Cyber Operations at Maidan: A First-Hand Account
|
|
|
- Britton Bates
- 10 years ago
- Views:
Transcription
1 Cyber Operations at Maidan: A First-Hand Account by Glib Pakharenko Chapter 7 in Kenneth Geers (Ed.), Cyber War in Perspective: Russian Aggression against Ukraine, NATO CCD COE Publications, Tallinn 2015
2 In Chapter 7, ISACA Kyiv researcher Glib Pakharenko has written a first-hand account of cyber attacks during the revolution in Ukraine. At the EuroMaidan street demonstrations, there were physical and logical attacks against opposition servers, smartphones, websites, and Internet accounts; the most serious incidents coincided with the lethal shooting of protestors. In Crimea, attacks ranged from severing network cables to commandeering satellites to wholesale changes in Wikipedia. In eastern Ukraine, cyber espionage such as the use of location data from mobile phones and Wi-Fi networks has aided in targeting Ukrainian army units; the region has also been isolated from the rest of Ukraine by Internet censorship and regular forensics checks on citizens computers and mobile devices. Pakharenko ends this chapter by providing the Ukrainian Government with a significant to do list of best practices in network security. Disclaimer This publication is a product of the NATO Cooperative Cyber Defence Centre of Excellence (the Centre). It does not necessarily reflect the policy or the opinion of the Centre or NATO. The Centre may not be held responsible for any loss or harm arising from the use of information contained in this publication and is not responsible for the content of the external sources, including external websites referenced in this publication. Digital or hard copies of this publication may be produced for internal use within NATO and for personal or educational use when for non-profit and non-commercial purpose, provided that copies bear a full citation. Please contact publications@ccdcoe. org with any further queries.
3 Chapter 7 Cyber Operations at Maidan: A First-Hand Account Glib Pakharenko ISACA Kyiv 1 Introduction: Cyber Conflict in Ukraine I would like to tell the story of what I experienced in Ukraine from the autumn of 2013 until the end of In this chapter, I will describe the nature and impact of numerous cyber attacks that took place during our revolution and the subsequent conflict between Ukraine and Russia. As background, it is important to understand the strategic value of Ukraine to Russia. Ukraine is the largest country in Europe, with over 42 million citizens and 27 administrative divisions. In the past, its rich farmland and industrial base have been coveted by Russia, Turkey, Poland, and even by Nazi Germany. Ukraine has also made significant contributions in politics; the Ukrainian Cossacks created the first constitution in contemporary European history. Following the horrors of World War II, the country continued to suffer under Soviet rule until it regained its independence in Despite that, Russia has never really let go of Ukraine. Ukraine has had internet connectivity since As everywhere else in the world, it has also had its share of cyber attacks. The majority of these have come in the form of Distributed Denial-of-Service (DDoS) incidents against politically or economically targeted websites. During election seasons, for example, hackers have frequently gone after the websites of political parties. In terms of cyber crime, Ukraine has long been home to carding, mobile operator fraud, spam factories, cyberlockers, pirated software, unauthorized bank transfers, and various attacks on rival businesses. 59
4 Responsibility for the enforcement of internet security in Ukraine belongs to the Ministry of Internal Affairs (MVS) and the Security Service of Ukraine (SBU). 1 Cyber security regulations are overseen by the State Service of Special Communication and Information Protection (SSSCIP), 2 but the ultimate responsibility for cyber crimes has never made explicit, and in this regard there has been competition between the MVS and SBU. Ukraine s Computer Emergency Response Team was created in National cyber security legislation is still in its nascent stages. Many of our current laws date from the Soviet era, and need to be updated for the information age. The national critical infrastructure domain is still largely unregulated. Definitions related to cyber security and information security are unclear, as is the distinction between them. Historically, the Ukrainian police have investigated straightforward cases related to illegal content, online gambling, and pornography. Their number of qualified personnel trained in cyber security was low, with little competency in computer or network forensics. Therefore, their most common tactic was simply to confiscate all IT equipment. Given these circumstances, Ukraine is currently ill-prepared to combat advanced, nation-state level cyber attacks. In the future, its specialists would like to see the arrival of more non-governmental organisation (NGO) support from the European Union and United States, with a view to implementing modern best practices and internationally recognised standards. 2 The Impact of Euromaidan The Revolution of Dignity in Ukraine began in late 2013 when citizens took to the streets to vent their fury at the decision of then-president Viktor Yanukovych not to sign an agreement of political association with the European Union (EU). This political movement became known as Euromaidan the Ukrainian word Maidan means square in English, and refers to the main square in the capital city, Kyiv. On November 30, mobile phone communications were systematically shut down through mobile operators, and armed police units physically attacked the protesters. However, the population was undeterred, and by December 2, more than 500,000 people crowded into Maidan. The sitting government made several more attempts to clear the city, using gas grenades and plastic bullets, and the author personally suffered a long-term injury from exposure to tear gas. The crackdown eventually led to the use of lethal force, 3 likely killing well over 100 protestors. 4 1 The SBU is a former constituent part to the Soviet KGB, and is still coming to terms with its legacy ideology and post-soviet corruption. 2 The SSSCIP was a former constituent part of SBU and has since had a conflicting relationship with its former parent over its role in the information security arena. 3 The author believes that Russian Security Services took part in these killings. 4 List of people killed during Euromaidan, Wikipedia, 60
5 The cyber attacks began on 2 December 2013 when it was clear that protesters were not going to leave Maidan. Opposition websites were targeted by DDoS attacks, the majority of which came from commercial botnets employing Black- Energy and Dirt Jumper malware. The cyber attacks began on 2 December 2013 when it was clear that protesters were not going to leave Maidan. Police confiscated mobile phones to acquire the protestors web, , social media, and financial activities. In one case, pornographic images were uploaded to a protestor s social media account, and were later used to prosecute him. Police seized computers from the opposition party s premises, and according to one city official, the lighting in city hall (which had been a base of opposition activity) was switched off remotely, via the internet. Opposition activists also conducted cyber attacks against the Ukrainian Government, using tools such as the Low Orbit Ion Cannon (LOIC) to launch DDoS attacks on the President s website. When one group of protestors entered the Ministry of Energy, the organisation sounded a red alert at Ukrainian nuclear facilities, due to the fact that the national electricity grid is remotely controlled via the internet from headquarters. During this period of intense cyber attacks in Ukraine, cyber criminal organisations proactively reduced their use of the Ukrainian Internet Protocol (IP) space, rerouting their malware communications through Internet Service Providers (ISP) in Belarus and Cyprus, which meant that, for the first time in years, Ukraine was not listed among the leading national purveyors of cyber crime. 5 The largest and most sophisticated attacks coincided with the lethal shooting of protestors in Maidan (February 18-20, 2014). The mobile phones of opposition parliament members were flooded with SMS messaging and telephone calls in an effort to prevent them from communicating and coordinating defences. One precision attack (which targeted the protesters on only one street in Kyiv) entailed spamming the IMSI catcher device on mobile phones with fake SMS messages, threatening the recipient with prosecution for participation in the protest. 6 In western Ukraine, the Government turned off the main opposition TV channel, and when protesters decided to enter police departments, those facilities were disconnected from the Public Switched Telephone Network (PSTN) and internet. Despite all of these police actions, the now-radicalised protesters were unbowed, and continued their revolutionary campaign. Therefore, on February 22, 2014, Ukrainian President Yanukovich fled to Russia, and a new and reformist government was established in Kyiv. 5 HostExploit analysis, 6 This tactic has also been used by Russian military units in eastern Ukraine. 61
6 3 Crimea and Donbass By the end of April 2014, the Russian Government had responded to these events by occupying and annexing the Ukrainian peninsula of Crimea, as well as military intervention in eastern Ukraine, where hostilities continue to this day. From the start of its Crimean operation, the Russian army moved to gain control of the peninsula s telecommunications infrastructure, severing cables and routing calls through Russian mobile operators. Ukrainian media companies lost their physical assets in Crimea, and local television programming shifted from Ukrainian to Russian channels. With physical access to its control infrastructure, Russia also commandeered the Ukrainian From the start of its Crimean operation, the Russian army moved to gain control of telecommunications infrastructure. national satellite platform Lybid. In Kyiv, as soon as the Russian military occupied Crimea, the internal security staff of one of Ukraine s largest mobile operators immediately demanded the severing of communications links between Ukraine and the occupied territory. However, its pro-russian management refused, and maintained unrestricted connectivity as long as possible, likely so that Russian security services could retain access to its internal systems, for intelligence gathering and other information operations. Ukrainian mobile operators saw an increase in the volume of cyber crime emanating from Crimea, and it is likely that Russian security services acquired intelligence from information collected in this way. Pro-Russia media, discussion forums, and social network groups were active in propaganda dissemination. The Crimea campaign was even buttressed by mass changes in Wikipedia, where Russian propaganda teams altered articles related to the events taking place there. Today in Crimea, Russian authorities have implemented content filtering for internet access, including the censorship of Ukrainian news sites. In November 2014, Russia announced it would create a cyber warfare-specific military unit in Crimea. Pro-Ukrainian hackers have attacked Crimean websites during the occupation, such as that of the Crimean Parliament 7 and a site linking to public web cameras. 8 They have also released allegedly official Russian documents related to the conflict which were claimed to be stolen from Russian government servers. 9 As the conflict shifted to Donbass, cyberspace played an increasingly important role in military operations. Physical attacks destroyed cabling, broadcast infra- 7 Vulnerabilities in March 2014, Websecurity 8 Ukrainian Cyber Army: video intelligence, Websecurity April 23, 2015, 9 Aric Toler. Russian Official Account of Attack on Ukraine Border Guards, bellingcat, 30 May com/news/uk-and-europe/2015/05/30/russian-official-account-of-attack-on-ukraine-border-guards/. 62
7 structure, and ATM networks, and this served to isolate the region from Ukrainian media, communications, and financial services. 10 Military operations were coordinated with propaganda disseminated on Russian TV channels and internet-based media. Finally, the occupation army performs regular forensics checks on computers and mobile devices owned by the population in eastern Ukraine. Russian signals intelligence (SIGINT), including cyber espionage, has allowed for very effective combat operations planning against the Ukrainian army. Artillery fire can be adjusted based on location data gleaned from mobile phones and Wi-Fi networks. 11 GPS signals can also be used to jam aerial drones. Ukrainian mobile traffic can be rerouted through Russian GSM infrastructure via a GSM signalling level (SS7) attack; 12 Russian signals intelligence (SIGINT) has allowed for effective combat operations against the Ukrainian army. in one case, this was accomplished through malicious VLR/HLR updates that were not properly filtered. Russian Security Services also use the internet to recruit mercenaries. Generally speaking, the computer systems and mobile communications of Ukrainian government, military, and critical infrastructure are under permanent attack, and their communications are routinely intercepted and analysed for information of intelligence value. There are also many attacks on Ukrainian businesses: examples include the Ukrainian Railway Company, Kievstar mobile operator, 13 a SMART-TV retail shop, 14 and a city billboard Cyber Tactics Cyberspace is a complex domain. In the Ukraine conflict, we have seen many different types of actors, tools, and tactics. Hacktivists have used the Low Orbit Ion Cannon; criminals have used malware like Blackenergy and DirtJumper. But with cyber attacks, attribution and motive are not always clear, and the level of deception is high. The pro-russia hacker groups Cyberberkut and Cyber-riot Novorissia have conducted DDoS attacks and released stolen and office documents from Ukrainian officials. Russian media, parliament members, and pro-russian 10 Some attacks against telecom infrastructure took place in Kyiv as well. 11 In the area of ATO proposes to ban military use mobile phones, Голос України, 12 May How the Russians attacked Ukrainian mobile operators, Delo.ua, 26 May 2014, 13 Kyivstar is owned and controlled by Russian business, so this attack may be from a non-russian actor. 14 The TV s firmware was compromised, after which the TV began to display channels from of pro-russian, separatist eastern Ukraine. 15 The billboard then displayed pro-russian messages. 63
