Home War Room War Room Computer Virus Infects United States Drone Fleet
Computer Virus Infects United States Drone Fleet PDF Print E-mail
Written by The Watchman   
Friday, 07 October 2011 11:28
AddThis Social Bookmark Button

Computer Virus Infects United States Drone Fleet

This is a new one.  I guess this goes to show you that no one is in-hackable.  For the sake of these operations success I do hope that our talented men and women in the military can wipe this virus out.  Nothing could be worse in this scenario than the enemy knowing the wherabouts of this advanced fleet of United States Predators and Reapers.  

The Strong Watchman

Original article at: 

http://www.wired.com/dangerroom/2011/10/virus-hits-drone-fleet/

Computer Virus Affects United States Drone Fleet

Computer Virus Infects United States Drone Fleet

A computer virus has infected the cockpits of America’s Predator and Reaper drones, logging pilots’ every keystroke as they remotely fly missions over Afghanistan and other warzones.

The virus, first detected nearly two weeks ago by the military’s Host-Based Security System, has not prevented pilots at Creech Air Force Base in Nevada from flying their missions overseas. Nor have there been any confirmed incidents of classified information being lost or sent to an outside source. But the virus has resisted multiple efforts to remove it from Creech’s computers, network security specialists say. And the infection underscores the ongoing security risks in what has become the U.S. military’s most important weapons system.

“We keep wiping it off, and it keeps coming back,” says a source familiar with the network infection, one of three that told Danger Room about the virus. “We think it’s benign. But we just don’t know.”

Military network security specialists aren’t sure whether the virus and its so-called “keylogger” payload were introduced intentionally or by accident; it may be a common piece of malware that just happened to make its way into these sensitive networks. The specialists don’t know exactly how far the virus has spread. But they’re sure that the infection has hit both classified and unclassified machines at Creech. That raises the possibility, at least, that secret data may have been captured by the keylogger, and then transmitted over the public internet to someone outside the military chain of command.

Drones have become America’s tool of choice in both its conventional and shadow wars, allowing U.S. forces to attack targets and spy on its foes without risking American lives. Since President Obama assumed office, a fleet of approximately 30 CIA-directed drones have hit targets in Pakistan more than 230 times; all told, these drones have killed more than 2,000 suspected militants and civilians, according to the Washington Post. More than 150 additional Predator and Reaper drones, under U.S. Air Force control, watch over the fighting in Afghanistan and Iraq. American military drones struck 92 times in Libya between mid-April and late August. And late last month, an American drone killed top terrorist Anwar al-Awlaki — part of an escalating unmanned air assault in the Horn of Africa and southern Arabian peninsula.

But despite their widespread use, the drone systems are known to have security flaws. Many Reapers and Predators don’t encrypt the video they transmit to American troops on the ground. In the summer of 2009, U.S. forces discovered “days and days and hours and hours” of the drone footage on the laptops of Iraqi insurgents. A $26 piece of software allowed the militants to capture the video.

The lion’s share of U.S. drone missions are flown by Air Force pilots stationed at Creech, a tiny outpost in the barren Nevada desert, 20 miles north of a state prison and adjacent to a one-story casino. In a nondescript building, down a largely unmarked hallway, is a series of rooms, each with a rack of servers and a “ground control station,” or GCS. There, a drone pilot and a sensor operator sit in their flight suits in front of a series of screens. In the pilot’s hand is the joystick, guiding the drone as it soars above Afghanistan, Iraq, or some other battlefield.

Some of the GCSs are classified secret, and used for conventional warzone surveillance duty. The GCSs handling more exotic operations are top secret. None of the remote cockpits are supposed to be connected to the public internet. Which means they are supposed to be largely immune to viruses and other network security threats.

But time and time again, the so-called “air gaps” between classified and public networks have been bridged, largely through the use of discs and removable drives. In late 2008, for example, the drives helped introduce the agent.btz worm to hundreds of thousands of Defense Department computers. The Pentagon is still disinfecting machines, three years later.

Use of the drives is now severely restricted throughout the military. But the base at Creech was one of the exceptions, until the virus hit. Predator and Reaper crews use removable hard drives to load map updates and transport mission videos from one computer to another. The virus is believed to have spread through these removable drives. Drone units at other Air Force bases worldwide have now been ordered to stop their use.

In the meantime, technicians at Creech are trying to get the virus off the GCS machines. It has not been easy. At first, they followed removal instructions posted on the website of the Kaspersky security firm. “But the virus kept coming back,” a source familiar with the infection says. Eventually, the technicians had to use a software tool called BCWipe to completely erase the GCS’ internal hard drives. “That meant rebuilding them from scratch” — a time-consuming effort.

The Air Force declined to comment directly on the virus. “We generally do not discuss specific vulnerabilities, threats, or responses to our computer networks, since that helps people looking to exploit or attack our systems to refine their approach,” says Lt. Col. Tadd Sholtis, a spokesman for Air Combat Command, which oversees the drones and all other Air Force tactical aircraft. “We invest a lot in protecting and monitoring our systems to counter threats and ensure security, which includes a comprehensive response to viruses, worms, and other malware we discover.”

However, insiders say that senior officers at Creech are being briefed daily on the virus.

“It’s getting a lot of attention,” the source says. “But no one’s panicking. Yet.”

Photo courtesy of Bryan William Jones

 

Add comment


Economic Outlook

Economic Outlook
 
Members : 922
Content : 877
Content View Hits : 1678028
Copyright © 2013 The Strong Watchman. All Rights Reserved.
Joomla! is Free Software released under the GNU/GPL License.
 

Who's Online

We have 100 guests online

Help. Donate.

Hey you...the reader! Help support this site! We need your help. Thanks! Google+

Amount: 

Armageddon Map

Banner
Banner

RSS War Room

Secrecy News
from the FAS Project on Government Secrecy
  • A Candid Look at the Senate Intelligence Committee

    Much of the continuing controversy over intelligence surveillance policy revolves around whether the sweeping collection of U.S. telephone data by intelligence agencies violates constitutional norms.  But it is also an occasion to assess the quality of intelligence oversight, and to review the performance of oversight mechanisms in representing the public...

  • Armed Conflict in Syria, and More from CRS

    Newly updated reports from the Congressional Research Service include the following. Armed Conflict in Syria: U.S. and International Response, June 14, 2013 Syria’s Chemical Weapons: Issues for Congress, June 14, 2013 U.S. Strategic Nuclear Forces: Background, Developments, and Issues, June 14, 2013 The Trans-Pacific Partnership Negotiations and Issues for Congress,...

  • Hundreds of Classified Leaks Under Review by IC Inspector General

    Hundreds of cases of unauthorized disclosures of classified information were under review by the Office of the Inspector General of the U.S. Intelligence Community as of last year, according to a 2012 report that was recently declassified. “The Investigations Division [of the IC Office of the Inspector General] is reviewing...

  • National Security Secrecy and the Right to Know

    While almost everyone would agree that national security secrecy has a role to play in an open society, such secrecy must be carefully circumscribed if robust public access to government information is to be preserved.  A set of principles that open societies around the world can use to help guide...

  • NASA Releases Online Library on Risk Mitigation

    NASA has produced a library of “knowledge bundles” describing how various technical problems that arose in the course of its space technology programs were successfully resolved. Last week, the library was posted online. If you want to know how a solar array was repaired in orbit, or how an astronaut...

  • Responding to Change in the Middle East, and More from CRS

    New and updated reports from the Congressional Research Service that have been withheld by Congress from public distribution online include the following. The United States and Europe: Responding to Change in the Middle East and North Africa, June 12, 2013 Israel: Background and U.S. Relations, June 12, 2013 U.S.-Mexican Security...

  • DoD Warns Employees of Classified Info in Public Domain

    As a new wave of classified documents published by news organizations appeared online over the past week, the Department of Defense instructed employees and contractors that they must neither seek out nor download classified material that is in the public domain. “Classified information, whether or not already posted on public...

  • Comprehensive Nuclear Test Ban, and More from CRS

    New and updated reports from the Congressional Research Service that have not been made readily available to the public include the following. Comprehensive Nuclear-Test-Ban Treaty: Background and Current Developments, June 10, 2013 Trans-Pacific Partnership (TPP) Countries: Comparative Trade and Economic Analysis, June 10, 2013 Carbon Capture and Sequestration: Research, Development,...

  • Secrecy News in the News

    “If President Obama really welcomed a debate [on intelligence surveillance policy], there are all kinds of things he could do in terms of declassification and disclosure to foster it. But he’s not doing any of them.” At least that’s my perception. See Debate on Secret Data Looks Unlikely, Partly Due...

  • Secret Surveillance and the Crisis of Legitimacy

    In December 1974, when a previous program of secret government surveillance was revealed by Seymour Hersh in the New York Times, the ensuing public uproar led directly to extensive congressional investigations and the creation of new mechanisms of oversight, including intelligence oversight committees in Congress and an intelligence surveillance court....

  • FISA Court Says It Cannot Easily Summarize Opinions

    The Foreign Intelligence Surveillance Court (FISC) told the Senate Intelligence Committee last March that there are “serious obstacles” that would prevent it from preparing summaries of Court opinions for declassification and public disclosure. The Court was responding to a February 13, 2013 letter from Senators Dianne Feinstein, Jeff Merkley, Ron...

  • Edward Snowden, Source of NSA Leaks, Steps Forward

    A former CIA employee and NSA contractor named Edward Snowden identified himself as the source of the the serial revelations of classified documents concerning U.S. intelligence surveillance activities that were disclosed last week. “I have no intention of hiding who I am because I know I have done nothing wrong,”...

  • DoD Releases Doctrine on Mass Atrocity Response Operations

    The Department of Defense this week released the 2012 update of its doctrine on “Peace Operations” including new guidance on so-called Mass Atrocity Response Operations that are designed to prevent or halt genocide or other large-scale acts of violence directed at civilian populations. A mass atrocity consists of “widespread and...

  • Identity of Fox News Reporter James Rosen Declassified

    The government declared today that the identity of the reporter to whom accused leaker Stephen Kim allegedly disclosed classified information is James Rosen of Fox News.  Mr. Rosen’s association with the case was publicly known for years.  But it was still classified.  Now it’s not. “The United States hereby gives...

  • Government Gathers Phone Records of Verizon Customers

    At the request of the FBI, the Foreign Intelligence Surveillance Court ordered a Verizon subsidiary to surrender the telephone records of its U.S. business customers to the National Security Agency for at least a three month period beginning last April 25. The startling disclosure was reported last night by Glenn...