Thursday, July 23, 2009

MegaFon Deploys Cisco CRS-1 Routing Platform as Foundation of Next-Generation Mobile Network

SAN JOSE, CA, May 27 (MARKET WIRE) --

http://www.reuters.com/article/pressRelease/idUS132685+27-May-2009+MW20090527


(NASDAQ: CSCO) -- Five years after being introduced, the Cisco(R) CRS-1 Carrier Routing System continues to be deployed by telecommunications service providers as the foundation of their Internet Protocol Next-Generation Networks (IP NGNs). The CRS-1 was recently deployed by Russian mobile operator MegaFon, one of the fastest-growing mobile operators in Europe and Russia's first service provider of 3G global system for mobile communications (GSM).

The Cisco CRS-1 platform was unveiled in May 2004 as a new class of routing system designed to deliver continuous system operation, service flexibility and extended system longevity to service providers. Designed to accommodate the acceleration of video, voice and data traffic on IP NGNs, the Cisco CRS-1 is the first router to scale to more than 90 terabits of bandwidth capacity. It helps enable reliable, large-scale network delivery of high-bandwidth applications, including video on demand, online gaming, multimedia content distribution, real-time interactive services and many others.

Facts:

-- The Cisco CRS-1 platform has been deployed by more than 300 customers in more than 40 countries on all continents except Antarctica.

-- Driven by a greater convergence of networks and applications to facilitate the delivery of video, voice and data services, total worldwide cumulative shipments of this platform have reached more than 3,200. That figure includes 250 multi-chassis configurations at more than 25 service providers. MegaFon is the first service provider in Russia to deploy a multi-chassis CRS-1 platform.

The total current capacity of all Cisco CRS-1 units shipped to date is estimated at 2,919 terabits per second or nearly three petabits-per-second. This capacity is equivalent to that of: -- More than 25,000 users downloading a 2.5-hour high-definition movie in one second.


-- Hosting 250 million simultaneous meetings on a Cisco TelePresence(TM) system. Based on an average of 12 megabits per second required for a Cisco TelePresence System 3000 and considering that each session can accommodate 12 people, the deployed current capacity of the Cisco CRS-1 would be enough to accommodate live Cisco TelePresence sessions with the entire combined populations of China, the European Union, the United States, Russia, Brazil, Saudi Arabia, Japan, Indonesia and Mexico -- (that is, nearly half of the world's population) -- at the same time.



-- Publicly announced Cisco CRS-1 customers to date include AT&T, BT, Cable & Wireless, Comcast, China Telecom (ChinaNet), China Education and Research Network (CERNET), Czech National Research Network (CESNET2), Deutsche Telekom, FairPoint Communications, Free (Iliad Group), Kabel Deutschland, Kazakh Telecom, Korea Telecom, Magyar Telekom, MTS Allstream, MTN, National Institute of Informatics' SuperSINET research network in Japan, Netia, Neuf Cegetel, National LambdaRail, nTelos, Pittsburgh SuperComputing Center (PSC), RAIRomtelecom, SaskTel, Savvis Communications, Sify, Softbank Yahoo! BB, Sprint, Swisscom, Shanghai Telecom, Strato Medien, TeliaSonera, Terremark, Telstra, Verizon Wireless, VTR and XO Communications.

Quotes:

-- "MegaFon is innovative in our approach to growing our customer base and improving our mobile services," said Sergei Soldatenkov, chief executive officer, MegaFon. "We have found that the multi-chassis Cisco CRS-1 platform, with highly secure domain routing, serves as the foundation of our Internet Protocol next-generation network. This gives us confidence in our ability to scale to meet increased traffic and quality demands."

-- "When we introduced the Cisco CRS-1, most industry observers believed we over-engineered a routing platform and made it too powerful for the needs of service providers," said Tony Bates, Cisco senior vice president and general manager, service provider group, and one of the lead developers of the Cisco CRS-1. "Now, no one disputes that the Cisco CRS-1 has been essential in allowing service providers to complete the move from the analog age to the digital age, from the era of the phone to the era of the Internet."

-- Bates added, "Cisco realized early on that Internet-based networks were going to be the platforms of choice to deliver communication, information and entertainment to consumers and businesses worldwide. The Cisco CRS-1's continuing success is evidence that our vision, strategy and execution were all in line with the evolution of the market and the needs of service providers."

-- "Rising demand for broadband, video and mobility continues to propel
Cisco CRS-1 deployments," Bates said. "The same trends that are driving the transformation toward 4G networks are also driving demand for the Cisco ASR 9000 Series Aggregation Services Router, which does for the edge what the Cisco CRS-1 does for the core."


Supporting Resources:


-- Cisco Web Site
-- Cisco Service Provider
-- Cisco CRS-1


Technorati Tags:
Cisco, Carrier Routing System-1, CRS-1, Internet
Protocol Next-Generation Network, IP NGN, Tony Bates, Cisco ASR 9000,
MegaFon

About Cisco
Cisco (NASDAQ: CSCO) is the worldwide leader in networking
that transforms how people connect, communicate and collaborate.
Information about Cisco can be found at http://www.cisco.com. For ongoing news, please go to http://newsroom.cisco.com.

Cisco, the Cisco logo, Cisco Systems, and Cisco TelePresence are
registered trademarks or trademarks of Cisco Systems, Inc. and/or its
affiliates in the United States and certain other countries. All other
trademarks mentioned in this document are the property of their
respective owners. The use of the word partner does not imply a
partnership relationship between Cisco and any other company. This
document is Cisco Public Information.

For direct RSS Feeds of all Cisco news, please visit "News@Cisco" at the
following link:

http://newsroom.cisco.com/dlls/rss.htmlImage Available:
http://www2.marketwire.com/mw/frame_mw?attachid=990074

Image Available: http://www2.marketwire.com/mw/frame_mw?attachid=990071


Cisco Press Contact:
Kevin Petschow
Cisco
(773) 444.5106
kpetscho@cisco.com

Industry Analyst Contact:
Carter Cromwell
Cisco
(408) 526.6914
ccromwel@cisco.com

Investor Relations Contact:
Matt Tractenberg
Cisco
(408) 525.3170
matthew2@cisco.com

Copyright 2009, Market Wire, All rights reserved.

Monday, July 20, 2009

Top 10 Web Attack Vectors in Second Half of 2008

http://securitylabs.websense.com/content/Assets/WSL_ReportQ3Q4FNL.PDF

As Internet users increase, the Web attack vector continues to grow. Web servers are increasingly compromised through persistent cross-site scripting (XSS) and SQL injection as well as DNS cache- poisoning attacks. The Web Application Security Consortium reports that 97 percent of sites it studied continue to be plagued with significant vulnerabilities.
Below are the top ten Web attack vectors over the last six months. Browser vulnerabilities, SQL injection attacks and the increase of social networking vulnerabilities rounded out the top three vectors. This list remains relatively consistent with the previous top-ten Web attack vector list cited
during the first half of 2008.

1. Browser vulnerabilities
2. Rogue antivirus/social engineering
3. SQL injection
4. Malicious Web 2.0 components (e.g. Facebook applications, third-party widgets and gadgets,
banner ads)
5. Adobe Flash vulnerabilities
6. DNS Cache Poisoning and DNS Zone file hijacking
7. ActiveX vulnerabilities
8. RealPlayer vulnerabilities
9. Apple QuickTime vulnerabilities
10. Adobe Acrobat Reader PDF vulnerabilities


Learn How To Hack

Learn How To Hack



Browser vulnerabilities continued to plague unsuspecting users. Opera version 9.5.1 enabled attackers to steal arbitrary samples of data in memory from desktops through specially crafted JavaScript code while vulnerabilities in Firefox provided attackers additional opportunities for spoofing by exploiting alternate names on self-signed certificates.

In August 2008, Digg, MSNBC, Newsweek, and MSN Norway were hit by a series of malicious third-party banner ads, which led visitors to rogue security software sites and hijacked the clipboards of visitors.

One of the vulnerabilities exploited was an integer overflow in Adobe Flash (CVE-2007-0071). That same month, Websense Security Labs discovered that a major Chinese ISP, China Netcom (CNC), had its DNS cache poisoned. Unsuspecting customers were redirected to a malicious site when the hostname in a URL was mistyped.

Thursday, July 16, 2009

US Ignored Warnings of Cyber Attack

Aggregated from: http://www.defensetech.org/archives/cat_cyberwarfare.html




Advance information did not prompt a response.

The U.S. Government now admits they did not properly handle the situation. Sources have revealed that the South Korean government knew in advance that the distributed denial of service (DDoS) attacks that hit multiple web sites of major institutions in South Korea had begun earlier in the United States.

Late last week South Korea's intelligence agency briefed its lawmakers on circumstantial and technical evidence behind their belief that North Korea was behind the recent cyber attacks. Other intelligence sources went as far as to state that Kim Chong Un, the third son of North Korean dictator Kim Jong Il, was the mastermind of the cyber attacks that have hit government computers in the United States, South Korea and other some 14 other countries.

Foreign intelligence sources have also reported that the North Korean government sent a cyber contingent of approximately a dozen people across the northern border into China to conduct some of the operations and that Kim Chong Un actually was in commanded of that unit. Also sources have speculated that North Korean Research and Development Unit (110 or 101) and Cyber Warfare Unit 121 were the primary military units involved in the planning and execution of the DDoS style cyber attack. At least one Republican lawmaker urged President Obama to take retaliatory action (cyber attacks) against North Korea for the cyber attacks launched last week.

Learn How To Hack

Learn How To Hack


Given the extremely limited telecommunication infrastructure (estimated 1.18 million phone lines) and the limited Internet connectivity (given the less than 80,000 broadband connections) a cyber attack would be next to useless. After studying and researching the cyber attacks the following observations are offered.

1. The current U.S. defenses against cyber attack are woefully inadequate against even moderate level attacks as we have just experienced.

2. The fact that these attacks were well-coordinated, lasted as long as they did and were able to bring down a number of sites says more about the state of our defenses than the moderate rated offensive cyber capabilities of North Korea.

3. This clearly shows the need for the international agreement for cyber attack investigation cooperation that has been called for by many cyber warfare experts including me. These attacks were routed/launched through compromised computers in 16 countries.

4. Reports that the Department of Defense was not alerted to the attacks and found out through the media indicate that better coordination between DOD, DHS, DOJ and other government organizations as well as the private sector is critical in times of cyber attack and therefore must be improved and maintained.

5. There are unconfirmed reports for typically reliable sources that a South Korean intelligence agency has obtained documents ordering North Korean army units to start the cyber attack. If true, this could be the smoking gun! Once verified, that would open the way for retaliatory action.

-- Kevin Coleman

Saturday, July 11, 2009

Link for Defense Tech's Cyber-Warfare Archives





Learn How To Hack

Learn How To Hack


Ironically, it is the most technologically advanced country in the world that lacks a coherent national cyberdefense-

Where Is Our Cyber Defense?

By Alexandra Petri

The prolonged assault on American and South Korean websites that began July 4 shows why President Obama declared cyber security a priority of his administration. But it also highlights that, so far, we don’t have a coherent national cyber defense.

Learn How To Hack

Learn How To Hack




The attacks this past weekend targeted a wide array of sites within the public and private sector, from the National Security Agency to NASDAQ to Washington Post Digital. But this is no isolated incident. Literally millions of attacks occur on U.S. systems every day. The past several years have seen a spike in online attacks on government agency sites -- from 5,503 in fiscal year 2006 to 16,843 in 2008. The private sector, too, is continually under attack, with 280 million sets of data compromised last year alone. What is noteworthy about the attacks of the past week is how organized and effective they were -- some sites, such as that of the Department of Transportation, experienced 24-hour outages.

The government is doing something. Currently, the Department of Homeland Security is responsible for securing dot-gov sites and the Department of Defense handles dot-mil, both of which were targeted in the recent assault. And Defense Secretary Gates announced last month the creation of a “cyber command” to handle the Defense Department’s side, to be helmed by the director of the National Security Agency.

