Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/6/2013
03:33 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

U.S. Cybersecurity Status Weak, Reports Charge

DOD report says the military is "not prepared" for cyber war, while a White House report says agencies fall short of federal cybersecurity goals.

Military Drones Present And Future: Visual Tour
Military Drones Present And Future: Visual Tour
(click image for larger view and for slideshow)
The Department of Defense is "not prepared" to defend against sophisticated international cyber attacks, and government-wide, agencies have failed to meet some White House cybersecurity targets, according to two new reports.

Although the reports differ in tone and structure -- one demands urgent action by the military and the other is a straightforward compliance report -- together they underscore the hard work the government still has ahead of it as it faces an onslaught of increasingly sophisticated cyber attacks.

The report on the military, a study by the Defense Science Board, a civilian committee providing solicited scientific and technical advice to DOD leadership, finds that the Department of Defense is woefully unprepared to fight in cyberspace due to "inherently insecure architectures," fragmented efforts, "inadequate" intelligence and the sheer limits of today's technology.

[ Will the finger pointing only get worse? Read China Targets U.S. In Hacking Blame Game. ]

"Without an urgently implemented and comprehensive strategy to offset the cyber security threat, U.S. national objectives will be nearly impossible to achieve in times of crisis," said the report on the military. "Additionally, the long term loss of so much intellectual property and capability will result in a serious competitive disadvantage to the U.S. economy."

The report warns of cyber attacks that could disrupt military actions by turning U.S. weapons against its own troops, and of civilian attacks that could disrupt food and medical distribution systems and make transportation systems "useless."

Despite the committee's concerns, however, the Defense Science Board says it thinks the challenges manageable. "The Department can effectively manage the risks presented by the cyber threat," the report notes.

In order to meet the challenges, the report prescribes a set of actions the military must take, from more aggressive pursuit of cyber intelligence to the use of deterrence to improved cyber defenses, to the adoption of metrics to measure performance against the military's cyber goals.

The report calls on the military to develop offensive cyber capabilities, including the development of a formal career path for both civilian and military workers involved in offensive cyber "actions"; strengthen the "cyber resiliency" of military vehicles and weaponry from submarines to bombers; and establish an enterprise security architecture.

The report also encourages the DOD's CIO to work with the military branches to create an "enterprise security architecture" that includes minimum standards to ensure a "reasonable" level of defensibility, and to increase the probability that attacks are detected. The report recommends these standards be integrated as requirements in new acquisitions and that existing systems be audited to ensure that the architecture is in place.

Putting the report's recommendations into place will not come cheaply. The report estimates that just providing the resources necessary to secure the U.S. nuclear arsenal will cost more than $500 million annually. Implementing these changes will also take time. The report predicts that it will take "years" for the military to execute an "effective" multi-part response to cyber threats.

The White House report, meanwhile, says agencies have seen a drop in compliance with White House goals over the last year, although the report notes that this is "associated with adjustments and improvements to measurement methodology" as opposed to any actual weakening of the government's cybersecurity readiness.

The recalibration should help improve agencies' cybersecurity stances, but the need for recalibration itself shows that the White House has been operating with a less-than-complete picture of agencies' cybersecurity.

Regardless of the reason behind the decrease in agencies' compliance scores, the metrics aren't all rosy. Only half of the agencies measured reached the fiscal 2013 goal for automated asset management, and a third of agencies reported actual decreases in automated vulnerability management, for example.

The report also tracks compliance with a requirement that employees and contractors use Personal Identity Verification (PIV) cards to access federal IT systems. Most agencies fall short of this requirement. The DOD and General Services Administration are heavy users of PIV cards, but at half of the agencies surveyed, only 2% of employees were using the cards to access agency IT systems.

The White House report said that the Office of Management and Budget and the White House's National Security Staff will work with agencies that appear to risk failing to meet White House cybersecurity performance standards, either through metrics-heavy CyberStat meetings with top agency IT staff or by "other appropriate action."

Overall, the picture appears mixed for federal agencies. For example, agencies appear to be meeting or close to meeting minimum targets on continuous monitoring, strong authentication and the Trusted Internet Connections network connection consolidation effort. The White House projects that agencies will far outstrip initial goals by early next in fiscal 2014.

The government in recent years has been aggressively pushing to improve cybersecurity and to make sure that the military is ready for disruptive cyber attacks. Although the White House and DOD reports indicate less-than-complete progress toward those goals, they also by their very nature inch the government closer to meeting those goals.

Still, the reports show that much work is left to be done to bring agencies fully into line with White House goals, and perhaps more work is left to ensure that the military is able to adequately defend the nation in cyberspace.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
lgarey@techweb.com
50%
50%
[email protected],
User Rank: Apprentice
3/8/2013 | 1:43:28 PM
re: U.S. Cybersecurity Status Weak, Reports Charge
That's discouraging, but I guess not surprising, as Deirdre says.
J. Nicholas Hoover
50%
50%
J. Nicholas Hoover,
User Rank: Apprentice
3/8/2013 | 1:15:50 PM
re: U.S. Cybersecurity Status Weak, Reports Charge
Lorna,

Sadly, bipartisan support for broader cybersecurity legislation has been hard to come by, and that has been the problem. Both the House and Senate have sought to improve cybersecurity in the DOD and modernize the legislation governing civilian agencies' cybersecurity. However, the Senate has sought to resolve cybersecurity issues comprehensively in one bill, and on other points there are significant differences between the parties.
Deirdre Blake
50%
50%
Deirdre Blake,
User Rank: Apprentice
3/7/2013 | 8:31:43 PM
re: U.S. Cybersecurity Status Weak, Reports Charge
I'd personally count on executive order for any action -- there is no such thing as "bipartisan" in the U.S. these days.
lgarey@techweb.com
50%
50%
[email protected],
User Rank: Apprentice
3/7/2013 | 6:49:25 PM
re: U.S. Cybersecurity Status Weak, Reports Charge
Nick, It seems like improving cyber security should be one place the administration can get bipartisan support. Is that the case? If so, do you see legislative action forthcoming, or will change happen mostly by executive order? Lorna Garey, IW Reports
Microsoft Patches Wormable RCE Vulns in Remote Desktop Services
Kelly Sheridan, Staff Editor, Dark Reading,  8/13/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
GitHub Named in Capital One Breach Lawsuit
Dark Reading Staff 8/14/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15132
PUBLISHED: 2019-08-17
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocki...
CVE-2019-15133
PUBLISHED: 2019-08-17
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
CVE-2019-15134
PUBLISHED: 2019-08-17
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network threads from working. This is related to _receive in sys/net/gnrc/transport_layer/tcp/gnrc_tcp_eventloo...
CVE-2019-14937
PUBLISHED: 2019-08-17
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
CVE-2019-13069
PUBLISHED: 2019-08-17
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an additional user account, and then use SSH and port forwarding to reach a 127.0.0.1 service.