Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

DHS Partners with Industry to Offer State, Local Gov'ts Cybersecurity Aid

The US Department of Homeland Security teams up with Akamai and the Center for Internet Security to provide state and local governments with cybersecurity through DNS for free.

The US Department of Homeland Security has funded a year-long project to make state and local government networks and systems more difficult to hack and, at the same time, give federal authorities more insight into how the nation's smaller governments are being attacked.

This initiative is called the Malicious Domain Block and Reporting (MDBR) service and is the result of a partnership among the DHS's Cybersecurity and Infrastructure Security Agency (CISA), the Center for Internet Security (CIS), and Akamai. It currently serves 346 of the approximately 40,000 state, local, tribal, or territorial (SLTT) governments in the United States. 

MDBR acts as the domain name system (DNS) servers for participating SLTT governments, blocking a variety of suspicious and malicious sites, known malware channels, and phishing domains while reporting trends to CISA, which will use the information to create threat intelligence feeds for government agencies.

Related Content:

Information Operations Spotlighted at Black Hat as Election Worries Rise

Local, State Governments Face Cybersecurity Crisis

The service will act as one more layer of defense for state and local governments during a critical time, says Patrick Sullivan, chief technology officer for security strategy at Akamai.

"It is a critical time for local government — you have the elections while everyone has become more dependent on the government services, because of the pandemic," he says. "And over the past year or so, local governments have also been targeted by ransomware attacks."

As the US presidential election nears, security experts are increasingly worried about the cybersecurity of state and local governments, especially counties, where voter rolls are typically managed. Russia put considerable effort into hacking and disinformation campaigns during the 2016 presidential election, according to the broad consensus among US intelligence agencies and multiple congressional reports.

Local governments are at particular risk as they typically have razor-thin budgets and no full-time cybersecurity specialists. In 2019, more than 163 ransomware attacks targeted local and county government agencies and organizations. 

By partnering with Akamai and CISA, the Multi-State Information Sharing and Analysis Center (MS-ISAC) believes the technology will give SLTT governments a simple way to beef up their cybersecurity, James Globe, vice president of operations and security services at CIS, which runs the MS-ISAC, said in a statement

"It will be a key player in [our] growing arsenal of our defense-in-depth toolkit," he said.

The DNS filtering and blocking technology central to MDBR comes from Akamai, but it is not unique. OpenDNS, which started in 2006 and was acquired by Cisco in 2015, made the approach popular. Several other cybersecurity firms have similar technology. Akamai, however, does have scope: the company's network currently processes about two trillion DNS requests every day, says Sullivan.

"It is an easy way to add security, because with the way that the US is organized, where many state and local governments may not be large organizations that can support a security team, they need the simplicity," he says. To use the MDBR service, government agencies can make a simple DNS change at their routers or domain server to gain the benefits of Akamai's security checks.

In addition to simplicity, a strong advantage of blocking malicious and suspicious links at the point of domain lookup is speed, Sullivan says. "The thought is that the earlier in the kill chain or the request flow that you can block, the better — there are less consequences and it is less work for IT to remediate," he says.

Threat intelligence gleaned from the service will be used by the DHS to increase threat awareness and push attack indicators back to state and local governments, according to Sullivan.

Since 2016, the DHS has become a primary source of threat intelligence for state and local governments but government agencies, including the cybersecurity functions at DHS, are often criticized for their lack of information sharing. This latest initiative could change, or at least mitigate, those concerns. 

"It is a really good way for DHS to share threat intelligence down to state and local governments," he says. "If you are a sophisticated organization, you can consume that threat intelligence, but if you are not, then the CIS can integrate that into the service."

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3243
PUBLISHED: 2021-04-15
Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function.
CVE-2021-29448
PUBLISHED: 2021-04-15
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
CVE-2021-30138
PUBLISHED: 2021-04-15
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2021-27112
PUBLISHED: 2021-04-15
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.
CVE-2021-20288
PUBLISHED: 2021-04-15
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associa...