Slashdot Log In
Operation 'Cyber Storm' Starts Tomorrow
Posted by
CmdrTaco
on Sun Feb 05, 2006 10:00 AM
from the are-you-ready-for-fun-and-excitement dept.
from the are-you-ready-for-fun-and-excitement dept.
cyberbian writes "Federal Computing Week reports that the Department of Homeland Security have moved up their rescheduled cyber security exercise, designed to test enterprise and private sector alike. The tests are expected to run from February 6-10, and are intended to gauge the state of readiness for a cyber attack on critical infrastructure. FCW also reports that the scope of the fake attacks will be global, and they are coordinating with partners in Australia, Canada and the UK."
Related Stories
[+]
Cyber Storm II Set To Begin 36 comments
mr sanjeev notes that Computerworld is running a story about Cyber Storm II, set to run from March 11th until the 14th.
The exercise will test the security of the US, Australia, the UK, New Zealand, and Canada. The organizers' goals are to test preparedness and responsiveness in relation to real-time threats. The previous Cyber Storm test identified "eight specific areas in need of improvement." We recently discussed the details of the tests themselves. From Computerworld:
"Security experts said the first Cyber Storm event last year improved participants' understanding of who to call in the event of an attack, but did not identify specific vulnerabilities in the nation's computer systems. 'What they're trying to do is highlight the inefficiencies in the process,' according to Marcus Sachs, deputy director with research group SRI International's Computer Science Laboratory. 'They're not really looking for technical solutions.'"
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
I wonder (Score:4, Funny)
Re:I wonder (Score:5, Insightful)
Parent
Re:I wonder (Score:3, Funny)
It was a secret military project to create a defense system capable of protecting the nation.
But... It became sentient
Re:I wonder (Score:3, Funny)
From TFA (Score:3, Funny)
"IT-ISAC has eight members participating in the exercise, the center's Web site states. The participants are Cisco Systems, Citadel Security Software, CA (formerly Computer Associates), Computer Sciences Corp., Intel, Microsoft, Symantec and VeriSign."
In other words, little, if any.
Re:From TFA (Score:4, Informative)
Parent
Damage (Score:5, Interesting)
They caused more damage to us with childhood tactics ( like locking out system accounts ) than doing 'real' tests. We were screwed for a week trying to undo damage, and trying to figure out how it was happening again and again.
Posting anonymously for obvious reasons.
Parent
Re:Damage (Score:4, Informative)
Parent
Re:I wonder (Score:4, Interesting)
Parent
Re:I wonder (Score:5, Funny)
Parent
Insanity Re:Call For A Red (Score:3, Insightful)
"The Mohammed cartoons are a transparent provocation by NATO intelligence through a Danish right wing newspaper of limited circulation."
I'm sure that makes much more sense to the conspiracists than the issue as put forward by both the original publisher (ma
good job (Score:5, Interesting)
I hope no real attacks take place during this time though...
Re:good job (Score:2, Insightful)
I also wonder how much this issue has influenced the court's handling of the "Crackberry" patent infringement case (not trying to start flame war-that time of disrupted communications when many people/agencies were using their Blackberries because nothing else was working-that really scared a l
Re:good job (Score:5, Funny)
Clock out of work when the attack happens and go to the corner pub?
Parent
A good idea.... (Score:4, Funny)
Re: A good idea.... (Score:3, Funny)
Re:A good idea.... (Score:2)
Re:A good idea.... (Score:5, Funny)
Parent
How to parcipate... (Score:5, Funny)
Then go home for a couple days!
WooHoo!
Re:How to parcipate... (Score:2)
So.... (Score:5, Interesting)
Thank Ford! (Score:5, Funny)
Post-Superbowl? (Score:3, Interesting)
Re:Post-Superbowl? (Score:3, Funny)
Re:Post-Superbowl? (Score:5, Funny)
Parent
More worrisome threats (Score:5, Insightful)
Re:More worrisome threats (Score:5, Interesting)
All admins do not necessarily agree with this. Most of messes I have to clean up are from malware, fraud, "traditional" crime (and attempts at such) that have taken on a 'net communications component, and the usual tsunami of noise and bot blather that lands on every public-facing port I have open.
