Showing posts with label computer virus. Show all posts
Showing posts with label computer virus. Show all posts

Tuesday, 7 January 2014

Computer virus


Computer in control room of Monju fast breeder reactor infected with virus



6 January, 2014


In November, Japan’s Nuclear Regulation Authority warned the Japan Atomic Energy Agency that its anti-terrorism measures at the Monju fast-breeder reactor were not sufficient.  The regulatory agency rebuked the JAEA for violating security guidelines meant to protect nuclear materials from terrorism and other malicious attacks.

This week, the operator of the reactor announced that computer hackers may have stolen private data including internal e-mails and training records.
On January 2nd, a server administrator identified that one of the eight computers in the reactor control room had been accessed over 30 times in the last five days after an employee updated free software on the PC on Thursday.
More than 42,000 e-mails and staff training reports were stored on the computer.
Investigators concluded that a virus likely infected the computer during the update and that some of the data was stolen after finding traces of out-bound transmissions.  The requests appeared to have come from a website based in South Korea.
The JAEA is currently investigating how the infection occurred and confirming the data on the computer that could have been accessed.
The JAEA itself has been plagued by problems and scandals related to the Monju reactor, including findings by regulators that regular safety checks had not been performed on over 14,000 different pieces of equipment.
In November of 2012, a computer located at the JAEA headquarters at Tokaimura in Ibaraki Prefecture was also found to be infected with a computer virus.
In May of 2013, the Nuclear Regulation Authority forbid JAEA from restarting the reactor, after it said that the safety culture at the plant had degraded.


Wednesday, 27 November 2013

NSA surveillance

NSA Infects 50,000 Computer Systems Worldwide



26 November, 2013


Dutch newspaper NRC Handelsblad reported it, headlining “NSA infected 50,000 computer networks with malicious software.”

