December 01, 2006
If the best they can do is take a website like The Jawa Report offline for a few days, then I think the NYSE is in pretty good shape to ward off an attack.
I mostly agree with noted anti-cyber jihad expert Laura Mansfield's assessment. Here is how she describes where the threat:
The posting [on a well known jihadi forum] called for attackers to use “destructive viruses†and to attempt to bring down the websites and penetrate and destroy databases....Go read the rest, especially about about the e-Jihad software now being distributed, if you are interested in cyber terrorism issues. I'm sure our friends at Black Flag will be particularly interested. Let me disagree with Laura on one minor issue, though. That is saying this isn't really an 'al Qaeda attack'. Well, it all depends on how you define "al Qaeda".These are basically “entrepreneurial terroristsâ€, individuals and small groups who are inspired and motivated by Al Qaeda but who do not receive orders or funding from Al Qaeda leadership. Instead, these individuals act on their own and without the support of the Al Qaeda infrastructure....
So far, these “attacks†have caused, at most, minor disruption and slowdown to targeted sites. The organization behind these “terrorist hackers†and their attacks just doesn’t seem to well enough developed to mount a successful attack.
We are now on al Qaeda 3.0. Al Qaeda 1.0 was an organizational structure of hierarchy (bin Laden at top, and soldiers at bottom). Al Qaeda 2.0 was more vertically organized--a 'franchise' if you will (Corporate headquarters in bin Laden or Zawahiri's cave, with Abu Musab al Zarqawi flying the franchise flag in Iraq).
Al Qaeda 3.0 is even less vertically organized. Al Qaeda 3.0 is less a 'franchise' and more of a 'brand'. This 'branded terrorism' is composed of individual and self-sustaining cells who carry the brand name of al Qaeda, but which may, in fact, have no official ties to the organization at all.
Some of them call themselves 'al Qaeda', but others don't. But, for all intents and purposes, those that don't officially brand themselves 'al Qaeda' may as well be. Think the branding of 'Kleenex'. A branding campaign so successful, that all tissues are called 'Kleenex'.
So, I do not believe it is erroneous to call the cyber jihadis 'al Qaeda' at all.
The U.S. government has warned U.S. private financial services of an al Qaeda call for a cyber attack against U.S. online stock trading and banking Web sites beginning Friday, officials said Thursday.The officials - a person familiar with the warning and a spokesman for the Department of Homeland Security - said the Islamic militant group aimed to penetrate and destroy the databases of the U.S. stock market and banking Web sites.
Posted by: Rusty at
10:42 AM
| Comments (9)
| Add Comment
Post contains 514 words, total size 4 kb.
Six of one ...
Posted by: slug at December 01, 2006 12:40 PM (IvTJ3)
slug,
There are ways to differentiate between the two but these are too technical for me to go into here. The attacker to worry about really isn't "Achmed living in a cave" its a group of Salafi sympathizers who fancy themselves hackers. Add in the bonus of living in a majority Muslim country where they don't face prosecution for attacking the kafir and you've got a recipe for trouble. There are roughly 300 million bot infected PC's on the globe divided into multiple bot nets of varying size. The Jawa Report, LGF, Malkin, Aarons Rantblog and many others have already had a taste of what attention from these groups is like. Fortunately the US a good infrastructure and can typically divert such attacks with a little effort.
Am I worried about the stock exchange being ddos'ed? Not really, I don't expect "Al Qaeda" proper has those kinds of resources, but it's sympathizers definitely have the ability to silence dissenting opinions if they wish.
Posted by: blackflag at December 01, 2006 01:35 PM (Mq5jS)
FYI--IQ is the country code for Iraq, meaning the registrant claims he's in that country. His hosting country just happens to be the UK, because he went through Lycos UK.
Posted by: Rusty at December 01, 2006 01:43 PM (JQjhA)
Posted by: davec at December 01, 2006 02:12 PM (yaQM4)
That is true, I just didn't make that part as clear as it should have been.
davec, care to expand on that thought a little?
Posted by: blackflag at December 01, 2006 02:23 PM (Mq5jS)
Posted by: Randman at December 01, 2006 05:46 PM (Sal3J)
not to get to far into it, but it was basically a client/server application that used agents to aggregate IDS triggered events and process. The agents were spread throughout the network architecture, once the agents received events from the IDS, it then used grouped rule sets, that were set into classifications like "footprinting", "shellcode-execution", "trojan activity", "ddos" etc that would profile the traffic and score the activity (to be delivered to incident response analysts) it kept low scores for common rules that were triggered by IDS's as False/Positives allowing the analysts to get high priority based events in "real time", it also used operating system based rulesets in a databases on the agents (so it would not deliver hacking attempts against a windows server by a Unix exploit as high priority)
Let's say certain people were more interested in HR related traffic profiling inside their network, e.x who was browsing for porn.
Posted by: davec at December 01, 2006 05:58 PM (yaQM4)
Sounds like a distributed IDS, like Sourcefires products. I monitor a dNIDS daily and perform intrusion analysis as well... I forget what the replacement for Carnivoure is offhand but I hope our guys are using it to it's fullest.
If you care to discuss IDS analysis in depth feel free to drop me an email.
/bf
Posted by: blackflag at December 01, 2006 08:42 PM (Ng7ee)
I can't discuss a lot of the ways threats, and the "network aware" modules worked, due to paperwork but the pilot project was suspended, and eventually R&D cut entirely.
Posted by: davec at December 01, 2006 10:23 PM (yaQM4)
34 queries taking 0.074 seconds, 164 records returned.
Powered by Minx 1.1.6c-pink.









