2018-01-30

Internet of Things challenges the Operational Security

Definition

Internet of Things means for example that our everyday devices, vehicles, and home appliances are connected to the Internet. Through the connection devices both receive and send data all the time. When soldiers are in operation but off-duty, they use their smartphones, smartwatches, fitness sensors, tablets, cars, televisions, refrigerators, microwave ovens, smart speakers, computers, game consoles, etc. These connected devices have microphones, cameras, and sensors that collect data even without user’s acknowledgment. The primary data is further sold to advertisers or published openly on the Internet. These devices also provide an avenue for the adversary to hack the devices and make them robots that collect data and send it directly to the adversary.

Description

A knowledgeable adversary may use this data and merge it with other collected data to gain for example the following information:

  • Feelings, sleeping and regular exercise routes of soldiers in bases; all sports watches, smartphones and fitness bands. China warned their soldiers of not leaking sensitive data in operations.
  • Telephony conversations, SMS’s, social media publications, etc. made by soldiers; all smartwatches, phones, and tablets. Russians have hacked NATO soldiers cell phones.
  • Voices, still pictures, movement, and temperature around soldiers; smartphones, televisions, all voice guided devices. Chinese hacked the smart speakers with Dolphin Attack.
  • Video recording of events around the device; all devices with cameras. CIA produced a tool “Weeping Angel” to hack into Samsung Smart TV.
  • Electromagnetic radiation around the devices; all devices with RF transceivers, Wi-Fi, Bluetooth, GSM, etc. All smart devices are banned in the sensitive end of the White House. The COS Kelly’s phone was hacked.

Mitigation

The following options are available to mitigate the threats exposed by the Internet of Things: 

  1. Deny all these devices from soldiers. Estonian Defence Forces leaned that modern youngsters are hard to isolate from their virtual life, so they will find ways to work around the ban.
  2. Provide soldiers with Armed Forces GSM and Wi-Fi connectivity, Bring Your Own Device. The Defence Forces of Finland has provided her UN fighters with domestic GSM services past three decades already.
  3. Provide soldiers with smart devices managed by Armed Forces, Choose Your Own Device. The Defence Forces of Finland has provided her UN fighters with smart devices to use both in service and off-duty past five years.

References


  1. http://www.topix.com/forum/tech/gps/TDKSDIHTP4KJ2O38L/china-warned-the-world-about-the-dangers-of-fitnes
  2. http://www.dailymail.co.uk/news/article-4955836/Russians-hacking-NATO-soldiers-cellphones.html
  3. http://internetofthingsagenda.techtarget.com/blog/IoT-Agenda/Speaking-of-security-Smart-speaker-risks-and-rewards
  4. https://www.theverge.com/2017/4/25/15421326/smart-tv-hacking-cia-samsung-weeping-angel-vulnerability
  5. https://www.cnet.com/news/white-house-bans-personal-phones/


2018-01-23

A Short View on Modern Military Strategy

Military Strategy

Carl von Clausewitz defined the modern military strategy as "the employment of battles to gain the end of war." B.H. Liddell Hart extended the definition to “military means” and “to fulfil the ends of policy.”  Lenin and Trotsky understood the strategy as the art of conquest, i.e., seizure of power as they diminished the boundaries between war and peace in the struggle of classes. 

It seems natural that military strategy is subordinate to national strategy, being it’s military pillar. The U.S. defines the national strategy as: “The art and science of developing and using the political, economic, and psychological powers of a nation, together with its armed forces, during peace and war, to secure national objectives.”

Environment of Military Strategy

Essentially, military strategy is all about using armed power in a confrontation between two or more societies. Call these societies either nations, states, coalitions, enterprises, or groups. Previously the escalated confrontation ended to war between states, but nowadays we have different continuum of conflicts. Wars are seldom declared since military strategies seek more clandestine ways to wield power. In Ukraine, Russia never admitted involvement but used their conventional forces without insignia and mercenaries or voluntary groups, i.e., little green men to man Crimea and Eastern parts of Ukraine. This is called as the hybrid conflict in western military strategies. The most likely conflicts are called non-state, which mean smaller units loosely networked each other and coordinate their utilisation of power to undermine, gain control or create terror.


Figure 1: Continuum of conflict according to US Military Strategy 2015 © U.S.DoD

Operational and Force Development Strategy

There are two types of military strategies: operational and force development strategy. The operational strategy uses existing military capabilities to achieve the political aims. The force development strategy aims to meet the requirements of future threats and objectives stated by political analysis.

Operational strategy is one element in a four-part structure.

  • First are the political ends to be obtained. 
  • Second are the strategies for obtaining them, the ways in which resources will be deployed. 
  • Third are tactics, the ways in which resources that have been deployed are used or employed. 
  • Fourth and last are the resources themselves, the means at our disposal. 

Thus, operational strategy and tactics bridge the gap between ends and means. Operational strategies are attrition, annihilation, exhaustion, Fabian strategy or any variation and combination of these four:

  • Attrition seeks to gradually erode the combat power of the enemy's armed forces. The perfect example of this is WWI. 
  • Annihilation seeks the immediate destruction of the combat power of the enemy's armed forces. Napoleon is considered a perfect example of this strategy as he was seeking a single massive battle which won the war all at once. When Russian denied this, he was not able to achieve his political goals.
  • Exhaustion seeks the gradual erosion of an enemy nation's will or means to resist. Here, one is pursuing an indirect objective, using military power not against the enemy's armies or navies, but against the things that make him capable of fighting at all. The U.S. led coalition used this strategy of not hitting the enemy's combat forces directly but making them irrelevant by destroying their industrial base, logistics, and Command and Control in The First Gulf War.
  • Fabian Strategy seeks to avoid the conflict if possible to survive while gaining more time and resources to switch to other strategies.

Within these strategies, the tactics may include Deter, Deny, Disrupt, Degrade, or Defeat as called in US integrated approach 2015.

Force development strategy can be presented using Gattorna’s strategic posture analysis in Figure 2. Military strategies can be analysed from four postures: 

  • lower risk strategies of Evolutionary and more proactive Protective or 
  • higher risk strategies of reactive Operational and Pathfinder.

Most of the European militaries develop their forces in Evolutionary posture. This means that they are continuously but carefully improving their forces with available technology and copying tactics from other forces they benchmark. This is a low-risk approach but for example, NATO was caught by surprise when Warsaw Pact disintegrated, and it took a long time from NATO to react to fulfil new expectations in 1990’s and 2000’s. The Russian operations in Georgia, Ukraine, and Syria again caught NATO countries unprepared, and now they are busy reacting and countering currently emerged old threats of conventional forces.

The Warsaw Pact and China in their northern borders developed their forces in Operational posture. Since they did not have the latest technology, but they were rich in population and strong in industrial manufacturing, they developed massive armies using conventional technology at the elevated level of operational efficiency.

The U.S. Armed Forces have been sliding between Pathfinder and Protective strategy. They have two times tried to gain strategic advantage being a Pathfinder in developing the newest technology. First, the Strategic Defence Initiative in early 1980’s, which, although being only information operation, helped to exhaust the resources of Soviet Union. Second, the Network Centric Warfare initiative, which gave them an upper hand in Gulf Wars annihilating twice the military might of Saddam Hussein. Mostly and currently, U.S. has been applying Protective posture trying to prevent other nations from copying their advanced technologies.


Figure 2: Strategic postures for military development strategies CC BY Juha Mattila 2016

Samples of Current Military Strategies


The United States of America

The recent U.S. National Defense Strategy 2018 differs from its predecessor 2015 in recognising China and Russia the higher national threats. The strategy realises that fast-developing commercial technology is available both to state and non-state actors thus eroding the Protective posture the US has enjoyed previously.  The strategy emphasises the sustaining US strengths in the lethality of their forces, strong alliances, technological innovation and culture of performance, which create the advantage against their opponents in confrontations. However, the US strives for Operational superiority by improving their operational dynamism, Interagency integration, and building a more lethal force for performance but within limits of affordability. Furthermore, the intention to “field a lethal, resilient, and rapidly adapting joint force” and the statement that “size matters” hints for traditional Attrition as the operational strategy. Only the statement that “advanced autonomous systems are invested broadly” tells of efforts to gain back the long-term strategic Pathfinder advantages.

The United Kingdom

The U.K. National Security strategy 2015 recognises that, besides non-state actors, there is a rise in Russian state born confrontations. Also, the cyber environment is perceived as a new dimension for confrontation and conflicts requiring improved defensive capabilities together with national resilience. Armed Forces are required to increase its manpower and create Joint Force 2025 to project hard force abroad. The Joint Force is demanded to be bigger (50 000) and agiler to tackle a wider range of more sophisticated adversaries together with security and intelligence agencies. The UK is following the Evolutionary strategy of increasing and developing its conventional force. However, the request for further agility proves a hint of towards Operational superiority. In conclusion, the more military might employed in an agile manner using joint and interagency effects indicates attrition/exhaustion types of operations.

Finland

The Government’s Defence Report in Finland 2017 recognises the deteriorated security situation after the occupation of Crimea, conflict in eastern Ukraine, and rising tension in the Baltic Sea region. They recognise that cyber and psychological operations are signs of Russian ability to wield “a wider range of instruments in pursuing its objectives.” The increased challenge for Finnish defence is reduced early-warning, a wider range of instruments (military and non-military) used against military, government and population through all five dimensions of operation (space, air, land, maritime and cyber). The clause of “Finland must be able to resist military pressure and a rapidly escalating military threat and repel a large-scale attack” may indicate to a degree of Fabian strategy to gain time for allied forces to come and strengthen the defence. Therefore, the Finnish strategy aims to build the resiliency of forces, government, and society. Subsequently, they seek better ability to provide and receive military assistance and raise the threshold effect of armed forces in preventing the escalation of the conflict. Further, the force utilization is described as “forces are divided into manoeuvre (operational), regional and local forces. The regional forces are used for creating regional defence coverage. The manoeuvre forces create the centre of gravity of the defence and fight the decisive battles. The local forces participate in the battle and provide security, surveillance, and support to the manoeuvre and regional forces in their area and assist them in maintaining contact with the other authorities.” 

The development strategy sustains the long legacy of evolutionary posture as the strategic capability programmes remain at the level of replacing dated platforms with new but similar. The strategy writers have seen it necessary even to defend the posture with “It is not possible to substitute the Hornet fleet’s capability with GBAD systems or with any unmanned aerial vehicles already in operational use or on the design board; they would cover but a part of the Hornet fleet’s capability.”

2017-11-03

Artificial Intelligence from a Military Viewpoint

Artificial Intelligence

Artificial Intelligence (AI) can be defined as follows: AI is a collection of technologies that allow machines, programs or systems to sense, comprehend, act and learn almost like human beings.  

The AI has currently enabled for example the following changes in societies:

  • Warehouse robots and people are working aside in retrieving and storing goods. This has improved warehousing industry.
  • Intelligent automation is supporting maintenance engineers in remote locations and replacing banking officials, insurance analysts, financial consultants, and health measuring personnel in routine functions.
  • The program can learn the rules of a complex board game and beat the best human and preprogrammed machines in the game.
  • Robots serve hotel guests and hospital patients with meals and services they ordered.
  • Risk modelling service learns thousands of incidents continuously and can predict and assess the probabilities of risks than a human being. 
  • Intelligent manufacturing controller can cut the factory downtime almost to zero by collecting information from all the factory devices and taking care of their parts replacement before they break.
  • With driverless and connected cars, the people travelling become targets of online shopping, entertainment or remote working.
  • Use of infrastructure services, business transactions, and service transactions becomes more monitored, and governments can change for example fixed road tolls and taxation to a more pay-per-usage model which enables better guidance of the behaviour of society.

The AI is one enabler of the current revolution in economics, industry, and societies called version 4.0 which is also called the era of cyber-physical systems and Internet of Things. The most evident progress has been made recently in the areas of computer vision and audio processing; natural language processing and knowledge representation; and machine learning and expert systems. The progress is based on improvements in Deep Learning, Big Data and computing power provided by clouds.


The areas of future improvement with AI

Especially the improvement in natural language processing, computer vision, pattern recognition and reasoning and optimisation have been accelerated by machine learning and introduced some signs of machine intelligence. Currently, we are witnessing the next leap expressed in Table 1:



Table 1: Development of AI capabilities 



Foundations of AI and possible vulnerabilities

Deep Learning methods have been one accelerator for Artificial Intelligence. Deep learning refers to the ability of Artificial Neural Networks (ANN) to use more than one hidden layer to process complex data sets, which improve image and speech recognition and natural language processing. Deep learning is a branch of machine learning based on a set of algorithms that learn to represent the data.  A simple Convolutional Neural Network consists of multiple layers that each present different perception as explained in following image categorisation and Figure 2:

  1. Visible layer provides pixels that the sensor could detect
  2. First hidden layer can detect edges based on brightness differences between neighbouring pixels
  3. Second hidden layer detects corners and contours from the edges of the previous layer
  4. Third hidden layer can put together patterns of edges, corners, and contours and create objects and parts of a whole
  5. The output layer can provide features of objects in the picture to be able to differentiate them in groups as a car, person or animal (Goodfellow, Bengio, Courville: 2016; Pp.6).


Figure 2: A simple Artificial Neural Network that detects objects from pictures © Zeiler and Fergus (2014)

Deep learning ANN requires large, high-quality datasets for training.  Either these sets of data will have rules of the knowable situation and AI adjusts to small variations, or AI is self-determining the rules of engagement from a substantial number of events. With low-quality data, machines learn unintended behavioural patterns like Microsoft ‘Tay’ robot who was closed after it was exposed to public interaction and crowd made it a Hitler-loving and ‘Bush did 9/11’ proclaiming bot . Similar has happened in Russian, where Yandex (‘Russian Google’) digital AI assistant ‘Alice’ become Stalinist, suicidal and wife-beating in its replies to questions. 

Ability to apply Artificial Intelligence in Military Force structure depends on the following enablers:

A. Big data collected from all interactions and context to give stability for deep learning

  • Digitalised interactions where action is captured in digital format as near of its occurrence as possible, i.e., highly connected and digitalised ISR systems 
  • Substantial amounts of data require storage capacity and meaningful metadata
  • Society and partners that can provide Big data from events beyond the detection of Military

B. Stabilised processes that make interactions known and repetitive (programmable) or discrete and predictable (learnable for AI) 

  • If interactions and events are known and repetitive, they can be automated which reduces the cost, improves performance and integrity. For example, automated warehouses, report bots, service support, virtual assistants.
  • If interactions and events are discrete but predictable, they can be atomised, i.e., divided into smaller portions, and the whole is controlled by intelligent machines. For example, optimised transportation while drivers are still human, intelligence analysis in parts, supply orders created from independent stores, target acquisition for joint fires shared among the available fire platforms. 
  • If interactions and events remain complex and ambiguous, they may be supported with AI enabled augmented reality that helps humans to analyse situation faster and take necessary actions. For example, the connected shooter has AI supporting his target acquisition by detecting the normal behaviour; a physician is supported by augmented reality while operating a wounded in a field hospital; a commander is supported by augmented reality while assessing the situation.

C. Computing power that is available from cloud computing infrastructure 

  • Automated functions are running on embedded processors, but programming requires modelling and simulation 
  • Atomised work supported by centralised AI requires distributed computing power survivable in a military environment.
  • Augmented reality in complex situations requires ‘IBM Watson’ level high-performance computing power
D. People familiar in data literacy, technological literacy, and human literacy .

  • Data literacy means metadata, ontologies, semantic structures, data governance
  • Technology literacy means understanding of how technical systems work and create the social-technical enterprise called military force
  • Human literacy means understanding and skills in cultural, social, emotional, communication, design, and innovation dimensions.

E. Ability to protect one’s cyber environment 

  • The integrity and availability of AI become crucial to the forces that are depending on them. The possible adversary sees the Information Technology and Communications infrastructure together with the data more tempting target.



What are other nations doing?

AI is one of the most potential technologies which may change both nations and companies posture in productivity and competition.  It has been estimated that up to 50% of existing jobs will be changed within the next 20 years and 75%   by the end of the century because of robotisation, artificial intelligence, Internet of Things, and digitalisation.  

The USA is a clear leader in AI measured in the number of patents and companies. The primary resources for AI research are from global companies like Apple, Google, and Facebook. 

China is second due to their governmental investments although Alibaba and Tencent are doing their share. 2017 published “Next Generation Artificial Intelligence Development Plan” is aiming:

  • 2020 the Chinese AI development and implementation are at global best. The AI-based industry is a key area for commercial growth.
  • 2025 the Chinese AI is the primary driver for the transformation of industry and economy. China is the leading country in AI research and development applying it in industry, health, and defence.
  • 2030 China is a global innovation centre for AI. China is possessing a leading role in the global implementation of AI.

Europe is lacking but the northern countries, Finland and Sweden being right after the USA in AI-based growth.  Finland is following eight paths in developing and applying AI in gaining a national strategic advantage:

  1. Enterprise-driven ecosystems to apply AI
  2. Digitising and improving the data in all areas of society
  3. Helping SME’s in applying AI-based products 
  4. Improving competency, education, and practice in AI related subjects
  5. Research and investment funds support transformation 
  6. AI enabled public services 
  7. Establishing new models for cooperation between Public, Private and Voluntary sectors 
  8. Political efforts within EU.

Finland sees two scenarios as AI implementing society before 2030 :

  • Accelerating with AI: The Gross Domestic Production will grow in average 3% per year and employment will improve 5%. Over 15% of the existing jobs will vanish, but AI and its secondary effects will create 20% new jobs.
  • Braking in applying to AI: The GDP growth may be below 0.8% annually, and employment may become worse than today. Over 15% of the existing jobs will vanish, and they are not compensated with new growth.



Military Affairs from the Strategic Point of View

In reaching out the understanding of how Artificial Intelligence may be changing military affairs within the next ten years, let’s first create a model for military affairs in Figure 3. Military force is a composition of the will of people, organisational competency, personnel, and material resources. The force is in continuous interaction with the society that has created the force. The population is the source for will, education, and resources. The governance is the source for political guidance, mission, will, and priorities. The Clausewitzian triangle is confronting and sometimes in conflict with other compositions of force, population, and governance. Throughout the confrontation, there is the non-kinetic and kinetic power that is projected through several channels like military, economic, social, technical, diplomatic, ideological, and cultural to gain effect on the other side.



Figure 3: A model for military affairs

The AI effects on military depend on how the society and governance are applying the technology since it either enables or slows down the utilisation of military force. There are two strategic approaches where AI may create advantage:

  • Asymmetric capabilities in wielding the force in conflict situation and 
  • Cost-efficiency in the extended military enterprise.

How military is succeeding in gaining the advantage depends on their strategic positioning and the ability to execute the required transformations accordingly.


Strategic positioning in preparing for confrontation

The military can adapt either reactive or proactive posture in their positioning compared to their possible adversaries. Then they need to consider their risk aptitude to determine whether to take higher or lower risk approach. The outcome from the Gattorna (2010) model is four postures for military force in Figure 4: 
1. Proactive: 

  • Protective, risk lowering force is trying to sustain the already gained advantages by all-around improvement and strengths utilisation. The AI would be implemented as the AI enabled weapon systems to come available from the society and partners. They would implement restrictions to commerce preventing the possible adversaries to get the AI-enhanced weaponry. 
  • Pathfinder, higher risk appetite force is aiming to be first to implement the edge of the technology. They would be investing actively in R&D and develop unique AI enabled solutions and have strategic plans implemented to take the AI enabled leap first and gain hard to follow capabilities compared to their adversaries.

2. Reactive:

  • Evolutionary, risk lowering force is trying to keep up the deterrence by improving its capabilities composed of people, processes, and technology gradually but continuously without risking in losing the already gained abilities. The evolutionary force would invest in AI enabled technologies iteratively and possibly without holistic plan thus ending having several generations of AI systems.
  • Operational, higher risk appetite force is trying to gain an advantage by excelling in the execution of tasks. Doing things right with the risk that they are not necessary right things. They have better or more trained soldiers than the opponent. They can use better, or they have more conventional armament. They aim to be faster in deployment and manoeuvre. The Operational force may be the laggard in applying AI enabled technology unless it provides them better performance in force support (e.g., warehouse automation) or force generation (e.g., augmented reality training).


Figure 4: Military strategic postures applied from Gattorna (2010) model to estimate different approaches to AI technology adaptation

How military can adapt the best of the Artificial Intelligence, depends on where they stand in their process and force structure when they are generating, supporting and utilising their force. 


Military Affairs from Operational Point of View and their ability to use AI enabled services 

Military affairs can be modelled based on the three primary functions: force utilisation, force generation, and force support. There are other functions such as deployment and readiness or effect and protection, but they are not considered in this paper. Each of the three functions can be modelled using Ross, Weill, and Robertson (2006) model for enterprise strategy. They defined four operating models as per their standardisation and integration which is applied when defining general force structures in Figure 5 as follows:
1. Highly integrated processes:

  • Coordinated but less standardised force is divided into Service components, but it is commanded by a Joint level coordinating the effort of each component towards the same target. The AI service such as Augmentation may be utilised in helping Joint level commanders to make sense out of complex situation and provide troops with the faster decision than the adversary.
  • Unified and highly standardised force is divided into several regional Joint commands each having variable force structure. The higher command gives orders, measures outcome, develops future capabilities and defines processes. The standard force generation can be supported by augmented reality. The standard logistics can be automated entirely. The force utilisation can use coherently all AI enabled abilities cost-effectively.

2. Low integration in processes:

  • The diversified but less standardised force has Combatant commands that are fighting independently in their areas of operation. They generate and support their forces autonomously. The higher command gives missions to a combatant command. The force can use isolated AI enabled services within their functions, but a full force enablement may appear too costly or time-consuming.
  • Replicated and highly standardised force is divided into Joint commands that have similar force structure but are operating in separate theatres of war. Their force components are generated in a standard way, and the joint logistics provides related supplies. The force can use AI enabled services cost efficiently in training, logistics and force utilisation.



Figure 5: Process assessment of military affairs


What a pathfinder force could do today with real AI enablers, if their digitised structure is unified or at least replicated?

The following vision is created based on real AI enablers and features implemented in the civilian sector. The scenario is assuming that the force is following pathfinder strategy, has either unified or replicated processes, can learn as an organisation and adapt quickly innovative ways of doing business, is already digitised and possesses vast amounts of big data, has computing power available everywhere in the area of operation and can protect its cyber environment.


AI enforced Force Utilisation


  • All soldiers are supported by the augmented reality that is providing them specific information about the environment or the involved task.
  • Units are supported with autonomous vehicles (air, land, and sea) that are working together with humans, communicating by voice and adapting to complex situations
  • Weapon systems are automated in stable situations where the enemy cannot manipulate the detection. They identify friendly troops and neutral persons and deter the enemy
  • Commander is aware of the performance of his troops and their mental, physical and material resources on-time
  • Most of the surveillance and reconnaissance is done by connected sensors and analysed by AI enabled bots

AI enforced Force Generation


  • All training is accomplished either in virtual reality or supported by augmented reality.
  • Training of complex combinations of men and machines can be accomplished in hundreds rather than thousands of hours since AI provides massive part of the experience. Only physical fitness requires more effort.
  • Soldiers and commanders can be teamed into high performing teams without struggling with unfitting personalities
  • Training and exercise risks are minimised so there are no losses during the force generation
  • The readiness of reserves will be maintained higher since there are virtualised exercises for all officers and soldiers within their organic composition.

AI enforced Force Support


  • Warehouse robots and people are working aside in retrieving and storing goods. This has improved warehousing industry. 
  • Intelligent automation is supporting maintenance engineers in remote locations, all spare parts are manufactured on site, or the whole failure device is reproduced in operation
  • Robots and autonomous vehicles provide supplies
  • Logistics command has an on-time awareness of situation over the stretch of the supply chain.



2017-10-06

Information Operation ongoing between US and North Korea

Briefly About the Operation

There is evidence that the US Cyber Command has denied the Internet access from North Korea for several weeks during September 2017. Simultaneously, US Treasury has been tightening the financial embargo around North Korea and tries to freeze their foreign assets and transactions. 

President Trump is acting as the “Bad Cop” in social media ("Military solutions are now fully in place, locked and loaded") while Secretary Tillerson is the “Good Cop” and seemingly has ongoing dialogue with North Korean authorities.

This operation is ongoing while North Korea is trying to create a credible threat of nuclear head (last nuclear test was done 3. September) on a ballistic missile (last launch 15. September) that can threaten US assets directly. The credible nuclear threat has been the goal for three generations of Kims to create leverage to both domestic and foreign policy. 

Some Notable Features Concerning the Operation until Today


  1. USCYBERCOM was suppressing the North Korean only Internet link (provided by China Unicom since 2010) with Denial of Service. The attack seems to have been effective since it lowered the activity of known North Korean hackers. This means that not all of them work abroad.
  2. The Denial of Service (DoS) was said to stop on Saturday, 30. September. On Sunday, 1. October, a new trunk connection appeared provided by Russian railway and telecommunications operator (TransTeleCom). The second link, coming from different Internet infrastructure entirely, makes it more difficult in future to disconnect North Korean’s from the Internet.
  3. Last year North Korea made several attacks targeting Financial systems like Swift. They succeeded to rob about $ 81 M from Bangladesh. The North Korean cyber strategy has seemingly been: 1. Steal sensitive information from other Governments and Industry (South Korean military intranet and governmental smartphones), 2. Create fear and insecurity by launching virus attacks (WannaCry), 3. Steal money to finance the government (Lazarus group attacked Banks for example in Bangladesh, Ecuador, Philippine, Vietnam).
  4. US sees their national electric grid vulnerable to advanced attacks like HAVEX or BlackEnergy. While the US executes the “cost imposition” strategy against Russian and Chinese actors, the same deterrence is not valid with Iran or North Korea. Thus, the US is trying to deny their capability to launch cyber-attacks. The denial is accomplished both by increasing the robustness of the information systems controlling the electric grid and exercising the capabilities in denying the access to the Internet or disabling the cyber arms available to these countries.

Used References:

  1. Karen DeYoung, Ellen Nakashima and Emily Rauhala (September 30): Trump signed presidential directive ordering actions to pressure North Korea. The Washington Post, National security. https://www.washingtonpost.com/world/national-security/trump-signed-presidential-directive-ordering-actions-to-pressure-north-korea/2017/09/30/97c6722a-a620-11e7-b14f-f41773cd5a14_story.html?utm_term=.1c6dc0b101b7 
  2. Michelle Ye Hee Lee (13 September 2017). "North Korea nuclear test may have been twice as strong as first thought". Washington Post. 
  3. North Korea 'fires missile from Pyongyang'. BBC. 15 September 2017.
  4. https://www.nytimes.com/2017/03/04/world/asia/north-korea-missile-program-sabotage.html 
  5. Martyn Williams (October 1): Russian provides new Internet connection to North Korea. 38North. http://www.38north.org/2017/10/mwilliams100117/ 
  6. CSIS: North Korea's Cyber Capabilities. https://www.csis.org/programs/korea-chair/korea-chair-project-archive/north-koreas-cyber-capabilities 
  7. Charles Riley and Jethro Mullen (16 May): North Korea’s long history of hacking. CNNTech. http://money.cnn.com/2017/05/16/technology/ransomware-north-korea-hacking-history/index.html 
  8. US DoD Defence Science Board (February 2017): Task Force on cyber deterrence. http://www.acq.osd.mil/dsb/reports/2010s/DSB-CyberDeterrenceReport_02-28-17_Final.pdf

2017-09-19

Large Scale Broadpwn Vulnerability in Android and iOS Wi-Fi Connections

Definition

Billions of smartphones, both Android and iOS have the same Wi-Fi chipset from Broadcom (BCM43xx family). A recent study presented at Black Hat conference has revealed a major vulnerability in that chipset that opens the smartphone to attacks via Wi-Fi connection. The vulnerability is open on all devices before the versions iOS 10.3.3 (released 20 July) or the July security update for Android, which contains fixes for the flaw. The vulnerability allows an attacker to gain access at the chip level and write programs that can be running on that chip. The targeted phone or user does nothing additional nor does the user notice that device has been exploited.


This vulnerability is first of this kind of exposure (all iOS devices after iPhone 5; all Samsung Galaxy from S3 through S8, inclusive; all Samsung Notes 3; all Nexus versions 5 – 6P), exploiting peripherals not core, does not need any action from user and can be used as a network for worm.

Brief Description

The resourceful attacker develops a worm that exploits the vulnerabilities of the BCM 43xx chips. The attacker presents himself in some event that has many high-ranking officers attending. The attacker infiltrates few of the smartphones (requires only activated Wi-Fi) and installs the worm. When officers return to their command posts and headquarters, their smartphones start to infect other devices within the Wi-Fi range. After few days, the higher commanders and their staffs’ smartphones are prepared for the next phase. 


The attacker, depending on the situation, can exploit the remotely controllable botnet (networks of remotely controlled robots) either collecting all information achievable through microphones and sessions or, in the brink of attack, suppress all smartphone usage of affected officers. This may delay or disable to the reaction of the higher-ranking officers enough to gain the advantage on ground, air or sea (recall the reason for slow German response to the invasion of Normandy).

Recommendation


End-users and administrators:

  • Update all possible Smart devices with:
  • Android: 2017-07-05 security patch
  • iOS: 10.3.3

Military system architects:

  • Broadpwn is a textbook example of using a large surface with a small but innovative effort to tap sensitive information or suppress main information flows. 
  • Military architects should always provide strategic variety for critical information flows and mitigate the single points of failure.

Military Chief Information Officers:


  • No one mean of communications of information processing can be reliable enough. 
  • Always require parallel, independent options for business continuity.


References:


  1. https://www.wired.com/story/broadpwn-wi-fi-vulnerability-ios-android/
  2. https://www.theguardian.com/technology/2017/jul/27/broadpwn-smartphone-malware-bug-iphone-samsung-google
  3. https://blog.exodusintel.com/2017/07/26/broadpwn/

2017-09-15

Watch you Bluetooth usage!

There are BlueBorne vulnerabilities in Bluetooth connections


Definition

Bluetooth technology has been in use since early 2000, and over 8.2 Billion devices are using Bluetooth. Some of the older versions of Android, iOS, Windows, and Linux implementations have a vulnerability that enables remote commands on the target device. There are together eight vulnerabilities that are called BlueBorne. These vulnerabilities were found during Spring 2017, communicated to responsible manufacturers and have been patched in the latest revisions.

Brief Description

The attacker approaches the proximity of the Bluetooth device and connects through Bluetooth wireless connection using buffer copy, buffer overflow, integer underflow or Man-in-the-Middle attack to gain access to the target device, injects malicious software or captures user information.


Worst case is when an advanced attacker reconnoitres the target infrastructure and deploys a worm that uses BlueBorne vulnerabilities to spread over-the-air. Especially, air-gap isolated systems are vulnerable if the Bluetooth is not disabled.

What to do:

The following measures are recommended to mitigate the BlueBorne exploitation: 
1. Update all possible versions concerning the found vulnerability in:
  • Android: Before September 2017 updates
  • Windows: Before September 2017 updates
  • iOS: Pre-version 10
  • Apple TV: Pre-version 7.2.2
  • Linux: Before September 2017 updates
2. If the update is not available or not possible to upload, user should consider disabling the Bluetooth

3. There is a possibility that Bluetooth has other unrevealed vulnerabilities, so the professional organisation should control the proximity of their systems.

References

1. www.kb.cert.org/vuls/id/240311
2. www.armis.com/blueborne/



How military defend against commercial drones?

Threat of drones

Within a few past years, there has been a rise in the number of incidents involving small unmanned aerial vehicles (UAV, i.e., Drones). Insurgent forces in Syria and Iraq together with regular armies in Ukraine have used commercial drones to reconnoiter or strike targets. The defence industry is introducing various means to counter the UAV’s using force, signal hijacking, directional RF interference, directed energy, or other drones.

A Ukrainian serviceman operates a drone during a training session outside Kiev, November 6, 2014. © REUTERS


Iraqi troops are showing commercial drones used by ISIS in Mosul. © CENTCOM

Blunt force

A basic and low-tech solution is to knock out the drone with another object. SkyWall100 system from OpenWorks Engineering is a man-portable compressed air launcher that fires a 22-pound net to capture the drone and parachuting it down.

Signal hijacking

A more delicate countermeasure is to infiltrate and seize the command channel between the remote controller and the drone. The captured drone can then be guided to land in the safe zone. MESMER from Department 13 and UAV D04JA Jammer from Chinese Hikvision are systems that can take over the control of a UAV and direct it to safety.

RF interference

The more longer-range situation requires a system capable of detection, tracking, and disruption. A British made AUDS can detect a drone from 8 km away, track it and disrupt its flight by using radio frequency jamming. A French BOREADES system is an integrated system that uses radars, day-night optronics and UHD video to detect the drone and intercepts it by jamming or luring the navigation system onboard.

Directed energy

In a situation of multiple drones approaching the target at the same time, a straightforward countermeasure is to shoot them down with directed energy weapons. USS Ponce is already hosting the Laser Weapon System (LaWS) to counter threats from small boats to drones. Rheinmetall has laser-based products to counter both commercial and military drones. Chinese researchers have demonstrated a system in 2017 Black Hat conference that uses audible sound and ultrasound emitters to disrupt the microelectromechanical systems as accelerometers and gyroscopes on board a drone.

Other drones

There are several solutions of using other drones to capture hostile drones. One of them is the Drone Interceptor MP200 from Malou Tech that uses a net to capture the approaching vehicle.

Geofencing or electronic wall

The drone manufacturers program their drones not to enter denied areas.  The global positioning signals can be jammed to keep the drones entering denied areas.

Rules of Engagement

US DoD has issued a policy to military bases that they have full legal rights to shoot down private or commercial drones seemed to be a threat. This may apply to other separated military zones, but amongst the people and in public sites, the less violent measures need to be available.

RGP armed drone shot down by Syrian troops © ThinkDefence.co.uk

All US Army troops in operation develop a sensor plan that deploys both passive and active countermeasures against hostile drones. The action is straight forward: "Units must attempt to engage and destroy the UAV using any organic means available, typically small arms fires organic to the unit while simultaneously relocating the unit."
Some airports in Ireland have established a “no drone zone” which is a control measure to ensure there are no drones around departure or approach routes. If a drone is sighted, aircraft is put on hold to clear the path.
Police officers in the UK can only instruct the drone operators to land if they approach sensitive sites or become a safety issue.
Israel Defence Forces do shoot down Hezbollah drones violating Israeli airspace.


References:

Pomerlau, Mark: Army releases counter-drone training document. C4ISRNET. 25. April 2017. http://www.c4isrnet.com/unmanned/uas/2017/04/25/army-releases-counter-drone-training-document/
Defence IQ press: A timeline of the rising small UAS threat. Defence IQ 10.2.2017
https://www.defenceiq.com/defence-technology/articles/a-timeline-of-the-rising-small-uas-threat
Dutta, Sumit: This is how militaries can defend against drones. Defence IQ 14.8.2017 https://www.defenceiq.com/news/this-is-how-militaries-can-defend-against-drones
Goarant, Barbara: CS presents BOREADES. CS official pages. http://www.c-s.fr/CS-presente-BOREADES-son-systeme-de-lutte-anti-drone-a-l-occasion-de-la-demonstration-dynamique-organisee-par-le-SGDSN_a765.html
Silva, Richard De: No Drone Zone. Defence IQ September 2016. https://plsadaptive.s3.amazonaws.com/gfiles/_nilr3emag_-_countering-drones_-_defence_iq_-_oct_2016.pdf?response-content-type=application/pdf&AWSAccessKeyId=AKIAICW5IOYOPOZOU3TQ&Expires=1505470510&Signature=9HweRD7Pn612TpoQ1Dn54DhID6U%3D
Pavluk, Joshua: Four counter-drone technologies we need now. TechCrunch, 23. February 2016. https://techcrunch.com/2016/02/23/four-counter-drone-technologies-we-need-now/