The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Hezbollah Has Hacking Chops


Posted by George Hulme, Jun 3, 2008 08:36 PM

Michael Chertoff, Homeland Security secretary, recently stated that Hezbollah is the greatest threat to U.S. national security. And Western intelligence agencies are increasingly taking the organization's cyberattack skills more seriously. What do you think their targets would be?

The topic of cyberwarfare reared its head again in this DefenseTech.org post. There's been talk about cyberwar for quite some time. Kevin Coleman writes that a 2002 CIA report noted that several groups were beginning to plan attacks on Western networks. I wrote this cover story about cyberwarfare on the eve of the Iraqi war.

Today, Coleman cites a number of estimated Hezbollah capabilities:

Equipment: Hezbollah possesses up-to-date information technologies -- broadband wireless networks and computers.

Cyber Capabilities: Global Rating in Cyber Capabilities -- Tied at Number 37
Hezbollah has been able to engage in fiber optic cable tapping, enabling data interception and the hijacking of Internet and communication connections.

Cyber Warfare Budget: $935,000 USD

Offensive Cyber Capabilities: 3.1 (1 = Low, 3 = Moderate and 5 = Significant)

Cyber Weapons Rating: Basic -- but developing intermediate capabilities

The post goes on:

Using new hacking techniques, taking advantage of security vulnerabilities, and using simple, proven cyberattack methods, terrorists have the capability to attack us in ways not seen before. Key infrastructure systems that include utilities, banking, media/TV systems, telecommunications, and air traffic control systems have already been compromised. No one knows if cyber terrorists created trap doors and left logic bombs allowing them to easily bypass security systems and disrupt our critical infrastructure in coordination with traditional style attacks.

The notion that cyberterrorists have created trap doors, or left logic bombs behind in previous attacks, strikes me as a bit far-fetched. It's possible, and the recent alarm from the FBI about counterfeit Cisco routers is cause for concern. But IT systems change fairly quickly, and the utility of such digital plants wouldn't have a long shelf life, and couldn't be guaranteed to work when needed. I'm not sure what the "new" hacking techniques would be.

However, there's no doubt in my mind that cyberattacks against Western interests are going to supplement traditional warfare. They'll be used to attempt to disrupt financial networks, emergency responders, power, and other fundamental aspects of society.

The good news is that there's no secret nation-state or terrorist attack kit. I'm not aware of any super-duper denial-of-service attack capabilities that have yet to be unleashed. These attacks, if they happen at all, will most likely resemble the attacks against unpatched systems, or social engineering a user to somehow provide access. The odds of sustaining such an attack are in your favor, if you build a resilient architecture, with good security, risk management, and business-continuity procedures in place. In fact, any such attacks should be far less disruptive than the possible hacks, hurricanes, tornadoes, fires, or any other natural disaster you're already planning for.

The takeaway: If you're prepared for a sizable natural disaster, and already hardening your systems, you're as covered as you can be.

« CIO Succession: Lack Of Inside Talent, Or Lack Of Opportunity? | Main | O2 Employees Fired For Selling iPhones On eBay »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 

  1. Actors, Messages and Low Lock Contention for Java
  2. Of Course The Transformers are Multicore with SMT technology
  3. Find John Fast!!


Join The InformationWeek Group On LinkedIn


                           


  1. Why I'm Dropping Bing For Google
  2. Video: iPhone Tips And Tricks
  3. Zero-Day Hits Microsoft DirectShow
  4. Palm Pre Sales Reports Not Meshing
  5. Is This Sony Ericsson's First Android Phone?


  1. Amazon's Kindle 2 Gets A Price Cut
  2. Texting Trolley Operator Indicted
  3. Amazon Launches Web Site For Cell Phones
  4. Military Grapples With Information Overload
  5. DHS Systems More Secure, Inspector General Finds
  6. EMC Acquires Data Domain For $2.4 Billion

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007