Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, February 22, 2014

Threat Agent Profile: Irrationals

The majority of system compromises can be traced to a simple principle – the benefits, at least in the short to medium term, outweigh the cost. Broadly, leaving governments aside, benefits can be divided into either financial or psychological. Money is the root of almost all compromises. The targets these hackers will go after are pretty simple to predict; roughly, they’ll go after systems that provide the highest return at the lowest personal risk of incarceration. Attacks motivated by psychology are more difficult. Most of the psych hacks are web site defacements and limited to simple exploits – more in the vandal category we reviewed. Within the psychology category is a subset that is irrational; system compromises that really can’t be explained or predicted, that stand against reason. What systems they will go after and how much resource they’ll dedicate in doing so is anyone’s guess. Here is one:

During a yearlong period beginning March 2001, Gary McKinnon, a British citizen, compromised scores of sensitive U.S. government and military systems, including systems at the Pentagon, Fort Benning, Fort Meade, the Earle Naval Weapons Station; and the Johnson Space Center.  In responding to journalists regarding the case, the U.S. Attorney heading up the prosecution, Paul McNulty said, “Mr. McKinnon is charged with the biggest military hack of all time.”[1] And what was Gary’s stated motive? It was to discover evidence of a UFO cover-up.[2]

The ‘irrationals’ represent a very small portion of the system hacks, but they are out there and they are very bothersome. Perhaps the people that scare us the most are the ones that we can’t explain.

Tuesday, December 31, 2013

Cybercrime in the 1970s

Note: This is a section of the full research paper

Environment
In the early 70s computers were limited to large, expensive timesharing mainframe and Unix systems owned by universities, large corporations, and government agencies. In 1975 Ed Roberts released the first microcomputer for sale to the public – the MITS Altair 8080. No keyboard, no screen – just a box with toggle switches for programming and LED lights to show the output of the program. He sold 2,000 of the systems the first year. The following year, Steve Jobs and Steve Wozniak released the Apple I. Again, no keyboard or screen. By the end of 1976 computing enthusiasts had purchased 40,000 microcomputers.[1] In 1977, the Apple II, the Tandy TRS-80 (I cut my teeth programming on this model), and the Commodore PET brought visual displays and keyboards to the market. People purchased 150,000 of these systems.[2]

Computer communications were pretty limited. The government, military, and a few universities had ARPA net and X25 networks. The public was limited to modem-based computer-to-computer phone calls, which was fine for dialing computers in your area, but a bit of a problem for those a long distance call away. The killer app for computer communications was Bulletin Board System software, which first came to public life, courtesy of Randy Seuss, during a snowstorm in February 1978.  This development connected computer enthusiasts across the U.S. in an electronic underground where they could publish ideas and communicate within their own realm on their own terms. From this technology the computer hacker underground took root.

While it took some time for microcomputers to take hold, the phone system was already built out and available. A large community of phone system fanatics – ‘phone phreaks’ – learned how to control the switching system of the predominant phone switching system in use at the time, largely in thanks to serious security flaws in the system and the publication of the details of the internal switching system in the November 1954 issue of the Bell Labs Technical Journal.

Motives and Crimes
The primary motives behind the computer crimes of the 60s and 70s were desire for system access, curiosity, and the sense of power attained from defeating security. The phone system was the first and favorite computer system targeted. The attraction to the phone system for the pioneers of phone phreaking was not free calls, but the desire to learn the system, the desire to beat the system, and the desire to control the system. John Draper, the father of phone phreaking, when asked about the techniques he developed for gaining operator access to phone systems, published in the October 1971 issue of Esquire Magazine, stated his motive behind unauthorized system access.

From Secrets of the Little Blue Box by Ron Rosenbaum, Esquire Magazine (October 1971)

The pioneers of ‘phone phreaking’ mastered the techniques for controlling the phone system and codified it in what is now called a ‘little blue box’. The box, commonly twice the size of a cigarette case, had buttons on the front that emitted tones. These tones could be used, if emitted at the right time and in the right sequence during a call would yield operator access to the phone system. The benefit, of course, was free calls to anywhere in the world.

Computers weren’t left alone. The first edition of Creative Computing magazine, published in 1976, had an article titled “Is Breaking Into A Timesharing System A Crime?”[3]



Besides the intellectual challenge of breaking in to systems, people were also motivated to break in to systems simply to gain access. In the 60s and early 70s time on the university-owned computer systems was limited. Students who wanted more time developed the first password crackers and trojan software in order to get the access they wanted.

With the introduction of microcomputers and Bulletin Board Systems in the mid to late 70s people wanted to connect to other computer systems. To foot the bill for the long-distance calls many resorted to stealing long distance access codes – wire fraud. Again, the primary motive to steal the access codes was not for profit, but curiosity – to connect and learn.




[1] http://jeremyreimer.com/postman/node/329
[2]http://arstechnica.com/old/content/2005/12/total-share.ars http://en.wikipedia.org/wiki/File:WIntHosts1981-2009.jpg



[3] http://www.atariarchives.org/bcc1/showpage.php?page=4

Saturday, December 28, 2013

The Conditions that Created the Perfect World for Cybercrime

Note: This is a section of the full research paper

Computer crime has changed from a 1970s characterization of hobbyists committing pranks and ‘exploring’ computer systems to a present day horizontally integrated industry of exploit researchers, malware writers, hackers, fraudster, and money mules that cause hundreds of millions of dollars in damages annually.  The articles below illustrate the juxtaposition of computer crimes from earlier decades with those of the present.

Teaching Hackers Ethics
Newsweek – January 14, 1985
The parents of "Echo Man," 16, "Thr ee Rocks," 15, and "Uncle Sam," 17, probably thought they were in their rooms doing homework.  Instead, the Burlingame, Calif., teen-agers were programming their Apples to scan the Sprint telephone-service computers for valid access numbers, which they used to make free calls.  The hackers then posted the numbers on an electronic bulletin board, so others could share in the spoils.  That was their undoing. Local police, who had been monitoring the bulletin board, raided each of the hackers' homes last month and found enough evidence to charge them with felony theft and wire fraud.


FBI: Cyber crooks stole $40M from U.S. small, mid-sized firms[1]
Washington Post, Brian Krebs – October 26, 2009
Cyber criminals have stolen at least $40 million from small to mid-sized companies across America in a sophisticated but increasingly common form of online banking fraud, the FBI said this week. According to the FBI and other fraud experts, the perpetrators have stuck to the same basic tactics in each attack. They steal the victim’s online banking credentials with the help of malicious software distributed through spam. The intruders then initiate a series of unauthorized bank transfers out of the company’s online account…

How do you explain the typical computer crime making the leap from petty phone access theft in the 70s to huge heists in 00s? As it turns out, in each decade, the computer crimes fit pretty well with the demographics of their time. The type and frequency of computer crime occurring in each decade seems to have been shaped by three demographics:
·      The number of computers online
·      The type and amount of online commerce
·      The globalization of internet use

The number of crime targets is limited by the number of computers online. The profitability of a target is dependent on the type of commerce being conducted on the computers. And the likelihood of being caught is positively correlated with the effectiveness of law enforcement in prosecuting crimes which, I have observed, is inversely proportional with the globalization of the internet.

As these demographics evolved, so too did the crime.

The Perfect Conditions for Crime

What are the perfect conditions for crime? How about easy targets, high profits, and very little chance of being caught.

That is what the Internet provides – lots of easy targets where 220 million people are online in the U.S. alone and with very weak security. An almost guaranteed high return – 50 million people in the U.S. conducting banking online. And little chance of being caught – attribution of crime on the Internet is nearly impossible and governments don’t have the resources to handle the volume, let alone the high cost of international investigations. They successfully prosecute a few per year for publicity, but little else. The Internet is the perfect place to commit crime.

