Cyberespionage, Cyberattacks Equals Cyberwarfare

by Daniel McNeet on July 4, 2012

Good day, good people.

For devotees of the English language: Bewray is a transitive verb. It means to betray or reveal a secret with prejudice.

Is the United States more vulnerable to cyberattacks and/or cyberwarfare from other nations, surrogates, or companies now that America has participated in an unprovoked-pre-emptive cyberattack against the infrastructure of another nation — Iran? Has the U.S. and Israel started cyberwarfare?

Did you know that cyberwarfare is in progress — but it is silent? If you had the ability to develop malware, a Trojan, worm or virus, and/or create kinetic destruction which would defeat the Iranian uranium-enrichment program for the purpose of developing a nuclear weapon would you?

The world has been involved in unrestricted warfare without a declaration since 1998 which includes cyberwarfare. The U.S. participated in launching a successful cyberespionage penetration into Iran in 2008. It was done in the belief it would impede Iran’s nuclear-weapons program. The motives of cyberattacks and cyberwarfare are to motivate, persuade and/or conquer an opponent. The question is: will the sanctions, Iran’s vulnerabilities to cyberwarfare and the impeding of Iran’s uranium-enrichment program bring Iran to an agreement with the rest of the world regarding the abandoning of its nuclear-weapons program and verification by inspection by the International Atomic Energy Agency, IAEA, of all facilities civilian and military?

Retrieving accurate information is almost impossible, particularly if it comes from a government. Whether you are in or out of Israel’s Mossad, the CIA or the National Security Agency, NSA, or any other intelligence agency retrieving accurate information is difficult to confirm because of a need-to-know environment. What you believe does not make it accurate. All you can do is take what is available, logic and motive and piece them together with a little help from others. This is what I have done with the help of some cybersecurity experts.

During the final year of the George W. Bush administration, a virus was developed to penetrate highly-secure networks in Iran code-named Olympic Games. Once it was in place, it retrieved and transmitted to its creator secrets. It could replicate, activate Bluetooth wireless technology and use it to send and receive commands. The code logged key strokes, geolocation data from images, took screen shots and activated computer microphones and cameras. When it was discovered by the Russian security company, Kaspersky Lab, they named it Flame. It had been hidden in a Microsoft Windows 7 update. It was designed to crack an encryption algorithm, and it was successful for several years.

The secrets retrieved by Flame laid the ground work for the development of the malware worm Stuxnet. It is smart and adaptable. The security system of the computer target is retrieved. It only attacks certain management systems and targets. Rather than destroying the systems, it misleads while it is causing ruin of test samples of uranium. Stuxnet infected the German company Siemens’ supervisory control and data acquisition system in Iran’s uranium enrichment plant in Natanz, Iran. The malfunctioning of the centrifuges spinning faster and suddenly stopping wore them out earlier than expected. No computer worm can destroy Iran’s nuclear program only delay it. If kinetic destruction could occur, the centrifuges and other equipment would have to be replaced.

Siemens conspired with the Russian company Atomstroyexport to violate United Nations sanctions by shipping key parts to Atomstroyexport knowing the company was working for Iran on its nuclear program. Siemens set up a commercial partnership with the Russian company.

The German company Siemens supplied their industrial centrifuges and software to Iran. Siemens had been working for Iran before the Russians took over. The centrifuges were used to enrich uranium so it could produce nuclear weapons. It is believed Flame and Stuxnet were developed by the U.S. and Israel. The penetration by Stuxnet ultimately caused the centrifuges to spin at excessive speeds. This impeded Iran’s uranium enrichment program. You might ask why would Siemens do this in violation of U.N. sanctions? The answer is: money, but if they had not another company would. Fortunately, for the world Siemens did.

In 2008 Siemens worked with the Energy Department’s, Idaho National Laboratory, INL. Later it formed a partnership with Siemens. The Energy Department is responsible for the development of our nuclear arms. INL identified cybervulnerabilities of Siemens’ computer controllers. As a result, the vulnerabilities were used to develop Stuxnet. It caused about one thousand centrifuges to be taken out of service. Also, it produced readings for the operators of the plant to believe the spinning rotors in the centrifuges wobble were performing normally so the safety system would not shut the plant down before the centrifuges slowly destroyed themselves.

