Showing posts with label trojans. Show all posts
Showing posts with label trojans. Show all posts

Tuesday, January 24, 2012

Rice lab mimics Jupiter's Trojan asteroids inside a single atom - YouTube



Rice University physicists have built an accurate model of part of the solar system inside a single atom.

In a new paper in Physical Review Letters, Rice's team and collaborators from Oak Ridge National Laboratory and the Vienna University of Technology showed they could make an electron orbit the atomic nucleus in the same way that Jupiter's Trojan asteroids orbit the sun.

The findings uphold a 1920 prediction by physicist Niels Bohr.

"Bohr predicted that quantum mechanical descriptions of the physical world would, for systems of sufficient size, match the classical descriptions provided by Newtonian mechanics," said lead researcher Barry Dunning, Rice's Sam and Helen Worden Professor of Physics and chair of the Department of Physics and Astronomy.

"Bohr also described the conditions under which this correspondence could be observed. In particular, he said it should be seen in atoms with very high principal quantum numbers, which are exactly what we study in our laboratory."

Bohr was a pioneer of . His 1913 atomic model, which is still widely invoked today, postulated a small nucleus surrounded by electrons moving in well-defined orbits and shells.

The word "quantum" in quantum mechanics derives from the fact that these orbits can have only certain well-defined energies.

Jumps between these orbits lead to absorption or emission of specific amounts of energy termed quanta.

As an electron gains energy, its quantum number increases, and it jumps to higher orbits that circle ever farther from the nucleus.

In the new experiments, Rice graduate students Brendan Wyker and Shuzhen Ye began by using an to create a Rydberg atom.

Rydberg atoms contain a highly excited electron with a very large quantum number. In the Rice experiments, potassium atoms with quantum numbers between 300 and 600 were studied.

Wednesday, July 27, 2011

Trojan asteroid: Earth stalker found in eternal twilight

AN ASTEROID 300 metres in diameter is stalking the Earth. 

Hiding in the pre-dawn twilight, it has marched in lockstep with our planet for years, all but invisible to our telescopes.

The rock is Earth's first confirmed Trojan, which can orbit the sun in either of two gravitational wells along the same orbital path as our planet. 

From the sun's point of view, these wells lie 60 degrees ahead of and behind the Earth, at Lagrange points where gravitational forces between the sun and the Earth balance out.

Trojans are common - Jupiter alone boasts about 5000, and Neptune and Mars each have their own smaller collections. But finding Earth's has proven difficult, because the Lagrange points lie towards the sun in the sky. 

Astronomers must look for the objects just before the sun rises or after it sets, and until now the glare of this sunlight has obscured the feeble light reflected from any rocks that might be hiding there.

Now Martin Connors of Athabasca University in Alberta, Canada, and colleagues have used a heat sensor to see past the gloaming. Using data from NASA's Wide-field Infrared Survey Explorer (WISE) satellite, they identified a 300-metre-wide Trojan now dubbed 2010 TK7.

The rock is leading the Earth, and based on the team's calculations it is expected to be stable in an elliptical orbit around its Lagrange point for at least the next 10,000 years, drifting at between 20 million and 300 million kilometres from us (Nature, DOI: 10.138/nature/10233).

Like most Trojans, says Connors, the story of where 2010 TK7 came from, and what it is made of, is an utter mystery.

It could be an errant, captured asteroid, or perhaps a "genesis rock" - a long-sought relic from the birth of the solar system about 4.5 billion years ago. 

If so, it may be identical to the rocks that came together to form the Earth, which means that studying its composition would tell us what the chemistry of our planet was like in the earliest stages of its existence.

Sunday, August 9, 2009

White Hats versus the Black Hats: Virtual Army takes on Conficker Worm and the Evil Botnets

"So we meet again in Cyberspace! Only this time I have the evil Conficker worms to do my bidding! "

Unfortunately, it's not another dubious plot in a Bond movie, its' real life in the virtual world of Cyberspace.

More than 1 million 'super-hero' virtual computers are set to provide insight into how the evil 'super-villain' botnets, networks of infected computers wreak havoc on the internet.

The Conficker worm is currently the most infamous and notorious of these. Much has been written about the damage it has done recently and much time nd effort is going into counter-measures.

Ron Minnich and Don Rudish of Sandia National Laboratories in Livermore, California, crammed 250 independent linux "kernels" - the core system of a computer - onto each of 4400 networked Thunderbird machines, creating a total of over 1.1 million individual virtual computers.

While this network cannot mimic the internet's estimated 600 million computers, the duo hope to use it to study how a small number of machines can attack and bring down larger networks. They can also study, for example, why some botnets prefer to be small and others large.

A good anti-Malware application will detect a high percentage of botnets but not the very smart ones. The most insidious of the botnets are the ones that use stealth to infect and remain resident and undetected on a "victim's" system. Good Luck guys!

Thursday, July 30, 2009

Severe Threat: Clampi Trojan revealed as financial-plundering botnet monster

A close look at the Clampi Trojan, an elusive piece of malware that uses encryption to help hide its nefarious data-stealing deeds, reveals it to be a botnet-controlled monster that can swipe a victim's sensitive data associated with more than 4,500 different sites, according to one researcher.

"We've been able to get through the layers of encryption in Clampi," says Joe Stewart, director of malware research at SecureWorks. "Clampi is collecting data associated with about 4,600 key sites, such as banks and other financial institutions targeted by criminal networks."

But it doesn't stop there.
Clampi is going after utilities, market research firms, online casinos and career sites, in a broad sweep to grab personally identifiable information, such as credentials and account information, that might be of use to criminals for financial gain. Clampi, also known as Ligats, Ilomo or Rscan, is using psexec tools to spread across Microsoft-based networks in a worm-like fashion.

SecureWorks
So far, the analysis by SecureWorks has identified 1,400 specific sites in 70 countries out of the 4,600 or so total sites the Clampi Trojan appears programmed to monitor once it has infected a victim's Windows-based machine.

The design
The design of the Clampi Trojan, which was first spotted in 2007, reveals its creator has gone out and methodically figured out a lot about the target sites.

He says the 4,600 number is enormous in comparison to what is usually found in Trojans designed for stealing financial data from victims trying to conduct transactions at online Web sites. Most Trojans of this sort, such as Zeus, normally would have not more than 30 banks as a target.

A Worm
The Clampi Trojan, once it worms its way into a victim's machine, will watch for the victim to try and do anything online associated with any of the 4,600 different sites and then leap into action to steal data, transferring it via an encrypted channel back to command-and-control servers.

According to SecureWorks, Clampi's main way of spreading is through drive-by downloads when a user visits a Web site that has been compromised by attackers.

Trusted Sites
Some of these sites may be trusted as legitimate by Web visitors, but the site has been compromised, often because the Webmaster or network manager security credentials for it have been stolen and the attacker has simply loaded up the malware to enable the Clampi drive-by download.

The Clampi Trojan, believed to have infected hundreds of thousands of machines, basically functions as a botnet under the command-and-control of a botmaster, probably in Eastern Europe or China.

Botnet
As a botnet, it is sweeping up victim's sensitive personal data and sending it back through a set of command-and-control servers to cybercriminals. Clampi seems to be picking up speed in its spread since July and may be the Trojan used in a cybertheft scam that hit the US earlier this month.

Command and Control
The Clampi command-and-control server is encrypted by 448-bit blowfish encryption, using a randomly generated key that is sent to the control server using 2,048-bit RSA encryption. SecureWorks got through the encryption layer by intercepting the session key in a test system and decrypting the network traffic. This allowed the security firm to examine the list of Web sites targeted by a module that's part of Clampi.

How can you defend yourself against Clampi?
There is no product you can buy to stop this as a zero-day attack, although antivirus software might eventually detect it and stop it later on your machine.

The best recommendation, is to find a way to use a "separate system" to conduct financial transactions, one that is not the same system as you might use to browse the Internet. That would lower the risk of being infected by the Clampi Trojan.

Wednesday, June 17, 2009

ATMs and Cash machines hacked

"SKULDUGGERY," says Andrew Henwood, "is a very good word to describe what this extremely advanced, cleverly written malware gets up to. We've never seen anything like it."

What he has discovered is a devious piece of criminal coding that has been quietly at work in a clutch of cash machines at banks in Russia and Ukraine. It allows a gang member to walk up to an ATM, insert a "trigger" card, and use the machine's receipt printer to produce a list of all the debit card numbers used that day, including their start and expiry dates - and their PINs. Everything needed, in fact, to clone those cards and start emptying bank accounts. In some cases, the malicious software even allows the criminal to eject the machine's banknote storage cassette into the street.

The software is the latest move in a security arms race after banks and consumers got wise to the fitting of fake fascias onto ATMs. These fascias have been criminals' main way of using ATMs to get the details they need to clone cards. They contain a camera to spy on PINs being entered on the keypad, and a card reader to skim data from the card's magnetic stripe. It's big business: across Europe, losses due to such fraud grew by 11 per cent to €484 million in 2008, according to the European ATM Security Team (EAST), funded by the European Union and based in Edinburgh, UK (see graph).

Banks responded by investing in anti-skimming technology - which can detect a fake fascia overlay and disable the ATM. So crooks are developing new tricks, which are being uncovered by Henwood and his colleagues at SpiderLabs, a computer forensics research centre in London.

Monday, May 25, 2009

FBI Shutdown by Mysterious Virus Attack!

The FBI and the U.S. Marshals Service were forced to shut down parts of their computer networks after a mystery virus struck the law-enforcement agencies.

A spokesperson for the U.S. Marshals Service confirmed that it had disconnected from Justice Department computers as a precaution after being hit with the virus, while an FBI spokesperson would only say that it was experiencing similar issues.

"We too are evaluating a network issue on our external, unclassified network that's affecting several government agencies," reported FBI spokesman Mike Kortan.

The virus' type and origin are unknown, but spokespeople for both agencies said agencies' access to the Internet and e-mail was shut down while the issue was evaluated.

Government regulations require agencies to report any security issues to US-Computer Emergency Readiness Team (US-CERT), but a call to CERT late Thursday for comment was not immediately returned.

All this following reports that a number of unfriendly governments may have penetrated the US Government sites and planted spybots, viruses, trojans, etc.