Friday, December 9, 2011

The Art of (Cyber) War It's halftime time America!

The Art of (Cyber) War -  It's Halftime America! Vote Obama 2012!
 (See the Clint Eastwood Chrysler Superbowl video http://www.youtube.com/chrysler?sid=1037056&KWNM=chrysler+half+time+in+america&KWID=3179867605SB_2012&channel=paidsearch)


For info on Cloud Computing (see below), diplomacy with Iran continues with possible war looming & Cyber Security expert Richard Clarke in the Wall Street Journal http://online.wsj.com/article/SB10001424052970204883304577219543897943980.html?mod=googlenews_wsj asks a critical question: In case war breaks out between Iran & Isra-el, is Isra-el ready for cyber attacks? (the U.S. is getting ready, to see how click on on the in depth report below near our report on Cloud Computing). 

As the U.S. Presidential election heats up the City of Detroit  http://www.detroitmi.gov/, the heart of the U.S. & world wide auto industry, is being talked about by the GOP candidates for President.  President Obama recently showed he gets the need to invest in the kids who will create the next set of start up companies such as Facebook http://www.facebook.com/ &  Google http://www.google.com/  by giving awards to students from Detroit, Michigan  and other students from around the nation who excel in science at the White House http://www.whitehouse.gov/.  To see the video click on http://www.whitehouse.gov/blog/2012/02/07/president-obama-launches-marshmallow-cannon. Also  to see the video clip of
Grand Torino is the movie Clint Eastwood made on location in the City of Detroit
The State of Michigan homepage: http://www.michigan.gov/




GM International HQ homepage: http://www.gmrencen.com/
GM's venture capital fund homepage: http://www.gmventures.com/

Tech Town http://techtownwsu.org/ is a hi-tech start up business incubator in Detroit on the Wayne State University http://wayne.edu/ campus which is in a building donated by GM.  Detroit Venture Partners http://detroitventurepartners.com/ houses several start up companies in their building in downtown Detroit.  I met the head of Detroit Venture Partners Mr. Linkner, at a start up elevator pitch event & after e-mailing him, he set up  a tour of the facility for me  in downtown Detroit where I met & shook hands with Mr. Sandy K. Baruah the President of the Detroit Regional Chamber http://www.detroitchamber.com/ who was also taking of tour of the facility.   I will report on my tour of the Detroit Venture Partners  building in the next blog.  Also to see a video of a speech that Vice-President of the United States Joeseph (Joe) Biden gave to the  Global Entrepreneurship Week/USA (GEW) annoucing a partnership to help start up companies click on http://unleashingideas.org/ges2012.

Ford homepage: http://www.ford.com/
For more information on the auto industry click http://www.prnewswire.com/news-releases/new-study-on-the-us-automotive-service-market-topples-key-industry-myths-138704234.html a link from the PR Newswire service http://www.prnewswire.com/.  Also to see how Detroit with the IT industry (Microsoft has a partnership with Ford, & GM works with IBM on their telematics solutions) is creating the car of tomorrow click on  http://online.wsj.com/article/SB10001424052970203824904577213041944082370.html written by Mr. Mike Ramsey of the Wall Street Journal.  Auto companies also buy supply chain/logistics software such as SAP from SAP AG http://www.sap.com/.  For more info on logistics click on http://www.logistics.about.com/.
February 6th, 2012 update It's halftime time America!  Detroit was down but not out during 2008 stock market crash when Mitt Romney (who was born in Detroit, Michigan and whose father helped to build one of the companies that was acquired by Chrysler) said to let them go into liquidation bankruptcy, (click here to see his actual editorial in the New York Times http://www.nytimes.com/2008/11/19/opinion/19romney.html) then Senator, now President Obama http://www.whitehouse.gov/  said no and when elected in 2008 gave Chrysler (See the Clint Eastwood Superbowl video http://www.youtube.com/chrysler?sid=1037056&KWNM=chrysler+half+time+in+america&KWID=3179867605SB_2012&channel=paidsearch)
GM http://www.gm.com/ , the City of Detroit and the State of Michigan another chance and they are now hiring and creating jobs in the Detroit, the State of Michigan, the rest of America and around the world!  It is halftime America, now go & finish the job and vote President Obama 2012 so we can continue the comeback in Detroit and the rest of the USA! http://www.barackobama.com/obama-for-america-2012-campaign?source=OM2012_LB_G_Obama2012-search_bo-reelect_d1c&gclid=CIPLzdXEiq4CFeEDQAod7iBl3Q - Romney's refusal to give his former home town of Detroit, and his home state, Michigan another chance would have been a trillion dollar mistake (GM http://www.gm.com/ alone is now the biggest car company in the world once again) had President Obama heeded his advice.  With the war in Afghanistan still raging and a possible war with Isra-el and Iran looming the U.S. can not afford another mistake in judgement by Mitt Romney.
For more information on legislation from President Obama to help start up companies such as Facebook http://www.facebook.com/ which has submitted the papers for a an initial public offering worth billions of dollars http://dealbook.nytimes.com/2012/02/01/tracking-facebooks-valuation/?nl=business&emc=dlbkpma1, click on http://www.whitehouse.gov/the-press-office/2011/09/16/president-obama-signs-america-invents-act-overhauling-patent-system-stim. Also to go to legislation for the America Invents Acts just click on http://innovate.umich.edu/, for updates on cyber security that shows the current U.S. administration understands the danger of cyber attacks click on http://www.dni.gov/reports/20111103_report_fecie.pdf, for info on Cloud Computing going mainstream and cyberwarfare read the folowing articles:




  1. The November 2011 Harvard Business Review article http://www.hbr.org/ titled Everything you need to know about "The Cloud"
  2. The November 14th, 2011 article from Information Week http://www.informationweek.com/ written by J. Nicholas Hoover nhoover@techweb.com titled The CIA Rethinks Data Centers for Big Data featuring an interview with Mr. Gus Hunt the CTO of the CIA https://www.cia.gov/library/publications/the-world-factbook.
  3. The January 2012 issue of CRN http://www.crn.com/ article titled Cloud Turbulence.
Note: Maximillian Bryan & Marcell Technologies Internationale's corporate website has a pilot cloud computing project at http://www.mbmtinternationale.com/ & the cloud computing pilot project is  transitioning after operating for over a year to http://mbmtinternationale.sharepoint.com/Pages/default.aspx  for the new corporate website.

You can still get to http://www.mbmtinternationale.com/,  but it crashes often. The company will resolve this soon as possible.  The company used a beta web design tool for cloud computing from Microsoft and these are the dangers when you jump into Cloud Computing & use beta tools, beta testers for software find out about problems before regular users do so companies such as Microsoft http://www.microsoft.com/ can correct the problems beta software releases have. I will mention in my next blog how to plan for make  your jump to the cloud so that it is a smooth jump and & list some tips for Microsoft if they want to make Office 365 work better & not have customers bolt to Google http://www.google.com/  or other companies such IBM http://www.ibm.com/.  Mr. Lou Gerstner of IBM wrote about the cloud years ago in his book Who Says Elephants Can't Dance (available on Amazon http://www.amazon.com/ & even today it is an excellent read if you want to understand the IT (information technology) industry & where it is going. 






Watch & listen to President Obama's 2012 State of the Union address http://www.whitehouse.gov/state-of-the-union-2012 to find out about the new tax breaks & tax break proposals for start up companies and read the October 10th, 2011 edition of the Forbes 400 http://www.forbes.com/ featuring Mr. Sean Parker (also see the Social Network movie video clip http://www.youtube.com/watch?v=10AeyTCeZJM&feature=relmfu, Justin Timberlake plays him in the movie) one of the officers of Facebook http://www.facebook.com/ in the early days, and see the list of the top venture capitalists in the U.S. and the network of companies such as Facebook, Spotify, and Reid Hoffman who helped to found LinkedIn http://www.linkedin.com/, along with other companies and investors.  News flash, according to media reports the source code for the Norton Anti-virus software from Symantec may have been compromised by hackers, for more info click on http://www.symantec.com/connect/blogs/symantec-investigates-possible-leak-norton-antivirus-source-code.  This is an important incident because most Fortune 500 corporations and Universities in the U.S. & abroad use Norton to scan for viruses and so a hacker, non-state actor, or country or whoever took the info might be able to launch a major cyber attack with this information and do a lot of damage.  More info will be reported as we do our research; and now for the top 10 cyber incidents world wide.....


