China sets up "Online Blue Army"

lambu

Regular Member
Joined
Jul 15, 2010
Messages
313
Likes
77
Beijing: Chinese military has set up "Online Blue Army", a dedicated web network aimed to beef up internet security of its defence installations from cyber attacks.

The "Online Blue Army" is based on the People's Liberation Army, (PLA) needs and enforcing the ability of Internet security protection is an important issue in its military training programs, Chinese Defence Ministry spokesman Geng Yansheng said.

Geng's comments came in response to questions if the "Online Blue Army" is China's Internet squad aimed at carrying out attacks on other countries' Internet systems, state run Peoples Daily reported. Geng said his country will not carry out cyber wars.

The PLA Daily had reported PLA's Guangzhou command had invested tens of millions of yuan in building the specialized Internet squad.

Geng said Internet security has become an international concern which affects not only the society but the military sector, adding that China, armed with comparatively lax online security protection is among the victims of Internet attacks.

The Daily said internationally, online military units have long been established. The United States destroyed Iraq's air defence system using PC viruses during the Gulf War in 1991. Thereafter, the online army of the United States also played major roles in the wars in Kosovo and Iraq.

follow link for further reading...

China sets up "Online Blue Army"
 

ace009

Freakin' Fighter fan
Senior Member
Joined
Sep 15, 2010
Messages
1,662
Likes
526
You mean "cyberoffense is the best cyberdefense"? Wow -

You know what Mao would have said -

"Power flows from the keyboard and mouse"

:D
 

amoy

Senior Member
Joined
Jan 17, 2010
Messages
5,982
Likes
1,849
Let's not be naive that has been going on for ages. No selective blindness pleazzzzz. Guess who sponsored below cyber attak?? >>>
BBC News - Stuxnet worm 'targeted high-value Iranian assets'

Stuxnet worm 'targeted high-value Iranian assets'By Jonathan Fildes
Some have speculated the intended target was Iran's nuclear power plant One of the most sophisticated pieces of malware ever detected was probably targeting "high value" infrastructure in Iran, experts have told the BBC.

Stuxnet's complexity suggests it could only have been written by a "nation state", some researchers have claimed.

It is believed to be the first-known worm designed to target real-world infrastructure such as power stations, water plants and industrial units.

It was first detected in June and has been intensely studied ever since.

"The fact that we see so many more infections in Iran than anywhere else in the world makes us think this threat was targeted at Iran and that there was something in Iran that was of very, very high value to whomever wrote it," Liam O'Murchu of security firm Symantec, who has tracked the worm since it was first detected, told BBC News.
Some have speculated that it could have been aimed at disrupting Iran's delayed Bushehr nuclear power plant or the uranium enrichment plant at Natanz.

However, Mr O'Murchu and others, such as security expert Bruce Schneier, have said that there was currently not enough evidence to draw conclusions about what its intended target was or who had written it.

Initial research by Symantec showed that nearly 60% of all infections were in Iran. That figure still stands, said Mr O'Murchu, although India and Indonesia have also seen relatively high infection rates.

'Rare package'

Stuxnet was first detected in June by a security firm based in Belarus, but may have been circulating since 2009.

Unlike most viruses, the worm targets systems that are traditionally not connected to the internet for security reasons.

Instead it infects Windows machines via USB keys - commonly used to move files around - infected with malware.

Once it has infected a machine on a firm's internal network, it seeks out a specific configuration of industrial control software made by Siemens.

The worm searches out industrial systems made by Siemens Once hijacked, the code can reprogram so-called PLC (programmable logic control) software to give attached industrial machinery new instructions.

"[PLCs] turn on and off motors, monitor temperature, turn on coolers if a gauge goes over a certain temperature," said Mr O'Murchu.

"Those have never been attacked before that we have seen."

If it does not find the specific configuration, the virus remains relatively benign.

However, the worm has also raised eyebrows because of the complexity of the code used and the fact that it bundled so many different techniques into one payload.

"There are a lot of new, unknown techniques being used that we have never seen before," he said These include tricks to hide itself on PLCs and USB sticks as well as up to six different methods that allowed it to spread.

In addition, it exploited several previously unknown and unpatched vulnerabilities in Windows, known as zero-day exploits.

"It is rare to see an attack using one zero-day exploit," Mikko Hypponen, chief research officer at security firm F-Secure, told BBC News. "Stuxnet used not one, not two, but four."

He said cybercriminals and "everyday hackers" valued zero-day exploits and would not "waste" them by bundling so many together.

Microsoft has so far patched two of the flaws.

'Nation state'

Mr O'Murchu agreed and said that his analysis suggested that whoever had created the worm had put a "huge effort" into it.

"It is a very big project, it is very well planned, it is very well funded," he said. "It has an incredible amount of code just to infect those machines."

Continue reading the main story
"
Start Quote
There have been no instances where production operations have been influenced or where a plant has failed"
End Quote
Siemen's spokesperson
His analysis is backed up by other research done by security firms and computer experts.

"With the forensics we now have it is evident and provable that Stuxnet is a directed sabotage attack involving heavy insider knowledge," said Ralph Langner, an industrial computer expert in an analysis he published on the web.

"This is not some hacker sitting in the basement of his parents' house. To me, it seems that the resources needed to stage this attack point to a nation state," he wrote.

Mr Langner, who declined to be interviewed by the BBC, has drawn a lot of attention for suggesting that Stuxnet could have been targeting the Bushehr nuclear plant.

In particular, he has highlighted a photograph reportedly taken inside the plant that suggests it used the targeted control systems, although they were "not properly licensed and configured".

Mr O'Murchu said no firm conclusions could be drawn.

However, he hopes that will change when he releases his analysis at a conference in Vancouver next week.

"We are not familiar with what configurations are used in different industries," he said.

Instead, he hopes that other experts will be able to pore over their research and pinpoint the exact configuration needed and where that is used.

'Limited success'
A spokesperson for Siemens, the maker of the targeted systems, said it would not comment on "speculations about the target of the virus".

He said that Iran's nuclear power plant had been built with help from a Russian contractor and that Siemens was not involved.

"Siemens was neither involved in the reconstruction of Bushehr or any nuclear plant construction in Iran, nor delivered any software or control system," he said. "Siemens left the country nearly 30 years ago."

Siemens said that it was only aware of 15 infections that had made their way on to control systems in factories, mostly in Germany. Symantec's geographical analysis of the worm's spread also looked at infected PCs.

"There have been no instances where production operations have been influenced or where a plant has failed," the Siemens spokesperson said. "The virus has been removed in all the cases known to us."

He also said that according to global security standards, Microsoft software "may not be used to operate critical processes in plants".

It is not the first time that malware has been found that affects critical infrastructure, although most incidents occur accidentally, said Mr O'Murchu, when a virus intended to infect another system accidentally wreaked havoc with real-world systems.

In 2009 the US government admitted that software had been found that could shut down the nation's power grid.

And Mr Hypponen said that he was aware of an attack - launched by infected USB sticks - against the military systems of a Nato country.

"Whether the attacker was successful, we don't know," he said.

Mr O'Murchu will present his paper on Stuxnet at Virus Bulletin 2010 in Vancouver on 29 September. Researchers from Kaspersky Labs will also unveil new findings at the same event.
 

Global Defence

New threads

Articles

Top