- Nokia's new N97 vs. the iPhone
- 10 Microsoft research projects
- Hard to get justice in MySpace case
- Smartphone smackdown: Storm vs. iPhone
- Apple removes antivirus support page
The U.S. government recently warned financial firms and services of an al-Qaida call for a cyberattack against online stock trading and banking Web sites. The Islamic militant group wants to "penetrate and destroy the databases of the U.S. financial sites," Reuters reported.
Should you care? Not if you have been doing your job.
The United States has been handling information warfare attacks for more than a decade, with varying degrees of success. Our biggest national failure has been defending against Class I information warfare, which targets personal information and is the backbone of identity theft, phishing and similar profit-oriented criminal endeavors.
Business has done better against Class II information warfare: company-to-company information conflicts and industrial espionage. In many ways it can be argued that American industry essentially has chosen to permit the continued theft of intellectual property, rather than institute appropriate (and perhaps politically incorrect) security policies and procedures.
The alleged al-Qaida threat is Class III information warfare. Nation-states, terrorists or other political and/or religious nongovernment organizations target their adversaries for nonprofit motivations, such as denial of service and systemic disruption, including psychological operations (PsyOps). Targeting the private critical infrastructures of perceived adversaries is called unrestricted warfare, as declared by the Chinese against the U.S. private sector in 1998.
Could the United States be promoting or exaggerating the al-Qaida cyberterrorism threat as a means to garner support for current U.S. policies? FUD - fear, uncertainty and doubt - is a powerful weapon that cannot be dismissed out of hand. Or is this al-Qaida using PsyOps, their own form of FUD? This form of FUD-based PsyOps, be it a videotaped beheading or the threat of economic meltdown, is a proven Class III weapon. A few years ago the Irish Republican Army effectively shut down London with a few well-placed threats. No bombs, no boom, but London was brought to a halt.
Let's say that al-Qaida has hired the best hackers and intrusion experts from the United States, China, Israel, Russia. Mass hiring on this scale is highly unlikely, but in examining risk, I like to turn up the dial full tilt to get a view of possibilities. Al-Qaida certainly has more than one guy on an oasis, but they do not have the power of DefCon. They do not have a magic switch to say, "Goodbye, New York Stock Exchange" or "Good riddance, Schwab!"
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment