1 US Homeland Security still infected with Trojans? - Security - News - ZDNet Australia

US Homeland Security still infected with Trojans?

The man in charge of IT security for the US Homeland Security department may lose his job after the revelations that his department's IT systems have misconfigured firewalls, suspicious botnet activity, trojans and virus infections.

In response to reports of persistent cybersecurity flaws at the Department of Homeland Security, a top congressional Democrat on Wednesday questioned whether the agency's chief information officer deserves to keep his job.

The department charged with safeguarding the security of the nation's computer systems has not been setting a good example and CIO Scott Charbo hasn't shown he's serious about fixing its vulnerabilities, said Bennie Thompson, chairman of the House of Representatives Homeland Security Committee.

"How can we ask the private sector to better train employees and implement more consistent access controls when DHS allows employees to send classified e-mails over unclassified networks and contractors to attach unapproved laptops to the network?" Thompson asked at a hearing held by a subcommittee that deals with cybersecurity issues.

He was referring to the Homeland Security department's revelation, as part of an ongoing subcommittee probe into its information security practices, that it experienced 844 security-related "incidents" on its computer systems in 2005 and 2006. Those episodes included unauthorised users hooking up personal computers to government networks, unauthorised software installations, classified e-mails traveling over unclassified networks, suspicious botnet activity, trojans and virus infections, classified data spillages and misconfigured firewalls.

Charbo, for his part, downplayed the lengthy list, saying that they didn't indicate actual penetrations of the system and varied widely in the level of severity. "Those are events that we report on as a data-gathering tool," the IT chief told the politicians, adding that he was confident all breaches considered significant had been addressed properly.

The congressional panel that convened Wednesday's hearing has been probing the extent to which various federal agencies are equipped to handle cyberthreats. At a hearing in April, committee members accused officials at the Commerce and State Departments of being ill-prepared to handle such threats in light of reports of intrusions from Chinese hackers, and they warned that Homeland Security would be undergoing scrutiny next.

Criticism of that department's cybersecurity efforts from Congress and federal auditors is hardly new. Some would argue the department has shown minor signs of improvement this year since it pulled up its federal information security "grade" from an "F" to a "D".

Even so, Government Accountability Office auditors at Wednesday's hearing said various components of Homeland Security still aren't doing enough to limit access to their systems, authenticate and identify users, encrypt sensitive data and keep logs of user activity.

The GAO is preparing to release a report based on a yearlong investigation that it says documents "pervasive" security flaws in Homeland Security's US-VISIT program, which is designed to verify the identity of foreigners through fingerprint scans and is currently being used at several US ports of entry.

Keith Rhodes, one of the report's authors, said the GAO found that US-VISIT is riddled with problems "across the board", which, left uncorrected, could put sensitive personal information at risk. The flaws are mostly due to "bad configurations" that could be fixed both easily and cheaply, he said. But because of the deficiencies, there's no way of knowing whether the database associated with the computer systems has already been hacked, he said.

"I did not see controls in place that would prevent (hacking), I did not see defensive perimeters, and I did not see detections systems in place that would let you know whether it had or had not" been hacked, Rhodes told the committee.

Charbo said he and department officials were still reviewing the draft version of that report but were prepared to address the weaknesses by year's end.

On a broader level, Charbo said he realises the agency has improvements to make but urged the politicians not to overlook what he called "significant progress" during the past few years. For instance, it has "remediated" 7,000 weaknesses identified by auditors and has certified that 95 percent of its systems have appropriate controls in place -- compared with only 26 percent in October 2005.

Others questioned whether the department has been dedicating enough of its overall tech budget to security. According to Homeland Security, it spent US$12.5 million in 2004, US$17.5 million in 2005, and US$15 million in 2006 and 2007. Charbo justified those expenditures by saying they reflected "our strategic security plan".

The lone Republican present at the hearing, subcommittee co-chairman Michael McCaul, said he and others were considering introducing legislation that would force Homeland Security to come up with a "national strategic threat assessment" regarding US cybersecurity.

