Friday, April 6, 2012

4th Law Enforcement IT Day 2012. April 18, 2012


4th Law Enforcement IT Day 2012
 

 
Law enforcement and national security depends on adaptation—adaptation to the economy, adaptation to technology and adaptation to criminal methodologies. As budgetary cutbacks become commonplace in the Federal government, creativity in new technology initiatives must take precedence as agencies are increasingly expected to do more with less. Law enforcement agencies and officers will need to use new tools, including, data analytics, secure mobility, biometrics and even social media to more effectively track, detain and prosecute criminals.

AFCEA Bethesda invites you to Law Enforcement IT Day 2012 for a look at how these new technologies and processes are redefining the way law enforcement agencies adapt to budgetary constraints and the evolution of criminal devices and tactics. The event will bring together more than 400 senior government leaders and IT professionals across industry and Federal agencies such as DOJ, DHS, State, Treasury and DOD to foster better communications, share lessons learned and best practices, and identify mission-critical IT issues. It will focus on federal initiatives and programs that harness current and emerging technologies to better protect and improve the safety and security of U.S. citizens.

 
Register today and benefit from:
  • Networking opportunities with more than 400 senior executives and IT professionals
  • Keynote presentations and panel discussions from key stakeholders at critical agencies such as DOJ, FBI, DHS, ICE, CBP, State, and Treasury, among others, responsible for achieving Federal law enforcement objectives through the use of IT
  • Federal roundtables allow Q&A opportunities to discuss challenges, trends and initiatives between government and industry that will lead to innovation and economic growth
    • Topics include: mobile force engagement, mobile security, data analytics, cloud computing, shared services, biometrics, information sharing, cyber defense, cyber incident response and social media as an investigative tool
  • Program updates from IT program and project managers and Department leaders
  • Small Business Innovation Luncheon featuring more than 125 small business representatives and systems integrators to look at real and planned set-aside programs throughout the health IT community
  • Meet one-on-one with Federal program offices such as FBI InfraGard, CJIS, LEO, NIEM PMO and NITAAC to discuss future law enforcement focused information technology opportunities and how the private sector can improve technology requirements
  • Receive continuing education credits from the Graduate School USA, an independent, educational, not-for-profit that prepares and advance your career in government, private sector and non-for-profit organizations
Wednesday, April 18, 2012 

Bethesda North Marriott and Conference Center –
5701 Marinelli Road, North Bethesda, MD 20852

Webinar: Societal security – Emergency management – Requirements for incident response. April 11, 2012.


BEMA is a partner organization of EIPP.

ISO Technical Committee 223 on Societal Security Update

April 11, 2012 -- 12:00 Noon Eastern

In follow up to our last program on emergency management standards, EMForum.org is pleased to host a one hour presentation and interactive discussion Wednesday, April 11, 2012, beginning at 12:00 Noon Eastern time (please convert to your local time). Our topic will be an update on the activities of ISO Technical Committee 223 since our last program during 2008. This past December, ISO announced the publication of a new standard, ISO 22320:2011, Societal security – Emergency management – Requirements for incident response.


Photo of Dr. Dean LarsonOur guests will include Dean Larson, Ph.D., CEM®, Chair of the U.S. Technical Advisory Group and Head of Delegation to Technical Committee 223. Dr. Larson also serves as a Commissioner on the Indiana Emergency Response Commission and chairs the Certified Emergency Manager (CEM®) USA Commission. He is project lead for the development of the first ISO Standard on exercises and testing. Additional certifications include Safety Professional (CSP) and Business Continuity Lead Auditor (CBCLA).


Photo of Orlando HernandezAlso joining us will be Orlando P. Hernandez, Senior Specialist with the National Fire Protection Association. Mr. Hernandez has over 20 years of experience conducting and administering Fire and Life Safety Inspection Programs for the State of Texas Fire Marshal's Office and Bexar County. He also has over 16 years of Fire Investigation experience and 6 years of experience as an Emergency Management Coordinator and Incident Management Team responder.


Photo of Brian ZawadaOur final presenter will be Brian Zawada, Co-founder and Director of Consulting for Avalution Consulting, a global firm specializing in business continuity solution design, development, implementation and long-term program maintenance. Mr. Zawada previously served on the ASIS International Technical Committee that authored the new American National Standard on business continuity and currently serves on the US Technical Advisory Group charged with authoring the new family of ISO Societal Security standards, including ISO 22301.
Please make plans to join us, and see the Background Page for links to related resources and the new Instructions. If this will be your first time to participate, you may set up WebEx in advance. On the day of the program you may use the Webinar Login link not more than 30 minutes before the scheduled time.


