Now Driving Online Now Hiring Online Home Seller Subscribe to the JG-TC
12°F
Severe
Who should Democrats choose as their lieutenant governor candidate?
More
Thomas Castillo
Mike Boland
Terry Link
Other
View Results
 






 
Thursday, July 9, 2009 8:52 PM CDT
Experts work to untangle US, Korea cyber attack



WASHINGTON (AP) — U.S. authorities trying to unravel the widespread cyber attacks against government Web sites in the United States and South Korea this week are facing a lengthy, complex investigation that may never identify a culprit, at least not one they would be willing to reveal.

Cyber experts familiar with the probe are divided over the extent of North Korean involvement, split between those who believe hackers may have simply used zombie computers in the region and those who think the communist nation has moved to the digital battlefield.

Active involvement by North Korea would signal a new advancement by the nuclear-ambitioned nation.

If Pyongyang is behind the attacks, “it probably establishes a new pattern of behavior,” said Rod Beckstrom, former head of the U.S. cybersecurity center. “If this is them, they are now in the club. And they’re probably only going to get better.”

Effects of the outage lingered Thursday, as State Department spokesman Ian Kelly said that cyber attacks on the department’s computers continued, though not at the high volume seen in the first wave of the assault. A new wave of computer attacks also battered government sites in South Korea but did not knock them offline.

“We are taking measures to deal with this and any potential new attacks,” Kelly said.

Investigators in both the U.S. and South Korea face a steep task in trying to trace the attack to its source. The assault involved more than 100,000 zombie computers linked together in a network known as a “botnet.” Most of those computers were in South Korea, but others were in Japan, China, the U.S. and possibly other countries, experts said.

Analysts and former government officials on Thursday said the effort to find the culprit in the wave of Web attacks would be a multi-pronged federal investigation that includes agents lurking in nefarious cyber chat rooms seeking tips on the attackers, and analysts poring over the computer code looking for digital fingerprints. And they say there’s just a 10 percent chance they’ll be successful.

Beckstrom, now head of the Internet’s key oversight agency, the Marina del Rey, Calif.-based Internet Corporation for Assigned Names and Numbers, said Thursday the attacks lacked sophistication and was just a “basic hack job” a smart teenager could have launched. But others suggest it displayed characteristics of a higher level, more coordinated effort.

The assault began July 4 and targeted dozens of government and private sites in the U.S., including some federal agencies that were shut down for days as the attack continued into Tuesday.

Treasury Department and Federal Trade Commission Web sites were knocked out by the blizzard of digital requests, while others such as the Pentagon and the White House were able to fend it off with little disruption.

Jack Thomas Tomarchio, head of Nicor Cyber Security and a former deputy undersecretary at the Homeland Security Department, said a North Korean link, if true, would be troubling because “they play by their own set of rules, so it is more difficult to calibrate how they’re going to respond.”

He added that the attacks overall show that the federal government is still very vulnerable in terms of its cyber security and that agencies have miles to go to plug the holes.

“This is not Pearl Harbor. I’m not trying to alarm the country,” he said. “But we do have a serious intrusion problem.”

Investigators — including staff at the Homeland Security Department and the National Security Agency and a number of government contractors — are following three paths, according to Alan Paller, director of research at SANS Institute, a computer-security organization in Bethesda, Md.

Copies of the malicious code, he said, have been shipped out to a dozens of analysts and cyber security companies, who are now analyzing it, looking for errors or other hints that would point them to the author. Investigators, including many who speak foreign languages, are roaming the Internet chat rooms, hoping to find someone bragging about the attack or providing clues as to its origin. And still others are following the electronic trail, tracing the attack back to the initially infected computers.

The attack, Paller said, was a wake-up call, that showed that — without a big effort hackers were able to bring some federal agencies’ Web presence to its knees.

What some analysts have been able to tell so far is that the program used in the attacks has elements of a fast-spreading e-mail worm from 2004 called “MyDoom.” But, experts said it has enough new elements that some antivirus software didn’t immediately recognize it as a threat.

The infection spread fast. Joe Stewart, director of malware research for the counterthreat unit of SecureWorks Inc., who has been analyzing the code, says it appears to have been written around July 3, which means it infected tens of thousands of computers in just a few days, before they started attacking.

He added that the malware also appears to contain a destructive Trojan designed to overwrite all the data on the victim’s hard drive at some point in the future.

One clue linking the attack to the Korean peninsula was that part of the program that appeared to have been written using a Korean-language Web browser, Stewart said. He cautioned that it was “not conclusive evidence of anything.”

Investigators also said the author of the programming code didn’t try to disguise it, which is unusual.


Share:          Submit to Reddit         Add to My Yahoo!   



  Add your comments

*Member ID:
*Password:
Remember login?
(requires cookies)
  Forgot Your Password?
 

Not already registered?
Then click Here.


JG-TC.com encourages readers to engage in civil conversation with their neighbors. Comments that are submitted are not posted to the site immediately. They go into a queue to be moderated and may take several hours to be reviewed. Comments posted on Saturday may not be reviewed until Sunday afternoon.

In order to keep the page a set width, long lines (mostly long links) will be chopped. Try putting spaces in your links or consider using tinyurl.com to make a smaller link that you can include.

We will never edit or alter your comments, but we do reserve the right to remove comments that violate our code of conduct.

No comment may contain:

* Potentially libelous statements; such as accusing somebody of a crime, defamation of character, or statements that can harm somebody's reputation.
* Obscene, explicit, or racist language.
* Personal attacks, insults, threats, harassment or inciting violence.
* Commercial product promotions.

If you have any questions, please contact our moderator.


 


YMCA seeks new director after Wall's resignation

Quinn talks over budget issues with women lawmakers

Four more winners named in Healthy Kids program

Depot renovations uncover historic artwork

Prairie plot in bloom at Douglas-Hart

Funding rally for Beacon is Saturday

ICC approves oil pipeline through Shelby County

Governor to sign construction bill

AP sources: Burris won't run for full Senate term

Abortion pill used in a quarter of US abortions, new study reports

Mass. is 1st state to sue feds over marriage law

Blagojevich aide pleads guilty in corruption case, promises to be witness for gov't trial

Security cameras
offer no clues in
storage shed fire

Deal bears load on sidewalk work

Illinois regulators sign off on planned pipeline

Cellmate: Man accused in death of boy, 2, said he 'did everybody a favor'

Experts work to untangle US, Korea cyber attack

GM sale cleared; path opens to exit Chapter 11

Neoga cleanup days start with Saturday pickup

Surprise: Ill. attorney gen. won't run for higher office

Is this cyber war? Possible US responses limited

4 Ill. cemetery
workers accused
in grisly plot

So far, state fairs are set to go on without budget

Storm's rainfall, lightning hit hard

Rural buildings to get federal stimulus help

Nationwide roundup nets more than 35,000 fugitives


 




©2007 Journal Gazette and Times-Courier, divisions of Lee Enterprises.    JG/T-C Do Not Call Policy    Privacy Policy    Contact Us
Tab
Content