Bad military botnet proposal

An article by Col. Charles W. Williamson III titled “Carpet bombing in cyberspace: Why America needs a military botnet” has been published by the Armed Forces Journal. Col. Williamson, seeing that miscreants are using compromised machines all over the Internet to create botnets used for malicious purposes, has decided that the military needs to create its own, legitimate botnet. He proposes that this would be used in order to respond to online attacks from foreign countries by attacking the attackers, including both government and civilian attacking machines as necessary. He specifically proposes not using compromised machines (which would be illegal), but using machines on the af.mil (U.S. Air Force) network, including all hosts on the NIPRNet (Nonsecret IP Network). The proposal doesn’t really make any sense to me. First of all, attacks from hostile compromised machines on the Internet occur on a daily basis and are already handled by network service providers. These attacks are never likely to be initiated specifically from an individual attacking country’s systems, but rather from compromised systems all over the world–sometimes including compromised systems belonging to the U.S. military. Second, the best way to respond to attacking systems is not by launching hostile traffic back at them, but by filtering them or nullrouting them. Again, network service providers already do this today, and cooperate with each other in addressing major attacks. Thirdly, if the U.S. military sets up a botnet and uses it to launch denial of service attacks, it will be in violation of its own contracts with its network service providers–I don’t know of any network service provider that offers a military exception to its terms of service regarding denial of service attacks. Fourth, if all of the U.S. military bots are on its own network, their aggregate bandwidth still can’t exceed the bandwidth of its connections to other networks. Fifth, if there are attacks coming from another country that the U.S. is at war with, the recent subsea cable outages in the Middle East suggest that there are other effective mechanisms for disabling their ability to engage in Internet attacks. Finally, it’s not clear to me what benefit would be obtained from the military setting up its own botnet on its own network using its own IPs. Botnets offer two main benefits–(1) offering a distributed platform for computing and traffic generation and (2) creating a buffer of separation between the agent performing an action and the action itself. The second benefit occurs because the miscreant doesn’t own the machines that make up the botnet, lots of other people do. A botnet composed entirely of hosts on the military’s network is relatively easy to identify, filter, and block–the second benefit doesn’t exist. The first benefit is also mostly lost if you use your own network and hosts. The point of a distributed denial of service attack is to use up the other guy’s bandwidth, but not your own. That’s very easy to do if you’re not using your own resources, which is why distributed denial of service attacks use compromised systems and, sometimes, methods to amplify attacks using other people’s servers that send out responses that are larger than the requests that prompt them. But if you’re using your own resources on your own networks, you’re limited to the bandwidth you have at your network interconnection points, and multiplying hosts inside that perimeter gains you nothing except a guarantee that you can saturate your own internetwork connectivity and cut yourself off from the outside unless your target has less bandwidth than you do. It’s ironic that Williamson complains about a “fortress mentality,” while making a proposal to create a gigantic bot army inside the military’s own perimeter. A million-man army doesn’t help you if they’re inside a fortress with exits that restrict its ability to be deployed, except when you can win the battle with the number of men who can leave the exits at any one time. I’ve also posted a comment on the Armed Forces Journal article at the AFJ’s forum where I make a few additional points. I also agree with many of the other critical remarks that have been made in the thread there. “Crass Spektakel”’s point that “Whoever controls BGP and the backbone routers controls the internet” and that most of the control of BGP routing and the routing registries resides in the U.S. is a good one. A similar point could be made about DNS. Other posts on this subject: Kevin Poulsen at the Wired blog Jon Stokes at Ars Technica UPDATE (May 14, 2008): I may take some heat for even suggesting this, but an idea which actually takes advantage of both of the characteristic benefits of botnets I listed above and would be far, far more effective than Williamson’s proposal would be if the military produced bot software along the lines of SETI@Home and Folding@Home, which anyone could volunteer to download and run on their home or corporate machines (or better still, made available to run on XBoxes and Play Station 3s), for use by the military when needed. Some of the abuse worries could be defeated if the activation and deactivation of the software was fully under the control of the end user, and the military obtained appropriate permission from upstream ISPs for activities which would otherwise constitute AUP violations by end users. I hasten to add that this is still a terrible idea–putting such software out in public makes it a certainty that it would be reverse-engineered, and the probability of it being compromised by third parties for their own abuses would correspondingly increase. UPDATE: Looks like Paul Raven beat me to the “Milnet@Home” idea, as he dubs it. A commenter at Bruce Schneier’s blog also came up with the same idea. F-Secure’s blog also offers some good criticisms of Williamson’s proposal. ...

May 13, 2008 · 5 min

Bill McCauley, RIP

I was saddened to learn this morning of the death of Bill McCauley, who was my boss when he was Vice President of Operations for GlobalCenter for a year or so around 1999-2000. I last saw him in 2001 at NANOG 21, when he was working for a company called iAsiaWorks, and we chatted briefly. I never knew him well, but when I worked for him he would occasionally chat with me about network security. Bill had left the technology field to run a food distributorship, Red Rock Foods, and recently opened a coffee shop in Queen Creek called Daily Buzz. Unfortunately, he was having financial troubles, and chose a gruesome and horrible way to end his own life, by backing his car into a storage area at his food distribution business, pouring gasoline behind his car, and setting it on fire. The fire burned him and his dachshund, Millikin, killing his dog and leading to his death in a hospital several hours after firefighters pulled him from his car, mortally injured but still alive. His death has been reported at the Arizona-Coffee blog where he frequently posted. He apparently left no suicide note. It’s very sad that he chose to end his life this way, as well as that of his dog. ...

May 13, 2008 · 4 min

April's Trustee's Sale Notices

<img style=“display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;” src="/images/08AprNTR.jpg" border=“0” alt=““id=“BLOGGER_PHOTO_ID_5196577505470399650” />Based on this chart, Ray Kurzweil would undoubtedly predict that in late 2009 or early 2010, Maricopa County will reach its foreclosure singularity - the moment at which all homes will simultaneously be served notices of foreclosure and beyond which it is impossible to predict what will happen. April’s 6184 notices were yet another unprecedented high. Historical Comments Michael Norton (2008-05-05): Perhaps Doug Adams would call it the "trustee sale event horizon"? ...

May 4, 2008 · 1 min · Einzige

Scammers scamming scammers

Marco Cova looks in some detail at the contents of some phishing scam kits targeting particular banks that were released to the public recently. These sorts of kits, containing web code, are ordinarily sold to scammers, but these were given away free. It wasn’t out of generosity, but part of a larger scam–the code was written using a variety of obfuscation techniques so that the unwary script kiddie who modifies it to send the captured information to their own email address will not receive it. Instead, that information is sent to various email addresses presumably controlled by the distributor of the scammer-scamming phishing kits.

April 8, 2008 · 1 min

Software awards scam

Andy Brice decided to test various download sites to see which ones would give awards (and expect a banner to be posted by the developer’s website with a link back) to a piece of “software” that consisted only of a text file named “awardmestars” containing the words “this program does nothing at all” repeated several times. He submitted it to 1033 sites, of which 218 sites listed it and 421 rejected it. Of those that accepted it, 11% gave it an award (he’s currently at 23 awards): The truth is that many download sites are just electronic dung heaps, using fake awards, dubious SEO and content misappropriated from PAD files in a pathetic attempt to make a few dollars from Google Adwords. Hopefully these bottom-feeders will be put out of business by the continually improving search engines, leaving only the better sites.He notes the following sites which wrote him to say to stop wasting their time, indicating that they actually check submissions: ...

March 26, 2008 · 2 min

Scientology sucks at JavaScript

The Swedish Church of Scientology’s online personality test page has a very interesting test for valid zipcodes, phone numbers, and ages, as TheDailyWTF reports. The same checks could each have been done in a single line with an appropriate regular expression.

March 26, 2008 · 1 min

NSA's data mining and eavesdropping described

The March 10 Wall Street Journal contains a fairly detailed description of the data mining operation being run by the NSA. The program described is more data mining than eavesdropping, though it does involve the collection of transactional data like call detail records for telephone calls, and intercepted Internet data like web search terms and email senders and recipients. Also included is financial transaction data and airline data. I think most of this had already been pieced together, but this is a fairly comprehensive summary in one place. The WSJ story reports that leads generated from the data mining effort are then fed into the Terrorist Surveillance Program, which does warrantless eavesdropping. (An earlier version of this post incorrectly referred to the whole operation as the Terrorist Surveillance Program.) ...

March 12, 2008 · 2 min

Interesting articles in The Economist

A few articles of interest from the last couple of issues of The Economist: February 23, 2008: “Moral thinking," a summary of recent research that sheds light on human moral reasoning processes. Video here. (A related, more in-depth story is Steven Pinker’s “The Moral Instinct” which appeared in The New York Times Magazine on January 13.) March 1, 2008: “Winds of change," a summary of research to use breathalyzer technology to diagnose medical conditions. “Telltale hairs," about new methods of forensics to use hair analysis to identify a person’s location at a given time (based on water consumption–could drinking imported bottled water be used to thwart this?).

March 10, 2008 · 1 min

RateMyCop

RateMyCop.com is a new website that allows you to rate individual police officers on the basis of your interactions with them, on the attributes of authority, fairness, and satisfaction, for which you can rate them poor, average, or good, and leave specific comments about your interactions. The site describes itself like this: Welcome to RATEMYCOP.com, the online watchdog organization serving communities nationwide. RATEMYCOP.com is not affiliated with any government agency; we are an independent, privately managed organization. Our mission is to compile information on cops’ performance and to provide a forum where users can freely share individual accounts. Good, bad or indifferent. Most of all, we would like to hear your stories. Your appreciation and your disapproval. Did you witness a cop doing a good deed, or were you involved in an unfortunate altercation? Tell us about it. Tell others about it. Let it out. Don’t feel intimidated by the badge to remain quiet. While we respect their authority we are also free to question it. You have the right to remain informed.The site has lists of 120,000 individual police officers from 450 departments around the country, which the site obtained directly from police departments, asking only for the names of patrol officers who work with the general public, not undercover officers. There are no photos, addresses, or telephone numbers, only names. The city of Tempe has expressed disapproval and its intention to try to remove this information from the site, according to an ABC 15 News story which claims the site is a danger to officers. Tempe Police Department Officer Tony Miller is quoted in the story raising issues about undercover officers, and the article says that he “feels as though officers like him are scrutinized enough.” The article also states that “Tempe officer Brandon Banks says the department’s chief, human resources and even the city’s prosecutor are looking into the website and fighting it.” I don’t see that they have a case, this information should all be a matter of public record. It seems to me that there is potential for abuse (especially in the form of inaccurate ratings and comments, just as on teacher rating websites), but less so than there is from other kinds of public records about all of us that are published on the web. I disagree with Officer Miller’s opinion that there is already sufficient accountability for police officers; this blog’s previous posts in the “police abuse and corruption” category and the far more numerous and detailed posts from Radley Balko’s The Agitator blog and his article “Overkill” are overwhelming evidence to the contrary. It’s worth noting that the courts have repeatedly ruled that there is no duty of police officers to protect individual members of the public, and many states have statutes which prevent individual officers and departments from being held civilly liable for a failure to provide adequate protection, a fact often used by gun advocates to argue for widespread gun ownership for individual protection (e.g., here, here, and here). The U.S. Supreme Court also eliminated a major protection against police abuse in 2006, when it ruled in Hudson v. Michigan (PDF) that evidence from an illegal no-knock raid need not be excluded from trial, because police officers have entered a new realm of “professionalism” in which they recognize civil liberties and can be trusted to investigate and deter their own abuses. In the wake of such decisions and continuing abuses, a website such as RateMyCop.com seems to me like a good idea. What the site seems to be missing, though, is a way to quickly find officers who have received ratings (very few seem to have any yet), and to sort those in order to find those with favorable or unfavorable ratings. UPDATE (March 12, 2008): Apparently GoDaddy has pulled the plug on RateMyCop.com’s website without notice to the owner, allegedly first for “suspicious activity” and then for exceeding bandwidth limits, and the site is up with a new web hosting provider. It looks like the ratings are now on a single category, and you can see a list of the most-rated and most-recently-rated on the front page. Another feature that would be nice would be a way to allow registered users to rate the raters for reliability, similar to the way Amazon.com book reviews can be rated as helpful or not helpful. That way, ratings could be weighted based on judgments of the reliability of the raters from the user base, and ratings from those with a personal axe to grind could have their weight minimized. Looks like Rackspace has also refused to host ratemycop.com. Interestingly, apparently Gino Sesto of RateMyCop.com was a Bush voter. ...

March 5, 2008 · 4 min

Jeremy Jaynes loses appeal on spamming case

Jeremy Jaynes, the spammer who was convicted and sentenced to nine years in prison in 2003 for violating Virginia’s anti-spam law, has lost his appeal before the Virginia Supreme Court in a 4-3 ruling. Several of the dissents claimed that Virginia’s anti-spam law, which criminalizes unsolicited bulk email with falsified headers, even if it is political or religious in content rather than commercial, is a violation of the First Amendment. The quotations from Justice Elizabeth Lacy and Jaynes’ attorney Thomas M. Wolf both state that the law has diminished everyone’s freedom by criminalizing “bulk anonymous email, even for the purpose of petitioning the government or promoting religion." Both Lacy and Wolf misrepresent the law, which makes it a crime to “Falsify or forge electronic mail transmission information or other routing information in any manner in connection with the transmission of unsolicited bulk electronic mail through or into the computer network of an electronic mail service provider or its subscribers." There is a difference between forging headers and sending anonymous email–the latter does not require the former, and the latter is not prohibited by the law. Jaynes wasn’t just trying to be anonymous–he was engaged in fraud, and falsifying message headers and from addresses to try to avoid the consequences of his criminality. He wasn’t using anonymous remailers to express a political or religious message, and if he had been, he wouldn’t have been able to be charged under this law. UPDATE (September 12, 2008): The Virginia Supreme Court has reversed itself and struck down Virginia’s anti-spam law as unconstitutional, on the grounds that prohibiting false routing information on emails infringes upon the right to anonymous political or religious speech. This is a very bad decision for the reasons I gave above. There are ways to engage in anonymous speech without doing what Jaynes did, falsifying message headers and domain names. The court’s argument that one must falsify headers, IP addresses, and domain names in order to be anonymous is factually incorrect. Anonymity doesn’t require header falsification, it only requires omission of identifying information.

March 1, 2008 · 2 min
Mastodon Verification