{"id":973,"date":"2010-06-02T02:22:34","date_gmt":"2010-06-02T09:22:34","guid":{"rendered":"http:\/\/lifeboat.com\/blog\/?p=973"},"modified":"2010-06-02T02:22:34","modified_gmt":"2010-06-02T09:22:34","slug":"new-terrorism-five-days-in-manhattan","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2010\/06\/new-terrorism-five-days-in-manhattan","title":{"rendered":"New Terrorism: Five days in Manhattan"},"content":{"rendered":"<p style=\"text-align: justify\"><a href=\"http:\/\/roderickbjones.com\/\"><em><span style=\"\">Originally posted @ Perspective Intelligence<\/span><\/em><\/a><\/p>\n<p style=\"text-align: justify\"><span style=\"\">Two events centered on New York City separated by five days demonstrated the end of one phase of terrorism and the pending arrival of the next. The failed car-bombing in Times square and the dizzying stock market crash less than a week later mark the book ends of terrorist eras.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"\">The attempt by <\/span><a href=\"http:\/\/en.wikipedia.org\/wiki\/Faisal_Shahzad\"><span style=\"\">Faisal Shahzad<\/span><\/a><span style=\"\"> to detonate a car bomb in Times Square was notable not just for its failure but also the severely limited systemic impact a car-bomb could have, even when exploding in crowded urban center. Car-bombs or Vehicle-Borne IED\u2019s have a long history (incidentally one of the first was the <\/span><a href=\"http:\/\/en.wikipedia.org\/wiki\/Wall_Street_bombing\"><span style=\"\">1920 \u2018cart and horse bomb\u2019<\/span><\/a><span style=\"\"> in Wall Street, which killed 38 people). VBIED\u2019s remain deadly as a tactic within an insurgency or warfare setting but with regard to modern urban terrorism the world has moved on. We are now living within a highly virtualized system and the dizzying <\/span><a href=\"http:\/\/www.streetinsider.com\/Insider+Trades\/May+6th+Market+Crash+-+Rage+Against+The+Machine,+Or+the+Human%3F\/5609781.html\"><span style=\"\">stock-market crash on the 6th May 2010<\/span><\/a><span style=\"\"> shows how vulnerable this system is to digital failure. While the NYSE building probably remains a symbolic target for some terrorists a deadly and capable adversary would ignore this physical manifestation of the financial system and disrupt the data-centers, software and routers that make the global financial system tick. Shahzad\u2019s attempted car-bomb was from another age and posed no overarching risk to western societies. The same cannot be said of the vulnerable and highly unstable financial system.<\/span><\/p>\n<p style=\"text-align: justify\"><strong><span style=\"\"> Computer aided crash (proof of concept for future cyber-attack)<\/span><\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"\">There has yet to be a definitive explanation of how stocks such as <\/span><a href=\"http:\/\/www.google.com\/finance?chdnp=1&amp;chdd=1&amp;chds=1&amp;chdv=1&amp;chvs=maximized&amp;chdeh=0&amp;chfdeh=0&amp;chdet=1273733091264&amp;chddm=1955&amp;chls=IntervalBasedLine&amp;q=NYSE:PG&amp;ntsp=0\"><span style=\"\">Proctor and Gamble<\/span><\/a><span style=\"\"> plunged 47% and the normally solid <\/span><a href=\"http:\/\/www.google.com\/finance?chdnp=1&amp;chdd=1&amp;chds=1&amp;chdv=1&amp;chvs=maximized&amp;chdeh=0&amp;chfdeh=0&amp;chdet=1273696444905&amp;chddm=1955&amp;chls=IntervalBasedLine&amp;q=NYSE:ACN&amp;ntsp=0\"><span style=\"\">Accenture plunged<\/span><\/a><span style=\"\"> from a value of roughly $40 to one cent, based on no external input of information into the financial system. The <\/span><a href=\"http:\/\/www.sec.gov\/\"><span style=\"\">SEC<\/span><\/a><span style=\"\"> has issued directives in recent years boosting competition and lowering commissions, which has had the effect of fragmenting equity trading around the US and making it highly automated. This has created four leading exchanges, <\/span><a href=\"http:\/\/www.nyse.com\/\"><span style=\"\">NYSE Euronext<\/span><\/a><span style=\"\">, <\/span><a href=\"http:\/\/www.nasdaqomx.com\/\"><span style=\"\">Nasdaq OMX Group<\/span><\/a><span style=\"\">, <\/span><a href=\"http:\/\/batstrading.com\/\"><span style=\"\">Bats Global Market<\/span><\/a><span style=\"\"> and <\/span><a href=\"http:\/\/www.directedge.com\/\"><span style=\"\">Direct Edge<\/span><\/a><span style=\"\"> and secondary exchanges include <\/span><a href=\"http:\/\/www.ise.com\/\"><span style=\"\">International Securities Exchange<\/span><\/a><span style=\"\">, <\/span><a href=\"http:\/\/www.cboe.com\/\"><span style=\"\">Chicago Board Options Exchange<\/span><\/a><span style=\"\">, the <\/span><a href=\"http:\/\/www.cmegroup.com\/\"><span