Risk
10/6/2010
08:24 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Inside DHS' Classified Cyber Coordination Headquarters

The Department of Homeland Security recently brought its classified National Cybersecurity and Communications Integration Center down to an unclassified level for one day only, and InformationWeek Government was there to take photos. The facility looks and functions like a state-of-the-art network operations center and much more. The NCCIC, as it's called, is the locus of DHS-led inter-agency cybersecurity work in the federal government. That includes providing an integrated response to cyber th
Previous
1 of 11
Next


Typically, the National Cybersecurity and Communications Integration Center, the agency's hub for coordinated responses to cyber attacks, is a classified facility, residing several floors above a chain restaurant in a non-descript Arlington, Va., office building. Visitors to the Department of Homeland Security facility are required to go through several layers of security before they can actually enter the office space, including locking up their cell phones in tiny lockers. But for one day only, the DHS brought the NCCIC offices down to an unclassified level and InformationWeek Government was there to take photos.

The occasion for DHS briefly opening the doors of NCCIC to reporters was a preview of Cyber Storm III, an international, coordinated cybersecurity simulation that entailed mock attacks on the Internet's domain name system. The exercise tested both the draft National Cyber Incident Response Plan, an effort to provide a coordinated response to major cybersecurity incidents NCCIC. The large-scale exercise included representatives from seven cabinet-level federal departments, intelligence agencies, 11 states, 12 international partners and 60 private sector companies in multiple critical infrastructure sectors like banking, defense, energy and transportation. Though the facility may have been brought down to an unclassified level for the event, we were still warned against taking pictures of cyber-analysts' faces, photos of physical security sensors on the walls and ceilings, and wandering off into areas of the facility where classified work might still be going on.

SEE ALSO:

DHS Launches Cyber Attack Exercise

Next Generation Defense Technologies

NSA Official Says Cybersecurity Starts At The Top

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-4231
Published: 2015-07-03
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

CVE-2015-4232
Published: 2015-07-03
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.

CVE-2015-4234
Published: 2015-07-03
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.

CVE-2015-4237
Published: 2015-07-03
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv0...

CVE-2015-4239
Published: 2015-07-03
Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report