Showing posts with label Iranian. Show all posts
Showing posts with label Iranian. Show all posts

Sunday, June 9, 2013

U.S. Helps Allies Trying to Battle Iranian Hackers

The American officials would not say which countries in the Persian Gulf have signed up for help in countering Iran’s computer abilities. But the list, some officials say, includes the nations that have been the most active in tracking Iranian arms shipments, intercepting them in ports and providing intelligence to the United States about Iranian actions. The three most active in that arena are Saudi Arabia, the United Arab Emirates and Bahrain.

In Asia, the countries most worried about being struck by North Korean computer attacks are South Korea and Japan.

The Defense Department’s assertive new effort in the gulf and Asia is the latest example of how the Obama administration is increasingly tailoring its national security efforts for a new era of digital conflict, in this case assuring the defense of computer networks and, if necessary, striking back against assaults.

A directive signed by the president that surfaced Friday — the third in a series of leaked documents published by the newspapers The Guardian and The Washington Post — underscored how the Obama administration is trying to prepare itself and its allies. The leaks also revealed how the Obama administration has put in place a large Internet surveillance operation to identify terrorism threats.

The presidential directive included the declaration that the United States reserved the right to take “anticipatory action” against “imminent threats,” a reference, it seemed, to the kind of crippling infrastructure attacks that Iran appears to be working on against American and allied targets.

The new help for strengthening computer-network defenses for allies, which has not been publicly announced, closely parallels earlier efforts by the Obama administration in two volatile parts of the world. In recent years it has helped install advanced missile-defense systems and early-warning radars in Persian Gulf nations to counter Iran’s missile ability, and it has done something similar in Asia in response to North Korea’s nuclear weapons program.

But deterring cyberattacks is a far more complex problem, and American officials concede that this effort, which will include providing computer hardware and software and training to allies, is an experiment. It has been propelled by two high-profile attacks in the past year. One was against Saudi Aramco, Saudi Arabia’s largest, state-run oil producer, and according to American officials it was carried out by Iran. That attack crippled 30,000 computers but did not succeed in halting production. The other, an attack on South Korea’s banking and media companies this spring, was later attributed to North Korea. It froze the ability of several banks to operate for days.

“The Iranian attack on the Saudis was a real wake-up call in the region,” said one senior administration official, who would not speak on the record about the American efforts to counter Iran. “It made everyone realize that while the Iranians might think twice about launching a missile attack in the region, they see cyber as a potent way to lash out in response to sanctions.”

The administration is capitalizing on the fear created by those attacks to build on the de facto alliance against Iran that it has constructed in the region. The Pentagon is drawing up proposals for providing advanced hardware and software for computer-network defense that could be sold throughout the Persian Gulf, much as American aircraft and missiles are sold to Arab allies. Training programs are being put together to teach computer security to military and law enforcement in the region, and to collaborate with private companies.

And, just as the Pentagon conducts naval exercises in the Persian Gulf to practice ways of keeping the Strait of Hormuz open, officials say future joint war games would include simulated cyberattacks, similar to the one Iran conducted against Saudi Aramco.

The idea is to give American and allied forces practice carrying out their missions with their networks under duress, officials said.

The new interagency effort in Washington comes at a time when Israeli and American intelligence officials have been concerned by Iran’s swift advances in its computer weaponry, particularly its ability to disrupt existing infrastructure. As one former senior American military commander said recently, “They have startled everyone with the speed at which their capabilities have increased.”

But one continuing point of dispute is whether Iran and North Korea are working together on the development of cyberweapons, the way they have worked together for years on the development of missile technology.

A senior Israeli military official said Israel had evidence that Iran and North Korea were beginning to collaborate on developing cyberweapons. He declined to cite the specific evidence.

Although there is concern in Washington that cooperation between Iran and North Korea could spread to computer tools, American officials say there is no proof of such collaboration.

Sunday, December 2, 2012

After Death of Sattar Beheshti, Iranian Blogger, Head of Tehran’s Cybercrimes Unit Is Fired

The dismissal of the commander, Gen. Saeed Shokrian, follows investigations by Parliament and Iran’s judiciary into the unexplained death of the blogger, Sattar Beheshti, 35, who died in early November just a few days after being arrested by the cybercrimes police unit, known here as FATA.

“Tehran’s FATA should be held responsible for the death of Sattar Beheshti,” said Iran’s national police chief, Ismael Ahmadi-Moqaddam, according to the Iranian Labor News Agency.

It is unclear whether General Shokrian will also face judicial charges over the blogger’s death.

The public nature of his dismissal suggests that he will bear most of the responsibility for the death. In similar cases in the past, officials have been punished, but it is rare for them to be named and publicly dismissed on the same day.

Mr. Beheshti’s Web site, My Life for My Iran, criticized Iran’s financial contributions to the Hezbollah movement in Lebanon. Mr. Beheshti posted pictures of Lebanese youths having parties alongside images of Iranians living in poverty.

The exact cause of Mr. Beheshti’s death remains murky. Mr. Ahmadi-Moqaddam said Tuesday that investigations had ruled out torture as a cause of death, saying it was possible that Mr. Beheshti, who in pictures looks big and strong, died of “psychological shock.”

Iranian activists and bloggers say Mr. Beheshti died of injuries following beatings. Iran’s judiciary spokesman, Gholam Hussein Mohseni-Ejei, recently admitted that Mr. Beheshti — while in prison — had lodged a written complaint against an interrogator, in which he accused the man of having beaten him during his detention in Tehran’s Evin prison.

“I, Sattar Beheshti, was arrested by FATA and beaten and tortured with multiple blows to my head and body,” read the document, published by the opposition Kalame Web site. He added, “If anything happens to me, the police are responsible.”

Mr. Ahmadi-Moqaddam said that Mr. Beheshti was given tranquilizers while in the prison’s clinic, but that when handed over to the cybercrimes unit its officers denied him the same tranquilizers. “This might be regarded as neglect,” he said. “However, there were no signs of beatings on his body.”

Official statements on the cause of death have been contradictory. An influential member of Parliament who earlier denied that Mr. Beheshti had been tortured in any way told the Tabnak Web site that the blogger had been beaten, but died of shock and fear.

“Definitely he was beaten inside the FATA detention center,” the lawmaker, Alaeddin Borujerdi, told the Web site, “but he didn’t die as a result of these beatings.” He also stressed that the cybercrimes unit must change the way it deals with prisoners.

Iranian activists who have been in contact with Mr. Beheshti’s family say his relatives were not allowed to see his body before a hurried funeral on Nov. 6 in his hometown, Robat Karim, 30 miles southwest of the capital, Tehran.

In Mr. Beheshti’s final post, on Oct. 29, a day before his arrest, he said he was being threatened by security officials. “They told me that if I didn’t close my big mouth my mother should prepare to wear black clothes,” for mourning.

The Iranian Parliament’s special investigator into the case, Mehdi Davatgari, said he welcomed the commander’s removal. “This move shows the civil rights of our citizens are our top priority,” he said.

Wednesday, August 1, 2012

The Lede Blog: Iranian Scientist Claims U.S. Cyberattack Was ... Loud

The United States has a rather bizarre history of blasting rock music into the ears of presumed enemies, so it seemed plausible when a prominent security expert reported Monday that a new cyberattack on Iran’s atomic program included workstations erupting in booms of “Thunderstruck” by AC/DC, an Australian rock band.

In a blog post, Mikko Hypponen, the chief research officer of F-Secure, a computer security company based in Finland, cited “a series of e-mails” he had received from “a scientist working at the Atomic Energy Organization of Iran.” He admitted he was unable to confirm any details of the alleged attack but said the sender was using the correct e-mail address, aeoi.org.ir.

Mr. Hypponen quoted the scientist as saying the music hit “in the middle of the night with the volume maxed out.”

His report created a sensation as blogs and news reports around the globe repeated the claim. ForeignPolicy.com went further, noting on its blog that the United States had repeatedly blasted loud music at supposed foes.

For instance, it noted that American troops in 1989 had tried to force the Panamanian president, Manuel Noriega, from his refuge in the Vatican embassy by bombarding it with loud music. The blog told of military DJs taking requests and creating a playlist that included AC/DC’s “You Shook Me All Night Long.”

More recently, Foreign Policy said, the United States Psychological Operations Company “admitted to the use of heavy metal in Iraq as a mechanism to break uncooperative prisoners’ resistance.” And the International Committee of the Red Cross, it noted, had reported the use of similar tactics against Guantánamo inmates.

Alas, the Iranian episode seems too good to be true.

Specialists in cyberwarfare said the e-mails could have easily been faked, including the seeming return address from the Iranian atomic program. Simple logic, one expert noted, suggested that an Iranian scientist writing such a report to a foreigner might quickly join the ranks of the martyrs. Finally, the tone of the alleged e-mails from the Iranian scientist seemed suspicious in their self-congratulatory tone about the success of the computer attack and its heavy-metal explosion.

“I doubt it,” a senior administration official who closely follows the Iranian program said of the cyber claim.

Sunday, July 29, 2012

The Lede Blog: Iranian Scientist Claims U.S. Cyberattack Was ... Loud

The United States has a rather bizarre history of blasting rock music into the ears of presumed enemies, so it seemed plausible when a prominent security expert reported Monday that a new cyberattack on Iran’s atomic program included workstations erupting in booms of “Thunderstruck” by AC/DC, an Australian rock band.

In a blog post, Mikko Hypponen, the chief research officer of F-Secure, a computer security company based in Finland, cited “a series of e-mails” he had received from “a scientist working at the Atomic Energy Organization of Iran.” He admitted he was unable to confirm any details of the alleged attack but said the sender was using the correct e-mail address, aeoi.org.ir.

Mr. Hypponen quoted the scientist as saying the music hit “in the middle of the night with the volume maxed out.”

His report created a sensation as blogs and news reports around the globe repeated the claim. ForeignPolicy.com went further, noting on its blog that the United States had repeatedly blasted loud music at supposed foes.

For instance, it noted that American troops in 1989 had tried to force the Panamanian president, Manuel Noriega, from his refuge in the Vatican embassy by bombarding it with loud music. The blog told of military DJs taking requests and creating a playlist that included AC/DC’s “You Shook Me All Night Long.”

More recently, Foreign Policy said, the United States Psychological Operations Company “admitted to the use of heavy metal in Iraq as a mechanism to break uncooperative prisoners’ resistance.” And the International Committee of the Red Cross, it noted, had reported the use of similar tactics against Guantánamo inmates.

Alas, the Iranian episode seems too good to be true.

Specialists in cyberwarfare said the e-mails could have easily been faked, including the seeming return address from the Iranian atomic program. Simple logic, one expert noted, suggested that an Iranian scientist writing such a report to a foreigner might quickly join the ranks of the martyrs. Finally, the tone of the alleged e-mails from the Iranian scientist seemed suspicious in their self-congratulatory tone about the success of the computer attack and its heavy-metal explosion.

“I doubt it,” a senior administration official who closely follows the Iranian program said of the cyber claim.