Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

DHS Partners with Industry to Offer State, Local Gov'ts Cybersecurity Aid

The US Department of Homeland Security teams up with Akamai and the Center for Internet Security to provide state and local governments with cybersecurity through DNS for free.

The US Department of Homeland Security has funded a year-long project to make state and local government networks and systems more difficult to hack and, at the same time, give federal authorities more insight into how the nation's smaller governments are being attacked.

This initiative is called the Malicious Domain Block and Reporting (MDBR) service and is the result of a partnership among the DHS's Cybersecurity and Infrastructure Security Agency (CISA), the Center for Internet Security (CIS), and Akamai. It currently serves 346 of the approximately 40,000 state, local, tribal, or territorial (SLTT) governments in the United States. 

MDBR acts as the domain name system (DNS) servers for participating SLTT governments, blocking a variety of suspicious and malicious sites, known malware channels, and phishing domains while reporting trends to CISA, which will use the information to create threat intelligence feeds for government agencies.

Related Content:

Information Operations Spotlighted at Black Hat as Election Worries Rise

Local, State Governments Face Cybersecurity Crisis

The service will act as one more layer of defense for state and local governments during a critical time, says Patrick Sullivan, chief technology officer for security strategy at Akamai.

"It is a critical time for local government — you have the elections while everyone has become more dependent on the government services, because of the pandemic," he says. "And over the past year or so, local governments have also been targeted by ransomware attacks."

As the US presidential election nears, security experts are increasingly worried about the cybersecurity of state and local governments, especially counties, where voter rolls are typically managed. Russia put considerable effort into hacking and disinformation campaigns during the 2016 presidential election, according to the broad consensus among US intelligence agencies and multiple congressional reports.

Local governments are at particular risk as they typically have razor-thin budgets and no full-time cybersecurity specialists. In 2019, more than 163 ransomware attacks targeted local and county government agencies and organizations. 

By partnering with Akamai and CISA, the Multi-State Information Sharing and Analysis Center (MS-ISAC) believes the technology will give SLTT governments a simple way to beef up their cybersecurity, James Globe, vice president of operations and security services at CIS, which runs the MS-ISAC, said in a statement

"It will be a key player in [our] growing arsenal of our defense-in-depth toolkit," he said.

The DNS filtering and blocking technology central to MDBR comes from Akamai, but it is not unique. OpenDNS, which started in 2006 and was acquired by Cisco in 2015, made the approach popular. Several other cybersecurity firms have similar technology. Akamai, however, does have scope: the company's network currently processes about two trillion DNS requests every day, says Sullivan.

"It is an easy way to add security, because with the way that the US is organized, where many state and local governments may not be large organizations that can support a security team, they need the simplicity," he says. To use the MDBR service, government agencies can make a simple DNS change at their routers or domain server to gain the benefits of Akamai's security checks.

In addition to simplicity, a strong advantage of blocking malicious and suspicious links at the point of domain lookup is speed, Sullivan says. "The thought is that the earlier in the kill chain or the request flow that you can block, the better — there are less consequences and it is less work for IT to remediate," he says.

Threat intelligence gleaned from the service will be used by the DHS to increase threat awareness and push attack indicators back to state and local governments, according to Sullivan.

Since 2016, the DHS has become a primary source of threat intelligence for state and local governments but government agencies, including the cybersecurity functions at DHS, are often criticized for their lack of information sharing. This latest initiative could change, or at least mitigate, those concerns. 

"It is a really good way for DHS to share threat intelligence down to state and local governments," he says. "If you are a sophisticated organization, you can consume that threat intelligence, but if you are not, then the CIS can integrate that into the service."

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31755
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31756
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copie...
CVE-2021-31757
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31758
PUBLISHED: 2021-05-07
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setportList allows attackers to execute arbitrary code on the system via a crafted post request.
CVE-2021-31458
PUBLISHED: 2021-05-07
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handlin...