2017-10-06

Information Operation ongoing between US and North Korea

Briefly About the Operation

There is evidence that the US Cyber Command has denied the Internet access from North Korea for several weeks during September 2017. Simultaneously, US Treasury has been tightening the financial embargo around North Korea and tries to freeze their foreign assets and transactions. 

President Trump is acting as the “Bad Cop” in social media ("Military solutions are now fully in place, locked and loaded") while Secretary Tillerson is the “Good Cop” and seemingly has ongoing dialogue with North Korean authorities.

This operation is ongoing while North Korea is trying to create a credible threat of nuclear head (last nuclear test was done 3. September) on a ballistic missile (last launch 15. September) that can threaten US assets directly. The credible nuclear threat has been the goal for three generations of Kims to create leverage to both domestic and foreign policy. 

Some Notable Features Concerning the Operation until Today


  1. USCYBERCOM was suppressing the North Korean only Internet link (provided by China Unicom since 2010) with Denial of Service. The attack seems to have been effective since it lowered the activity of known North Korean hackers. This means that not all of them work abroad.
  2. The Denial of Service (DoS) was said to stop on Saturday, 30. September. On Sunday, 1. October, a new trunk connection appeared provided by Russian railway and telecommunications operator (TransTeleCom). The second link, coming from different Internet infrastructure entirely, makes it more difficult in future to disconnect North Korean’s from the Internet.
  3. Last year North Korea made several attacks targeting Financial systems like Swift. They succeeded to rob about $ 81 M from Bangladesh. The North Korean cyber strategy has seemingly been: 1. Steal sensitive information from other Governments and Industry (South Korean military intranet and governmental smartphones), 2. Create fear and insecurity by launching virus attacks (WannaCry), 3. Steal money to finance the government (Lazarus group attacked Banks for example in Bangladesh, Ecuador, Philippine, Vietnam).
  4. US sees their national electric grid vulnerable to advanced attacks like HAVEX or BlackEnergy. While the US executes the “cost imposition” strategy against Russian and Chinese actors, the same deterrence is not valid with Iran or North Korea. Thus, the US is trying to deny their capability to launch cyber-attacks. The denial is accomplished both by increasing the robustness of the information systems controlling the electric grid and exercising the capabilities in denying the access to the Internet or disabling the cyber arms available to these countries.

Used References:

  1. Karen DeYoung, Ellen Nakashima and Emily Rauhala (September 30): Trump signed presidential directive ordering actions to pressure North Korea. The Washington Post, National security. https://www.washingtonpost.com/world/national-security/trump-signed-presidential-directive-ordering-actions-to-pressure-north-korea/2017/09/30/97c6722a-a620-11e7-b14f-f41773cd5a14_story.html?utm_term=.1c6dc0b101b7 
  2. Michelle Ye Hee Lee (13 September 2017). "North Korea nuclear test may have been twice as strong as first thought". Washington Post. 
  3. North Korea 'fires missile from Pyongyang'. BBC. 15 September 2017.
  4. https://www.nytimes.com/2017/03/04/world/asia/north-korea-missile-program-sabotage.html 
  5. Martyn Williams (October 1): Russian provides new Internet connection to North Korea. 38North. http://www.38north.org/2017/10/mwilliams100117/ 
  6. CSIS: North Korea's Cyber Capabilities. https://www.csis.org/programs/korea-chair/korea-chair-project-archive/north-koreas-cyber-capabilities 
  7. Charles Riley and Jethro Mullen (16 May): North Korea’s long history of hacking. CNNTech. http://money.cnn.com/2017/05/16/technology/ransomware-north-korea-hacking-history/index.html 
  8. US DoD Defence Science Board (February 2017): Task Force on cyber deterrence. http://www.acq.osd.mil/dsb/reports/2010s/DSB-CyberDeterrenceReport_02-28-17_Final.pdf

2017-09-19

Large Scale Broadpwn Vulnerability in Android and iOS Wi-Fi Connections

Definition

Billions of smartphones, both Android and iOS have the same Wi-Fi chipset from Broadcom (BCM43xx family). A recent study presented at Black Hat conference has revealed a major vulnerability in that chipset that opens the smartphone to attacks via Wi-Fi connection. The vulnerability is open on all devices before the versions iOS 10.3.3 (released 20 July) or the July security update for Android, which contains fixes for the flaw. The vulnerability allows an attacker to gain access at the chip level and write programs that can be running on that chip. The targeted phone or user does nothing additional nor does the user notice that device has been exploited.