Tiered internet? That's a misnomer, I think. Big internet users pay for the bandwidth they (or their visitors) use. More traffic means higher costs. I don't care if some Comcast user has already paid for "his" bandwidth... serving up a streaming video to him isn't only using his bandwidth. I don't know where people get that idea. But regardless, if SBC or Verizon or any other carrier wants to screw with per-site or per-visitor metering or biasing, they're welcome to. Other ISPs will just set a price that's easier to predict and work with, and win the business away from the people trying to make it more complicated. But how much time do I have to give "upper management" or "government meddling" vs. attempted attacks, fraud killing, malware, etc? It's not even close. The bad guys are much more of an issue.
Parent
Re:More worrisome threats (Score:3, Funny)
I think you are underestimating upper management.
This sounds extremely logical (Score:4, Interesting)
Homeland security is going to turn around and tell everyone that we're NOT ready for a "terrorist cyber attack"? No, it makes much more political sense to say "see? Our networks can survive millions of nerf-ball hits; more funding please."
Re:This sounds extremely logical (Score:3, Interesting)
"Cool! Well, right then. Turns you aren't actually needed after all so we're shutting your dept. down."
You don't understand how the game is played. The DHS depends on terrorism for their funding, but; they are the terrorists.
KFG
Re:This sounds extremely logical (Score:2)
Wait a minute (Score:2, Insightful)
Re:Wait a minute (Score:5, Insightful)
Parent
DDO Stress test (Score:2, Interesting)
Time to Go Phishing (Score:5, Funny)
I can see it now...
FROM: cyberstorm@dohs.gov
TO: unlucky.recipient@yourcompany.com
SUBJECT: Participation in Cyber Storm exercise
Your company has been identified by the Department of Homeland Security as potentially vulnerable to cyber attack. During the week of February 6th - February 10th, the DoHS will be testing cyber infrastructure as part of our Cyber Storm security exercise. In order to participate, you will need to supply us with [insert favorite hacking data here]...
That was a game... (Score:2)
Cyber Storm? (Score:4, Funny)
And so it begins. (Score:2, Funny)
nice war game (Score:2)
Greenspan (Score:2)
What, you don't believe me? See this historical proof [rdwarf.com] and prove it to yourself. Alan Greenspan is a l33t h4xor, that fact is undeniable!
Wierd. (Score:3, Interesting)
I didn't know that computers only speak English.
Hmmm... learn sumthin new evry day.
recovery during pen testing (Score:3, Interesting)
Goverments can't hack it (Score:5, Insightful)
I doubt the Department of Homeland Security has anything like a globally distributed botnet, or permission to run DDoS like a real attacker might. The virus attack [com.com] on the Russian stock market is not something goverments can replicate.
The only winners will be the companies who sell the extra bandwidth!
Digg and Slashdot (Score:4, Funny)
What about the information gathered??? (Score:5, Insightful)
Is this just another end run around warrantless search and seizures of data?
What kind of oversite is there on this process and how can we be sure the information is not used, stored, or otherwise desiminated among the various US spook agencies and their foreign lackeys.
And how much do you want to bet Google will be a very well excercised target since they have been fighting the governments abuse of power already.
Your tinfoil hat is on a bit too tight (Score:3, Insightful)
Suppose their attacks allow them to get into various machines and networks, what will they do with the data that is accesible in those machines?
Well, according to TFA, "IT-ISAC has eight members participating in the exercise, the center's Web site states. The participants are Cisco Systems, Citadel Security Software, CA (formerly Computer Associates), Computer Sciences Corp., Intel, Microsoft, Symantec and VeriSign." So those companies seem to have signed up and are ready to have their networks accessed a
Shouldn't they wait for the next Leap Day? (Score:5, Funny)
Original Message - 1996
DO NOT CONNECT TO THE INTERNET FROM 12:01 AM GMT ON FEB. 29 TO 12:01 AM GMT, MARCH 1 !!
*** *** Attention ***
It's that time again!
As many of you know, each leap year the Internet must be shut down for 24 hours in order to allow us to clean it. The cleaning process, which
eliminates dead email and inactive ftp, www and gopher sites, allows for a better-working and faster Internet.
This year, the cleaning process will take place from 12:01 a.m. GMT on
Feb. 29 until 12:01 a.m. GMT on March 1. During that 24-hour period, five powerful Internet-crawling robots situated around the world will search the Internet and delete any data that they find.
In order to protect your valuable data from deletion we ask that you do the following:
1. Disconnect all terminals and local area networks from their Internet
connections.
2. Shut down all Internet servers, or disconnect them from the Internet.
3. Disconnect all disks and hardrives from any connections to the Internet.
4. Refrain from connecting any computer to the Internet in any way.
We understand the inconvenience that this may cause some Internet
users, and we apologize. However, we are certain that any
inconveniences will be more than made up for by the increased speed and efficiency of the Internet, once it has been cleared of electronic flotsam and jetsam. We thank you for your cooperation.
Kim Dereksen
Interconnected Network Maintenance staff
Main branch, Massachusetts Institute of Technology
Sysops and others: Since the last Internet cleaning, the number of
Internet users has grown dramatically. Please assist us in alerting
the public of the upcoming Internet cleaning by posting this message
where your users will be able to read it. Please pass this message on to
other sysops and Internet users as well. Thank you.
Hurricane CyberPam (Score:3, Insightful)
The decision-makers will decide (as they have so far about everything involving actual defensive measures involving the homeland that they would prefer to spend the money in some other way. They'll appoint yet another cyber defense "czar" as evidence of action, he will start with the clear understanding that the one thing he can't do is get the funding to implement the measures recommended in the report.
And when the actual attack happens and is devastating, they'll say nobody could have anticipated it.
See also Hurricane Pam [fema.gov]
"Cyber Storm" (Score:3, Insightful)
Disturbingly Odd Timing (Score:4, Interesting)
The type of test I participated in wasn't invalidated by this lack of surprise because it was deliberately designed to expose procedural flaws and systematic gaps that fell between different areas of responsibility. The lack of surprise was a nuscience in the design of the test, but it was planned for and accounted from the very beginning. Having an announced testing window was a necessary security feature and not a flaw in the test.
These tests either were performed within the announced window of time or they were cancelled outright. Delay was out of the question. Delay was insecure. Cancelled tests were a nuscience for the test teams because it meant almost a month delay before they'd be allowed to perform the test, but the insecurity introduced by saying "Oh wait, the tests are back on schedule" or "Oh we'll just delay the test window a few days" was unnaceptable to security.
I've heard a time (though I didn't participate) in a test where a piece of equipment failed the day before the two day test window. Without this piece of equipment data measurements would be fuzzed by an order of magnitude on one part of the test. A replacement was ordered but on the day the tests were to begin it still required a day of prep time. To you and me our first inclination might be to simply delay the test a day. That was not acceptable to the security team. The test went on with the bad piece of equipment and the test results were compromised but in only that part of the test. Another test window was scheduled six weeks in the future and the test team's budget was increased to have redundant pieces of certain test equipment on hand and ready as part of the design of new testing procedures.
What seems almost absurd was the idea of moving forward the timeframe of an announced security test. There were times when test teams were very ready ahead of time, but they used the time to double and triple check their preparation, take documentation for next test, meet and discuss the game plan, and use the extra time productively while waiting for the arrival of the upcoming announced testing window. Why not just go ahead with the tests? Because once again, moving the announced test window was a security risk. And performing the test outside a test window was considered a break-in by security, and unnecessary for properly designed tests by the test teams.
I know banking security differs from computer security, but it still seems rather insecure and dangerous to move an announced test window period at all. What's worse is that it seems unnecessary, unusual, and odd to move the test period forward. If the test requires surprise, then it's either a poorly designed test or it was compromised by having an announced test window to begin with. If we're dealing with computer security on an international scope, then it would seem incredibly helpful to take the extra test time and double check the game plan. Tests inside a single banking company with far fewer issues of timing, language, and politics welcomed an extra week to plan and prepare before most tests of even moderate complexity. It seems arrogant, ignorant, or careless to say "Oh, we don't need this extra time before the tests. We'll deliberately tamper with our security and throw away this extra time we could use to prepare and coordinate this very complex international test."
So what's really going on here?