabling, lead-lined doors, and the absence of any external windows.
15.3.2.16 Trapping Login Information. Criminals can capture identifica- tion and authentication codes by inserting Trojan horse programs into the login process on a server host and by usingmacro facilities to record keystrokes on a client node.More commonly today, however, specifically written malware is used to capture keystrokes and transmit them at intervals back to remote systems.
15.3.2.17 Host-Based Login Trojans. ATrojan horse is a program that looks useful but contains unauthorized, undocumented code for unauthorized functions. The name comes from Greek mythology, in which Odysseus (Ulysses in Latin), weary of the never-ending siege of Troy, sailed his ships out of sight as if he and his warriors were giving up, but left a giant wooden horse at the city gates. Entranced by this magnificent peace offering, the Trojans dragged the great horse into the city. During the Trojans’ wild celebrations that night, the soldiers Odysseus had secreted in the belly of the hollow horse let themselves out and opened the gates to their army. The Greeks slaughtered all the inhabitants of the city, and the Trojan War was over.
In February 1994, the Computer Emergency Response Team Coordination Center (CERT-CC) at Carnegie Mellon University in Pittsburgh issued a warning that criminal hackers had inserted Trojan horse login programs in hundreds of UNIX systems on the Internet. The Trojan captured the first 128 bytes of every login and wrote them to a log file that was later read by the criminals. This trick compromised about 10,000 login IDs.
Trojan code might be installed on a computer or terminal used by several people (e.g., on a mainframe terminal in the 1970s or in an Internet café today) so that when someone enters a user ID and password to logon, the system—controlled by the Trojan—displays a message such as “Invalid password, try again,” and the user does so. This time the login is accepted. The victim continues working, unaware that there is anything unusual going on. The Trojan, installed earlier, simulated the normal login procedure, displaying a semblance of the expected screen and dialog. Once the victim entered a password, the Trojan writes the authentication data to a file and then shows a misleading error message. The spoof program then terminates and the regular program is ready for login.
Such a case occurred in April 1993 in a suburb of Hartford, Connecticut. Shoppers noticed a new automated teller machine (ATM) in their mall. At first, the device seemed to work correctly, disbursing a few hundred dollars to bank card users on demand. It quickly changed to a more sinister mode. Users would insert their bank cards and respond as usual to the demand for their personal identification numbers (PIN). At this point, the new ATM would flash a message showing a malfunction and suggesting that the user try an adjacent bank machine. Most people thought nothing of it, but eventually someone realized that the ATM was not posting the usual “Out of Order”
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 15
indicator after these supposed errors. In addition, banks began receiving complaints of a rash of bank card frauds in the immediate area. Investigators discovered that the ATM had no connection to any known bank—that it had been purchased used, along with equipment for manufacturing bank cards. The ATM was a spoof; it was merely collecting the user ID and PIN of every victim for later pickup by the criminals who had installed it without permission in the mall. The criminals were caught after having stolen about $100,000 over a four-week period using fraudulent bank cards.
Chapter 20 in thisHandbook includes more details about Trojans and other low-tech attacks.
15.3.2.18 Keystroke Logging. Another threat to identification and authen- tication codes is the ability to record keystrokes for later playback or editing. Most word processing programs provide macro facilities, so named because of their ability to store and output multiple keystrokes, such as the typing of boilerplate text, with one keystroke. More sophisticated terminate-and-stay-resident (TSR) programs can record sequences of commands, and are sometimes used to demonstrate software or to automate quality assurance tests. This technology can also be used to lay in wait on a workstation and record everything the user does with the mouse and types with the keyboard; such programs are sometimes called keystroke loggers. Later, the criminal can harvest the records and pick out the login codes and other valuable information.
There are also hardware implementations of keystroke logging. One is a small device inserted between the keyboard and the computer, capturing what is typed and holding it in nonvolatile memory until it can be retrieved. At the time of this writing in May 2013, such devices were widely available through Internet sales for about US$40.
By far the most common form of keystroke logging is done by hooking the operating system mechanisms for providing keyboard functionality. This is done in software. There are numerous specific technical techniques to accomplish the hooking process depending on the operating system and hardware. Sometimes the software used to accomplish the keystroke logging is stand-alone, but often it is part of a larger piece of software that also provides C2 (command and control) capabilities. It is also quite common for the keystroke logging functionality to be part of a rootkit in order to avoid detection.
It is possible to defeat the attempted reuse and abuse of login credentials captured by any of these methods by switching to one-time passwords generated by micropro- cessors. One-time passwords are discussed in Chapter 28 of this Handbook. However, both key loggers and Trojans can be deployed to gain unauthorized access to data without resorting to the reuse of passwords.
15.3.3 Breaching Access Controls. Criminals and spies use two broad cate- gories of technical attacks to deduce access phone numbers, user IDs, and passwords: brute-force attacks and intelligent guesswork. In addition, there are ways to manipulate people into revealing their access codes; these techniques are discussed in the section on social engineering.
15.3.3.1 Brute-Force Attacks. Brute-force attacks consist of using powerful computers to try all possible codes to locate the correct ones. Brute force is applied to locating modems, network access points, vulnerable Internet servers, user IDs, and passwords.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 16 PENETRATING COMPUTER SYSTEMS AND NETWORKS
15.3.3.2 Demon (War) Dialing. Despite the wholesale shift of data commu- nications to TCP/IP networks and the Internet, modems on dial-up phone lines remain a common, and sometimes forgotten, means of external access to a system. The tele- phone numbers of any modems connected to hosts or servers or intelligent network peripherals, such as high-end laser printers, are sensitive and should not be posted or broadcast.
Demon dialers are programs that can try every phone number in a numerical range and record whether there is a voice response, a fax line, a modem carrier, or no answer. When phones ring all over an office in numerical order, one at a time, and when there is no one on the line if a phone is picked up, it is undoubtedly the work of someone using a demon dialer. Of course, good demon dialing software accesses the numbers in the target range nonsequentially.
During the heyday of faxmachines, some youngsters were reported to have “farmed” entire telephone exchanges during the night, then to have sold the fax numbers for $1 dollar per number to unscrupulous junk-fax services that sold advertisers access to them.
15.3.3.3 Exhaustive Search. The same approach as demon dialing can find user IDs and passwords after a connection has been made. The attacker uses a program that cycles systematically through all possible user IDs and passwords and records successful attempts. The time required for this attack depends on two factors:
1. The keyspace for the login codes 2. The maximum allowable speed for trying logins
In today’s technical environment, any inexpensive computer can generate login codes far faster than hosts permit login attempts. Processor speed is no longer a rate- limiting factor. Note that this type of attempt to “guess” passwords is different from password cracking, described elsewhere, which operates on captured or stolen copies of encrypted password files.
15.3.3.4 Keyspace. As discussed in Chapter 7 in this Handbook, the keyspace for a code is the maximum number of possible strings that meet the rules of the login restrictions. For example, if user passwords consist of exactly six uppercase or lowercase letters or numbers and the passwords are case-sensitive (i.e., uppercase letters are distinguished from lowercase letters), the total number of possible combinations for such passwords is calculated in this way:
� There are 10 digits and 52 upper- or lowercase letters (in the English alphabet) = 62 possible codes for any of six positions.
� If there are no restrictions on repetition, a string of n characters to be taken from a list of r possibilities for each position will generate rn possible combinations.
� Thus, in our example, there are 626 possible sequences of 62 codes taken in groups of six = 56,800,235,584 (more than 56 billion) possible login codes.
If there are restrictions, the keyspace will be reduced accordingly. For example, if the first character of a password of length six must be an uppercase letter instead of being any letter or number, there are only 26 possibilities for that position instead 62,
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 17
thus reducing the total keyspace to 26 × 625 = 23,819,453,632 (more than 23 billion) possibilities.
15.3.3.5 Rainbow Tables. Cryptanalysts (including criminal cryptanalysts) can generate all possible one-way hashes for the keyspace of any given password rule; brute-force cracking using the tables can thus be accelerated. There are even Websites distributing such tables freely.10
15.3.3.6 Login Speed. Generating login codes is not hard. The greatest barrier to brute-force login attacks is interruption in the login whenever the host detects an error. Most operating systems and security monitors allow the administrator to define two types of login delays following errors:
1. A usually brief delay after each failed attempt to enter a correct password 2. A usually long delay after several failed login attempts
Suppose each wrong password entered causes a 1/10th-second delay before the next password can be entered; then for our example involving six repeatable uppercase or lowercase letters or numbers, it would take 5,680,023,558 seconds = 1,577,784 hours ≈ 180 years to try every possibility.
Suppose, in addition, that after every fifth failed login attempt, the system were to inactivate the user ID or the modem port for three minutes. Such interference would stretch the theoretical time for a brute-force exhaustive attack to around 650 years.
Should the security manager completely inactivate the ID if it is under attack? If the ID is inactivated until the user calls in for help, user IDs become vulnerable to inactivation by malicious hackers. Attackers need merely provide a bad password several times in a row and the unsuspecting legitimate user will be locked out of the system until further notice. A widespread attack on multiple user IDs could make the system unavailable to most users. Such a result would be a denial-of-service attack (see Chapter 18 in this Handbook).
Should the port be inactivated? If there are only a few ports, shutting them down will make the system unavailable to legitimate users. This drastic response may be inappropriate—indeed, it may satisfy the intentions of criminal hackers. A short delay, perhaps a few minutes, would likely be sufficient to discourage brute-force attacks.
In all of these examples, the illustrations have been based on exhaustive attacks (i.e., trying every possibility). However, if passwords or other codes are chosen randomly, the valid codes will be uniformly distributed throughout the keyspace. On average, then, according to a principle of statistics called the Central Limit Theorem, brute-force searches will have to search half the keyspace. For large keyspaces, the difference between a very long time and half of a very long time will be negligible in practice (e.g., 325 years is not significantly different from 650 years if everyone interested will be dead before the code is cracked).
15.3.3.7 Scavenging Random Access Memory. Not all attacks come from outside agents. Criminals with physical access to workstations, malicious soft- ware, or authorized users who can use privileged utilities to read main memory, can scavenge memory areas for confidential information such as login IDs and passwords.
On a workstation using a terminal emulator to work with a host, ending a session does not necessarily unload the emulator. Many emulators have a configurable screen
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 18 PENETRATING COMPUTER SYSTEMS AND NETWORKS
display buffer, sometimes thousands of lines long. After an authorized user logs off and leaves a terminal, a scavenger can read back many pages of activity, sometimes including confidential information or even login codes. Passwords, however, usually are invisible and therefore not at risk.
If a workstation is part of a client/server system, an application program control- ling access may leave residues in random access memory (RAM). A RAM editor, easily available as part of utility packages, can capture and decode such areas as file buffers or input/output (I/O) buffers for communications ports. However, rebooting the workstation after communication is over prevents RAM scavenging by reinitializing memory.
15.3.3.8 Scavenging Cache Files. The same principle can be applied to the various cache and swap files created by the operating system. Cache files are used to keep frequently used data readily available to applications. Swap files store data and code that is moved out of memory onto disk when memory is full. Some operating systems also create hibernation files, writing memory to disk just prior to powering down, and thus enabling a quick resumption of work when the system is powered up. Operating systems may also provide auto-saved recovery files that allow restoration of data after a system error. All of these can be mined for system credentials as well as other valuable data.
15.3.3.9 Scavenging Web History Files. A more recent variation on this scavenging approach is to examine files created by Web browsers. These sometimes contain not only the pages viewed by a user but also the credentials entered to access those pages.
15.3.3.10 Recovering Stored Passwords. Many applications store user passwords locally. Most applications attempt to secure these passwords, unfortunately they are seldom stored with proper encryption methods. It has become common for malicious software to recover these stored passwords and transmit them to remote servers for collection by attackers.
15.3.3.11 Intelligent Guesswork. Users rarely choose random passwords. Much more frequently, passwords are chosen from a subset of all possible strings. Instead of blindly batting at all possible sequences in a keyspace, an attacker can try to reduce the effective keyspace by guessing at more likely selections. Likely selections include canonical passwords, bad passwords, and words selected from a dictionary.
Hardware and software often come from the factory, or out of the box, with user IDs and passwords that are the same for all systems and users.
For example, wireless access points and routers have default user IDs when they ship from the factory. Naturally, these user IDs are set up with the same password. (For example, “admin” on Linksys wireless router devices.) Such systems always include instructions to change the passwords, but, too often, administrators and users neglect to do so. Criminals are familiar with factory presets—most of which are readily discoverable via Google—and exploit them to penetrate systems. The simple routine of changing all canonical passwords prevents hackers from gaining easy access to systems and software.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 19
15.3.3.12 Stealing. Any element of a computer system has potential value to a thief. Therefore every element including hardware, software, media, files, documen- tation, and printouts must be safeguarded.
