Monday, December 21, 2009

Drones

The Army Times reports that Iraqi insurgent militias supported by Iran seemed to have early warning of U.S. actions, apparently because of their ability to hack U.S. drones.

"We noticed a trend when going after these guys; that sometimes they seemed to have better early warning” of U.S. actions, said the officer briefed on the raid. “We went and did a raid on one of their safe houses and found all of this equipment that was highly technical, highly sophisticated. It was more sophisticated than any other equipment we’d seen Iraqi insurgents use.”

The militia, known as Kata’ib Hezbollah based out of Sadr City, Baghdad, has long been suspected of being a surrogate for Iran’s Quds Force, the wing of the Iranian Army responsible for conducting clandestine warfare outside of Iran via various insurgent groups.

“It was the technological know-how to make the antennas, computers and software go together and pick up the appropriate bands that was impressive,” the officer said.

Soon after the raid, top commanders in Iraq convened a task force to identify the extent of the threat and how best to deal with it, according to the officer. Initial findings showed the threat was isolated to Kata’ib Hezbollah.

“They knew that we were flying Predators over their heads 24/7, so it’s easy to say, ‘yeah, I know that I’m going to do a signals analysis search for [the drone] and take advantage of it,” the officer said.

The laptops loaded with the SkyGrabber software also had footage filmed by smaller Army UAVs as well as the Predators.

Meanwhile, over at Danger Zone, Nathan Hodge opines that the problem isn't just that the signals from the drones aren't encrypted, but that they would be decrypted the second they hit terrestrial networks like the Defense Information Systems Network.

“The disadvantage is that the encryption is stripped off at the [DISN] ground terminal,” he says. “So you get direct interception protection (which is what this exploit appears to be). But you don’t get any protection for the YouTube effect — wiretapping the terrestrial internet.”

Now, this is heading more into theoretical territory: The immediate threat is from insurgents who can use cheap, readily available tools to spy on poorly protected video feeds, not a state adversary who can tap into the military’s secure fiber optic networks. But what Buddenberg is arguing for is a more comprehensive solution: Encrypting the data “at the camera” so it is protected as it travels across the network, regardless of what datalink is used to haul bits. It’s an “end-to-end” approach, versus an approach that looks at communications security as an afterthought to aircraft design.

Still waiting for that Cyber Security Manhattan Project, guys.

Labels: , ,

Sunday, December 20, 2009

What Were They Thinking?

So it seems that our Predator drones, on which we depend for so much intelligence and air-to-ground support in Afghanistan, have been using unencrypted communications. Which have been intercepted by Serbs, Iraqi insurgents, and probably the Taliban and al-Qaeda. (Because, y'know, a Western-educated multimillionaire like Osama just couldn't possibly understand how a satellite dish works.)

The fact that a sophisticated, multi-million-dollar aerial surveillance system could be compromised so easily because of a fundamental security oversight is stunning, several security analysts said.

"Frankly, this is shocking to me," said
Ira Winkler, president of the Internet Security Advisors Group. (Winkler is also the author of Spies Among Us and a Computerworld columnist.) "You have one of the most critical weapon systems in the most critical regions transmitting intelligence data unencrypted," Winkler said.

In order to intercept these communications, you require (1) a satellite dish [now I have a use for my old one!], and (2) a copy of a $26 Russian software tool called SkyGrabber, which is designed to help people in remote Russian locations (there being few other kind) to access satellite TV and Internet.

"Those sorts of assumptions always get us in trouble," said Lewis, who earlier this year led a group that developed a set of cybersecurity recommendations for the White House. "You can be sure that the insurgents weren't the only folks watching the feeds," he said.

The insurgents have not, so far as we know, actually succeeded in seizing control of a Predator. (Though of course you always have to wonder when a Hellfire supposedly targeting the al-Qaeda leadership blows up a Muslim wedding instead.)

The Air Force has known about this for ten years! And done nothing! (The CIA drones flying out of Pakistan apparently encrypt all transmissions, showing that the CIA know at least a little about elementary communications security.)

But wait! There's more! Not only are the Predator drones vulnerable, so are all our fighters and bombers!

The
military initially developed the Remotely Operated Video Enhanced Receiver, or ROVER, in 2002. The idea was let troops on the ground download footage from Predator drones and AC-130 gunships as it was being taken. Since then, nearly every airplane in the American fleet — from F-16 and F/A-18 fighters to A-10 attack planes to Harrier jump jets to B-1B bombers has been outfitted with equipment that lets them transmit to ROVERs. Thousands of ROVER terminals have been distributed to troops in Afghanistan and Iraq.

But those early units were “fielded so fast that it was done with an unencrypted signal. It could be both intercepted (e.g. hacked into) and jammed,” e-mails an Air Force officer with knowledge of the program. In a presentation last month before a conference of the Army Aviation Association of America, a military official noted that the
current ROVER terminal “receives only unencrypted L, C, S, Ku [satellite] bands.”

So the same security breach that allowed insurgent to use satellite dishes and $26 software to intercept drone feeds can be used the tap into the video transmissions of any plane.

Sure is lucky we're fighting a bunch of unsophisticated tribal know-nothings, because otherwise, y'know, we could be in trouble.

Labels: ,