8 Ukrainian politicians often mention these groups by name, but true attribution is difficult. For example, spam is used to deliver news about their operations. 16 For DDoS, various types of network flooding have been used against web and DNS servers from spoofed source IPs. 17 Sometimes, the attacks overwhelmed internet channel bandwidth; at other times, they affected the capability of an internet router to process packets. The offending DDoS attacks lasted up to weeks at a time, which had never been seen before. bots were located all over the world, but when Ukrainian ISPs began to filter traffic based on national IP ranges, the point of attack simply shifted to Ukrainian bots, which served to defeat this protection measure. During the revolution in Ukraine, DDoS attacks lasted up to weeks at a time, which had never been seen before. Cloud DDoS protection services provided some relief, but the attackers could usually find some worthwhile computer to shut down, such as when they blocked updates to an online media portal. Over time, computer security companies have improved their ability to place malware into families and attacks into campaigns. To some degree, this helps to provide attribution, especially when some sophisticated, persistent campaigns can only be the work of nation-state actors for reasons of mission focus, cost, and the overall level of operational effort required. Researchers believe, for example, that the Ouroboros/Snake malware family, which avoided detection for 8 years and actively targeted the Ukrainian Government, has Russian origins. 18 With enough data, it is possible to see large cyber espionage campaigns that encompass many different types of targets; it is also possible to see that they generally work within a particular time zone, such as Moscow. 19 One possible Russia-based campaign against Ukraine (and other nations), called Sandworm, exploits advanced zero-day vulnerabilities and targets national critical infrastructure. 20 Finally, in Operation Armageddon, researchers believe that they tied malware activity to ongoing Russian military operations in Ukraine Even the pro-russian NGO Mothers of Soldiers, which fights the mobilization efforts of the Ukrainian army, uses spam to distribute information. 17 The breadth of the attacks included IPv6->IPv4 to bypass DDoS filters, NTP amplification, slow HTTP POST packets against vulnerable Apache servers, DAVOSET, and SSL renegotiation against misconfigured web servers. The maximum volume I am aware of was <30 Gbt/s. 18 David E. Sanger and Steven Erlangermarch, Suspicion Falls on Russia as Snake Cyberattacks Target Ukraine s Government, New York Times, 8 March 2014, 19 APT28: A Window into Russia s Cyber Espionage Operations? FireEye, 27 October 2014, threat-research/2014/10/apt28-a-window-into-russias-cyber-espionage-operations.html. 20 Stephen Ward. isight discovers zero-day vulnerability CVE used in Russian cyber-espionage campaign, isight Partners, 14 October, 2014, 21 Robert Hackett. Russian cyberwar advances military interests in Ukraine, report says Fortune, 29 April 2015, com/2015/04/29/russian-cyberwar-ukraine/. 64
9 5 Conclusion and Recommendations Ukraine is vulnerable to Russia, both in traditional geopolitical space and in cyberspace. In 2015, Ukrainians are still dependent on Russian web resources, including social media (Vkontakte), (Mail.ru), search engines (Yandex), antivirus software (Kaspersky), and much more. Our IT supply chain acquires hardware that is either produced in Russia or travels through Russia this creates vulnerabilities out of the box, and facilitates future attacks. Whereas Russia is a world leader in cyber espionage and attack, Ukraine s security services are new and inexperienced. In the current conflict with Russia, the only option available to Ukraine is simply a self-inflicted denial-of-service: block access to pro-russian sites, remove access to Russian TV channels, limit the use of Russian hardware and software, ban mobile phone and social network usage for Ukrainian soldiers, and sever network access with occupied eastern Ukraine. In the future, Ukraine must modernise its cyber security legislation. One critical aspect of that process will be transparency: it must publish proposed and new laws on government websites so that they are easy to read and understand. In the past, even the few websites available were often knocked offline by hackers. There have been many lessons learned. Here are some of the author s personal recommendations to the Ukrainian Government: Clear Ukrainian IP space of botnets and misconfigured servers (NTP, DNS, etc.) that facilitate cyber attacks; Remove illegal and pirated software from critical infrastructure and public agencies; Reduce Ukraine s IT dependency in the context of crisis scenarios; Implement continuity standards for media and telecoms in conflict zones; Create mechanisms to reliably deliver messages from the government to its citizens in occupied territories; Incorporate anti-ddos solutions into Internet-facing services; Ensure multiple, independent routes for internet traffic between Ukraine and the rest of the world; Implement effective filtering mechanisms on national traffic exchange points; Develop a culture of continuous cyber attack monitoring, investigation, information sharing, and research; Develop strong cyber security and cryptography capabilities across Ukraine; Implement effective civil society controls over unauthorised interception and collection of data; Improve emergency data erasure and disaster recovery capabilities; 65
10 Provide resources to military and security services to effectively conduct large-scale cyber operations and computer forensics during their missions; and Ensure supply chain security for IT services coming from Russia. Finally, the world should not underestimate Russia, which is seeking to re-establish its former empire, to include Ukraine and other parts of the defunct Soviet Union and Warsaw Pact. In the context of its wide-ranging political and military campaigns, Russia has developed a cyber attack capability that can target national critical infrastructures, via the internet, anywhere in the world.