As always, please feel free to extend this invitation to your colleagues.

EIIP and Jacksonville State University are now partnering to offer CEUs for attending EMForum.org Webinars.  See http://www.emforum.org/CEUs.htm for details.

Is your organization interested in becoming an EIIP Partner? Click here to review our Mission, Vision, and Guiding Principles and access the Memorandum of Partnership.

Cybersecurity: Interesting reading. Kingpin

http://kingpin.cc/



KINGPIN: How One Hacker Took Over the Billion-Dollar Cybercrime Underground, by Kevin Poulsen
Former hacker Kevin Poulsen has, over the past decade, built a reputation as one of the top investigative reporters on the cybercrime beat.  In Kingpin, he pours his unmatched access and expertise into book form for the first time, delivering a gripping cat-and-mouse narrative—and an unprecedented view into the twenty-first century’s signature form of organized crime.
The word spread through the hacking underground like some unstoppable new virus:  Someone—some brilliant, audacious crook—had just staged a hostile takeover of an online criminal network that siphoned billions of dollars from the US economy.
The FBI rushed to launch an ambitious undercover operation aimed at tracking down this new kingpin; other agencies around the world deployed dozens of moles and double agents.  Together, the cybercops lured numerous unsuspecting hackers into their clutches…yet at every turn, their main quarry displayed a seemingly uncanny ability to sniff out their snitches and see through their plots.
The culprit they sought was the most unlikely of criminals, a brilliant programmer with a hippie ethic and a supervillain’s double identity.  As prominent ‘white hat’ hacker Max ‘Vision’ Butler, he was a celebrity throughout the programming world, even served as a consultant for the FBI.  But as the black-hat ‘Iceman,’ he found in the world of data theft an irresistible opportunity to test his outsized abilities.  He infiltrated thousands of computers around the country, sucking down millions of credit card numbers at will.  He effortlessly hacked his fellow hackers, stealing their ill-gotten gains from under their noses.  Together with a smooth-talking con artist, he ran a massive real-world crime ring.
And for years, he did it all with seeming impunity, even as countless rivals fell afoul of police.
Yet as he watched the fraudsters around him squabble, their ranks riddled with infiltrators, their methods inefficient…he began to see in their dysfunction the ultimate challenge.  He would stage his coup and fix what was broken, run things as they should be run—even if it meant painting a bullseye on his forehead.
Through the story of this criminal’s remarkable rise, and of law enforcement’s quest to track him down,Kingpin lays bare the workings of a silent crime wave still affecting millions of Americans.  In these pages, we watch as a new generation of for-profit hackers cobbles together a criminal network that today stretches from Seattle to St. Petersburg to Shanghai. We are ushered into vast online-fraud supermarkets stocked with credit card numbers, counterfeit checks, hacked bank accounts, dead drops, and fake passports. We learn the workings of the numerous hacks—browser exploits, phishing attacks, Trojan horses, and much more—these fraudsters use to ply their trade, and trace the complex routes by which they turn stolen data into millions of dollars.  And, thanks to Poulsen’s remarkable access to both cops and criminals, we step inside the quiet, desperate arms-race law enforcement continues to fight with these scammers today.
Ultimately, Kingpin is a journey into an underworld of startling scope and power, one in which ordinary American teenagers work hand-in-hand with murderous Russian mobsters, in which a simple wi-fi connection can unleash a torrent of gold worth millions.

Article: Critical Infrastructure. Researchers Release New Exploits to Hijack Critical Infrastructure


