Risk
2/2/2010
04:35 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%
Repost This

U.S. 'Severely Threatened' By Cyber Attacks

The U.S. intelligence chief is urging greater cooperation and funding to defend against online threats.

Testifying before the Senate Intelligence Committee on Tuesday, the top U.S. intelligence official warned that U.S. critical infrastructure is "severely threatened" and called the recent cyber attack on Google "a wake-up call to those who have not taken this problem seriously."

"Sensitive information is stolen daily from both government and private sector networks, undermining confidence in our information systems, and in the very information these systems were intended to convey," said Dennis C. Blair, Director of National Intelligence, in prepared remarks outlining the U.S. intelligence community's annual assessment of threats.

While Blair's testimony covered terrorism, nuclear proliferation, geo-political conflicts, global economic problems, risks associated with climate change, and global health challenges, it addressed cyber threats first.

"Malicious cyber activity is occurring on an unprecedented scale with extraordinary sophistication," he said, citing as an example the emergence in 2009 of malware that modifies itself to avoid detection.

Cyber criminals' capabilities presently exceed the response capabilities of those defending networks, Blair said, and urged companies to promptly report attacks to help the government understand and address the full range of cyber threats. He warned that cyber-facilitated bank fraud and credit fraud have serious implications for the economy and national security.

Looking ahead, he said that voice and data networks will converge over the next five years and that this convergence amplifies the potential disruption from cyber attacks.

To protect cyberspace, the U.S. government will need to collaborate more effectively with private sector partners and international authorities, said Blair.

He also urged Congress to fully fund the U.S. government's cyber security initiatives, noting that Congress had funded most, but not all, of the Administration's request last year.

Blair's comments come just days after the emergence of a leaked report from MI5, the U.K.'s counter-intelligence agency, about the risk of Chinese cyber-espionage and malware-infected electronic gifts.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: LOL.
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6212
Published: 2014-04-19
Unspecified vulnerability in HP Database and Middleware Automation 10.0, 10.01, 10.10, and 10.20 before 10.20.100 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVE-2013-6213
Published: 2014-04-19
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1833.

CVE-2013-6214
Published: 2014-04-19
Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 9.05, 10.01, and 10.10 allows remote authenticated users to obtain sensitive information via unknown vectors, aka ZDI-CAN-2042.

CVE-2013-6215
Published: 2014-04-19
Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 10.01 and 10.10 allows remote authenticated users to execute arbitrary code via unknown vectors, aka ZDI-CAN-1977.

CVE-2013-6218
Published: 2014-04-19
Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors.

Best of the Web