This vulnerability is first of this kind of exposure (all iOS devices after iPhone 5; all Samsung Galaxy from S3 through S8, inclusive; all Samsung Notes 3; all Nexus versions 5 – 6P), exploiting peripherals not core, does not need any action from user and can be used as a network for worm.

Brief Description

The resourceful attacker develops a worm that exploits the vulnerabilities of the BCM 43xx chips. The attacker presents himself in some event that has many high-ranking officers attending. The attacker infiltrates few of the smartphones (requires only activated Wi-Fi) and installs the worm. When officers return to their command posts and headquarters, their smartphones start to infect other devices within the Wi-Fi range. After few days, the higher commanders and their staffs’ smartphones are prepared for the next phase. 


The attacker, depending on the situation, can exploit the remotely controllable botnet (networks of remotely controlled robots) either collecting all information achievable through microphones and sessions or, in the brink of attack, suppress all smartphone usage of affected officers. This may delay or disable to the reaction of the higher-ranking officers enough to gain the advantage on ground, air or sea (recall the reason for slow German response to the invasion of Normandy).

Recommendation


End-users and administrators:

  • Update all possible Smart devices with:
  • Android: 2017-07-05 security patch
  • iOS: 10.3.3

Military system architects:

  • Broadpwn is a textbook example of using a large surface with a small but innovative effort to tap sensitive information or suppress main information flows. 
  • Military architects should always provide strategic variety for critical information flows and mitigate the single points of failure.

Military Chief Information Officers:


  • No one mean of communications of information processing can be reliable enough. 
  • Always require parallel, independent options for business continuity.


References:


  1. https://www.wired.com/story/broadpwn-wi-fi-vulnerability-ios-android/
  2. https://www.theguardian.com/technology/2017/jul/27/broadpwn-smartphone-malware-bug-iphone-samsung-google
  3. https://blog.exodusintel.com/2017/07/26/broadpwn/

2017-09-15

Watch you Bluetooth usage!

There are BlueBorne vulnerabilities in Bluetooth connections


Definition

Bluetooth technology has been in use since early 2000, and over 8.2 Billion devices are using Bluetooth. Some of the older versions of Android, iOS, Windows, and Linux implementations have a vulnerability that enables remote commands on the target device. There are together eight vulnerabilities that are called BlueBorne. These vulnerabilities were found during Spring 2017, communicated to responsible manufacturers and have been patched in the latest revisions.

Brief Description

The attacker approaches the proximity of the Bluetooth device and connects through Bluetooth wireless connection using buffer copy, buffer overflow, integer underflow or Man-in-the-Middle attack to gain access to the target device, injects malicious software or captures user information.


Worst case is when an advanced attacker reconnoitres the target infrastructure and deploys a worm that uses BlueBorne vulnerabilities to spread over-the-air. Especially, air-gap isolated systems are vulnerable if the Bluetooth is not disabled.

What to do:

The following measures are recommended to mitigate the BlueBorne exploitation: 
1. Update all possible versions concerning the found vulnerability in:
  • Android: Before September 2017 updates
  • Windows: Before September 2017 updates
  • iOS: Pre-version 10
  • Apple TV: Pre-version 7.2.2
  • Linux: Before September 2017 updates
2. If the update is not available or not possible to upload, user should consider disabling the Bluetooth

3. There is a possibility that Bluetooth has other unrevealed vulnerabilities, so the professional organisation should control the proximity of their systems.

References

1. www.kb.cert.org/vuls/id/240311
2. www.armis.com/blueborne/



How military defend against commercial drones?

Threat of drones

Within a few past years, there has been a rise in the number of incidents involving small unmanned aerial vehicles (UAV, i.e., Drones). Insurgent forces in Syria and Iraq together with regular armies in Ukraine have used commercial drones to reconnoiter or strike targets. The defence industry is introducing various means to counter the UAV’s using force, signal hijacking, directional RF interference, directed energy, or other drones.

A Ukrainian serviceman operates a drone during a training session outside Kiev, November 6, 2014. © REUTERS


Iraqi troops are showing commercial drones used by ISIS in Mosul. © CENTCOM

Blunt force

A basic and low-tech solution is to knock out the drone with another object. SkyWall100 system from OpenWorks Engineering is a man-portable compressed air launcher that fires a 22-pound net to capture the drone and parachuting it down.