Top 10 Cyber Security Incidents World Wide

1. US Drone Key Logger Virus - http://www.wired.com/dangerroom/2011/10/virus-hits-drone-fleet.  I now consider this cyber warfare incident the top incident because the implications of this incident with the recent story on page 1 of the New York Times http://www.nytimes.com/  with a picture of the alleged U.S. Drone by Iranian military forces. My theory and Lance http://www.linkedin.com/pub/lance-miller/3/b38/5b6 a friend with the group Black Hat & Infosec agrees; this incident may be related to that story. For video on this incident click on http://www.youtube.com/watch?v=_MrVihH3r3g.  My theory is the key logger virus exploit information may have been sold to Iran. Then using an electro magnetic pulse http://en.wikipedia.org/wiki/Electro-magnetic_pulse  or other cyber warfare electronic counter measures against the downed Drone, Iran took control of the alleged U.S. Drone (if it is a U.S. Drone) and landed it because in the picture on the front page of the The New York Times the UAV appears to be intact. This has serious implications in command and control of these UAVs and the possiblity they could be disabled, and worse turned against whoever controlls the drone(s) during this flight and future flights. The first thing I would do if I was an IT person on the drone program with the U.S., NATO, or whoever the drone belongs is to do a security assessment of any incidents of drones not flying according to their flight plan before this latest drone incident, with a time line of when the US Drone Key Logger Virus was discovered. The second thing I would do in the IT security audit is to investigate and record suspicious LAN/WAN activity on Windows, UNIX, Linux, Oracle Sparc servers, or mainframe servers at the Drone bases, along with doing an inventory of all Drone control equipment that is in use, being repaired, or that is missing, destroyed and talk to the military personnel & defense contractors in charge of destroying damaged equipment and also making sure any possible thefts of Drone equipment have been reported. The last thing would be to account for the possiblity that any planned UAV missions may be compromised and ASAP have built into any future UAV flights equipment, & software that will by default have the UAVs self destruct automatically if the remote pilots lose control of the UAVs for longer than 30-45 minutes unless a bio-metric image of say a finger print or eye scan built into the keypad/joystick is pressed (or for eyes scanned) by the pilot and sent to the UAV in flight if a similar security procedure is not already in place. For more on this story click on this video from MS-NBC http://www.msnbc.msn.com/id/3032619.  In a recent update according to media reports Iran has sold the drone to China, this has not been confirmed, once research has confirmed this report we will post it.










Cyber Threat Levels



Tier 5 - Entry level threat.



Tier 4 - Script kiddies



Tier 3 - Denial of Service (connection to internet or major outage)



Tier 2 - Skilled attackers, organized crime, terrorists, and/or state actors



Tier 1 - A zero day threat where vulnerabilities are found in software, custom code is written to create a threat, and/or the threat is undetected and is collecting data and/or waiting to cause damage when signaled or on a certain day.




2. NASDAQ attack – a few months ago there were media reports on a cyber attack on the NASDAQ http://www.nasdaq.com/,  this is critical infrastructure for the U.S. and world financial markets as NASDAQ is where some key hi-tech companies such as Microsoft http://www.microsoft.com/ are listed on the stock market http://content.usatoday.com/communities/technologylive/post/2011/02/did-nasdaq-hackers-grab-holy-grail-of-insider-information/1





3. Stuxnext Iran Attack – In 2010 a computer worm/virus named Stuxnext attacked a nuclear plant in Iran, the political leadership admitted the attack had slowed down progress at the facility. http://www.telegraph.co.uk/news/worldnews/europe/russia/8262853/Stuxnet-virus-attack-Russia-warns-of-Iranian-Chernobyl.html.  Iran is a major supplier of oil to China and this has implications in regard to the UN Security Council as China is a permanent member. There have been media reports that the original Stuxnext virus hackers or someone with access to the Stuxnext code have made a new update to the virus, we will let you know as we gather more information. Let me introduce you to best expert I know on the Stuxnext virus; he works for Microsoft http://www.microsoft.com/ and his blog is http://blogs.technet.com/b/markrussinovich/archive/2011/03/30/3416253.aspx  I call him Stuxnext Man, for his real name go to his blog and tell me what you think...







4. Google China network attack – The Wide Area Network of Google http://www.google.com/  in mainland China was hacked and Google reported the incident to the U.S. government after checking with other U.S. companies based in China and finding they had been attacked also. This was a key moment in cyber warfare as President Obama formulated a more sophisticated cyber warfare doctrine for the U.S. Armed Forces as a result of this attack, and Google actually relocated to Hong Kong, China from mainland China as a result of the attack. This has lead to a greater coordination between the U.S. armed forces and private companies in protecting key critical infrastructure of the U.S. civillian economy. The Google attack and move from mainland China led to Baidu http://www.baidu.com/ the Chinese version of Google becoming the top search engine in mainland China instead of Google. http://voices.allthingsd.com/20100222/hacking-inquiry-puts-china%e2%80%99s-elite-in-new-light/?mod=ATD_rss.  China has long had a very sophisticated IT approach, which led to them building the Great Firewall of China to defend against an asymmetric network attack in China, to prevent attacks such as the attack against Google. A good way to shore up your your defenses are to follow some of the tips in the article http://www.baselinemag.com/c/a/IT-Management/Ensuring-ITs-Survival-301220  in Baseline http://www.baselinemag.com/  an online and print technology magazine for CIOs based in New York, New York. China has also been a victim of cyber attacks, more on this in the next update. 


5. Baidu Iranian Cyber Army Attack – The Chinese search engine Baidu has been attacked by a group called the Iranian Cyber Army. I am still researching this story for more details but allegedly a group called the Iranian Cyber Army attacked Baidu, China’s most popular search engine, China is still conducting a computer forensics investigation to see if this group is actually affiliated with the government of Iran. http://www.forbes.com/2010/01/13/baidu-cyber-attack-markets-technology-china.html.  This leads to what makes cyber attacks so effective, because attacks can be routed through the computers of businesses, governments, and individuals who may be unaware that the attacks are being launched from their PC networks, governments who are attacked have to do computer forensics analysis before their response or they may strike the wrong target, which may the true attacker’s intent. At this point with the hand of Iran being shown in Syria, Egypt, and Lebanon, it is pretty good guess that Iran is the culprit.




6. Estonia Denial of Service Attack – The President of Estonia in 2007 at the time of the attack, Toomas  Hendrik Ilves gives an interview in Government Executive http://www.govexec.com/ of how he coped with the first major cyberwarfare battle, to read this tale click on http://www.govexec.com/magazine/features/2011/08/leading-the-way/34657. This attack is crucial in the understanding of cyber warfare. Estonia was former part of the USSR/Soviet Union, now Russia http://moscow.usembassy.gov/  that got into a dispute over the price they would pay Russia over natural gas shipped to Europe, and the pipelines that Russia paid for were on Estonia’s soil. To make a long story short, while the payment dispute over natural gas shipped over the pipelines was in progress, Estonia suffered Denial of Service attacks that shut down vital government services and dropped Estonia to it’s knees http://news.cnet.com/8301-17938_105-9721429-1.html.  This was a key cyber battle because it made Europe aware of it’s vulnerability when states like Estonia go rogue from Russia, and make Europe's natural gas supplies vulnerable. In the next update we will list where you can find an interview with the leader of Estonia and how the dealt with this cyber attack and how Estonia came to be a leader in Eastern Europe in cyberspace. Russia has offered aid to NATO http://www.nato.int/cps/en/natolive/index.htm  to try to resolve the situation in Libya before the death and the overthrow of Libiya's previous government by NTC.  In light of Isra-el's threat to attack Iran it should be noted in 2007 that Isra-el used a cyber weapon to cripple Syrian air defenses on building where work on Atomic energy was suspected; more info on this exploit can be found in the August 15th, 2011 issue of Government Executive magazine. 




