Showing posts with label cyber attack. Show all posts
Showing posts with label cyber attack. Show all posts

Wednesday, September 21, 2011

Cyber Attack: The New Act of War?

Photo Source: http://ramkshrestha.wordpress.com
There have been a lot of cyber attacks incidents globally targeting both private enterprises and government agencies. Some limited to "seemingly harmless practical jokes” –such as defacing websites; while others involve serious DDOS attacks causing site downtime or information leak, translating to monetary losses in sales and advertising or worse classified data.

The most recent of these attacks is against Mitsubishi Heavy Industries, Japan's biggest defense contractor. MHI is the country's topmost weapon manufacturer from missiles to warships and submarines.

BBC reported that last August, MHI's 5 network servers and 38 PCs were infected with malware from an outside source, allegedly through spear phishing. The attacks infected 10 facilities across Japan, notably its Kobe and Nagoya sites which makes engine parts for missiles. While there is no lead yet as to the motive and the person behind the attack. The MHI assured the public that no sensitive information has been leaked.

Over the years of technological development, cyber crime has likewise evolved. What was once considered as a form of annoyance -such as the introduction of virus, have turned into destructive mechanisms destroying business networks and causing financial losses globally. However, what is alarming about this written attack is that the thrust of cyber crime is not about destruction anymore. It has shifted to information war, to be specific -stealing highly classified data, which could be valuable not only financially but more importantly politically.

As Matthew Lesko puts it, "Information is the currency of today's world. Those who control information are the most powerful people on the planet." Thus, we can only expect two things: more attacks in the future and the government as well as private entities taking active participation in online security development in terms of technology as well in law or policy.

News Source:  http://www.bbc.co.uk/news/world-asia-pacific-14982906

---
Entry No. 14

Wednesday, August 3, 2011

Operation Shady RAT (Remote Access Control)

The internet is perhaps the most dangerous place on the planet. No one is safe. Not even the United Nations.
Photo Source: http://www.presstv.ir/detail/163926.html
Security company McAfee, discovered the biggest series of cyber attacks in the last 5 years which involved the the infiltration of the networks of 72 organizations including the United Nations, governments (US, Taiwan, India, South Korea, Vietnam and Canada) and companies around the world. It believed there was one "state actor" behind the attacks but declined to name it, though the evidence "allegedly" points to China. (Source: Reuters)

Cyber attacks are perhaps as old as the internet. However, what is alarming about this report is that a "state actor" is involved in the attacks against various governments of different countries. Should the "state actor" be proven, could such cyber attacks escalate to a dispute under the principles of international law?

In international law, the state is responsible for all actions of its officials and organs, even if the organ/actor/official is acting ultra vires. However, before a state can be held responsible for any action, it is necessary to prove a causal connection between the injury and an official act or omission attributable to the state alleged to be in breach of its obligations.

In the case at bar, it is not clear whether the "hacker-state-actor" owed an international obligation to the injured governments under either a treaty or customary law. So far, the only relevant document regarding the matter is the 2007 resolution passed by the UN Disarmament and International Security Committee related to IT security concerns related to organized crime, terrorism and politically motivated cyber attacks. Take note that this is not even the General Assembly or the Security Council, but a Committee. Hence, no "force" so to speak.

While the use of all the illegally obtained data is still largely an open question, the need for an international legal framework to combat malicious or illegal use of information technology is called for by many sectors around the world. After all, we live in the age where information is power ---political or economic.


Entry No. 7
Soleil Flores

Saturday, September 25, 2010

IMHO: We should be prepared for Cyberwars and Cyber Attacks


My partner and I discussed cyberwars over running errands two weekends ago. He mentioned that there's a worm called Stuxnet that can make factory plants explode according to recent news. We discussed this while I complain about my laptop crashing down when it's nearing finals week. I was absentmindedly putting bread, spread, and hotdogs into the grocery cart thinking about how vulnerable these computer systems are. I was mentally listing things I do with my laptop and how I can still be productive without it. (I decided to just wake up early everyday so that I can use the library's computer for work and school for free--working in the library is productive.) Until, I realized, he was really trying to engage me in a discussion so that I will stop thinking about my laptop.

Over text, we exchanged messages talking about international relations and law--whether the UN Security Council will have jurisdiction over this, whether this is similar to the nuclear testing case by France, whether the High Court has jurisdiction, and others. I was thinking whether impunity will be enjoyed by the perpetrator. He decided to write a paper on it while I promised myself to read more about it (since the topic that was approved for my SLR was on the Automated Elections). Risks. Management. IT. Cyberlibertarianism. Just some of the things that got stuck in my head.

IMHO, people should read more about digital armory and how in the future, ICT risk management will be a lucrative niche of our generation.

Is Stuxnet the best malware ever? Will I ever get my laptop back?

Paulyn Duman
Blog #19