<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Layer 7 - Blogs &#187; Cyber Security</title>
	<atom:link href="http://www.layer7tech.com/blogs/index.php/category/cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.layer7tech.com/blogs</link>
	<description>API Management &#124; SOA Governance &#124; Cloud Integration</description>
	<lastBuildDate>Mon, 10 Jun 2013 21:00:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Layer 7 at Gartner Security &amp; Risk Management Summit</title>
		<link>http://www.layer7tech.com/blogs/index.php/layer-7-at-gartner-security-risk-management-summit/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/layer-7-at-gartner-security-risk-management-summit/#comments</comments>
		<pubDate>Fri, 08 Jun 2012 16:00:00 +0000</pubDate>
		<dc:creator>Jaime Ryan</dc:creator>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Mobile Access]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2236</guid>
		<description><![CDATA[Next week (June 11-14), Layer 7 will be exhibiting at the Gartner Security &#38; Risk Management Summit near Washington, DC (in National Harbor, MD). Speakers will run the gamut from Michael Dell to the Cybersecurity Coordinator for the White House, because enterprises and governmental organizations share a serious interest in securing data and applications. The [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.gartner.com/technology/summits/na/security/" target="_blank"><img class="alignleft size-full wp-image-2238" style="margin: 5px;" title="Gartner Security and Risk Management" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/06/Gartner-Security-Risk-Management-v2.jpg" alt="Gartner Security and Risk Management" width="300" height="130" /></a>Next week (June 11-14), Layer 7 will be exhibiting at the <a href="http://www.gartner.com/technology/summits/na/security/" target="_blank">Gartner Security &amp; Risk Management Summit</a> near Washington, DC (in National Harbor, MD). Speakers will run the gamut from Michael Dell to the Cybersecurity Coordinator for the White House, because enterprises and governmental organizations share a serious interest in securing data and applications.</p>
<p>The combination of security and risk management is particularly interesting these days, as rapid migration to Cloud and Mobile has introduced a new set of risks. These new platforms raise issues around compliance, information security and identity management, which can only be addressed with a comprehensive approach to security, using proven technology.</p>
<p>If you’re at the show, stop by and visit Layer 7 at Booth 92. We’d love to demonstrate how our SOA Governance and API Management solutions can counteract the risks involved with adopting these new technologies. Our solutions – flexibly deployed on-premise or in the Cloud – provide control over data and applications being exposed to partners, Cloud and Mobile.</p>
<p>And <a href="http://www.layer7tech.com/products/industry-leading-xml-gateway-overview" target="_blank">our industry-leading technology</a> has been certified at the highest levels for use in both corporate and governmental organizations – <a href="http://www.layer7tech.com/solutions/pci-compliance-for-apis" target="_blank">PCI-DSS compliance</a> for retail, STIG vulnerability testing for the DoD, FIPS 140-2 for cryptographic functionality and <a href="http://www.layer7tech.com/products/eal4-common-criteria-certified-soa-gateway" target="_blank">Common Criteria certification</a> for overall security.</p>
<p>Don’t let the risk outweigh the reward – come <a href="http://www.layer7tech.com/contactus" target="_blank">talk to us</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/layer-7-at-gartner-security-risk-management-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Layer 7 at the 2012 DoDIIS Worldwide Conference</title>
		<link>http://www.layer7tech.com/blogs/index.php/layer-7-at-the-2012-dodiis-worldwide-conference/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/layer-7-at-the-2012-dodiis-worldwide-conference/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 16:00:38 +0000</pubDate>
		<dc:creator>Jim Rice</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Integration]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SOA]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=1674</guid>
		<description><![CDATA[Layer 7 is proud to be exhibiting at the 2012 Department of Defense Intelligence Information Systems (DoDIIS) Worldwide Conference, which will be taking place in Denver this April 1-4. The show will be focusing on the Defense Intelligence Agency’s goal of unifying defense intelligence infrastructure and information sharing initiatives. Never before has so much intelligence [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ncsi.com/dodiis12/index.html" target="_blank"><img class="alignleft size-full wp-image-1677" style="margin: 10px;" title="2012 DoDIIS Worldwide Conference" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/03/2012-DoDIIS-Worldwide-Conference-v1.jpg" alt="2012 DoDIIS Worldwide Conference" width="300" height="139" /></a>Layer 7 is proud to be exhibiting at the <a href="http://www.ncsi.com/dodiis12/index.html" target="_blank">2012 Department of Defense Intelligence Information Systems (DoDIIS) Worldwide Conference</a>, which will be taking place in Denver this April 1-4. The show will be focusing on the Defense Intelligence Agency’s goal of unifying defense intelligence infrastructure and information sharing initiatives.</p>