"This has never been done, it's long overdue, and the nation needs this to protect it," he said, adding that he feared a devastating cyberattack could be worse than the "effects of a weapon of mass destruction."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Quick Poll

What is the biggest data management challenge in your organisation?

ZDNet Australia Live

Ansell comes back from IT **** up - Ansell has said it is rectifying problems with its new business processing syste... http://t.co/7QH6c8Oq

What is missing from the code is a ban on the telcos creating their own funny-money by offering (say) "$500 worth of calls for $50" (and...

10 minutes ago by MaudeLynne on Telco customer code goes to the regulator

@joshgnosis who is responsible for this? that is one hell of a #newspun !!! http://t.co/9dd7tvx3

Open source needed to save democracy - Software - News - ZDNet Australia http://t.co/nH2C1VPb

Ansell comes back from IT **** up: Ansell has said it is rectifying problems with its new business processing sy... http://t.co/hVtbecMH

Spamvertised 'Tax information needed urgently' emails lead to malware http://t.co/ma7weWG1

Does Facebook accurately count users? http://t.co/KLSlJsgO

by http://t.co/vmlQ0Ecb: Ansell comes back from IT **** up: Ansell has said it is rectifying problems with its ne... http://t.co/UJdAxaMX

Tech? Done in days. Business model? A little longer :-) Finally! LoadRunner, more #agile than ever in #AWS and #vcloud http://t.co/O8ZaBty3

#trollDay “@lukehopewell: Our headline of the year: http://t.co/ldugUO77

RT @mwyres: #trollDay “@lukehopewell: Our headline of the year: http://t.co/ldugUO77

You may not realise but massive numbers of metro suburban citizens cannot currently get broadband and many more cannot get anywhere near ...

38 minutes ago by harryinthesoup on NBN Co inks $620m satellite deal

RT @stilgherrian: SOPA/PIPA fail, studios try anti-piracy 'charm offensive'. http://t.co/xuqzY3Rm

"If you are trying to trace with the ftp trick it's just worthless." Hackers: $50,000 to keep source code private - http://t.co/x4BBGyav

Malware's the next nuclear bomb: Kaspersky: Governments have begun to create malware in the form of cyberweapons... http://t.co/VpOaDbIR

Malware's the next nuclear bomb: Kaspersky - ZDNet Australia http://t.co/dubHKvUX #B

NBN Co inks $620m satellite deal http://t.co/qgNiZcFH

Does Facebook accurately count users? http://t.co/hQcOtd2s via @zdnetaustralia

by http://t.co/vmlQ0Ecb: Malware's the next nuclear bomb: Kaspersky: Governments have begun to create malware in ... http://t.co/KfveHrKX

Malware's the next nuclear bomb: Kaspersky http://t.co/wJTLAbCP (via @Shogannai)

I guess we will hear more about this in the future..

1 hour ago by borrisz0r on Cochlear implant recall costs over $100m

Malware is the next nuclear bomb: Kaspersky http://t.co/j3oBGlxc

Malware's the next nuclear bomb: Kaspersky http://t.co/ILhLnszV

RT @zdnetaustralia: Malware is the next nuclear bomb: Kaspersky http://t.co/j3oBGlxc

Govt mulls closing Optus TV loophole - In the wake of Optus' victory over the sporting codes in its TV Now case, spo... http://t.co/6PxhKfB2

Can't believe how quickly things are happening on operation kill TV Now http://t.co/BK3Ecj1D

RT @zdnetaustralia: NBN Co inks $620m satellite deal: http://t.co/LsbQBeXL

Yahoo loses board chairman in reshuffle: By Josh Lowensohn, http://t.co/lS9JInfl on February 8th... http://t.co/R2FuBaYx #dualstack #ipv6

Rights holders lobbying for a quick change to the copyright act in the wake of the Optus TV Now case. http://t.co/dZAkzp0f #optusnrl

This is my point of view and like I said I cannot please everyone and I'm not going to try. Nor am I arguing about the economics, what I...

