Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

DHS Partners with Industry to Offer State, Local Gov'ts Cybersecurity Aid

The US Department of Homeland Security teams up with Akamai and the Center for Internet Security to provide state and local governments with cybersecurity through DNS for free.

The US Department of Homeland Security has funded a year-long project to make state and local government networks and systems more difficult to hack and, at the same time, give federal authorities more insight into how the nation's smaller governments are being attacked.

This initiative is called the Malicious Domain Block and Reporting (MDBR) service and is the result of a partnership among the DHS's Cybersecurity and Infrastructure Security Agency (CISA), the Center for Internet Security (CIS), and Akamai. It currently serves 346 of the approximately 40,000 state, local, tribal, or territorial (SLTT) governments in the United States. 

MDBR acts as the domain name system (DNS) servers for participating SLTT governments, blocking a variety of suspicious and malicious sites, known malware channels, and phishing domains while reporting trends to CISA, which will use the information to create threat intelligence feeds for government agencies.

Related Content:

Information Operations Spotlighted at Black Hat as Election Worries Rise

Local, State Governments Face Cybersecurity Crisis

The service will act as one more layer of defense for state and local governments during a critical time, says Patrick Sullivan, chief technology officer for security strategy at Akamai.

"It is a critical time for local government — you have the elections while everyone has become more dependent on the government services, because of the pandemic," he says. "And over the past year or so, local governments have also been targeted by ransomware attacks."

As the US presidential election nears, security experts are increasingly worried about the cybersecurity of state and local governments, especially counties, where voter rolls are typically managed. Russia put considerable effort into hacking and disinformation campaigns during the 2016 presidential election, according to the broad consensus among US intelligence agencies and multiple congressional reports.

Local governments are at particular risk as they typically have razor-thin budgets and no full-time cybersecurity specialists. In 2019, more than 163 ransomware attacks targeted local and county government agencies and organizations. 

By partnering with Akamai and CISA, the Multi-State Information Sharing and Analysis Center (MS-ISAC) believes the technology will give SLTT governments a simple way to beef up their cybersecurity, James Globe, vice president of operations and security services at CIS, which runs the MS-ISAC, said in a statement

"It will be a key player in [our] growing arsenal of our defense-in-depth toolkit," he said.

The DNS filtering and blocking technology central to MDBR comes from Akamai, but it is not unique. OpenDNS, which started in 2006 and was acquired by Cisco in 2015, made the approach popular. Several other cybersecurity firms have similar technology. Akamai, however, does have scope: the company's network currently processes about two trillion DNS requests every day, says Sullivan.

"It is an easy way to add security, because with the way that the US is organized, where many state and local governments may not be large organizations that can support a security team, they need the simplicity," he says. To use the MDBR service, government agencies can make a simple DNS change at their routers or domain server to gain the benefits of Akamai's security checks.

In addition to simplicity, a strong advantage of blocking malicious and suspicious links at the point of domain lookup is speed, Sullivan says. "The thought is that the earlier in the kill chain or the request flow that you can block, the better — there are less consequences and it is less work for IT to remediate," he says.

Threat intelligence gleaned from the service will be used by the DHS to increase threat awareness and push attack indicators back to state and local governments, according to Sullivan.

Since 2016, the DHS has become a primary source of threat intelligence for state and local governments but government agencies, including the cybersecurity functions at DHS, are often criticized for their lack of information sharing. This latest initiative could change, or at least mitigate, those concerns. 

"It is a really good way for DHS to share threat intelligence down to state and local governments," he says. "If you are a sophisticated organization, you can consume that threat intelligence, but if you are not, then the CIS can integrate that into the service."

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Inside North Korea's Rapid Evolution to Cyber Superpower
Kelly Sheridan, Staff Editor, Dark Reading,  12/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-29565
PUBLISHED: 2020-12-04
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the...
CVE-2020-5675
PUBLISHED: 2020-12-04
Out-of-bounds read issue in GT21 model of GOT2000 series (GT2107-WTBD all versions, GT2107-WTSD all versions, GT2104-RTBD all versions, GT2104-PMBD all versions, and GT2103-PMBD all versions), GS21 model of GOT series (GS2110-WTBD all versions and GS2107-WTBD all versions), and Tension Controller LE...
CVE-2020-29562
PUBLISHED: 2020-12-04
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
CVE-2020-28916
PUBLISHED: 2020-12-04
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
CVE-2020-29561
PUBLISHED: 2020-12-04
An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exception.