Ensuring Proper Coverages With Low Cost Insurance By Jason Shroot.
Thursday, November 29, 2012
Senate Rejects Cybersecurity Measure a Second Time
The vote forecloses action on the legislation until next year, despite warnings by national security officials that the U.S. needs new ways to protect financial institutions, power plants and other critical infrastructure from assault.
"The bill that was, and is, most important to the intelligence community and to the Pentagon was just killed," Senate Majority Leader Harry Reid said after the vote. "So everyone should understand, cyber security is dead for this Congress. What an unfortunate thing. But that is the way it is."
The legislation, dubbed the Cybersecurity Act or 2012, would make it easier for companies and the government to share information about cyber threats and encourage companies to take steps to reinforce security on their networks.
In a repeat of a Senate vote in August, most Democrats voted in favor of the measure while most Republicans voted against it.
Business groups, led by the U.S. Chamber of Commerce, opposed the legislation.
"Frankly, the underlying bill is not supported by the business community, for all the right reasons, and they are the ones who are impacted by it," said Senator Saxby Chambliss, a Georgia Republican and vice chairman of the Intelligence Committee, who opposed the bill. "They are the ones who are going to be called on to comply with the mandates and the regulations. Frankly, it is not going to give them the kind of protection they need from cyber-attacks."
Senator Dianne Feinstein, who chairs the Senate Intelligence Committee, warned before the vote of a looming digital threat.
"I am very worried there will be a major cyberattack on this nation," Feinstein said. "I do not say that without intelligence to back it up."
The vote follows a string of cyberattacks since September on at least 10 banks and a vow from a group that has claimed responsibility for the assaults to mount others.
The attacks flooded lines that connect banks to the Internet and prevented customers from retrieving their accounts.
In October, Defense Secretary Leon Panetta called the attacks "unprecedented" in their scale and speed.
View the Original article
Saturday, September 29, 2012
White House Readies Executive Order on Cybersecurity
The prospective order would give the agencies 90 days to propose new regulations and create a new cybersecurity council at the Department of Homeland Security with representatives from the Defense Department, Justice Department, Director of National Intelligence and the Department of Commerce, a former government cyber-security official told Reuters.
“It tells those who have the ability to regulate to go forth and do so,” said the person, who is currently outside the government and spoke on condition of anonymity in order to preserve access to government officials.
The draft executive order includes elements of what had been the leading cybersecurity overhaul bill in the Senate, which was defeated this summer amid opposition from industries opposed to increased regulation.
Senate Homeland Security Committee Chairman Joe Lieberman, an independent and one of the principal authors of that bill, on Monday urged the White House to issue such an order.
“The Department of Homeland Security has clear authority, if directed by you, to conduct risk assessments of critical infrastructure, identify those systems or assets that are most vulnerable to cyber attack and issue voluntary standards for those critical systems or assets to maintain adequate cybersecurity,” Lieberman wrote to President Barack Obama.
The document has been circulating among the agencies and might go to top officials for their comments as soon as this week, another person involved in the process said.
A spokeswoman for the administration’s National Security Council, Caitlin Hayden, confirmed that an order was being considered but would not provide details. “We’re not commenting on the elements,” Hayden said.
PUBLIC-PRIVATE COOPERATIONFormer White House cybersecurity policy coordinator Howard Schmidt said the proposed order would also ask DHS to confer with independent agencies, such as electric regulators and others that don’t answer to the president, to see who would take responsibility on cybersecurity.
The hope, said Schmidt, who has seen a recent draft, is that if those agencies won’t let DHS act they would do it themselves, as the Securities and Exchange Commission did in October when it issued guidance on when companies should disclose cyber attacks.
The Commerce Department and the Pentagon declined to comment. Spokespeople for Lieberman and for Senator John Rockefeller, another Democratic leader on the issue who has asked for an executive order, said their offices had not been given copies of the draft.
Cybersecurity has become a major issue in Congress and for the White House, with intelligence officials warning of constant exploration of protected computer systems by hackers and both past incursions and the likelihood of more damaging future attacks on electric plants, banks and stock exchanges.
As of two weeks ago, the planned order did not include any penalties for companies that fail to adhere to the standards. or rewards for those who do. “There are no carrots or sticks,” one person with a recent copy said.
If the order emerges before the election in November, it could become an issue in the campaign. Leading Republicans faulted the Lieberman bill as too onerous. The U.S. Chamber of Commerce, which also criticized that bill, declined to comment on Monday on the merits of a prospective order.
But Lieberman said his bill had been watered down in pursuit of a compromise and asked in his letter Monday that Obama explore means for making the standards mandatory.
Both Lieberman and administration officials have said they will still seek legislation, which could go further in many ways. It might, for example, provide liability protection for companies that share information with government officials or that meet the standards but still get hacked.
Copyright 2012 Reuters. Click for restrictions.Email ThisPrintNewslettersTweetCategories: National NewsTopics: federal cybersecurity legisaltion, Obama Administration cybersecurity executive order, Senate cybersecurity billHave a hot lead? Email us at newsdesk
View the Original article
Tuesday, May 15, 2012
Cybersecurity Experts Eye Self-Correcting Network to Thwart Hackers
In the online struggle for network security, Kansas State University cybersecurity experts are adding an ally to the security force: the computer network itself.
Scott DeLoach, professor of computing and information sciences, and Xinming “Simon” Ou, associate professor of computing and information sciences, are researching the feasibility of building a computer network that could protect itself against online attackers by automatically changing its setup and configuration.
DeLoach and Ou were recently awarded a five-year grant of more than $1 million from the Air Force Office of Scientific Research to fund the study “Understanding and quantifying the impact of moving target defenses on computer networks.” The study, which began in April, will be the first to document whether this type of adaptive cybersecurity, called moving-target defense, can be effective. If it can work, researchers will determine if the benefits of creating a moving-target defense system outweigh the overhead and resources needed to build it.
Helping Ou and DeLoach in their investigation and research are Kansas State University students Rui Zhuang and Su Zhang, both doctoral candidates in computing and information sciences from China, and Alexandru Bardas, doctoral student in computing and information sciences from Romania.
As the study progresses the computer scientists will develop a set of analytical models to determine the effectiveness of a moving-target defense system. They will also create a proof-of-concept system as a way to experiment with the idea in a concrete setting.
“It’s important to investigate any scientific evidence that shows that this approach does work so it can be fully researched and developed,” DeLoach said. He started collaborating with Ou to apply intelligent adaptive techniques to cybersecurity several years ago after a conversation at a university open house.
The term moving-target defense
View the Original article