7 février 2019 | Local, C4ISR, Sécurité

Cyber-warfare could be entering a new and alarming phase, ex-CIA analyst tells MPs

Murray Brewster · CBC News

Online attacks on Canada's financial system could become far more destructive as more militaries around the globe get involved in cyber operations, a security expert and former CIA analyst told a House of Commons committee Wednesday.

Christopher Porter, the chief intelligence strategist for the cyber security company Fireeye, Inc., testified that as NATO countries share their expertise on how to defend against and defeat online threats, "major cyber powers outside the alliance" will likely do the same.

The consequences, he said, could be dire.

The West's imposition of sanctions on "some countries" has in the past been met with denial-of-service attacks on financial services websites, he said — attacks that have only been disruptive.

"In the future, they may respond with destructive attacks aimed at permanently disabling financial services or altering data in ways that undermine trust in the global financial system, such as by delaying or impairing the trustworthy settlement of collateralized government debt," Porter said.

"For countries sufficiently sanctioned and therefore increasingly outside that financial system anyway, there is little incentive not to do so during a confrontation."

Where the threat comes from

He did not name the countries he believes pose an imminent threat, but North Korea, Russia and Iran are widely known to possess sophisticated cyber capabilities and — in some cases — loose associations with groups of private hackers.

The Commons public safety committee is studying security in the financial sector. Wednesday's hearing focused on online threats.

"I am gravely concerned about the militarization of cyber operations," said Porter, who spent nearly nine years at the CIA and served as the cyber threat intelligence briefer to White House National Security Council staff.

"(The) proliferation of cutting-edge offensive cyber power, combined with an increased willingness to use it with minimal blowback and spiraling distrust, has set the stage for more disruptive and destabilizing cyber events, possibly in the near future."

The cyber espionage threat Canada faces is still "moderate," said Porter, but his organization has noted at least 10 groups from China, Russia and Iran that have targeted Canada in the last few years.

His grim assessment was echoed by another private sector expert who appeared before the committee. Jonathan Reiber, head of cybersecurity at Illumio, an American business data center, said most of Washington's efforts to get everyone to step back from the cyber-warfare brink have gone nowhere.

He also suggested that online militarization was inevitable. "Adversaries have escalated in cyberspace, despite U.S. efforts at deterrence," he said.

The United States, Canada and other western nations must take a more aggressive stance to deter cyber aggression by "defending forward" and conducting offensive cyber operations to disrupt hacking, Reiber said.

The Liberal government's defence policy, released in June 2017, gave the Canadian military permission to conduct those kinds of operations.

"Nation states have the right to defend themselves in cyberspace just as they do in other domains," Reiber said.

Mutual defence

Determining the point at which a online attack provokes a real world military response is something that NATO and many western countries have been grappling with over the last five years.

The alliance has a mutual assistance clause, known as Article 5, which requires NATO nations to aid an ally under attack.

Liberal MP John McKay, head of the public safety committee, asked whether NATO's decision-making mechanisms are nimble enough to keep pace with cyber attacks.

Porter said he believes the system is sound. The challenge, he said, is to get all allies on the same page.

"I think a bigger issue is who is going to call for such a response and under what circumstances," he said. "In the States, I think, you're always waiting for a cyber Pearl Harbour destructive event."

Such a massive attack is still less likely than a series of smaller events, he said, "a death by a thousand cuts" that might not rise to the level of provoking allies.

https://www.cbc.ca/news/politics/cyber-warfare-could-be-entering-a-new-and-alarming-phase-ex-cia-analyst-tells-mps-1.5008956

Sur le même sujet

  • Canadian Army credits Liberals for TAPV instead of Conservatives - new roles for vehicle added

    14 février 2019 | Local, Terrestre

    Canadian Army credits Liberals for TAPV instead of Conservatives - new roles for vehicle added

    There seems to be some revisionism underway in the Canadian Army about the Tactical Armoured Patrol Vehicle (TAPV) program as well as changes to the role of the wheeled vehicle. When it was originally announced part of the stated goal of the TAPV was to take on the role of reconnaissance, with 193 of the vehicles being a reconnaissance variant that would replace the Army's Coyote vehicle. The remaining 307 TAPVs would serve as armoured personnel carriers for battlefield troop transportation, according to the Army. In addition, the $1.2 billion project, when it was announced in 2012, was clearly part of the Conservative government's defence program (The original TAPV plans also emerged under the Conservatives in 2008/2009). The situation has changed in the meantime. The Army says it is expanding the role of the vehicle. The TAPV is being assigned to headquarters and military police units for use as protected and mobile transport. It will be used as well for command and control, VIP transport and patrolling. As for the more sophisticated reconnaissance capability fielded by the Coyotes, the Army notes that it has the new LAV 6 and its Reconnaissance Surveillance System (LRSS) Project. “The remaining Coyote fleet will be divested upon the fielding of the LAV 6.0 LRSS which are expected to be delivered in 2021 and 2022,” it added in an email to Postmedia. As for the TAPV project, as pointed out below in the Army Facebook posting last year, that program is now being credited to the Liberal government and its Strong, Secure and Engaged defence policy. https://ottawacitizen.com/news/national/defence-watch/canadian-army-credits-liberals-for-tapv-instead-of-conservatives-new-roles-for-vehicle-added

  • Aerospace industry calls for essential designation

    24 mars 2020 | Local, Aérospatial

    Aerospace industry calls for essential designation

    The Aerospace Industries Association of Canada issued the following letter to the Canadian government, asking to be declared as an essential service during the COVID-19 crisis. Dear Prime Minister and provincial Premiers, Canada's aerospace sector plays a critical role in Canada's overall economy and continues to do so even during this current COVID-19 crisis. Employing nearly 215,000 people, including jobs in manufacturing, technical trades, and management, we have built world-class capability and capacity when it comes to high-value, innovative aerospace products and series. AIAC members operate in all regions of the country, offering products and services to Canada and indeed the entire world. Home to leading aviation and space companies, Canada is a world leader in producing and servicing all aspects of the global aerospace, defence and space industry. It is also a sector that can, and will, play a significant role in Canada's economic recovery, if allowed to do so. The unprecedented Coronavirus (COVID-19) health crisis is resulting in difficult decisions, including shutting down parts of our economy that are not deemed essential. However, Canada's aerospace industry ensures the safe transport of products and services necessary in times of crises, and also products and services required for maintaining critical infrastructure such as satellite systems in space and defence infrastructure. Aerospace businesses must have the option to remain open to support the flow of these goods and services. Therefore, the Aerospace Industries Association of Canada (AIAC) calls on the government, and the provincial premiers, to declare the aerospace industry as an essential service. As this uncertain global situation continues, AIAC and its members are in contact daily with many of your ministers and their officials. We are in this together and have indicated our full support. We are actively engaging with our members and working closely with officials at the department of Innovation, Science, & Industry and Economic Development and Small Business, Export Promotion and International Trade to determine how we can best support the critical need in terms of items and supplies required to combat the virus. Prime Minister and Premiers, as you take further action to prevent the spread of the virus, please allow aerospace to stand with you and continue our vital contributions to the safety and security of Canadians, and indeed the world. https://www.skiesmag.com/news/aerospace-industry-calls-for-essential-designation

  • 3 New R&D Challenges & CyberSecure Program / 3 nouveaux défis de R&D et programme CyberSécuritaire

    29 novembre 2021 | Local, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    3 New R&D Challenges & CyberSecure Program / 3 nouveaux défis de R&D et programme CyberSécuritaire

    (le français suit) We launched 3 new R&D funding opportunities! We worked with the National Research Council of Canada (NRC) to release three new challenges. With the launch of these opportunities, ISC has surpassed our 100th challenge milestone! Think you can solve any of the below challenges? Compete for funding to prove your feasibility and develop a solution! Apply online SME News: Get certified with new cybersecurity program See below to learn more about CyberSecure, a federal certification program to help SMEs improve cybersecurity practices. High Performance Low Cost Detection of Biomarkers The NRC is seeking robust cost effective point-of-care testing innovations. This challenge closes on December 23rd, 2021 at 2pm EST! Reducing Airborne Transmission of Respiratory Viruses in Buildings Lacking a Mechanical Ventilation System The NRC is seeking the Canadian industry to develop and manufacture building technologies and products that can protect occupants by effectively mitigating airborne transmission of respiratory viruses in buildings lacking a mechanical ventilation system. This challenges closes December 23rd, 2021 at 2pm EST! Made-in-Canada Compostable Elastomeric Materials for Medical Glove Manufacturing The NRC, in collaboration with Environment & Climate Change Canada (ECCC), Health Canada (HC) and Natural Resources Canada (NRCan), are seeking solutions for Made-in-Canada sustainable elastomeric materials, that are compostable, to be used in the manufacturing of an equivalent alternative to disposable medical gloves. This challenges closes December 23rd, 2021 at 2pm EST! Get certified with CyberSecure Canada CyberSecure Canada is the country's cybersecurity certification program for SMEs. Learn more about how you can enhance your competitive advantage by letting your supply chain know you're a trusted business partner. Nous avons lancé 3 nouvelles opportunités de financement R&D ! Nous avons travaillé avec le Conseil national de recherches du Canada (CNRC) pour lancer trois nouveaux défis. Avec le lancement de ces opportunités, SIC a dépassé le cap de son 100ème défi ! Vous pensez pouvoir résoudre l'un des défis ci-dessous ? Appliquer pour compétitionner au financement afin de prouver votre faisabilité et de développer une solution ! Postulez en ligne Nouvelles des PME : Obtenez une certification gr'ce au nouveau programme de cybersécurité Voir ci-dessous pour en savoir plus sur CyberSécuritaire, un programme de certification fédéral visant à aider les PME à améliorer leurs pratiques en matière de cybersécurité. Détection haute performance à faible coût de biomarqueurs Le CNRC cherche des solutions innovantes, robustes et économiques pour des tests effectués sur les lieux de prestation de soins. Ce défi se termine le 23 decembre, 2021 à 14 h HNE. Réduction de la transmission par voie aérienne des virus respiratoires à l'intérieur des immeubles sans système de ventilation mécanique Le CNRC invite les industriels canadiens à développer des technologies et des systèmes permettant de protéger efficacement les occupants des immeubles sans système de ventilation mécanique en atténuant la transmission par voie aérienne des virus respiratoires. Ce défi se termine le 23 decembre, 2021 à 14 h HNE. Élastomères de fabrication canadienne pour la confection des gants médicaux Le CNRC, en collaboration avec Environnement et Changement climatique Canada (ECCC), Santé Canada (SC) et Ressources naturelles Canada (RNCan), est à la recherche de solutions faisant appel à des élastomères écologiques et compostables, fabriqués au Canada, qui pourront être utilisés pour la fabrication d'un nouveau type de gants médicaux jetables. Ce défi se termine le 23 decembre, 2021 à 14 h HNE. Soyez certifié avec CyberSécuritaire Canada CyberSécuritaire Canada est le programme de certification en cybersécurité réservé aux petites et moyennes entreprises. Découvrez comment vous pouvez renforcer votre avantage concurrentiel au niveau supérieur en informant votre chaîne logistique que vous êtes un partenaire d'affaires de confiance.

Toutes les nouvelles