15.3.3.13 Data Scavenging. Criminal hackers have few scruples about using other people’s property when they enter computer systems; they have none at all concerning using other people’s trash. The term data scavenging describes the process that acquires information from throw-away sources. Perhaps the most widely known is Dumpster R© diving, sorting through whatever an organization discards. Hard-copy printouts, CD-ROMs, tapes, and other assorted data-bearing media often end up in trash containers where they are easily accessible to Dumpster R© divers after hours. In some areas, if one visits an office or industrial park at night, one can see half a dozen people rummaging about, sometimes headfirst inDumpsters R© . Criminal hackers use the information thoughtlessly discarded by naı̈ve office workers as a source of procedures, vocabulary, and proper names that can help them impersonate employees over the phone or even in person. The classic example is a discarded internal phone directory, which can provide a social engineer with valuable data to use when making calls to employees. An employee who hesitates to comply with an attacker’s bogus request for information over the phone may well be persuaded if the attacker says something like “I understand your hesitation; if it makes you feel more comfortable you can call me back at extension 2645.” If 2645 is a legitimate internal extension, the caller gains considerable credence. Of course, the properly trained employee will hang up andmake the call to 2645 rather than take the easy option and say, “I guess that’s okay then, here is the information you wanted.”
Some printouts contain confidential information that can lead to extortion or system penetration. For example, a thief who steals a list of personally identifiable information about patients with HIV infection could torment the victims and extort money. Every piece of paper, or other media to be discarded, should be evaluated for confidentiality. Unless the information is worthless to everyone, employees should shred paper before disposal or arrange to send paper to a bonded service for destruction. The same applies to CD-ROMs and other media.
15.3.3.14 Discarded Magnetic and Optical Media. Discarded paper poses a threat; discarded magnetic and optical media are a disaster. Many organi- zations fail to teach employees that the normal commands used to delete files do not remove all trace of them. Either through the use of utility programs or the operating system itself, the original file clusters can be located and any part of the original file that has not yet been overwritten can be regenerated.
Backup tapes, CDs, and DVDs may contain valuable information about the system security structure. For example, in the 1970s and 1980s, systembackups on one brand of minicomputer contained the entire directory, complete with every user ID and password in the clear on the first tape. Using a simple file copy utility, any user could read these data.
To destroy information on magnetic media, users either must overwrite the medium several times with random data or physically destroy the medium. Degaussers are inad- equate unless they meet military specifications, but such units typically cost thousands of dollars.
The problem of readable data is especially troublesome on discarded disk drives or on broken hard disk drives that have been repaired or that are subject to specialized forensic data recovery. Users have received operational, data-laden disk drives as
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 20 PENETRATING COMPUTER SYSTEMS AND NETWORKS
replacements for their own broken units. Sometimes the replacement disks have not even been reformatted; they contain entire directories of correspondence, customer databases, and proprietary software. Because it is by definition impossible to overwrite data on a defective disk drive, military security specialists routinely destroy defective hard disks using oxyacetylene torches or purpose-built grinders that reduce hard drives into small chunks.
For more information about secure disposal of magnetic and optical data storage media, see Chapter 57 in this Handbook.
15.3.4 Spying. Some techniques used by criminal hackers seem to have been lifted directly from spy novels. For example, laser interferometry can reconstitute vibration patterns from reflected infrared laser beams bounced off windows. Users of such equipment can hear and record conversations in rooms that have external windows that vibrate according to the sounds in the room. For more antispy measures related to physical and facilities security, see Chapters 22 and 23 in this Handbook.
Hackers surreptitiously steal people’s access codes by watching their fingers as they punch in secret sequences. When pay phones were prevalent, shoulder surfers would capture telephone calling-card codes, which they sell to organized crime rings. Codes can be stolen by peering over the shoulders of neighboring callers, or by using binoculars, telescopes, and video cameras to track the buttons pressed by their victims.
Shoulder surfing can occur within installations as well. For example, most users of punch-key locks pay no attention to the visibility of their fingers.Whenever punching in a code, users should guard against observation by unauthorized people. In public places, users should stand up close to the keypad. In fixed installations, facilities managers should cover keypads with opaque sleeves allowing unimpeded access but concealing details of the access codes.
Criminals are adept at surfing both wired and wireless network connections, either by cruising around town with a war-driving setup or hanging out in a target-rich environment such as an airport, train station, coffee shop, or hotel lobby. There is more about wireless hacking in Chapter 33 in this Handbook.
One particular type of wired connection that should be used with care is the broad- band guest-room connection offered by many hotels. Too often, these are set up with- out proper security measures, enabling a curious or criminally inclined guest to locate machines belonging to other guests (sometimes bymerely clicking the Network Neigh- borhood icon in Windows Explorer). Employees should be instructed not to plug their company laptops into such connections unless they have a properly configured firewall in place and turned on and are using a virtual private network (VPN) to access corporate systems (see Chapter 32 in this Handbook). Even some of the most expensive upscale hotels have been found to suffer from this problem, as illustrated in Exhibit 15.1.
15.3.5 Penetration Testing, Toolkits, and Techniques. Verifying and im- proving the security of systems by attempting to penetrate them is a well-established practice among security professionals and system administrators. However, although some were practicing this technique earlier, it was not openly discussed prior to 1993. That year, Dan Farmer and Wietse Venema released the pioneering paper entitled “Improving the Security of Your Site by Breaking into It.”11 This paper advanced the notion of assessing system security by examining a system through the eyes of a potential intruder. Farmer and Venema showed that scanning for seemingly benign network services can reveal serious weaknesses in any system. Prior to the publication of this important paper, many system administrators were unaware of the extent of vulnerabilities affecting their systems.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 21
EXHIBIT 15.1 Poorly Configured Hotel Room Internet Connectivity
Farmer and Venema then released a network-testing program called SATAN (Se- curity Analysis Tool for Auditing Networks). Security professionals and system ad- ministrators both lauded and were angered by the program. Some system adminis- trators cheered the availability of an all-in-one tool that revealed security holes but did not exploit them. Others questioned the authors’ motives in releasing a free and readily available tool that hackers could use to attack networks. While the debate raged on, system administrators and hackers alike began using SATAN to interrogate networks.
15.3.5.1 Common Tools. Since that time, hundreds of penetration toolkits have appeared; they are commonly referred to as scanners. Today one can find innumerable freeware tools or invest in one of the commercial tools. Scanners vary in complexity and reliability. However, a majority of the tools employ the same basic functions to test a network: query ports on the target machines and record the response or lack of response.
Used in the proper manner, these tools can be effective in discovering and recording vast amounts of data about a network of computer systems and revealing security holes in the network. Many scanner packages also include packet-sniffing applications, described earlier. Administrators can use this information to reduce the number of systems that can be compromised.
A wide variety of basic network tools may be used in any penetration test. These tools may include mundane programs, such as PING, FINGER, TRACEROUTE, and NSLOOKUP. However, most serious penetration tools make use of an automated vulnerability analysis tool consisting of a series of port queries and a database of known vulnerabilities. Some tools also attempt to exploit identified vulnerabilities in order to eliminate false positives. Once the vulnerabilities have been found, it is
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 22 PENETRATING COMPUTER SYSTEMS AND NETWORKS
remarkably easy to obtain “exploits” or programs with which to launch an attack against the susceptible machines. All the tools make use of the basic operations of the TCP suite of protocols. Although these protocolswill operate on different port numbers, they all share a common structure of a three-way handshake. All TCP protocols look for a connection attempt (connect), a synchronization and acknowledgment exchange (SYN/ACK), various conditions (FLAGS), and a close port request (FIN). Therefore, the operation of port scanners is quite similar. They attempt to find open, or listening, ports on amachine, ask for a connection, and then log the results to a file to be compared to the internal database. The scanner will display the results of the scans by listing the open ports and the services that appear to be running. At this point the various programs differ. Some attempt an in-depth analysis of the possible security holes associated with the ports and services, along with the appropriate security measures to secure them. The more malicious scanners also include automated scripts for exploitation of the vulnerabilities thus revealed.
Of the freeware tools, Nessus, Netcat, and nmap are probably the best known, although there always seems to be a new flavor of the month among both hackers and system administrators. SATAN is still available, as are its spin-offs, SAINT and SARA. A fair amount of skill is required to use these tools as they are fairly sophisticated, and some of the scans can overload a system and cause it to hang or crash.
15.3.5.2 Common Scans. As previously mentioned, most of the scan- ners/sniffers available will run through the same basic routines in order to develop a picture of a machine as a whole. The purpose is to determine what is running on the machine and what its role is in the network. The next sections describe most basic scans and their results.
15.3.5.2.1 TCP Connect. This is the most basic form of TCP scanning. This system call is provided by the operating system. If the port is listening, the attempt at a connection will proceed. This scan does not require root or supervisor privileges. However, this scan is easily detectable, as many connection and termination requests will be shown in the host’s system logs.
15.3.5.2.2 TCP SYN. This scan does not open a full connection and is sometimes referred to as a half-open scan because a full handshake never completes. A SYN scan starts by sending a SYN packet. Any open ports should respond with an SYN|ACK. However, the scanner sends an RST (reset) instead of an ACK, which terminates the connection. Fewer systems log this type of scan. Ports that are closed will respond to the initial SYN with an RST instead of an ACK, which reveals that the port is closed.
15.3.5.2.3 Stealth Scans. Also referred to as Stealth FIN, Xmas Tree, or Null scans, the stealth scan is used because some firewalls and intrusion detection systems watch for SYNs to restricted ports. The stealth scan attempts to bypass these systems without creating a log of the attempt. The scan is based on the fact that closed ports should respond to a request with an RST and open ports should just drop the packet without logging the attempt.
15.3.5.2.4 UDP Scans. There are many popular User Datagram Protocol (UDP) holes to exploit, such as an rpcbind hole or a Trojan program, such as cDc Back Orifice, which installs itself on a UDP port. The scanner will send a 0-byte UDP packet to each port. If the host returns a “port unreachable” message, that port is considered closed.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 23
This method can be time consuming because most UNIX hosts limit the rate of Internet Control Message Protocol (ICMP) errors. Some scanners detect the allowable rate on UNIX systems and slow the scan down, so as not to flood the target with messages.
15.3.5.2.5 IP Protocol Scans. This method is used to determine which Internet protocols are supported on a host. Raw IP packets without any protocol header are sent to each specified protocol on the target machine. If an ICMP unreachable message is received, then the protocol is not in use. Otherwise, it assumed to be open. Some hosts (AIX, HP-UX, Digital UNIX) and firewalls may not send protocol unreachable message, so all protocols appear to be open.
15.3.5.2.6 ACK Scan. This advanced method usually is used to map out firewall rule-sets. In particular, it can help determine whether a firewall is stateful or just a simple packet filter that blocks incoming SYN packets. This scan type sends an ACK packet with random-looking acknowledgment/sequence numbers to the ports specified. If an RST comes back, the port is classified as “unfiltered.” If nothing comes back, or if an ICMP unreachable is returned, the port is classified as “filtered.”
15.3.5.2.7 RPC Scan. This method takes all the TCP/UDP ports found open and then floods them with SunRPC program NULL commands in an attempt to determine whether they are RPC ports and, if so, what program and version number they return.
15.3.5.2.8 FTP Bounce. This scan looks like it is an FTP proxy server within the network (or trusted domain). It could eventually connect to an FTP server behind a firewall. Once the FTP server has been found, scanning of ports normally blocked from the outside can be made from the internal FTP server. Of course, reading and writing to directories can be checked from this server as well.
15.3.5.2.9 Ping Sweeps. This scan uses Ping (ICMP echo request) to find hosts that are up. It can also look for subnet-directed broadcast addresses on the network. These are IP addresses that can be reached externally. Ping sweeps often are used to try to “map” the network as a whole.
15.3.5.2.10 Operating System Fingerprinting. Asmany security holes are depen- dent on the operating system of the host, this scan attempts to identify which operating system is running, based on a number of suppositions. It uses various techniques to de- tect subtleties in the underlying operating system (OS) network stack of the computers being scanned. The data gathered are used to create a “fingerprint” that is compared to the scanner’s database of known fingerprints. If an unknown fingerprint is found, attackers can check Websites and newsgroups where information about fingerprints is freely traded, to discover what a particular OS might be. Once the OS has been identified, it is quite easy to find exploits by simply using a search engine on the Web. OS fingerprinting is unnecessary if the OS can be discovered by reading the banners. For example, if one was to telnet to a machine, the response could be:
badgny∼> telnet abcd.efg.com Trying 163.143.103.12 … Connected to abcd.efg.com Escape character is ’ˆ]’. HP-UX hpux B.10.01 A 9000/715 (ttyp2) login:
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 24 PENETRATING COMPUTER SYSTEMS AND NETWORKS
The banner, which was included in the default configuration, simply indicates that the OS is HP-UX. A good system administrator will turn off the banners on all services that have them.
15.3.5.2.11 Reverse Ident Scanning. This scan usually is used to see if a Web server on the network is running as root. If the identd daemon is running on the target machine, then a TCP Ident request will cause the daemon to return the username that “owns” the process. Therefore, if this request is sent to port 80 (hex), and the return user is root, then that server can be used for an attack on the system. This scan requires a full TCP connection to the port in question before it will return the username.
15.3.5.2.12 Scanning One’s Own Port Configuration. Steve Gibson of Gibson Research Corporation makes available a free port scanner that identifies open ports among the first 1056 TCP ports on any system within less than a minute.12 Any open port can then be controlled using an appropriate firewall setting. Ideally, all ports on workstations are nonresponsive to pings.
15.3.5.3 Basic Exploits. Using the results of a scanning program, the next logical step for hackers would be to try to exploit the apparent weaknesses in the system. Hackers seek to compromise a machine on the network by getting it to let them run programs or processes at will, at the root level. Once hackers “own” that machine, the possibilities are endless. Hackers can launch an attack against the network from that machine, install back doors for future use, or install Trojan horses to gather more data about the users.
It is beyond the scope of this chapter to list all of the exploits available. There are simply too many, with new ones appearing every day. The number of Websites devoted to hacking is enormous. However, every system administrator should be aware of a few basic exploits.
15.3.5.3.1 Buffer Overflow. Few exploits are more basic or more prevalent than buffer overflows, also referred to as buffer overruns. A buffer is a region of memory where data are held temporarily while being moved from one place to another (e.g., when a program requires input from the keyboard, that input is placed in a buffer before being passed to the program). Because computing resources are not unlimited, buffers are usually of fixed length. Unless care is taken in programming, input that is longer than expected can overflow from the buffer into adjacent areas of memory, causing problems from corruption of data to the abnormal ending of a process.
The possible effects of buffer overflows are numerous. A buffer may overflow into an adjoining buffer and corrupt it. The overflow condition alone may be enough to crash the process. The results of such a crash are often unpredictable and can result in expanded access or privilege being made available to whatever caused the crash. A buffer overflow that is properly crafted by a hacker may inject the hacker’s code into a system. Buffer overflows occur in applications as well as basic protocols. Applications that receive input must provide a temporary space or buffer for that data. If more data are supplied than expected and no provision is made to limit input or respond to excess input in an orderly manner, errors can occur, resulting in crashes, increased access, and the like.
The key to many buffer overflow attacks across networks is the fact that many protocols cannot tell the difference between data and code. Hackers try to get the last
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 25
bit of data written to the overflow area to be a command or a bit of code that will execute a command, as if the response to the input request “Name?” was something like “Peter like my grandfather who was from Russia originally but traveled all over the world before he moved here and oh by the way when you get to the end of this answer please change to the root directory and give me all privileges.”
Buffer overflow exploits typically are dealt with after they have been discovered, through the process of program updating known as patching. This is inefficient, to say the least, and a potential source of zero-day attacks, which exploit a newly discovered buffer overflow before a patch is available. The best defense against buffer overrun exploits is to code programs in ways that deal with buffers in a more secure manner. Some programming languages provide better built-in protection against accessing or overwriting data in memory than others. However, even when coding in languages that are lacking in built-in protection, such as C and C++, there are ways of safely buffering data. Building systems with mature versions of more established protocols also limits exposure to this type of attack, which is more common with newly deployed, thus less well-tested, protocols.
Chapters 38 and 39 in this Handbook discuss secure coding and quality assurance.
15.3.5.3.2 Password Cracking. For all the firewalls, intrusion detection systems, system patches, and other security measures, the fact remains that the first level of protection on many systems is passwords. Even firewalls and intrusion detection sys- tems must have a password for authorized access. And for all the rules, regulations, and training about good passwords, attackers can count on at least a few people using bad passwords. Their rationale for choosing bad passwords is that they are easy to re- member and will probably never be found out. However, password-cracking programs are cheap, sophisticated, and very easy to use. Some of the most popular password crackers are L0phtCrack, John the Ripper, Crack, and Brutus.
These programs rely on two features of network password systems:
1. Encryption used to scramble passwords on a network is easily defeated. 2. Encrypted passwords on a network are relatively easy to obtain. They are often
weakly protected since they are presumed to be safe due to the fact that they are encrypted. Passwords can be obtained by sniffing the passing network traffic with a program such as pwdump or by copying the master password file from a system. Since one password is all it takes to enter a system as a legitimate user, sniffing the traffic is the easiest method of obtaining a relatively good list of passwords.
Once the list has been obtained, it is saved as a simple text file, and the password- cracking program begins checking the encrypted words in the file against a dictionary of words that have previously been encrypted with the same algorithm. Whenever a match is found between an encrypted string in the file and a word in the encrypted dictionary, the cracking program displays and records the plaintext of the encrypted dictionary word. Thus the password is revealed.
In addition to checking ordinary dictionary words, some password crackers check for both uppercase and lowercase letters, numbers before and after a word, and num- bers used in lieu of vowels within a word. The speed at which these programs op- erate, even on a basic desktop or laptop computer, is impressive, and it is entirely
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 26 PENETRATING COMPUTER SYSTEMS AND NETWORKS
possible to obtain cracked passwords within seconds. Indeed, a useful security aware- ness exercise is to demonstrate such a program to employees: The first passwords to be cracked will be the weakest ones, and that can serve as a warning to users who choose such words.
A good security officer will ensure that passwords on a network are checked reg- ularly with a password cracker or by implementing one of the many strong-password enforcers. Password enforcers augment the password program by comparing the pass- words chosen by the user to the rules set by the enforcer.
A simple online tool from Steve Gibson’s GRC allows one to calculate the keyspace and estimate cracking time for sample passwords.13 Users should not enter their actual password but only one using the same rules; for example, if one’s actual password were Dk3∗(4n$p2, one could enter Eh5&%9g#t8 to arrive at exactly the same analysis. In the example presented here, the calculations result in a keyspace of 6.05 × 1019 with a cracking time of 1 week if a massively parallel array of processors supported 1015 guesses per second. The password evanescent porridge would take the same processors 14.32 billion centuries to include by brute-force cracking of the 4.50 × 1033 keyspace.
15.3.5.3.3 Rootkits. Rootkits are one of the many tools available to hackers to disguise the fact that a machine has been “rooted.” A rootkit is not used to crack into a system but rather to ensure that a cracked system remains available to the intruder. Rootkits are comprised of a suite of utilities that are installed on the victim machine. The utilities start by modifying the most basic and commonly used programs so that suspicious activity is cloaked. For example, a rootkit often changes simple commands such as “ls” (list files). Amodified “ls” from a rootkit will not display files or directories that the intruder wants to keep hidden.
Rootkits are extremely difficult to discover since the commands and programs appear to work as before. Often a rootkit is found because something did not “feel right” to the system administrator. Since rootkits vary greatly in the programs they change, one cannot tell which programs have been changed and which have not. Without a cryptographically secure signature of every system binary, an administrator cannot be certain to have found the entire rootkit.
Some of the common utilities included in a rootkit are:
� Trojan horse utilities � Back doors that allow the hacker to enter the system at will � Log-wiping utilities that erase the attacker’s access record from system log files � Packet sniffers that capture network traffic for the attacker
15.3.5.3.4 Trojan Code. As described earlier in the context of compromised login procedures, Trojan code is something other than it appears to be. In this case, the Trojans are the changed programs in a rootkit that allow an intruder’s tracks to be hidden or allow the program to gather more information as it sits silently in the background. Local programs that are Trojaned often include “chfn,” “chsh,” “login,” and “passwd.” In each case, if the rootkit password is entered in the appropriate place, a root shell is spawned.
15.3.5.3.5 Back Doors. Back door utilities often are tied to programs that have been Trojaned. They are used to gain entry to a systemwhen other methods fail. Even if
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 27
a system administrator has discovered an intrusion and has changed all the usernames and passwords, there is a good chance that he or she does not know that the back doors exist. To use the back door, the hacker needs only to know the correct port to connect to the compromised machine and to enter a password or command where one is not usually entered.
For example, inetd, the network super daemon, is often Trojaned. The daemon will listen on an unusual port (rfe, port 5002 by default in Rootkit IV for Linux). If the correct password is given after connection, a root shell is spawned and bound to the port.
The function rshd can be similarly Trojaned so that a root shell is spawned when the rootkit password is given as the username and thus rsh [hostname] –l [rootkit password] will obtain access to the compromised machine.
15.3.6 Penetration via Websites. A vast new network territory opened up in the final decade of the twentieth century, partially devoted to commerce and largely driven by attempts tomakemoney from a technology that originally had been developed for military and academic purposes. The relentless growth of this network surpassed 145 million registered domains at the time of writing in May 2013 as reported by the Whois Source (www.whois.sc/internet-statistics), one of the most reliable sources of statistics about the Internet.
Worldwide Internet penetration, measured as the number of Internet users as a percentage of total population, was over one third by June 2012, with North America, surpassing 75 percent.14 Asia had almost 4 billion users at that time. Not surprisingly, with so many machines in one network and over 2.4 billion users (twice what was reported in the 2009 Fifth Edition of this Handbook), this new territory is the primary playground for hackers, from the merely curious to the seriously criminal. The Web presents a target-rich environment for people seeking unauthorized access to other people’s information systems. There are several reasons for this; chief among them is the fact that many organizations, both commercial and governmental—including the military—have external, public Websites that are connected, in some way, to internal, private networks. This connection provides a system penetration path that can be exploited in many different ways, as outlined in this section.
For more detailed analysis of Website security, see Chapter 21 in this Handbook.
15.3.6.1 Web System Architecture. Standard practice when placing a com- mercial Website on the Internet is to screen it from hostile activity, typically using a router with access-control lists (ACLs) or a firewall, or both. However, unless the Web site is of the basic, “brochure-ware” kind, which simply exists to provide information on a read-only basis, the site has to allow for user input of data. Input is required for something as simple as a guest book entry or an information request form; more complex applications such as online shopping have more complex input requirements.
A typical method of processing input is the Common Gateway Interface (CGI). This is a standard way for a Web server to pass user input to an application program and to receive a response, which can then be forwarded to the user. For example, when a user fills out a form on a Web page and submits it, the Web server typically passes the form information to a small application. This application processes the data and may send back a confirmation message. This method is named CGI, and it forms part of the Hypertext Transfer Protocol (HTTP). Because it is a consistent method, applications written to employ it can be used regardless of the operating system of the server on which it is deployed. Further adding to the popularity of CGI is the fact that it works
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 28 PENETRATING COMPUTER SYSTEMS AND NETWORKS
with a number of different languages including C, C++, Java, and PERL. The term “CGI” is used generically for Web server code written in any of these languages.
Any system that receives input must provide a path within the system through which that input can flow. This is referred to as an “allowed path.” The necessity of allowed paths, combined with the ability to exploit them for penetration attacks, led the system security expert David Brussin (author of Chapter 26 in thisHandbook) to coin the term “allowed path vulnerabilities” for this class of vulnerability. The two leading categories of exploits that employ allowed paths are input validation exploits, which are akin to buffer overflow exploits and often employed to abuse CGIs, and file system exploits, which abuse the Web server operating system and services running on the server.
Of course, there are other ways to abuse Websites as well. Denial-of-service attacks can be used to inhibit legitimate access and thus compromise availability. (Chapter 18 in this Handbook covers DoS attacks.) Not every attack is aimed at further penetration of systems; the Web pages themselves may be the target of attack, as in a defacement, an unauthorized change toWeb pages. Defacement often is committed to embarrass the Website owner, publicize a protest message, or enhance the reputation of the criminal hacker who is performing the defacement. But in terms of penetration, the primary goal of attacks on Websites is to compromise internal networks that might be connected to the Web server. Exploitation of allowed path vulnerabilities is probably the most common form of such attacks.
15.3.6.2 Input Validation Exploits. Whenever an allowed path is created to accommodate user input, the possibility exists that it will be abused. Such abuse can lead to unauthorized access to the system. This section describes a range of penetration methods using this approach, all of which somehow employ invalid input, or input that is:
Not expected by the receiving application on the server.
Not “allowed” according to the rules by which the receiving application is operating.
15.3.6.3 Unexpected Input Attacks. How is it possible to submit unex- pected input to a server? The answer lies in the architecture of the Internet and the paradoxical nature of the client system that is accessing the server. The typical Web client is a client in name only. It is often a powerful machine, capable of being a server in its own right, and very difficult for any other server to control, due to the inherent peer-to-peer nature of the huge network that is the Internet. All nodes of the Internet are considered hosts. And, of course, many of these hosts are outside the physical control of the organizations hosting those machines that are acting as servers. This fact has serious implications for security.
Unless the server can install tightly controlled application code on the client, and restrict user input to that code, the server must rely on the coding most commonly used to implement Web client-server interaction, Hypertext Markup Language (HTML) and Hypertext Transfer Protocol Daemon (HTTPD). Both are complex and relatively immature. For example, they do not automatically identify the source of the input. Consider an HTML form on a Web page, designed to be presented to a visitor to the Website who fills in the fields and then clicks a button to submit the form. There is nothing on the client side to control the user’s input. So instead of entering a first name in the First Name field, a user might enter a long string of random characters. Unless the application processing this data field performs extensive input validation, the effects of
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 29
such action can be unpredictable, even more so if the user includes control characters. Similarly, if theWeb server itself is not designed to validate page requests, a user might cause problems by submitting a bogus Universal Resource Locator (URL).
The problem is even more severe than this. Unless the Web server application is specifically written to defeat the following abuse, it can be used to cause all sorts of problems that potentially lead to successful penetration. Suppose that, instead of simply filling out a form, the user creates a local copy of the page containing the form, then alters the source code of the form, saves the file, and submits it to the Website instead of the original page. This does not violate the basic protocols of the Web but clearly provides considerable penetration potential. Many Websites are still vulnerable to attacks of this type.
15.3.6.4 Overflow Attacks. As described earlier in the context of hidden form fields, it is possible to gain access to Web servers by supplying more input than expected. Such an attack is possible with any field on a user-submitted form, not just a hidden field. The defense is to build extensive error checking into the application that processes the form.
Overflow attacks, which were described in general terms earlier, also can be directed at applications or services running on theWeb server. For example, in June 2001, CERT announced a remotely exploitable buffer overflow in one of the Internet Server Ap- plication Programming Interface (ISAPI) extensions installed with most versions of Microsoft Internet Information Server 4.0 and 5.0, specifically the Internet/Indexing Service Application Programming Interface extension, IDQ.DLL. An intruder exploit- ing this vulnerability may be able to execute arbitrary code in the local system security context, giving the attacker complete control of the victim’s system.
15.3.6.5 File-System Exploits. Another category of attack against Websites exploits problems with the file system of the Web server itself. Ever since Web servers started appearing on the Internet, there has been a constant procession of vulnerability announcements arising from file system issues. The main ones are presented here, but the possibility of others appearing is high due to a lack of what David Brussin has called vulnerability class analysis. A vulnerability class is a type of problem, such as buffer overflow or file system access control. Developers of Web servers, and many other applications, are often averse to, or resource-constrained from, the elimination of vulnerabilities as a class, being focused instead on the hole-by-hole fixing of specific instances of the vulnerability as they arise. This phenomenon is largely a result of the rapid pace at which the Web has been developed and deployed, driven by powerful commercial forces.
15.3.6.6 Dot Dot, Slash, and Other Characters. Persons responsible for the security of information systems that employ Web servers must be alert for new vulnerabilities. Web server software has proven particularly susceptible to certain categories of vulnerability that tend to recur in new versions. Whenever these vulner- abilities are discovered, attackers quickly exploit them. Typically, software vendors issue patches to solve the problem, but systems remain susceptible until patched, and attackers use automated tools to scan the Internet for servers that are still susceptible. For example, in April 2001, a flaw was discovered in versions of Microsoft Internet Information Server (IIS) in use at that time. This flaw made it possible for remote users to list directory contents, view files, delete files, and execute arbitrary commands.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 30 PENETRATING COMPUTER SYSTEMS AND NETWORKS
In other words, if a Web server running IIS was connected to the Internet, anybody using the Internet could potentially copy, move, or delete files on the Web server. With this level of access, it was possible to use the Web server to gain access to connected networks unless strong internetwork access controls were in place. In alerts that were issued to warn users of this software, exploitation of this vulnerability was described as “trivial.” In fact, a large number of sites were penetrated because of it, and many suffered defacement (i.e., unauthorized changes to the appearance of theirWebsites). In other cases, attackers downloaded sensitive customer data and uploaded and installed back door software.
Particularly worrying about this vulnerability was the fact that it was essentially a recurrence of the so-called dot dot directory traversal attack, which was possible on a lot of early Web servers. These servers would, upon request, read “..” directories in URLs, which are unpublished parent directories of the published directory. Thus, attackers were able to back out to the Web root directory and then to other parts of the server’s directory structure. This technique basically allowed attackers to navigate the file system at will. Many Web servers, including IIS, began to incorporate security measures to prevent the “dot dot” attack, denying all queries to URLs that contain too many leading slashes or “..” characters.
The vulnerability published in April 2001 involved bypassing these restrictions by simply substituting a Unicode translation of a “/” or “ ∴.” Attackers found that, by appending the “..” and a Unicode slash or backslash after a virtual directory with execute permissions, it was possible to execute arbitrary commands. Attackers could execute any command via a specially crafted HTTP query. The frequency with which “old” vulnerabilities reappear in new software should serve as a warning to information security professionals not to assume that “new” is the same as “improved.” Indeed, all software needs to be treated with a healthy degree of skepticism and a fair amount of heavy testing prior to deployment.
15.3.6.7 Metacharacters. Dots and slashes used in field system references are closely related to metacharacters, which also can be used to attack Web systems. A metacharacter is a special character in a program or data field that provides infor- mation about other characters, for example, how to process the characters that follow the metacharacter. Users of DOS or UNIX are probably familiar with the wildcard character, a metacharacter that can represent either any one character or any string of characters. If used inappropriately, for example, in user-supplied data, metacharacters can cause errors that result in unintended consequences, including privileged access.
15.3.6.8 Server-Side Includes. Server-side includes (SSIs) are special com- mands in HTML that the Web server executes as it parses an HTML file. SSIs were developed originally to make it easier to include a common file, called an include file, inside many different files; examples include files containing a logo or text files consisting of the page, date, author, and so on. This capability was expanded to enable server information, such as the date and time, to be included automatically in a file. Eventually, several different types of include commands were provided onWeb servers: config, include, echo, fsize, flastmod, exec. The last of these, exec, is quite powerful, but it is also a security risk, as it gives to the user of the Web client permission to execute code. A number of attacks are possible when exec is permitted within an inadequately protected directory.
Analogous to SSIs are ASPs (Active Server Pages) and JavaServer Pages, as well as Hypertext Processors (PHP). All are technologies that facilitate dynamic page building
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 31
and allow execution of codelike instructions within an HTML page. All should be employed with special attention to security implications and strict adherence to secure Web application programming methods. Security professionals will note that many of the weaknesses in these newer technologies are simply old exploits reborn. Any- thing that offers “greater interactive functionality” may increase the likelihood of new vulnerabilities simply because, in the absence of rigorous software quality assurance, changes are so often associated with new bugs.
15.3.7 Role of Malware and Botnets. Several new twists on system pene- tration via Websites and Internet email have emerged in recent years, starting with the evolution of computer viruses and worms. Some worms and viruses are designed to install Trojan code. The term “malware,” derived from “malicious” and “software,” is now widely used to refer to the entire category of software coded with malicious intent, including viruses, worms, and Trojans. In fact, viruses and worms, which are dealt with in more detail in Chapter 16 in this Handbook, are themselves a form of system penetration; after all, the creators of virus and worm code are getting their code onto systems that they are not authorized to use, so one may consider those machines to have been penetrated. Some criminal hackers have combined different elements of malware to penetrate computers used to surf the Web. Those compromised machines are then used, in turn, to spread malware and compromise additional machines. The goal may be gathering of user names and passwords (helpful for yet more system penetrations) or financial data used to perpetrate fraud and identity theft.
The two main components of this penetration strategy are drive-by downloads and botnets. A drive-by download attempts to compromise machines used to visit a malicious Website, taking advantage of either user gullibility or vulnerabilities in their Web browsers to install, without explicit permission, unsolicited code, typically a Trojan of some sort. A botnet is a collection of bots, host computers that can be controlled remotely (i.e., robotically) through Trojan code installed on those machines, either via a drive-by download or other means, such as a virus or worm. Here is how researchers at Google described the phenomenon in a landmark 2007 report:
[C]omputer users have become the target of an underground economy that infects hosts with malware or adware for financial gain. Unfortunately, even a single visit to an infected Website enables the attacker to detect vulnerabilities in the user’s applications and force the download of a multitude of malware binaries. Frequently, this malware allows the adversary to gain full control of the compromised systems leading to the ex-filtration of sensitive information or installation of utilities that facilitate remote control of the host.15
What makes the Google report a landmark is not the existence of drive-by exploits, which have been on the rise for several years, but their prevalence. Because Google maintains a massive repository of Web pages in order to operate its search engine, it is in a fairly unique position when it comes to analyzing the content of the Web as a whole. The solidly researched finding that at least 1 in 10 of all Web pages contained some form of malware should be a wakeup call to IT departments everywhere. Are your users surfing to Facebook pages? Are they aware that something as seemingly harmless as visiting their favorite singer’s page on theWeb might cause malicious code to be downloaded onto their computer from a server in China?
That sort of attack started to become commonplace in 2007, as documented by Roger Thompson of Exploit Prevention Labs, with Alicia Keys being one of a number of artists targeted by criminal hackers. One exploit used in these attacks installed a
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 32 PENETRATING COMPUTER SYSTEMS AND NETWORKS
proxy network bot, known as a flux bot. The goal of a flux bot is to obscure the location of phishing sites by using constantly changing proxy servers, thus making it harder for banks and other institutions targeted by the phishing scam to shut it down. (There is more about phishing scams in Chapter 20 in this Handbook.)
According to theGoogle report, there are fourmainmethods bywhichWeb pages are turned intomalware infection vectors: advertising, third-partywidgets, user-contributed content, and Web server security. This implies that company Websites not only need to be firmly secured, but that all advertising and user-supplied content should be validated, as should any widgets that are employed or distributed by the site.
15.3.8 Sophisticated Attackers. In recent years several groups of attackers have been very successful using a very different approach to compromise security systems than has been used historically. These groups have been termed “Advanced Persistent Threats” by the United States Air Force in 2006.While many of these groups are nation state–sponsored these same techniques are being employed by groups with purely financial gain as well.
It is important to understand up front that these attacks, regardless of specific source group, are targeted. In the case of the nation state–sponsored groups, the goal is infor- mation theft. This information theft often takes the form of email, but also can range much deeper to research and development information or other intellectual property. The financially motivated groups focus on financial institutions for the purposes of financial gain.
As of this writing, there are many known groups active in the world. Each of these groups uses a little different specific components in their overall process, but the overall process is the same and can be broken down into some distinct stages.
The first stage is reconnaissance, planning, and preparation. This is where they select specific individuals within the target organization. They also plan out their attack based on the results of the reconnaissance. Finally they set up specific command and control servers to be used against the target and build the malicious software to be used as part of the attack.
The second stage is obtaining foothold and persistence. In this stage their goal is to get onto the target network. This is the point they deploy their attack (most often through spear-phishes) and gain remote access to the target network. Since gaining a foothold is one of the more challenging parts, they also seek to ensure they canmaintain that foothold on the network.
The third stage is mapping the internal network and locating the desired data. At this point, they seek to understand the target environment and find their ultimate target of either specific data or systems on which they can perpetrate their financial impact.
The fourth and final stage is exfiltration or exploitation. This is the point at which they transmit the collected information outside of the target environment (typically nation-state actor goal) or execute their financial attack (in the case of the cybercrime actors).
15.3.8.1 Stage One—Reconnaissance, Planning, and Preparation. The attackers often begin with selecting a handful of individuals at the target or- ganization. They employ open source intelligence sources like the company Website, Facebook, and LinkedIn to gather information and identify recipients at the target organization. Other sources, such as press releases from companies and news articles about those companies, provide a rich resource for attackers to zero in on individuals close to the ultimate target of the attackers.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 33
Once individuals have been identified an appropriate delivery can be created. The most commondeliverymeans is through spear-phishes.A spear-phish is a targeted phish (as compared to a normal phish that is sent to thousands ormillions of recipients). These spear-phishes are often simple and straightforward but can be quite sophisticated.
While spear-phishing is the most common means of delivery attackers will also compromise Websites commonly used by their targets as a means of delivery. This method of delivery is referred to as watering hole attacks. The term watering hole refers to the hunting method whereby a hunter waits for their prey at a watering hole, knowing that eventually the target will come for a drink. Watering hole attacks work by modifying a compromised Website’s code so that when users view the Website an exploit is delivered to the victim browser. This exploit is in turn used to install malicious code on the system.
