Essay revision to meet specific criteria
Cybersecurity threats 1
Cybersecurity threats 2
Military Cyber-attacks have emerged from stealing personal information to controlling military equipment. Cyber intelligence has become an indispensable aspect of military training to curb the growing dangers of espionage, data leaks, and denial of service attacks. Military critical infrastructure networks are not excluded in cyber warfare as well. Exposure of military strategies, weapons designs, soldier deployment areas, and missile deployments are of most importance. It is, therefore, necessary to protect military networks from attacks or risk exposing such information to the enemies.
Recently North Korean hackers were involved in espionage attacks targeting more than ten countries (center for strategic international studies, 2021). In this attack, military spies use cyber warfare techniques to get intelligence information from other countries. Although military espionage is critical to obtain crucial leads that can help in planning and execution of missions. The data is of great military value as they can get military doctrine and operations of their perceived enemies. Espionage is an international computer crime that is punishable by death or life imprisonment in many countries.
Man in the middle attack (eavesdropping) is another attack that involves an attacker impersonating a genuine user in a two-way exchange of information. Attackers usually compromise data transfer mechanisms by intercepting communication between two legitimate parties. Packet sniffer applications are used in insecure military infrastructure to analyze network traffic. When a genuine user is authenticated to the system, the ‘man in the middle’ redirects the user's login details to another fake website that resembles the genuine one. Another approach attackers use is creating a phony website that unsuspecting users log in, providing the attacker with the credentials necessary to access the actual website.
The US military has also faced a denial of service (DoS) attack in the past. In this attack, the servers are overwhelmed with requests from client computers which hamper bandwidth and network resources. This prevents genuine requests from being processed. The attackers use several devices to flood the servers and network infrastructure to cause the system to halt by exhausting the RAM. According to a Radware report (Cisco,2020), 33 percent of DoS attacks last for sixty minutes, 60 percent in less than 24 hours, and 15 percent can last more than thirty days. Botnets are commonly used to launch DoS attacks. In June 2020, China attackers used a DoS attack against Indian banks and government agencies over a border row in Galway Valley (center for strategic international studies, 2021).
Malware attack is also widespread in military cyber warfare. The malware is usually a malicious program designed to exploit network vulnerability. The attacker packages the virus in a link or an email attachment that, when clicked it installs itself. Once installed, the malware is capable of blocking access to other genuine users of the network. Other malware programs (spyware) gather data from the system and send it back to the attackers. In May 2020, Chinese hackers were accused of stealing Covid-19 vaccine research (center for strategic international studies, 2021).
Phishing is another cyber-attack that is executed through communication channels such as emails that are disguised as genuine mails. A phishing attack intends to steal sensitive data such as log-in credentials, credit card details, or installing spyware in the target’s device. Phishers use compelling messages that evoke emotions, urgency, and fear to invoke the victims to click the links or download the attachments. In May 2020, Japan's defense docket announced it was probing a well-coordinated cyber-attack against Mitsubishi Electric that would have potentially interfered with new missile designs (center for strategic international studies, 2021).
Structured query language (SQL) injection is also a typical cyber threat to military infrastructure. In this attack, a malicious code is injected into the server that uses SQL database to reveal sensitive information, which in normal circumstances it would not. The attack involves modifying SQL codes in web-based applications (Tweneboah, 2017). Poorly structured SQL statements and weak input validation mechanism provide a loophole which attackers usually exploit to gain access to vital server information. SQL injection can be used to execute various attacks such as authentication bypass, deletion of data, modifying contents of the database, and managing remote control.
A drive-by attack is another cyber-attack used by hackers to spread malware to insecure webpages by inserting malicious code in HTTP code. Once a user visits the site, it redirects to the website operated by the hackers. Unlike phishing attack that installs malware or spyware when a user clicks the malicious link, the drive-by attack exploits the insecure websites, browser, or operating system to install malware to the machine. To prevent this type of attack, users are required to updates their operating systems, browsers and avoid visiting suspicious websites.
Social engineering tricks can also be utilized by hackers to get crucial information that they can use to launch cyber -attacks. This technique uses human weakness by luring them into a trap to steal their confidential data. Attackers can use various approaches to steal sensitive data, such as scareware programs that users are tricked into installing without fully understanding what the software does. Additionally, an insider leak also contributes to cyber-attacks. For instance, if military personnel intentionally leaks log-in details and passwords to unauthorized personnel, then the attackers can access sensitive information.
To sum up, protecting Army data is a very delicate task that requires expertise to anticipate emerging threats in cyberspace. The consequences of not protecting personal data are very dire and can lead to legal repercussions, especially in the Army where we rely on
References
Center for strategic international studies (2021). Significant cyber- attacks.
Cisco (2021). Common cyber attacks. https://www.cisco.com/c/en/us/products/security/common-cyberattacks.html
https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents
J.R. Wilson (2019, December 18). Military cybersecurity. https://www.militaryaerospace.com/trusted-computing/article/14073852/military-cyber-security-tactical-network
Tweneboah-Koduah, S., Skouby, K. E., & Tadayoni, R. (2017). Cybersecurity threats to IoT applications and service domains. Wireless Personal Communications, 95(1), 169-185.