Showing posts with label Cyber-Infrastructure. Show all posts
Showing posts with label Cyber-Infrastructure. Show all posts

Sunday, August 2, 2009

Internet Security Alliance News & Information Security Resources

 

From The Internet Security Alliance

In The News…

July 24, Orange County Register – (California) FBI to investigate Placentia library hacking. The FBI is hunting down the hackers that hijacked the Placentia Public Library Web site the morning of July 24, a bureau official said the same afternoon. “The FBI will open and investigation into this incident,” said an FBI spokeswoman. The spokeswoman, who works out of the bureau’s Los Angeles field office, said that the FBI has a special unit that investigates “cyber crimes, computer intrusions, defacements, more traditional crimes like fraud and child exploitation.” Visitors to the Placentia Library Web site were greeted by an image of a flapping flag with a crescent moon and star behind a portrait of famed Turkish leader Mustafa Kemal Ataturk. Underneath was the phrase “Editaarruz is back.” A group calling itself the “Federal Attack Team” has apparently hacked www.placentialibrary.org — disabling the site completely. The word “taarruz” means “attack” or “offensive” in the Turkish language.
Source: http://www.ocregister.com/articles/site-web-search-2506225-google-placentia

Internet Security Alliance News 7-29-09 : Information Security Resources

Tuesday, July 28, 2009

Securing a Hacker-Free Zone on the Internet

 Jackie Herships
By Jacqueline Herships, Founder of Jacqueline Herships & Associates
(This article was first published in the Gerard Group International, Inc. newsletter “INTELANALYSIS”.)


Patented Telecommunications Plan Would Create Secure VoIP Communications

A recent patent series promises a new, secure telecommunications system by mitigating risks to Internet telephony like Voice over Internet Protocol (VoIP) from espionage, hacking, intrusion, and interruption of service.

computer-hackingThe entire worldwide Domain Name System (DNS) was brought to its knees by hackers not too long ago; however, this new Internet telecommunications system will not depend on DNS.

In theory at least, the Wild West days of Internet telecommunications are over.

Based upon the inventions articulated in his five-patent suite, inventor Harry Emerson III, has mapped out a union between our secure and venerable telephone system - (Plain Old Telephone Service; a.k.a., POTS) - and the hyper-evolving, media-rich Internet which is so famously not one bit secure.

As it evolves, he believes this next generation telecommunications system, dubbed IronPipe™, will have huge implications for national security as well as tremendous new revenue opportunities for the carriers and supply chains which serve them.

Conceived in response to what he views as the seriously flawed paradigm, which is currently developing as telecommunications migrates to the Internet, Mr. Emerson says he designed IronPipe™ to offer an alternative with a high degree of security.

The Internet has produced something akin to a gold rush experience for those mining its resources and developing its vast potentialities, he said.

However, in the midst of this frenzy, he has observed that fundamental requirements of privacy, secrecy, and security are seldom openly discussed when it comes to Internet-based phone services known as Voice over Internet Protocol (VoIP) systems such as Skype, which are proliferating in cyberspace.

These are serious issues, he maintains, and they need to be fully considered by users such as corporations, telecommunications carriers, VoIP carriers, law enforcement agencies, and federal and state governments, as well as by the millions of Internet using individuals who are concerned with their own personal privacy.

According to Mr. Emerson, our current state of vulnerability came about because we have turned a blind eye to these issues of privacy, secrecy and security, combined with the scramble for profit, and an unregulated environment for VoIP.

“The Internet is a lawless frontier where nothing is safe and secure and reliability is always one step away from calamity,” he says.

“As things stand today, VoIP does little to protect the interests of the aforementioned entities, not to mention protecting the security of the United States. We are suffering untold numbers of hacker attacks DAILY, with systems broken into and identities stolen. Not too long ago the entire worldwide DNS system (Domain Name System) was brought to its knees by hackers,” Emerson said.

In his opinion, if the technology continues to develop in its current direction, no one will be able to guarantee that communications cannot be intercepted and monitored.

In addition, if we examine our circumstances, a lot of the excitement generating the rush to VoIP is based upon an illusion, the appearance that we are being offered new and sophisticated technologies.

In fact, existing VoIP offerings are simply discounted POTS service, he says, with no value-added features, only lower cost caused by fierce price pressure from cable TV and other low-overhead vendors.

The result is the continued downward spiral on price that has plagued the telecommunications industry for 30 years.

IronPipe™ is a re-thinking of 21st century telecommunications architecture, which will return a sense of safety to our society as a whole, reinvigorating our economy from the inside out.

If his vision is implemented, Mr. Emerson says we won’t have to put up with either the fear of intrusion or the huge financial burden of protecting ourselves from the ever-increasing army of those with malicious intent.

We will now have a choice.