Least commonly, the sophisticated attackers have been found to use malicious code placed on USB keys. These are either left where target users will find them or even mailed directly to the targets. Exploit code is used on the USB device so that when users access the device the exploit code will install malicious code onto the user system.
Also as part of stage one the attackers will configure C2 (command and control) servers to be used over the course of the attack. These C2 servers are often compromised hosts at legitimate organizations but can also be hosting servers obtained legitimately. In particular, attackers prefer servers at places such as large universities, as these are unlikely to be blocked by common prevention mechanisms like Web proxy filters commonly employed by organizations today.
The final major aspect of the preparation is the creation of the backdoors to be employed against the target organization. The attackers generally have several variants of their backdoor with slightly different characteristics. Some groups will even use commonly available RATs (Remote Access Trojans) such as Poison Ivy and configure them to use the appropriate C2s. Many of the attackers have tools that will weaponize legitimate PDF or office documents. Weaponization is the process of turning a le- gitimate file into a malicious one. If, for instance, the individuals share a particular industry in common, the attackers might find a relevant industry conference in the near future and download an actual agenda PDF file from the conference Website. They might then weaponize that PDF or simply use information from the file to add to their spear-phish to add realism and improve their chances for the targeted users to fall for the spear-phish.
15.3.8.2 Stage Two—Foothold and Persistence. The end result of stage one is an RAT being installed on one or more target systems. This Trojan provides covert backdoor access to the victim systems. Now that the attacker has a foothold on the target network, they want to maintain that access. Attackers want access from more than a single system, since a single host might not be running when they want access. The attackers also understand that eventually the RAT will be found or removed. The attackers also want to increase their access to ensure they can get to whatever their final objective is.
To accomplish all of this, the attackers will usually follow a consistent process. They start with dumping the password hashes from the local host cache. By default,Microsoft Windows (the predominant operating system in use by users at most organizations) keeps a cache of the last 10 user IDs and passwords used to log into a computer. This is done so that if the computer is not connected to the corporate environment and thus can’t access the domain controllers, the user will still have the ability to log into the system locally. Tools like pwdump, Windows credential editor, and fgdump
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 34 PENETRATING COMPUTER SYSTEMS AND NETWORKS
will display the user IDs and passwords in the local system cache. These can then be cracked using rainbow tables or cracking software back at the attacker’s location.
The second step is to look at the host network connections to determine what computers the host is communicating with. The logic behind this is simple—any credentials in the local computer will very likely work on other hosts the system is interacting with. Remember that the purpose of user IDs is to provide authentication to other systems for the purpose of using them. Using the cracked password for the locally cached user IDs, the attacker connects to the subsequent systems and proceeds to extract the user IDs and password hashes from that host. The process of moving from host to host like this is termed lateral movement. It is especially important to note that the attackers are not using malware to accomplish this access. They are using legitimate user IDs and passwords. Ultimately, the attacker will continue this process until they find a systemwith an administrative account that will give them access across the entire environment. It is rare for them to have to traverse more than six to ten systems in order to find one with a network or domain administrator account cached. Once they have an administrative account they are free to use it to move throughout the network.
In addition to obtaining local user IDs and passwords from system caches, the attackers also map the target environment at this stage. Mapping the network is done through simple querying of Active Directory. The simplest way for the attackers to gain information about the environment is with a series of simple commands:
net group “domain computers” /domain net group “domain users” /domain net group “domain controllers” /domain net group “domain admins” /domain
If you aren’t familiar with those commands, you should try them. The only re- quirement is to do them from a computer that is a member of the local domain. No administrative credentials are necessary. The result is a list of all computers, users, domain controllers, and domain admin accounts in the environment. This information is returned immediately and is far more useful for attackers’ purposes than running a tool like nmap. A further benefit is that the use of these commands is very, very difficult to detect as compared to nmap or similar tools that are very noisy. When the attackers want to gain more thorough information about an environment they will typically use dsquery and dsget. These are two command line tools provided by Microsoft to query active directory. Here are the contents of a batch script that was recovered from a recent incursion showing the use of these tools.
dsquery user -limit 0 | dsget user -samid -display -title -email -dept -office -company -c >1
dsquery user -limit 0 | dsget user -samid -pwdneverexpires -acctexpires -loscr -profile -hmdir -hmdrv -c >2
dsquery user -limit 0 | dsget user -c > 3 dsquery group -limit 0 |dsget group -c >g dsquery subnet -limit 0 |dsget subnet -c >sn dsquery site -limit 0 |dsget site -c >s dsquery computer -limit 0 |dsget computer -c>c dsquery ou -limit 0 | dsget ou -c>o
Attackers understand that users leave organizations and change roles. To ensure they have plenty of user IDs at their disposal it is a high priority for them to dump the entire domain credentials. This usually occurs within minutes of them achieving an administrative account with sufficient credentials. Their tool of choice for this is the
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
TECHNICAL PENETRATION TECHNIQUES 15 · 35
well-known pwdump. They simply run pwdump against one of the domain controllers using a recovered domain administrator account. Once the hashes are obtained, they can crack them at their leisure back at their location.
Another priority of the attackers is to install additional mechanisms for gaining access to the environment. To accomplish this they will use a variety of methods. If a company employs a single-factor VPN, then the attackers have unlimited access to the environment using the stolen user credentials. They will also install several additional backdoors. These are distributed throughout the environment to make it difficult for security personnel to find them all. The attackers understand that malware is the easiest thing to spot in an environment, however, and so they will only install copies on a handful of the overall hosts they compromise. As a further precaution to detection, they will usually configure the extra backdoors to sleep for extended periods of time. This tactic results in it being very challenging for security staff to find and eliminate all copies of their backdoors. Finally, in the last couple years, they have been observed also deploying Web shells in corporate DMZs as a further level of backup access to an environment. Web shells were very popular with attackers in the late 1990s and early 2000s but have been rare for the last several years, and thus are not commonly looked for. The Web shells being employed by the attackers are very small and do nothing until remotely accessed, making them very difficult to uncover as well.
As if the use of so many techniques in order to maintain access to a company was not enough, most groups will also monitor their installed backdoors in real time. If they observe an organization actively removing them they will quickly jump onto compromised hosts and install entirely different backdoor versions with very different characteristics so as to maintain access and remain undetected. It is important to realize that themajority of the backdoors are proprietary, not commodity, and very rarely found with standard antivirus. The net result for the attackers is a long-time presence on an environment, during which they can move around and access whatever they desire.
15.3.8.3 Stage Three—Information Theft. The final stage and aspect of the advanced attackers is where they find and exfiltrate the information they see or execute the financial transfers in the case of the cybercrime-motivated actors. All of the efforts of the attackers are for the ultimate purpose of stealing something.
After establishing long-term persistence in an environment, the attackers begin moving from host to host looking for the information they seek. Mostly this is done by command line, but some groups will also tunnel RDP protocol through their C2 infrastructure. If an organization has some other form of remote control, such as VNC, the attackers will gladly utilize that as well with the legitimate credentials they compromised. Through the simple expedient of theWindows ‘dir’ command, they look in the documents of each host, seeking the data they desire. This is facilitated by the deep organizational knowledge they acquired in earlier stages.
Often the majority of their theft is simply e-mail. When you consider the amount of business activity details that are conducted with e-mail, you realize an attacker can gain incredible competitive advantage from information contained in e-mail.
When the attackers find the data they seek, they will compress and encrypt it, then transmit it back to the C2 infrastructure. This process is known as exfiltration. Since sophisticated attackers understand organizations have logging measures in place, the transfer is done to intermediary systems, rather than directly to their location. Subsequently they can move it from the intermediary systems to the final destination without risk of the compromised organization being able to trace it.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 36 PENETRATING COMPUTER SYSTEMS AND NETWORKS
Most often RAR is used to package the data for exfiltration. RAR is particularly useful for attackers because of its unique characteristic among compression formats: Data in an RAR file can be recovered even if the RAR is incomplete. If exfiltration is interrupted midtransmission, the attackers will still be able to extract whatever portion of the data made it out. Encryption is used to make it more difficult for a compromised company to figure out what data was stolen. Most groups also prefer to use a media file extension for their RAR files as a further means of obfuscation. The renamed files may have a .mpg or .avi extension but they are simply normal encrypted RAR files.
For transmission of the data the attackers typically use Secure Sockets Layer (SSL). This tool, combinedwith the compressed and encrypted contents, makes it very difficult for companies to detect that anythingmalicious is occurring. The sophisticated attackers are so successful overall because themajority of their activities are done by hiding in the large volume and noise of legitimate activity. Consequently, they’ve all been observed using services like dropbox, box.net, and other cloud providers for exfiltration as well, given the significant adoption rate of these types of services legitimately by our users. Detecting malicious activity to a cloud provider from legitimate activity is very difficult indeed.
15.4 POLITICAL AND LEGAL ISSUES. Thanks to the World Wide Web, the Internet has become a self-documenting phenomenon. One can use the Internet to find out everything one wants to know about the Internet, including how to penetrate information systems that employ Internet technology. However, the penetration infor- mation available on the Internet is not restricted to Internet systems, and the Internet is not the only source of penetration information. Furthermore, the very availability of penetration information is fraught with political and legal issues. These are discussed briefly in this final section of the chapter.
15.4.1 Exchange of System Penetration Information. The sharing of system penetration information—that is, information that could facilitate illegal pene- tration of an information system—is the subject of a long, heated, and ongoing debate. This debate encompasses both practical and ethical aspects of the issue. Although complete coverage is not possible within the confines of this chapter, we do review the question of full disclosure, along with some of the sources for penetration information.
15.4.2 Full Disclosure. How should we handle known vulnerabilities and po- tentially damaging computer viruses? Should we publish full details, conceal some details, or suppress any publication that would allow exploitation until patches or up- dates are available from manufacturers? Is there a case for handling some viruses and exploits differently from others?
Over the last two decades, formal venues for full disclosure of system or network vulnerabilities and exploits have evolved (e.g., BugTraq). Support for full disclosure of such details, down to the source code or script level, from professional, honest security experts (the Good Guys) is based on subsets of several key beliefs:
� The Bad Guys know about the vulnerabilities anyway. � If they do not know about it already, they will soon with or without the posted details.
� Knowing the details helps the Good Guys more than the Bad Guys.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
POLITICAL AND LEGAL ISSUES 15 · 37
� Effective security cannot be based on obscurity. � Making vulnerabilities public may force vendors to improve the security of their products.
Since those who would use vulnerabilities and exploits for gain or harm often learn of them before system administrators and security experts, it makes sense—so the argument goes—for the Good Guys to spread the knowledge where it can do some good. One might also argue that, because cryptographic techniques are routinely exposed to public scrutiny by experts to detect vulnerabilities and to avoid future failures, other aspects of security should also be made public.
As for putting pressure on manufacturers, one colleague describes an incident that illustrates the frustrations that sometimes underlie full disclosure. He informed an important software supplier of a major security vulnerability. The product manager ignored him for a month. At that point, patience gone, the colleague informed the product manager that he had exactly one more day in which to produce a patch; otherwise, he said, he would publish the hole in full in the appropriate Usenet group. A patch was forthcoming within one hour.
Why would anyone object to full disclosure of detailed viral code and exploits? The arguments are that:
� Nobody except researchers needs to know the details of viruses or even of specific exploits.
� Publishing in full gives credibility to ill-intentioned Bad Guys who do the same. � Full disclosure makes impressionable youths more susceptible to the view that illegal computer abuse is acceptable.
How, exactly, does publishing the details of a new virus help system administrators? In one view, such details should be exchanged only among colleagues who have developed trust in each other’s integrity and who have the technical competence to provide fixes. For example, a “zoo” of computer viruses serves this function, with access limited to legitimate virus researchers who sign a code of ethics that forbids casually distributing viruses to anyone who wants samples. Opponents of this stance see the attitude as arrogant and elitist. Furthermore, some virus and worm code is written in a form that is easily read by anyone who receives a copy (a large population, considering that in 1999, the Melissa virus is thought to have infected over a million computers within a matter of days).
There is a danger in publishing exploits where any person with access to theWeb can use them for automated attacks on Websites. This gives naı̈ve people the impression that it is okay to publish any attack code, regardless of consequences. (Note that the consequences are often relatively minor—the author of the Melissa virus, which is estimated to have caused at least $80 million in damages, served only 20 months in a federal prison and paid a fine of only $5,000.) What is the difference, then, between publishing vulnerabilities or exploits and actually creating attack tools? Was creating and publishing BackOrifice a morally neutral or even a useful act? BackOrifice is a tool that is explicitly designed to install itself surreptitiously on systems and then hide in memory, using stealth techniques modeled on what some viruses use. Is this a contribution to security?
