Chinese cyberattacks hit key US weapons systems

N&P: Discussion of news headlines and politics.

Moderator: frigidmagi

Post Reply
User avatar
rhoenix
The Artist formerly known as Rhoenix
Posts: 7998
Joined: Fri Dec 22, 2006 4:01 pm
19
Location: "Here," for varying values of "here."
Contact:

#1 Chinese cyberattacks hit key US weapons systems

Post by rhoenix »

Christian Science Monitor wrote:Dozens of key US weapons system designs and technologies have been compromised by Chinese hackers, creating fresh uncertainty over America’s warfighting capabilities in any future conflict in Asia, according to a defense advisory group study and defense policy experts.

The laundry list of US weapons systems whose files have been accessed during the past decade by Chinese hackers includes some of the nation’s most expensive and exotic programs. The list was contained in a confidential version of a Defense Science Board report, according to The Washington Post.

The list includes the Terminal High Altitude Area Defense missile system, the V-22 Osprey tilt-rotor aircraft, Patriot Advanced Capability-3 antimissile system, along with the Global Hawk unmanned aerial vehicle, the Aegis ballistic missile defense system, and the F-35 Joint Strike Fighter.

The long-term impact, experts say, could be to give China an edge in any confrontation as well as speeding deployment of advanced military technology that will cost it billions less to develop, defense experts say.

The unclassified version of the Defense Science Board report entitled, “Resilient Military Systems and the Advanced Cyber Threat,” which did not contain the list and barely mentions China, was released in January. But defense officials, speaking anonymously, told the Post that Chinese hackers are behind the attacks on most of the systems on the list in the restricted version.

“The Defense Science Board, a senior advisory group made up of government and civilian experts, did not accuse the Chinese of stealing the designs,” the newspaper reported. “But senior military and industry officials with knowledge of the breaches said that the vast majority were part of a widening Chinese campaign of espionage against US defense contractors and government agencies.”

Earlier this month, the Pentagon went on record with another report, this one to Congress, saying that Chinese cyberespionage of weapons systems is a key part of China’s effort to vault itself forward. That report for the first time specifically cited China’s government and military as directly responsible for cyberthefts involving US weapons systems.

“China is using its computer network exploitation capability to support intelligence collection against the US diplomatic, economic, and defense industrial base sectors that support US national defense programs,” the unusually blunt report to Congress said. “The information targeted could potentially be used to benefit China’s defense industry, high technology industries, policymaker interest in US leadership thinking on key China issues, and military planners building a picture of US network defense networks, logistics, and related military capabilities that could be exploited during a crisis.”

The unclassified version of the Defense Science Board report cited cyber vulnerabilities in “systems that are used to support and operate those weapons or critical IT capabilities embedded within them.”

What the pair of reports, along with the emergence of the restricted list, suggests is a wholesale loss of integrity and introduction of new levels of potential vulnerability of those weapons systems to Chinese military hackers, defense policy and cybersecurity experts told the Monitor.

“All the stuff on this list is extremely sensitive – it’s like the kitchen sink,” says Kenneth Flamm, a technology expert at the Pentagon during the Clinton administration, and now an economist at the University of Texas at Austin. “It raises serious questions about whether we can rely on these systems.”

The list includes systems compromised during an ongoing Chinese cyberespionage campaign that began in late 1990s. Its first significant successes came in 2002-03 and peaked in 2007, when the hackers got into at least five federal agencies, including the Defense Department, Commerce Department, State Department, NASA, and the Energy Department, says James Lewis, a senior fellow and cybersecurity expert with the Center for Strategic and International Studies, a Washington think tank.

About that time, government officials started to get serious about cybersecurity, and the incoming Obama administration also kicked off in 2008 a strategic review of cybersecurity. Since 2009, the Pentagon’s cybersecurity has been vastly improved, Dr. Lewis says.

“A lot of these cyberthefts happened before the Obama program kicked in,” Lewis adds. “But we still can’t rest easy, because we don’t know what they got and what they did while they were inside these networks.”

Software can make up perhaps one-third of the value of weapons systems like the Patriot missile and other system, he notes. Software for other systems on the list may now need an overhaul in order to ensure their integrity, he notes.

“If they got into the software code and left something behind, we’ve got a serious problem,” he says. “How do we know? We don’t. So the answer is that we have to redo the system to be sure it isn’t compromised.”

For its part, China regularly denies cyberespionage charges – and claims it, too, is a victim. But the emergence of the list comes amid heightened tensions between the US and China over charges of rampant cyberespionage by China against US defense industry, energy systems, and other economic targets.

In discussing an April visit to China by Gen. Martin Dempsey, chairman of the Joint Chiefs of Staff, Defense Secretary Chuck Hagel called cyberattacks “the greatest threat to our security – economic security, political security, diplomatic security, military security – that confronts us.”

During the visit, a top Chinese military officer, Gen. Fang Fenghui, seemed to concur, saying of cyberinsecurity that “the damaging consequences it causes may be as serious as a nuclear bomb.”
I keep seeing articles about this, and they keep admitting that the problem is a little worse each time. In my mind, it actually goes right back to the issue the US has right now with a declining number of scientists and engineers per capita, compared to twenty or thirty years ago - our ability to keep infrastructure intact is being hampered by the same.

More to the point though, things like this aren't stopping, and I don't ever hear much about what America's doing in response.
"Before you diagnose yourself with depression or low self-esteem, make sure that you are not, in fact, just surrounded by assholes."

- William Gibson


Josh wrote:What? There's nothing weird about having a pet housefly. He smuggles cigarettes for me.
User avatar
frigidmagi
Dragon Death-Marine General
Posts: 14757
Joined: Wed Jun 08, 2005 11:03 am
21
Location: Alone and unafraid

#2 Re: Chinese cyberattacks hit key US weapons systems

Post by frigidmagi »

I don't see the connection. This isn't Oh Noes, America doesn't have enough engineers. This is a Chinese cyberninjas keep stealing our shit. Having more aerospace engineers isn't gonna keep Chinese crackers out. As it stands first thing we need to do?

Stop leaving this shit on terminals with internet connections.

Second thing we need to do?

Go over our internal security, we clearly have problems.

Third thing we need to do?

Get the lasers and railguns up to speed. Nothing says your stolen F-35 doesn't matter like a railgun. ... This last one may just be me wanting a railgun.

I should point out, that as the article mentions but glosses over the Chinese are getting Cyber attacks to. Gee... I wonder who would be so mean to the Chinese.
"it takes two sides to end a war but only one to start one. And those who do not have swords may still die upon them." Tolken
User avatar
rhoenix
The Artist formerly known as Rhoenix
Posts: 7998
Joined: Fri Dec 22, 2006 4:01 pm
19
Location: "Here," for varying values of "here."
Contact:

#3 Re: Chinese cyberattacks hit key US weapons systems

Post by rhoenix »

frigidmagi wrote:I don't see the connection. This isn't Oh Noes, America doesn't have enough engineers. This is a Chinese cyberninjas keep stealing our shit. Having more aerospace engineers isn't gonna keep Chinese crackers out. As it stands first thing we need to do?

Stop leaving this shit on terminals with internet connections.

Second thing we need to do?

Go over our internal security, we clearly have problems.

Third thing we need to do?

Get the lasers and railguns up to speed. Nothing says your stolen F-35 doesn't matter like a railgun. ... This last one may just be me wanting a railgun.
The connection to the lack of scientists & engineers I drew because otherwise, I imagine the Chinese would be having a much more difficult time because of how often things would be updated, though I admit that's pure conjecture.

I agree with you that to avoid this issue, we should get weapons systems stable that they can't reproduce, like your examples of lasers and railguns.
frigidmagi wrote:I should point out, that as the article mentions but glosses over the Chinese are getting Cyber attacks to. Gee... I wonder who would be so mean to the Chinese.
That's a great counterpoint, actually. If the US was retaliating in such a fashion, it wouldn't be something we'd loudly broadcast.
"Before you diagnose yourself with depression or low self-esteem, make sure that you are not, in fact, just surrounded by assholes."

- William Gibson


Josh wrote:What? There's nothing weird about having a pet housefly. He smuggles cigarettes for me.
User avatar
Josh
Resident of the Kingdom of Eternal Cockjobbery
Posts: 8114
Joined: Mon Jun 06, 2005 4:51 pm
21
Location: Kingdom of Eternal Cockjobbery

#4 Re: Chinese cyberattacks hit key US weapons systems

Post by Josh »

frigidmagi wrote:Get the lasers and railguns up to speed. Nothing says your stolen F-35 doesn't matter like a railgun. ... This last one may just be me wanting a railgun.
Ditto.

Double ditto.

As for the cybersecurity stuff, I have no doubt we have issues. But I'm kinda thinking that there are folks with a vested monetary interest in promoting the idea that we're doomed from cyberwarfare if we don't hire lots of security consulting firms to protect us.

Not denying the threat. My best friend is in networking for the local school district and they have to secure against shit from China. It's just that the article trend matches some other overinflated threats I've seen hyped to the heavens in the past, inevitably by folks who make money off perceived danger.
When the Frog God smiles, arm yourself.
"'Flammable' and 'inflammable' have the same meaning! This language is insane!"
GIVE ME COFFEE AND I WILL ALLOW YOU TO LIVE!- Frigid
"Ork 'as no automatic code o' survival. 'is partic'lar distinction from all udda livin' gits is tha necessity ta act inna face o' alternatives by means o' dakka."
I created the sound of madness, wrote the book on pain
Post Reply