The Brave New World of InfoSec
A seasoned security pro's take on events around the world.
Taking a stroll down memory lane reaching back into my roots, I find a need to discuss the subject of Cyber Jihad or Firesale ( www.cyberfiresale.com ). Triggered by the recent viewing of ‘Live Free or Die Hard’ and the concept of an internet or cyber firesale, I find that this blog is an outlet for a subject that gnaws at me on a regular basis.
The combination of a physical and cyber attack using our own infrastructure is inevitable. Attempts have already been made and continue to be made.
It is easy to appreciate the devastation of a physical attack and what it can bring because as Americans, we need to see things in order to understand them. But we must not underestimate the potentially devastating consequences of an electronic attack, especially when used in conjunction with or as a precursor to a physical attack. It may be just that cyber attack that enables the physical attack. Just like our combined sea, air and land battle plans, ‘cyber’ is a core component.
Our first responders depend upon our electronic infrastructure in order to respond to physical attacks. If we suffer a devastating blow to our electronic capabilities that stymies our efforts to respond to the corresponding physical attacks, and clogs the cyber arteries we depend upon, there will be a new 9/11 report asking why once more.
In April of this year, a former engineer at the nation's largest nuclear power plant (Palo Verde Nuclear Generation Station outside Phoenix) was charged with taking computer access codes and software to Iran and using it to download details of plant control rooms and reactors. Using these codes could potentially combine the two (electronic/physical) for a massive loss of life and thousands of years of radiation contamination. Are you scared yet?
How many of the 9/11 attackers were from the Kingdom of Saudi Arabia? How many study computer science and engineering in the US? Thousands! When living in Saudi, several organizations required students to attend the University of Tampa not far from the US Special Operations Command and CENTCOM and of course, return to the KSA. Those who were corrupted by the infidels in this country faced significant scrutiny and pressure. Some linked to the royals even faced a potential stint in the ‘Rub Al-Khali or Empty Quarter. Regardless, the point is that when they return with their new found knowledge, they have no real job which turns to apathy, anger and attendance at the radicalized schools or as they are known in the West as madrasa (or school).
Electronic jihad sections of online jihadist sites host the cyber war information and gives up to the minute instructions or warnings of website penetration, suggestions for targets or timing of attacks, with detailed advice on the methods.
Follow me on Twitter http://twitter.com/jsbardin
Just to ensure you have the proper level of paranoia and fear, there is a book and movie entitled Ameristan by Charles Welty. The major premise is that the United States of America becomes a conservative Muslim state where Islamic Sharia is the law of the land. You can even download it for a small fee.
Pakistanis harbor Usama bin Laden and the rest of terror incorporated while we prop up a Shah Reza Pahlavi type regime that already has nuclear weapons. General Musharraf’s regime is on shaky ground. Pakistanis have since October 2001 attempted cyber jihad against the US. We all know what happened on Novermber 4, 1979 in Teheran, don’t we.
What will you do when the day comes? What will I do for that matter when we are hit? Are you and your security and risk teams read for such activity? Is our critical infrastructure prepared for such a hit that is not only multi-vector but multi-faceted in its approach? Will we be prepared? Inshallah bukarah
Are you considering implementing a proactive archiving and eDiscovery solutions? This paper summarizes 15 separate soft cost savings when implementing Symantec Enterprise Vault and the Clearwell eDiscovery Platform.
The report explores the correlation between the current use of patch management and the level of endpoint-related risk that companies are effectively accepting.