Risk
2/17/2010
06:48 PM
50%
50%

U.S. Fails Test In Simulated Cyberattack

Organizers, observers of 'Cyber Shockwave' conclude nation is not ready for the real thing

A large-scale simulated cyberattack on the U.S. yesterday proved one thing, according to organizers: The country isn't prepared for a real attack.

In a press release issued today, the Bipartisan Policy Center (BPC) -- which organized "Cyber Shockwave" using a group of former government officials and computer simulations -- concluded the U.S is "unprepared for cyber threats."

Former Secretary of Homeland Security Michael Chertoff, who chaired the simulated National Security Council, says cyberterrorism "ought to be treated as a threat of sufficient seriousness that we give it the priority attention we've given weapons of mass destruction." Cyberterrorism is "more complicated by the fact that it involves every individual," Chertoff says. "Anybody who has a smartphone, who downloads an app, or gets on their PC is engaged in this process."

Reports from those who witnessed the simulation indicate that the U.S. defenders had difficulty identifying the source of the simulated attack, which in turn made it difficult to take action.

"During the exercise, a server hosting the attack appeared to be based in Russia," said one report. "However, the developer of the malware program was actually in the Sudan. Ultimately, the source of the attack remained unclear during the event."

The simulation envisioned an attack that unfolds during a single day in July 2011. When the council convenes to face this crisis, 20 million of the nation's smartphones have already stopped working. The attack -- the result of a malware program that had been planted in phones months earlier through a popular "March Madness" basketball bracket application -- disrupts mobile service for millions. The attack escalates, shutting down an electronic energy trading platform and crippling the power grid on the Eastern seaboard.

"A useful aspect of something like this simulation is it helps people visualize what is realistic and possible in some circumstances," says John McLaughlin, who played the role of director of national intelligence. "The smart thing is to prepare now, to do the legislation now, to do the bipartisan work now, to do the intelligence work now, the foreign policy work. These are all very complicated things, and we need to get started on them."

Stephen Friedman, who played the role of secretary of the Treasury, says of a potential cyberattack on the U.S.: "There is no question in my mind that this is a predictable surprise, and we need to get our acts together."

The panel of government officials agreed that cyberterrorism is a national security issue that needs to be addressed quickly and in a bipartisan manner. "It raises an issue of the system's responsibility to be able to come together in a nonpartisan way and figure out the answer to questions as opposed to kicking the can down the road until we're in an emergency," Chertoff says.

The exercise also raised legal questions regarding personal privacy versus national security. "We have to come to grips with the implications for our personal privacy and the relationship between the federal government and the private sector," says Jamie Gorelick, who played the role of attorney general.

"Cyber ShockWave demonstrated the tremendous challenges the government has in dealing with potential cyberattacks," says Jason Grumet, founder and president of the BPC. "Our goal for Cyber Shockwave was to identify real policy and preparedness issues that need to be addressed in order to combat an attack of this magnitude that escalates rapidly and is of unknown origin."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: nice post
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1950
Published: 2015-07-01
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.

CVE-2015-1951
Published: 2015-07-01
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.

CVE-2015-1967
Published: 2015-07-01
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.

CVE-2014-9734
Published: 2015-06-30
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php.

CVE-2014-9735
Published: 2015-06-30
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin a...

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report