The challenge is that VoIP companies such as Skype (NASDAQ: EBAY), Vonage (NYSE: VG) and the various Cable carriers (Comcast NASDAQ: CMCSA, Time Warner: NYSE TMC, and CableVision: NYSE CVC) , which have migrated to the Internet, did so not only to provide cheaper communications, but to avoid regulatory scrutiny.

“If you don’t have to deal with the regulations it tends to make it cheaper,” Emerson said, “but these profits come at a price.”

“The integrity of the communications system has been compromised because of this short term thinking geared towards reducing costs.”

In its simplest terms, IronPipe™ enables us to make Web 2.0 Internet-style media rich calls utilizing the existing private, protected, secure, Public Switched Telephone Network (PSTN), and its unseen private data network - known as Signaling System #7 (SS7), which connects all the main switches around the world.

While VoIP uses the Internet exclusively and thus can be, and regularly is, compromised by persons of malicious intent, if we establish Internet calls through these telephone company switches there will be no access from the outside.

We can create rich media visual telephone calls on broadband Internet connections, using wire-line or wireless touch-screen phones such as the Apple (NASDAQ: AAPL) iPhone, simply by dialing a phone number, and still enjoy the privacy, security and reliability of traditional telephone calls.

Mr. Emerson says that his technology seamlessly merges the best of the Internet with the best of the telephone network.

Considering the cost to government, industry and “society at large” to protect against intrusion and to remediate the damage caused by intrusion, IronPipe™ could be well worth looking into.

About Harry Emerson, Co-Founder Emerson Development LLC:

  Mr. Harry Emerson is an expert in computers, voice and data communications, and the Internet.

Harry EmersonHis career history includes 25 years in various sales, management, and strategic capacities at AT&T (NYSE: T) and the design and management of large-scale, multi-million dollar enterprise applications and data systems.

He has numerous patents issued and pending against a variety of technologies including FM radio, Internet streaming, PC software, and telecommunications.

Mr. Emerson co-founded GEODE Electronics to commercialize a series of patented enhancements to commercial FM radio. Subsequently, Mr. Emerson co-founded SurferNETWORK, an Internet streaming media business.

His background in switching systems and data networking, along with concepts he developed in corporate architecture and strategy positions, ultimately led to the development of the patent portfolio that defines the next generation of secure telecommunications, known as IronPipe™, featuring secure, rich Multimedia capabilities.

He is a member of the New Jersey Technology Council (http://www.njtc.org/) Telecommunications/Media Industry Network Advisory board.

Emerson Development, LLC has been awarded a fifth telecommunications patent that introduces breakthrough technology combining the multimedia capability of the Internet with the safety, security, and reliability of the phone network.

This exciting new technology enables a world in which audio/visual phone calls will become the standard for routine, daily communications. The Emerson Development Multimedia Telecommunications technologies will create the next generation of telecommunications — visual, multimedia, and videophone communications on screen-based phones that require no knowledge or training for users. Just dial a phone number.

Emerson Development Multimedia Telecommunications provides the carrier class infrastructure, operations, management, and billing capabilities that will be absolutely necessary for the major telecommunications companies throughout the world to venture into this field.

These mandatory capabilities include requirements for security, privacy, secrecy of communications, and unlisted numbers, including the guaranteed ability to keep the identities of callers secret under every circumstance imaginable.

In addition, just as importantly, Multimedia Telecommunications provides for these privacy and security requirements while still enabling government mandated provisions for law enforcement wiretapping and call tracing.

Overview of the Emerson Development, LLC Patents

Patent Number


Description

6,704,305

“Integrated Device For Integrating The Internet With The Public Switched Telephone Network”

This patent, describes telephone devices such as screen phones that support audible and visual communications across the Internet simply by dialing a telephone number. These “Integrated” phones have both a telephone connection and an Internet connection. By using digital call control messages that are sent to and from the local telephone central office, an “Integrated” telephone can set up an Internet Multimedia call to a compatible phone. If the called phone is not Internet capable, a standard phone call is established.

6,700,884

“Integrating the Internet With The Public Switched Telephone Network”

This patent, describes a system for a telephone device as described in 6,704,305 to be able to create an Internet call. The system includes a mechanism for correlating the telephone number of a calling or called device with its associated IP address. That information could be stored in the telephone itself, in a record system of the local central office, or in one or more central registries.

6,697,357

“Call Management Managing System For Integrating The Internet With The Public Switched Telephone Network”

This patent describes a digital call management messaging system, that could be thought of as an extension of ISDN and SS7, that enables an “Integrated” telephone device to communicate across the Internet. When one of these telephones places a call, it sends a digital message to its serving central office switching system. That message includes its telephone number and IP address, as well as the telephone number of the called party. By sending a compatible message to the central office serving the called party, the originating central office can determine if the called party is capable of an Internet call. If so, once the called device receives the call setup message, it has the Internet IP address of the calling device, and can then establish a connection across the Internet.

6,928,070

“Integrating The Internet With The Public Switched Telephone Network”

This patent, describes a sophisticated system, which greatly enhances the privacy, secrecy, and security of Internet calls. This system enables the telephone-switching network to dynamically assign an IP address to both the calling and called device, and route the resulting Internet call through an intermediate proxy server. Internet phones require more than just “unlisted number” capability since a called party can easily determine the geographic location of a caller, and thus putting the life of some individuals at risk (such as a battered spouse). With this invention, the proxy servers can be in other geographic regions to cloak a device’s actual geographic location. Furthermore, the Internet call can be split into two unidirectional streams, and each of those streams can be routed through a separate pair of proxy servers. Since the proxy servers can be dynamically selected for each call, the true location of an “Integrated” phone can be protected.

7,327,720

“Integrated Telephone Central Office Systems For Integrating The Internet With the Public Switched Telephone Network”

This patent describes a telephone central office switching system having a digital messaging capability to send and receive call setup and management messages to and from compatible phones. These call management messages can initiate and control a communications session transpiring across the Internet. The central office switching system can communicate similar digital messages to other central offices and central office systems to create and manage end-to-end Internet communications.

Emerson Development, LLC’s IronPipe™ Benefits

Telephone carriers stand to benefit from this new technology because it preserves their business position by providing high value in the PSTN and in the underlying private SS7 network that connects the PSTN together.

Traditional telephone carriers, as well as VoIP vendors that participate in this new technology, will benefit by offering new high value consumer services instead of competing by cutting prices.

Consumers will benefit from a flourish of new Multimedia features. The experience will be similar to accessing a web page with a browser, but would be done by dialing a phone number.

Industry and governments will benefit from a rich communications environment that is secure from espionage, hacking, intrusion, and interruption.

Questions and comments for Mr. Emerson may be directed to:
Direct - (973) 641-7420 
Email - hemerson@EmersonDevelopmentLLC.com
Via LinkedIn: http://www.linkedin.com/in/harryemerson

Jacqueline Herships is the founder of Jacqueline Herships & Associates, a strategic communications and new business development company. Jacqueline developed her skills in the documentary film business, as a journalist, and as an organizer in her own right. She believes in the power of alliances and builds these into her strategic plans. In addition to her work with Emerson Development, Ms Herships’ client projects have included the US Green Building Council of New Jersey, the Sierra Club - NYC, the Local Initiatives Support Corporation Greater Newark & Jersey City (a funding agency for inner city community development), HANDS, Inc; Wildlight Productions, a critically acclaimed social issues documentary film company; and a variety of artists and arts projects. She is a workshop facilitator for the Support Center for Nonprofit Management in Manhattan and others on the subject of laser communications-developing attention in the age of information overload; she has twice been a member of the board of the International Furnishings and Design Association, IFDA/NY as well as their publicist for 2 years. And, she is the co-founder of Professionals in Media (PIM), a regional organization of media professional including writers, editors, publishers, filmmakers, consultants, etc., who meet across professional lines.

Comments and questions may be directed to: Jacqueline Herships & Associates: 
Direct - (973) 763-7555
Email - jacqueline@jacquelineherships.com

The Publisher gives permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author and to Information-Security-Resources.com

© Copyright 2009 – Jacqueline Herships – All Rights Reserved  

(This article may be reprinted in whole or in part only with proper attribution to the author.  See: Information Security Resources)

Saturday, June 13, 2009

Cyberwar - Privacy May Be a Victim in Cyberdefense Plan - Series - NYTimes.com

http://www.nytimes.com/ 

June 13, 2009

Cyberwar - The New York Times

Privacy May Be a Victim in Cyberdefense Plan

By THOM SHANKER and DAVID E. SANGER

WASHINGTON — A plan to create a new Pentagon cybercommand is raising significant privacy and diplomatic concerns, as the Obama administration moves ahead on efforts to protect the nation from cyberattack and to prepare for possible offensive operations against adversaries’ computer networks.

President Obama has said that the new cyberdefense strategy he unveiled last month will provide protections for personal privacy and civil liberties. But senior Pentagon and military officials say that Mr. Obama’s assurances may be challenging to guarantee in practice, particularly in trying to monitor the thousands of daily attacks on security systems in the United States that have set off a race to develop better cyberweapons.

Much of the new military command’s work is expected to be carried out by the National Security Agency, whose role in intercepting the domestic end of international calls and e-mail messages after the Sept. 11, 2001, attacks, under secret orders issued by the Bush administration, has already generated intense controversy.

