Critical Infrastructure in the Cyber Crosshairs - Can U.S. Stop More Attacks?


Just weeks after the Colonial Pipeline - which provides 45% of the East Coast's diesel, gasoline, and kerosene supplies - went offline following a ransomware attack - the New York City Metropolitan Transit Authority announced that it was also being targeted became a cyber attack. The news also came when JBS Foods, the world's largest meat producer, was also the victim of a Russia-based hacking group.

The White House urged private companies to take "immediate action" to strengthen their ransomware defenses.

"Ransomware attacks have disrupted organizations around the world, from hospitals in Ireland, Germany and France to pipelines in the US and banks in the UK," Anne Neuberger, assistant national security advisor for cyber and new technologies, wrote in a memo to company and business leaders at the beginning of the week.

“The threats are serious and increasing. We urge you to take these critical steps to protect your organizations and the American public, ”she added. "The private sector has a distinct and central responsibility."

Cyber ​​defense needed everywhere

The deputy national security adviser urged the private sector to adopt the best practices that President Joe Biden set out in an executive order signed last month aimed at removing the country's vulnerability to cyberattacks.

These practices included the use of multi-factor authentication and encryption. Neuberger also urged companies to regularly back up data and keep backups offline so that they are not vulnerable to ransomware variants; Regularly update and patch systems; Develop and test an incident response plan so organizations can continue to operate in the event of an attack; and for segmenting networks in order to separate company functions from manufacturing and production processes.

“These are all excellent recommendations. However, an element of proactive defense is missing here, ”said Saryu Nayyar, CEO of the unified security and risk analysis company Gurucul.

"Organizations need to implement cyber defenses that reduce the attack surface and detect ransomware attacks in real time, rather than just prepare to quickly resume operations after a ransomware attack," Nayyar told ClearanceJobs via email. "Modern security operations should incorporate data science technologies combined with traditional cyber defense measures to thwart ransomware attacks."

She suggested that privileged access management, continuous authentication, MFA, risky account discovery and cleansing, intrusion detection, behavior analysis, data loss prevention, firewalls, endpoint detection and response (EDR) or even better, extended detection and response (XDR) are modern security measures required to prevent attackers from successfully breaking into corporate networks and disrupting operations.

"The technology is available," added Nayyar. "It's just a matter of setting it up and working carefully to identify and derail cyber criminals and malicious insiders before they derail you."

Stay one step ahead of the cybersecurity curve

It's not just the White House who tries to stay ahead of the curve in the next cyber attack. This month, US Army Gen. Paul M. Nakasone, commander of US Cyber ​​Command and director of the National Security Agency, warned that cyberspace was a major threat to the nation.

"Our opponents operate with a scope, scope and sophistication that we have never seen before," said Nakasone during a virtual speech to the Armed Forces Communications and Electronics Association.

"Their tactics go way beyond spear phishing and exploiting weak passwords," added Nakasone. "Today, our adversaries are targeting and infiltrating our systems by exploiting supply chain and zero-day vulnerabilities, and our adversaries are demonstrating a new approach to risk that has transformed the traditional threat landscape."

The chief of cyber command also suggested that US adversaries could cause damage through operations in cyberspace while operating below the level of an armed conflict. These operators - including state actors - are already targeting the US economies, critical infrastructures and electoral processes. Nakasone warned that these adversaries carried out persistent malicious cyber campaigns aimed at undermining US military advantages. This also includes the use of social media to carry out and influence operations.

The main threats are Russia and China; But other states like Iran and North Korea should not be disregarded, all of which continue to have an unpredictable and destabilizing presence in their respective regions. Still, China could pose the greatest threat to the United States today.

"China is becoming more assertive economically, diplomatically, militarily and technologically," warned Nakasone. "It tries to undermine a stable and open international order in order to establish its credibility and dominance in the global system."

More to do than White House and DODOD efforts

Even as the White House and DoD announce efforts are being made to stop such attacks, experts told ClearanceJobs that much more remains to be done. Our efforts so far have probably been neglected.

"I don't think we're doing enough," said Fred H. Cate, senior fellow at the Center for Applied Cybersecurity Research. “I think we're better together, but we have so much vulnerable infrastructure to defend and the attackers are getting better organized and more sophisticated in their attacks, so our net position may actually be weakened. Or the threat is shifting away from ordinary fraud and towards more damaging attacks on the infrastructure. "

Cate indicated that the government's response was far weaker than the industry's response so far.

"Just think of the fact that (a) the TSA has primary authority over pipeline safety and (b) hasn't done anything about it until last week," Cate told ClearanceJobs. “We've seen dozens of attentive attacks, with the recent ransomware attacks being just the most recent examples, but it's sobering to remember that there are dozens of other exposed, non-headline attacks, and hundreds or thousands more that never do. "disclosed."

One problem has been that for every failure to stop these attacks that make the headlines, there are attempts by the cybercriminals that have not been successful.

"Many attempts are thwarted, but there is probably no reasonable way to measure them," noted Jim Purtilo, associate professor of computer science at the University of Maryland. “Your store out on Main Street could be closed for the day with a door lock blocking pedestrians who happened to rattle on the handle. How many of these were foiled exploits? It's the same on the net. Every day, agents of all kinds casually rattle on the digital front door of systems. I can pull up a system log and watch it scroll by while the activity is recorded in real time. It is those who don't just rattle the doorknob that draws our attention. "

Purtilo told ClearanceJobs that the military has come a long way in cybersecurity and those responsible for operations in general have an awareness of the problems they face.

“I think there are parts of the industry that still have a way to go. It's mainly a mindset concern, ”he added. “We don't magically harden systems and then brand them as 'safe'. What could that even mean? Instead, we create a threat model and work back from there to find appropriate measures to address these attack vectors. "

A good defense is not good enough

When it comes to cybersecurity, defense needs to be one step ahead of an attack, but the problem is that it rarely does. Antivirus software responds to threats, while many efforts are still focused on both "recovery" and prevention.

“Defense is always more difficult than attack, to be fair, but we have taken a largely direct approach as we move more and more essential activities to digital tools - such as industrial control systems, aircraft autopilots, and driver assist technologies , Insulin pumps, implanted cardiac pacemakers, automated alarms and door locks, wireless payment systems, military drones - we know that and we admit that we don't have enough coverage, but we're making progress, ”said Cate.

“In a way, we say we're safe about a list of potential threats,” Purtilo said. “Managers who then build systems think, almost in retrospect, that they could use a bit of security, have a way of thinking that opens them up to disaster. Glad it occurred to you at some point, but your system is probably suffering from some fundamental flaws at this point. We don't first make a product and only later set about building up the quality; Quality is something that we need to prioritize from the start. The same goes for security. Like quality, safety requires that we pay attention from the start. "

That is not to say that good defense is impossible - and in fact, it should be as important as emphasis, like stopping a terrorist attack.

"One way to put this in perspective is our response to COVID: we have deployed warring forces, allocated public and private sector resources, issued extensive ordinances, and invested hundreds of billions of dollars," added Cate. “Compare that to our approach to cybersecurity, which pales in comparison, even though the threat is potentially as big or bigger.

"I am sorry that I am neither optimistic nor optimistic," Cate admitted. “So far, we have only been lucky that the worst attacks so far have not been from parties like terrorists who really want to destroy or destabilize us instead of making money or demanding bragging rights. Dependent on the enemy's good intentions seems like a bad strategy. "

https://dailytechnonewsllc.com/critical-infrastructure-in-the-cyber-crosshairs-can-u-s-stop-more-attacks/

Comments

Popular posts from this blog

Open call: ACC Residency 2023 - Announcements

Show Me a Good Loser, and I'll Show You a Good Trader

Trading Penny Stocks This Week? 3 For Your April 2021 Watch List