Feeds

US Navy malware infection risked submarine prang

Disgruntled contractor donned black hat after losing business

The essential guide to IT transformation

An American contractor holding top-level security clearance has been convicted of sabotaging critical US Navy computers used for submarine traffic control.

Richard F Sylvestre, from Massachusetts, installed malware on a computer network at the Italian HQ of the US 6th Fleet, America's standing taskforce in the Mediterranean.

He later told investigators that he was upset after his company Ares Systems, which he then owned, had failed to win important naval business.

"If we can't trust people with top-security clearance, where are we?" lamented District Judge Rebecca B Smith when sentencing Sylvestre. Perhaps ironically, the hearing took place earlier this month at Norfolk, Virginia, one of the US Navy's biggest bases. Events were reported by the Virginian Pilot.

The computer network in question was used to track and record the actual and planned movements of US and allied submarines. A nuclear submarine proceeding at high speed underwater has very little ability to avoid collisions, as its sonar is typically blinded by the flow of water over its hull. Thus, it is normal practice for submarines to deconflict their journeys using a central traffic control system in which details of planned movements are stored. It was a system of this type that Sylvestre attacked.

The contractor turned saboteur apparently only intended to bring the system down, rather than extract highly-classified sub movements data from it. According to reports, he successfully crippled three machines of a possible five. Had all five succumbed "the Navy would have been blind", according to the prosecution.

Rear Admiral Jeffrey L Fowler, second in command of the 6th Fleet, broadly supported this position in a letter to the judge. The admiral wrote that malware infections in the systems at issue impaired "the ability of submarines to prevent collisions, and could result in loss of life". He also said that extra security procedures had been implemented since the incident.

After being nabbed by naval investigators, Sylvestre folded easily and pleaded guilty to a single count of damaging protected computers. That could have got him as much as 10 years in the federal pen, but his attorneys submitted a wide range of mitigating testimony. Sylvestre paid the Navy $25,000 towards repairs before appearing in court, and a psychiatrist said he suffered from depression and bipolar disorder. This might put the trick-cyclist concerned in dispute with the vetters who gave Sylvestre his clearance in the first place, assuming the testimony wasn't mere renta-psych court manoeuvring.

Perhaps most tellingly of all, the errant techie's sister also testified on his behalf. Ms Nancy Rapaport stated that if she had been asked to choose between aliens landing or her brother copping a felony rap, she would have assessed the alien arrival as the more likely event. There was no word on Ms Rapaport's overall opinion on the likelihood of an alien landing in the near future.

Sylvestre was sentenced to 12 to 18 months in federal prison and fined $10,000. ®

5 things you didn’t know about cloud backup

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
KER-CHING! CryptoWall ransomware scam rakes in $1 MEEELLION
Anatomy of the net's most destructive ransomware threat
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
prev story

Whitepapers

Gartner critical capabilities for enterprise endpoint backup
Learn why inSync received the highest overall rating from Druva and is the top choice for the mobile workforce.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.