2011
08.13
By: kyle
Category:
All /
Tags: no tag /
Will major hacking attacks hide behind the next “Solar Flare”…
We just had a solar flare event a few days ago: http://www.pcmag.com/article2/0,2817,2390826,00.asp
Solar Flare, if NASA is right on their prediction, there will be a lot of problems in the next major solar flare in 2012 – 2013. When that happens, I can see major hacking attacks align their timing around it and just blame on the solar flare. Attacks could be launched during the chaos, and it might be hard initially to see if the mess is caused by natural event or human sabotage…
Remember the major blackout in Northeastern USA in 2003 which effected 45 million people? It was due to a “computer bug”, but I’m really not sure exactly what that means…
(http://en.wikipedia.org/wiki/Northeast_Blackout_of_2003)
Here is the “Super Solar Flare” article on the NASA website - http://science.nasa.gov/science-news/science-at-nasa/2008/06may_carringtonflare/
So, are we are prepared for the next solar flare event?
Thoughts?
2011
08.02
By: kyle
Category:
All /
Tags: no tag /
Some problems I see in addition to CyberSecurity
How would terrorist organizations target and recruit talents they really need?
- Look at Monster or Linkedin and see who listed themselves with Top Secret or TS/SCI clearance, or are in the Government Security Clearance / Top Secret Candidate groups
- Start a staffing firm and pretend that it is a TS cleared facility, then start calling candidates with clearance, and ask for their SSN over the phone, telling them that they need SSN to verify security clearance through JPAS…. When they get the SSN’s, they will be able to learn a lot more about these “candidates” through the background check services like credit check, family tree, etc.
- Start a cyber security penetration testing project with “unidentified targets” or “special ethical hacking exercise” and asking the newly hired security specialists to use all their knowledge to achieve the “goals” (whatever it might be).
- For the people who did not get hired, launch a campaign on social networking sites to befriend with these individuals and gain their trusts, for “future projects”.
So, my 2 cents on mitigating scenarios like this:
- Really marketing the Social Networking training from DISA (http://iase.disa.mil/eta/index.html) and hope people take this short training.
- Let the cleared personnel know not to list clearance info, specific intelligence agencies or projects experience on the web
- Change how clearance is verified by the security cleared facilities. It is becoming too common to have recruiters asking for SSN from cleared people so they can check on their JPAS… All the other industries are trying to stay away from SSN, so DSS should find an alternate way to verify.
- Is there a way for the candidates to verify trust worthy or certified contractors or recruiting/staffing firms?
Thoughts?