Mobile UPI  |   About UPI  |   UPI en Español  |   UPI Arabic  |   UPIU  |   My Account
Search:
Go

Internet security faces chronic problems

|
|
 
  
Published: Jan. 5, 2009 at 2:59 PM
By LOREN B. THOMPSON, UPI Outside View Commentator

ARLINGTON, Va., Jan. 5 (UPI) -- U.S. network software and procedures must be continually updated to eliminate weaknesses, and tested to assure gaps have been successfully closed.

Also, there must be a mechanism among network administrators across the United States for sharing information about threats that provides timely and useful warnings of danger.

Finally, defensive measures carried out by the U.S. government and its relevant agencies must be sensitive to the missions of users, so that they do not impair network functionality in the process of providing protections.

The respected SANS Institute uses a six-step framework for explaining how cyber incidents should be addressed that begins with being prepared, and then proceeds through identification of danger, containment of the threat, eradication of the threat, system recovery and follow-up.

Each of these steps may entail dozens of discrete actions aimed at detecting, characterizing, isolating and suppressing the danger, and then restoring the network to its beginning state.

Experts typically stress the importance of being prepared before an attack occurs, and conducting postmortems to derive useful lessons about how dangers can be minimized in the future. Military experts also emphasize the importance of developing offensive cyber capabilities as a way of deterring or countering attacks.

While the generic measures necessary to cope with cyber aggression are easy enough to identify, applying them to specific threats and mission areas can be devilishly difficult. Efforts to do so have revealed a number of chronic problems that policymakers eventually must address.

First, vital national networks are so balkanized among military, civil and commercial operators that it is difficult to enforce any particular standard with regard to cyber defense.

Second, the inability to trace attacks made over the Internet to their point of origin severely hampers efforts to deter or punish predators.

Third, network administrators seldom have the sort of enterprise-wide view of their information assets needed to fashion a durable and complete security regime.

Fourth, government by its nature is not well equipped to keep up with such a fluid and multifaceted challenge.

The U.S. federal government acquired most of its information networks on a piecemeal basis, without much thought as to how the parts one day might fit together or how enemies might try to exploit them.

The U.S. government's recent efforts to organize for cyber defense have been hampered by the fragmented character of federal information systems. This problem is compounded by the fact that many networks vital to the economy are in the private sector, and the legal authorities for implementing security measures there are incomplete at best.

--

(In Part 7: The role of the National Security Agency in securing U.S. national cyber and Internet security)

--

(Loren B. Thompson is chief executive officer of the Lexington Institute, an Arlington, Va.-based think tank that supports democracy and the free market.)

--

(United Press International's "Outside View" commentaries are written by outside contributors who specialize in a variety of important issues. The views expressed do not necessarily reflect those of United Press International. In the interests of creating an open forum, original submissions are invited.)

Recommended Stories
© 2009 United Press International, Inc. All Rights Reserved. Any reproduction, republication, redistribution and/or modification of any UPI content is expressly prohibited without UPI's prior written consent.

Order reprints
  
Join the conversation
Most Popular Collections
The 84th Academy Awards winners The breakout star of the Oscars The Daytona 500
Radiohead performs in Miami Ice and Snow Festival in China 2012 Governors Dinner
Additional Security Industry Stories
1 of 29
Youngsters compete in Scripps National Spelling Bee
View Caption
Contestants (L-R) Cooper Barth of West Long Branch, New Jersey, Eboseremhen Eigbe of Galloway, New Jersey, Jacob Bayly Hunter of Sante Fe, New Mexico and Massound Sharif of Albany, New York, all await their turns to compete during the 3rd round of the Scripps National Spelling Bee, May 30, 2012, in National Harbor, Maryland. UPI/Mike Theiler
fark
"While searching the man's purse, officers found a holster containing four throwing stars, which...
Confirmed: Drake and billionaire oil man T. Boone Pickens are this generation's Abbott and Costello...
Cannibal attack victim's family thought he had killed himself 30 years ago
House debates bans on sex-selective abortions. So... they want to make it legal for men to get abortions?...
Aging Wisconsin billionaire that clearly is trying to keep herself alive through plastic surgery...
Mosque build halted by TN judge over public notice "in relatively small type near the bottom of...