It cited leaked Edward Snowden information. His revelations are the gift that keeps on giving. Activists representing him keep important information coming.
It’s vital. Everyone needs to know. Unchecked NSA spying threatens fundamental freedoms. They’re fast disappearing.
Their on the chopping block for elimination. Police state lawlessness runs America. It’s too great a threat to ignore.
According to NRC, NSA hacked over 50,000 computer networks. It installed malware. It facilitates surveillance.
It’s “designed to steal sensitive information.” Snowden provided documents prove it. A 2012 management presentation showed NSA uses “Computer Network Exploitation (CNE) in more than 50,000 locations.”
It secretly infiltrates computer systems through malware. Belgian telecom provider Belgacom was hacked.
Britain’s Government Communications Headquarters (GCHQ) installed malware in its network. It did so to gain access to its customers’ telephone and data traffic.
It did it through a false Linkedin page. It was done through unwitting company employees.
NSA has a “special department.” It has over 1,000 military and civilian hackers, intelligence analysts, targeting specialists, computer hardware and software designers, and electrical engineers.
It’s top secret. It’s called the Office of Tailored Access Operations (TAO). It identifies computer systems and supporting telecommunications networks to attack.
It successfully penetrated Chinese computer and telecom systems for around 15 years. It does the same thing globally.
Most NSA employees and officials know little or nothing about TAO. Its operations are extraordinarily sensitive. Only those needing to know are kept informed.
Special security clearances are required to gain access to its top secret work spaces. Armed guards keep others out.
Entering requires a correct six digit code. Retinal scanner checks are used. TAO targets foreign computer systems.
It collects intelligence by hacking, cracking passwords, compromising computer security systems, stealing hard drive data, and copying all subsequent emails and text messages.
NSA calls doing so Computer Network Exploitation (CNE). In October 2012, Obama issued a secret presidential directive. It selected overseas targets for cyber attacks.
His Offensive Cyber Effects Operations (OCEO) claimed to “offer unique and unconventional capabilities to advance US national objectives around the world with little or no warning to the adversary or target and with potential effects ranging from subtle to severely damaging.”
Washington “identif(ies) potential targets of national importance where OCEO can offer a favorable balance of effectiveness and risk as compared with other instruments of national power.”
It operates domestically the same way. NSA director Keith Alexander heads US Cyber Command (Cybercom). He’s waging global cyberwar.
US Cyber Command (USCYBERCOM) has full operational control. It’s a cyber hit squad. It’s part of the US Strategic Command.
Rules of engagement are classified. Anything goes is policy. Cyber-warriors are freewheeling. They operate globally. Cyber-preemption reflects greater police state power.
TAO personnel penetrate, steal, damage, destroy or otherwise compromise targeted sites. It’s perhaps the most important component of NSA’s Signal Intelligence (SIGINT) Directorate.
NRC said TAO operations installed about 20,000 “implants” by early 2008. By mid-2012, they “more than doubled to 50,000.”
NSA prioritizes cyber operations. “Computer hacks are relatively inexpensive.” They give NSA information otherwise not available.
Malware “can remain active for years without” detection. ” ‘Sleeper cells’ can be controlled remotely and be turned on and off at will.”
Implants are digital sleeper cells. A “push of a button” activates them. NSA has been conducting these type operations since the late 1990s.
Dutch intelligence services AIVD and MIVD “displayed interest in hacking.” In early 2013, a Joint Cyber Unit (JSCU) was created.
It’s an inter-agency operation. It uses experts with a range of IT skills. It doesn’t go as far as NSA. Dutch law prohibits it. For how long remains to be seen.
Last August, the Washington Post headlined “The NSA has its own team of elite hackers.” It discussed TAO operations.
It may “have had something to do with (developing) Stuxnet and Flame malware program.” Washington and Israel were involved.
In spring 2010, Iranian intelligence discovered Stuxnet malware contamination. It infected its Bushehr nuclear facility. At the time, operations were halted indefinitely.
Israel was blamed. So was Washington. Had the facility gone online infected, Iran’s entire electrical power grid could have been shut down.
Flame is a more destructive virus. Internet security experts say it’s 20 times more harmful than Stuxnet. Iran’s military-industrial complex is targeted.
So is its nuclear program. Maximum disruption is intended. Whether plans to do so continue remains to be seen. Iran is alerted to the possibility.
Leaksource calls itself the “#1 source for leaks around the world.” Last August, it headlined “Codename GENIE: NSA to Control 85,000 ‘Implants’ in Strategically Chosen Machines Around the World by Year End,” saying:
According to “top secret documents” the Washington Post obtained, “US intelligence services carried out 231 offensive cyber-operations in 2011.”
Doing so represents “the leading edge of a clandestine campaign that embraces the Internet as a theater of spying, sabotage and war.”
Snowden leaked information revealed it. GENIE involves using computer specialists. They break into foreign networks. They do so to “put (them) under surreptitious US control.”
Budget documents say the $652 million project has placed ‘covert implants,’ sophisticated malware transmitted from far away, in computers, routers and firewalls on tens of thousands of machines every year, with plans to expand those numbers into the millions,” said Leaksource.
GENIE’s next phase involves an automated online system code-named “TURBINE.” It’s able to potentially manage “millions of implants.”
It elevates intelligence gathering to a higher level. It lets it engage in widespread “active attack(s).”
Teams of FBI, CIA, and Cyber Command operatives work at NSA’s Remote Operations Center (ROC).
Their missions overlap. So does NSA’s National Threat Operations Center. It focuses on cyberdefense.
Snowden was involved as a Booz Allen Hamilton contractor. He learned NSA’s best hacking techniques.
The agency designs most of its implants. It spends millions of dollars annually on “additional covert” “software vulnerabilities” purchases.
It gets them from “private malware vendors.” They represent a growing source. They’re largely European based.
China, Russia, Iran and North Korea are called the “most challenging targets” to penetrate.
Other prioritized countries include so-called terrorist safe havens. They include Afghanistan, Pakistan, Yemen, Iraq and Somalia.
NSA’s goal is sweeping. It wants to revolutionize data gathering. It wants to access “anyone, anywhere, anytime.”
It intends to “identify new access, collection and exploitation methods by leveraging global business trends in data and communication services.”
It wants total information control worldwide. It wants to go where no previous spy agency went before. It wants no operational restraints. It intends to keep doing whatever it wants.
Congress is a willing facilitator. Fake fix legislation facilitates NSA lawlessness. It codifies collecting phone records of hundreds of millions of Americans.
It permits the same thing online. It’s already out of committee. It’s heading for Senate passage.
Obama will sign into law whatever Congress sends him. He supports mass surveillance.
He’s waging war on fundamental freedoms. Police state lawlessness is official US policy. Obama is its leading exponent.

Stephen Lendman lives in Chicago. He can be reached at lendmanstephen@sbcglobal.net
His new book is titled “Banker Occupation: Waging Financial War on Humanity.”
Visit his blog site at sjlendman.blogspot.com. 
Listen to cutting-edge discussions with distinguished guests on the Progressive Radio News Hour on the Progressive Radio Network.
It airs Fridays at 10AM US Central time and Saturdays and Sundays at noon. All programs are archived for easy listening.


Wednesday, 26 December 2012

The Middle East


Iran 'fends off new Stuxnet cyber attack'
A power plant and other industries in southern Iran have been targeted by the Stuxnet computer worm, an Iranian civil defence official says.





BBC,
25 Decembr, 2012

But the cyber attack has been successfully rebuffed and prevented from spreading, Iranian media report.

Iran's nuclear enrichment efforts were hit hard in 2010 by the Stuxnet worm, which was also blamed for problems at industrial plants and factories.

Tehran accused Israel and the US of planting the malware.

Provincial civil defence chief Ali Akbar Akhavan said Iranian industry was constantly being targeted by "enemy cyber attacks" and companies in Hormozgan province had recently been infiltrated, the semi-official Isna news agency reported.

"The Bandar Abbas electricity supply company has come under cyber attack," he told a news conference. "But we were able to prevent its expansion owing to our timely measures and the co-operation of skilled hackers."


The Bandar Abbas plant, on Iran's southern coast in the Strait of Hormuz, is said to supply power to neighbouring provinces as well as Hormozgan.

Spyware

Iran has regularly claimed success in defeating computer viruses, such as Stuxnet and Flame, which have affected its industries.

In April, a malware attack on Iran's oil ministry and national oil company forced the government to disconnect key oil facilities, including the Kharg Island oil terminal that handles most of Tehran's exports.

Late last year, Iran said some of its computer systems were infected by the Duqu spyware which was believed to have been designed to steal data to help launch further cyber attacks.

The attacks have affected its energy exports as well as its controversial uranium enrichment programme, which Western countries suspect is aimed at constructing nuclear weapons. Tehran insists it is solely for peaceful purposes.


The biggest cyber attack so far was from the Stuxnet worm, believed to be the first known virus specifically targeted at infrastructure such as power stations.

In 2010, Iran accused the West of trying to disrupt its nuclear facilities with the Stuxnet worm.

Researchers estimated that five industrial processing organisations in Iran were hit repeatedly between June 2009 and April 2010 by the worm which they believed had been created by a "nation state" in the West.

Iran said centrifuges used in uranium enrichment had been sabotaged and the UN nuclear watchdog said the enrichment programme had been temporarily brought to a halt.

Reports suggested that the worm had infected the personal computers of staff at Iran's first nuclear power station at Bushehr.

In September this year, Israeli Prime Minister Benjamin Netanyahu told the United Nations General Assembly that time was running out to stop Tehran having enough enriched uranium to build a nuclear bomb.

US President Barack Obama has said the US will do "what we must" to stop Iran acquiring nuclear weapons.


Israel, Like US, Doubts Syrian Rebels’ ‘Poison Gas’ Claims


No Real Evidence for Rebel Allegations


25 December, 2012

Israeli Vice Premier Moshe Ya’alon, seen as one of a handful of front-runners for the Defense Ministry post after the January election, has added more doubts to the Syrian rebels’ claims of the regime using “poison gas,” saying there was no “confirmation or proof” for the allegation.


The opposition has an interest in drawing in international military intervention,” Ya’alon added. The US has also said they doubt the rebels’ claims were authentic, noting several inconsistencies in the story.

The Syrian opposition claimed the attack was in Homs and that six rebel fighters had died after inhaling “poison gas” on the front line. Ya’alon said that from the photos released “it could be other things,” but did not elaborate.


The Assad government has repeatedly ruled out using chemical or biological weapons for its internal fighting, saying those weapons are exclusively meant as a foil against foreign invasion. The Obama Administration’s repeated threats to attack if such weapons were used, however, has added a great deal of incentive into the rebels selling that narrative.

Syrian Army: Rebels Massacred Civilians in Hama Province

Claims Factions Aimed at Covering for Losses in Region



25 December, 2012

In a statement released today on Syrian state media, the Syrian Army general command claimed that rebel forces have attacked several towns in Hama Province in recent days and accused them of massacre civilians in some of them
.

The army statement was light on details but attributed the incidents to rebel “losses” in the area, claiming that the groups were desperate to make up for their losses by capturing the towns, and had turned on the residents.
It isn’t clear what losses the statement is referring to, but the rebels do appear to have moved against towns like Maan and al-Tleisia with Alawite populations, accusing those towns of housing the army and hindering rebel advances against the highway, which would give them access to a supply route through Turkey.


Though the province is majority Sunni and home to several rebel factions, Hama is also home to a number of Alawite and Christian villages and towns, and rebels have argued that many of those will have to be conquered to prevent the populations aiding the regime.




Saturday, 10 November 2012

Cyber warfare


Stuxnet goes out of control: Chevron infected by anti-Iranian virus, others could be next
America’s cyberwar is already seeing collateral damage, and it’s hitting the country’s own billion-dollar companies. Oil giants Chevron say the Stuxnet computer virus made by the US to target Iran infected their systems as well.


RT,
9 Novemberl, 2012

America’s cyberwar is already seeing collateral damage, and it’s hitting the country’s own billion-dollar companies. Oil giants Chevron say the Stuxnet computer virus made by the US to target Iran infected their systems as well.

California-based Chevron, a Fortune 500 company that’s among the biggest corporations in the world, admits this week that they discovered the Stuxnet worm on their systems back in 2010. Up until now, Chevron managed to make their finding a well-kept secret, and their disclosure published by the Wall Street Journal on Thursday marks the first time a US company has come clean about being infected by the virus intended for Iran’s nuclear enrichment program. Mark Koelmel of the company’s earth sciences department says that they are likely to not be the last, though.

We’re finding it in our systems and so are other companies,” says Koelmel. “So now we have to deal with this.”

Koelmel claims that the virus did not have any adverse effects on his company, which generated a quarter of a trillion dollars in revenue during 2011. As soon as Chevron identified the infection, it was taken care of immediately, he says. Other accidental targets might not be so lucky though, and the computer worm’s complex coding means it might be a while before anyone else becomes aware of the damage.
 
I don’t think the US government even realized how far it had spread,” Koelmel adds.
Discovered in 2010, the Stuxnet worm was reported with all but certainty to be the creation of the United States, perhaps with the assistance of Israel, to set back Iran’s nuclear enrichment program as a preemptive measure against an eventual war. Only as recently as this June, however, American officials with direct knowledge of the worm went public with Uncle Sam’s involvement.
 
In a June 2012 article published by The New York Times, government agents with direct knowledge of Stuxnet claimed that first President George W. Bush, then Barack Obama, oversaw the deployment of the worm as part of a well-crafted cyberassault on Iran. Coupled with another malicious program named Flame and perhaps many more, Stuxnet was waged against Iran as part of an initiative given the codename “Olympic Games.” Rather than solely stealing intelligence through use of computer coding, the endeavor was believed to be the first cyberattack that intended to cause actual hard damage.


Previous cyberattacks had effects limited to other computers,” Michael Hayden, the former chief of the CIA, explained to the Times earlier this year. “This is the first attack of a major nature in which a cyberattack was used to effect physical destruction.”

On the record, the federal government maintains ignorance on the subject of Stuxnet. With American companies perhaps soon coming out of the woodwork to discuss how they were hit, though, the White House may have to finally admit that they’ve had direct involvement.

After the Times published their expose in June, Senator Dianne Feinstein, chairwoman of Intelligence Committee, called for an investigation to track down how the media was first made aware of America’s involvement in Olympic Games.
 
"I am deeply disturbed by the continuing leaks of classified information to the media, most recently regarding alleged cyber efforts targeting Iran's nuclear program,” Feinstein said through a statement at the time. “I made it clear that disclosures of this type endanger American lives and undermine America's national security."


When Feinstein spoke to DC’s The Hill newspaper, she said, "the leak about the attack on Iran's nuclear program could 'to some extent' provide justification for copycat attacks against the United States." According to the chairwoman,"This is like an avalanche. It is very detrimental and, candidly, I found it very concerning. There's no question that this kind of thing hurts our country."


Just last month, a shadowy Iranian-based hacking group called The Qassam Cyber Fighters took credit for launching a cyberattack on the servers of Capital One Financial Corp. and BB&T Corp., two of the biggest names in the American banking industry. Days earlier, Google informed some of its American users that they may be targeted in a state-sponsored cyberattack from abroad, and computer experts insist that these assaults will only intensify over time.


We absolutely have seen more activity from the Middle East, and in particular Iran has been increasingly active as they build up their cyber capabilities,” CrowdStrike Security President George Kurtz told the Times.

Speaking of the accidental impact Stuxnet could soon have in the US, Chevron’s Koelmel tells the Journal, "I think the downside of what they did is going to be far worse than what they actually accomplished.”


Tuesday, 18 September 2012

US government behind computer viruses


US Government Linked To Three New Computer Viruses
Researchers have found evidence suggesting that the United States may have developed three previously unknown computer viruses for use in espionage operations or cyber warfare.


17 Sepetmber, 2012



The findings are likely to bolster a growing view that the U.S. government is using cyber technology more widely than previously believed to further its interests in the Middle East. The United States has already been linked to the Stuxnet Trojan that attacked Iran's nuclear program in 2010 and the sophisticated Flame cyber surveillance tool that was uncovered in May.

Anti-virus software makers Symantec Corp of the United States and Kaspersky Lab of Russia disclosed on Monday that they have found evidence that Flame's operators may have also worked with three other viruses that have yet to be discovered.

The two security firms, which conducted their analyses separately, declined to comment on who was behind Flame. But current and former Western national security officials have told Reuters that the United States played a role in creating Flame. The Washington Post has reported that Israel was also involved.

Current and former U.S. government sources also told Reuters that the United States was behind Stuxnet. Kaspersky and Symantec linked Stuxnet to Flame in June, saying that part of the Flame program is nearly identical to code found in a 2009 version of Stuxnet.

For now, the two firms know very little about the newly identified viruses, except that one of them is currently deployed in the Middle East. They are not sure what the malicious software was designed to do. "It could be anything," said Costin Raiu, director of Kaspersky Lab's Global Research and Analysis Team.


"Newsforyou"


Kaspersky and Symantec released their findings in reports describing analysis of "command and control" servers used to communicate with and control computers infected with Flame.

Researchers from both firms said the Flame operation was managed using a piece of software named "Newsforyou" that was built by a team of four software developers starting in 2006.

It was designed to look like a common program for managing content on websites, which was likely done in a bid to disguise its real purpose from hosting providers or investigators so that the operation would not be compromised, Kaspersky said in its report.

Newsforyou handled four types of malicious software: Flame and programs code-named SP, SPE and IP, according to both firms. Neither firm has obtained samples of the other three pieces of malware.

Kaspersky Lab said it believes that SP, SPE and IP were espionage or sabotage tools separate from Flame. Symantec said it was not sure if they were simply variations of Flame or completely different pieces of software.
"We know that it is definitely out there. We just can't figure out a way to actually get our hands on it. We are trying," Symantec researcher Vikram Thakur said in an interview.

About a dozen computers in Iran and Lebanon that are infected with one of the newly identified pieces of malware are trying to communicate with command and control servers, according to Kaspersky Lab.

The researchers found a large cache of data on one of the command and control servers, but cannot analyze it because it is encrypted using a password that they said would be virtually impossible to crack.

They believe that it was encrypted so heavily because the people coordinating the attack did not want the workers using the Newsforyou program to be able to read potentially sensitive information.

"This approach to uploading packages and downloading data fits the profile of military and/or intelligence operations," Symantec said in its report.

Saturday, 1 September 2012

State-sponsored cyber warfare


State-Sponsored Cyber Espionage Projects Now Prevalent, Say Experts
At least four government-sponsored programmes to deploy cyber-espionage software like the Flame, Duqu and Stuxnet software – the latter used against computers in Iran – are in progress around the world, according to sources in the intelligence and computer communities.



31 August, 2012

Computer security experts say privately that the number of projects deployed is actually much higher, and that the systems have been under development since at least 1996, when the internet had barely begun its transition from a US government and academic network to an international and public one.
"There are a lot of countries that now have these systems. Every Middle Eastern country and all the states now known as the 'Stans' [Pakistan and the former satellite states of the Soviet Union] have them", said another expert with close links to the UK intelligence agencies and who is actively engaged in combating the software.
A former military officer based in London, he declined to be named on security grounds. "Every nation now has an armoury; whether well-stocked or not depends on their resources," he said. "They have a suite of weapons and another for intelligence gathering. Most of them are big players and their suites of tools all have different functions. Some are crude and blunt, some are very stealthy. Some have the ability to attack and they are built for that purpose," the expert said.
In the past year the discovery of the Stuxnet virus – and subsequently of the Flame, Duqu and most recently Gauss malware – has brought the issue of state-sponsored cyberwarfare into sharp focus. Stuxnet was written jointly by the US and Israel and tested in Israel, according to authoritative reports, and performed the equivalent of a precision cyber attack to disrupt Iran's uranium refining systems – an attack which would have been impossible by conventional means.
Suspicions that intelligence agencies have been developing such a capability for a long time were confirmed by a computer expert who has worked with a western intelligence agency.
"Work was done in 1996 on pixel call-back software," he said. "It was used to infect websites and then track where people were coming from and then infect their machines and pass information back about them." The software worked by including a single pixel which linked to a web address controlled by the agency in an otherwise innocuous web page. If access by a target computer was detected, the agency could send malware to infect the machine.
"It was the basis of the work that we are seeing now," said the expert, adding that the mechanisms developed then found their way into the advertising industry — where "web bugs" became infamous as means of tracking users.
"They were a sort of cookie before people had even thought of them," said the man, who worked to develop the bugging programs to combat online criminals and potential terrorists. He says many of the programs now used by the advertising industry can be reverse-engineered to serve a similar function.
The discovery of the Flame virus caused a furore among the technology community when it was found that the 20-megabyte program – unusually large for a virus – had been specifically designed as a highly targeted industrial espionage tool.
Flame, which was first found by Kaspersky Labs, was specifically targeted at the Middle East and had been deliberately built to work for a limited amount of time in a specific geographical area. The virus works by turning over control of a computer to the system controlling it, and become both a remote listening device and information forwarding mechanism.
The Kaspersky researchers say that the Flame virus shared similar components and telltale programming to the Stuxnet virus, which the Iranian government has blamed for the damage caused to its nuclear enrichment facility at Nantanz. That caused the facility's centrifuges to behave erratically and effectively sabotaged the Iranian nuclear programme, according to some experts, for between five and 10 years.
Computer security companies working on both viruses have suggested that Flame was possibly an earlier system designed to collect data for the Stuxnet attack.
Using parts of the same software for both made sense as Flame would have already penetrated part of the target to obtain the information needed, and so the payload could be guaranteed a way through.
In the beginning of July, Indian officials announced that the headquarters of the Indian naval command had been penetrated by Chinese hackers who had used infected USB keys to smuggle an espionage virus onto its computers. This had occured at the same time as the Indian Navy's first nuclear submarine, INS Arihant, was undergoing trials at the facility.
The Stuxnet virus also deployed infected USB keys as part of the method used to penetrate the Nantanz facility, and many similarities have been drawn between the attack on the Indian naval headquarters and Stuxnet.
"I am not surprised that we are seeing this," says Professor Andrew Blyth, head of the University of Glamorgan's Information Security Research Group, one of the GCHQ accredited centres of excellence.
"It takes around £1m to develop a good piece of malware like this. We don't talk about that because it's so highly classified. I am surprised why, post-Stuxnet, people seem to be so shocked. We are in an information age and that has disrupted our world. There's an irony to that it's taken 60 years for Iran to try to develop a [nuclear] bomb, and two years for so many people to develop a cyber weapon."
One reason, according to a former police officer now working in the computer forensics industry, is because the new espionage tools are being developed relatively easily out of innocent components. Like the anonymous expert, he says internet advertising components have provided convenient covers for espionage tools.
"We have seen three programs that are like the Transformers film franchise. They look to all intents and purposes like a genuine computer program but will develop other functions the moment that they get to where they are meant to be.
"We have also seen another program which is a TCP/IP worm that breaks into a number of different pieces like the melting alloy robot in Terminator. It attaches itself to TCP/IP packets so that it can get through the security systems and then reassembles itself on the other side."
But according to Commodore Patrick Tyrrell, who wrote the first paper warning the UK Government of the threat of an information war in 1996, the rapid development of cyber weaponry was an inevitability.
"There is now the ability for a lot of countries to do this. Once the genie was out of the bottle with Stuxnet then it was always going to be a case of we must have our own variant or we will get left behind.
"I think what people are missing is military theory. Sun Tzu, the ancient Chinese military general, said that 'to subdue the enemy without fighting is the essence of skill', and [Carl von] Clausewitz said 'war is the continuation of policy by other means', and cyberspace is perfect for those ideas. It allows you to do something better with another tool," said Tyrrell, adding that the new developments meant that these weapons offer the opportunity for a different conflict over information assets.
That point is underlined by Graham Wright, a former RAF Jaguar pilot, who until recently worked as the deputy head of cyber at the Cabinet Office. "I think that people are badly obscuring this debate by using the word 'war'," he comments. "There is a difference between warfare and war and I think people need to subject this to the test of does it look and feel like war? The only time you are at war is when you can see the intent of the individual.
"I think that we may be getting closer to the boundaries and the development of capability is something that we need to counter, but talking of war is exaggerated."
It's a distinction many agree with, pointing to the Cabinet Office-sponsored report into intellectual property theft which claimed the UK is losing £27bn a year to foreign powers – a figure some observers say errs on the low side.
"A new industry has been generated in information theft that was not there a year ago. These are not tanks they are scouting systems and they are collecting information," said Mark Raeburn, CEO of Context, a company specialising in protecting against cyber espionage. It all depends on what use you put that information to."


Pete Warren is chairman and founder of the Cyber Research Security Institute