The FBI Cyber Program. Bauer Advising Symposium //UNCLASSIFIED
The FBI Cyber Program Bauer Advising Symposium October 11, 2012 Today s Agenda What is the threat? Who are the adversaries? How are they attacking you? What can the FBI do to help? What can you do to stop
White Paper. Intelligent DDoS Protection Use cases for applying DDoS Intelligence to improve preparation, detection and mitigation
White Paper Intelligent DDoS Protection Use cases for applying DDoS Intelligence to improve preparation, detection and mitigation Table of Contents Introduction... 3 Common DDoS Mitigation Measures...
Estonia 2007 Cyberattakcs
Estonia 2007 Cyberattakcs 2010 Agenda Background April 2007 What is cyberattack Estonia as an information society Cyberattacks Protection measures used Lessons learned What are we doing - measures Background
Home Security: Russia s Challenges
Home Security: Russia s Challenges A Russian Perspective Andrei Fedorov * Home security: Russia s challenges Home security and the struggle against terrorism is one of the most crucial issues for the Russian
Online International Interdisciplinary Research Journal, {Bi-Monthly}, ISSN2249-9598, Volume-III, Issue-IV, July-Aug 2013
Need to understand Cyber Crime s Impact over national Security in India: A case study P.R. Patil and D.V. Bhosale Dept. of Defence & Strategic Studies, Tuljaram Chaturchand College, Baramati, Dist- Pune,
ESTABLISHING A NATIONAL CYBERSECURITY SYSTEM IN THE CONTEXT OF NATIONAL SECURITY AND DEFENCE SECTOR REFORM
Information & Security: An International Journal Valentyn Petrov, vol.31, 2014, 73-77 http://dx.doi.org/10.11610/isij.3104 ESTABLISHING A NATIONAL CYBERSECURITY SYSTEM IN THE CONTEXT OF NATIONAL SECURITY
KASPERSKY DDoS PROTECTION. Protecting your business against financial and reputational losses with Kaspersky DDoS Protection
KASPERSKY DDoS PROTECTION Protecting your business against financial and reputational losses A Distributed Denial of Service (DDoS) attack is one of the most popular weapons in the cybercriminals arsenal.
THE SECURITY SERVICE OF UKRAINE (SBU)
THE SECURITY SERVICE OF UKRAINE (SBU) Dr. Taras Kuzio (Centre for Political and Regional Studies, Canadian Institute for Ukrainian Studies, University of Alberta) Copyright: Research Institute for European
How To Protect Yourself From A Dos/Ddos Attack
RELEVANT. INTELLIGENT. SECURITY White Paper In Denial?...Follow Seven Steps for Better DoS and DDoS Protection www.solutionary.com (866) 333-2133 In Denial?...Follow Seven Steps for Better DoS and DDoS
Understanding & Preventing DDoS Attacks (Distributed Denial of Service) A Report For Small Business
& Preventing (Distributed Denial of Service) A Report For Small Business According to a study by Verizon and the FBI published in 2011, 60% of data breaches are inflicted upon small organizations! Copyright
KASPERSKY DDOS PROTECTION. Discover how Kaspersky Lab defends businesses against DDoS attacks
KASPERSKY DDOS PROTECTION Discover how Kaspersky Lab defends businesses against DDoS attacks CYBERCRIMINALS ARE TARGETING BUSINESSES If your business has ever suffered a Distributed Denial of Service (DDoS)
Stop DDoS Attacks in Minutes
PREVENTIA Forward Thinking Security Solutions Stop DDoS Attacks in Minutes 1 On average there are more than 7,000 DDoS attacks observed daily. You ve seen the headlines. Distributed Denial of Service (DDoS)
Alexa, Top Sites in Georgia, http://www.alexa.com/topsites/countries/ge, accessed September 20, 2010. 2
141 2009 2011 INTERNET FREEDOM STATUS Partly Free Partly Free Obstacles to Access 15 12 Limits on Content 15 10 Violations of User Rights 13 13 Total 43 35 POPULATION: 4.6 million INTERNET PENETRATION
Acquia Cloud Edge Protect Powered by CloudFlare
Acquia Cloud Edge Protect Powered by CloudFlare Denial-of-service (DoS) Attacks Are on the Rise and Have Evolved into Complex and Overwhelming Security Challenges TECHNICAL GUIDE TABLE OF CONTENTS Introduction....
CYBER SECURITY THREATS AND RESPONSES
CYBER SECURITY THREATS AND RESPONSES AT GLOBAL, NATION-STATE, INDUSTRY AND INDIVIDUAL LEVELS Heli Tiirmaa-Klaar* Although cyber security has accompanied the ICT sector since the first computer systems
NATIONAL CYBERSECURITY STRATEGIES: AUSTRALIA AND CANADA
NATIONAL CYBERSECURITY STRATEGIES: AUSTRALIA AND CANADA JOÃO MANUEL ASSIS BARBAS Coronel de Artilharia. Assessor de Estudos do IDN INTRODUCTION Globalization and information and communication technologies
Denial of Service Attacks
2 Denial of Service Attacks : IT Security Sirindhorn International Institute of Technology Thammasat University Prepared by Steven Gordon on 13 August 2013 its335y13s2l06, Steve/Courses/2013/s2/its335/lectures/malicious.tex,
Achieving Truly Secure Cloud Communications. How to navigate evolving security threats
Achieving Truly Secure Cloud Communications How to navigate evolving security threats Security is quickly becoming the primary concern of many businesses, and protecting VoIP vulnerabilities is critical.
The trend of the Cyber Security and the efforts of NEC. December 9 th, 2015 NEC Corporation
The trend of the Cyber Security and the efforts of NEC December 9 th, 2015 NEC Corporation Agenda 1. NEC Corporate Profile 2. NEC s Activity for Safer-City 3. NEC Cyber Security Solution 3.1 Security Operation
The Advanced Cyber Attack Landscape
The Advanced Cyber Attack Landscape FireEye, Inc. The Advanced Cyber Attack Landscape 1 Contents Executive Summary 3 Introduction 4 The Data Source for this Report 5 Finding 1 5 Malware has become a multinational
Zscaler Internet Security Frequently Asked Questions
Zscaler Internet Security Frequently Asked Questions 1 Technical FAQ PRODUCT LICENSING & PRICING How is Zscaler Internet Security Zscaler Internet Security is licensed on number of Cradlepoint devices
www.prolexic.com Stop DDoS Attacks in Minutes
www.prolexic.com Stop DDoS Attacks in Minutes Prolexic gives us the strong insurance policy against DDoS attacks that we were looking for. Mark Johnson, Chief Financial Officer, RealVision You ve seen
ASEAN Regional Forum Cyber Incident Response Workshop Republic of Singapore 6-7 September 2012. Co-Chair s Summary Report
ASEAN Regional Forum Cyber Incident Response Workshop Republic of Singapore 6-7 September 2012 Co-Chair s Summary Report 1. Pursuant to the 18 th ASEAN Regional Forum (ARF) Ministerial meeting in Bali,
Anthony Minnaar Dept of Criminology & Security Science School of Criminal Justice College of Law University of South Africa
SECURING THE DIGITAL DIVIDE: COMBATING CYBERCRIME Anthony Minnaar Dept of Criminology & Security Science School of Criminal Justice College of Law University of South Africa INTRODUCTION q Given modern
Strategic Priorities for the Cooperation against Cybercrime in the Eastern Partnership Region
CyberCrime@EAP EU/COE Eastern Partnership Council of Europe Facility: Cooperation against Cybercrime Strategic Priorities for the Cooperation against Cybercrime in the Eastern Partnership Region Adopted
Unknown threats in Sweden. Study publication August 27, 2014
Unknown threats in Sweden Study publication August 27, 2014 Executive summary To many international organisations today, cyber attacks are no longer a matter of if but when. Recent cyber breaches at large
TLP WHITE. Denial of service attacks: what you need to know
Denial of service attacks: what you need to know Contents Introduction... 2 What is DOS and how does it work?... 2 DDOS... 4 Why are they used?... 5 Take action... 6 Firewalls, antivirus and updates...
CloudFlare advanced DDoS protection
CloudFlare advanced DDoS protection Denial-of-service (DoS) attacks are on the rise and have evolved into complex and overwhelming security challenges. 1 888 99 FLARE [email protected] www.cloudflare.com
UN Emergency Summit on Cyber Security Topic Abstract
UN Emergency Summit on Cyber Security Topic Abstract Dear Delegates and Moderators, Welcome to the UN Emergency Summit on Cyber Security! Cyber security is one of the most relevant issues in the international
Embedded Network Solutions Australia Pty Ltd (ENSA) INTERNET ACCEPTABLE USE POLICY
T: 1300 00 ENSA (3672) F: 03 9421 6109 (ENSA) INTERNET ACCEPTABLE USE POLICY 1 ABOUT THIS POLICY... 2 2 GENERAL... 2 3 ILLEGAL ACTIVITY... 2 4 SECURITY... 2 5 RISKS OF THE INTERNET... 3 6 CONTENT PUBLISHING...