1 hour ago by fibretech on NBN Co inks $620m satellite deal

Govt mulls closing Optus TV Now loophole: http://t.co/mWyxcaNm

@chrispilgrim: Do you know how much it costs currently to get top tier NBN speeds in Surry Hills (basically 3 or 4 kms from the CBD)? It...

1 hour ago by gammprog on Libs would wind back NBN to fund roads

RT @stilgherrian: SOPA/PIPA fail, studios try anti-piracy 'charm offensive'. http://t.co/xuqzY3Rm

AVADirect, Maingear start shipping gaming laptops with Sandy Bridge-E desktop ... http://t.co/IUDDJdJg

My yahoo account has been down all day, and I use it to run my business. If you call Yahoo, they will set up your MS Outlook account to h...

1 hour ago by tenderfoot on Yahoo Mail suffers overnight outage

Chrome for Android finally arrives - Software - News - ZDNet Australia http://t.co/dIpXYS0I

fibretech, that's totally wrong. The metro users of the NBN will be subsidizing the NBN services in the regional zones because they co...

1 hour ago by tsudo77 on NBN Co inks $620m satellite deal

I know many people won't like this (not that you can please everyone anyway) but in one word "Equality"

1 hour ago by fibretech on NBN Co inks $620m satellite deal

Best thing ever! ZDNET is sending an aircraft into space and taking suggestions for what to attach to it: http://t.co/JpwkoQB5

SOPA/PIPA fail, studios try anti-piracy 'charm offensive'. http://t.co/xuqzY3Rm

What's the alternative fibre tech?

1 hour ago by mwil19 on NBN Co inks $620m satellite deal

Full Spectrum: getting tough on telcos: The standard of telecommunications customer service has been a sore poin... http://t.co/dmyelSn1

Cochlear implant recall costs over $100m: Cochlear, the Australian company behind the revolutionary hearing impl... http://t.co/le30SLB5

Windows 8 revealed
http://t.co/KoQA3QCh

@Spiraldeath Don't you think every tax payer deserves the same level of QOS? After all these people are leaders in primary industry whic...

2 hours ago by fibretech on NBN Co inks $620m satellite deal

@Fibretech so how would you propose to give broadband to a residence that is out in the middle of the Australian Desert and there is not ...

2 hours ago by Spiraldeath on NBN Co inks $620m satellite deal

Satellite technology is always a backward step when it comes to providing broadband. No matter how much bandwidth satellite provides the ...

2 hours ago by fibretech on NBN Co inks $620m satellite deal

I'm doing an assignment at my school about whether Facebook should have age restrictions; I think that even if you put an age limit on fa...

2 hours ago by Student onetwothree on Facebook to get age bans, parent control?

More TV Now => More mainstream fanbase in the future => More revenue streams from complementing products and accessories e.g. shirts, sho...

2 hours ago by pcr on More TV Now may mean less TV later

Shame on the Pilot, a company which employed him and gave him livelihood now he wants to sue the company. What if it was his personal lug...

3 hours ago by karan.vinayak on Pilot sues Virgin for being iPad Luddite

is Australian Cloud a puplic traded co. and if so what are the stock symble
thanks perry222

4 hours ago by perry222 on Australian clouds compared

I could care less about mobile footy coverage but if it wipes out Ray Warrens inane bleatings after forty years of aural misery I am all ...

4 hours ago by btone on More TV Now may mean less TV later

5mb/s calculates out to 625kb per second which means that a 1mb eMail will go out in under 1 second. Why isn't this fast enough ?

5 hours ago by deandari on Optus unveils NBN small business plans

PS. Living in Europe.

6 hours ago by Sparcosso on Chrome for Android finally arrives

Region-restriction on Chrome for Android on app market. Thanks Google! Guess it's time to flog the Nexus on ebay and head back to the iPh...

6 hours ago by Sparcosso on Chrome for Android finally arrives

This story has been voted 20 times in the last 24 hours!

19 hours ago, Symantec confirms hacker extortion

This story has been voted 10 times in the last 24 hours!

21 hours ago, Symantec confirms hacker extortion

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar