Security Beat 

Expert Warns of Nexus Between Cybercriminals and Terrorists 

10  2,010 

By Stew Magnuson 

Terrorists who want to stage a cyberattack against the United States may lean on criminal networks to assist them, a former Defense Department official said.

Steven Bucci, former deputy assistant secretary for homeland defense, said conventional wisdom states that terrorist organizations aren’t interested in cyberattacks because they don’t make for spectacular, bloody video footage that can be used for propaganda.

He disagrees. Imagine infiltrating the computers of a chemical plant, and ordering them to “open up all the valves,” he said at a Heritage Foundation talk. Such an attack could rival the Bhopal disaster in India, and deliver the effects groups such as al-Qaida are looking for.

“That’s pretty darn spectacular, and pretty elegant from an attack standpoint. You don’t really need that big a capability,” he said.

A full-scale cyberwar between nations is possible, but unlikely, Bucci said. It’s akin to nuclear war where there was mutually assured destruction. “The most likely threat in my mind is a cyberterrorist attack enabled by cybercriminal capabilities,” Bucci said.

Such an operation would require more than a single hacker sitting at a computer, but not a whole lot more. “It does not require an entire cyberarmy to pull off one of these events.”

It may require the expertise found in cybercriminal networks, though.

Bucci predicted a nexus between terrorists and the criminal underworld. “They are more than happy to work with anybody who has the money.”

Such cooperation may have already happened when there was a massive denial-of-service attack on the Israeli civil defense system as forces prepared to invade the Gaza Strip last year.

While there is no direct evidence that such a cooperative agreement occurred, the attack had all the hallmarks of the Estonia denial-of-service attack in 2007, which involved a criminal network, he said.

Alejandra Bolanos, a National Defense University assistant professor of international security studies, predicted state-actors seeking to attack or infiltrate networks will use these criminal organizations as a proxy. That way, they can have “plausible deniability” when the victim is searching for those responsible for the network intrusions, she said.

Reader Comments

Re: Expert Warns of Nexus Between Cybercriminals and Terrorists

It's refreshing to see some realism make it to the press, any press. It's nice gentle little wake up call, but it covers less than half the rapidly evolving problem. Would you like a column or article on the whole scope of the real problem?

Michael Monterey on 09/27/2010 at 15:58

Submit Your Reader's Comment Below
*Name
 
*eMail
 
The content of this field is kept private and will not be shown publicly.
*Comments
 
 
Refresh
Please enter the text displayed in the image.
The picture contains 6 characters.
*Characters
  
*Legal Notice

NDIA is not responsible for screening, policing, editing, or monitoring your or another user's postings and encourages all of its users to use reasonable discretion and caution in evaluating or reviewing any posting. Moreover, and except as provided below with respect to NDIA's right and ability to delete or remove a posting (or any part thereof), NDIA does not endorse, oppose, or edit any opinion or information provided by you or another user and does not make any representation with respect to, nor does it endorse the accuracy, completeness, timeliness, or reliability of any advice, opinion, statement, or other material displayed, uploaded, or distributed by you or any other user. Nevertheless, NDIA reserves the right to delete or take other action with respect to postings (or parts thereof) that NDIA believes in good faith violate this Legal Notice and/or are potentially harmful or unlawful. If you violate this Legal Notice, NDIA may, in its sole discretion, delete the unacceptable content from your posting, remove or delete the posting in its entirety, issue you a warning, and/or terminate your use of the NDIA site. Moreover, it is a policy of NDIA to take appropriate actions under the Digital Millennium Copyright Act and other applicable intellectual property laws. If you become aware of postings that violate these rules regarding acceptable behavior or content, you may contact NDIA at 703.522.1820.

 
 
  Bookmark and Share