Risk
3/8/2012
04:14 PM
50%
50%

Feds Simulate Crippling Cybersecurity Attack On NYC Electricity

Senators and agencies participate in exercise, which simulated how the government might respond in the event of a cyberattack on New York's electricity supply during a summer heat wave.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
U.S. senators Wednesday participated in a multi-agency exercise to simulate how the government might respond in the event of a cyber attack that cripples New York City’s electric supply during a summer heat wave.

The demonstration was part of an effort by lawmakers to encourage bi-partisan cooperation on cybersecurity to underscore how important it is for the feds to align on the issue.

In addition to members of the Senate, top cybersecurity officials from various departments and agencies--including the White House, the Department of Homeland Security (DHS), FBI, and National Security Agency--also participated in the event, which illustrated the consequences of a massive cyber attack at a critical time in a major U.S. city. Officials were keeping exact details of what happened at the exercise confidential.

The senior administration officials involved--including DHS secretary Janet Napolitano, White House cybersecurity coordinator Howard Schmidt, and FBI director Robert Mueller--used the exercise to stress the need for legislation to more effectively prevent and respond to potential cyber attacks in the United States, said DHS press secretary Matt Chandler. Laws that officials want Congress to pass include risk-based performance standards for critical infrastructure systems so they meet at least a baseline level of security.

[ Federal cybersecurity incidents are growing. See Federal Cybersecurity Incidents Rocket 650% In 5 Years. ]

The Obama administration submitted a cybersecurity proposal to Congress last May to outline its priorities for cybersecurity and to press lawmakers to pass comprehensive legislation to protect critical U.S. infrastructure that powers the Internet, utilities, and other control systems that are vulnerable to attack. Cybersecurity coordinator Schmidt also pressured Congress in January to pass cybersecurity legislation; however, it has yet to do so, though it is considering a number of bills.

Since then other officials also have been sounding the alarm to get Congress to take action. Thursday National Security Council spokeswoman Caitlyn Hayden urged it to provide legislation to support federal cybersecurity efforts already underway.

"Only Congress can modernize our underlying laws and give us the full range of tools our cybersecurity professionals need to more effectively deal with this growing and increasingly sophisticated threat," she said.

Earlier this week commission co-chairs Tom Kean and Lee Hamilton, former 9/11 commission co-chairs, also took up the cause in a letter sent to Majority Leader Harry Reid and Minority Leader Mitch McConnell. Senate co-sponsors of bi-partisan cybersecurity legislations--Sens. Joe Lieberman, I-Conn., Susan Collins, R-Maine, Jay Rockefeller, D-W.Va., and Dianne Feinstein, D-Calif.--released the letter.

"Comprehensive legislation is needed to flesh out a range of pressing cyber security policy questions, including how the federal government should defend against and respond to cyber attacks and what measures private sector owners of critical infrastructure should take to prevent the damage or disruption of their often interconnected and interdependent networks," the senators said in the letter, which Rockefeller’s office sent to InformationWeek. "Nothing less than the security of our electricity, communications, financial, and water systems is at stake."

How 10 federal agencies are tapping the power of cloud computing--without compromising security. Also in the new, all-digital InformationWeek Government supplement: To judge the success of the OMB's IT reform efforts, we need concrete numbers on cost savings and returns. Download our Cloud In Action issue of InformationWeek Government now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ANON1241624276539
50%
50%
ANON1241624276539,
User Rank: Apprentice
3/9/2012 | 6:24:56 PM
re: Feds Simulate Crippling Cybersecurity Attack On NYC Electricity
BPrince, Is that a serious question? (Just being cynical, not insulting.) OF COURSE I don't!
Bprince
50%
50%
Bprince,
User Rank: Ninja
3/9/2012 | 5:15:59 PM
re: Feds Simulate Crippling Cybersecurity Attack On NYC Electricity
@ readers: how confident are you in the goverment's ability to respond effectively to this type of cyber attack?
Brian Prince, InformationWeek/Dark Reading Comment Moderator
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6196
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSp...

CVE-2014-7247
Published: 2014-11-25
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?