On BNET: 5 classic computer pranks
BNET Business Network:
BNET
TechRepublic
ZDNet

August 26th, 2005

The myth of the cyber-meltdown

Posted by George Ou @ 10:36 am

Categories: Security

Tags:

We’ve all heard of the impending doom of the cyber-meltdown by all the so-called experts in cyber-terrorism but unfortunately they couldn’t be further from the truth.  There will be no cyber-meltdown in the form of a massive cyber-attack that will cripple the Internet and IT infrastructure.  Not only is such a thing extremely unlikely on a technical level, but it’s foolish to think that any terrorist is interested in a glorified denial of service cyber attacks designed to kill computers because they’re much more interested in killing civilians.  They’re not interested in shutting down a bunch of computers or networks for a few hours because they’re more interested in shutting down critical infrastructure such as buildings and bridges.

Having said all that, the real and present danger is cyber-intrusion and it’s growing by leaps and bounds.  This includes cyber-terrorism, government and corporate cyber-espionage, and cyber-crime and it’s all about intrusion for the purpose of acquiring information.  If anything, denial of service attacks and worms that harass the computing world are the enemy of cyber-intruders because they raise the alarm bells and harden the network against further exploit.  No serious hacker in the arena of cyber-intrusion is interested raising any alarm bells because it will only result in the loss of a valuable backdoor planted deep inside the soft underbelly of the network. 

In the case of cyber terrorism, valuable information comes in the form of military planning and blueprints for public buildings and bridges.  Such information is extremely valuable to Al Qaeda for the purpose of planning their next terrorist bombing.  According to Roberto Preatoni who founded Zone-H.com and is an instructor on cyber-intrusion, he had actually seen evidence that Al Qaeda hackers gave blueprints of US military bases to the terrorists.  The reconnaissance value in cyber-intrusion is almost priceless whereas a denial of service attack is nothing more than a temporary nuisance that only draws unwanted attention.  The only time denial of service attacks makes sense to cyber-criminals is when they’re trying to blackmail individual businesses with the threat of a distributed denial of service attack, but this is usually under the radar where it doesn’t draw any attention.

In this weeks report on the massive and escalating number of Chinese cyber attacks against US military and Government networks in our new ZDNet Government section, the story illustrated the alarming exponential rate of growth in cyber-warfare.  Russian President Vladimir Putin recently boasted that his country had the world’s best hackers, but China is trying to challenge Russia for that title.  So far they’ve only managed to lead in the quantity of attacks but not capability.  According to Preatoni who has seen the state of Chinese cyber penetration research labs, China lags behind Russia on most things but excels in Internet Explorer exploit research.  Foreign Governments and terrorists alike have found that cyber-intrusion pays great dividends and are actively recruiting hackers to wage cyber-warfare.  The US and other technologically advanced nations have the most to lose because they are the most computerized and susceptible to cyber-intrusion.  With over 3 million computers in just the Department of Defense alone, the US military has a huge problem keeping intruders out.  Information security in general is far behind the times and the problem seems to get worse with each passing day.  While "expert" witnesses divert congress and the media to the myth of the cyber-meltdown as the next great imminent threat, the real problem of cyber-intrusion grows and the era of cyber-warfare is upon us.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 47 Talkback(s)
its v it's
I laughed when I read your post. Things like this bring out my mental "red pen" if not a physical one. I understand. happy... (Read the rest)
Posted by: cheshirecaaat Posted on: 09/03/05 You are currently: a Guest | | Terms of Use
The very reason hardware DRM is required.  No_Ax_to_Grind | 08/26/05
DRM is not crypto  george_ou | 08/26/05
Yes and no...  No_Ax_to_Grind | 08/26/05
Let me say that differently George.  No_Ax_to_Grind | 08/26/05
This is why I always promote the death of passwords  george_ou | 08/26/05
True, but how do I force it on others...  No_Ax_to_Grind | 08/26/05
The Europeans lead in smartcards  george_ou | 08/26/05
Not certain they work well enough.  No_Ax_to_Grind | 08/26/05
You misunderstand how smartcards work  george_ou | 08/26/05
The thing is though, *I* still want to be in control.  No_Ax_to_Grind | 08/26/05
If you find a way, you'd make a billion dollars from that patent  george_ou | 08/26/05
Many countries lead the US in smartcard usage.  B.O.F.H. | 08/26/05
Biometrics is not a silver bullet  george_ou | 08/26/05
And it'd nimbly take care of those evil whistleblowers too...  HypnoToad | 08/26/05
Larger Issues  Harry Bardal | 08/26/05
Way off base, the "hacked" banks were not running Windows.  No_Ax_to_Grind | 08/26/05
What Banks?  Harry Bardal | 08/26/05
And what do you think the article is about?  No_Ax_to_Grind | 08/26/05
Cyber Intrusion vs Cyber Terrorism  Harry Bardal | 08/26/05
Monocultures are good for security  george_ou | 08/26/05
Absolutely  Harry Bardal | 08/26/05
I never mentioned Microsoft in my post  george_ou | 08/26/05
Your kidding? Right?  MacGeek2121 | 08/29/05
Are you sure?  palmwarrior | 08/27/05
Don't need ALL the computers to intrude  george_ou | 08/27/05
What?  Richard Flude | 08/28/05
You just made my point  george_ou | 08/28/05
hmmm  Richard Flude | 08/29/05
Ok let's pin this down  george_ou | 08/30/05
Lets  Richard Flude | 08/30/05
It's called market share  george_ou | 08/31/05
The use and abuse of the apostrophe!  timpin1@... | 09/02/05
its v it's  cheshirecaaat | 09/03/05
Opportunity for misinformation  enduser_z | 08/26/05
This is very wishful thinking  george_ou | 08/26/05
Who knows?  enduser_z | 08/26/05
Re: There will be no cyber-meltdown  George Jay | 08/26/05
You don't get the point  george_ou | 08/26/05
they can spy on us?  George Jay | 08/26/05
History repeats itself  george_ou | 08/27/05
Out of context  george_ou | 08/27/05
Exactly!  MacGeek2121 | 08/29/05
Good reading for this topic  toadlife | 08/26/05
Myth? You fail to demonstrate the point  coreDev | 08/27/05
You completely missed the point  george_ou | 08/27/05
Cyber Terror or Cyber Intelligance?  papatator | 08/29/05
Your are right George, Cyper-intrusion  SimonSays | 08/29/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    Meet Doc