It took until the late 1990s for these conditions to converge to create the perfect storm.  Before that essential elements were missing – people, connectivity, commerce, and insecurity.

+ Computers and Connectivity
The first dimension to set in to motion was personal and commercial use of computers in the mid 1970s. In the 70s there weren’t very many computer systems and they weren’t interconnected. In the 80s private citizen computer ownership started ramping up, but their connectivity was limited largely to computer-to-computer modem services and access to the Internet was restricted to government and university. In the 90s the government opened up the Internet to commercial and then public access. By the end of the decade, about half of the U.S. population was ‘online’.




+ Commerce
The explosion of online commerce was another important ingredient in creating the cyber crime environment. Without commerce, all the potential targets connected to the Internet are just targets. With commerce, computers become rich targets – credit card processing systems and automated tellers. In 2000, 40 million people in the U.S. had ever bought something online[2]. By 2008, that number reached 201 million[3]. Nearly everyone who can shop online does shop online.

In 1998 8 million people in the U.S. were conducting banking online. By 2008 that grew to 50 million – 23% of online users and fully 17% of the entire U.S. population! Consider this fact: there are about 220 million people in the U.S. who use the Internet regularly. Twenty-three percent of them – 50 million – conduct banking online. 



+ Insecurity
The build out of the Internet network infrastructure and the connected systems was fast and furious. At this pace, all focus was on feature and functionality. Little thought was given to the consequences of the risks and to the security requirements of such a critical, complex infrastructure.  As a security consultant in the late 1990s, I examined up close the lack of security controls in even critical infrastructure. On one engagement, my co-worker and I were called up on short notice to conduct an Internet perimeter test of a company that provided core processing services to credit unions. One of their services was outsourced Internet Banking. Compromising their perimeter was simple, taking about 10 minutes. We scanned their public address space for common ports, noticed 135 and 139 were listening on their Internet Banking server, established a net session and went to work guessing the administrator account password. The password was ‘snow’. It was easy pickings from there. Towards the end of the engagement, I met on-site with the company’s system administrators to discuss the findings. In response to my recommendations they asked, “What is a firewall?”

+ Internationalization and No Law Enforcement
In 1998 – 1999 about 80% of the people using the Internet were U.S. citizens and about 95% were U.S. citizens or citizens of U.S. allied countries.[4] Under these conditions, serious computer crimes could be investigated and prosecuted because the crimes were largely occurring from within the borders of governments that were willing to cooperate in cyber crime investigations. This acted as a deterrent of sorts, deterring many people from committing really serious cyber crimes.

Even in to 2000, people using the Internet in developing economies were limited to the professional class – people in government, education, and industry, due to Internet access constraints. As Internet accessibility increased and cost decreased non-professionals quickly got online. By 2005, the number of Internet users in BRIC countries – Brazil, Russia, India, and China – surpassed the number of Internet users in the U.S. Among these Internet users were, as in other countries, criminals. The difference this time though was that governments proved inept in dealing with the volume, the costs and international legal and political barriers of prosecuting crime.  And frankly, non-U.S. allies were and continue to not be seriously interested in assisting other countries in criminal investigations. Ever contact a bank in Russia to request that they return a fraudulent wire? Ever participated in an FBI investigation that requires cooperation of Chinese authorities? Good luck.



The early financially driven international cyber crime spree in 2001 – 2002 went unchecked. This encouraged additional investment in cyber crime. Success continued to meet success, which continues to spiral to where we are today.




[1] http://voices.washingtonpost.com/securityfix/2009/10/fbi_cyber_gangs_stole_40mi.html
[2]http://www.pewinternet.org/Reports/2002/Getting-Serious-Online-As-Americans-Gain-Experience-They-Pursue-More-Serious-Activities.aspx
[3] http://www.pewinternet.org/Reports/2008/Online-Shopping.aspx?r=1
[4] http://datafinder.worldbank.org/internet-users