<p>Never before has so much intelligence data been collected and never has the challenge of securely sharing these valuable assets been greater. As new intelligence systems come online, issues inevitably arise around the need to make data and security credentials interoperable between these new systems and existing capabilities.</p>
<p>As the leading provider of secure messaging and security Gateway solutions to the US Federal Intelligence Community, Layer 7 will be at the show, demonstrating its solutions for data and security interoperability within the enterprise and the Cloud. If you’re attending the DoDIIS conference, stop by Booth 917 to see first-hand how you can resolve interoperability and fine-grained access challenges with a <a href="http://www.layer7tech.com/products/eal4-common-criteria-certified-soa-gateway" target="_blank">Common Criteria EAL 4+ certified solution from Layer 7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/layer-7-at-the-2012-dodiis-worldwide-conference/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Layer 7 Helps Keep America Safe</title>
		<link>http://www.layer7tech.com/blogs/index.php/layer-7-helps-keep-america-safe-2/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/layer-7-helps-keep-america-safe-2/#comments</comments>
		<pubDate>Mon, 19 Mar 2012 21:10:28 +0000</pubDate>
		<dc:creator>Jim Rice</dc:creator>
				<category><![CDATA[API]]></category>
		<category><![CDATA[API Management]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SOA]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=1703</guid>
		<description><![CDATA[At Layer 7, we often talk about how we can help enterprises open up net-centric information-sharing APIs. Often overlooked is the vital national security role APIs and net-centric computing perform – they are crucial to connecting applications residing across national agencies and even on mobile devices, vehicles and machines. For several years, Layer 7 has [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://washingtontechnology.com/articles/2012/03/14/northrop-af-center-upgrade.aspx" target="_blank"><img class="alignleft size-full wp-image-1709" style="margin: 10px;" title="Layer 7 Helps Keep America Safe" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/03/Layer-7-Helps-Keep-America-Safe-v3.jpg" alt="Layer 7 Helps Keep America Safe" width="300" height="199" /></a>At Layer 7, we often talk about how we can help enterprises open up net-centric information-sharing APIs. Often overlooked is the vital national security role APIs and net-centric computing perform – they are crucial to connecting applications residing across national agencies and even on mobile devices, vehicles and machines.</p>
<p>For several years, Layer 7 has proudly served national security communities in the US, Canada and Europe, with <a href="http://www.layer7tech.com/products/eal4-common-criteria-certified-soa-gateway" target="_blank">high-resiliency API security and management technologies for various SOA, mobile and Cloud initiatives</a>. We are proud to include among our clients some of the most demanding organizations on Earth, including the US DoD, US Department of Homeland Security, US Department of Justice, US Department of Transportation and NATO.</p>
<p>Layer 7 is continuing its efforts to help organizations like these address the challenges and opportunities associated with SOA-based information sharing and interoperability in the context of reduced budgets, increasing cyber threats, Cloud infrastructure and the need to leverage existing systems in a networked environment.</p>
<p>Due to the sensitive nature of the projects, much of our work to make these efforts successful goes unheralded. However, we are thrilled that one of our recent efforts in supporting Northrup Grumman modernize the US Air Force Air &amp; Space Operations Center Weapons System <a href="http://washingtontechnology.com/articles/2012/03/14/northrop-af-center-upgrade.aspx" target="_blank">has been publicly announced</a>.</p>
<p>Layer 7 is working with a consortium of vendors under Northrup Grumman to <a href="http://www.af.mil/news/story.asp?id=123241047" target="_blank">make the Air &amp; Space Operations Center more agile and net-centric via Service-Oriented, API-based approaches to information sharing</a>. Clearly, SOA and net-centric computing are becoming cornerstones of how applications are discovered, connected and protected and how information is shared.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/layer-7-helps-keep-america-safe-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defense Department Contractors Targeted</title>
		<link>http://www.adamdvincent.com/2011/06/defense-department-contractors-targeted.html</link>
		<comments>http://www.adamdvincent.com/2011/06/defense-department-contractors-targeted.html#comments</comments>
		<pubDate>Thu, 02 Jun 2011 20:26:00 +0000</pubDate>
		<dc:creator>Adam Vincent</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Information Assurance]]></category>
		<category><![CDATA[RSA]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?guid=9e6914d8bf2961e10a7a8cee58e75721</guid>
