Original URL: http://www.theregister.co.uk/2006/09/14/us_cyber_security_exercise/
Simulated internet attacks in the US have uncovered gaps in the nation’s cybersecurity defences. In particular, cyber-defenders struggled to understand if simulated hack attacks were isolated or part of a more co-ordinated assault.
The four-day cyber-war exercise, conducted in February and the biggest such exercise to date, tested the US government's response to internet-based attacks on critical systems. The AP reports (http://www.smh.com.au/news/Technology/Government-says-simulated-Internet-attack-finds-holes-incybersecurity/2006/09/14/1157827049978.html) that these were of a type that "could crash air traffic control systems, halt subways or trigger power outages".
It is open to question if attacks of such a scope are feasible: we note that cyber-Armageddon has not happened yet, despite dire prognostications from prophets of doom. More plausible is the idea that cyber-attacks could create additional confusion in conventional terrorist attacks. But the exercises (which involved around 300 people from the US federal and state government agencies, nine IT companies and six public utilities looked at a different scenario.
During the simul-attacks, a motley crew of fake perpetrators, including "activist groups, disgruntled employees-turned-hackers and bloggers" were able to "[crash] the Federal Aviation Administration's control system, deface newspaper Web sites and threaten power outages".
The score-card of defenders contains these set-backs, but Department of Homeland Security (DHS) officials said that tests were successful as they will help to improve response to real attacks. There's more background on the exercise at the DHS website here (http://www.dhs.gov/dhspublic). ®
Task force aims to improve US cybersecurity (2 November 2007)
http://www.theregister.co.uk/2007/11/02/us-cybersecurity_task_force/
ITU pools experts to thwart cybercrime (8 October 2007)
http://www.theregister.co.uk/2007/10/08/itu_cybercrime_summit/
Bush on cyber war: 'a subject I can learn a lot about' (26 June 2007)
http://www.channelregister.co.uk/2007/06/26/bush_soothes_estonians_on_cyber_war/
Feds mandate 'secure' Windows set-up (22 March 2007)
http://www.channelregister.co.uk/2007/03/22/us_common_security_config/
UK air passengers feel safer (28 September 2006)
http://www.theregister.co.uk/2006/09/28/airport_security_theatre/
US appoints cybersecurity chief (20 September 2006)
http://www.theregister.co.uk/2006/09/20/us_cybersecurity_boss_appointed/
Cybersecurity contests go national (5 June 2006)
http://www.channelregister.co.uk/2006/06/05/security_contests/
Dept of Homeland Security tests cyberterrorism response (13 February 2006)
http://www.theregister.co.uk/2006/02/13/us_cyber_storm/
FBI publishes computer crime and security stats (5 August 2004)
http://www.theregister.co.uk/2004/08/05/fbi_security_stats/
The farce of federal cybersecurity (22 March 2004)
http://www.theregister.co.uk/2004/03/22/the_farce_of_federal_cybersecurity/
Fed: Cyberterror fears missed real threat (1 August 2003)
http://www.theregister.co.uk/2003/08/01/fed_cyberterror_fears_missed_real/
Mock cyberwar fails to end mock civilization (30 August 2002)
http://www.theregister.co.uk/2002/08/30/mock_cyberwar_fails_to_end/
© Copyright 2008