Showing posts with label AusCert. Show all posts
Showing posts with label AusCert. Show all posts

Sunday, August 04, 2013

Australian CyberWarfare Battalion


Tom Worthington aboard USS Blue Ridge
Tom Worthington
on USS Blue Ridge
This is to propose the Australian Defence Force (ADF) raise an Australian CyberWarfare Battalion (ACWB) of 300 personnel, to protect Australia's national information infrastructure. All but a small cadre would be reserve military personnel who have full time jobs as computer security professionals.

After very basic military training, personnel would be issued with secure communications and return to their workplace. Personnel would remain in touch with each other monitoring computer security threats. In the event of a large scale attack, most of the Battalion would stay in their workplaces to protect  infrastructure,  while a small number would deploy to industry, government and military centers (including any Cyber Security Operations Centre) to coordinate operations.

Compared to an infantry battalion,  a cyberwarfare battalion would be fast to raise and inexpensive to maintain. Personnel would receive the minimum of military training, sufficient for them to be able to work alongside regular personnel in a headquarters. Use would be made of the facilities and expertise in Australia's universities, including the University of NSW Cyber Range and the Queensland University of Technology Industrial Control System Security Course.

There is provision for the ADF to work alongside the civilian administration, as described in: "Civil-Military Operations", Australian Defence Doctrine Publication (ADDP) 3.11, 1 April 2009.

Without an effective form of cyber-defence Australia could expect its government and civilian infrastructure to be crippled within a few hours of the commencement of a major on-line attack. The ADF would then be required concentrate on aid to the community, with a reduction in its capacity to undertake conventional military operations.

Tuesday, July 02, 2013

Current trends in Cyber Security

Greetings from the CSIRO Discovery Centre in Canberra, where Asher Jamieson from CERT Australia is speaking on current and emerging threats in the Cyber Security landscape.

Mr. Jamieson pointed out that more than half of compromised systems are not detected by the organization itself but by someone else. He also mentioned that the amount of Spam being sent has reduced in the last year, not because of measures against spammers, but because they have found more targeted messages to be more effective.  Also hackers are persistent and will continue to attack the same organization, even when countermeasures are put in place, because the risk of being caught is so low.A recent trend has been extortion, using the threat of a Denial of Service Attack (DoS).

Mr. Jamieson described "Watering Hole Attacks", where a trusted third party's website is compromised, such as a service supplier.

Mr. Jamieson  pointed out that there had been attacks on SCADA industrial control computer systems. He ended with the worrying consequences of poor security in medical devices.

The main message from tonight's talk was to install security patches on package software. That is good advice, but in my view is no substitute for an Australian cyber security strategy. The Australian government abandoned work on a cyber security white paper and no effective strategy has been put in its place. As a result Australia's national infrastructure is at risk.

Attorney General's Department is hosting Security in Government Conference in Canberra, 12 - 14 Aug, 2013. This will include a Panoply "capture the flag" cyber-security competition, where teams will compete for control of a system.
Current trends in Cyber Security
CERT Australia’s views on current and emerging threats in the Cyber Security landscape, and what ICT Professionals can do to combat them. The last 12 months have clearly shown that no company can assume that they are immune to ICT Security threats, or assume that they will not be a target. While the focus of security is usually on preventing a threat from causing damage, having effective plans to deal with the aftermath of an incident is critical to maintaining security. Topics covered will include targeted intrusions, 2nd tier targeting, industrial control systems, Distributed Denial of Service attacks (DDOS), and will include several Australian case studies.

Asher Jamieson Technical Advisor, CERT Australia Asher Jamieson has worked in ICT Security in a number of different environments and is currently working as part of the Operations team in CERT Australia. He enjoys the variety and complexity of problems that the ICT Security field offers, and doesn’t see the rate of new challenges slowing down any time soon.

ps: Due to the topic, there was a strong presence from the defence community at the meeting. One informal discussion before the meeting was about if the China Houbei-class missile boat  was based on the Australian AMD design.

Saturday, June 01, 2013

Australia's Cyber Security


Technical Advisor, CERT Australia will speak on "Current trends in Cyber Security" at the Australian Computer Society in Canberra, 2nd July 2013.

ACS Branch Forum: Current trends in Cyber Security

CERT Australia’s views on current and emerging threats in the Cyber Security landscape, and what ICT Professionals can do to combat them.

The last 12 months have clearly shown that no company can assume that they are immune to ICT Security threats, or assume that they will not be a target. While the focus of security is usually on preventing a threat from causing damage, having effective plans to deal with the aftermath of an incident is critical to maintaining security.
Topics covered will include targeted intrusions, 2nd tier targeting, industrial control systems, Distributed Denial of Service attacks (DDOS), and will include several Australian case studies.

Wednesday, February 13, 2013

Virtual Australian Cyber Security Centre

Australian Prime Minister, Julia Gillard speaking in the DSD Cyber Security Operations Centre
There are media reports critical of the level of planning and resourcing for the Australian Cyber Security Centre ("Gaps exposed in Australian Cyber Security Centre plan, John Hilvert, IT News,Feb 13, 2013 7:00 AM). However, the Australian Cyber Security Centre at present is a goal, more than a "plan". It may be that the Australian Government is waiting for release of Cyber security measures by the US White House, which are due shortly. It would make sense for Australia to coordinate its efforts with its the USA. One area not sufficiently addressed in Australian announcements so far is coordination with private industry, who operate most of Australia's critical infrastructure. It would be little consolation to Australians to know their government is still functioning after a cyber-attck, if supplies of medicine, food, water and electricity are disrupted. Also there is no need for more than a very small cyber security centre, as telecommunications can be used to securely link existing operations centres. Seconded staff in the central facility can then work with their colleagues in law enforcement, the military, government and industry across Australia and around the world.

Friday, January 25, 2013

New Australian National Cyber Security Centre

Australian Prime Minister, Julia Gillard speaking in the DSD Cyber Security Operations Centre
The Australian Prime Minister, Julia Gillard,  visited the Australian Defence Department's Cyber Security Operations Centre (CSOC) at the Defence Signals Directorate in Canberra to announce an "Australian cyber security centre to be established". This followed the launch of the  "Strong and Secure: A Strategy for Australia’s National Security". The centre is planned to be staffed by the Defence Signals Directorate, Defence Intelligence Organisation, Australian Security Intelligence Organisation, the Attorney-General’s Department’s Computer Emergency Response Team Australia, Australian Federal Police and the Australian Crime Commission. However, I suggest the government personnel will need to be supplemented by industry and academia, as that is where the greatest expertise in cyber-security resides and because it is the civilian infrastructure which is more vital and more at risk than government computer systems. It is not clear where the new centre will be located, when it will be established or what budget it will have. The DSD Cyber Security Operations Centre would be an obvious choice, but it may not be large enough. Also it is not clear if one physical centre is needed, or if it would be better to connect existing centres of expertise secure broadband links. A one minute video of the PM's Australian National Cyber Security Centre presentation is available;e from the Defecne Department. Interestingly, the PM mentions being "in the pit", referring to the horseshoe shaped sunken section of the centre.

Thursday, January 24, 2013

Australian National Security Strategy Emphasizes Cybersecurity

The Australian Prime Minister, Julia Gillard, launched "Strong and Secure: A Strategy for Australia’s National Security" at the Australian National University in Canberra, on 23 January 2013. The 58 page document is available as a 3.4 Mbyte PDF file 3.44MB and RTF 1.37MB. Also available are a Media release on the National Security Strategy and the text of the PM's speech "Australia's National Security Beyond the 9/11 Decade". In the list of key national security risks, "Malicious cyber activity" is placed third, ahead of the proliferation of weapons of mass destruction.

DSD Cyber Security Operations Centre, 13 January 2010, DoD photo
The PM also mentioned that an "Australian Cyber Security Centre" would be separately announced. The policy document also mentions as a priority "Integrated cyber policy and operations
to enhance the defence of our digital networks". This would be a welcome change in the government's current approach, which is to announce cyber-security strategies, such as the Cyber Security White paper, and then  not properly resource and implement them. Also the approach has been fragmented, with different government agencies having separate uncoordinated initiatives and not involving the private sector, or state governments. The Australian Defence Department officially opened its Cyber Security Operations Centre (CSOC) at the Defence Signals Directorate in Canberra on 15 Januar 2010. Unfortunately the government chose not to support the non-government AusCERT , leaving the private sector open to attack.

Some excerpts from the "Strong and Secure: A Strategy for Australia’s National Security" document:

AUSTRALIA’S NATIONAL SECURITY STRATEGY

VISION

A unified national security system that anticipates threats, protects the nation and shapes the world in Australia’s interest

NATIONAL SECURITY OBJECTIVES

  • To protect and strengthen our sovereignty
  • To ensure a safe and resilient population
  • To secure our assets, infrastructure and institutions

KEY NATIONAL SECURITY RISKS

  • Espionage and foreign interference
  • Instability in developing and fragile states
  • Malicious cyber activity
  • Proliferation of weapons of mass destruction
  • Serious and organised crime
  • State-based conflict or coercion significantly affecting Australia’s interests
  • Terrorism and violent extremism

PILLARS OF AUSTRALIA’S NATIONAL SECURITY

Countering terrorism, espionage and foreign interference
Deterring and defeating attacks on Australia and Australia’s interests
Preserving Australia’s border integrity
Preventing, detecting and disrupting serious and organised crime
Promoting a secure international environment conducive to advancing Australia’s interests
Strengthening the resilience of Australia’s people, assets, infrastructure and institutions
The Australia–United States Alliance
Understanding and being influential in the world, particularly the Asia-Pacific

AUSTRALIA’S NATIONAL SECURITY OUTLOOK

Economic uncertainty and global reordering

  • Ongoing global economic uncertainty and volatility
  • Shift in economic and strategic weight, and trade flows towards the Asia–Pacific region creating new risks and opportunities for Australia
  • Active middle powers increasingly influential in the region; but the United States - China relationship will be the single most influential force in shaping the strategic environment
  • Multilateralism is becoming more important for regional security and at the same time more difficult

Continuing importance of non-state actors

  • Persistent threat from terrorism and increasingly sophisticated serious and organised crime, aided by money laundering and corruption
  • Technology enabling remote but pervasive threats - for example malicious cyber activity
  • Increasing influence of legitimate non-state actors such as private companies

Fragility and conflict in at-risk areas

  • Low likelihood of major power war, but probable ongoing low-level instability in Australia’s region
  • Fragile states and instability in the Middle East and South Asia will remain a challenge
  • Possibility for strategic shocks or local conflicts
  • High demand for international development assistance

Broader global challenges with national security implications

  • Resource security and scarcity
  • Climate change
  • Changing demographics
  • Increasing urbanisation
  • Increasing online engagement
  • Resurgence of violent political groups
  • Corruption

FIVE YEAR PRIORITIES

Enhanced regional engagement in support of security and prosperity in the Asian-Century
Integrated cyber policy and operations to enhance the defence of our digital networks
Effective partnerships to achieve innovative and efficient national security outcomes
...

Executive Summary

This National Security Strategy (the Strategy) is Australia’s first. It provides an overarching framework for our national security efforts, and sets priorities for the next five years. The Strategy is an important next step following the 2008 National Security Statement, which articulated Australia’s national security agenda and set in motion reforms to strengthen the national security community.
The Strategy is in two parts:
  • Part I explains the national security framework - our vision and objectives, and the activities we undertake to achieve these objectives.
  • Part II looks to the future - it examines the strategic outlook and sets priorities to ensure Australia embraces the opportunities and confronts the challenges of the Asian Century.
The Strategy lays out the pillars of Australia’s national security, and sets directions for the next five years. It will aid in focusing the Government’s pursuit of policies and objectives identified in the Australia in the Asian Century White Paper. The Strategy will help inform prioritisation of our resources in a time of fiscal constraint.
Importantly, the Strategy also serves to inform the Australian public, industry and our international partners of our approach to national security. The Strategy will be implemented through enhanced annual planning and budgeting arrangements across national security agencies. There will be a greater focus on partnerships that will see the strengthening of ties with states, territories and business.
Building on the existing strong foundation, our vision for Australia’s national security is for a unified system that anticipates threats, protects the nation, and shapes the world in our interests.
Chapter One discusses Australia’s national security objectives: to ensure a safe and resilient population; to protect and strengthen our sovereignty; to secure our assets, infrastructure and institutions; and to promote a favourable international environment. These objectives anchor decision-making and planning for the national security community.
Chapter Two explains the evolution of Australia’s strategic environment. Given our geography and alliances, our approach to security has always emphasised the defence of our nation and its borders. Naturally, there has been a focus on our own region. Our efforts are reflected in our many regional partnerships. Importantly, our international engagement is imbued with our commitment to liberal democratic values, such as the rule of law, human rights, and equality of opportunity.
The events of the past decade were instrumental in shaping our approach to national security. We have built our capacity to combat terrorism and transnational crime, including through an expansion of our intelligence and law enforcement capability. We developed a more integrated approach to supporting regional stability, for example through our assistance to Timor-Leste and Solomon Islands. This experience also shaped our strong emphasis on civil-military cooperation in Iraq and Afghanistan.
Chapter Two concludes with a summary of the important national security challenges that Australia will continue to face, and the opportunities we must look to seize.

Chapter Three sets out Australia’s fundamental approach to national security and how this approach reflects the current national security environment. It describes the eight pillars of our approach to national security:
  • Countering terrorism, espionage and foreign interference.
  • Deterring and defeating attacks on Australia and Australia’s interests.
  • Preserving our border integrity.
  • Preventing, detecting and disrupting serious and organised crime.
  • Promoting a secure international environment conducive to advancing Australia’s interests.
  • Strengthening the resilience of Australia’s people, assets, infrastructure and institutions.
  • The Australia–United States Alliance.
  • Understanding and being influential in the world, particularly the Asia–Pacific.
The second part of the Strategy looks to the future. In particular, Chapter Four examines the strategic outlook to anticipate challenges and opportunities in the years ahead. Most importantly, it examines the shifting geopolitical environment of the Asian Century. As the Australia in the Asian Century White Paper made clear, our approach to national security must make the most of the transformative economic and strategic changes occurring in Asia.
Asia’s economic growth will increase pressure on water resources and food and energy supplies, with implications for global markets and stability. The growing economic and political weight of China, India and other Asian powers, is also changing the established strategic order, including as a result of their increased military spending.
Neither strategic competition nor the growth in defence capabilities of regional countries makes conflict in the region inevitable or even more likely. Major regional powers understand that a war would be catastrophic. Deepening relationships between states across the region and the increasingly complex interdependencies that now underpin the Asia–Pacific also act as strong stabilising forces.

But there is no room for complacency. The interdependencies that make conflict less likely also make the potential consequences of even the most minor conflicts more far reaching.The increasing capability of armed forces in the region likewise increases the potential for minor clashes to have dangerous outcomes. A concerted effort will be required to shape a peaceful and stable order. Trust and entrenched patterns of dialogue and cooperation will be critical.The threat posed by non-state actors is also likely to evolve and possibly expand - new technology will be harnessed by criminals and terrorists, as they continue to augment their tactics and approaches.
Chapter Five considers the implications of the strategic outlook for Australia’s national security arrangements. It outlines three priorities for the next five years, to achieve our vision for our national security:
  • Enhanced engagement in support of regional security and prosperity in the Asian Century.
  • Integrated cyber policy and operations to enhance the defence of our digital networks.
  • Effective partnerships to achieve innovative and efficient national security outcomes.
... There are also more immediate national security
challenges facing governments around the globe.
In particular, non-state actors such as criminal and
terrorist organisations pose an enduring challenge.
Organised crime is becoming more sophisticated.
Our systems, methods and tools for dealing with it
must keep pace—cyber-enabled crime in particular
requires innovative responses that protect both the
rights and security of citizens. Terrorism remains a
serious threat requiring vigilance through a proactive
intelligence effort, strong partnerships with states and
territories, across business, the Australian community
and our international counterparts.
... In recent times, new and more complex national
security challenges have received greater global
attention. The growing number of malicious cyber
incidents has juxtaposed the dangers of a
hyper-connected world against the considerable
economic and social benefits afforded by the Internet.
Our national security and law enforcement agencies
are now focusing more urgently on how best to
combat cyber-based threats, but not at the expense
of Australians’ privacy and the broader benefits the
online environment brings.
... Malicious cyber activity: Every day, Australian
governments, businesses and individuals face a
range of cyber-related threats such as state-based
and commercial espionage, identity theft, and denial
and disruption of services. If left unchecked,
cyber-related threats have the potential to undermine
confidence in our social and economic stability and
our prosperity.
... Other activities, like our efforts to promote
international norms for cyberspace, see our
diplomats, international lawyers and policy specialists
working with industry, the not-for-profit sector and
foreign governments to shape a secure, open and
accessible online environment that directly benefits
our national security, societal safety and digital
economy.
... Serious and organised crime: Serious and
organised crime can undermine our border integrity
and security. It can erode confidence in institutions
and law enforcement agencies, and damage our
economic prosperity and regional stability. It can
involve the procurement, distribution and use of illegal
weapons. This type of crime is highly adaptive and
may link to, or exacerbate, other significant issues
of national security, such as terrorism and malicious
cyber activity.
... States have always used espionage as a tool to
pursue national interests. Today, our reliance on
cyberspace has increased our exposure to this threat.
Espionage and foreign interference activities against
Australia place a range of our national interests at
risk, including: classified government information;
commercial information with direct consequences for
business and the economy; intellectual property; and
the private information of our citizens.
...


From: Strong and Secure: A Strategy for Australia’s National Security, Australian Government, 23 January 2013

Tuesday, December 11, 2012

Hacking of medical records

ABC Radio South East is going to interview me at 8:46am Wednesday, about the hacking of medical records. According to the report "hackers" have demanded $4,000 to restore the records of a medical centre. I did not pay much attention when I first heard the story as it sounded like the usual scare story issued by anti-virus software companies to promote their products. The ransom amount sounds too low to be credible. Also even if the medical practice paid the ransom, there is no way they could rely on the records being intact and unaltered.

The obvious reaction to such a story would be to call for medical records to be stored offline, on a server not connected to the Internet. But Australian state and federal governments are spending billions of dollars on ehealth to put records online. These online systems are intended to no only reduce costs, but impressive health, by providing a consolidated and more accurate medical record to all of a patients heath care providers. Speaking from experience, when you are lying semi-conscious in an intensive care ward of a hospital being asked about your medical history you would welcome an online record the doctor could access, so they could get on with treating you urgently.

Some guides and standards for cloud use, such as AGIOM's "Privacy and Cloud Computing for Australian Government Agencies Better Practice Guide" and  IITP's "Cloud Computing Code of Practice" are discussed in my presentation "Records in the Cloud?" for the For Transitioning to Digital Recordkeeping, conference this year.

Medical centres should have good internal security procedures (attack by an employee still remains the biggest threat to an organisation, rather than attack from outside), as well as backing up their data,  securing their computer systems, using anti-virus software and having a firewall separating the internal system from the Internet. Small medical practices might be better off with cloud based outsourced services run by companies with the required expertise, rather than relying on locally run and maintained systems.

