We have been flagging a threat to the entire WWW.
How the web could be shut down and highlighted proof of
concepts.
Our threat matrix looks something like:
5) Spam bots. dos attacks
5) Non state actors, Terrorist hackers
Desk threat matrix:
2) Then the programing items, rootkits, trojans software
3) Then the people: wetware.
Our cyber attack matrix is extensive and we haven't left the Desk yet.
Off the desk threats;
1) SLQ injections,
2) exploits,
3) social engeering,
4) malware, trojans,
5) rootkits, bots, virus,
6) other vectors of penetration.
Vendor Security programs cannot protect a PC connected to the WWW
today against penetration and invisible take over.
And against that threat matrix we ask the question:
"Can an attack of 1s and 0s be deterred, like a strike with tanks or missiles or bombs?"
Yes; but they imply that they want to track down the perp and attack him during the attack.
Their paradigm is twisted, they suggest that the PC's doing an DOS attack that have been turned
into bots, shouldn't be attacked, but the operators of the bots should be tracked and atacked.
So The swat team can't take out a sniper they have to find the owner of the buliding, and then
track the man that hired the sniper and take him out.
If your PC is turned into a bot, you should expect it to be taken out at least temporraly.
As a self defense, offensive measure. "Take out the Bots."
If someone picks up your gun and starts shooting, nothing is gonna happen?
If someone seizes your PC and attacks the US Government NETWORK, NOTHING DOES HAPPEN.
THATS NOT A DETERENT...
Part of the question is Psychological
And implys a counter threat strong enough to deter an attack.
Currently USA is the one of the softest targets.
Not much happens if you try and hack the Government networks.
Could a force with cyber weapons have enough threat to be a deterrent?
YES but you have to display that force, take down a herd of 1 million bots,
shutting all those PC's off for 24 hrs.
What cyber weapons are they talking about?
But will taking down a million bots deter them.
Now thats not going to deter the Bot herder? is it? But it willl get
better security installed on those PC's and get many of the Bots removed
by the owners.
And if a bot herder looses a million bots from attacking a US Network,
because the PC owners getting their pcs shut down, they will remove the bots,
that WILL deter the Herders.
Yes that is do able. If the Gov is prepares in advance.
Thinking outside the box and outside the room.
Its a chess game, set traps, triggers, Large heavy duty IT teams with access to
super computers.
Countering a bot DOS attack with a counter bot DOS attack can be productive,
but at some point bot counter attacks will just contribute to taking down the
WWW.
The other big concern are the inactive bot farms and right now the Gov.
response is a reactionary response, relpete with heavy investment in HR
to investigate attack.
There is a working paradigm to employ a method that just turns the Bot farms PCs off.
All the bots in that farm involoved in the attack are shut off.
There have been some interesting paradigm developements, First, I think it was the Army with a
The cyber attack and counter attack paradigms are like something out of a cyber war movie,
cool stuff, do able, but either the will is lacking or NSA already has it covered.
The Military still need their own cyber offensive capabilities, if only as a back up to NSA.
If NSA is on top of it the WWW will not go down on first attempt, but after that its all
paradigms and context. A second response attack will be based on new Intel and known defenses.
A sucessfull second strike will be a tremondus force multiplier.
This battle will be for the survial of modern Internet dependent countries.
The paradigm suggests the battle will center around shutting down PC's and activating
huge bot farms, co ordinating Dos bot attacks against the Internet cores.
Perdoic Internet outages, the first around 12 hrs down time then getting progressively
longer streaching into days and weeks maybe even months.
As the WWW is brought back up it automaticly engages the huge bot farms and DOS
attacks on the core, taking it back down again.
This is one NSA has to have right, and adjust paradigms and context as the battle develops.
If the second strike belongs to the USA then they will have won the battle.
Paradigm suggests expected first strike against the WWW 3 to 5 years based upon players and
curent capabilities.
Gerald
Tactical Internet Systems analyst
.
No comments:
Post a Comment