US Gov't to Probe Network Intrusions by Foreign Hackers
- 18 April, 2007 12:06
- Comments
A House subcommittee is scheduled to hear testimony from government and industry representatives about the extent to which US federal networks and critical infrastructure have been compromised by foreign hackers.
The hearing will take place before a subcommittee of the Committee on Homeland Security, which is chaired by Republican Bennie Thompson.
Among those scheduled to testify are David Jarrell, manager of the critical infrastructure protection program at the Department of Commerce, and Don Reid, senior coordinator for security infrastructure from the Department of State. Both agencies were infiltrated last year by hackers using servers that appeared to be based in China. Also slated to testify are representatives from the Department of Homeland Security, the Idaho National Laboratory and security vendor VeriSign.
The hearing is designed to raise awareness of the extent to which foreign entities have infiltrated government networks, according to briefing materials made available to Computerworld.
"The purpose of this hearing is to afford [House members] the opportunity to understand how deeply our systems have been penetrated," the materials said. "Experts believe that the remediation efforts that are currently under way are not able to completely clear out hackers from government networks."
In June 2006, attackers using computers with IP addresses in China penetrated the State Department's networks and stole passwords and other data that the agency claimed was unclassified. The hackers also planted backdoor programs on several servers to allow them to access the systems at will. The compromise resulted in the agency having to shut down Internet access for several days.
Similarly, the Bureau of Industry and Security (BIS), an agency in the Commerce Department, was hacked into last July, resulting in the theft of user account information. And in October, the agency admitted to being hit by sustained distributed denial-of-service attacks launched by servers based in China. Those attacks forced the BIS to restrict Internet access to only those workstations that were not connected to any of the bureau's internal systems.
This hearing will focus on security executives at the two agencies and their responses to the compromises.
A letter from Thompson to the secretary of one of the federal departments, a copy of which was obtained by US Computerworld, lists a series of very detailed questions that the subcommittee wants answers to at the hearing. The information sought includes details on how quickly the agency detected the intrusion into its networks, how long the hackers remained undetected and details about all of the systems compromised.
The subcommittee also wants detailed information on what the agency did to "eliminate any infestations" from perpetrators who had control of the systems. Members, for instance, are looking into whether the agency completely wiped all the disks on the compromised systems and reloaded them from backups and whether "rogue tunnel audits" were done to look for backdoors on the systems.
"Members will understand that the penetrations on our systems were bad - so bad that we don't even know whether we or the attackers now control our own systems," the briefing materials noted.
The hearing also plans to look at whether the agencies implemented all the requirements of the Federal Information Security Management Act (FISMA) and whether those controls really improved defences. Officials at one of the agencies, for example, are expected to testify that even if it had received an A+ on its FISMA grades, the attacks would still have happened, the briefing materials said.
"I always hoped Congress would wake up one day and finally discover that the federal government had been deeply and broadly penetrated by cyberattackers from other countries," said Alan Paller, director of research at security research and training company the SANS Institute. He also asserted "that the defences they have in place have not protected them, that much of the money they have spent on FISMA reports has been wasted, and [that FISMA funding] should have been spent on actual security", he said.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Top seven firewall capabilities for effective application control
-
Pfizer's Future Depends on IT Transformation
-
Face Time - Interview with John Brennan and Robert DiStefano
-
SOA and Business Processes: Making the Connection
Service-Oriented Architecture (SOA) is also complex, and one of its main characteristics is that an SOA system is comprised of multiple applications that are combined to accomplish critical business processes. Discussions of SOA can quickly grow so complex that the system’s main benefits to an organization are difficult to fully understand. This article discusses SOA Suite 11g, a family of products that take SOA to a new level and correct some of the problems caused by the very combination of components and multiplication of languages that make SOA a flexible, agile system. -
Why Two Thirds of Enterprise Architecture Projects Fail
This is the conclusion of a study for the R otterdam U niversity carried out by J onathan B roer in the summer of 2008, ordered by BPM and E A software vendor IDS S cheer. B roer questioned 161 respondents from 89 organizations representing a range of industries about their vision and implementation of the enterprise architecture concept. -
Oracle Enterprise Gateway
Oracle Enterprise Gateway is a standards-based, policy-driven, standalone software security solution that provides first line of defense in Service-Oriented Architecture (SOA) environments. Learn more.
-
Maya Hyper-realistic Creature Creation, 2nd Edition W/DVD
-
Santa Shops on Ebay
-
Office 2003 Simplified
-
The Mac OS X Panther Book
-
Al Ward's Photoshop Productivity Toolkit
-
Designing and Implementing Ip/Mpls-based Ethernet Layer 2 Vpn Services
-
Security Standards in a Web + 2.0 World - a Standards-based Approach
-
Excel 2007 Formulas
-
Microsoft Office Access 2007 International Student Edition (77-605)








Comments
Post new comment