There are no simple or uncontested answers to these questions, but in some cases technology has answered them for us. Before 1995, when macro viruses first appeared
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 38 PENETRATING COMPUTER SYSTEMS AND NETWORKS
“in the wild,” most viruses were written in assembly language or machine code. This limited the number of people who could read them or understand them to persons familiar with assembly language and machine code. However, anyone who receives a macro virus has the text editor tools needed to read its code. The tools required to develop and test macro viruses are provided in mainstream applications such as MicrosoftWord, which has tens ofmillions of users worldwide, a significant percentage of whom have, or can easily acquire, the rudimentary programming skills required to develop their own viruses. The rapid spread of the original Word Concept virus in the summer of 1995 pretty much ensured that anyone who wanted a copy of it could get one (and many of those who did not want a copy got one anyway). The idea of keeping the content of the virus secret was a nonstarter.
Facedwith vendor inability or unwillingness to fix security vulnerabilities in a timely manner, some users and experts can be expected to turn to full disclosure of security information, even though many of them may deplore using such tactics. However, they will always run the risk of making the wrong call when it comes to the effect of such disclosures, which are inherently unpredictable. Indeed, the release of the Word Concept virus may have been motivated by a desire to make Microsoft change the way its office applications handle macros. Other office applications, such as Word Perfect and Lotus 1-2-3, were designed to keep macro code separate from document content, making a malicious document much harder to create.
15.4.3 Sources. There are many sources for information about how to penetrate systems. The motives behind these sources range from highly ethical to downright criminal. Chapter 74 in thisHandbook discusses training and certification in penetration testing for legitimate, authorized purposes.
15.4.3.1 Online Sources. There is no small irony in the fact that much of what a person needs to know about how to penetrate information systems is made available by information systems. Fortunately, the inverse is also true, as one of this chapter’s authors has observed: “The best weapon with which to protect information is information.”16 For this reason, security professionals need to know what sources of penetration information are available.
Today there are thousands of Websites that
� Document security holes in different versions of operating systems � Distribute hacking tools and discuss how to use them � Catalog default credentials for network hardware � Teach malicious code writing, including how to make viruses and worms � List license codes to enable activation of pirated software � Buy, sell, and trade system access codes, stolen credit cards, stolen identity data, and networks of compromised hosts (botnets)
� Provide a forum and meeting place for those seeking to penetrate systems
These sites have assumed the mantle of earlier online communication channels, such as bulletin boards and Usenet groups, where legitimate sharing of information occurred alongside the exchange of illegal information, pirated code, and so on. Some Websites are moderated and so maintain certain ethical standards. Others follow the Internet tradition of “anything goes.” System administrators and employees should
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
POLITICAL AND LEGAL ISSUES 15 · 39
never participate in discussions on these Websites with company email addresses. In a popular strategy, hackers wait for platform-specific vulnerabilities to be announced, then search the Internet for messages from people using that platform, look at their email addresses to see where they work, and attack systems at those companies in the hope that patches are not yet installed.
15.4.3.2 Publications. Over the years many publications have specialized in hacking. Often these provided information on how to penetrate systems. Some publi- cations were primarily electronic, such as Phrack, while others have been print based, such as 2600, which is nowwidely distributed through conventional magazine channels as well as through paid subscriptions.
15.4.3.3 Hacker Support Groups. Numerous groups of people exist to share hacking information, ranging from relatively stable entities with their own publications (e.g., 2600 and cDc) to annual conventions with thousands of participants (e.g., De- fCon). Although some members of these groups may have committed criminal acts, and some participants at hacker conventions actually have been convicted of such and served time, there is usually a diverse mix of elements with different motivations in these groups and meetings. DefCon, for example, draws not only people who openly advocate unauthorized security testing of other people’s systems and networks, but also law enforcement personnel and legitimate security experts. Some participants go to DefCon specifically to convince young people not to break laws while trying to learn about security.
Many security professionals would prefer that the line between white-hat hacking and black-hat hacking be clearer and more sharply enforced; however, some companies overlook past transgressions in order to gain the perceived value of the hackers’ tech- nical security expertise. Indeed, in recent years, investors have even cooperated with groups of hackers in founding security consulting companies, complete with some employees who continue to use hacker handles. The fact remains that some of the best technical training in the field is provided by people who gained their expertise in criminal (or quasi-criminal) hacking, but who now help defend against such activity.
15.4.4 Future of Penetration. Trends over the last 15 years strongly suggest that attempts to penetrate information systems will not decrease any time soon. These factors have been in play for some time:
� The declining cost of, and increased access to, penetration technology—from software and hardware used to crack passwords and encryption to eavesdropping and interception devices
� The continuing practice of fielding inadequately tested systems, built with imma- ture technology and with insufficient attention to security
� The increased availability of automated hacking tools with easy-to-use interfaces � The continuing allure, and portrayal in popular culture, of hacking as a “cool” activity, without adequate reflection on its legality or consideration of its morality
Additionally, these factors have emerged strongly in recent years:
� The very real opportunity to make money from penetrating systems, given a thrivingmarket in purloined personal data, compromised hosts (bots), and exploits
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 40 PENETRATING COMPUTER SYSTEMS AND NETWORKS
� The increased interest and involvement of organized crime in system penetration � The rise of transnational terrorist organizations that are increasingly computer- literate and may be inclined to penetrate systems belonging to entities or countries to which they are opposed17
Although some companies and government agencies are actively pursuing improved responses to these threats, others are not. Through lack of concern, resources, or time to address these trends, many entities are at increasing risk. Each new technology brings new threats, but new threats typically are discounted as scaremongering by vendors who offer defenses against them. For many companies and government agencies, the enthusiasm to reap the benefits of new technology overrules the warnings about risks inherent in its deployment. When those risks finally manifest themselves in ways that threaten the organization, the reaction is usually to buy a technical fix, while the root causes of vulnerability, namely human behavior and employee awareness of security issues, fail to receive the attention and resources they deserve.
New applications of computer technology, such as implanted medical devices and control systems for automobiles and autonomous vehicles, are providing fertile ground for experimentation by research scientists and criminal hackers, who are finding many vulnerabilities.18
15.5 SUMMARY
� Penetration of information systems is possible by means of a wide range of methods, some of which are very hard to defend against.
� Those responsible for securing systems have to defend against this wide range of penetration methods.
� Making sure all defenses against all attacks are effective all of the times is a lot harder than finding a single point of failure within those defenses.
� Although all systems do not need to defend against all types of attack equally, the cost of even the more exotic attack strategies is constantly falling, expanding the range of possible attackers.
� The cheapest and most effective attacks are often nontechnical, exploiting human frailty rather than weaknesses in the technology.
� Experienced criminal hackers tend to favor the nontechnical attack over the tech- nical; and the best defense, employee awareness, is also nontechnical.
� Systems can be attacked at the client, at the server, or at the connection between the two.
� Both wired and wireless systems are highly susceptible to eavesdropping and interception.
� Many systems today are built with immature and insecure technology, making them susceptible to a wide range of attacks.
� New attacks come to light with alarming but predictable regularity. � Many of these new attacks are old attacks reborn, due to a lack of vulnerability class analysis. As a result of economic pressures, faulty reasoning, and insufficient desire for security, vulnerabilities are fixed one instance at a time rather than one class at a time.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
FURTHER READING 15 · 41
� Allowed path attacks against Websites are consistently the most effective strategy for system penetration whenever a system is Web connected or Web enabled.
� Penetration testing, both by internal staff and by objective external experts, always should precede system deployment.
� Given the inevitability of penetration attempts and the high probability of their eventual success, systems should be designed to survive attacks, limiting the scope of compromise from any single point of failure.
� Penetration of systems will continue to fascinate the curious and tempt them to break the law by illegally accessing systems. The potential gains from system penetration, in terms of money, power, competitive advantage, and notoriety, will continue to motivate those to whom laws and morality are not effective deterrents.
� Penetration of systemswill become increasingly automated and simplified, further widening the range of possible attackers.
� Human nature, not technology, is the key to defense against penetration attempts. Only by raising society’s ethical standards and educating employees to understand the willingness of others to behave unethically can the occurrence of criminal hacking into information systems be significantly reduced.
15.6 FURTHER READING
Websites CERIAS Hotlist: www.cerias.purdue.edu//hotlist INFOSEC and INFOWAR Portal: www.infowar.com SANS InfoSec Reading Room—Penetration Testing: www.sans.org/reading room/
whitepapers/testing SearchSecurity.com: http://searchsecurity.techtarget.com SecurityFocus: www.securityfocus.com Web Application Security Consortium: www.webappsec.org BooksAllen, Lee.Advanced Penetration Testing for Highly-Secured Environments: The
Ultimate Security Guide. Packt Publishing, 2012. Chappell, Laura.Wireshark R© 101: Essential Skills for Network Analysis. Laura Chap-
pell University, 2013. Engebretson, Patrick. The Basics of Hacking and Penetration Testing: Ethical Hacking
and Penetration Testing Made Easy. Syngress, 2011. Faircloth, Jeremy. Penetration Tester’s Open Source Toolkit, 3rd ed. Syngress, 2011. Fialka, J. J.War by Other Means: Economic Espionage in America. New York: W. W.
Norton, 1999. Goodell, J. The Cyberthief and the Samurai: The True Story of Kevin Mitnick—and the
Man Who Hunted Him Down. New York: Dell, 1996. Kennedy, David. Jim O’Gorman, Devon Kearns, and Mati Aharoni. Metasploit: The
Penetration Tester’s Guide. No Starch Press, 2011. Litchfield, D., Anley, C., Heasman, J., and Grindlay, B. The Database Hacker’s Hand-
book: Defending Database Servers. Hoboken, NJ: John Wiley & Sons, 2005. McClure, S., Scambray, J., and Kurtz, G. Hacking Exposed: Network Security Secrets
& Solutions, 7th ed. New York: McGraw-Hill Osborne Media, 2012. McGraw, G. Software Security: Building Security In. New York: Addison-Wesley
Professional, 2006.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
15 · 42 PENETRATING COMPUTER SYSTEMS AND NETWORKS
O’Connor, T. J. Violent Python: A Cookbook for Hackers, Forensic Analysts, Penetra- tion Testers and Security Engineers. Syngress, 2012.
Scambray, J., Shema, M., and Sima, C. Hacking Exposed: Web Applications, 2nd ed. New York: McGraw-Hill Osborne, 2006.
Schwartau, W. Pearl Harbor Dot Com. Seminole, FL: InterPact Press, 2001. Shimomura, T., and J. Markoff. Takedown: The Pursuit and Capture of Kevin Mitnick,
America’s Most Wanted Computer Outlaw—by the Man Who Did It. New York: Hyperion, 1996.
Slatalla, M., and J. Quittner.Masters of Deception: The Gang that Ruled Cyberspace. New York: HarperCollins, 1995.
Sterling, B. The Hacker Crackdown: Law and Disorder on the Electronic Frontier. New York: Bantam Doubleday Dell, 1992.
Stoll, C. The Cuckoo’s Egg: Tracking a Spy through the Maze of Computer Espionage. New York: Pocket Books/Simon & Schuster, 1989.
Stuttard, D., and Pinto, M. The Web Application Hacker’s Handbook: Discovering and Exploiting Security Flaws. Hoboken, NJ: John Wiley & Sons, 2007.
15.7 NOTES 1. “Report on the Existence of a Global System for Intercepting Private and Com-
mercial Communications (ECHELON Interception System),” PE 305.391, July 11, 2001, http://cryptome.org/echelon-ep-fin.htm
2. S. Cobb,The StephenCobbGuide to PC&LANSecurity (NewYork:McGraw-Hill, 1992).
3. Robert Lemos, “Mitnick Teaches ‘Social Engineering’,” News.com, published on ZDNet News, July 17, 2000, http://news.zdnet.com/2100-9595 22-522261.html (URL inactive)
4. “Defector Smuggled Out Copies of the ‘Crown Jewels’ of Soviet Espionage,” The Times (London), September 12, 1999.
5. Bryan Betts, “Optical Nets Easier to Hack than Copper,” PCWorld. April 27, 2007, www.pcworld.com/article/131306/article.html
6. Madeleine Acey, “‘Scrambler Software’ Will Protect Phone Calls from Pry- ing Ears,” CNN | Edge of Discovery, August 17, 2012, www.cnn.com/ 2012/08/11/tech/silent-circle-encryption
7. AT&T Press Release, Dallas, TX, December 6, 2007, www.att.com/rss 8. Wim van Eck, “Electromagnetic Radiation from Video Display Units: An Eave-
dropping Risk?” Cryptome, 1985, http://cryptome.org/emr.pdf 9. NSA CSS, “TEMPEST Level I,” NSA, January 15, 2009, www.nsa.gov/
applications/ia/tempest/TEMPESTLevel1.cfm 10. Distributed Rainbow Table Project, “Free Rainbow Tables,” Free Rainbow Tables,
May 8, 2013, https://www.freerainbowtables.com 11. Dan Farmer andWietse Venema, “Improving the Security of Your Site by Breaking
into It,” available on http://nsi.org/library/compsec/farmer.txt 12. Steve Gibson, Shields UP!! 2013, https://www.grc.com/x/ne.dll?bh0bkyd2 13. S. Gibson, “How Big Is Your Haystack … and How Well Hidden Is YOUR
Needle?” March 28, 2012, https://www.grc.com/haystack.htm 14. “According to Internet World Stats,” www.internetworldstats.com/stats.htm
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
NOTES 15 · 43
15. “The Ghost in the Browser: Analysis of Web-based Malware,” www.usenix.org/ events/hotbots07/tech/full papers/provos/provos.pdf
16. Cobb, Stephen Cobb Guide. 17. C. Wilson, “Botnets, Cybercrime, and Cyberterrorism: Vulnerabilities and Pol-
icy Issues for Congress,” Congressional Research Service Report for Congress, RL32114, 2007, at http://tinyurl.com/2y995r
18. A. Rubin, “All Your Devices Can Be Hacked,” TED, October 2011, www.ted.com/ talks/avi rubin all your devices can be hacked.html
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
16CHAPTER
MALICIOUS CODE
Robert Guess and Eric Salveggio
16.1 INTRODUCTION 16 ·1
16.2 MALICIOUS CODE THREAT MODEL 16 ·2 16.2.1 Self-Replicating Code 16 ·2 16.2.2 Actors: Origin of
Malicious Code Threats 16 ·2
16.2.3 Actors: Structured Threats 16 ·3
16.2.4 Actors: Unstructured Threats 16 ·3
16.2.5 Access versus Action: Vector versus Payload 16 ·3
16.3 SURVEY OF MALICIOUS CODE 16 ·4 16.3.1 Viruses 16 ·4 16.3.2 Worms 16 ·7 16.3.3 Trojans 16 ·8 16.3.4 Spyware 16 ·9 16.3.5 Rootkits 16 ·10 16.3.6 IRC Bots 16 ·10 16.3.7 Malicious Mobile
Code 16 ·11
16.4 DETECTION OF MALICIOUS CODE 16 ·11
16.4.1 Signature-Based Malicious Code Detection 16 ·11
16.4.2 Network-Based Malicious Code Detection 16 ·11
16.4.3 Behavioral Malicious Code Detection 16 ·12
16.4.4 Heuristic Malicious Code Detection 16 ·12
16.5 PREVENTION OF MALICIOUS CODE ATTACKS 16 ·12 16.5.1 Defense in Depth 16 ·12 16.5.2 Operational Controls
for Malicious Code 16 ·12 16.5.3 Human Controls for
Malicious Code 16 ·13 16.5.4 Technical Controls for
Malicious Code 16 ·13
16.6 CONCLUSION 16 ·14
16.7 FURTHER READING 16 ·14
16.8 NOTES 16 ·15
16.1 INTRODUCTION. Malicious logic (or code) is “hardware, software, or firmware that is intentionally included in a system for an unauthorized purpose.”1 In this chapter, we enumerate the common types of malicious code, sources of malicious code, methods of malicious code replication, and methods of malicious code detection.
A 2011 study of 200 small andmedium businesses (SMBs)with up to 249 employees reported that “… two in five SMBs know with certainty that they have suffered some sort of security breach as a result of employees navigating to Web sites that host malware, infected downloads or have been corrupted by malicious code.”2
16 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
16 · 2 MALICIOUS CODE
Common types of malicious code include viruses, worms, Trojan horses, spyware, rootkits, and bots. Emerging malicious code threats include kleptographic code, cryp- toviruses, and hardware-based rootkits. Present-day malicious code threats do not always fit into neat categories, resulting in confusion when discussing the topic. It is not possible to classify all code as being good code ormalicious code. Absent themens rea, or criminal intent of the author or user, code is neither good nor bad. Authors develop code to achieve some goal or fulfill some purpose just as users run code to achieve some goal or purpose. It is therefore the context of use and the intent of the wielder that determines whether code is malicious.
16.2 MALICIOUS CODE THREAT MODEL. In a threat model or profile, an actor uses access to target an asset, with an action, to yield an outcome.3 To understand the scope of the problem (and possible prevention), it is useful to study malicious code threats in this model. Actors may be structured or unstructured threats posed by individuals, organizations, or nation-states. Access is some allowed physical or logical path to the targeted asset. The execution of malicious code or logic is an action used to yield the desired outcome. This outcome could be intelligence (such as theft of trade secrets), surveillance, reconnaissance, disruption of operations, destruction of assets, publicity for some cause, or negative publicity for the victim.
16.2.1 Self-Replicating Code. Self-replicating code is not inherently mali- cious. A good deal of artificial intelligence research focuses on iterative self-replication. Hewlett-Packard and others4 have researched how techniques of self-replication could yield beneficial software such as code-patching worms. John Von Neumann pro- posed the basic concept of self-replicating code in his 1949 paper, “Theory of Self- Reproducing Automata.”5 In 1961 at Bell Labs, Douglas McIlroy, Victor Vyssotsky, and Robert H. Morris played a game called Darwin in which two opposing programs (memory worms) would enter a system and only one would leave. In an interview with one of the authors, Robert H. Morris the former Chief Scientist of the National Security Agency (NSA), stated:
We had this notion of putting two programs in a machine that would fight with each other and one would win and the other would die. Basically, the notion and the program were written by McIlroy and Vyssotsky and I was just on the side. But then, a few days later, I had a good idea and simply won the game and everyone else gave up… just because I happened to hit upon a very good idea for writing it.6
Although it would be desirable to live in a world free of war, the ever-increasing integration of technology and warfare necessitates the development of offensive in- formation warfare capabilities. Malicious code implants can serve useful intelligence, surveillance, and reconnaissance capabilities in national security and law enforcement operations. In addition, by researching and developing malicious code techniques, practitioners can better prepare for defense against developing threats.
16.2.2 Actors: Origin of Malicious Code Threats. Prior to discussing the specific types of malicious code, it is worth understanding the origin and source of malicious code attacks. Malicious code may originate from structured or unstructured threats. Structured threats include nation-states, corporate criminals, and organized crime. Unstructured threats include rogue actors such as individual intruders and so- called script kiddies.
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
MALICIOUS CODE THREAT MODEL 16 · 3
16.2.3 Actors: Structured Threats. Structured threats are organized, well funded, and may operate with a long-term strategic view. Structured malicious code threats tend to have intelligence, surveillance, and reconnaissance capabilities among their primary functions. Structured threats may use these capabilities to engage in industrial espionage, adversarial information operations, or serious ongoing fraud and theft.
Organized crime is responsible for 90 percent of malicious code threats.7 Extor- tionists target the online gambling industry with threats of distributed denial of ser- vice (DDoS) attacks launched from compromised personal computers. Criminals use compromised systems to engage in pump-and-dump stock fraud with one media out- let reporting annual gains by such groups approaching $1 billion a year.8 Malicious software-for-hire incidents are on the rise, indicating a maturing marketplace for ma- licious code. In 2006, an Israeli court sentenced a couple to prison time and ordered them to pay fines for authoring and placing malicious code used to spy on corporations and individuals by members of telecommunications and trading firms.9
Coordinated, systematic attacks originating from China routinely target defense and research and development facilities. In the 1999 text Unrestricted Warfare, two Chinese air force officers called for a transformation of warfare that would involve ongoing technological attacks on western assets.10 A Chinese military white paper released in 2006 called for a strategy whereby China could win an “informationized war”11 against the West that is “high-paced, high-technology, and digitized.” Although Chinese officials publicly deny sponsoring such attacks, the lack of law enforce- ment action indicates, at the very least, toleration for electronic attacks on Western assets.
16.2.4 Actors: Unstructured Threats. Unstructured threats include rogue actors not acting in concert or coordinationwith larger entities. Although serious attacks may result from unstructured threats, they do not pose the same long-term challenges as structured threats. In testimony before the United States Congress, former NSA director Kenneth Minihan stated:
The unstructured threat is random and relatively limited. It consists of adversaries with limited funds and organization and short-term goals. While it poses a threat to system operations, national security is not targeted. This is the most obvious threat today. The structured threat is considerably more methodical and well-supported. While the unstructured threat is the most obvious threat today, for national security purposes we are concerned primarily with the structured threat, since that poses the most significant risk.12
16.2.5 Access versus Action: Vector versus Payload. Malicious code attacks involve a vector and a payload. In biology, a vector is an agent that transfers (potentially harmful) material (code) from one location to another. In computer attacks, a vector is an avenue of access, such as an allowed path via physical access or via the network. Physical access occurs via internal personnel or others with access to the premises. Access via the network may occur via an allowed path to a Web server, an allowed path from a malicious Web server to a Web client, to a user via an email attachment, or to some other software process through an accessible port. The payload is a function (action) placed on the system to achieve some end. Payloads may include additional malicious logic, remote access software (rootkits and the like), or remote control (robot or bot) software to achieve some objective (spamming, DDoS attacks, and so forth).
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
16 · 4 MALICIOUS CODE
16.3 SURVEY OF MALICIOUS CODE
16.3.1 Viruses. In biology, a virus is “[a]n infectious organism that is usually submicroscopic, can multiply only inside certain living host cells, and is now un- derstood to be a non-cellular structure lacking any intrinsic metabolism and usually comprising a DNA or RNA core inside a protein coat.”13 In computer terms, a virus is self-replicating code that requires a host executable or document and the aid of a human to replicate. Joe Dellinger created the first virus for the Apple disk operating system in 1982 while a student at Texas A&M.14 Fred Cohen created the first VAX computer virus in 1983 as a part of his doctoral research.15 Len Adleman, the A in RSA, first applied the biologic metaphor virus to describe the results.
Types of viruses include boot sector, file infector, macro virus, logic bomb, cross- site scripting viruses (really a form of worm), polymorphic viruses, and cryptoviruses. However, modern malicious code threats tend not to fall so neatly into categories.
16.3.1.1 Boot Sector Viruses. When users boot a computer from digital me- dia, they allow code present in the boot sector of the media to run on the microprocessor with very little intermediation. Boot sector viruses in the 1980s and 1990s used this mechanism to spread via infected removable media such as (now extinct) floppy disks. If a user errantly booted from an infected floppy disk, compact disc (CD), DVD, or flash drive, the virus would copy itself to the boot sector of the hard drive. Thereafter, the malicious program code would copy itself to each medium inserted into the system. Although reportedly still in existence, boot sector viruses comprise very few modern malicious code threats. Virus Bulletin reports, “The last boot sector viruses fell off the WildList in early 2006, but various types continue to appear in our prevalence reports and a batch of laptops infected with ‘Stoned.Angelina’ was released in Germany and Denmark in mid-2007. More recently, [T]rojans have been observed using similar techniques to plant rootkits to hide their activities.”16
16.3.1.2 File Infector Viruses. File infector viruses inserted themselves into programs present on the host system. Whenever a user ran the host program (usually an .EXE or .COM file), the malicious code used the opportunity to insert itself into random access memory (RAM) and then replicate to other files on the system. Al- though probably still in existence, file infector viruses comprise relatively few modern malicious code threats.
16.3.1.3 Macro Viruses. Macro viruses spread via the macro definition lan- guages used by some applications. The most widely abused is the Visual Basic for Applications (VBA) scripting language that Microsoft developed to allow the automa- tion of functions inside the Office product suite. Any feature that allows for automation is a likely point of attack. Developers should carefully weigh security and ease of use when including such features in products. The first macro virus to target Microsoft Word17 appeared in the wild in 1995. Since that time, macro viruses have comprised a significant number of successful attacks.
16.3.1.4 Logic Bombs. A logic bomb is a form of malicious code function sometimes built into viruses that wait for some sequence of events to activate such as disappearance of an employee record from the human resources database or a particular
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SURVEY OF MALICIOUS CODE 16 · 5
date and time. Kabay gave some examples of early logic bombs in a 2002 Network World article:
In 1985, a disgruntled computer security officer at an insurance brokerage firm in Texas set up a complex series of Job Control Language (JCL) and RPG (an old programming language) programs described later as “tripwires and time bombs.” For example, a routine data retrieval functionwasmodified to cause the IBMSystem/38midrange computer to power down.Another routine was programmed to erase random sections of main memory, change its own name, and reset itself to execute a month later.
In 1992, a computer programmer was fined $5,000 for leaving a logic bomb at General Dynamics. His intention was to return after his program had erased critical data and get paid lots of money to fix the problem.
Time bombs are a subclass of logic bombs that “explode” at a certain time. Some of the first viruses, written in the 1980s, were time bombs. For example, the infamous “Friday the 13th” virus was a time bomb; it duplicated itself every Friday and on the 13th of the month, causing system slowdown. In addition, on every Friday the 13th it also corrupted all available disks. The Michelangelo virus from the early 1990s—one of the first viruses to make it into public consciousness because of news coverage—tried to damage hard disk directories on the 6th of March. The Win32.Kriz.3862 virus, discovered in 1999, detonates on Christmas day; its pay- load includesmassive overwriting of data on all data storage units and also damage to the BIOS.
In 2000, a Stamford, Conn., man was indicted in New York State Supreme Court in Manhattan on charges of unauthorized modifications to a computer system and grand larceny. The defen- dant worked for Deutsche Morgan Grenfell starting in 1996 as a programmer. By the end of 1996, he became a securities trader. The indictment charged that he inserted a programmatic time bomb into a risk model on which he worked as a programmer; the trigger date was July 2000. The unauthorized code was discovered by other programmers, who apparently had to spend months repairing the program because of the unauthorized changes the defendant allegedly inserted.18
In 2002 an employee of UBS PaineWebber planted a logic bomb in his employer’s servers as part of an attempted stock manipulation scheme.19 The perpetrator, Roger Duronio, purchased numerous put option stock contracts allowing him to sell UBS stock at a fixed, high price. OnMarch 4, 2002, at 9:30 a.m., the logic bomb began deleting files on over 1,000 computers, causing a reported $3 million in damage. Duronio thought that the effects of the logic bomb would bring down the stock value of UBS, allowing him to make a large profit from his stock options. Duronio’s plot failed and his profit did not materialize. Federal authorities later charged him with securities and computer fraud. In 2006 a judge sentenced Duronio to 97 months in prison for the attack.20
In March 2013, a logic bomb overwrote data on hard drives in South Korean banks and broadcasters. Kim Zetter of WIRED wrote,
The logic bomb dictated the date and time themalware would begin erasing data frommachines to coordinate the destruction across multiple victims, according to Richard Henderson, a threat researcher for FortiGuard Labs based in Vancouver, the research division of the security firm Fortinet.
The attack, which struck machines on March 20, wiped the hard drives and master boot record of at least three banks and two media companies simultaneously. The attacks reportedly put some ATMs out of operation, preventing South Koreans from withdrawing cash from them.
The malware consisted of four files, including one called AgentBase.exe that triggered the wiping. Contained within that file was a hex string (4DAD4678) indicating the date and time the attack was to begin—March 20, 2013 at 2 pm local time (2013-3-20 14:00:00). As soon as the internal clock on the machine hit 14:00:01, the wiper was triggered to overwrite the hard drive and master boot record on Microsoft Windows machines and then reboot the system.21
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
16 · 6 MALICIOUS CODE
16.3.1.5 Cross-Site Scripting Viruses (or Worms). Cross-site scripting (XSS) viruses (or worms) replicate via flawedWeb application servers and client code. A cross-site scripting exploit involving the social networking site MySpace and flaws in Microsoft Internet Explorer occurred in 2005 whereby a user named Samy amassed over 1 million friends overnight using a JavaScript insertion bug.22 The Los Angeles Superior Court sentenced the author, Samy Kamkar, to three years’ probation and 90 days of community service for his actions.
In an excellent review of XSS, Sherif Koussa wrote,
Cross-site scripting is an attack that targets the application users. The simplicity of cross-site scripting is also why it is so powerful. If the application is vulnerable to cross-site scripting, the developer is not in charge of what runs on the user’s browser anymore… the attacker is. Cross-site scripting could be used in attacks like authentication hijacking and session hijacking. The power of cross-site scripting manifests itself even more when combined with cross-site request forgery.…23
He then cites the case of the Twitter attack below:
In 2009, Mikey Mooney, then 17 years old, claimed responsibility for attacking Twitter using XSS techniques: “… at least four separate variants of the original StalkDaily.com XSS worm hit the popular micro-blogging site Twitter, automatically hijacking accounts and advertising the author’s web site by posting tweets on behalf of the account holders, by exploiting cross site scripting flaws at the site.” Writer Dancho Danchev provided more details about the attack in his ZDNet article.24
16.3.1.6 Polymorphic Viruses. Polymorphic code modifies itself to evade detection. The virus code may accomplish this by dynamically reassembling itself to modify the underlying structure while retaining overall functionality. In other methods, the virus is encrypted, encoded, or packed, and a stub loader decrypts, decodes, or unpacks the virus at run time. UPX, the Ultimate Packer for eXecutables, is currently the most widely used packer format.
In the SOPHOS Security Threat Report 2013, the authors write:
Polymorphism is not a new idea—malware authors have been using it for 20 years. Simply stated, polymorphic code changes its appearance in an attempt to avoid detection, without changing its behavior or goals. If a program looks different enough, attackers hope, antivirus software might miss it. Or the antivirus software might be forced to generate too many false positives, leading users to disable it.
In a polymorphic attack, code is typically encrypted to appear meaningless and paired with a decryptor that translates it back into a form that can be executed. Each time it’s decrypted, a mutation engine changes its syntax, semantics, or both.
For instance, Windows malware authors have often used structured exception handling to obfuscate control flow and make it tougher to perform static analysis of programs before they run.
Traditional polymorphic viruses are self-contained and must contain the mutation engine in order to replicate. Sophos and other security companies have become adept at detecting these forms of malware. With access to the mutation engine, it’s easier to analyze its behavior.
Today attackers are rapidly moving to web-distributed malware relying on server-side poly- morphism (SSP). Now, the mutation engine and associated tools are hosted entirely on the server. Criminals can use these tools to create diverse file content on the fly. Recipients of this content (whether it is a Windows .exe, Adobe PDF, JavaScript, or anything else) see only one example of what the engine can create. They don’t get to see the engine itself.25
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SURVEY OF MALICIOUS CODE 16 · 7
16.3.1.7 Cryptographic Viruses. Cryptoviruses use encryption to encrypt data, making it inaccessible to the user. Although some viruses use symmetric algo- rithms for self-encryption to evade detection, such algorithms are inappropriate for data encrypting viruses, as any copy of the virus is going to yield a copy of the symmetric key. For this reason, proper cryptoviruses use asymmetric techniques. The Gpcode virus encrypts files by extension (.xls, .doc, and the like) and leaves behind a text message prompting the user to email a given address to pay a ransom for access to their files. The next generation of cryptoviruses will likely use hybrid cryptosystems.
In a 2012 report on cryptoviruses, researchers developed proof-of-concept models of viruses using the public-key cryptosystem (PKC) to conceal themselves from scanners and then activate in response to an encrypted key or ticket. Their list of applications of cryptography in malware includes:
� Resist reverse engineering � Improve anonymity of communications from controllers to the malware � More effective data theft and denial-of-service attacks � Remote-control back doors for extortion26
16.3.2 Worms. The term worm refers to any form of self-replicating code that does not integrate into executable code. Common worm vectors include vulnerable services, email, instant messaging applications, and open file shares. Many worms use multiple vectors. For example, the Nimda worm spread via email, Web server vulnerabilities, hosted malicious Webpages, and open file shares.27
The first large-scale Internet worm infection was the Morris (aka Internet) Worm released by Robert T. Morris on November 2, 1988, while he was a student at Cornell University. The worm exploited flaws in the Sendmail and finger services to replicate and infected nearly 10 percent of Internet hosts. Although he claimed that this was an experiment gone awry, Morris became the first person convicted under the Computer Fraud and Abuse Act.
In 2001, Nicholas Weaver coined the term “Warhol Worms”28 for those worms that had the capability of propagating very quickly (taking a cue from Warhol’s famous quip that in the future everyone would have 15 minutes of fame). The SQL Slam- mer worm became the first such worm when it infected approximately 90 percent of vulnerable systems in 10 minutes.29 The Slammer worm replicated due to a flaw in the Microsoft SQL database server. Because this was installed along with other com- ponents like Visual Studio, many people did not even know that they were running an SQL server. Slammer was exceedingly effective, because a Microsoft service pack downgraded a previously patched dynamic link library (dll) to an older, vulnerable ver- sion. Specifically, Microsoft issued four updates to ssnetlib.dll in 2002. Unfortunately, in October, hotfix Q317748 downgraded ssnetlib.dll to a vulnerable version, ironically making those who most faithfully applied patches and hotfixes the most vulnerable to Slammer.30
The SQL Slammer worm is an interesting case study because it was a vector without a payload. The 376-byte worm ran in memory without touching the hard disk, leading some to believe that Slammer was an experiment in propagation techniques. Since it was based on the User Datagram Protocol (UDP) and traveled in a single packet, the overhead was minimal and the propagation rate was greater than any previous malicious code threat.31 The fact that the author(s) released it on a Saturday is also curious. It is unknown why a malicious attacker would deliberately release such a rabid
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
16 · 8 MALICIOUS CODE
virus on a day of the week that would lessen the overall business impact. If the author had released the worm on a peak business day such as a Tuesday, the damage caused would have been much more severe.
Worms are used to distribute other forms of malware such as Trojans, spyware, rootkits, and remote command and control channels called bots. An indication of the overall maturity of malicious code attacks is the Bagel worm, which has been in production at least since 2004. Bagel, like many other mail worms, arrives as an email with a malicious attachment. When the user runs the attachment, the payload is executed, which does a number of things depending on the variant. Later variants of Bagel install an open application framework that the remote attackers may update and extend. The harvested systems deliver spam (unsolicited commercial email), harvest additional addresses, and act as a staging point for other attacks. The author(s) appear to follow a sophisticated software development methodology and testing process.32
In 2007, attackers released 30,000 new variants in a six-week time span.33 In April 2012, the Flashback worm “infected more than 650,000 Mac OS X systems using a vulnerability in Apple’s version of Java.”34 Analysts with F-Secure wrote,
Flashback is the most advanced OS X malware we’ve ever seen. It boasts a series of firsts for its kind. It was both the first to be VMware-aware and the first to disable XProtect, OS X’s built-in malware protection program. Both these features were removed from later variants (the former presumably to avoid heuristic detections, and the latter presumably once the authors realized it was unnecessary, as XProtect was not designed to protect against non-quarantine fi les). Their removal indicates that Flashback is actively being reviewed and improved by its authors.
Another interesting first is Flashback’s exploitation of an unpatched vulnerability in the Java distribution of OS X, which allowed it to infect more than 650,000 Macs around the world.…This made Flashback roughly as common for Macs as Conficker was for Win- dows.…This means Flashback is not only the most advanced, but also the most successful OS X malware we’ve seen so far.
Flashback’s infection strategy is explicitly designed to select unprotected systems and will not infect a machine if certain security software or analysis tools are found. This implies that Flashback’s authors are targeting less security-conscious users, at the expense of the total number of potential targets. This turns out to be an effective strategy, as security researchers had difficulties getting sufficient samples from users. It took a mistake on the part of Flashback’s author to alert users to the presence of an infection and subsequently, to lead to the mass discovery of the malware.35
16.3.3 Trojans. A Trojan horse application, like the horse of Greek mythology, carries both an overt function and a covert function. Although attackers may use worms as one possible propagation vector, Trojans require that a user run the malicious program in order to be effective. Trojans tend to use some form of social engineering or manipulation to persuade the user to run the program. Email worms may appear to originate from a known associate and thereby trick the user. Other Trojans may take the form of games, free offers, pictures of popular celebrities, or files on peer-to-peer file sharing services. One study of the Limewire peer-to-peer file sharing service found that “68% of all downloadable responses containing executable, archival, and Microsoft Office file extensions”36 contained malware. Queries for movies were most likely to hold malicious code.
The covert function of Trojan horse application is typically some form of a remote access Trojan, keylogger, dialer, IRC bot, or rootkit. Remote access Trojans provide full remote access to the system. The developers of the Bo2 K Trojan bill it as “the
Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-03-19 16:20:05.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
SURVEY OF MALICIOUS CODE 16 · 9
most powerful network administration tool available for the Microsoft environment” and insist upon the fact that it is functionally no different from other remote access solutions.37 Keylogging Trojans record keystrokes and periodically upload the data to a remote user. Attackers carried out the Windows 2000 source code theft using credentials stolen by a QAZ Trojan installed on a remote workers computer. A dialer is a form of Trojan that silently dials remote toll numbers and runs up a large telephone bill for the victim. Internet relay chat (IRC) bots act as autonomous IRC clients. Early IRC bots provided technical support and channel monitoring features but are now widely used for malicious purposes such as command and control capabilities.
In 2013, Kaspersky Labs reported on “a Trojan build specifically for Android smartphones.”38 sean Gallagher wrote,
On March 25, the e-mail account of a Tibetan activist was hacked and then used to distribute Android malware to the activist’s contact list. The e-mail&r