Signal hijacking

A more delicate countermeasure is to infiltrate and seize the command channel between the remote controller and the drone. The captured drone can then be guided to land in the safe zone. MESMER from Department 13 and UAV D04JA Jammer from Chinese Hikvision are systems that can take over the control of a UAV and direct it to safety.

RF interference

The more longer-range situation requires a system capable of detection, tracking, and disruption. A British made AUDS can detect a drone from 8 km away, track it and disrupt its flight by using radio frequency jamming. A French BOREADES system is an integrated system that uses radars, day-night optronics and UHD video to detect the drone and intercepts it by jamming or luring the navigation system onboard.

Directed energy

In a situation of multiple drones approaching the target at the same time, a straightforward countermeasure is to shoot them down with directed energy weapons. USS Ponce is already hosting the Laser Weapon System (LaWS) to counter threats from small boats to drones. Rheinmetall has laser-based products to counter both commercial and military drones. Chinese researchers have demonstrated a system in 2017 Black Hat conference that uses audible sound and ultrasound emitters to disrupt the microelectromechanical systems as accelerometers and gyroscopes on board a drone.

Other drones

There are several solutions of using other drones to capture hostile drones. One of them is the Drone Interceptor MP200 from Malou Tech that uses a net to capture the approaching vehicle.

Geofencing or electronic wall

The drone manufacturers program their drones not to enter denied areas.  The global positioning signals can be jammed to keep the drones entering denied areas.

Rules of Engagement

US DoD has issued a policy to military bases that they have full legal rights to shoot down private or commercial drones seemed to be a threat. This may apply to other separated military zones, but amongst the people and in public sites, the less violent measures need to be available.

RGP armed drone shot down by Syrian troops © ThinkDefence.co.uk

All US Army troops in operation develop a sensor plan that deploys both passive and active countermeasures against hostile drones. The action is straight forward: "Units must attempt to engage and destroy the UAV using any organic means available, typically small arms fires organic to the unit while simultaneously relocating the unit."
Some airports in Ireland have established a “no drone zone” which is a control measure to ensure there are no drones around departure or approach routes. If a drone is sighted, aircraft is put on hold to clear the path.
Police officers in the UK can only instruct the drone operators to land if they approach sensitive sites or become a safety issue.
Israel Defence Forces do shoot down Hezbollah drones violating Israeli airspace.


References:

Pomerlau, Mark: Army releases counter-drone training document. C4ISRNET. 25. April 2017. http://www.c4isrnet.com/unmanned/uas/2017/04/25/army-releases-counter-drone-training-document/
Defence IQ press: A timeline of the rising small UAS threat. Defence IQ 10.2.2017
https://www.defenceiq.com/defence-technology/articles/a-timeline-of-the-rising-small-uas-threat
Dutta, Sumit: This is how militaries can defend against drones. Defence IQ 14.8.2017 https://www.defenceiq.com/news/this-is-how-militaries-can-defend-against-drones
Goarant, Barbara: CS presents BOREADES. CS official pages. http://www.c-s.fr/CS-presente-BOREADES-son-systeme-de-lutte-anti-drone-a-l-occasion-de-la-demonstration-dynamique-organisee-par-le-SGDSN_a765.html
Silva, Richard De: No Drone Zone. Defence IQ September 2016. https://plsadaptive.s3.amazonaws.com/gfiles/_nilr3emag_-_countering-drones_-_defence_iq_-_oct_2016.pdf?response-content-type=application/pdf&AWSAccessKeyId=AKIAICW5IOYOPOZOU3TQ&Expires=1505470510&Signature=9HweRD7Pn612TpoQ1Dn54DhID6U%3D
Pavluk, Joshua: Four counter-drone technologies we need now. TechCrunch, 23. February 2016. https://techcrunch.com/2016/02/23/four-counter-drone-technologies-we-need-now/

2017-08-31

Russian Turla Group Attacks at Governments and Diplomats

Definition

Russian Advanced Persistence Threat group called “Turla” has been using special espionage attacks against Governmental agencies and Embassies for past year. The backdoor software has been recently detected and “Gazer or Whitebear.” It is very clandestine malware trying to be as unnoticeable and undetectable as possible. The backdoor software collects information from the target and sends it to the controller.

Brief description of scenario

Gazer is distributed via spearphishing email that infects the target with first stage backdoor such as “Skipper.” Skipper downloads Gazer as the primary payload. Gazer uses 3DES and RSA encryption and stores its configuration within the Windows Registry. Gazer wipes files, changes code strings and looks like a video game to remain secret.