EXTREME CYBER SCENARIO PLANNING & ATTACK TREE ANALYSIS
EXTREME CYBER SCENARIO PLANNING & ATTACK TREE ANALYSIS Ian Green Manager, Cybercrime & Intelligence Commonwealth Bank of Australia Session ID: GRC T17 Session Classification: ADVANCED WHY? What keeps you
Legal Issues / Estonia Cyber Incident
Control System Cyber Security Conference 22 October 2009 Legal Issues / Estonia Cyber Incident Maeve Dion Center for Infrastructure Protection George Mason University School of Law Legal Issues / Estonia
Guide to DDoS Attacks December 2014 Authored by: Lee Myers, SOC Analyst
INTEGRATED INTELLIGENCE CENTER Technical White Paper William F. Pelgrin, CIS President and CEO Guide to DDoS Attacks December 2014 Authored by: Lee Myers, SOC Analyst This Center for Internet Security
OVERVIEW. 1. Cyber Crime Unit organization. 2. Legal framework. 3. Identity theft modus operandi. 4. How to avoid online identity theft
OVERVIEW 2 1. Cyber Crime Unit organization 2. Legal framework 3. Identity theft modus operandi 4. How to avoid online identity theft 5. Main challenges for investigation 6. Conclusions ORGANIZATION 3
Digital Evidence and Threat Intelligence
Digital Evidence and Threat Intelligence 09 November 2015 Mark Clancy CEO www.soltra.com @soltraedge External Threats Growing 117,339 incoming attacks every day The total number of security incidents detected
Cloud Security In Your Contingency Plans
Cloud Security In Your Contingency Plans Jerry Lock Security Sales Lead, Greater China Contingency Plans Avoid data theft and downtime by extending the security perimeter outside the data-center and protect
DISTRIBUTED DENIAL OF SERVICE OBSERVATIONS
: DDOS ATTACKS DISTRIBUTED DENIAL OF SERVICE OBSERVATIONS 1 DISTRIBUTED DENIAL OF SERVICE OBSERVATIONS NTT is one of the largest Internet providers in the world, with a significant share of the world s
AUDITOR GENERAL S REPORT. Protection of Critical Infrastructure Control Systems. Report 5 August 2005
AUDITOR GENERAL S REPORT Protection of Critical Infrastructure Control Systems Report 5 August 2005 Serving the Public Interest Serving the Public Interest THE SPEAKER LEGISLATIVE ASSEMBLY THE PRESIDENT
DDoS Attack Mitigation Report. Media & Entertainment Finance, Banking & Insurance. Retail
DDoS Attack Mitigation Report Media & Entertainment Finance, Banking & Insurance Retail DDoS Attack Mitigation Report Media & Entertainment Attack on Spanish-Language News Site is Abandoned When Traffic
NEW ZEALAND S CYBER SECURITY STRATEGY
Appendix 1 NEW ZEALAND S CYBER SECURITY STRATEGY June 2011 New Zealand Government 7 June 2011 ISBN: 978-0-478-38200-6 www.med.govt.nz/cyberstrategy MED11 Foreword from the Minister The Internet and digital
Hong Kong Information Security Outlook 2015 香 港 資 訊 保 安 展 望
Hong Kong Information Security Outlook 2015 香 港 資 訊 保 安 展 望 Agenda Information Security Trends Year 2014 in Review Outlook for 2015 Advice to the Public Hong Kong Computer Emergency Response Team Coordination
Network Security. Dr. Ihsan Ullah. Department of Computer Science & IT University of Balochistan, Quetta Pakistan. April 23, 2015
Network Security Dr. Ihsan Ullah Department of Computer Science & IT University of Balochistan, Quetta Pakistan April 23, 2015 1 / 24 Secure networks Before the advent of modern telecommunication network,
Acceptable Use Policy
Acceptable Use Policy Contents 1. Internet Abuse... 2 2. Bulk Commercial E-Mail... 2 3. Unsolicited E-Mail... 3 4. Vulnerability Testing... 3 5. Newsgroup, Chat Forums, Other Networks... 3 6. Offensive
Fighting Cyber Crime in the Telecommunications Industry. Sachi Chakrabarty
Fighting Cyber Crime in the Telecommunications Industry Sachi Chakrabarty Agenda Cyber Crime What s all the fuss about CyberCrime? DoS Attacks Telco Solutions Cybercrime? Cybercrime Definition All criminal
KEY STEPS FOLLOWING A DATA BREACH
KEY STEPS FOLLOWING A DATA BREACH Introduction This document provides key recommended steps to be taken following the discovery of a data breach. The document does not constitute an exhaustive guideline,
Russian Federal Security Service (FSB) Internet Operations Against Ukraine A TAIA GLOBAL REPORT
Russian Federal Security Service (FSB) Internet Operations Against Ukraine A TAIA GLOBAL REPORT COPYRIGHT 2015 TAIA GLOBAL INC ALL RIGHTS RESERVED Russian Federal Security Service (FSB) Internet Operations
Statement for the Record. Richard Bejtlich. Chief Security Strategist. FireEye, Inc. Before the. U.S. House of Representatives
Statement for the Record Richard Bejtlich Chief Security Strategist FireEye, Inc. Before the U.S. House of Representatives Committee on Energy and Commerce Subcommittee on Oversight and Investigations
Next Generation Security Strategies. Marc Sarrias Regional Sales Manager [email protected]
Next Generation Security Strategies Marc Sarrias Regional Sales Manager [email protected] IT Ever-Evolving Challenges & Constraints Support IT Initiatives Minimize Business Risks from Cybersecurity
CHAPTER 3 : INCIDENT RESPONSE THREAT INTELLIGENCE GLOBAL THREAT INTELLIGENCE REPORT 2015 :: COPYRIGHT 2015 NTT INNOVATION INSTITUTE 1 LLC
: INCIDENT RESPONSE THREAT INTELLIGENCE 1 THREAT INTELLIGENCE How it applies to our clients, and discuss some of the key components and benefits of a comprehensive threat intelligence strategy. Threat
SUMMARY OF THE ESTONIAN INFORMATION SYSTEM S AUTHORITY ON ENSURING CYBER SECURITY IN 2012
SUMMARY OF THE ESTONIAN INFORMATION SYSTEM S AUTHORITY ON ENSURING CYBER SECURITY IN 2012 Cyberspace is both an ecosystem consisting of an infrastructure and services, and an environment where and through
Cyber Security Strategy
NEW ZEALAND S Cyber Security Strategy 2015 A secure, resilient and prosperous online New Zealand Ministerial Foreword The internet and technology have become a fundamental element in our lives. We use
The UK cyber security strategy: Landscape review. Cross-government
REPORT BY THE COMPTROLLER AND AUDITOR GENERAL HC 890 SESSION 2012-13 12 FEBRUARY 2013 Cross-government The UK cyber security strategy: Landscape review 4 Key facts The UK cyber security strategy: Landscape
2015 Michigan NASCIO Award Nomination. Cyber Security Initiatives: Michigan Cyber Disruption Response Strategy
2015 Michigan NASCIO Award Nomination Cyber Security Initiatives: Michigan Cyber Disruption Response Strategy Sponsor: David Behen, DTMB Director and Chief Information Officer Program Manager: Rod Davenport,
Quality Certificate for Kaspersky DDoS Prevention Software
Quality Certificate for Kaspersky DDoS Prevention Software Quality Certificate for Kaspersky DDoS Prevention Software Table of Contents Definitions 3 1. Conditions of software operability 4 2. General
2 Gabi Siboni, 1 Senior Research Fellow and Director,
Cyber Security Build-up of India s National Force 2 Gabi Siboni, 1 Senior Research Fellow and Director, Military and Strategic Affairs and Cyber Security Programs, Institute for National Security Studies,
Keynote. Professor Russ Davis Chairperson IC4MF & Work Shop Coordinator for Coordinator for Technology, Innovation and Exploitation.
Keynote Professor Russ Davis Chairperson IC4MF & Work Shop Coordinator for Coordinator for Technology, Innovation and Exploitation 6 & 7 Nov 2013 So many of us now don t just work online but live part
Cyber Security Strategy
2014 2017 Cyber Security Strategy Ministry of Economic Affairs and Communication 2014 TABLE OF CONTENTS Introduction... 2 1. Analysis of current situation... 2 1.1. Sectoral progress... 2 1.2. Trends...
Protecting against DoS/DDoS Attacks with FortiWeb Web Application Firewall
Protecting against DoS/DDoS Attacks with FortiWeb Web Application Firewall A FORTINET WHITE PAPER www.fortinet.com Introduction Denial of Service attacks are rapidly becoming a popular attack vector used
DDoS ATTACKS: MOTIVES, MECHANISMS AND MITIGATION
DDoS ATTACKS: MOTIVES, MECHANISMS AND MITIGATION Stephen Gates Chief Security Evangelist Corero Network Security Session ID: SEC-W04 Session Classification: Intermediate Recent Headlines Are Denial of
Locked Shields 2013. Kaur Kasak 24 Sept 2013
Locked Shields 2013 Kaur Kasak 24 Sept 2013 Disclaimer: This briefing is a product of the CCD COE. It does not represent the opinions or policies of NATO and is designed to provide an independent position.
資 通 安 全 產 品 研 發 與 驗 證 (I) ICT Security Overview. Prof.. Albert B. Jeng ( 鄭 博 仁 教 授 ) 景 文 科 技 大 學 資 訊 工 程 系
資 通 安 全 產 品 研 發 與 驗 證 (I) ICT Security Overview Prof.. Albert B. Jeng ( 鄭 博 仁 教 授 ) 景 文 科 技 大 學 資 訊 工 程 系 Outline Infosec, COMPUSEC, COMSEC, and Network Security Why do we need Infosec and COMSEC? Security
Cybercrime: risks, penalties and prevention
Cybercrime: risks, penalties and prevention Cyber attacks have been appearing in the news with increased frequency and recent victims of cybercrime have included well-known companies such as Sony, LinkedIn,
Policies and Practices on Network Security of MIIT
2011/TEL43/SPSG/WKSP/004 Policies and Practices on Network Security of MIIT Submitted by: China Workshop on Cybersecurity Policy Development in the APEC Region Hangzhou, China 27 March 2011 Policies and
HOW TO PREVENT DDOS ATTACKS IN A SERVICE PROVIDER ENVIRONMENT
HOW TO PREVENT DDOS ATTACKS IN A SERVICE PROVIDER ENVIRONMENT The frequency and sophistication of Distributed Denial of Service attacks (DDoS) on the Internet are rapidly increasing. Most of the earliest
DDoS Overview and Incident Response Guide. July 2014
DDoS Overview and Incident Response Guide July 2014 Contents 1. Target Audience... 2 2. Introduction... 2 3. The Growing DDoS Problem... 2 4. DDoS Attack Categories... 4 5. DDoS Mitigation... 5 1 1. Target
Spear Phishing Attacks Why They are Successful and How to Stop Them
White Paper Spear Phishing Attacks Why They are Successful and How to Stop Them Combating the Attack of Choice for Cybercriminals White Paper Contents Executive Summary 3 Introduction: The Rise of Spear
MEMORANDUM. Date: October 28, 2013. Federally Regulated Financial Institutions. Subject: Cyber Security Self-Assessment Guidance
MEMORANDUM Date: October 28, 2013 To: Federally Regulated Financial Institutions Subject: Guidance The increasing frequency and sophistication of recent cyber-attacks has resulted in an elevated risk profile
Cyber, Social Media and IT Risks. David Canham (BA) Hons, MIRM
IIA South Event 16 th June 2015 Cyber, Social Media and IT Risks 1 st and 2 nd Line Perspective David Canham (BA) Hons, MIRM Agenda This evening we ll cover the following: Who, why and what? Traditional
Cyber security Time for a new paradigm. Stéphane Hurtaud Partner Information & Technology Risk Deloitte
Cyber security Time for a new paradigm Stéphane Hurtaud Partner Information & Technology Risk Deloitte 90 More than ever, cyberspace is a land of opportunity but also a dangerous world. As public and private
SECURITY REIMAGINED SPEAR PHISHING ATTACKS WHY THEY ARE SUCCESSFUL AND HOW TO STOP THEM. Why Automated Analysis Tools are not Created Equal
WHITE PAPER SPEAR PHISHING ATTACKS WHY THEY ARE SUCCESSFUL AND HOW TO STOP THEM Why Automated Analysis Tools are not Created Equal SECURITY REIMAGINED CONTENTS Executive Summary...3 Introduction: The Rise
BUCKEYE EXPRESS HIGH SPEED INTERNET SERVICE ACCEPTABLE USE POLICY
BUCKEYE EXPRESS HIGH SPEED INTERNET SERVICE ACCEPTABLE USE POLICY The Acceptable Use Policy ("the Policy") governs use of the Buckeye Express High Speed Internet Service ("the Service"). All subscribers
WRITTEN TESTIMONY OF
WRITTEN TESTIMONY OF KEVIN MANDIA CHIEF EXECUTIVE OFFICER MANDIANT CORPORATION BEFORE THE SUBCOMMITTEE ON CRIME AND TERRORISM JUDICIARY COMMITTEE UNITED STATES SENATE May 8, 2013 Introduction Thank you
Ukraine Document Based Question (DBQ) Central Question: What is happening in Ukraine?
