Cyberattaque mondiale : pourquoi Israël a été épargné

[:fr]150 pays sont affectés par une cyberattaque d’une ampleur inédite depuis vendredi. En Israël, où la cybersécurité est une priorité nationale, les dégâts sont mineurs. Au moins 150 pays ont été touchés par la cyberattaque mondiale sans précédent lancée vendredi 12 mai. Parmi les rares pays épargnés : Israël. L’Etat hébreu a fait de la cybersécurité l’une de ses priorités en dotant son armée d’une unité d’élite consacrée à l’informatique et tournée vers la cybersécurité : l’unité 8200. Les futurs experts sont recrutés dans les lycées et formés dans deux centres dédiés au perfectionnement informatique.

Israël, qui a des ennemis déclarés, est régulièrement la cible d’activistes opposés à l’occupation. Un risque pris très au sérieux par l’armée. Selon la presse israélienne, l’Iran a également tenté de s’attaquer récemment au réseau informatique national, sans succès.

Un demi-milliard de dollars investis dans la cybersécurité en 2016

Ce week-end, le Premier ministre israélien, Benyamin Netanyahou, s’est félicité de la capacité de résistance du pays. D’après un officier cité par le journal Maariv, le « rançongiciel » utilisé était connu depuis mars dernier. Enjeu militaire, la cybersécurité est aussi un enjeu économique pour Israël. Depuis 2010, les entreprises spécialisées se multiplient. En 2016, un demi-milliard de dollars a été investi dans 365 sociétés d’après des éléments révélés lors du dernier salon consacré à la cybertechnologie. 1 600 emplois sont à pourvoir dans le secteur.

Source francetvinfo

En savoir plus : « 22 mai 2014, présentation par Inbal Arieli de l’incubateur EISP« [:en]

While Israel is preparing for a cyber attack liable to hit in full force this week, defense systems personnel are carefully assessing the worldwide attack and seeing the positive results of the systems they developed. The attack struck almost 100 countries. In most cases, ransom was demanded from the user in return for reactivating the system. Among other things, the attack damaged health services, communications, and deliveries. The experts stressed the importance of the national center for cyber threats (CERT), and expressed some optimism about Israel’s readiness for the attack.

CyberGrip owner Adam Feld: Hackers don’t wait. As soon as they learn about a breach, they go into action. »

« It is important to keep in mind that the hackers don’t wait. As soon as they learn about a breach, whether or not it’s reported, they go into action, » said Adam Feld, owner of CyberGrip, a company that provides consultation and advanced cyber defense services. « It is therefore very likely that the attack was planned and executed a few days after WikiLeaks exposed the breach, » he added, referring to the leaking three months ago of the encryption methods used by the US National Security Agency (NSA).

Feld also said, « The fact that hundreds of thousands of computers worldwide, including government agencies and essential infrastructure entities, were exposed for a prolonged period following what happened at NSA demonstrates how important the involvement of a Global agency like CERT is in managing the event like a responsible adult and warning ahead of time about the potential damage. It is also correct to reassess how decisions are made in organizations about the inclusion of defense products, and whether those products that were supported by the research companies really prevented a disaster by offering their own relevant updates in real time. »

Marketing and communications consultant Anat Miron, who has worked with the cyber industry for 17 years, said, « It was interesting to following the activity at the end of last week of the Israel CERT, which hastened to respond to the events responsibly and professionally. After many years in which any change on a home page of obscure websites was portrayed as a ‘cyber attack,’ we have received a small taste of the real meaning of the term. Even if it takes a little time before they manage to investigate the entire event and understand what really happened, it can already be assumed, at least at the macro level, that the attack involved a worm sent a few days after the breach was revealed, and remained dormant waiting for the crucial day, because it is illogical to think that the attackers were relying on an active opening of hundreds of thousands files at the same second. »

« The breach was exposed a month ago, and a security update for it was offered. Organizations that took care to prepare their systems again in advance avoided the attack, » said Eyal Wachsman, CEO of Cymulate, which recently raised $3 million from US investment fund Susquehanna International Group. « Organizations that forgot or ignored the breach, or assumed that it wouldn’t happen to them are now learning how important it is to check yourself daily and hourly, even if you checked the system at the beginning of the day. »

Wachsman added, « Our system detected thousands of computers requiring an update in order to plug up the reported breach, and we’re continuing our recommendation of repeated scans in order to ensure that the systems are proof against any renewed version of the worm. Fortunately, our customers in Israel and around the world reported that an attack on their systems had been attempted, but due to Cymulate’s ability to warn against the weakness six weeks ago, they were not damaged, and the defense systems did exactly what was expected of them. »

Minister of National Infrastructure, Energy, and Water Resources Yuval Steinitz today declared a high cyber alert at Israel’s energy and water resources as a result of the cyber attack. Over the past 24 hours, action was taken at the Ministry of National Infrastructure, Energy, and Water Resources, Israel Electric Corporation (IEC) (TASE: ELEC.B22), power stations, and energy and water infrastructure to strengthen the computer defense and increase the alert in accordance with form taken by the current wave of worldwide attacks.

These actions were coordinated by the Ministry of National Infrastructure, Energy, and Water Resources cyber center founded a year ago in order to protect Israel’s energy infrastructure against a network attack.

Source globes.co.il

[:]