Home » Posts tagged 'hackers' (Page 2)
Tag Archives: hackers
C4ISTAR for Hacking and Cyber Conflict
As per http://en.wikipedia.org/wiki/C4ISTAR
C2I stands for command, control, and intelligence.
C3I stands for command, control, communications, and intelligence.
C4I stands for command, control, communications, computers, and (military) intelligence.
C4ISTAR is the British acronym used to represent the group of the military functions designated by C4 (command, control, communications, computers), I (military intelligence), and STAR (surveillance, target acquisition, and reconnaissance) in order to enable the coordination of operations
I increasingly believe that cyber conflict will develop its own terminology and theory and paradigms in due time. In the meantime, it will adopt paradigms from existing military literature and adapt it to the unique sub culture of cyber conflict for both offensive, defensive as well as pre-emptive actions. Here I am theorizing for a case of targeted hacking attacks rather than massive attacks that bring down a website for a few hours and achieve nothing but a few press headlines . I would also theorize on countering such attacks.
So what would be the C4ISTAR for -
1) Media company supporting SOPA/PIPA/Take down Mega Upload-
Command and Control refers to the ability of commanders to direct forces-
This will be the senior executives including the members of board, legal officers, and public relationship/marketing people. Their name is available from corporate websites, and social media scraping can ensure both a list of contact addresses (online) as well as biases for phishing /malware attacks. This could also include phone (flooding or voicemail hacking ) attacks , and attacks against the email server of the company rather than the corporate website.
Communications- This will include all online and social media channels including websites of the media company , but also those of the press relations firms handling communications , phones,websites- anything which the target is likely to communicate externally (and if possible internal communication)
Timing is everything- coordinating attacks immediately is juevenile, but it might be more mature to attack on vulnerable days like product launches or just before a board of directors meeting
Intelligence-
Most corporates have an in-house research team, they can be easily targeted using social media channels, but also offline research and digging deep. Targeting intelligence corps of the target corporate is likely to produce a much better disruption. Eventually they can be persuaded to stop working for that corporate.
Computers- Anything that runs on electricity and can be disabled – should be disabled. This might require much more creativity than just flooding.
surveillance- This can be both online as well as offline, and would be of electronic assets, likely responses for the attack, and the key people who are to be disrupted.
target acquisition- at least ten people within each corporate can and should be ideally disrupted, rather than just the website. this would call for social media scraping, and prior planning. even email in-boxes can be disrupted (if all else fails)
and reconnaissance-
study your target companies, target employees, and their strategies.
Then segment and prioritize in a list of matrix of 10 to 10, who is more vulnerable and who is more valuable to attack.
the C4ISTAR for -a hacker activist organization is much more complicated but forensics reveal that most hackers tend to leave a signature style (in terms of computers,operating systems,machine ids,communication, tools, or even port numbers used)
the best defense for a media rich company to prevent hacking attacks is to first identify its own C4ISTAR structure for its digital content strategy and then fortify as well as scrub vulnerabilities (including from online information regarding its own employees)
(to be continued)
http://www.catb.org/~esr/faqs/hacker-howto.html
The Hacker Attitude
SOPA RIP
- Any effort to combat online piracy must guard against the risk of online censorship of lawful activity and must not inhibit innovation by our dynamic businesses large and small (AJ-yup)
- We must avoid creating new cybersecurity risks or disrupting the underlying architecture of the Internet. (AJ-note this may include peer-to-peer browsers, browser extensions for re-routing and newer forms of encryption, or even relocation of internet routers in newer geographies )
We must avoid legislation that drives users to dangerous, unreliable DNS servers and puts next-generation security policies, such as the deployment of DNSSEC, at risk.
While we are strongly committed to the vigorous enforcement of intellectual property rights, existing tools are not strong enough to root out the worst online pirates beyond our borders.
We should never let criminals hide behind a hollow embrace of legitimate American values
and
We should all be committed to working with all interested constituencies to develop new legal tools to protect global intellectual property rights without jeopardizing the openness of the Internet. Our hope is that you will bring enthusiasm and know-how to this important challenge
Authored by
Victoria Espinel is Intellectual Property Enforcement Coordinator at Office of Management and Budget
————————————————————————–
AJ-Why not sponser a hackathon, White House and create a monetary incentive for hackers to suggest secure ways? Atleast a secure dialogue between policy makers and policy breakers could be a way forward.
SOPA in its current form is dead. We live to fight another day.
—————————————————————————–
Quote-
Let us never negotiate out of fear. But let us never fear to negotiate. John F K
Poets and Hackers
My latest book , a collaboration with many fine artists is now up. Its called Poets and Hackers
Enjoy!
Poets & Hackers v5http://www.scribd.com/embeds/66419481/content?start_page=1&view_mode=list&access_key=key-23x8ifmmz5noevn8m4vn//
Poets and Hackers
analysts analyze bloggers blog but scientists research
if hackers hack and writers write why dont poets poe
or maybe everybody is a closet poet
some write prose some write code
some play in ones and zeros some play with images
some with video while most stick to playing with A to Z
we all have our favorite toys some we choose most are given to us
poets and hackers playjoes and crackers
choosing to play in a divine farmville playing till we slacken