The Australian Computer Society was assisting the Australian Government to prepare a Cyber Security White Paper, which was to be released in early 2012. I helped prepare the ACS Submission for the Australian Cyber Policy White Paper.Unfortunately the Department of Prime Minister and Cabinet then canceled the white paper. Perhaps this needs to be renewed.

Thursday, May 31, 2012

Computer virus stirs cyber espionage fears

On Tuesday I was interviewed by ABC Radio about the Flame virus, see: "Computer virus stirs cyber espionage fears" (transcript and audio, Adam Rollason, ABC Radio, PM Program, Tuesday, May 29, 2012 18:35:00). Essentially I said that this was a sophisticated security threat which was designed to covertly collection information, but Australia had good protections against it, with multiple levels of security.

As far as I know it is just a coincidence that CERT Australia coming to Canberra next Tuesday 5th June 2012, to talk about Cyber Security.

Saturday, June 12, 2010

CERT Australia high risk strategy

As explained by the Prime Minister in a speech at ANU, 28 May 2010, the Australian Government will now be relying on the the Attorney General's Department "Computer Emergency Response Team Australia" (CERT Australia) for cyber security information and advice, both the government agencies and the public.

The Australian Government previously helped fund the not-for-profit, non-government AusCERT based at the University of Queensland.

The ability of CERT Australia to provide authoritative advice is unproven and its ability to provide independent advice unclear. This change therefore represents a high risk strategy for protecting Australia's cyber infrastructure.

AusCERT advised that some government services, such as the National Information Technology Alert Service and National IT Incident Reporting Scheme, would be discontinued in February 29010.

However, some services funded by government agencies, such as Stay Smart Online Alert Service, funded by the Department of Broadband, Communications and the Digital Economy, would continue.

AusCERT intends to continue to offer subscription services to non-government and government organisations.

According to a media report, federal agencies using their own service will result in a loss to AusCERT of $250,000 in annual subscriptions.

However, an IT professional managing operations at a medium to large federal government agency is likely to feel it is prudent to pay for an AusCERT subscription, even though they can get free advice from the government CERT Australia. In the event of a major security breech resulting in loss of life, economic loss or sensitive information loss, the individuals involved may have to explain to a court why they failed to take sufficient steps to protect the public. That a non-expert told them they did not need independent IT security advice, even if that person is the Prime Minister, would not make a strong defence.

Friday, November 27, 2009

Cyberwar Podcast

Stilgerrian, interviewed me for a ZDNet Australia podcast on "Cyberwar: What is it good for?". This was recorded shortly before the Attorney-General released the new Australian Government Cyber Security Strategy and IBM announced a new computer security centre in Canberra.

Tuesday, November 24, 2009

Australian Government Cyber Security Strategy

The Federal Attorney-General, Robert McClelland has released an Australian Government Cyber Security Strategy. This is a high risk strategy as it proposes transferring the functions of the successful and experienced non-government AusCert to an inexperienced government body. A better strategy would be to resource AusCert so it can provide services to non-government bodies and work with DSD to look after government and military computer security.

The Australian Government Cyber Security Strategy has three objectives:
  1. Make Australians aware of cyber risks,
  2. Make businesses operate secure and resilient information and communications technologies,
  3. Secure Australian Government information and make communications technologies resilient.

The seven Strategic priorities are:

  1. Improve the detection, analysis, mitigation and response to sophisticated cyber threats,
  2. Provide Australians with information and tools to protect themselves online,
  3. Partner with business to promote security and resilience,
  4. Protection of government ICT systems,
  5. Promote a secure, resilient and trusted global electronic operating environment,
  6. Maintain an effective legal framework and enforcement against cyber crime,
  7. Promote research and development of cyber security a skills.

By early 2010 the Australian Government expects to have:

  1. CERT Australia: with Attorney-General’s Department taking over AusCert's responsibilities. This will incorporate the Australian Government Computer Emergency Readiness Team,
  2. Cyber Security Operations Centre (CSOC): The Defence Signals Directorate (DSD) will continue to provide civilian and military government agencies with cyber security assistance.