Why should countries and companies which need high technology spend hundreds of millions of dollars on research and development if they can get it at a deep discount or free from the technology goldmine — the United States of America? They just mine it with cyberespionage software — illegally penetrating insecure networks. The networks belong to the U.S. government agencies and companies which are defense contractors and others doing classified research.

General Keith B. Alexander, head of the military’s Cyber Command, said cybertheft has been “the greatest transfer of wealth in history.” The former lead agent at the FBI on cybercrime said one American company had spent ten years and a billion dollars on a research program, and the data was stolen by a hacker in one night. Cyberattacks-cyberterrorism will replace noncyber terrorism as the FBIs first priority. This activity is destroying our competitive lead in the world and costing American jobs.

This is particularly true of China. It is building a navy. It has already stolen U.S. attack submarine technology. They also want our warship propulsion systems and everything else they can mine. They want to be able to be on a par with the U.S. Navy in the South China Sea and the Indian Ocean. They also want any and all technology they can steal — faster and less expensive than their own research and development programs.

Security firms are not perfect or maybe they are incompetent, inefficient and/or ineffective. Whichever, never believe your firewall is secure. Ninety-four percent of the companies supposedly protected by the computer-security firm Mandiant were unaware they had been penetrated. Was Mandiant taking money under false pretenses, lazy or not qualified to be in the business? Government-owned National Laboratories, Citibank, Lockheed, Booz Allen, Google, EMC, Nasdaq, and Sony have all been penetrated. There are many other companies which have been, but refuse to admit it.

Members of Congress with its lack of expertise and/or will has refused to protect the United States and its companies for the past decade, because they fear privacy-rights and Internet-freedom advocates. This is an excuse for their lack of ability to know how to do it correctly without causing the fears of the advocates. It is all right to leave our computer-controlled infrastructure vulnerable as long as they get reelected. After all, we do not wish to offend China. It might point out a vulnerability among a myriad in our infrastructure by accessing it, and then giving us a demonstration which would cause our nation to finally get a wakeup call. Unfortunately, we live in a crisis society. We do not believe in spending money on prevention which by the way costs less than correction. Therefore, we will do nothing until there is a crisis which will surely come just like the rising of the sun tomorrow morning.

The president has the right to use a finding pursuant to the Intelligence Act. All the agencies in the intelligence services should be authorized to scan Internet traffic outside the U.S. borders and seize data stolen from within our borders. The Department of Homeland Security should inspect what enters and leaves the U.S. in cyberspace, too.

Another threat is the illegal sales of U.S. technology by American companies to foreign entities. United Technologies Corp in Hartford, Connecticut and two of its subsidiaries, Pratt and Whitney Canada and Hamilton Sundstrand, sold embargoed software and components to China. They were used to build the Z-10 sophisticated helicopter. The CEOs were not prosecuted the company just paid a fine. Why?

Employees and/or contractors bewray proprietary technology of U.S. companies. It is one of the most dangerous threats to national security. Stealing documents and downloading files onto portable drives is increasing. Dual-use technology and military-grade equipment are prime targets for theft and sale. Economic espionage is growing rapidly. It appears loyalty to country is only money deep.

President Obama must act now to protect American companies from China, other countries and companies cyberthreats.

What is your thought on the contribution you can make by urging your members of Congress to protect our vulnerable infrastructure?

In my opinion, friendship and love are surpassed only by loyalty to country.

I hope this post will give you something to consider. To be successful you must understand other people’s opinions and care about them.

I care about your opinion. Contacting me with comments and constructive criticisms at Daniel McNeet with honesty and pleasantness their constant companions will always be welcomed.

Cyberstorm Brewing

{ 0 comments… add one now }

Leave a Comment

Previous post:

Next post: