Welcome | Sign In
TechNewsWorld.com
Cyberattacks

CONFERENCE REPORT
RSA Town Hall: It Takes a Village to Weather a Cyber Storm

Print Version
E-Mail Article
Reprints
RSA Town Hall: It Takes a Village to Weather a Cyber Storm

Forming relationships ahead of time is key to cooperation during a cyber attack, said Greg Garcia, assistant secretary for cyber security and communications at the Department of Homeland Security, during a town hall meeting at the RSA Security Conference on Cyber Storm II. Cyber Storm II was a huge exercise in protecting the nation's IT infrastructure held last month.


Tech Industry Paper - Finding Strength Through Customer Service
Poised to capitalize on an upturn in the economy, technology companies are focused on retention & service. This paper, from Convergys, provides the latest research on customer experience for B2B & B2C technology customers. Learn more.

How do you respond when hit by a cyber attack tsunami?

That's what Cyber Storm II, the most comprehensive cyber exercise ever held in the U.S., was designed to answer.

Forty private sector companies, 11 Cabinet-level agencies, 10 states and five countries were involved in the March exercise, which examined the processes, procedures, tools and organizational response to a multi-sector coordinated attack through, and on, the global cyber infrastructure.

The adversary in the exercise launched simulated coordinated cyber and physical attacks on critical infrastructures within selected sectors to meet specific political and economic goals.

Public, Private Involvement

Greg Garcia, assistant secretary for cyber security and communications at the Department of Homeland Security (DHS), gave highlights of what the DHS learned to an audience at a town hall meeting at the RSA Security Conference (Nasdaq: RSAS) in San Francisco.

"The public/private partnership in cyber security is very important," Art Coviello, president and CEO of RSA Security, said when he opened the meeting. It was a "real thrill" to have this topic revised in Cyber Storm II and to see that the current administration is involved in it at such a high level because the cooperation "will not take a back seat like before," he added.

Government cannot tackle the issue of cyber security alone, and it has to be dealt with "on an industry by industry basis," Coviello said.

Fast Response

Garcia, who has held this post since 2006, said the exercise had three major priorities: To strengthen against cyber attacks; respond in real time in a synchronized fashion; and to build awareness, "mainly through forums like this."

Cyber Storm II was "fundamentally about identifying and responding to fast-breaking cyber epidemics -- testing our ability to identify and act, validate our ability to respond, and make decisions from the executive level down to the operational level," Garcia said.

The relationships built up over the 18 months of planning for Cyber Storm II "will last well beyond the one week of the exercise" and will result in better responses and improve our defense capabilities, he added.

Early Connections Essential

The cooperation of industry was, and will be, "critical" when we are under cyber attack, Garcia said.

Another lesson the DHS learned was that social networking is essential well before any threat occurs. Exchanging business cards "in a crisis when your hair is on fire" is of no use, Garcia said.

Cyber Storm II let large corporations exercise across national borders, Garcia said. That will be useful because cyber security "is a planetary issue."

Panelists on Lessons Learned

Panelists at the Town Hall meeting were Dan Lohrmann, director, Office of Enterprise Security for the state of Michigan; Christine Adams, senior information systems manager at Dow Chemical (NYSE: DOW), Paul McKitrick, business manager of New Zealand's Center for Critical Infrastructure Protection, Paul Nicholas of Microsoft's (Nasdaq: MSFT) Critical Infrastructure Protection Team, and Randy Vickers, deputy director of the U.S. Computer Emergency Readiness Team (US-CERT) at the Department of Homeland Security.

"For IT staff, Storm Cloud II tested our processes and procedures and enhanced our capabilities," Lohrmann said. "Lots of cities are used to exercising for nuclear attack scenarios but not really for cyber security attacks."

The 18-month planning process for Storm Cloud II impressed New Zealand's McKitrick the most. "If the preparation time was all the exercise gave us, developing relationships, the planning process, that would be worth it," he said.

Although it was generally doing the right things, US-CERT learned a few lessons. "There were still some shortfalls in information sharing, and most of it was as simple as groups or organizations not having the means to share information or having the means but these weren't robust enough for good information flow," Vickers said.

One of the new things US-CERT learned is that it needs to take the National Advisory Color System (red for high threat, yellow for low threat and so on) into account. "How do we integrate that with the cyber security alert system?" Vickers said.

Threats Without Borders

While coordination between the public and private sectors is becoming a catchphrase, it isn't as easy as everyone thinks. "Public-private partnerships roll off the tongue; it's easy to say but very hard to implement in reality," Microsoft's Nicholas said. Constantly exercising these capabilities is crucial: "One of the key takeaways for Microsoft was that exercises are important, and we as a community have to think about drills in the space if we are going to sustain that."

The international nature of cyber threats was also a concern. "We don't have borders around cyber security," Nicholas said. "How do you engage if a cyberstorm lands in another country where our State Department can't work with them easily?"


Print Version E-Mail Article Reprints More by Richard Adhikari


More by Richard Adhikari

New Pogoplug Brings Mobile Devices Into the Cloud
November 20, 2009
The Pogoplug allows a user to run a personal cloud server from a home network. The data resides on hard drives and thumb drives that plug directly into the Pogoplug device; from there, the data can be accessed from anywhere via the Internet. Keep in mind that some ISPs forbid customers from hooking servers up to residential connections, though those rules are rarely enforced.
Google Spills Chrome OS' Guts
November 19, 2009
Google has made public the source code for its upcoming Chrome operating system. The OS will begin appearing on consumer-targeted netbooks next year. Chrome is built to live completely on the Web -- very little data is stored directly on the user's hard drive. This could make for much faster boot times and enhance security.
Cyberfraud Arrests Unlikely to Stem ZeuS Rampage
November 18, 2009
Two alleged cybercrooks have been nabbed in the UK on suspicion of using a well-know Trojan to commit banking fraud. The malware in question in known as "ZeuS" or "Zbot," and althought it's quite common, it's also sometimes difficult for antivirus applications to nail. Simple software kits exist online for relatively inexperienced hackers to create unique malware for the purpose of fraud.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network