Showing posts with label homeland security. Show all posts
Showing posts with label homeland security. Show all posts

Wednesday, April 09, 2008

U.S. Starts "Manhattan Project" on Cyber Security (Finally)

And it only took the resignation of four Cyber-Security Czars for them to get around to taking the threat seriously...

From Wired:

U.S. Has Launched a Cyber Security 'Manhattan Project,'
Homeland Security Chief Claims

SAN FRANCISCO -- The federal government has launched a cyber security "Manhattan Project," U.S. homeland security secretary Michael Chertoff said Tuesday, because online attacks can be a form of "devastating warfare", and equivalent in damage to "physical destruction of the worst kind."

Speaking to hundreds of security professionals at the RSA security conference, Chertoff cited last year's denial-of-service attacks against Estonia, and hypothetical hack attacks on financial networks and air traffic control systems, as proof that a federal strategy was needed.

"Imagine, if you will, a sophisticated attack on our financial systems that caused them to be paralyzed," Chertoff said. "It would shake the foundation of trust on which our financial system works."

...

The Bush administration's Cyber Initiative has gotten $150 million in funding for this year, and the administration is requesting $192 million for 2009.

Chertoff hopes that the government's new cyber security efforts will lead to technology breakthroughs that it can share with the private sector. Silicon Valley entrepreneur Rod Beckstrom was recently named to head that effort.

In fact, Chertoff imagines the government's cyber security center will transform its current intrusion detection system, named Einstein, into a pre-computer crime detector.

"We might have the ability to understand the signature of an attack before it is launched," Chertoff said. "I think it could become an early warning system that might be able to detect an attack before it is coming. Giving an adversary one bite at the apple before we understand the attack's meta data, or the code, is one bite too many."

One side-benefit of better cyber security is less identity and intellectual property theft...

I've been harping about the need for this for a long time. Its good to see DHS and the administration taking this seriously. The attack on Estonia as well as increased hacking by China into govt and private networks probably greatly contributed to the DHS finally taking network security seriously. I just wish that they had been more proactive in implementing this initiative. Given the amount of time it'll take the R&D people to come up with solutions our networks will continue to be vulnerable for a long while. In theory had we taken up a similar initiative shortly after 9/11 we could have already had security solutions in place by now.

However internet security tends to be reactive rather than proactive. So while I'm glad to see them finally getting the ball rolling on this I'm hoping they'll get everything up and running before the Zombies get us all.

Wednesday, June 20, 2007

Dept. of Homeland Security Hacked 800 Times

DHS acknowledges own computer break-ins

By TED BRIDIS, Associated Press Writer

The Homeland Security Department, the lead U.S. agency for fighting cyber threats, suffered more than 800 hacker break-ins, virus outbreaks and other computer security problems over two years, senior officials acknowledged to Congress.

In one instance, hacker tools for stealing passwords and other files were found on two internal Homeland Security computer systems. The agency's headquarters sought forensic help from the department's own Security Operations Center and the U.S. Computer Emergency Readiness Team it operates with Carnegie Mellon University.

In other cases, computer workstations in the Coast Guard and the Transportation Security Administration were infected with malicious software detected trying to communicate with outsiders; laptops were discovered missing; and agency Web sites suffered break-ins.

The chairman of the House Homeland Security Committee, Rep. Bennie Thompson, D-Miss., said such problems undermine the government's efforts to encourage companies and private organizations to improve cyber security.

"What the department is doing on its own networks speaks so loudly that the message is not getting across," Thompson said.

Congressional investigators, expected to testify Wednesday during an oversight hearing about the department's security lapses, determined that persistent weaknesses "threaten the confidentiality, integrity and availability of key DHS information and information systems," according to a new report from the Government Accountability Office being released later in June.

The Homeland Security Department's chief information officer, Scott Charbo, assured lawmakers his organization was working to prevent such problems. more

Boy, doesn't that just make you feel safe? DHS is now on its fourth cybersecurity chief in six. years. That seems like a high turnover rate for such an important job. But maybe that's because they still aren't taking the threat seriously enough.

Former cybersecurity chief Richard Clarke once stated in an interview:

"We, as a country, have put all of our eggs in one basket. The reason that we're successfully dominating the world economically and militarily is because of systems that we have designed, and rely upon, which are cyber-based. It's our Achilles heel. It's an overused phrase, but it's absolutely true.

It could be that, in the future, people will look back on the American empire, the economic empire and the military empire, and say, "They didn't realize that they were building their whole empire on a fragile base. They had changed that base from brick and mortar to bits and bytes, and they never fortified it. Therefore, some enemy some day was able to come around and knock the whole empire over." That's the fear."

Take some time to read the full interview here.