7. U.S. Senate Cyber Attack - http://uk.ibtimes.com/articles/162353/20110614/senate-hacked-hack-investigate-review-lulz-lulzsec-cyber-attack-cyberattack-us-u-s-security.htm  more info later...








8. IMF Cyber Attack - http://www.nytimes.com/2011/06/12/world/12imf.html  more info later...







9. RSA Security Software compromised - for more details on the cracking of the key part of the U.S. and world wide cyber security infrastructure click on http://aggressivevirusdefense.wordpress.com/2011/04/10/rsa-security-attack-timeline. RSA has a security conference coming up soon that we will list in a future update.  



10. This is not an incident but is a must read for any bank IT executive who needs to know how to protect his network. The article is titled How Wall Street Works with the Feds by Mr. Andrew Conry-Murray in Information Week. For more info go to http://www.informationweek.com/  and do a search on the story and maybe think about giving a Information Week subscription as a Valentines Day gift.



11. The FBI http://www.fbi.gov/  jailed a hacker who found a security flaw in the AT&T http://www.att.com/?WT.srch=1#fbid=6XcuvBGz-Gy website. This flaw
revealed the info of over 100,000 iPad users, including e-mails of people who included government officials and Fortune 500 executives. In case you are one of those people please e-mail us and give us your view of what happened and how you felt. For more info on the incident which occurred in June of 2010, and if you want to find out if you are on the list e-mail delivery@ic.fbi.gov.  The FBI also uncovered an intrusion on the LAN (Local Area Network)/WAN (Wide Area Network) of the U.S. Chamber of Commerce http://www.uschamber.com/  with alleged links to China. China has denied an official attack against the U.S. Chamber of Commerce for more information on the incident from an article in the Wall Street Journal https://customercenter.wsj.com/public/view/login.html?mg=selfserv-wsj&url=https%3A%2F%2Fcustomercenter.wsj.com%2Fview%2Fhome.html  click on http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html.  For video on this attack click on http://online.wsj.com/article/SB10001424052970204058404577110541568535300.html#articleTabs%3Dvideo


Mr. Winston Shines is a consultant for Maximillian Bryan & Marcell Technologies Internationale LLC http://www.mbmtinternationale.com/ he has been published in Baseline magazine http://www.baselinemag.com/, (to view the article click on http://www.baselinemag.com/c/a/IT-Management/Ensuring-ITs-Survival-301220  Baseline is going all digital soon). has written the copyrighted book Training Today's Youth for Tomorrow's Technology http://www.amazon.com/Training-Todays-Youth-Tomorrows-Technology/dp/1441400362/ref=sr_1_1?s=books&ie=UTF8&qid=1323746481&sr=1-1  which is on sale at Amazon http://www.amazon.com/  and has been a paid speaker at the Michigan State University School of Education http://www.educ.msu.edu/  Annual Education Technology Seminar in East Lansing Michigan. The company has also won the Global Entrepreneurship Week/USA partnership Award. For more info on GEW/USA click on http://unleashingideas.webjam.com/usa/activities_calendar.   also to see a video that Vice-President of the United States Joeseph (Joe) Biden gave to the GEW annoucing a partnership click on http://unleashingideas.org/ges2012.  Maximillian Bryan & Marcell Technologies Internationale http://www.mbmtinternationale.com/  has completed the Kauffman Foundation's http://www.kauffman.org/Section.aspx?id=About_The_Foundation  Fast Trac New Ventures program for start up companies; Maximillian Bryan & Marcell Technologies Internationale's (a start up company)core competencies are IT, cyber security along with PC/Server LAN/WAN implementation so that the company can advise clients on how to best protect their computer & smart phone networks (yes smart phones are vulnerable to Blue tooth viruses) in this age of never ending cyber attacks.......







0 comments: