Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Sunday, July 19, 2009

Cybersecurity: Senate bill would make international cooperation a priority

US and EU are both going in the direction of International cooperation. On the 30th of March 2009, European Commission Directorate General Information Society and Media released a communication on Critical Information Infrastructure Protection. Below you find an articole abou the new US legislation proposal, introduced on July 10.

Apart from the declarations, we need to define the building blocks of international cooperation. In particular:
a. Research funds that can be obtained by international consortia (all US and UE funds are closed only to US or EU members)
b. Cooperation legislation framework: a new legislation framework should be defined in order to allow exchange of data (data sets for researchers), information sharing (threats, vulnerabilities, incidents) and information exchanges between operators and government agencies from the same sectors
c. Establish clear point of contacts and responsibilities: who do you contact in US or EU in case of incidens/attacks
d. Exercices and simulations

(FederalComputerWeek) A new Senate bill would encourage the secretary of state to work with other governments to further cooperation on cybersecurity and would require the secretary to submit a report to Congress about those efforts.

The legislation, introduced by Sen. Kirsten Gillibrand (D-N.Y.) on July 10, states the secretary should work with other governments to:

  • Develop cooperative activities.
  • Encourage international cooperation for improving cybersecurity.
  • Develop safeguards for privacy, freedom of speech and commercial transactions to be included in agreements or other cybersecurity activities.

The bill would require the secretary to submit a detailed report to congressional committees about actions taken to meet these goals in 270 days of the legislation’s enactment.

“Relevant international cybersecurity agreements focus only on issues relating to cyber crime and common operating standards, and have not been signed by certain countries from which cyberattacks may be launched,” the bill states.

The Obama administration’s cyberspace policy review, released in May, also emphasized the need for international cooperation to secure cyberspace.

"International norms are critical to establishing a secure and thriving digital infrastructure," the policy review states. "The United States needs to develop a strategy designed to shape the international environment and bring like-minded nations together on a host of issues, including acceptable norms regarding territorial jurisdiction, sovereign responsibility, and use of force."

The review recommended that the government develop positions for an international cybersecurity policy framework and strengthen its international partnerships related to cybersecurity.



Wednesday, July 15, 2009

UK Cyber-security strategy launched

(BBC)

Britons face a growing online threat from criminals, terrorists and hostile states, according to the UK's first cyber security strategy.

Businesses, government and ordinary people are all at risk, it says.

The strategy has been published alongside an updated, wider National Security Strategy.

Its publication is a sign of the growing recognition within government of the need to bolster defences against a growing threat.

In line with a wider focus within the National Security Strategy on not just protecting the state but also citizens, the cyber-strategy encompasses protecting individuals from forms of fraud, identity theft and e-crime committed using technology as well as defending government secrets and businesses.

'Attack capability'

Launching the strategy, cyber security minister Lord West said: "We know that various state actors are very interested in cyber warfare. The terrorist aspect of this is the least (concern), but it is developing."

He warned that future targets could include key businesses, the national power grid, financial markets and Whitehall departments.

He said: "We know terrorists use the internet for radicalisation and things like that at the moment, but there is a fear they will move down that path (of cyber attacks).

"As their ability to use the web and the net grows, there will be more opportunity for these attacks."

He confirmed that the UK government has already faced cyber attacks from foreign states such as Russia and China.

But he denied that hackers had successfully broken into government systems and stolen secret information.

He also said he could not deny that the government had its own online attack capability, but he refused to say whether it had ever been used.

"It would be silly to say that we don't have any capability to do offensive work from Cheltenham, and I don't think I should say any more than that."

'Missed opportunity'

Among those the government has turned to for help on cyber crime are former illegal hackers, Lord West added.

He said the government listening post GCHQ at Cheltenham had not employed any "ultra, ultra criminals" but needed the expertise of former "naughty boys" he said.

"You need youngsters who are deep into this stuff... If they have been slightly naughty boys, very often they really enjoy stopping other naughty boys," he said.

Dame Pauline Neville-Jones, for the Conservatives, called the strategy was a "missed opportunity".

"It is impossible to know how significant these announcements are because we do not know what funding will be made available to enhance our ability to tackle cyber threats. It is also not clear how these new cyber security structures fit into the existing national security machinery."

Her colleague in the Commons, Crispin Blunt, called it a "pale imitation" of an initiative launched by US President Barack Obama.

Lib Dem home affairs spokesman Tom Brake said: "This new cyber security strategy could lead to an extension of the Government's invasive counter-terrorism powers which already pose significant threats to our civil liberties.

"The cyber security strategy uses broad, undefined terms that risk creating panic among the public and a demand for further government powers. We must not retreat into a Cold War mentality."

'Forensics'

Officials said e-crime crime is estimated to costs the UK several billion pounds a year.

Two new bodies will be established in the coming months as part of the strategy.

A dedicated Office of Cyber Security in the Cabinet Office will co-ordinate policy across government and look at legal and ethical issues as well as relations with other countries.

The second body will be a new Cyber Security Operations Centre (CSOC) based at GCHQ.

This will bring people together from across government and from outside to get a better handle on cyber security issues and work out how to better protect the country, providing advice and information about the risks.

"CSOC's aim will be to identify in real time what type of cyber attacks are taking place, where they come from and what can be done to stop them", according to a Whitehall security official.

Experts say the "forensics" of detecting who is behind a cyber attack and attributing responsibility remains extremely difficult.

Officials said it would require input from those who had their own expertise in hackers. "We need youngsters," an official said.

The range of potentially hostile cyber activity - from other states seeking to carry out espionage through criminal gangs to terrorists - is daunting.

Critical information

At one end of the spectrum, military operations - such as Russia's conflict with Georgia last year - are now accompanied by attacks on computer systems.

The UK's critical national infrastructure is also more reliant on technology than it was even five years ago and terrorists who have used the internet for fundraising and propaganda are also believed to have the intent - if not yet the capability- to carry out their own cyber-attacks.

Officials declined to give a figure of how many attacks on government computer networks take place each day.

In a speech in 2007, the head of MI5, Jonathan Evans, explicitly mentioned Russia and China in the context of a warning that that "a number of countries continue to devote considerable time and energy trying to steal our sensitive technology on civilian and military projects, and trying to obtain political and economic intelligence at our expense. They do not only use traditional methods to collect intelligence but increasingly deploy sophisticated technical attacks, using the internet to penetrate computer networks."

Officials said they were not aware of any "key pieces of information" that had gone missing yet but said that British companies had lost critical information.

The new Cyber Security Operations Centre will work closely with the designated parts of the critical national infrastructure and wider industry and officials say that business are keen for the government to take a lead but also share as much information as possible.

US President Barack Obama has been carrying out a similar re-organisation for defending US computer networks and British officials said the two countries were co-ordinating closely not least because of the intimate relationship between GCHQ and its US equivalent.

British officials believe that their government systems may also have fewer vulnerabilities than their US counterparts partly because they moved online later and have fewer connections between the internal government system and the rest of cyberspace to monitor.

Officials in the US and UK are also thought to be working on forms of offensive cyber-warfare capability but officials are unwilling to go into any details of what this might involve.



Tuesday, February 24, 2009

Consensus Audit Guidelines (CAG) draft 1.0 released

A small revolution is going on almost silently in US: SANS published the first version of "Consensus Audit Guidelines" (CAG) a set of 20 recommendations to better protect federal Systems. SANS is open to receive comments till March 25 2009.

The guidelines have been developed with knowledge of actual attacks that have compromised systems in order to construct effective defence.

This is not a replacement for other guidelines (i.e. NIST Security Guidelines), but a complement to help CIOs and CISOs to identify their top priorities. The CAG has been developed with the support of NSA, US-Cert, DoD, DoE, GAO and many Federal CIOs and CISOs. Also, a reference to NIST 800-53 Rev 3 Controls has been provided.

Below a summary of the 20 controls. You find the Guidelines here.

  1. Inventory of Authorized and Unauthorized Hardware.

  2. Inventory of Authorized and Unauthorized Software.

  3. Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers.

  4. Secure Configurations of Network Devices Such as Firewalls and Routers.

  5. Boundary Defense

  6. Maintenance and Analysis of Complete Security Audit Logs

  7. Application Software Security

  8. Controlled Use of Administrative Privileges

  9. Controlled Access Based On Need to Know

  10. Continuous Vulnerability Testing and Remediation

  11. Dormant Account Monitoring and Control

  12. Anti-Malware Defenses

  13. Limitation and Control of Ports, Protocols and Services

  14. Wireless Device Control

  15. Data Leakage Protection

Additional Critical Controls (not directly supported by automated measurement and validation):

  1. Secure Network Engineering

  2. Red Team Exercises

  3. Incident Response Capability

  4. Data Recovery Capability

  5. Security Skills Assessment and Training to Fill Gaps



Monday, December 29, 2008

US: Getting the Ear of the New President


(Americanbanker.com) If you follow the logic of FBI Director Louis Freeh, a cyber attack against America is inevitable and will feel like another September 11. He compares the current lack of coherent strategy and national will to prevent such an attack to the shoulder-shrugging response Americans had when the USS Cole was nearly sunk in the Yemeni port of Aden in 2000. "Neither the country, nor its leadership on both sides of the aisle, were motivated by this," Freeh lamented in a speech to attendees at the SC World Congress in New York in early December.

Freeh's words preceded Congressmen Jim Langevin (D-RI) and Michael T. McCaul (R-TX), who discussed their advice to president-elect Barack Obama on how to address the daily cyber threats and attacks against the nation's government, military and civilian networks. Langevin and McCaul co-chaired the Commission on Cybersecurity for the 44th Presidency, which spent more than 15 months formulating recommendations. The report has two main takeaways: the president should replace the current hodge-podge approach to cyber security with a new National Office for Cybersecurity, which would be part of the Executive Office of the President; and the government should issue strong, mandatory authentication identities for critical cyber infrastructures such as finance.

The first recommendation seems painfully obvious. Several technologists with strong industry credibility have held a variety of cyber "Czar" posts - Richard ClarkAmit YoranGreg Garcia, and the latest, Rod Beckstrom - to little avail. Creating a National Office of CyberSecurity charged with creating a comprehensive national security strategy might actually accomplish that goal.

As for authentication, the committee gave the FFIEC kudos for promoting stronger authentication for online financial services but wants to extend that effort even further. The report envisions a world where the government issues digital credentials that require in-person proofing - similar to a drivers license - which can then be accepted online by merchants and banks with greater certainty. The challenge is twofold: protecting individual privacy while at the same time preventing commercial interests and the government from requiring overly burdensome authentication, which could violate civil liberties.

Another challenge for cybersecurity experts is that many people are vying for the ear of President-elect Obama. Will the issue of cybersecurity prevail? There were four members of the Obama transition team on the committee, notes Jerry Dixon, a former FBI cybersecurity guru who is now director of analysis at cybersecurity consultancy Team Cymru. "It'd be bad form for them to ignore their own writing, wouldn't it?"