Showing posts with label Government. Show all posts
Showing posts with label Government. Show all posts

Saturday, July 2, 2011

Government in cyber fight but can't keep up

Notwithstanding the military's efforts, but, the overall gap appears to be widening, as adversaries and criminals move faster than government and corporations, and technologies just as mobile applications for smart phones proliferate more rapidly than policymakers can respond, officials and analysts said.

* Spin-offs of the malicious code dubbed "agent.btz" used to attack the military's U.S. Central Command in 2008 are for all that roiling U.S. networks today. People inside and outside the U.S. government strongly suspect Russia was behind the attack, which was the most significant known breach of military networks.

* There are serious questions about the security of "cloud computing," even as the U.S. government prepares to embrace that research in a big way for its cost savings.

That's the technique that was used by the Stuxnet worm that snarled Iran's enriched uranium-producing centrifuges last summer, and which many experts say may have been created by the United States or Israel. A mere 12 months later, would-be hackers can gladly find digital tool kits for building Stuxnet-like weapons on the Internet, according to a private-sector expert who requested anonymity.

"We're much better off than we were a few years ago, however we have not kept pace with opponents," said Jim Lewis, a cyber expert with the Center for Strategic and International Studies think tank. "The network is so deeply flawed that it can't be secured."

The private-sector expert who requested anonymity said a top official at a major Internet service provider told him that he knew his network had been infiltrated by elite hackers. He could digitally kick them out - however that would risk provoking a debilitating counter-attack.

The idea behind the before long-to-be-announced Pentagon program for defense contractors is to boost information-sharing with the Defense Department on cyber threats. It as well aims to speed reporting of attacks on firms that make up what the Pentagon calls the Defense Industrial Base.

Ultimately, the new program may lead to agreement to put for the time being some Pentagon contractors behind military-grade network perimeter defenses, just as those that protect the Pentagon's own classified networks.

On another front, the Pentagon's far-out technology arm, the Defense Advanced Innovation Projects Agency, is expected to launch by mid-2012 the National Cyber Range, a kind of replica of the Internet costing an estimated $130 million that would be used to test cutting-edge cyber defense technologies and help train cyber warriors.

Experts say that one of the toughest challenges of cyber defense is, oddly, definitions. What constitutes "cyber"? Computers and digital networks, undoubtedly. However how about digitized pictures or video streams from a pilotless Predator drone flying over Pakistan?

Offensive actions against foreign systems would require White House authorization. However the Pentagon does not need special approval to do the kind of cyber surveillance work that can identify vulnerabilities in foreign networks, a U.S. official told Reuters, speaking on condition of anonymity.

That includes leaving hidden digital "beacons" inside adversaries' networks that could be used to pinpoint future targets. The beacons can phone home to tell U.S. military computers that they are however operational, the official said.

Even as such policy debates rage, the technological landscape is being remade, seemingly by the month, posing new challenges - and opportunities. Tens of thousands of mobile applications for smartphones and tablet computers represent new vectors for hacks and attacks.

Meanwhile, the U.S. federal government is planning to move in a big way into "cloud computing," in which off-site providers offer network and storage resources accessible remotely from a variety of computing platforms.

Potential cost savings are significant. Handled correctly, computing clouds could offer added security, specialists say. Nevertheless there are as well risks.

A study released in April by CA Technologies and the Michigan-based Ponemon Institute contained alarming findings. Based on a survey of 103 U.S. and 24 European cloud computing providers, it found that a majority did not view security of their services as a competitive advantage, and believed that security was their clients' responsibility, not theirs.

Lynn told Reuters that "cloud computing has the potential to offer greater capability at equal or lesser costs." He added: "I want to make sure we are taking full advantage of these advanced technologies."

The Pentagon is preparing a cloud computing strategy, which it expects to complete by the end of the summer, a U.S. defense official told Reuters.

Schmidt, the White House coordinator, said as many as 170 security controls are being built into government cloud computing projects from the start. "It's not deploying something and securing it later. We're setting the requirements in the beginning."

So how safe are the computer networks of the United States, which like as not more than any nation relies on them for banking, electric power and other basics of modern civilization?