There is simply no way, the officials say, to effectively conduct computer operations without entering networks inside the United States, where the military is prohibited from operating, or traveling electronic paths through countries that are not themselves American targets.

The cybersecurity effort, Mr. Obama said at the White House last month, “will not — I repeat, will not — include monitoring private sector networks or Internet traffic.”

But foreign adversaries often mount their attacks through computer network hubs inside the United States, and military officials and outside experts say that threat confronts the Pentagon and the administration with difficult questions.

Military officials say there may be a need to intercept and examine some e-mail messages sent from other countries to guard against computer viruses or potential terrorist action. Advocates say the process could ultimately be accepted as the digital equivalent of customs inspections, in which passengers arriving from overseas consent to have their luggage opened for security, tax and health reasons.

“The government is in a quandary,” said Maren Leed, a defense expert at the bipartisan Center for Strategic and International Studies who was a Pentagon special assistant on cyberoperations from 2005 to 2008.

Ms. Leed said a broad debate was needed “about what constitutes an intrusion that violates privacy and, at the other extreme, what is an intrusion that may be acceptable in the face of an act of war.”

In a recent speech, Gen. James E. Cartwright, vice chairman of the Joint Chiefs of Staff and a chief architect of the new cyberstrategy, acknowledged that a major unresolved issue was how the military — which would include the National Security Agency, where much of the cyberwar expertise resides — could legally set up an early warning system.

Unlike a missile attack, which would show up on the Pentagon’s screens long before reaching American territory, a cyberattack may be visible only after it has been launched in the United States.

“How do you understand sovereignty in the cyberdomain?” General Cartwright asked. “It doesn’t tend to pay a lot of attention to geographic boundaries.”

For example, the daily attacks on the Pentagon’s own computer systems, or probes sent from Russia, China and Eastern Europe seeking chinks in the computer systems of corporations and financial institutions, are rarely seen before their effect is felt inside the United States.

Some administration officials have begun to discuss whether laws or regulations must be changed to allow law enforcement, the military or intelligence agencies greater access to networks or Internet providers when significant evidence of a national security threat was found.

Ms. Leed said that while the Defense Department and related intelligence agencies were the only organizations that had the ability to protect against such cyberattacks, “they are not the best suited, from a civil liberties perspective, to take on that responsibility.”

Under plans being completed at the Pentagon, the new cybercommand will be run by a four-star general, much the way Gen. David H. Petraeus runs the wars in Afghanistan and Iraq from Central Command in Tampa, Fla. But the expectation is that whoever is in charge of the new command will also direct the National Security Agency, an effort to solve the turf war between the spy agency and the military over who is in charge of conducting offensive operations.

While the N.S.A.’s job is chiefly one of detection and monitoring, the agency also possesses what Michael D. McConnell, the former director of national intelligence, called “the critical skill set” to respond quickly to cyberattacks. Yet the Defense Department views cyberspace as its domain as well, a new battleground after land, sea, air and space.

The complications are not limited to privacy concerns. The Pentagon is increasingly worried about the diplomatic ramifications of being forced to use the computer networks of many other nations while carrying out digital missions — the computer equivalent of the Vietnam War’s spilling over the Cambodian border in the 1960s. To battle Russian hackers, for example, it might be necessary to act through the virtual cyberterritory of Britain or Germany or any country where the attack was routed.

General Cartwright said military planners were trying to write rules of engagement for scenarios in which a cyberattack was launched from a neutral country that might have no idea what was going on. But, with time of the essence, it may not be possible, the scenarios show, to ask other nations to act against an attack that is flowing through their computers in milliseconds.

“If I pass through your country, do I have to talk to the ambassador?” General Cartwright said. “It is very difficult. Those are the questions that are now really starting to emerge vis-à-vis cyber.”

Frida Berrigan, a longtime peace activist who is a senior program associate at the New America Foundation’s arms and security initiative, expressed concerns about whether the Obama administration would be able to balance its promise to respect privacy in cyberspace even as it appeared to be militarizing cybersecurity.

“Obama was very deliberate in saying that the U.S. military and the U.S. government would not be looking at our e-mail and not tracking what we do online,” Ms. Berrigan said. “This is not to say there is not a cyberthreat out there or that cyberterrorism is not a significant concern. We should be vigilant and creative. But once again we see the Pentagon being put at the heart of it and at front lines of offering a solution.”

Ms. Berrigan said that just as the counterinsurgency wars in Iraq and Afghanistan had proved that “there is no front line anymore, and no demilitarized zone anymore, then if the Pentagon and the military services see cyberspace as a battlefield domain, then the lines protecting privacy and our civil liberties get blurred very, very quickly.”

Cyberwar - Privacy May Be a Victim in Cyberdefense Plan - Series - NYTimes.com

Powered By Blogger