Thursday

18th Jul 2019

EU cyber assault would cost €86 million, expert says

  • A technician overlooks EU air traffic at Eurocontrol, the Brussels-based European air safety body - a potential target in any cyber assault (Photo: Eurocontrol)

A malicious foreign power could - given €86 million, 750 people and two years to prepare - launch a devastating cyber attack on the EU, a US security expert has said.

The assault would begin with a member of staff at, say, the London Stock Exchange or the French electricity grid operator, RTE, opening a PDF attachment in an email which looks as if it had been sent by a colleague.

Read and decide

Join EUobserver today

Support quality EU news

Get instant access to all articles — and 18 year's of archives. 30 days free trial.

... or join as a group

The PDF would contain software enabling a hacker on a different continent to silently take over his computer. Over time, the hacker would monitor the employees' keystrokes, sniff out passwords, and use the information to take over computers higher up the command chain, eventually putting him in a position to switch off the target's firewalls, leaving it open to DOS (Denial of Service) attacks, and to install RATs (Remote Administration Tools), which control its hardware.

Around 18 to 21 months down the line, with enough targets compromised, the assault could take place.

The EU 27 countries would wake up to find electricity power stations shut down; communication by phone and Internet disabled; air, rail and road transport impossible; stock exchanges and day-to-day bank transactions frozen; crucial data in government and financial institutions scrambled and military units at home and abroad cut off from central command or sent fake orders.

Normal life could be restarted in a few days' time. But the damage done to administrative capacity, consumer confidence and the economy by loss of vital data would last years.

Charlie Miller, a mathematician who served for five years at the US' National Security Agency stress-testing foreign targets' computer systems and designing "network intrusion detection tools," calculated the EU scenario on the basis of a more detailed study of US vulnerability.

Mr Miller said the bulk of the money, €83 million, would be used to pay an army of 750 hackers, with just €3 million spent on hardware - a testing lab with 50 computers, another two computers each per hacker and assorted smartphones and network equipment.

An elite corps would consist of 20 "world class" experts whose main job would be to find "0-day exploits" - previously undetected security gaps in popular software such as Windows, Java or Adobe. The experts would have to be paid a small fortune, over €200,000 each a year, or extorted.

Another 40 people, drawn from the enemy country's secret services or recruited inside EU member states, would get inside "air-gapped" facilities - the most secure targets, such as military command structures or air traffic control bodies, which are physically cut-off from the Internet in order to prevent cyber attacks. When the time came, the agents would un-airgap targets by connecting them to the Internet via 3G modems and satellite phones.

The rest of the cyber army, 690 people, mostly computer science graduates and post-graduates from inside the hostile state, would use the 0-day exploits to take over target networks. They would also collect, maintain, create and test "bots" - software which secretly uses computers in ordinary people's homes to run automated tasks, such as DOS attacks, which bombard target systems with overwhelming amounts of data. The final assault would require 500 million bots in diverse locations.

Dr Miller, who currently works for the Baltimore, US-based company, Independent Security Evaluators, admitted that Internet scare stories help firms like his to get business. But he noted that classic intelligence gathering, rather than hiring IT experts, is the best line of defence.

"It's really hard to defend against an attack that's well equipped and carried out by smart people. But you do have years to detect it before it happens. If you have an elaborate intelligence gathering network you could detect it, not technically because you can see it, but because you have human intel," he said. "If you want to spend your money well, spend it on your intelligence services."

Learning from Estonia

The threat of cyber war against EU targets became a reality on 27 April 2007 when hackers crashed Estonian online news agencies with DOS attacks in the middle of an Estonia-Russia political dispute.

The assault gathered pace over the next three weeks disrupting online banking services and government communications. Three and a half years down the line there is no hard evidence linking the attack to a foreign power, although activists in the pro-Kremlin youth group, Nashi, claim to have taken part.

"If these cyber attacks were used to test the Estonian cyber defense capabilities, much more sophisticated attacks could possibly follow, based on the knowledge acquired during the attacks," a report on the 2007 events by the Estonian government's Computer Emergency Response Team said.

Nato and EU countries are putting more resources into joint cyber-security projects.

Liisa Tallinn, a spokeswoman for Nato's Tallinn-based Co-operative Cyber Defence Centre of Excellence (CCDCOE), told this website that Turkey and the US are "about to" send staff to join personnel from its eight current participating countries - Estonia, Germany, Hungary, Italy, Latvia, Lithuania, Slovakia and Spain.

The CCDCOE in May ran a "Baltic Cyber Shield" exercise in which a "red team" of "friendly hackers" took on a "blue team" of defenders to try and disable factories and communications infrastructure. Part of the results will be made public in September.

'Like water out of the tap'

The EU's own cyber-security unit, the Crete-based European Network and Information Security Agency (Enisa), will in late October or early November carry out the first ever pan-EU cyber security exercise. Enisa spokesman, Ulf Bergstrom, said the exercise will look at disrupting normal Internet operations in the EU's internal market and the way EU member states' authorities co-operate across the union's internal borders.

Mr Bergstrom noted that Enisa's initial mandate, which covers security of ecommerce, online banking and mobile phones, is being expanded to cover cyber-criminality.

"We have been given political signals, for example by [information society] commissioner Neelie Kroes, to work more closely with agencies like Europol and Interpol," he said. "Cyber security is vital for the economy of Europe, to protect the businesses and operations of ordinary citizens. This is the digital society that we take for granted, like water out of the tap, which we need to defend."

