10 Years After 9/11, Are America’s Cyberdefenses Weaker?

Following the Sept. 11, 2001, terrorist attacks, many physical security systems in the United States underwent radical change. But what of our constantly growing online systems? Each new hacking attack and government revelation seems to indicate that national online defenses are weaker than ever.

So how much of a problem is the current state of national cybersecurity, and what can government agencies do to improve it beyond spying on other countries — and on U.S. citizens?

“How real is the threat? One needs to look no further than the latest headlines to know that this is not a theoretical concern,” said Michael Sutton, vice president of security research at Sunnyvale, Calif.-based security firm Zscaler.

Several remarkable revelations accompanied this past summer’s release of the U.S. Department of Defense’s long-awaited Strategy for Operating in Cyberspace. According to Deputy Secretary of Defense William J. Lynn III, an unnamed foreign spy agency broke into a corporate defense contractor’s system in March and managed, in a single hack attack, to make off with approximately 24,000 Pentagon files.

While neither the contractor nor the content of the files was disclosed, Lynn went on record to admit that other critical files had been stolen in the past, including details about U.S. fighter jets, missile systems and unmanned drones. (Top defense contractor Lockheed Martin said in May that it had been a victim of a sophisticated cyberattack.)

Crippling strike

How could such stolen information be used against the United States?

“The next Pearl Harbor we confront could very well be a cyberattack that cripples our power systems, our grid, our security systems, our financial systems, our governmental systems,” said Secretary of Defense Leon Panetta during his June confirmation hearings in front of the Senate Armed Services Committee.

There’s already some precedent that’s cause for concern. During the Aug. 14, 2003, blackout in the eastern U.S. and Canada, the then-rampant Blaster computer worm was said to have contributed to the severity of the power outage by crippling utility companies’ computers, according to a 2004 congressional report on potential cyberterrorism.

The report also noted that during the same year, another computer worm penetrated the control-room systems of the Davis-Besse nuclear power plant in Carroll Township, Ohio. Fortunately, the plant was shut down at the time.

Systemic flaws

Experts say that these and other online threats to American infrastructure and lives exist because of three areas of vulnerability: outside government contractors (such as in the March defense-related break-in case), foreign governments (friendly or otherwise) and the software systems themselves.

By necessity, the government must work with outside companies to get the latest technology and to further develop systems. And those companies aren’t only defense contractors like Lockheed. Even Google reportedly supplies special search-and-mapping software to the U.S. intelligence community. But Google itself has been among the victims of serious hacking attacks that laid bare information and systems of dozens of major U.S. corporations.

While the attackers are rarely conclusively identified, many security experts point out that foreign governments are engaged in cloak-and-dagger digital maneuvers.

The Chinese air force has a division whose goal is to use cyberattacks to wreak havoc with command-and-control systems in other countries, according to Tom Patterson, chief security officer for security device manufacturer MagTek Inc. in Seal Beach, Calif.

Other governments, including our own, have similar departments. In an online fact sheet, the U.S. Cyber Command states that its mandate is to “direct the operations and defense of specified Department of Defense information networks and prepare to, and when directed, conduct full-spectrum military cyberspace operations.”

Of course, the principal vulnerability in planning and executing such cyberwarfare is the software. According to a DoD release, more than 60,000 new malicious software programs or variations “threatening our security, our economy and our citizens” are identified every day.

Some experts — and some congressional reports — suggest that the government’s reliance on commercial off-the-shelf (COTS) software makes its systems more vulnerable. It gives hackers a known target at which to direct their efforts, and cybercriminals often trade information on weaknesses in popular COTS programs.

Custom-built software and systems can provide better security, some experts claim, because the details about how such systems work are not well known, and attackers don’t have the necessary access to identify vulnerabilities.

Zscaler’s Sutton disagrees. He pointed out that COTS programs undergo more security checks and fixes, making such programs inherently more secure.

“For my money, I’d rather implement a system secured via peer review, as opposed to security through obscurity,” Sutton said.

Tracking down the enemy

There is still much discussion about what strategy should be adopted to protect American online resources. Gen. James E. Cartwright, vice chairman of the Joint Chiefs of Staff, told reporters in July that the military should adopt a strategy that essentially boils down to the idea that the best defense is a good offense.

Cartwright said that most digital resources are currently focused on building better firewalls, rather than on deterring hackers from attacking in the first place. Some listeners took Cartwright’s comments as a suggestion that U.S. agencies should engage in digital counterattacks.

However, identifying the enemy in cyberspace can be difficult at best. Most attackers use anonymizing Web services based in countries such as Thailand and Russia, and often take control of computers in still more countries to coordinate their activities.

Given the lack of official international cybercooperation, getting several foreign governments to coordinate a search before the attackers disappear can be next to impossible. There’s also the unresolved question of whether the U.S. government’s cybersecurity personnel should step in when private American companies are attacked.

The result is a murky picture when assessing online safety and security.

“Overall, we are less secure than we were 10 years ago,” Sutton said.

“The decreased security has little to do with technology,” he added. “The human element is the weak link today, just as it always has been, and in a world where the majority of data is stored digitally, it is only a matter of time before human error leads to data leakage.”

Or worse.

*   10 Ways the Government Watches You
  *   Cyberhijackers Pose Threat to Planes, Trains and Automobiles
  *   Internet Safety Tips for Kids

Copyright © 2011 TechMediaNetwork.com. All Rights Reserved. This material may not be published, broadcast, rewritten or redistributed.

Leave a Reply

Your email address will not be published. Required fields are marked *

universo-virtual.com

buytrendz.net

thisforall.net

benchpressgains.com

qthzb.com

mindhunter9.com

dwjqp1.com

secure-signup.net

ahaayy.com

soxtry.com

tressesindia.com

puresybian.com

krpano-chs.com

cre8workshop.com

hdkino.org

peixun021.com

qz786.com

utahperformingartscenter.org

maw-pr.com

zaaksen.com

ypxsptbfd7.com

worldqrmconference.com

shangyuwh.com

eejssdfsdfdfjsd.com

playminecraftfreeonline.com

trekvietnamtour.com

your-business-articles.com

essaywritingservice10.com

hindusamaaj.com

joggingvideo.com

wandercoups.com

onlinenewsofindia.com

worldgraphic-team.com

bnsrz.com

wormblaster.net

tongchengchuyange0004.com

internetknowing.com

breachurch.com

peachesnginburlesque.com

dataarchitectoo.com

clientfunnelformula.com

30pps.com

cherylroll.com

ks2252.com

webmanicura.com

osostore.com

softsmob.com

sofietsshotel.com

facetorch.com

nylawyerreview.com

apapromotions.com

shareparelli.com

goeaglepointe.com

thegreenmanpubphuket.com

karotorossian.com

publicsensor.com

taiwandefence.com

epcsur.com

odskc.com

inzziln.info

leaiiln.info

cq-oa.com

dqtianshun.com

southstills.com

tvtv98.com

thewellington-hotel.com

bccaipiao.com

colectoresindustrialesgs.com

shenanddcg.com

capriartfilmfestival.com

replicabreitlingsale.com

thaiamarinnewtoncorner.com

gkmcww.com

mbnkbj.com

andrewbrennandesign.com

cod54.com

luobinzhang.com

bartoysdirect.com

taquerialoscompadresdc.com

aaoodln.info

amcckln.info

drvrnln.info

dwabmln.info

fcsjoln.info

hlonxln.info

kcmeiln.info

kplrrln.info

fatcatoons.com

91guoys.com

signupforfreehosting.com

faithfirst.net

zjyc28.com

tongchengjinyeyouyue0004.com

nhuan6.com

oldgardensflowers.com

lightupthefloor.com

bahamamamas-stjohns.com

ly2818.com

905onthebay.com

fonemenu.com

notanothermovie.com

ukrainehighclassescort.com

meincmagazine.com

av-5858.com

yallerdawg.com

donkeythemovie.com

corporatehospitalitygroup.com

boboyy88.com

miteinander-lernen.com

dannayconsulting.com

officialtomsshoesoutletstore.com

forsale-amoxil-amoxicillin.net

generictadalafil-canada.net

guitarlessonseastlondon.com

lesliesrestaurants.com

mattyno9.com

nri-homeloans.com

rtgvisas-qatar.com

salbutamolventolinonline.net

sportsinjuries.info

topsedu.xyz

xmxm7.com

x332.xyz

sportstrainingblog.com

autopartspares.com

readguy.net

soniasegreto.com

bobbygdavis.com

wedsna.com

rgkntk.com

bkkmarketplace.com

zxqcwx.com

breakupprogram.com

boxcardc.com

unblockyoutubeindonesia.com

fabulousbookmark.com

beat-the.com

guatemala-sailfishing-vacations-charters.com

magie-marketing.com

kingstonliteracy.com

guitaraffinity.com

eurelookinggoodapparel.com

howtolosecheekfat.net

marioncma.org

oliviadavismusic.com

shantelcampbellrealestate.com

shopleborn13.com

topindiafree.com

v-visitors.net

qazwsxedcokmijn.com

parabis.net

terriesandelin.com

luxuryhomme.com

studyexpanse.com

ronoom.com

djjky.com

053hh.com

originbluei.com

baucishotel.com

33kkn.com

intrinsiqresearch.com

mariaescort-kiev.com

mymaguk.com

sponsored4u.com

crimsonclass.com

bataillenavale.com

searchtile.com

ze-stribrnych-struh.com

zenithalhype.com

modalpkv.com

bouisset-lafforgue.com

useupload.com

37r.net

autoankauf-muenster.com

bantinbongda.net

bilgius.com

brabustermagazine.com

