Risk
12/2/2011
12:42 PM
50%
50%

Bill Would Open Channels On Cyber Threats

Proposed legislation encourages the feds and private companies to share cyberintelligence information to stop threats to networks and critical infrastructure.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
House members have introduced new legislation that would promote information sharing between the government and private companies on matters of cybersecurity.

The Cyber Intelligence Sharing and Protection Act, introduced Wednesday by Reps. Mike Rogers and Dutch Ruppersberger of the House Permanent Select Committee on Intelligence--chairman and a ranking member of the committee, respectively--allows the feds to share intelligence information with companies to help them prevent cyber attacks before they happen.

The bill also allows for "approved businesses" to share cyber threat information among themselves and also with the government, according to a statement.

The bill would go "a long way in helping American businesses better protect their networks and their intellectual property," Rogers said in the statement.

"There are two types of companies in this country, those who know they've been hacked, and those who don't know they've been hacked," he said. "Economic predators, including nation-states, are blatantly stealing business secrets and innovation from private companies."

[ The Defense Department tests its networks to protect against cyber attack. Learn more: U.S. Cyber Command Practices Defense In Mock Attack. ]

The bill is a "good start" to helping lock down U.S. intellectual property and critical infrastructure such as the power grid and banking systems, Ruppersberger added.

While the feds has been sharing cyber-threat information with the private sector through a Department of Homeland Security program, the bill would expand and formalize this type of intelligence sharing among the government and private companies.

The bill would require the Director of National Intelligence to set up procedures for sharing cyber-threat intelligence with the private sector, ensuring those that receive the information have the proper security clearance.

It also allows private sector entities to share information anonymously or restrict who they share with, including the government. Congress has been considering a number of cybersecurity bills, but so far has not passed definitive, sweeping legislation in this area.

The Obama administration has taken strides to partner with the private sector particularly on matters of cybersecurity and sharing information. DHS fusion centers around the country routinely share information with local and state authorities, as well as some companies, about cyber threats.

Thursday, President Obama proclaimed December Critical Infrastructure Protection Month, highlighting and promoting efforts the feds are taking to partner with the private sector to share cybersecurity information.

Our annual Federal Government IT Priorities Survey shows how agencies are managing the many mandates competing for their limited resources. Also in the new issue of InformationWeek Government: NASA veterans launch cloud startups, and U.S. Marshals Service completes tech revamp. Download the issue now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/2/2011 | 10:28:32 PM
re: Bill Would Open Channels On Cyber Threats
Nothing wrong with sharing information to improve security.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
12/5/2011 | 9:13:57 PM
re: Bill Would Open Channels On Cyber Threats
This is a good step. I'd be happy to see a lot more disclosure about threats and known attacks among companies but any move towards information sharing is a good one.

Jim Rapoza is an InformationWeek Contributing Editor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-5084
Published: 2015-08-02
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically approximate attackers to obtain sensitive information via unspecified vectors.

CVE-2015-5352
Published: 2015-08-02
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time ...

CVE-2015-5537
Published: 2015-08-02
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.

CVE-2015-5600
Published: 2015-08-02
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumptio...

CVE-2015-1009
Published: 2015-07-31
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.

Dark Reading Radio
Archived Dark Reading Radio
What’s the future of the venerable firewall? We’ve invited two security industry leaders to make their case: Join us and bring your questions and opinions!