Friday 12th May 5:41 pm
Cyber crime on a global scale
Tuesday 12th May 2015 12:00 pm
I’m talking about cybercrime again. Cyber bad guys operate at all levels — from intercepting your car’s bluetooth, to using apps and the internet to steal private financial details of tens of millions of citizens.
Even a single person can create cybercrime mayhem.
In April 2015, Navinder Singh Sarao, a 36-year-old, appeared in court in the UK wearing baggy sweatpants, running shoes and a hoodie. This small-time investor drove a broken-down car, and lived in his parents’ run-down flat near the flight path of Heathrow airport. But back on 6 May, 2010, he had used off-the-shelf software to manipulate high-frequency trading algorithms to create the infamous ‘flash crash’.
He sent the Dow Jones industrial average on a wild ride up and down some 1000 points. He briefly wiped over $1 trillion from the stock markets. To put that in perspective, that’s about 1/60 of the gross domestic product of the entire planet — for a whole year. And along the way, using techniques called ‘spoofing’ and ‘layering’, he picked up $40 million — all done using a simple home computer.
Given it’s that easy for one person to create havoc, think how much easier it would be for a government with all of its resources. People talk about ‘cyber warfare’, but it is a fairly vague term, referring to governments attacking other governments. Specifically, what happens when governments use the internet for sabotage, espionage and subversion.
Financial markets, military assets, communication networks, infrastructure — you name it, if it’s got a computer, it can be hacked.
In September 2010, nuclear enrichment facilities in Iran were attacked by the Stuxnet worm.
The Iranians were purifying uranium up to weapons-grade using centrifuges. These centrifuges were taken over by this worm. They spun so quickly they destroyed themselves. But while the attack was actually happening, the control panels of the Iranian operators wrongly indicated that the centrifuges were spinning normally.
This attack delayed the Iranian weapons-grade uranium program by over a year. Who did this? In June 2012, theNew York Times claimed that President Obama had authorised this sabotage.
A modern country relies absolutely on infrastructure — sewerage, transport, drinking water, power, and so on. In 2009, President Obama said: “cyber intruders have probed our electrical grids”.
Then, in 2012, an American company that monitors over 50 per cent of the gas and oil pipelines in the USA discovered that the Chinese had hacked its computer systems.
Were the Chinese simply looking for industrial secrets? Or were they planting bugs, so that they could shut down the US energy grid if China and the USA were to have a conflict sometime in the future?
In 2012, Iranian hackers took control of 30,000 computers belonging to the world’s largest oil producer, Saudi Aramco. We know they changed the Aramco logo to a burning US flag. But what else did they do?
In March 2013, the major banks and broadcasting TV stations in South Korea were hacked. Was North Korea to blame, or was it somebody pretending to be North Korea?
In the Middle East, the Syrian Electronic Army hacked into the Twitter account of Associated Press. They then published a fake news item about a bomb at the US White House. That incident alone sucked $136 billion out of the US Equity Market.
One of the beauties of cyber warfare is its anonymity. While there are suspects, there is often still not enough information to positively identify the culprits.
Cyber warfare can also be done relatively cheaply. But of course, you get better results if you spend more.
In May 2010, the four-star general, Keith Alexander, was put in charge of the newly formed US Cyber Command. By 2014, its budget had jumped from $1 billion to $4.7 billion. They claim they need this money to deal with incessant attacks from other governments.
The US Deputy Secretary of Defense said, William J. Lynn, said: ” .. cyberspace .. (is) a new domain in warfare … just as crucial to military operations as land, sea, air and space”.
As part of their recruitment, the US Defense Department has annual competitions with cyber warriors running banks of military computers. Each team typically has to protect five computers (which are running seven different operating systems) against relentless waves of ever-sophisticated cyber attacks. The average age of the competitors? Just 16 years.
China and many other countries are doing the same.
After all, since time immemorial, teenagers have been given weapons and told to fight. This is just the 21st-century version.
This blog first appeared on Dr Karl's Great Moments in Science
© 2017 Karl S. Kruszelnicki Pty Ltd