近期网络事件和对武装部队可能产生的影响#7

ID:25588

大小:0.20 MB

页数:6页

时间:2022-12-01

金币:15

上传者:战必胜
Recent Cyber Events and Possible
Implications for Armed Forces
#7 November 2020
About this paper
This paper is the collaborative view of NATO CCDCOE researchers highlighting the potential effects
on the military of current events and of developments in cyberspace during the previous month,
based on publicly available information. It does not set out to be exhaustive. While the authors have
made every effort to describe events from a perspective relevant to NATO and partner nations, there
may be national and regional differences which this paper does not address.
The authors of this paper are independent researchers at the NATO CCDCOE; they do not represent
NATO, nor does this paper reflect NATO’s position. The aim of the paper is not to replace information
about vulnerabilities and incidents provided by CSIRTs and providers of CIS products and services.
1. Targeted threats against the
military and national security
Cyber conflict in Nagorno-Karabakh
‘It’s the worst outbreak of violence related to
Nagorno-Karabakh since Armenia and
Azerbaijan, two former Soviet republics,
fought a war over the enclave in the 1990s.
And this time, hacking has come with the
fighting.’ (CyberScoop, 6 October 2020)
Tensions over the territory of Nagorno-
Karabakh are decades old. Recently the
situation has flared up into violent conflict. As
is commonplace in the modern era, spillover
to cyberattacks and information campaigns
from both sides accompany kinetic action. In
most cases, it is related to defacing internet
pages and supporting information operations.
1
Attacks targeted public and private institutions
in the energy industry.
2
Sophisticated cyberattacks have been
employed in this conflict. One example is
PoetRAT malware which targets government
and critical infrastructure sectors. According to
Cisco Talos, actors have modified PoetRAT
malware, showing increased capacity and
maturity. PoetRAT was reportedly used
1
BBC: Nagorno-Karabakh: The Armenian-Azeri
‘information wars’
2
Cisco Talos Blog: PoetRAT: Python RAT
uses COVID-19 lures to target Azerbaijan
public and private sectors
against Azerbaijan previously and continue
during the current campaign. New versions of
PoetRAT are said to target the Azerbaijani
public sector by using malicious Microsoft
Word documents.
3
This allows targeting
through spear-phishing specific individuals to
collect intelligence. Overall, the campaigns
using PoetRAT seem to be efficient and to
have given the cyber actors access to
sensitive information.
What it means:
1. Cyber operations are part and parcel of kinetic
military campaigns. Their tactical use is still in
its infancy, while its use for strategic and
operational objectives is real and promising.
2. If proper tools for malicious activity are
employed, it will be easier and quicker to use
them within military campaigns. It also shows
that a cyber campaign could be employed
quicker and more efficiently to produce an
effect.
3. Recoding of malware is constant and follows
the KISS principle ‘keep it simple, stupid’. A
campaign requires a thorough analysis of the
target and an understanding of the cognitive
domain to influence specified targets.
3
Cisco Talos Blog: PoetRAT: Malware targeting
public and private sector in Azerbaijan evolves
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