Could hackers devastate the U.S. economy?
Browse the article Could hackers devastate the U.S. economy?
Could hackers devastate the U.S. economy?
Image TM and © Twentieth Century Fox Film Corporation. All rights reserved. “Live Free or Die Hard” pits Detective John McClane (Bruce Willis) against a band of terrorists attempting to bring down the United States’ technological infrastructure. |
Cyber security is becoming an important issue. Many media organizations and government officials rank it just as grave a threat as terrorist attacks, nuclear proliferation and global warming. With so many commercial, government and private systems connected to the Internet, the concern seems warranted. To add to the concern, consider that today's hackers are more organized and powerful than ever. Many work in groups, and networks of black-market sites exist where hackers exchange stolen information and illicit programs. Credit-card data is sold in bulk by "carders" and phishing scams are a growing concern. Malware -- viruses, Trojan horse programs and worms -- generates more money than the entire computer security industry, according to some experts. Hackers are also distributed all over the world, many in countries like Romania that have lots of Internet connectivity and loose enforcement of laws.
Rich Mogull is a research vice president at Gartner, the best known analyst group in the IT and security industries. Check out this video on cyber security and privacy. |
To respond to these threats, the European Union, G8 and many other organizations have set up cybercrime task forces. In the United States, some local law enforcement organizations have electronic crime units and the FBI shares information with these units through its InfraGard program.
Great Britain thinks it's facing a threat, but should the United States be concerned? Recent events in Estonia may actually shed some light on the situation.
Cyber Attacks in Estonia
Image courtesy NATO NATO assisted Estonia in combating the cyber attacks and has voted to work with member governments to improve cyber security. |
Weeks of cyber attacks followed, targeting government and private Web sites. Some attacks took the form of distributed denial of service (DDoS) attacks. Hackers used hundreds or thousands of "zombie" computers and pelted Estonian Web sites with thousands of requests a second, boosting traffic far beyond normal levels.
The Estonian government compared the cyber attacks to a terrorist attack. At first, many people thought the attacks were being committed by the Russian government, causing some pundits to label the events the first "cyber war." It's now believed that the Russian government didn't directly participate in the attacks, although they did contribute a lot of angry rhetoric. Instead, incensed Russians were likely behind most of the attacks.
The Estonian cyber attacks weren't larger than other DDoS attacks, but they were able to shut down some sites for a time. The government didn't lose any infrastructure, but the events proved extremely time consuming, expensive to combat and indicative of weaknesses in Estonia's cyber security.
The Estonia cyber attacks were not the first of their kind. Previously other political grievances have spilled over into hacker feuds. Indian and Pakistani hackers have in the past launched barrages of viruses and DDoS attacks as part of the long-standing tensions between those countries. Israeli and Palestinian hackers have launched tit-for-tat attacks, defacing each others' Web sites. But the weeks of cyber attacks suffered by Estonia appear unique because they, for a time, consumed the affairs of an entire government and drew the attention of the world.
Estonia, a country considered to be especially "wired," weathered its cyber attacks with some economic and governmental disruption, but without significant or long-term damage. How would the United States fare in such a situation? Read on to find out.
U.S. Cyber Security
On April 19, 2007, the Congressional Subcommittee on Emerging Threats, Cybersecurity, Science and Technology, part of the Homeland Security Subcommittee, learned that systems at the Departments of Commerce and State were hacked in 2006. The Chief Information Office at the Department of Homeland Security, Scott Charbo, may lose his job as a result of "844 security-related incidents" that occurred at the DHS in 2005 and 2006 [Source: News.com]. Those incidents include classified e-mails sent over unsecured networks, personal computers used on government networks, installation of unapproved software, leaks of classified data and problems with viruses and unsecured firewalls. The DHS also received a "D" grade on its annual computer security report card, though that was up from the failing grades it received from 2003 through 2006. (The entire federal government scored a C-minus, up from a D-plus the year before.)Image TM and © Twentieth Century Fox Film Corporation. All rights reserved. Detective McClane is assisted by young hacker Matt Farrell (Justin Long) in combating the terrorist-hacker group. |
Because of these and other failures, the government is responding. The DHS now has an Assistant Secretary for Cyber Security and Telecommunications, Greg Garcia. In early February 2006, the U.S. government, along with 115 partners in five countries, conducted a set of cyber war games known as Cyber Storm. This large-scale simulation included major corporations, government agencies and security organizations. Cyber Storm served as a test of what would happen in the event of cyber attacks against important government, business and private Web sites. The faux attacks caused blackouts in 10 states, infected commercial software with viruses and caused important online banking networks to fail. The exercise dealt with defending against and responding to the attacks as well as managing misinformation that might be spread by the attackers themselves. Cyber Storm II is scheduled to occur sometime in 2008. Meanwhile, at Barksdale Air Force Base in Louisiana, 25,000 members of the military work on electronic warfare, network security and defending the country's Internet infrastructure.
In the event the U.S. is ever faced with a massive cyber attack, intelligence agencies, the Department of Defense, the military and the unit at Barksdale Air Force Base would likely be among the so-called "first responders." The US-CERT, the United States Computer Emergency Readiness team, would also play a major role. US-CERT was established in 2003 and is charged with protecting Internet infrastructure and defending against cyber attacks.
Next, we'll look at the possibility of a cyber attack in the United States.
Cyber Attacks in the United States
Clearly, the United States faces a lot of security holes in its Internet infrastructure, despite the government's efforts to shore up security. But do these security lapses translate into "Die Hard"-style mayhem and destruction? Not quite. No one died in the cyber attacks on Estonia, nor is there a record of anyone ever having been killed because of a cyber attack or a computer being hacked. Some terrorist groups have expressed a desire to launch Internet-based attacks, but the main concerns actually revolve around criminal gangs that extort companies for money and angry hackers trying to make a statement (as with Estonia). Image used under the GNU Free Documentation License Contrary to what some action movies or espionage novels might depict, it’s impossible for hackers to wreak havoc on a major installation like the Hoover Dam. |