The sum of all the fears

20/03/15

An unusual activity on web traffic out of Texas and directed to the United Kingdom was routed through Ukrainian and Russian telecommunications systems. An apparently unusual deviation and perhaps the result of an error.

Network traffic often requires a tortuous route due to web congestion or difficulties with interconnection, but neither would be sufficient to justify such an unusual path.

The mistake may have been engendered by the Ukrainian telecommunications company Vega, which inadvertently redirected web traffic between the United States and the United Kingdom, but if that were the case, it would have had an effect that was not so far-reaching.

This phenomenon is known as "route hijacking" and is a common security problem for network technicians, but in this case it involved particularly sensitive and protected sites: the Atomic Weapons Establishment, which manages the nuclear warheads of the United Kingdom; Royal Mail and the American defense Contractor Lockheed Martin.

The traffic was obviously encrypted, but not the IP addresses and this exposed the companies involved in cyber attacks, with the danger that the data exchanged on the network could undergo changes.

The routing tables, called "traceroute", can be easily consulted, as public, so it was easy to verify exactly when and how the hijacking of the route occurred. The reason has not yet been clarified, but above all it is not possible to demonstrate the reliability of the information transited, as it may have been modified by hackers.

The analyzed traceroute reveals that there was an interconnection between Ukraine and Russia, so the two nations are involved in this matter, because they were the targets of an event that convinced the Russian Ministry of Defense to investigate 'it happened.

The decision to investigate the case is mainly linked to an unequivocal message that appeared on Vega's computers. The assignment was entrusted to the FSB which, in collaboration with the Kaspersky laboratory, Лаборатория Касперского, a Moscow-based company specializing in information security products, discovered an NSA computer attack, the purpose of which was to cancel the Russian strategic defenses and to issue a precise order.

Kaspernsky's experts were able to isolate the malware, and used it to decipher the content of information traffic. The latter revealed a nuclear attack plan against Russia that was to be launched by Britain. Verge had unintentionally discovered "A Network Error Routed Traffic For The UK's Nuclear Weapons Agency Through Russian Telecom".

It could have been a simple exercise, but this made it necessary to secure President Vladimir Putin and put the Russian strategic nuclear forces in a state of alarm. This alert lasted ten days, during which the whole world wondered why the Russian President was not informed.

It is plausible that this was an exercise, but also that the involuntary intervention of Vega, has deprived the decisive factor of surprise, of the NATO attack plan.

Giovanni Caprara

Source: Vega telecom