US Homeland Security still infected with Trojans?

The man in charge of IT security for the US Homeland Security department may lose his job after the revelations that his department's IT systems have misconfigured firewalls, suspicious botnet activity, trojans and virus infections.

In response to reports of persistent cybersecurity flaws at the Department of Homeland Security, a top congressional Democrat on Wednesday questioned whether the agency's chief information officer deserves to keep his job.

The department charged with safeguarding the security of the nation's computer systems has not been setting a good example and CIO Scott Charbo hasn't shown he's serious about fixing its vulnerabilities, said Bennie Thompson, chairman of the House of Representatives Homeland Security Committee.

"How can we ask the private sector to better train employees and implement more consistent access controls when DHS allows employees to send classified e-mails over unclassified networks and contractors to attach unapproved laptops to the network?" Thompson asked at a hearing held by a subcommittee that deals with cybersecurity issues.

He was referring to the Homeland Security department's revelation, as part of an ongoing subcommittee probe into its information security practices, that it experienced 844 security-related "incidents" on its computer systems in 2005 and 2006. Those episodes included unauthorised users hooking up personal computers to government networks, unauthorised software installations, classified e-mails traveling over unclassified networks, suspicious botnet activity, trojans and virus infections, classified data spillages and misconfigured firewalls.

Charbo, for his part, downplayed the lengthy list, saying that they didn't indicate actual penetrations of the system and varied widely in the level of severity. "Those are events that we report on as a data-gathering tool," the IT chief told the politicians, adding that he was confident all breaches considered significant had been addressed properly.

The congressional panel that convened Wednesday's hearing has been probing the extent to which various federal agencies are equipped to handle cyberthreats. At a hearing in April, committee members accused officials at the Commerce and State Departments of being ill-prepared to handle such threats in light of reports of intrusions from Chinese hackers, and they warned that Homeland Security would be undergoing scrutiny next.

Criticism of that department's cybersecurity efforts from Congress and federal auditors is hardly new. Some would argue the department has shown minor signs of improvement this year since it pulled up its federal information security "grade" from an "F" to a "D".

Even so, Government Accountability Office auditors at Wednesday's hearing said various components of Homeland Security still aren't doing enough to limit access to their systems, authenticate and identify users, encrypt sensitive data and keep logs of user activity.

The GAO is preparing to release a report based on a yearlong investigation that it says documents "pervasive" security flaws in Homeland Security's US-VISIT program, which is designed to verify the identity of foreigners through fingerprint scans and is currently being used at several US ports of entry.

Keith Rhodes, one of the report's authors, said the GAO found that US-VISIT is riddled with problems "across the board", which, left uncorrected, could put sensitive personal information at risk. The flaws are mostly due to "bad configurations" that could be fixed both easily and cheaply, he said. But because of the deficiencies, there's no way of knowing whether the database associated with the computer systems has already been hacked, he said.

"I did not see controls in place that would prevent (hacking), I did not see defensive perimeters, and I did not see detections systems in place that would let you know whether it had or had not" been hacked, Rhodes told the committee.

Charbo said he and department officials were still reviewing the draft version of that report but were prepared to address the weaknesses by year's end.

On a broader level, Charbo said he realises the agency has improvements to make but urged the politicians not to overlook what he called "significant progress" during the past few years. For instance, it has "remediated" 7,000 weaknesses identified by auditors and has certified that 95 percent of its systems have appropriate controls in place -- compared with only 26 percent in October 2005.

Others questioned whether the department has been dedicating enough of its overall tech budget to security. According to Homeland Security, it spent US$12.5 million in 2004, US$17.5 million in 2005, and US$15 million in 2006 and 2007. Charbo justified those expenditures by saying they reflected "our strategic security plan".

The lone Republican present at the hearing, subcommittee co-chairman Michael McCaul, said he and others were considering introducing legislation that would force Homeland Security to come up with a "national strategic threat assessment" regarding US cybersecurity.

"This has never been done, it's long overdue, and the nation needs this to protect it," he said, adding that he feared a devastating cyberattack could be worse than the "effects of a weapon of mass destruction."

Advertisement

Talkback 3 comments

    what a mess... Jordan Michaud -- 22/06/07

    You would think that the governement would have impenetrable network security. Apparently not. Good article in informing the insecurity of important classified docs.

    www.ecorablog.com

    DHS Infected with Hacks ??? Anonymous -- 22/06/07

    No wonder, they are running WinBloze !!! Wonder why they didn't choose SecureLinux, developed by the National Security Agency, the National Spook Shop !!! I guess somebody pocketed a nice bribe to "Select" M$ CrapWare !!! Now, they reap as they have sown !!!

    heh, no wonder... Anonymous -- 23/06/07

    No wonder that you guys have serious issues with security, using Windowss 2000/2003/XP at work, spending 15 MILLION DOLLARS FOR SECURITY THAT DOESN'T EVEN EXIST!!! Virus writes are nowadays exploiting everything they get their hands on, not reporting red alert exploits so they can do it beforehand, owning every servers they get. So, you guys better straighten up and start patching, start doing some good for the community, maybe this is what americans have to pay for turning their backs on 3rd world countries and attacking them without a notice. This is the thruth that americans have to handle and start thinking again before another election. Anyways, have phun posting crappy news, start patching vulnerable systems maybe that's how you guys won't get owned by romanian kiddies using ./exploits and bruteforcing your username root, passworded root systems, getting access to critical information and getting in jail for your **** stupidity, just wake up already and start doing something...

Add your opinion

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured