Wednesday, April 28, 2010

X-37B and Prompt Global Strike Launch

At 7:52 p.m., April 23rd, an Air Force Atlas 501 rocket shot the capsule enclosed X-37B Orbital Test Vehicle into space from Cape Canaveral. Resembling a small space shuttle, the OTV was built in Boeing’s famed Phantom Works.

The OTV will serve as an “on-orbit” laboratory for new sensors and other high-tech devices that will later be built into satellites. Its payload is highly classified, but the Air Force says test flights aboard the retrievable OTV will prove out new technologies before they are shot into space to stay.

The 29-foot OTV is powered by a combination of lithium ion batteries and solar panels. Air Force deputy undersecretary for space programs, Gary Payton, told reporters: “Probably the most important demonstration is on the ground, see what it really takes to turn this bird around and get it ready to go fly again.”

The turnaround goal is 15 days.

As for how long it will stay up there: “In all honesty, we don’t know when it’s coming back for sure,” said Payton. “I don’t think we’ve set any specific goal, but I would think handling this bird more like an SR-71 and less like a routine space launch vehicle would be a good objective,”

With all the focus on the launch of the X-37B, the launch of a Minotaur IV rocket from Vandenberg Air Force base in California received less attention.

The Minotaur IV reportedly carried the prototype of the new Prompt Global Strike weapon that can hit any target around the world in less than an hour.

The PGS is designed as the conventional weapon of the future. Reportedly, it could hit Osama bin Laden’s cave, an Iranian nuclear site or a North Korean missile with a huge conventional warhead.

Friday, April 16, 2010

Ambassador To Cyberspace

Legislation introduced in the Senate Monday would, figuratively speaking, create a United States ambassador to cyberspace.

The International Cyberspace and Cybersecurity Coordination Act of 2010 would authorize the creation of a senior coordinator at the State Department with the rank of ambassador at large, according to a statement issued by its sponsors, Senate Foreign Relations Committee Chairman John Kerry, D.-Mass., and Sen. Kirsten Gillibrand, D.-N.Y.

"This bill is the first step to better organize U.S. efforts to develop a coordinated strategic approach to international cyberspace and cybersecurity issues by designating a single diplomat responsible for U.S. cyber policy overseas," Kerry said in the statement.

The senior coordinator would be the principal adviser to the secretary of state on international cyberspace and cybersecurity issues and provide strategic direction for federal government policy and programs aimed at addressing cyberspace and cybersecurity issues abroad.

The sponsors said the legislation would ensure the development of a clear and coordinated strategy for international cyber engagement, including the potential negotiation of a multilateral framework to provide internationally acceptable principles to prevent cyberwarfare.

Gillibrand said this measure meshes with another bill she introduced last month., the International Cybercrime Reporting and Cooperation Act, which would use financial incentives to get foreign nations to combat cybercriminals. "Our legislation will make America safer by making our cyber diplomacy more robust, and coordinating with our partners in the international community," she said in a statement.

One of President Obama's cybersecurity priorities in his Cyberspace Policy Initiative outlined last May is to develop a coordinated, international response to global cyber threats.

The Kerry-Gillibrand bill is the latest of a growing number of cybersecurity bills before Congress.

This post is excerpted from the GovInfoSecurity article, Cybersecurity Ambassador, by Eric Chabrow, April 12th, 2010.

Monday, April 12, 2010

The Census

The 2010 Census is underway and you may be wondering about whom you can trust. The Census is easy, important, and safe — just fill out your form and mail it back.

The IC3 and the Better Business Bureau (BBB), a 2010 Census partner, are encouraging participation in the 2010 Census while cautioning consumers to get the facts:

2010 Census takers will never contact you by e-mail or solicit for donations. Do not respond to unsolicited (spam) e-mail or text messages; including clicking on links and/or opening attachments contained within. Criminals often capitalize on legitimate campaigns to spread computer viruses through e-mails, text messages, "pop-ups," fraudulent Web sites, or infected legitimate Web sites. The viruses are embedded in an attachment (including pictures), link, and/or computer application. This also applies to tactics used in social networking sites. Remember, not all anti-virus software detects every virus, especially if the virus is newly created.

Visit 2010.census.gov for official information on the 2010 Census. Beware of groups using a similar name to a reputable agency, especially through Web sites. Rather than following a purported link to the Web site, log on directly to the official Web site for the business identified in the e-mail and/or text. Web sites can be verified by utilizing various Internet-based resources to confirm their status and to obtain feedback.

2010 Census takers will not ask you for your Personally Identifiable Information (PII) such as your social security account number (SSAN), driver's license number, bank account number, or credit card number. Do not provide this type of information to anyone claiming to be a 2010 Census taker. Please be aware, the Census Bureau asks for the last four digits of the respondent's SSAN for one survey: the National Health Interview Survey. This survey touches approx 65,000 housing units per year.