		<description><![CDATA[In the last week Lockheed Martin, then L-3 Communications Holdings have been in the news due to sophisticated cyber attacks on their networks by unknown actors.   Now there are rumors that Northrop Grumman may have been targeted as well, since the comp...]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">In the last week Lockheed Martin, then L-3 Communications Holdings have been in the news due to sophisticated cyber attacks on their networks by unknown actors.<span style="mso-spacerun:yes">  </span><span style="mso-spacerun:yes"> </span>Now there are rumors that Northrop Grumman may have been targeted as well, since the company shut down remote access to the company's network.<span style="mso-spacerun:yes">  </span>Are these events linked to the attack on <a href="http://www.cybersquared.com/rsa-hacked-by-advanced-persistent-threat-apt/">RSA which was reported on May 17th</a>?</p>  <p class="MsoNormal">For those that haven't been keeping up, it is assumed the adversaries responsible for the RSA intrusion may have access to the seed files, serial numbers and the algorithm for multiple RSA keyfobs used by over 40 million RSA customers worldwide.<span style="mso-spacerun:yes">  </span>Although RSA is saying that this information alone can't be used to launch an attack, it's not hard to assume that the attackers either already have or are confident they can get what they needed to use the stolen RSA information to launch a successful attack.<span style="mso-spacerun:yes">  </span></p>  <p class="MsoNormal">This recent activity goes beyond the need for "cleanup on isle 9", and leads one to believe that all these events could be the start to a series of attacks which were extensively planned, beginning with the RSA attack, and are now and will continue to be well resourced.<span style="mso-spacerun:yes">  </span>Given the high profile nature of the businesses being targeted, and the level of effort involved, I think it's safe to assume that we will see more from these attackers in the future. In an effort to better prepare ourselves for future attacks here are some questions needing answers:</p><p class="MsoNormal"></p><p class="MsoNormal"></p><ol><li>What data were the attackers after and why?</li><li>How did those companies get exploited?</li><li>Were there signs prior to the exploitation attempts?</li><li>Was there active reconnaissance of the company or their users?</li><li>Were there exploitation attempts against their users that failed?</li><li>Were there exploitation attempts against the company network?</li><li>Is the RSA attack and these incidents truly linked?</li></ol><p></p><p></p>  <p class="MsoNormal">VPN access, albeit a necessity for remote users, is a major security risk that needs to be actively monitored.<span style="mso-spacerun:yes">  </span>One of the initial steps in conducting network defense is to define the enclave’s borders which is increasingly difficult because of the needs of remote users and the federations across organizations.<span style="mso-spacerun:yes">  </span>Each access point of a network needs to be heavily monitored and the systems that are used to access the VPN need to be examined on a regular basis to ensure there is no malicious software located on their systems.<span style="mso-spacerun:yes">  </span>Given the current trend to move to the cloud one begins to wonder where the enterprise starts and stops and how we can truly protect the enterprise from the perimeter.<span style="mso-spacerun:yes">  </span></p>  <p class="MsoNormal" style="tab-stops:279.15pt">Reference:<span style="mso-tab-count: 1">                                                                                                     </span></p>  <p class="MsoNormal"><a href="http://www.eweek.com/c/a/Security/Northrop-Grumman-L3-Communications-Hacked-via-Cloned-RSA-SecurID-Tokens-841662/"><span class="Apple-style-span">http://www.eweek.com/c/a/Security/Northrop-Grumman-L3-Communications-Hacked-via-Cloned-RSA-SecurID-Tokens-841662/</span></a></p>  <p class="MsoNormal"><a href="http://www.informationweek.com/news/government/security/229700151"><span class="Apple-style-span">http://www.informationweek.com/news/government/security/229700151</span></a></p>  <p class="MsoNormal"><a href="http://www.lockheedmartin.com/news/press_releases/2011/0528hq-secuirty.html"><span class="Apple-style-span">http://www.lockheedmartin.com/news/press_releases/2011/0528hq-secuirty.html</span></a></p><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7677804843756920987-1827694546479307344?l=www.adamdvincent.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://www.adamdvincent.com/feeds/1827694546479307344/comments/default</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Attack on Google and Others</title>
		<link>http://www.adamdvincent.com/2010/01/cyber-attack-on-google-and-others.html</link>
		<comments>http://www.adamdvincent.com/2010/01/cyber-attack-on-google-and-others.html#comments</comments>
		<pubDate>Fri, 15 Jan 2010 16:43:00 +0000</pubDate>
		<dc:creator>Adam Vincent</dc:creator>
				<category><![CDATA[Cloud Access Control]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Information Assurance]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?guid=e9b34cef93477de0f7c77ab3e5322c6a</guid>
		<description><![CDATA[On Tuesday, Google reported in their official blog that in mid-December they detected a "highly sophisticated and targeted" attack on their corporate infrastructure originating from China that resulted in the theft of intellectual property from Google....]]></description>
			<content:encoded><![CDATA[<p style="font-family: arial;" class="MsoNormal"><span style="font-size:85%;"><span class="Apple-style-span">On Tuesday, Google reported in their official blog that in mid-December they detected a "highly sophisticated and targeted" attack on their corporate infrastructure originating from China that resulted in the theft of intellectual property from Google. Additionally, Google stated in this blog that 20 other large companies were similarly targeted.  Google went on to state that they have evidence to suggest that a primary goal of the attackers was to access the Gmail accounts of Chinese human rights activists.  This incident, as well as the limitation on free speech imposed on Google by the Chinese government, is forcing Google to review the feasibility of their business operations in China.   </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p style="font-family: arial;" class="MsoNormal"><span style="font-size:85%;"><span class="Apple-style-span">In follow-up, a number of security firms who are supporting the investigation have concluded that the number of attacked companies is not 20 but between 30 and 34.  Most of the attacked were large Fortune 500 companies.  The attack code named "Aurora" by the attackers was made up of dozens of pieces of malware, and several levels of encryption to hide itself in the targeted company networks and to obscure activity.  </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p style="font-family: arial;" class="MsoNormal"><span style="font-size:85%;"><span class="Apple-style-span">The U.S. Government has been under this type of attack for many years.  This is the first time that a highly organized and sophisticated attack was launched on private industry.    Who knows what the impact of this will be on the global economy?  The mind can only fathom what would happen if each of the companies attacked lost some intellectual property which resulted in them being "second to market" for a product that they have been planning for and building for months or even years.  </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">What we know about Aurora </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">There is some debate currently on whether Aurora leveraged a vulnerability in Internet Explorer and Adobe's Reader and Acrobat applications or whether the attack only leveraged Internet Explorer.  Either way, Aurora installation began on the targeted system by viewing a malicious website or potentially through opening a PDF document sent in an email but as I mentioned this has not been substantiated by Adobe.  Once executed in the browser  an encrypted shell script would run.  The shell script downloaded the binary from an external machine which once executed would open a backdoor to the attackers Command and Control servers.  These servers were purportedly running in hosted facilities in the US.  This allowed the attacker some level of access into the users machine and the network to which the machine is connected.  </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin-bottom: 0.0001pt; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span"> </span></span><span style="font-size:85%;"><span class="Apple-style-span">Microsoft Versions Affected:</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-family: arial;"><span class="apple-style-span"  style="font-size:85%;"><span style=";color:black;" ><span class="Apple-style-span">According to Microsoft, Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6, Internet Explorer 7 and Internet Explorer 8 on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are affected.</span></span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p style="font-family: arial;" class="MsoNormal"><span style="font-size:85%;"><span class="Apple-style-span">Let's review the time line of events in this event.  The following dates/times were derived from various sources on the internet. </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.25in; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">Mid-December - Google detects a "highly sophisticated and targeted" cyber attack</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.25in; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">January 2nd - Adobe becomes aware of "sophisticated, and coordinated" cyber attack</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.25in; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">January 4th - Attack seems to have stopped as Command  &amp; Control  Servers are shut down</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.25in; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">January 12th/3pm - Google announces the Cyber Attack via blog</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.25in; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">January 12th/3:16pm - Adobe announces the Cyber Attack via blog</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.25in; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">January 12th/Evening - U.S. Government asks China for an Explanation</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.25in; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">January 14th - Microsoft issues a security advisory</span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-family: arial;"><span style="font-size:85%;"><o:p><span class="Apple-style-span"> </span></o:p></span></p><p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-family: arial;"><span class="Apple-style-span"  style="font-size:85%;"><span class="Apple-style-span"><span class="Apple-style-span"><br /></span></span></span></p>  <p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-family: arial;"><span style="font-size:85%;"><span class="Apple-style-span">When looking at the time line the scary thing is that the attack seems to have been commencing from mid-December (let's say the 15th).  If Google detected it at its start, which may not be the case, and it was not shut down till January 4th, the attackers had 21 days of access.  It's scary to think how much information could have been stolen and potentially how much damage the attackers could have done in 21 days should this have been their goal.  </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p style="font-family: arial;" class="MsoNormal"><span style="font-size:85%;"><span class="Apple-style-span">As stated in the U.S. Government Cyberspace policy review, information and communication networks are largely owned and operated by the private sector, both nationally and internationally.  The report goes on to state that Cyber security requires a public-private partnership as well as international cooperation.  Unfortunately, we are sorely lacking in the ability to ensure a coordinated response and recovery to a significant incident should one occur.  This time line only proves this point.  It appears as though private/public communication did not effectively start till January 12th, during this time companies were infiltrated, but yet may not have known.  Even if Google had notified all the companies it derived were under attack from the information they had available, there is nothing to say that another attack was not going on simultaneously by the same attackers but disconnected from the one affiliated with Google.   </span><span class="Apple-style-span"><o:p></o:p></span></span></p>  <p class="MsoNormal"><span style="font-size:11;"><span style="font-family: arial;font-family:arial;font-size:85%;" class="Apple-style-span"  >With worldwide cyber attacks becoming more focused, we must accelerate our ability to deal with them more rapidly in a coordinated fashion.  This particular instance seems to have been about stealing information, monetary gain, or political issues.   We need to remember that it could just have easily been about disrupting critical national infrastructure for pursuit of national disorganization and loss of life.  </span><o:p></o:p></span></p><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7677804843756920987-4110723421395324853?l=www.adamdvincent.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://www.adamdvincent.com/feeds/4110723421395324853/comments/default</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Iranian Cyber Army Hacks Twitter</title>
		<link>http://www.adamdvincent.com/2009/12/iranian-cyber-army-hacks-twitter.html</link>
		<comments>http://www.adamdvincent.com/2009/12/iranian-cyber-army-hacks-twitter.html#comments</comments>
		<pubDate>Fri, 18 Dec 2009 12:58:00 +0000</pubDate>
		<dc:creator>Adam Vincent</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Information Assurance]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?guid=71d4eea2a6324051c7514317b518fe8e</guid>
		<description><![CDATA[Last night Twitter.com was hacked by a group purportedly titled the Iranian Cyber Army, at least that is what they want people to think.   This group advertised they were responsible by displaying a redirected Web page with an Iranian flag and text tha...]]></description>
			<content:encoded><![CDATA[Last night Twitter.com was hacked by a group purportedly titled the Iranian Cyber Army, at least that is what they want people to think.   This group advertised they were responsible by displaying a redirected Web page with an Iranian flag and text that takes credit, saying "This website has been hacked by the Iranian Cyber Army".  This morning another Web site (mawjcamp.org), which appears to be a Iranian Reformist website based outside of Iran, was also found to have been hacked.<div><br /></div><div>This event comes at a time when the United States Government is saying that cyberspace is the next frontier for "organized" military/terrorist organizations to attack US critical infrastructure. Most probably don't think that Twitter is critical, however this does represent a formidable day in the cyber war.  Although there have been other organized attacks to date, this is one of the most high profile instance of a politically motivated group attacking a website.  Whether it is the so-called "Iranian Cyber Army" or a random group of mischiefs, this illustrates how vulnerable sites are to attack.</div><div><br /></div><div>According to Twitter, the attack was accomplished by temporarily compromising the Twitter DNS records via DNS hijacking, to redirect incoming www.twitter.com to another webpage which was likely hosted on a free web hosting server, which hasn't been identified as of yet.  DNS hijacking or DNS redirection is the proactive act of redirecting the resolution of Domain Name System (DNS) names to IP addresses from legitimate DNS servers to rogue DNS servers. This is done particularly for the practice of injecting malware into unsuspecting computers, pharming, phising or defacing.  </div><div><br /></div><div>This appears to only have been a successful defacing attack, the attacker could have just as easily created a fake twitter page, and pharmed or phished information from users.  Those users would have unknowingly divulged their username and password to the attackers, and potentially their private tweets.</div><div><br /></div><div>The question is: What is next from the Iranian Cyber Army?</div><div><br /></div><div><br /></div><div><br /></div><div>  </div><div><br /></div><div><br /></div><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7677804843756920987-4126092337641010042?l=www.adamdvincent.com' alt='' /></div>]]></content:encoded>
			<wfw:commentRss>http://www.adamdvincent.com/feeds/4126092337641010042/comments/default</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
