The snooping dragon: social-malware surveillance of the Tibetan movement

نویسندگان

  • Shishir Nagaraja
  • Ross Anderson
چکیده

In this note we document a case of malware-based electronic surveillance of a political organisation by the agents of a nation state. While malware attacks are not new, two aspects of this case make it worth serious study. First, it was a targeted surveillance attack designed to collect actionable intelligence for use by the police and security services of a repressive state, with potentially fatal consequences for those exposed. Second, the modus operandi combined social phishing with highgrade malware. This combination of well-written malware with well-designed email lures, which we call social malware, is devastatingly effective. Few organisations outside the defence and intelligence sector could withstand such an attack, and although this particular case involved the agents of a major power, the attack could in fact have been mounted by a capable motivated individual. This report is therefore of importance not just to companies who may attract the attention of government agencies, but to all organisations. As social-malware attacks spread, they are bound to target people such as accounts-payable and payroll staff who use computers to make payments. Prevention will be hard. The traditional defence against social malware in government agencies involves expensive and intrusive measures that range from mandatory access controls to tiresome operational security procedures. These will not be sustainable in the economy as a whole. Evolving practical low-cost defences against social-malware attacks will be a real challenge.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Look at Targeted Attacks Through the Lense of an NGO

We present an empirical analysis of targeted attacks against a human-rights Non-Governmental Organization (NGO) representing a minority living in China. In particular, we analyze the social engineering techniques, attack vectors, and malware employed in malicious emails received by two members of the NGO over a four-year period. We find that both the language and topic of the emails were highly...

متن کامل

Targeted Threat Index: Characterizing and Quantifying Politically-Motivated Targeted Malware

Targeted attacks on civil society and non-governmental organizations have gone underreported despite the fact that these organizations have been shown to be frequent targets of these attacks. In this paper, we shed light on targeted malware attacks faced by these organizations by studying malicious e-mails received by 10 civil society organizations (the majority of which are from groups related...

متن کامل

نقش و مفهوم اژدها در بافته های ایران و چین با تأکید بر دوره صفوی ایران و اواخر دوره مینگ و اوایل چینگ چین

The Iranian textures in the Safavid era are associated with some phenomena such as symbolism and myth. These textures contain some motifs that indicate the beliefs and ideas of the Iranian people, and these motifs have preserved the concepts over time. The dragon is one of these symbolic motifs whose presence can be traced back to the oldest literary sources in Iran's history. Dragon is referre...

متن کامل

The effect of rootstocks on sugars, acids, carotenoids, chlorophylls, and ethylene of Satsuma mandarin (Citrus unshiu)

This study aimed to evaluate the effect of rootstocks on fruit sugars, organic acids, and carotenoids. The contents of sugars and organic acids in fruits were determined by HPLC. Total acidity (TA), total soluble solids (TSS), and pH value of the juice were also evaluated. Total carotenoids and chlorophylls contents were measured using a spectrophotometer. The content of ethylene in fruits was ...

متن کامل

Measles Surveillance System in the Islamic Republic of Iran: History, Structures and Achievements

Background and Objectives: Elimination and eradication of measles requires designing and implementing an enhanced surveillance system. The purpose of this study was to review the measles surveillance system in Iran.   Methods: The data of this study were obtained from the surveillance system of the Center for Communicable Disease Control; a review of the records, documents, books, and publish...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2009