style=\"\">CME Group<\/span><\/a><span style=\"\"> and the <\/span><a href=\"https:\/\/www.theice.com\"><span style=\"\">Intercontinental Exchange<\/span><\/a><span style=\"\">. There are also broker-run matching systems like those run by <\/span><a href=\"http:\/\/www.knight.com\/ourofferings\/rule605.asp\"><span style=\"\">Knight<\/span><\/a><span style=\"\"> and <\/span><a href=\"http:\/\/www.itg.com\"><span style=\"\">ITG<\/span><\/a><span style=\"\"> and so called \u2018<\/span><a href=\"http:\/\/en.wikipedia.org\/wiki\/Dark_pools_of_liquidity\"><span style=\"\">dark-pools<\/span><\/a><span style=\"\">\u2019 where trades are matched privately with prices posted publicly only after trades are done. As similar picture has emerged in Europe, where rules allowing competition with established exchanges and known by the acronym \u201c<\/span><a href=\"http:\/\/ec.europa.eu\/internal_market\/securities\/isd\/index_en.htm\"><span style=\"\">Mifid<\/span><\/a><span style=\"\">\u201d have led to a similar explosion of types and venues.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"\">To navigate this confusing picture traders have to rely on \u2018<\/span><a href=\"http:\/\/gmi.ml.com\/sor\/\"><span style=\"\">smart order routers<\/span><\/a><span style=\"\">\u2019 \u2013 electronic systems that seek the best price across all of the platforms. Therefore, trades are done in vast data centers \u2013 not in exchange buildings. This total automation of trading allows for the use of a variety of \u2018<\/span><a href=\"http:\/\/en.wikipedia.org\/wiki\/Algorithmic_trading\"><span style=\"\">trading algorithms<\/span><\/a><span style=\"\">\u2019 to manage investment themes. The best known of these is a \u2018Volume Algo\u2019, which ensures throughout the day that a trader maintains his holding in a share at a pre-set percentage of that share\u2019s overall volume, automatically adjusting buy and sell instructions to ensure that percentage remains stable whatever the market conditions. Algorithms such as this have been blamed for exacerbating the rapid price moves on May 6th. High-frequency traders are the biggest proponents of algos and they account for up to 60% of US equity trading.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"\">The most likely cause of the collapse on May 6th was the slowing down or near stop on one side of the trading pool. So in very basic terms a large number of sell orders started backing up on one side of the system (at the speed of light) with no counter-parties taking the order on the other side of the trade. The counter-party side of the trade slowed or stopped causing this almost instant pile-up of orders. The algorithms on the other side finding no buyer for their stocks kept offering lower prices (as per their software) until they attracted a buyer. However, as no buyer\u2019s appeared on the still slowed or stopped counter-party side prices tumbled at an alarming rate. Fingers have pointed at the NYSE for causing the slow down on one side of the trading pool as it instituted some kind of circuit breaker into the system, which caused all the other exchanges to pile-up on the other side of the trade. There has also been a focus on <\/span><a href=\"http:\/\/dealbook.blogs.nytimes.com\/2010\/05\/12\/market-inquiry-focuses-on-one-trader\/\"><span style=\"\">one particular trade<\/span><\/a><span style=\"\">, which may have been the spark igniting the NYSE \u2018circuit breaker\u2019. Whatever the precise cause, once events were set in train the system had in no way caught up with the new realities of automated trading and diversified exchanges.<\/span><\/p>\n<p style=\"text-align: justify\"><strong><span style=\"\">More nodes same assumptions<\/span><\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"\">On one level this seems to defy conventional thinking about security \u2013 more diversity greater strength \u2013 not all nodes in a network can be compromised at the same time. By having a greater number of exchanges surely the US and global financial system is more secure? However, in this case, the theory collapses quickly if thinking is switched from examining the physical to the virtual. While all of the exchanges are physically and operationally separate they all seemingly share the same software and crucially trading algorithms that all have some of the same assumptions. In this case they all assumed that because they could find no counter-party to the trade they needed to lower the price (at the speed of light). The system is therefore highly vulnerable because it relies on one set of assumptions that have been programmed into lighting fast algorithms. If a national circuit breaker could be implemented (which remains doubtful) then this could slow rapid descent but it doesn\u2019t take away the power of the algorithms \u2013 which are always going to act in certain fundamental ways ie continue to lower the offer price if they obtain no buy order. What needs to be understood are the fundamental ways in which all the trading algorithms move in concert. All will have variances but they will all share key similarities, understanding these should lead to the design of logic circuit breakers.<\/span><\/p>\n<p style=\"text-align: justify\"><strong><span style=\"\">New Terrorism<\/span><\/strong><\/p>\n<p style=\"text-align: justify\"><span style=\"\">However, for now the system looks desperately vulnerable to both generalized and targeted cyber attack and this is the opportunity for the next generation of terrorists. There has been little discussion as to whether the events of last Thursday were prompted by malicious means but it certainly is worth mentioning. At a time when Greece was burning launching a cyber attack against this part of the US financial system would clearly have been stunningly effective. Combining political instability with a cyber attack against the US financial system would create enough doubt about the cause of a market drop for the collapse gain rapid traction. Using targeted cyber attacks to stop one side of the trade within these exchanges (which are all highly automated and networked) would, as has now been proven, cause a dramatic collapse. This could also be adapted and targeted at specific companies or asset classes to cause a collapse in price. A scenario where-by one of the exchanges slows down its trades surrounding the stock of a company the bad-actor is targeting seems both plausible and effective.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"\">A hybrid cyber and kinetic attack could also cause similar damage \u2013 as most trades are now conducted within data-centers \u2013 it begs the question why are there armed guards outside the NYSE \u2013 of course if retains some symbolic value but security resources would be better placed outside of the data-centers where these trades are being conducted. A kinetic attack against financial data centers responsible for these trades would surely have a devastating effect. Finding the <\/span><a href=\"http:\/\/online.wsj.com\/article\/SB124890969888291807.html\"><span style=\"\">location of these data centers<\/span><\/a><span style=\"\"> is as simple as conducting a Google search.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"\">In order for terrorism to have impact in the future it needs to shift its focus from the weapons of the 20th Century to those of the present day. Using their current tactics the <\/span><a href=\"http:\/\/en.wikipedia.org\/wiki\/Tehrik-i-Taliban_Pakistan\"><span style=\"\">Pakistan Taliban<\/span><\/a><span style=\"\"> and their assorted fellow-travelers cannot fundamentally damage western society. That battle is over. However, the next era of conflict motivated by a radicalism from as yet unknown grievances, fueled by a globally networked generation Y, their cyber weapons of choice and the precise application of ultra-violence and information spin has dawned. Five days in Manhattan flashed a light on this new era.<\/span><\/p>\n<p style=\"text-align: justify\"><a href=\"http:\/\/roderickbjones.com\/\"><span style=\"\">Roderick Jones<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Originally posted @ Perspective Intelligence Two events centered on New York City separated by five days demonstrated the end of one phase of terrorism and the pending arrival of the next. The failed car-bombing in Times square and the dizzying stock market crash less than a week later mark the book ends of terrorist eras. [\u2026]<\/p>\n","protected":false},"author":58,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35,34,14,45],"tags":[156,157,155],"class_list":["post-973","post","type-post","status-publish","format-standard","hentry","category-counterterrorism","category-cybercrime-malcode","category-defense","category-finance","tag-cyber","tag-flash-crash","tag-terrorism"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/973","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/58"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=973"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/973\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=973"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=973"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=973"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}