DefenseTech Military.com
  • Categories
  • Full Archives
  • Monthly Archives
  • About Defense Tech
Subscribe to RSS

About Defense Tech

Defense Tech exam­ines the inter­sec­tion of tech­nol­ogy and defense from every angle and pro­vides analy­sis on what’s ahead.

Tip Us Off

Tip for Defense Tech?

SEND IT!

It’s Confidential!

Categories

  • 'Canes
  • Afghan Update
  • Ammo and Munitions
  • Armor
  • Around the Globe
  • Av Week Extra
  • Axe in Iraq (and Elsewhere)
  • Bizarro
  • Blimps
  • Blog Bidness
  • Body Armor Blues
  • Bomb Squad
  • Brownshoes in Action
  • Bubbleheads, etc.
  • Cammo Green
  • Catch the "Buzz"
  • Chem-Bio
  • Civilian Apps
  • Cloak and Dagger
  • Commandos
  • Comms
  • Contingency Ops
  • Cops and Robbers
  • Cyber-warfare
  • Data Diving
  • Defense Tech Poll
  • Defense Tech Radio
  • Dissent Tech
  • Door Kickers
  • Drones
  • DT Administrivia
  • Eat DT's Dust
  • Extra! Extra!
  • Eye on China
  • Fast Movers
  • FCS Watch
  • Fire for Effect
  • FOS Files
  • Friday Funnies
  • Gadgets and Gear
  • Going Green
  • Grand Ole Osprey
  • Ground Vehicles
  • Guns
  • Homeland Security
  • In the Weeds with Eric
  • Info War
  • Iraq Diary
  • Jarhead Jazz
  • JSF Watch
  • Just War Theories
  • Lasers and Ray Guns
  • Less-lethal
  • Logistics
  • Los Alamos and Labs
  • M4 Monopoly
  • Medic!
  • Mercs
  • Missiles
  • Money Money Money
  • Most Wanted
  • MRAP Edge
  • Net-Centric
  • Nukes
  • Old Skool
  • Our Shrinking Planet
  • PEO Soldier
  • Planes, Copters, Blimps
  • Podcast
  • Politricks
  • Polmar's Perspective
  • Popular Mechanics
  • Rapid Fire
  • Raptor Watch
  • Red Team
  • Retro-Futuro
  • Robots
  • Roll Your Own
  • Sabra Tech
  • Ships and Subs
  • Snipertech
  • Soldier Systems
  • Space
  • Special Ops
  • Star Wars
  • Strategery
  • Stray Trons
  • Tactical Development
  • Terror Tech
  • The Deadlies
  • The Defense Biz
  • The Peoples' Site
  • The Sunday Paper
  • The Tanker Tango
  • The View from Av Week
  • Those Nutty Norks
  • Training and Sims
  • Trimble on the Case
  • Uncategorized
  • Video Lounge
  • War Update
  • Ward'z Wonderz
  • You can run…

Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003
  • August 2003
  • July 2003
  • June 2003
  • May 2003
  • April 2003
  • March 2003
  • February 2003
  • January 2003

Home » Cyber-warfare » Bring in the CPP

Bring in the CPP

cyber-protection.jpg

Multiple coun­tries are now dis­cussing the need to estab­lish a com­pre­hen­sive cyber pro­tec­tion pro­gram given the con­tin­ued increase in the threat of cyber attacks and cyber war­fare. The attack on Estonia and the more recent attack on Georgia are being viewed as the har­bin­ger of what is to come. I was recently asked what might a com­pre­hen­sive Cyber Protection Program (CPP) look like. So I thought I would put down my top ten areas that I think would be crit­i­cal to include in a CPP.

1. Mandatory require­ment to have up-​​to-​​date pro­tec­tion soft­ware on any device con­nect­ing to the Internet that includes:

  • a. Anti-​​Virus
  • b. Anti-​​Spyware
  • c. Anti-​​Malwared.
  • d. Anti-​​Adware

This soft­ware will auto­mat­i­cally upload attack data to a cen­tral report­ing center.

2. Mandatory iso­lat­ing capa­bil­ity on every sys­tem with high pro­cess­ing capa­bil­i­ties and a fire­wall on every device con­nect­ing to the Internet with the fol­low­ing functionality.

  • a. Cannot be dis­abled other than for a few seconds
  • b. Has pre-​​configuration for manda­tory protection
  • c. Automatically uploads attack data to a cen­tral report­ing center
  • d. Automatic dis­con­nec­tion when mas­sive out­bound DDoS traf­fic from com­pro­mised com­puter sys­tems is detected

3. Legislation man­dat­ing soft­ware ven­dors com­ply with the following:

a. Report to author­i­ties within 24 hours of dis­cov­ery mal­ware soft­ware vul­ner­a­bil­i­ties
b. Minimum secu­rity test­ing require­ments that must be met prior to release of any soft­ware program. 

4. Criminal laws specif­i­cally address­ing the unique char­ac­ter­is­tics of cyber attacks, mali­cious code and sys­tem com­pro­mise includ­ing lan­guage that addresses the threat of DDos attacks.

5. Criminal laws specif­i­cally address­ing the devel­op­ment and sale of cyber weapons.

6. Criminal and civil laws that address orga­ni­za­tions who fail to imme­di­ately report cyber attacks or data breaches that include those who destroy evi­dence of cyber attacks, sys­tems com­pro­mise and data theft.

7. Establishment of a quasi government/​business entity that coor­di­nates defen­sive and pro­tec­tive capa­bil­i­ties of the infor­ma­tion infra­struc­ture. This would also include a cyber attack and threat alert­ing system.

8. Establishing an Intelligence Center that is charged with cyber intel­li­gence col­lec­tion, analy­sis, trend report­ing as well as col­lab­o­ra­tion across the other intel­li­gence agencies.

9. A fed­eral cyber attack inves­ti­ga­tion unit that is the cen­ter of excel­lence and devel­ops tools and tech­niques as well as works with all other agen­cies and law enforce­ment to dis­sect cyber attacks and mali­cious code and assist with investigations.

10. Implement within the fed­eral cyber attack inves­ti­ga­tion unit a divi­sion that pro­vides suf­fi­cient audit and con­trol mea­sures to ensure the laws are being fol­lowed. The pri­vate sec­tor has already proven self gov­er­nance is unre­li­able to ensure adher­ence to the pro­tec­tion nec­es­sary for cyber defense.

Now I know there will be many com­ments about “big brother” and “big gov­ern­ment,” but given what has taken place thus far, I am not sure we have any other choice. It is deeply con­cern­ing that 85 per­cent of orga­ni­za­tions have admit­ted they have had sys­tems and data breaches. A sig­nif­i­cantly smaller num­ber have actu­ally reported them in accor­dance with the 40 data breach noti­fi­ca­tion laws that are cur­rently in place.

An improp­erly pro­tected com­puter or other device con­nected to the Internet is a cyber weapon wait­ing to be loaded and used.

– Kevin Coleman

Share |

September 29th, 2008 | Cyber-warfare | 409312 Comments »http://defensetech.org/2008/09/29/bring-in-the-cpp/Bring+in+the+CPP2008-09-29+11%3A54%3A45Ward You can skip to the end and leave a response. Pinging is currently not allowed.

« « Starship Troopers Meets G.I. Joe | The Next Generation of Drone Pilots » »

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

  1. Dr. Curiosity says:
    September 29, 2008 at 10:11 am

    A good, com­pre­hen­sive list. Okay, imme­di­ate thoughts that spring to mind:
    1/​2: Centralised repos­i­to­ries for upload­ing attack data. If I were attempt­ing to com­pro­mise a device or a net­work, that would be the first place I would look to take out of the loop, much like the pri­or­ity of remov­ing malware’s “phone home” capa­bil­i­ties to pre­vent any fur­ther poten­tial data leaks while clean­ing it up on a sys­tem. Any thoughts you’d care to share on hard­en­ing such a report­ing mech­a­nism?
    5: Given that a num­ber of “cyber weapons” are essen­tially weaponised secu­rity tools, I’d be rather con­cerned about throw­ing out the baby with the bath­wa­ter in terms of such leg­is­la­tion. I’m uncom­fort­able with the thought that merely pos­sess­ing a use­ful tool will be crim­i­nalised. We def­i­nitely need leg­is­la­tors who have secu­rity exper­tise or good access to it, as I’m sure you will agree.
    As a com­ment on your “big brother” point, I feel it’s impor­tant than any stan­dards and pro­vi­sions for soft­ware in such a sys­tem are formed as part of an open stan­dard (albeit fed­er­ally tested, ver­i­fied and cer­ti­fied — no pro­pri­etary “black box” devel­op­ments). Otherwise there’s too much of a chance that some lob­by­ist on the hill could attempt to turn a use­ful trusted com­put­ing par­a­digm into a ven­dor lock-​​in monop­oly which would not serve anyone’s best interests.

    Reply
  2. gsak says:
    September 29, 2008 at 11:17 am

    Officers & Directors of most com­pa­nies aren’t famil­iar enough with stuff like this to autho­rize it in their bud­gets; IT Managers are some­times gut­less, and aren’t will­ing to press for it. I’ve seen this, first-​​hand. Unless you come-​​down on a com­pany with the fire of Sarbanes-​​Oxley, you will get min­i­mal results, despite your best inten­tions.
    Maybe you’d get a few high-​​schoolers arrested for hav­ing direc­tional anten­nas, WiFi adapters that sup­port Promiscuous Mode, and BackTrack-​​equipped USB keys.
    This level of reg­u­la­tion, how­ever excel­lent on paper, would be counter-​​productive if writ­ten and enforced by the wrong minds.

    Reply
  3. Ptsfp says:
    September 29, 2008 at 11:30 am

    How about a rule for wire­less con­nec­tions? Wireless is the most unse­cure con­nec­tion type avail­able. And not just for the office, what about home?
    I read once that these guys would get the home addresses of exec­u­tive users and “war drive” their homes. They would sit out­side their homes with wifi lap­tops and see if they could access the exec’s home net­work. Many times the home net­works had no secu­rity enabled at all…
    Training the employ­ees to look out for social engi­neer­ing attacks would also be a huge pri­or­ity. In 18 years of com­puter sup­port I have only been chal­lenged twice when ask­ing for a user’s pass­word. Also many employ­ees assume that if you are inside the facil­ity, you belong there. I was unescorted 98% of the time on a clients site and have only been chal­lenged when walk­ing through a facil­ity 3 times in 18 years. Two of the chal­lenges were at a sin­gle loca­tion.
    During these times when every com­pany is mak­ing cut backs, many lob­bies are not even manned any­more. Turn off live net­work con­nec­tions in ungau­rded lob­bies. One pen­e­tra­tion test­ing com­pany bypassed a very high end fire­wall by sim­ply con­nect­ing a wifi router to a live jack in an unpro­tected lobby. Then they taped “IT depart­ment do not remove” on the router. They then could sit in the park­ing lot and have access to the net­work.
    Just some thoughts.

    Reply
  4. George says:
    September 29, 2008 at 2:53 pm

    Part one sec­tions a — d could be solved with a dif­fer­ent OS (Solaris, Linux, BSD, OS X, etc…) Security is a weak­est link, why does “evil”-ware still exist when we know what the weak link is…
    Part three, Legislation that man­dates soft­ware test­ing and vul­ner­a­bil­ity. What about open source soft­ware… Who is the ven­dor. Who gets the law­suit?
    Part five, cyber weapon. Uhhh what’s that? Give me a 486 with an inter­net con­nec­tion is that a “cyber weapon”. Are nmap, nc, dig, ping, nes­sus, all cyber weapons? Careful with laws and def­i­n­i­tions our we will out­law the “series of tubes”.
    LOVE part 10. Where do I put in the job appli­ca­tion that would be a fun team to work for “IF” prop­erly funded.

    Reply
  5. Kevin says:
    September 29, 2008 at 4:02 pm

    OPEN SOURCE
    Open source is a very small part of the over­all mar­ket. I was focus­ing on the 80% in the Posting. That being said we do need to address the Open Source issue. My Idea on open source con­sists of two parts.
    Part 1
    The author must cer­tify they have tested to what­ever they post to a cer­tain stan­dard.
    Part 2
    The orga­ni­za­tion that chooses to use open source must cer­tify they have tested the soft­ware to a cer­tain stan­dard.
    So both the authors and the users share in the respon­si­bil­ity for Open Source

    Reply
  6. Ptsfp says:
    September 30, 2008 at 3:20 pm

    Kevin,
    On the fire­wall side, I know a lot of com­pa­nies use Checkpoint.
    The founder and CEO, Gil Shwed, is a for­mer mem­ber of Israeli intel­li­gence, Unit 8200. I always fig­ured once an intel­li­gence offi­cer, always an intel­li­gence offi­cer. Could this pos­si­bly be a national secu­rity issue?
    Don’t get me wrong, I love Israel, but spooks mak­ing secu­rity devices always makes me nervous.

    Reply
  7. gsak says:
    October 1, 2008 at 4:28 pm

    Solid advice, all around.

    Reply
  8. Rigma says:
    October 1, 2008 at 7:05 pm

    Military pages that have forums/​specops dis­cus­sions should be kicked of WAN/​VOIP etc…
    They always hack people!

    Reply
  9. angel says:
    October 23, 2008 at 1:21 am

    That’s OK!But take a closer look fol­low­ing link,It’s great to DVD and PSP
    con­verter for mac!
    http://​www​.macd​v​drip​per​.org
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​r​i​p​p​e​r​-​s​u​i​t​e​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​c​o​n​v​e​r​t​e​r​-​s​u​i​t​e​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​c​o​p​y​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​c​r​e​a​t​o​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​t​o​-​i​p​o​d​-​c​o​n​v​e​r​t​e​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​t​o​-​i​p​h​o​n​e​-​c​o​n​v​e​r​t​e​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​t​o​-​m​p​4​-​c​o​n​v​e​r​t​e​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​t​o​-​a​p​p​l​e​-​t​v​-​c​o​n​v​e​r​t​e​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​t​o​-​p​s​p​-​c​o​n​v​e​r​t​e​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​t​o​-​b​l​a​c​k​b​e​r​r​y​-​c​o​n​v​e​r​t​e​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​m​a​c​-​d​v​d​-​a​u​d​i​o​-​r​i​p​p​e​r​.​h​tml
    http://​www​.macd​v​drip​per​.org/​h​o​w​-​t​o​-​e​d​i​t​-​d​v​d​-​t​r​i​m​-​v​i​d​e​o​-​c​r​o​p​-​t​a​k​e​-​e​f​f​e​c​t​s​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/,
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​i​p​o​d​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​a​p​p​l​e​-​t​v​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​p​s​p​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​m​p​e​g​4​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​m​4​v​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​3​g​p​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​m​p​g​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml
    http://​www​.vob​con​vert​er​mac​.com/​v​o​b​-​t​o​-​a​v​i​-​c​o​n​v​e​r​t​e​r​-​f​o​r​-​m​a​c​.​h​tml

    Reply

Leave a Reply

Click here to cancel reply.

Spam Protection by WP-SpamFree

By commenting on this topic you agree to the terms and conditions of our User Agreement

    Today's Hottest Topics
    • New Camo Pattern on the Block
    • Pinnacle's New Armor
    • Army Launches Examination of Armor Testing
    • BREAK-BREAK: Units to Get New Camo Revealed
    • Marines Quiet About Brutal New Weapon
    Recent Comments
    • Army Launches Examination of Armor Testing
      They are going to have to look at the whole...
      Wembley
    • New Camo Pattern on the Block
      Just look at this " picture " for a moment. The...
      Zandor
    • Zapping Drones from a Truck
      I know LOSAT seemed awesome but wasn't it cancelled? I...
      JimboJones
    • BAE to Market Mantis UAV to North America
      Yes you're quite right, I get to witness...
      JimboJones
    • New Camo Pattern on the Block
      I'm disappointed. When are they going to make clothes...
      Nadnerbus
    • VTOL JSF Arrives at Pax River
      Part II : * USMC attempts to make a single seat (no...
      freefallingbomb
    • VTOL JSF Arrives at Pax River
      Part I : I think we're not the only ones on the...
      freefallingbomb
    • Zapping Drones from a Truck
      Part III : Guided missiles will also be programmed to...
      freefallingbomb
    • Zapping Drones from a Truck
      Part II : If a tank shoots at another tank at only 5...
      freefallingbomb
    • Zapping Drones from a Truck
      Part I : To the poster "Will" : You wrote:...
      freefallingbomb
    Recent Articles
    • Army Launches Examination of Armor Testing
    • New Camo Pattern on the Block
    • BAE to Market Mantis UAV to North America
    • Pinnacle’s New Armor
    • Zapping Drones from a Truck
    • Northrop Invests Own Money In Fire Scout
    • IMINT: French Fashion Mavens Model MultiCam
    • VTOL JSF Arrives at Pax River
    • Super Cavitation and the Truth
    • Mantis Begins Search For Prey
    Recent Hot Topics
    • Marines Quiet About Brutal New Weapon
    • The Osprey has Landed
    • UPDATED: Details on Army's New Afghanistan Duds
    • VTOL JSF Arrives at Pax River
    • Iraq Cyber Attack and the DigiSEALs
    • Pinnacle's New Armor
    • (Proof) The Osprey Has Landed
    • Grim Wanat Footage
    • REPLACEMENT ARM, GOOD AS NEW
    • IMINT: French Fashion Mavens Model MultiCam
  • Channels: Military.com | Military Benefits | Military News | Off Duty | Join the Military | Military Education | Veteran Jobs | Military Money | Military Deals | Military Family | Military Community
  • Military.com Network: Military.com | MilBlogging | Defense Tech | DoD Buzz | SpouseBuzz | Fred's Place | GI Bill Express
  • Services: Army | Navy | Air Force | Marine Corps | Coast Guard | National Guard | Military Spouse
  • About Military.com About Us | Advertise With Us | Press | Affiliate Program | Monster Network | Help | Feedback | Privacy Policy | User Agreement | © 2009 Military Advantage