For the 2010 Census, the Census Bureau will hire approximately 1.4 million people. Do not respond to work-at-home opportunities to be a Census taker, especially if the offer is unsolicited and it occurs through e-mail, text, or other indirect means. However, the Census Bureau may contact, in person, trusted third-party stakeholders, such as schools, media, businesses, community-based organizations, faith-based organizations, state, local, and tribal governments to spread the recruiting message. Criminals often use work-at-home scams to commit identity theft by collecting individuals' PII such as their bank account information, SSAN, and driver’s license number. Be wary if someone claiming to be a Census Bureau representative attempts to sign you up as a new employee on the spot. The Census Bureau has a hiring process, which includes taking a test in person, not on-line. To learn more information on what is required to become a census taker, visit http://www.bbb.org/us/article/out-of-work-the-us-census-bureau-is-hiring- nationwide-14365.

If you have information pertaining to a 2010 Census scheme, please file a complaint with the www.IC3.gov and contact your local BBB along with your local law enforcement agency.

The 2010 Census helps ensure your community receives its fair share of political representation and government funding. Fill out and mail back your census form today!

This post is excerpted from the Intelligence Note, 2010 Census, by the Internet Crime Complaint Center [IC3], April 12th, 2010.

Tuesday, April 6, 2010

There Are No Mushroom Clouds In Cyberspace

The National Academies of Science functions in part to provide independent scientific advice to the US government. In that capacity, the office of the Director of National Intelligence contracted with the NAS to look into the prospects of developing cyberwarfare capabilities that are sufficient to deter an attack on its national infrastructure. The NAS has recently submitted a progress report on its efforts, and the dry text of the introductory letter (the report is termed, "The first deliverable for Contract Number HHM-402-05-D- 0011") obscures a sometimes fascinating look into how the cold-war thinking that drove the development of the concept of nuclear deterrence fails to scale to the networked world.

That may seem like a statement of the obvious, but the report points out that deterrence was actually a fully fleshed-out conceptual framework, and there is a significant parallel between cyber and nuclear weapons that's a major component of this framework: it's much easier to engage in offense than defense. "Passive defensive measures must succeed every time an adversary conducts a hostile action, whereas the adversary’s action need succeed only once," the text notes, and recent history is replete with evidence that hostile actions can easily succeed far more often than once.

So, the prospect of mutually assured cyberdestruction might seem to offer the possibility of a framework that's at least similar to the one that governed the world of nuclear weapons. The body of the report, however, focuses on the various reasons it probably doesn't.

Perhaps the biggest reason is that, for deterrence to work, we and our adversaries have to have a rough idea of each other's offensive capabilities. "Classical deterrence theory bears many similarities to neoclassical economics, especially in its assumptions about the availability of near-perfect information (perfect in the economic sense) about all actors," as the report notes. Leaving aside the shortcomings of these assumptions in neoclassical economics, this simply doesn't describe the current reality.

Right now, the US has chosen to keep its offensive cyber weaponry entirely classified and, since there's no launch infrastructure or physical indications of testing (hallmarks of nuclear weaponry), nobody is likely to develop a complete picture of what we can do. The US is unlikely to disclose its capabilities because, in contrast to nuclear weaponry, knowing these capabilities may help adversaries plan defenses. It may be somewhat effective as a deterrent—it's generally assumed that the US has the most potent capabilities around. But it leaves the US in a situation where it is counting on everyone to assume it has the weapons.

This post is excerpted from the Ars Technica article, Modeling cyberattack deterrence on nuclear deterrence fails, by John Timmer, April 6th, 2010.

For more on cyber attack deterrence, visit Ars Technica.

Thursday, February 25, 2010

MultiCam Ready To Replace UCP

Last Friday, the Army announced that this summer it will begin fielding uniforms with a new camouflage pattern to all its troops serving in Afghanistan.

According to a statement obtained by Military.com, Army Secretary John McHugh decided that the so-called "MultiCam" pattern developed by New York-based Crye Precision is the most effective camouflage in the varied terrain of Afghanistan's forests, deserts, mountains and rural villages.

"This decision … reflects the Army's commitment to giving Soldiers in Afghanistan the most effective concealment possible," the statement said. "Camouflage alternatives represent one facet of the Army's ongoing efforts to improve the Army Combat Uniform."

The decision comes four months after the service relented to pressure from then-chairman of the House Appropriations Committee's defense panel, the late Rep. John Murtha, D-Pa., who ordered the Army to study whether its current Universal Camouflage Pattern was the best scheme for Afghan operations.

At the time, Murtha recounted comments he'd received from Army noncommissioned officers complaining about the UCP's colors and their inability to meld into Afghanistan's rural backgrounds.

MultiCam had long been a favorite of Army Special Operations forces, including Rangers and Green Berets, and had also been fielded in limited numbers to Air Force special operations Airmen.

Army officials launched a program in September to determine whether the UCP was adequate for Afghanistan and fielded a limited number of uniforms patterned in MultiCam and so-called "UCP-Delta," which was developed by the Army Soldier Systems Center in Natick, Mass. The 2nd Battalion of the 12th Infantry Regiment received an entire suite of gear in MultiCam, with the 3rd Squadron of the 61st Cavalry Regiment getting the UCP-D ensemble.

The Army will begin issuing the MultiCam "fire-resistant Army Combat Uniform" to troops deploying to Afghanistan this summer before shipping them to troops already there who are still wearing UCP, said Army spokesman Lt. Col. Jimmie Cummings. The Army has nearly 48,000 troops deployed to Afghanistan.

Joes will receive a full set of combat uniforms, including combat shirt, plate carriers, packs, pouches and helmet covers in MultiCam.

In November, officials from PEO Soldier, the Army's Asymmetric Warfare Group, and Special Operations Command tested a variety of patterns against a number of backgrounds in Afghanistan. The patterns included AOR-II, a SEAL-developed pattern similar to the Marine Corps' woodland digital; UCP-D; MultiCam; UCP; the Natick-designed Desert Brush camo and Mirage, which was developed by Bulldog Tactical, a civilian company.

"The results, along with surveys of Soldiers in the two battalions who received alternate camouflage, formed the basis for the Army's decision on MultiCam," the Army said.

The Army's MultiCam pick is part of a recent string of victories for the specialty design company which recently won a competition to revamp the British military's 40 year-old woodland Disruptive Pattern Material camo scheme.

The study on Afghan camo patterns will feed into an overall re-look at the Army's UCP choice and help determine whether the service should jettison the unpopular camo after less than five years in service.

For more visit Military.com, or check out Christian Lowe's article, Army Picks New Camo for Afghanistan Units, February 19th, 2010.

Friday, February 19, 2010

It's Phishing Season

The "white hat" hackers at Intrepidus, a New York-based information security service provider, recently tested 2400 employees at two of its clients with a "tax refund" scenario phishing email. The clients were a state agency and a small bank. This test got interesting, says Rohyt Belani, CEO of Intrepidus, when an average of 35 percent of the employees clicked on the email to find out what the tax refund email contained.

"That is a big foothold for a hacker," Belani says. "Just imagine that over one-third of your employees (or customers) clicked on a link that could potentially infect their PC and your network."

The good news says Belani, is that it was only a test. The bad news, unfortunately, is that these kinds of phishing attacks can and do happen to any business or individual consumer.

Here are some other scams for employees and customers to avoid:

Anything Claiming to be from the IRS -- Despite the flood of messages purportedly from the agency, the IRS doesn't discuss tax account matters via email. It also doesn't initiate taxpayer contact via unsolicited email or ask for personal identifying or financial information. Taxpayers do not have to complete a "special form" to obtain a refund.

Social Security Alerts -- Another phony email claims to be from the Social Security Administration (SSA), threatening that if the person doesn't update their account information (on a bogus site) they will not receive a cost-of-living increase. Now, consumers may receive official letters from SSA attempting to verify that their address or bank has changed, or that they have become ineligible for benefits. Such letters are likely to be legitimate if they do not request information. But it's always best to verify communications by calling SSA: (800-772-1213).

FBI Windfalls -- Earlier this month, the Federal Bureau of Investigation warned Hawaii residents to not fall for emails that claimed to be from the bureau. The phishing emails include FBI letterhead, seal and banners with the FBI Director's photos to make them appear genuine. The notes claimed that the recipient had inherited money, or others claimed that the FBI was imposing fines through email -- which isn't done. The FBI says they have received a large number of complaints, leading investigators to believe that hundreds or even thousands of residents received the emails.

Oh, and where do you think the emails originated?

Nigeria.

To look deeper into the world of phishing, visit GovInfo Security.

Saturday, January 30, 2010

Pump and Dump

First, there’s the glowing press release about a company, usually on its financial health or some new product or innovation.

Then, newsletters that purport to offer unbiased recommendations may suddenly tout the company as the latest "hot" stock. Messages in chat rooms and bulletin board postings may urge you to buy the stock quickly or to sell before the price goes down. Or you may even hear the company mentioned by a radio or TV analyst.

Unsuspecting investors then purchase the stock in droves, pumping up the price. But when the fraudsters behind the scheme sell their shares at the peak and stop hyping the stock, the price plummets, and innocent investors lose their money.

Fraudsters frequently use this ploy with small, thinly traded companies because it's easier to manipulate a stock when there's little or no information available about the company. To steer clear of potential scams, always investigate before you invest.

Steps You Can Take

- Don't believe the hype
- Find out where the stock trades
- Independently verify claims
- Research the opportunity
- Watch out for high-pressure pitches
- Always be skeptical

Learn more about "pump and dump" schemes at The Securities and Exchange Commission.