Mitigation

The following are some security measures recommended to lower the probability of Gazer type attack: 

  • Security architecture should include several layers to create depth for cyber defence
  • The security operations should be able to monitor 24/7 the traffic flow from and to defended domain
  • There should be more than one layer of virus detection using different detection applications
  • End users should be trained for awareness against phishing attempts



References


  1. https://www.welivesecurity.com/wp-content/uploads/2017/08/eset-gazer.pdf
  2. https://threatpost.com/turla-apt-used-whitebear-espionage-tools-against-defense-industry-embassies/127737/
  3. https://www.scmagazine.com/turla-apt-group-linked-to-gazer-backdoor-that-spies-on-embassies/article/685230/
  4. http://securityaffairs.co/wordpress/55915/apt/turla-javascript-malware.html
  5. https://www.cyberscoop.com/kaspersky-whitebear-turla-russia/

Wireless Local Area Network Man in the Middle Attacks

Definition

Open wireless local area network (Wi-Fi or WLAN), connections in café's, hotels, malls, airports, airplanes and other public places, provide easy and free access to the Internet with a wider bandwidth. Unfortunately, an open and unsecured wireless local area network allows anyone to receive victims traffic and launch a Man in the Middle attack (MitM). Even if the victim is securing the communications for essential services, unsecured communications may reveal the victim's password if they are reused in several services.

Brief scenarios

A hacker creates an “evil twin” Wi-Fi access point in the same premises that open Wi-Fi is expected. Once a victim launches unsecured sessions, a hacker can capture all traffic. Another way is to listen to the public Wi-Fi traffic over unsecured access and sniffing “session cookies” to acquire passwords. If the victim further allows file sharing over the Wi-fi, hacker plants software into the targetted device to execute malicious deeds.
Even if the Wi-Fi access is secured, but the password given to the public is simple, seldom changed or easily cracked, a hacker can obtain the traffic.

Protection

There are the following ways to prevent a probable Man in the Middle attack:

  • Use Virtual Private Network but acknowledging that researchers have studied 283 free VPN apps on Google Play and found that 50% of them store client’s traffic for their use, 38% of them injected malware or malvertising. About 18% of them did not encrypt the traffic. So, use only professionally provided VPN services (Ikram et al., 2016).
  • Use Secure Sockets Layer (SSL), i.e., sessions using https.
  • Turn off sharing by choosing ‘Public’ option from Operating System
  • Keep Wi-Fi off when not using it.


References

1. https://usa.kaspersky.com/resource-center/preemptive-safety/public-wifi-risks
2. http://www.huffingtonpost.com/michael-gregg/six-ways-you-could-become_b_8545674.html
3. http://www.npr.org/sections/alltechconsidered/2017/08/17/543716811/turning-to-vpns-for-online-privacy-you-might-be-putting-your-data-at-risk
4. http://www.icir.org/vern/papers/vpn-apps-imc16.pdf

2017-08-19

Controller Area Network (CAN) standard ISO 11898 data link vulnerability

Description

The Controller Area Network, CAN is the most common (in US the only legal) intravehicular databus standard ISO 11898-1993 for road vehicles. It allows all “Things” within the vehicle to communicate with each other. A university level research (Palanca and Zanero, 2016) has found that normal protocol at CAN link layer intended to handle malfunctioning nodes can be manipulated. 

Since the MILCAN (Open standard for military vectronics) is based on same ISO 11898, although rugged, there might be similar vulnerability within military vehicles (Majoewsky and Davies).

Case of exploitation

An attacker couples into CAN bus, receives the error frames, multiplies and forwards them further causing a Bus Off State to targeted subsystem. This means that targeted system is not listened anymore within the CAN bus i.e. the vehicle does not function as system of systems anymore. 

The coupling is easiest accomplished by connecting additional device into vehicle CAN bus. There is also possibility to use some wireless devices attached to CAN bus. In civilian vehicles, this may happen through Infotainment devices (radio, mobile phone) as happened in Chrysler Jeep hacking 2015 (Miller and Valasek). In military vehicles the vectronics is used more widely to connect sensors, weapons and C3 systems to vehicle. Thus, direct ways to effect the bus are available. Would there be one worm that can take down the fleets of military vehicles when they are dearly needed?

Mitigation

There are no software updates available and since the vulnerability is in the standard protocol itself, it requires to be changed. There may be some technical mitigation measures as follows:
  • Network segmentation or topology alteration
  • OBD-II diagnostic port access
  • Encryption