Inside Cyber Warfare - Jeffrey Carr [136]
[94] The FSTEC list tries to obfuscate by listing the 18th CRI as the organization requesting certification and Vch 11135 as the testing laboratory. However, the Russian tax identification number is the same for both, showing that they are the same organization. In short, the 18th CRI is certifying itself.
Internal Security Services: Federal Security Service (FSB), Ministry of Interior (MVD), and Federal Security Organization (FSO)
Russia’s Information Security Doctrine shows a tension between the government’s assessment that the Internet drives technical progress while spreading ideas threatening “Russia’s spiritual revival.” As a result, the FSB and the MVD have developed Internet-oriented components. These components are direct first at the internal threat to domestic stability. However, they also have offensive potential.
Federal Security Service Information Security Center (FSB ISC)—Military Unit (Vch) 64829
The FSB’s Information Security Center (FSB ISC) is the FSB’s component for counterintelligence operations involving Russia’s Internet (RuNET). FSB ISC operations include monitoring RuNET and analyzing Internet content. However, FSB ISC also plays a role in offensive IO.
The FSB’s Information Security Center was formed in 2002 when FSB Director Nikolay Patrushev reorganized the Department of Computer and Information Security. The reorganization transferred some administrative and developmental functions to other FSB components—including the Center for Communications Security; the Center for Licensing, Certification, and Protection of State Secrets; and the Scientific Technical Center—while focusing FSB ISC on counterintelligence operations on RuNET. FSB ISC is also designated as an FSB expert investigative center, performing forensic investigations for criminal prosecution. Russian law authorizes FSB ISC to conduct legal investigations and take action against Russian citizens. FSB ISC works closely with the Russian Ministry of the Interior Directorate K—the cyber crime directorate—headed by Lieutenant-General Boris Nikolayevich Miroshnikov, who transferred to the MVD after heading FSB ISC.
FSB ISC First Deputy Director Dmitri Frolov speaks frequently, stressing FSB ISC’s role in preventing terrorist and criminal activity on RuNET. Frolov also speaks on the FSB’s need for improved technical capabilities and increased legal authority to counter cyber terrorism and cyber crime.
The FSB monitors Internet traffic using hardware and software installed at Russian Internet Service Providers (ISPs), Internet access points, and Internet exchanges. The Internet monitoring system—known as SORM—was first established in the 1990s. The existing system began a major upgrade with contracts let during 2007 and 2008. The upgrade will enhance FSB ISC’s ability to remotely task the Internet monitoring system and analyze collected information offline in a dedicated center located at the FSB ISC building. The upgrade also enhances FSB ISC nonattributable Internet operations.
FSB ISC capabilities can be used for offensive purposes. In 2008 Cnews.ru quoted deputy head of the Russian Armed Force General Staff Major-General Aleksandr Burutin on Russian Information Operations. General Burutin stated that the FSB, along with the Ministry of Defense, was developing “special methods of conducting information warfare.” Websites named by FSB ISC First Deputy Director Frolov as supporting terrorist and extremist activity—such as Chechen-oriented Kavkazcenter.org—have suffered disruptive attacks. Russian press attributes the attacks to patriotic hackers, although they note FSB’s tacit approval.[95] After Wikileaks threatened to publish embarrassing information on Russia, including possible Russian intelligence service operations, a November 2010 article by Aleksey Mukhin stated that the FSB ISC had informed Russian leadership that Wikileaks could be rendered inaccessible forever “given the appropriate command.”
Russian Federal Security Service Center for Electronic Surveillance of Communications (FSB TSRRSS)