Feeds

For security's sake! Send your kid to hacker camp

No easy fix for doom and gloom

SANS - Survey on application security programs

Containing the threat

So far, the panelists agreed, the US has yet to find a way to effectively contain the threats it faces in the event of a wide-scale cyber attack. And at least part of the responsibility for that failure is the result of treating the cyber attacks as if they were a traditional national security threat.

Although the cold war and cyber warfare both involve prolonged conflicts with high stakes, they have little else in common, said Scott Algeier, exec director IT-ISAC, a non-profit IT consulting group.

For one thing, throughout the cold war's five decades, it was always clear who the adversaries were, and for another, a tenet known as mutually assured destruction provided a strong incentive not to use nuclear arms. Unfortunately, a US cyber war could involve many different actors who could be scattered across the globe. Many of them believe they have little to lose, so it's much harder to deter them as well.

"The generals had better pay attention to their IT infrastructure before they go to war," said Kenneth Geers, the US representative to the NATO cyber center of excellence. "Your planes, if they cross the airspace and they pull the trigger, what if nothing happens? Theoretically that's quite possible."

By 2010, the majority of US planes will be unmanned, he said. "The attack surface is getting larger and larger, potentially too large to defend," he added.

The panelists sounded a grim tone on the possibility of deterring attacks, mainly because they involve the dynamics of what analysts call asymmetrical warfare. That means an adversary with relatively modest resources is nonetheless able to mount a paralyzing attack on a much larger target.

"One of the things I don't think we'll be able to neutralize is the very low cost that is required to develop attacks," said Skoudis. "Somebody spending a few hundred dollars on a netbook and spending some time mastering various kinds of reverse engineering analysis can come up with computer attacks that can spread to millions of machines."

Hence, Skoudis's calls for a major push a la the US space program in the 1950s or the Manhattan Project, the World War II campaign by the US to build a nuclear bomb. To the extent it's possible at all, deterrence will only come by making attacks too hard and costly to be worth carrying out.

"The guy who's trying to find a flaw and write a big worm and take over millions of machines will have to work that much harder," he explained. "I think it's going to be hard to get there, but that's one of the things we could do." ®

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.