  • http://www.wired.com/threatlevel/2012/04/exploit-for-quantum-plc/

  • By  
  •  
    •  

    The Modicon Quantum programmable logic controller, which is used in critical infrastructure systems, contains common security vulnerabilities that would allow attackers to upload rogue commands to it. Photo: Reid Wightman/Digital Bond
    Researchers have released two new exploits that attack common design vulnerabilities in a computer component used to control critical infrastructure, such as refineries and factories.
    The exploits would allow someone to hack the system in a manner similar to how the Stuxnet worm attacked nuclear centrifuges in Iran, a hack that stunned the security world with its sophistication and ability to use digital code to create damage in the physical world.
    The exploits attack the Modicon Quantum programmable logic controller made by Schneider-Electric, which is a key component used to control functions in critical infrastructures around the world, including manufacturing facilities, water and wastewater management plants, oil and gas refineries and pipelines, and chemical production plants. The Schneider PLC is an expensive system that costs about $10,000.
    One of the exploits allows an attacker to simply send a “stop” command to the PLC.
    The other exploit replaces the ladder logic in a Modicon Quantum PLC so that an attacker can take control of the PLC.
    The module first downloads the current ladder logic on the PLC so that the attacker can understand what the PLC is doing. It then uploads a substitute ladder logic to the PLC, which automatically overwrites the ladder logic on the PLC. The module in this case only overwrites the legitimate ladder logic with blank ladder logic, to provide a proof of concept demonstration of how an attacker could easily replace the legitimate ladder logic with malicious commands without actually sabotaging the device.
    The exploits take advantage of the fact that the Modicon Quantum PLC doesn’t require a computer that is communicating with it to authenticate itself or any commands it sends to the PLC – essentially trusting any computer that can talk to the PLC. Without such protection, an unauthorized party with network access can send the device malicious commands to seize control of it, or simply send a “stop” command to halt the system from operating.
    The attack code was created by Reid Wightman, an ICS security researcher with Digital Bond, a computer security consultancy that specializes in the security of industrial control systems. The company said it released the exploits to demonstrate to owners and operators of critical infrastructures that “they need to demand secure PLC’s from vendors and develop a near-term plan to upgrade or replace their PLCs.”
    The exploits were released as modules in Metasploit, a penetration testing tool owned by Rapid 7 that is used by computer security professionals to quickly and easily test their networks for specific security holes that could make them vulnerable to attack.
    The exploits were designed to demonstrate the “ease of compromise and potential catastrophic impact” of vulnerabilities and make it possible for owners and operators of critical infrastructure to “see and know beyond any doubt the fragility and insecurity of these devices,” said Digital Bond CEO Dale Peterson in a statement.
    But Metasploit is also used by hackers to quickly find and gain access to vulnerable systems. Peterson has defended his company’s release of exploits in the past as a means of pressuring companies like Schneider into fixing serious design flaws and vulnerabilities they’ve long known about and neglected to address.
    Peterson and other security researchers have been warning for years that industrial control systems contain security issues that make them vulnerable to hacking. But it wasn’t until the Stuxnet worm hit Iran’s nuclear facilities in 2010 that industrial control systems got widespread attention. The makers of PLCs, however, have still taken few steps to secure their systems.
    “[M]ore than 500 days after Stuxnet the Siemens S7 has not been fixed, and Schneider and many other ICS vendors have ignored the issues as well,” Peterson said.
    Stuxnet, which attacked a PLC model made by Siemens in order to sabotage centrifuges used in Iran’s uranium enrichment program, exploited the fact that the Siemens PLC, like the Schneider PLC, does not require any authentication to upload rogue ladder logic to it, making it easy for the attackers to inject their malicious code into the system.
    Peterson launched a research project last year dubbed Project Basecamp, to uncover security vulnerabilities in widely used PLCs made by multiple manufacturers.
    In January, the team disclosed several vulnerabilities they found in the Modicon Quantum system, including the lack of authentication and the presence of about 12 backdoor accounts that were hard coded into the system and that have read/write capability. The system also has a web server password that is stored in plaintext and is retrievable via an FTP backdoor.
    At the time of their January announcement, the group released exploit modules that attacked vulnerabilities in some of the other products, and have gradually been releasing exploits for other products since then.

    Tuesday, April 3, 2012

    STEM Initiative: Plan Now! Summer Engineering Program. Johns Hopkins University



     

     

     

     

     

     

     

     

    Eligibility Requirements

    • Completion of sophomore, junior, or senior year of high school
    • Successful completion of a laboratory science (Physics, Chemistry, or Biology), Algebra II, and Trigonometry
    • Knowledge of a spreadsheet application, such as Excel
    • Residential students must be 15 as of June 30, 2012

    Expand Your Possibilities

    • Curriculum developed by Johns Hopkins University
    • Nearly 90% of Engineering Innovation graduates have gone on to study engineering or science in college
    • 10:1 student/teacher ratio
    • Students learn from practicing engineers about careers, internships, and educational opportunities in the field
    • Students with a final grade of A or B receive three transferable Johns Hopkins University credits
    • Certificates of Completion are awarded to all students who successfully complete the course
    • A residential option is available at the Johns Hopkins University Homewood campus site
    • The program runs four to five weeks, depending on the location
    Downloadable brochure

    RECOMMENDED READING LIST

    Search This Blog

    ARCHIVE List 2011 - Present