Feeds

US Navy malware infection risked submarine prang

Disgruntled contractor donned black hat after losing business

High performance access to file storage

An American contractor holding top-level security clearance has been convicted of sabotaging critical US Navy computers used for submarine traffic control.

Richard F Sylvestre, from Massachusetts, installed malware on a computer network at the Italian HQ of the US 6th Fleet, America's standing taskforce in the Mediterranean.

He later told investigators that he was upset after his company Ares Systems, which he then owned, had failed to win important naval business.

"If we can't trust people with top-security clearance, where are we?" lamented District Judge Rebecca B Smith when sentencing Sylvestre. Perhaps ironically, the hearing took place earlier this month at Norfolk, Virginia, one of the US Navy's biggest bases. Events were reported by the Virginian Pilot.

The computer network in question was used to track and record the actual and planned movements of US and allied submarines. A nuclear submarine proceeding at high speed underwater has very little ability to avoid collisions, as its sonar is typically blinded by the flow of water over its hull. Thus, it is normal practice for submarines to deconflict their journeys using a central traffic control system in which details of planned movements are stored. It was a system of this type that Sylvestre attacked.

The contractor turned saboteur apparently only intended to bring the system down, rather than extract highly-classified sub movements data from it. According to reports, he successfully crippled three machines of a possible five. Had all five succumbed "the Navy would have been blind", according to the prosecution.

Rear Admiral Jeffrey L Fowler, second in command of the 6th Fleet, broadly supported this position in a letter to the judge. The admiral wrote that malware infections in the systems at issue impaired "the ability of submarines to prevent collisions, and could result in loss of life". He also said that extra security procedures had been implemented since the incident.

After being nabbed by naval investigators, Sylvestre folded easily and pleaded guilty to a single count of damaging protected computers. That could have got him as much as 10 years in the federal pen, but his attorneys submitted a wide range of mitigating testimony. Sylvestre paid the Navy $25,000 towards repairs before appearing in court, and a psychiatrist said he suffered from depression and bipolar disorder. This might put the trick-cyclist concerned in dispute with the vetters who gave Sylvestre his clearance in the first place, assuming the testimony wasn't mere renta-psych court manoeuvring.

Perhaps most tellingly of all, the errant techie's sister also testified on his behalf. Ms Nancy Rapaport stated that if she had been asked to choose between aliens landing or her brother copping a felony rap, she would have assessed the alien arrival as the more likely event. There was no word on Ms Rapaport's overall opinion on the likelihood of an alien landing in the near future.

Sylvestre was sentenced to 12 to 18 months in federal prison and fined $10,000. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.