The original text quoted Liisa Tallinn as saying France is about to join the CCDCOE. This quote was incorrect, as she did not mention France

PiS & Fidesz claim credit for von der Leyen victory

Warsaw and Budapest are boasting about their support for von der Leyen after the german is confirmed only by a small margin of MEPs, but the illiberals should not expect the softening of rule of law scrutiny.

Analysis

Von der Leyen faces gender battle for commission posts

The first-ever female president of the European Commission wants half of her team of commissioners to consist of women. But most of the commissioners put forward so far by EU member states so far have been male.

EU proposes yearly rule of law 'reports'

EU states ought to undergo a yearly "Rule of Law Review Cycle" to help stop countries such as Hungary, Poland, and Romania from backsliding on EU norms, the European Commission has said.

Analysis

What did we learn from the von der Leyen vote?

The vote on von der Leyen showed the fundamental change in EU politics. The rise of the European Parliament, the power of political parties, and the fragmentation of politics, are new realities to be taken into account.

Analysis

What did we learn from the von der Leyen vote?

The vote on von der Leyen showed the fundamental change in EU politics. The rise of the European Parliament, the power of political parties, and the fragmentation of politics, are new realities to be taken into account.

Stakeholders' Highlights

  1. UNESDAUNESDA reduces added sugars 11.9% between 2015-2017
  2. International Partnership for Human RightsEU-Uzbekistan Human Rights Dialogue: EU to raise key fundamental rights issues
  3. Nordic Council of MinistersNo evidence that social media are harmful to young people
  4. Nordic Council of MinistersCanada to host the joint Nordic cultural initiative 2021
  5. Vote for the EU Sutainable Energy AwardsCast your vote for your favourite EUSEW Award finalist. You choose the winner of 2019 Citizen’s Award.
  6. Nordic Council of MinistersEducation gets refugees into work
  7. Counter BalanceSign the petition to help reform the EU’s Bank
  8. UNICEFChild rights organisations encourage candidates for EU elections to become Child Rights Champions
  9. UNESDAUNESDA Outlines 2019-2024 Aspirations: Sustainability, Responsibility, Competitiveness
  10. Counter BalanceRecord citizens’ input to EU bank’s consultation calls on EIB to abandon fossil fuels
  11. International Partnership for Human RightsAnnual EU-Turkmenistan Human Rights Dialogue takes place in Ashgabat
  12. Nordic Council of MinistersNew campaign: spot, capture and share Traces of North

Latest News

  1. PiS & Fidesz claim credit for von der Leyen victory
  2. Von der Leyen faces gender battle for commission posts
  3. EU proposes yearly rule of law 'reports'
  4. Poland 'optimistic' despite new EU law checks
  5. What did we learn from the von der Leyen vote?
  6. Is Golden Dawn's MEP head of a criminal organisation?
  7. Finland rejects call to end sponsorship of EU presidency
  8. MH17 five years on: when will Russia be punished?

Stakeholders' Highlights

  1. Nordic Council of MinistersLeading Nordic candidates go head-to-head in EU election debate
  2. Nordic Council of MinistersNew Secretary General: Nordic co-operation must benefit everybody
  3. Platform for Peace and JusticeMEP Kati Piri: “Our red line on Turkey has been crossed”
  4. UNICEF2018 deadliest year yet for children in Syria as war enters 9th year
  5. Nordic Council of MinistersNordic commitment to driving global gender equality
  6. International Partnership for Human RightsMeet your defender: Rasul Jafarov leading human rights defender from Azerbaijan
  7. UNICEFUNICEF Hosts MEPs in Jordan Ahead of Brussels Conference on the Future of Syria
  8. Nordic Council of MinistersNordic talks on parental leave at the UN
  9. International Partnership for Human RightsTrial of Chechen prisoner of conscience and human rights activist Oyub Titiev continues.
  10. Nordic Council of MinistersNordic food policy inspires India to be a sustainable superpower
  11. Nordic Council of MinistersMilestone for Nordic-Baltic e-ID
  12. Counter BalanceEU bank urged to free itself from fossil fuels and take climate leadership

Stakeholders' Highlights

  1. Intercultural Dialogue PlatformRoundtable: Muslim Heresy and the Politics of Human Rights, Dr. Matthew J. Nelson
  2. Platform for Peace and JusticeTurkey suffering from the lack of the rule of law
  3. UNESDASoft Drinks Europe welcomes Tim Brett as its new president
  4. Nordic Council of MinistersNordic ministers take the lead in combatting climate change
  5. Counter BalanceEuropean Parliament takes incoherent steps on climate in future EU investments
  6. International Partnership For Human RightsKyrgyz authorities have to immediately release human rights defender Azimjon Askarov
  7. Nordic Council of MinistersSeminar on disability and user involvement
  8. Nordic Council of MinistersInternational appetite for Nordic food policies
  9. Nordic Council of MinistersNew Nordic Innovation House in Hong Kong
  10. Nordic Council of MinistersNordic Region has chance to become world leader when it comes to start-ups
  11. Nordic Council of MinistersTheresa May: “We will not be turning our backs on the Nordic region”
  12. International Partnership for Human RightsOpen letter to Emmanuel Macron ahead of Uzbek president's visit

Join EUobserver

Support quality EU news

Join us