Defending Caribbean Networks: CaribNOG Strengthens Regional Technical Community

Recent attacks on Caribbean computer networks by Internet hackers should be a major concern for Caribbean businesses and governments.

“Computer hacking is a global problem," technology expert Bevil Wooding said at the fifth regional meeting of the Caribbean Network Operators Group (CaribNOG) in Bridgetown, Barbados.

"As the region increases in its dependence on information and communication technologies, it must at the same time build greater capacity to manage and protect its technology assets."

Wooding gave several examples from around the world of volunteer groups of ethical hackers who had mobilised to protect their local and regional networks.

“Since the Caribbean is no less vulnerable to cyberattacks, we must make similar investments in the development of our human resources. The region needs a trustworthy technical community, capable of defending Caribbean networks. CaribNOG is key part of the response to that challenge,” he said.

The Barbados meeting, CaribNOG’s largest to date, drew 100 tech practitioners from around the region and as far away as Africa, Europe and New Zealand. In his address, Wooding, one of the co-founders of CaribNOG, described the meetings as “invaluable for advancing the skills of the region’s ICT professionals who design, procure, operate, manage and secure the network infrastructure.”

The CaribNOG 5 program included a mix of hands-on technical training sessions delivered by regional and international facilitators. Topics covered over the three-day event included cybersecurity, Internet Exchange Point management, IPv6 deployment and DNSSEC implementation techniques.

“We need more people in the Caribbean with an advanced understanding network engineering. Diligent enough to stay current. But also bold enough to experiment and innovate to solve local as well as global needs.”

One major issue discussed at the event was the changeover from IPv4 to IPv6.

IPv4 protocol was developed as a management tool providing addresses for all devices that use the Internet in the 1970s and published in 1981. However, the number of devices now connected to the Internet may be equal to or exceed the global population. This explosion of IP enabled devices on the market has exhausted addresses under the IPv4 protocol.

Its replacement, IPv6, is the next-generation protocol, providing approximately 340 undecillion addresses (340 trillion trillion trillion) IP addresses. This is calculated to be sufficient to ensure the availability of IP addresses to meet the needs of the rapidly growing Internet, far into the future.

Wooding, an Internet Strategist with US-based research firm Packet Clearing House (PCH), also touched on the status of Internet Exchange Point (IXP) proliferation in the region. An IXP’s primary purpose is to allow networks to interconnect directly, resulting in savings in cost of delivering local Internet traffic, reduced latency and increased network resilience.

He charged participants to “embrace the opportunity to cooperate for the greater good”.

The three-day event was jointly hosted by the Caribbean Telecommunications Union (CTU), the American Registry for Internet Numbers (ARIN) and Packet Clearing House (PCH), with the support of the Government of Barbados, The Internet Society (ISOC), the Latin American and Caribbean Internet Addresses Registry (LACNIC) and Columbus Communications.

Is 2013 the Year of the Hacker?

The Caribbean is not the only region being hit by cybercriminals. Cyber attacks are big business.Norton's annual cybercrime report put the global cost of cybercrime in 2012 at $110 billion. According to the report, 1.5 million people are impacted every day across the world--close to 18 people per second. The highest numbers of cybercrime victims were found in Russia (92%), China (84%) and South Africa (80%).

 Nearly half of all adults online (46%) have first-hand experience of cybercrime, a slight rise from the 2011 figure of 45 per cent. Of real concern is an increase in cybercrime that takes advantage of social networks and mobile technology. 21 per cent have fallen prey to social or mobile crime. Specifically within social networking, the report found that 15 per cent of users have had their account infiltrated, and only half (49%) used privacy settings effectively to control the information they share.

 However, one commentator speculates that is not 2012 but 2013 that may well be remembered as the year of the hacker. And February was the bellwether. In that month alone, industry giants such as Facebook, Apple, Twitter and Microsoft, as well as large players like Dropbox and Evernote all officially acknowledged having fallen prey to cyber attacks.

On February 15, Facebook Security posted a statement acknowledging that their "systems had been targeted in a sophisticated attack".

 On February 19, Reuters reported that "unknown hackers infected the computers of some Apple workers when they visited a website for software developers that had been infected with malicious software."

Days later, Twitter disclosed that it had been breached February 1 and that hackers might have accessed some information on about 250,000 users, was hit in the same campaign that attacked Apple.

 On February 22, the general manager of Trustworthy Computing Security at software giant Microsoft confirmed that the company had experienced a security intrusion similar to breaches that occured at Facebook and Apple days before.

 A message posted by Dropbox in its own support forum in March did little to disconfirm rumours that it was still suffering from the vestiges of a major data breach it experienced last July.

Most recently, cloud storage provider Evernote was hacked and subsequently required all of its users to change their passwords.

Other attacks gain prominence because of the flambuoyant modus operandi of the agents involved. On February 18, hackers gained unauthorised access to Burger King’s Twitter account, transformed the company’s profile to promote McDonald’s new Fishy McBites and subsequently began tweeting increasingly inappropriate messages. Two days later, Jeep’s Twitter account was hacked and visitors to Jeep’s Twitter page saw a graphic header announcing that the Chrysler division had been sold to Cadillac.

 Cybersecurity issues also have a strong international relations undertone. The Washington Post, The New York Times, Bloomberg News and The Wall Street Journal are among a growing list of U.S. news organisations whose computers are thought to have been penetrated by Chinese hackers since 2012.

 On March 11, AFP reported that computer networks at the Reserve Bank of Australia had been hacked, “with some reportedly infected by Chinese-developed malware searching for sensitive information”. Meanwhile, Iranian media outlet PressTV recently reported that Chinese officials have identified the US as the source of over half of all the cyber attacks targeting the nation’s computer systems in the first two months of 2013 amid rising tensions between the two rivals over cyber intrusions.