Tuesday, 10 February 2015

White House to set up new early warning cyber-threat center



The new cyberthreat center will help build intelligence amid cyberattacks (Image: NSA)
The U.S. government is to set up a new agency to monitor cyber-threats and share intelligence.
In a speech Tuesday, assistant to the president for homeland security and counterterrorism Lisa Monaco announced the new division would be a new intelligence-based center that will "connect the dots" between incoming cyber-threats so that various government agencies can be aware, and prepare.

Ahead of the State of the Union later this month, the president's proposed laws aim to force companies to disclose hacks and breaches inside a month.
"Cyber-threats to our national security and economic security are increasingly in their frequency and sophistication." Monaco said. "No-one it seems is immune, from healthcare companies and universities, to technology companies.
She warned that nation states and non-state hackers are constantly "seeking to steal, to spy, to manipulate, and to destroy data."
President Obama made cyber-threat and intelligence sharing a key priority in his State of the Union address last month, in which he promised better cybersecurity in the wake of high-profile hacks against Sony Pictures, and most recently health insurance provider Anthem.
A number of federal agencies, including the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Dept. of Homeland Security (DHS), all have divisions focusing on cybersecurity.
The Obama administration wants the newly-formed Cyber Threat Intelligence Integration Center (CTIIC) to do exactly that -- linking the various federal divisions in order to create a "seamless intelligence flow," according to an official speaking to Reuters on Tuesday.
"There's so many different pieces of intelligence coming in, you've got to collaborate and put it together," said CrowdStrike president Shawn Henry on CBS This Morning.
The new agency, which will begin with about 50 staff and a budget of $35 million, aims to learn from the intelligence failings that led to the September 11 terrorist attacks in New York, officials said.
"We need to sync up our intelligence with our operations, and respond quickly against threats to our citizens and companies," said Monaco.
The center will "have to work in lock-step with the private sector," she said. "The federal government won't leave the private sector to fend for itself. Partnership is a precondition of success."
That means "daily collaboration" to identify threats in order to stave off attacks. She said in an example that the U.S. government will alert private sector companies as soon as it becomes available to it, in an effort to prevent attacks from happening.
But Monaco confirmed CTIIC will "not collect intelligence."
The director of national intelligence James Clapper will head up the division.

Friday, 6 February 2015

Death threat hacker who fooled police is jailed

Yusuke Katayama Yusuke Katayama set riddles and made threats that engrossed Japanese media
A hacker who hijacked computers to make death threats has been jailed for eight years.
Yusuke Katayama played a game of cat and mouse with the authorities, leading them to make numerous wrongful arrests.
He threatened a massacre at a comic book event, as well as to attack a school attended by the grandchildren of Japan's Emperor Akihito.
Katayama's campaign highlighted the difficulties the country's police force has had in dealing with cyber crime.
"He committed the crime, and the purpose of it was [for police] to make wrongful arrests," said presiding judge Katsunori Ohno at Tokyo District Court, adding that Katayama's actions had been "vicious".
Riddles Throughout 2012, the 32-year-old used a virus to gain control of strangers' computers. He then issued threats - which appeared to come from the computer's owner - and a series of riddles that captured the attention of the national media.
Among the other threats made by Katayama - who went by the alias Demon Killer - was one to attack a plane.
The case highlighted the Japanese police's tendency to extract confessions from suspects, as four people owned up to crimes which the National Police Agency (NPA) later admitted they did not commit.
Computers belonging to each had been infected with a Trojan Horse virus, introduced via a link on the popular Japanese chat forum 2channel.
The NPA's chief apologised, acknowledging his force had been tricked by the hacker, and promising his cyber crime unit would improve.
Reward Police held one falsely suspected person for several weeks before media and a cyber crime expert received anonymous messages containing information that investigators conceded could only have been known by the real culprit.
Katayama had taunted police in emails that sent them all over Japan.
In one message, investigators were told to go to Enoshima, an island off Tokyo, and to look for a cat that turned out to be wearing a collar on which was a memory card.
The card held details of the code and malicious program he had used to gain remote control of victim's computers.
In December 2012, the police offered a 3m yen (£16,822) reward for information leading to the arrest of the culprit.
But it was the cat that led police to arrest Katayama in February 2013, who was seen on CCTV footage with the animal.