Latest news
During the simulated cyber attack that took place yesterday in Washington and was recorded by the CNN, one thing became clear: the US are still not ready to deflect or mitigate such an attack to an extent that would not affect considerably the everyday life of its citizens.The ballroom of the Washington's Mandarin Oriental Hotel was for this event transformed into the the White House Situation Room, complete with three video screens displaying maps of the country, simulated updates and broadcasts by "GNN", an imaginary television network "covering" the crisis.
A bevy of former top US officials were given various roles to play:
- John Negroponte, the former Director of National Intelligence, as the Secretary of State
- Michael Chertoff, the ex DHS Secretary, as the National Security Adviser
- Fran Townsend, former White House Homeland Security Advisor, as the Secretary of DHS
- John McLaughlin, ex CIA deputy director, as the Director of National Intelligence
- Jamie Gorelick, former deputy attorney general, as attorney general
- Charles Wald, retired Air Force general, as the Secretary of Defense
- Stephen Friedman, former director of the National Economic Council, as the Treasury Secretary.
According to The Sydney Morning Herald, the group considered various maneuvers to put an end to the attack and mitigate the effects it had on national networks.
When the servers serving the malware were "discovered" to be located in Russia, "National Security Advisor" Chertoff immediately began inquiring about the possibility of shutting them down and the implications of such an action. "Would the Russians view that as an attack?" he wanted to know. "If the attacker is either a state actor or a terrorist group what are our options for responding or retaliating?"
Regarding a possible shutdown of the cell phone and Internet service to prevent a cascading effect, the group found out that federal agencies actually don't have the authority to do so, and that companies providing these services might be unwilling to do it when asked.
Another thing that might prove to be an issue is the Governors' reluctancy to put their power in the hands of the federal government, which would possibly lead to a nationalization of the National Guard.
Federal Times reports that "attorney general" Gorelick mused on the idea of introducing laws that would allow the government to seize broader power for the time it takes to suppress a nation-wide cyber attack.
When the "exercise" came to an end, the likelihood of such a scenario was discussed. "Secretary of State" Negroponte declared that the attack seemed very plausible to him. "I don't think we're as prepared as we should be," said "Secretary of Defense" Wald.
Joe Lockhart, the former press secretary during the Clinton administration, worries that the possibility of such an attack and the development of an effective response is still not high enough on the government priority list.
Will a real cyber attack of these proportions be required to wake the government up? Probably. In the meantime, war games such as these can start the ball rolling into the right direction.


Spotlight

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

Application vulnerabilities still a top security concern
Posted on 16 May 2013. | Respondents to a new (ISC)2 study identified application vulnerabilities as their top security concern. A significant gap persists between software developers’ priorities and security professionals’ concerns.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