In May 1998, at that time-President Clinton signed Presidential Decision Directive 63, calling for a "reliable, interconnected, and secure" network by 2003, and establishing a national coordinator for protecting critical infrastructure.

A central conundrum is that the Pentagon's National Security Agency, which specializes in electronic eavesdropping, has personnel with the best cyber skills, nevertheless has been until recently taking everything into consideration shut out of protecting domestic networks. That's due to the highly classified nature of the NSA's work, and fears that it will stray into domestic spying.

Last October, the Defense Department and Homeland Security - responsible for protecting civilian U.S. government networks - signed a memorandum to cooperate, with the NSA sharing innovation and the agencies swapping personnel.


View the original article here

Sunday, May 1, 2011

Irish Government called on to open up its data to citizens

27.04.2011 Research giant Sony's PlayStation division has admitted an "illegal intrusion" and "compromise of personal information" on its systems has caused the current ongoing outage of...

By embracing open data principles, open source innovation and cloud computing, it is envisaged Ireland could follow in the steps of the US Government and European nations like Norway that have embraced open data principles to great success.

According to the CEO of the Irish Internet Association, Joan Mulvihill, wind and wave energy are considered great however untapped natural resources, yet what of data, the nation’s untapped non-natural resources?

Chris Vein, deputy US chief research officer, said: “Whether you call them geeks or techies, some of the greatest innovations in government have been the result of citizen developers who simply want to do their part to make our government work better. From the Department of Health and Human Services’ Community Data Health Initiative to 'Transportation Camps' - un-meetings aimed at solving transportation problems - throughout the United States, citizens are using their talents to help make government data that are simply lying around as a matter of fact work for the American people.

“Someone would at that time be accountable for getting it fixed and by opening up data the concerned citizen would know what’s happening and what is being done about it. It’s that simple and represents major opportunities for savings, as so then as business opportunities for software developers to create compelling products. Some of these products might end up being exported to other countries and governments.”

Mulvihill acknowledged that development talent is a scarce resource right now in any country nevertheless software developers could create meaningful and lasting business models that go beyond attending hackatons.

“At present nevertheless, the rules around data are prohibiting these opportunities. National data represents a huge untapped non-natural resource that we should be embracing. The key is Government trusting their own citizens and supporting enterprising developers who in turn could create jobs and open up exciting new export markets for Irish-made innovation.”

A glimpse of what was possible was offered previously this year at the IIA’s Cloud Computing event, where Torstein Harildstad, CEO of Software Technology and a former head of innovation at publishing giant Conde Nast, described how Norway opened up its data to its citizens.

Harildstad’s company is indigenous to Norway however has grown to more than 300 people in Sweden and India as well and is nearly a tantalising glimpse of what should and could be possible for Irish software companies if we had a public sector ready to invest in the cloud. The company has a strong foothold in the public-sector market and is now moving into the private sector, unlike its Irish counterparts who have to go global and win private-sector business overseas without even a sniff of business from the Irish Government.

“We are not selling the cloud to public-sector organisations, we are selling business value,” he explained, as he outlined how cloud computing is enabling very real transparency for the public, for business and ultimately for leaders in public-sector organisations by publishing and providing open access to crucial documentation and correspondence.

Mulvihill says open data is a logical step nevertheless bad PR, miscommunication and misconceptions have created a fear among policy makers and civil servants that data miners are, as a matter of fact, a rebel group of underworld hackers, hell bent on using data to expose the inadequacies and yikes ‘corruption’ of our current system.

“There is not enough engagement between public bodies and the grassroots of the internet industry. In a role where I sit squarely between the two I have a rare vantage point. I can see this case from both sides to bring these groups at the same time, facilitating a more constructive and open conversation where each can present their side and reconcile them to a plan for government that will benefit everyone. 

“Now is the time to be taking a chance on ourselves, trusting our own people to do what is best for the society in which are all participants. The internet industry in Ireland has come of age, it’s time we were trusted with a set of keys!”


View the original article here

Related Posts Plugin for WordPress, Blogger...