But as our defense grows, we need to make sure that whatever system develops is one that respects privacy. Like real war, cyber warfare has a tendency to take civilian casualties, and as the battle wages on, any hard lines between public and private threats will be easy to blur. As happened this weekend, the same attackers can target public and private sites. Collaboration between government and private cyber defenders to anticipate and thwart attacks is key to a successful defense, but there must be a system in place to protect privacy and make certain that the sharing goes both ways -- for instance, an anonymous, secure database where businesses and government entities can share information about ongoing threats and responses.

President Obama can start by appointing a cyber czar who will ensure our cyber defense doesn’t fall into the cracks between government agencies. And as we deal with threats that tread the line between public and private, we need someone in place to ensure transparency and accountability, too, so that it won’t infringe on the privacy we seek to protect.

By Alexandra Petri | July 8, 2009; 3:20 PM ET

Tuesday, July 7, 2009

George Ledin teaches students how to write viruses, and it makes computer-security software firms sick.

The Virus Professor

This Bug Man Is a Pest

By Adam B. Kushner | NEWSWEEK

In a windowless underground computer lab in California, young men are busy cooking up viruses, spam and other plagues of the computer age. Grant Joy runs a program that surreptitiously records every keystroke on his machine, including user names, passwords, and credit-card numbers. And Thomas Fynan floods a bulletin board with huge messages from fake users. Yet Joy and Fynan aren't hackers—they're students in a computer-security class at Sonoma State University. And their professor, George Ledin, has showed them how to penetrate even the best antivirus software.

The companies that make their living fighting viruses aren't happy about what's going on in Ledin's classroom. He has been likened to A.Q. Khan, the Pakistani scientist who sold nuclear technology to North Korea. Managers at some computer-security companies have even vowed not to hire Ledin's students. The computer establishment's scorn may be hyperbolic, but it's understandable. "Malware"—the all-purpose moniker for malicious computer code—is spreading at an exponential rate. A few years ago, security experts tracked about 5,000 new viruses every year. By the end of this year, they expect to see triple that number every week, with most designed for identity theft or spam, says George Kurtz, a senior vice president at antivirus software maker McAfee. "You've got a whole business model built up around malware," he says.

Ledin insists that his students mean no harm, and can't cause any because they work in the computer equivalent of biohazard suits: closed networks from which viruses can't escape. Rather, he's trying to teach students to think like hackers so they can devise antidotes. "Unlike biological viruses, computer viruses are written by a programmer. We want to get into the mindset: how do people learn how to do this?" says Ledin, who was born to Russian parents in Venezuela and trained as a biologist before coming to the United States and getting into computer science. "You can't really have a defense plan if you don't know what the other guy's offense is," says Lincoln Peters, a former Ledin student who now consults for a government defense agency.

That doesn't mean Ledin isn't trying to create a little mischief. His syllabus is partly a veiled attack on McAfee, Symantec and their ilk, whose $100 consumer products he sees as mostly useless. If college students can beat these antivirus programs, he argues, what good are they for the people and businesses spending nearly $5 billion a year on them? Antivirus software makers say Ledin's critique is misleading, and that they are a step ahead of him—and the hackers. "We've changed the game, and viruses have changed in recent years because of the protection we're putting into place," says Zulfikar Ramzan, the technical director of Symantec's security team.

Still, beneath Ledin's critique lies a powerful polemic. Ledin compares the companies' hold over antivirus technology (under the Digital Millennium Copyright Act of 1998, the companies' codes are kept secret) to cryptography decades ago, when the new science of scrambling data was largely controlled by the National Security Agency. Slowly, the government opened the field to universities and companies, and now there are thousands of minds producing encryption that is orders of magnitude more complex than code from just a decade ago. That's why you can safely transmit your credit-card numbers online. "Why should we shy away from learning something that is important to everyone?," Ledin asks. "Yes, you could inflict some damage on society, but you could inflict damage with chemistry and physics, too." He hopes one day to share antivirus techniques. But that would require infrastructure and financial support, which the federal government so far has declined to give. Until then, Ledin will have to live with his reputation as the guy who gave away the secrets to the Internet's bomb.



Learn How To Hack

Learn How To Hack

Federal Web Sites Knocked out by Cyber Attack

Federal agency Web sites knocked out by massive, resilient cyber attack


A widespread and unusually resilient computer attack that began July 4 knocked out the Web sites of several government agencies, including some that are responsible for fighting cyber crime, The Associated Press has learned.

The Treasury Department, Secret Service, Federal Trade Commission and Transportation Department Web sites were all down at varying points over the holiday weekend and into this week, according to officials inside and outside the government. Some of the sites were still experiencing problems Tuesday evening.

Federal government officials refused to publicly discuss any details of the cyber attack, and would only generally acknowledge that it occurred. It was not clear whether other government sites also were attacked.

Others familiar with the outage, which is called a denial of service attack, said that the fact that the government Web sites were still being affected three days after it began signaled an unusually lengthy and sophisticated attack. The officials spoke on condition of anonymity because they were not authorized to speak on the matter.

The Homeland Security Department confirmed that officials had received reports of "malicious Web activity" and they were investigating the matter, but had no further comment. Two government officials acknowledged that the Treasury and Secret Service sites were brought down, and said the agencies were working with their Internet service provider to resolve the problem.

Ben Rushlo, director of Internet technologies at Keynote Systems, called it a "massive outage" and said problems with the Transportation Department site began Saturday and continued until Monday, while the FTC site was down Sunday and Monday.

Keynote Systems is a mobile and Web site monitoring company based in San Mateo, Calif. The company publishes data detailing outages on Web sites, including 40 government sites it watches.

According to Rushlo, the Transportation Web site was "100 percent down" for two days, so that no Internet users could get through to it. The FTC site, meanwhile, started to come back online late Sunday, but even on Tuesday Internet users still were unable to get to the site 70 percent of the time.

Ben Rushlo, director of Internet technologies at Keynote Systems, called it a "massive outage" and said problems with the Transportation Department site began Saturday and continued until Monday, while the FTC site was down Sunday and Monday.

Keynote Systems is a mobile and Web site monitoring company based in San Mateo, Calif. The company publishes data detailing outages on Web sites, including 40 government sites it watches.

According to Rushlo, the Transportation Web site was "100 percent down" for two days, so that no Internet users could get through to it. The FTC site, meanwhile, started to come back online late Sunday, but even on Tuesday Internet users still were unable to get to the site 70 percent of the time.

"This is very strange. You don't see this," he said. "Having something 100 percent down for a 24-hour-plus period is a pretty significant event."

He added that, "The fact that it lasted for so long and that it was so significant in its ability to bring the site down says something about the site's ability to fend off (an attack) or about the severity of the attack."

Denial of service attacks against Web sites are not uncommon, and are usually caused when sites are deluged with Internet traffic so as to effectively take them off-line. Mounting such an attack can be relatively easy using widely available hacking programs, and they can be made far more serious if hackers infect and use thousands of computers tied together into "botnets."

For instance, last summer, in the weeks leading up to the war between Russia and Georgia, Georgian government and corporate Web sites began to see "denial of service" attacks. The Kremlin denied involvement, but a group of independent Western computer experts traced domain names and Web site registration data to conclude that the Russian security and military intelligence agencies were involved.

Documenting cyber attacks against government sites is difficult, and depends heavily on how agencies characterize an incident and how successful or damaging it is.

Government officials routinely say their computers are probed millions of times a day, with many of those being scans that don't trigger any problems. In a June report, the congressional Government Accountability Office said federal agencies reported more than 16,000 threats or incidents last year, roughly three times the amount in 2007. Most of those involved unauthorized access to the system, violations of computer use policies or investigations into potentially harmful incidents.

The Homeland Security Department, meanwhile, says there were 5,499 known breaches of U.S. government computers in 2008, up from 3,928 the previous year, and just 2,172 in 2006.



Learn How To Hack

Learn How To Hack