Ukraine Document Based Question (DBQ) Central Question: What is happening in Ukraine? Map of the Soviet Union and Eastern Europe during the Cold War: Located in Eastern Europe, Ukraine became a part of
TDC s perspective on DDoS threats
TDC s perspective on DDoS threats DDoS Dagen Stockholm March 2013 Lars Højberg, Technical Security Manager, TDC TDC in Sweden TDC in the Nordics 9 300 employees (2012) Turnover: 26,1 billion DKK (2012)
Cybersecurity and internal audit. August 15, 2014
Cybersecurity and internal audit August 15, 2014 arket insights: what we are seeing so far? 60% of organizations see increased risk from using social networking, cloud computing and personal mobile devices
CSE 3482 Introduction to Computer Security. Denial of Service (DoS) Attacks
CSE 3482 Introduction to Computer Security Denial of Service (DoS) Attacks Instructor: N. Vlajic, Winter 2015 Learning Objectives Upon completion of this material, you should be able to: Explain the basic
Defending Against Data Beaches: Internal Controls for Cybersecurity
Defending Against Data Beaches: Internal Controls for Cybersecurity Presented by: Michael Walter, Managing Director and Chris Manning, Associate Director Protiviti Atlanta Office Agenda Defining Cybersecurity
The Foreign Policy of Ukraine
The Foreign Policy of Ukraine One Year After the Orange Revolution PONARS Policy Memo No. 372 Volodymyr Dubovyk Odessa National University December 2005 It has been a year since the Orange Revolution in
Understanding and Defending Against the Modern DDoS Threat
Understanding and Defending Against the Modern DDoS Threat SESSION ID: CLE-T09 Stephen Gates Chief Security Evangelist Corero Network Security @StephenJGates Understand you re vulnerable! How well are
for Critical Infrastructure Protection Supervisory Control and Data Acquisition SCADA SECURITY ADVICE FOR CEOs
for Critical Infrastructure Protection Supervisory Control and Data Acquisition SCADA SECURITY ADVICE FOR CEOs EXECUTIVE SUMMARY Supervisory Control and Data Acquisition (SCADA) systems are used for remote
Threats and Attacks. Modifications by Prof. Dong Xuan and Adam C. Champion. Principles of Information Security, 5th Edition 1
Threats and Attacks Modifications by Prof. Dong Xuan and Adam C. Champion Principles of Information Security, 5th Edition 1 Learning Objectives Upon completion of this material, you should be able to:
Protect your network: planning for (DDoS), Distributed Denial of Service attacks
Protect your network: planning for (DDoS), Distributed Denial of Service attacks Nov 19, 2015 2015 CenturyLink. All Rights Reserved. The CenturyLink mark, pathways logo and certain CenturyLink product
How To Perform A Large Scale Attack On A Large Network
95 95 9. Exercise: Large Scale Incident Handling Main Objective Targeted Audience Total Duration Time Schedule The main objective of the exercise is to teach incident handlers the key information and actions
RUSSIA CHINA NEXUS IN CYBER SPACE
RUSSIA CHINA NEXUS IN CYBER SPACE E. Dilipraj Associate Fellow, CAPS On May 08, 2015 Russia and China inked an important agreement in the field of cyber security. This bilateral agreement is the latest
OVERVIEW BY THE US-CCU OF THE CYBER CAMPAIGN AGAINST GEORGIA
A US-CCU Special Report August 2009 OVERVIEW BY THE US-CCU OF THE CYBER CAMPAIGN AGAINST GEORGIA IN AUGUST OF 2008 The ramifications of the August 2008 cyber campaign against Georgia are still being felt
CYBER SECURITY AND RISK MANAGEMENT. An Executive level responsibility
CYBER SECURITY AND RISK MANAGEMENT An Executive level responsibility Cyberspace poses risks as well as opportunities Cyber security risks are a constantly evolving threat to an organisation s ability to
Beyond the Hype: Advanced Persistent Threats
Advanced Persistent Threats and Real-Time Threat Management The Essentials Series Beyond the Hype: Advanced Persistent Threats sponsored by Dan Sullivan Introduction to Realtime Publishers by Don Jones,
Cyber Threats Insights from history and current operations. Prepared by Cognitio May 5, 2015
Cyber Threats Insights from history and current operations Prepared by Cognitio May 5, 2015 About Cognitio Cognitio is a strategic consulting and engineering firm led by a team of former senior technology