indigrow.org

miicrosofts.net

mysmiletravel.com

selinasims.com

spellcubesapp.com

usa-faction.com

snn01.com

hope-kelley.com

bancodeprofissionais.com

zjccp99.com

liturgycreator.com

weedsmj.com

majorelenco.com

colcollect.com

androidnews-jp.com

hypoallergenicdogsnames.com

dailyupdatez.com

foodphotographyreviews.com

cricutcom-setup.com

chprowebdesign.com

katyrealty-kanepa.com

tasramar.com

bilgipinari.org

four-am.com

indiarepublicday.com

inquick-enbooks.com

iracmpi.com

kakaschoenen.com

lsm99flash.com

nana1255.com

ngen-niagara.com

technwzs.com

virtualonlinecasino1345.com

wallpapertop.net

nova-click.com

abeautifulcrazylife.com

diggmobile.com

denochemexicana.com

eventhalfkg.com

medcon-taiwan.com

life-himawari.com

myriamshomes.com

nightmarevue.com

allstarsru.com

bestofthebuckeyestate.com

bestofthefirststate.com

bestwireless7.com

declarationintermittent.com

findhereall.com

jingyou888.com

lsm99deal.com

lsm99galaxy.com

moozatech.com

nuagh.com

patliyo.com

philomenamagikz.net

rckouba.net

saturnunipessoallda.com

tallahasseefrolics.com

thematurehardcore.net

totalenvironment-inthatquietearth.com

velislavakaymakanova.com

vermontenergetic.com

sizam-design.com

kakakpintar.com

begorgeouslady.com

1800birks4u.com

2wheelstogo.com

6strip4you.com

bigdata-world.net

emailandco.net

gacapal.com

jharpost.com

krishnaastro.com

lsm99credit.com

mascalzonicampani.com

sitemapxml.org

thecityslums.net

topagh.com

flairnetwebdesign.com

bangkaeair.com

beneventocoupon.com

noternet.org

oqtive.com

smilebrightrx.com

decollage-etiquette.com

1millionbestdownloads.com

7658.info

bidbass.com

devlopworldtech.com

digitalmarketingrajkot.com

fluginfo.net

naqlafshk.com

passion-decouverte.com

playsirius.com

spacceleratorintl.com

stikyballs.com

top10way.com

yokidsyogurt.com

zszyhl.com

16firthcrescent.com

abogadolaboralistamd.com

apk2wap.com

aromacremeria.com

banparacard.com

bosmanraws.com

businessproviderblog.com

caltonosa.com

calvaryrevivalchurch.org

chastenedsoulwithabrokenheart.com

cheminotsgardcevennes.com

cooksspot.com

cqxzpt.com

deesywig.com

deltacartoonmaps.com

despixelsetdeshommes.com

duocoracaobrasileiro.com

fareshopbd.com

goodpainspills.com

kobisitecdn.com

makaigoods.com

mgs1454.com

piccadillyresidences.com

radiolaondafresca.com

rubendorf.com

searchengineimprov.com

sellmyhrvahome.com

shugahouseessentials.com

sonihullquad.com

subtractkilos.com

valeriekelmansky.com

vipasdigitalmarketing.com

voolivrerj.com

zeelonggroup.com

1015southrockhill.com

10x10b.com

111-online-casinos.com

191cb.com

3665arpentunitd.com

aitesonics.com

bag-shokunin.com

brightotech.com

communication-digitale-services.com

covoakland.org

dariaprimapack.com

freefortniteaccountss.com

gatebizglobal.com

global1entertainmentnews.com

greatytene.com

hiroshiwakita.com

iktodaypk.com

jahatsakong.com

meadowbrookgolfgroup.com

newsbharati.net

platinumstudiosdesign.com

slotxogamesplay.com

strikestaruk.com

trucosdefortnite.com

ufabetrune.com

weddedtowhitmore.com

12940brycecanyonunitb.com

1311dietrichoaks.com

2monarchtraceunit303.com

601legendhill.com

850elaine.com

adieusolasomade.com

andora-ke.com

bestslotxogames.com

cannagomcallen.com

endlesslyhot.com

iestpjva.com

ouqprint.com

pwmaplefest.com

qtylmr.com

rb88betting.com

buscadogues.com

1007macfm.com

born-wild.com

growthinvests.com

promocode-casino.com

proyectogalgoargentina.com

wbthompson-art.com

whitemountainwheels.com

7thavehvl.com

developmethis.com

funkydogbowties.com

travelodgegrandjunction.com

gao-town.com

globalmarketsuite.com

blogshippo.com

hdbka.com

proboards67.com

outletonline-michaelkors.com

kalkis-research.com

thuthuatit.net

buckcash.com

hollistercanada.com

docterror.com

asadart.com

vmayke.org

erwincomputers.com

dirimart.org

okkii.com

loteriasdecehegin.com

mountanalog.com

healingtaobritain.com

ttxmonitor.com

bamthemes.com

nwordpress.com

11bolabonanza.com

avgo.top