COGNITIVE HACKING – A BATTLE FOR THE MIND
“On 25th August 2000, stockholders were stunned by news that EMULEX, a server & storage provider was revising its earnings from a 25$ per share gain to a 15$ loss and that it was lowering its reported net earnings from the previous quarter as well.
The press release, which business news services like CBS Market Watch were distributing, went on to state that CEO Paul Folino had resigned and that the company was under investigation.
Within 16 minutes, Emulex shares plummeted from their previous day’s close of approximately $104 per share to $43”.
NONE OF THIS WAS TRUE
A 23-year old hacker, Mark Jakob had created the bogus release expressly to lower Emulex stock prices and thus recoup his recent $100,000 loss in a stock short sale.In a short sale, stock prices must fall for the seller to profit.
Jakob had launched the release via his former employer, Internet Wire, a Los Angeles firm that distributes press releases and the business news services had picked it up and widely redistributed it without independent verification.
More than 3 million shares traded hands at this artificially low rates and Jakob earned back his $100,000 nearly three times over.He was subsequently charged with security fraud and faced a 44- month prison term.
The EMULEX case illustrates the speed, scale & the subtlety with which networked information can propagate and how quickly severe consequences can occur.Although Nasdaq halted trading at the artificial price after only an hour, Emulex lost $2.2 billion in market capitalization.
The damage had little to do with penetrating the network infrastructure or technology. It had to do with manipulating perception & waiting for altered reality to produce actions that would complete the attack.
The damage had little to do with penetrating the network infrastructure or technology. It had to do with manipulating perception & waiting for altered reality to produce actions that would complete the attack.
Jakob cracked no code and planted no virus. He merely wrote a convincing press release, used a believable distribution medium and sat back to watch events unfold.
COGNITIVE HACKING
The manipulation of perception or cognitive hacking is outside the domain of classical computer security, which focuses on the technology and network infrastructure.
The Emulex case is an example of how the variety & complexity of attacks parallel information technologies and the way we use them with no end in sight for either side.
The Emulex case is an example of how the variety & complexity of attacks parallel information technologies and the way we use them with no end in sight for either side.
In 1981, Carl Landwehr observed, “without a precise definition of what security means and how a computer can behave, it is meaningless to ask whether a particular computer system is secure”.
Twenty years ago, computer security focused on systems for handling military messages. Since then, particularly with the growth of the Internet, computer systems are widely used to disseminate information of all types to a variety of users.It is precisely this dissemination that has enabled cognitive hacking.
As Albert Einstein wrote, “we cannot solve the problems that we have created with the same thinking that created them. We certainly have security & privacy problems today. How did we get there? How might we move forward? “.
ONE THREAT: MANY FACES –
Cognitive attacks can be overt or covert. No attempt is made to conceal overt cognitive attacks. e.g., website defacements. Provision of misinformation, the intentional distribution or insertion of false or misleading information intended to influence reader’s decisions and or activities are covert cognitive hacking. Overt cognitive hacking, while more prevalent than covert forms is more of a nuisance and embarrassment than a serious threat.Covert cognitive hacking is likely to have more significant and less predictable consequences.
Cognitive attacks can be overt or covert. No attempt is made to conceal overt cognitive attacks. e.g., website defacements. Provision of misinformation, the intentional distribution or insertion of false or misleading information intended to influence reader’s decisions and or activities are covert cognitive hacking. Overt cognitive hacking, while more prevalent than covert forms is more of a nuisance and embarrassment than a serious threat.Covert cognitive hacking is likely to have more significant and less predictable consequences.
The Internet’s open nature makes it an ideal arena for dissemination of misinformation. Cognitive hacking differs from social engineering, which, in the computer domain, involves a hacker's psychological tricking of legitimate computer system users to gain information, e.g., passwords, in order to launch an autonomous attack on the system.
As a new threat, cognitive hacking requires new counter measures, source authentication, information trajectory modeling, linguistic analysis are relatively mature technologies in the context of application such as e-commerce.
As a new threat, cognitive hacking requires new counter measures, source authentication, information trajectory modeling, linguistic analysis are relatively mature technologies in the context of application such as e-commerce.
However, these measures are immature as applied to preventing misinformation and detecting user behavior.Legal issues are another concern. Users currently have little protection against the consequences of attacks. Often, the penalties for spoofing and defacement are light or non-existent. Relevant laws that apply to other media should apply to the Internet, but the application of the law to cognitive hacking and other Internet related areas is volatile.
The events of sep-11 2001 have only made the situation more unpredictable, as the balance between privacy and security has shifted towards security. More legislation affecting this area must be enacted, and the associated case law will continue to evolve.
The events of sep-11 2001 have only made the situation more unpredictable, as the balance between privacy and security has shifted towards security. More legislation affecting this area must be enacted, and the associated case law will continue to evolve.
UNTIL THEN, USERS BE ALERT.



0 Comments:
Post a Comment
<< Home