Government // Cybersecurity
6/26/2014
09:10 AM
Tim Wilson
Tim Wilson
Quick Hits
50%
50%

Alexander: Cyber Security Pros Face Uphill Battle

Former NSA chief says rapid growth of data, malware will challenge security teams in coming years.

WASHINGTON -- Gartner Security & Risk Management Summit 2014 -- Former National Security Agency Director Keith Alexander says security professionals have their work cut out for them in the days ahead.

Shedding his customary uniform for an everyday suit and tie, the former general -- who retired last month and is now hanging out a shingle as a security consultant -- offered a wide range of views in a keynote presentation here. The gist: Data and malware are growing at rates so fast that it will be difficult for any security organization to keep up.

"In the coming year, it's estimated that we will create approximately 3.5 zetabytes of unique data -- that's more information than humans have produced in the last 5,000 years combined," Alexander said. "New technology is doubling every year. The top ten most in-demand jobs in 2013 were all jobs that didn't exist in 2004.

"So what we're doing right now is preparing students for jobs that don't yet exist, using technology that hasn't yet been invented, and facing problems that we don't know about yet. It's a huge challenge," he said.

At the same time, malware is growing at a corresponding rate, the former NSA director said. He recalled a recent partnership between the NSA and the Department of Defense in which the organizations uncovered 1,500 pieces of malware on US secret networks.

"What causes me the greatest concern is what might happen if our nation was hit by a destructive cyber attack," Alexander said, noting that most of the country's critical networks are operated by private industry. "If [a destructive attack] hit one of our Wall Street banks, the monetary damage could be in the trillions of dollars. We're not ready." He called for more cooperation across agencies, and across government and private industry.

Not surprisingly, Alexander also condemned recent "media leaks" -- he never mentioned Edward Snowden by name -- and said that they have contributed to recent physical attacks and an increase in deaths in places such as Iraq and Afghanistan. "The situation isn't getting better, it's getting worse," he said.

Even less surprisingly, Alexander defended the actions of the NSA in its intelligence-gathering and surveillance activities. He pointed to three recent investigations -- including one headed by ACLU investigator Jeff Stone -- which all indicate that the NSA is acting according to law.

"The NSA is not authorized to do something without a court order describing how to do it," Alexander said. "If you have a problem with what the NSA is doing, it's probably not with the NSA itself, but with what they've been asked to do."

 

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
6/26/2014 | 4:52:56 PM
what a difference a year makes
Hard to believe it was nearly a year ago that Gen. Alexander delivered the keynote at Black Hat while director of the NSA. It will be interesting to see if he comes to BH or DEF CON again. It's interesting to see him in a new role.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?