ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

White House preps cybersecurity plan

Declan McCullagh, CNET News.com CNet

Published: 17 Sep 2002 15:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The White House's cyberspace security plan, scheduled to be released Wednesday, envisions a broad new role for the federal government in maintaining Internet security.

While couching many concepts as mere suggestions, a draft of the plan seen by CNET News.com says the government should improve the security of key Internet protocols and spend tens of millions of dollars on centres to recognise and respond to cyberattacks.

The draft report, however, is still in flux. As of late Monday, one controversial section that appears to have been deleted would have required companies to contribute money to a fund to secure computer networks.

Prepared by Richard Clarke, President Bush's special advisor for cyberspace security, the draft says changes "will be needed" in key Internet protocols and endorses "trustworthy computing" technologies such as Microsoft's proposed system. Also under consideration are a "cyber emergency response plan" that would be activated during Internet crises and a National Cyberspace Academy to "advance research in cybersecurity education."

It says the executive branch should consult with privacy groups and attempt to preserve civil liberties, but concludes that in some cases, privacy could be limited. "Allowing completely anonymous communications on a wide-scale basis, with no possibility of determining the source, could shelter criminal, or even terrorist communications," the draft says.

Because the report is simply a set of recommendations prepared by the Bush administration, there is no compulsion for private firms to follow its recommendations. But because it is backed by the White House during a time of heightened security consciousness, it likely will be taken seriously by legislators when they consider new laws.

In October 2001, in the wake of the 11 September terrorist attacks, President Bush appointed Clarke to coordinate the administration's Internet security efforts.

Harris Miller, president of the Information Technology Association of America, said he believes any remaining disagreements that industry groups have with the White House report will be worked out before Wednesday's scheduled release.

"The issues that we're focusing on are on the margins," Miller said. "There weren't any fundamental concerns... Assuming the final draft is close to the draft we've seen, we generally support it."

Government-crafted protocols
One Internet protocol the draft singles out for criticism is the Border Gateway Protocol (BGP), which is used to exchange routing information among interconnected networks. The report concludes that "changes in BGP will be needed" because of current security vulnerabilities.

Another point of criticism is the Domain Name System (DNS), which translates domain names such as cnet.com into numeric addresses such as 206.16.0.148. "The accuracy of the data in the DNS databases needs to be improved and stronger mechanisms are needed to ensure the authentication of the DNS database along with changes to the database," the report concludes.

The draft suggests that it's time for the federal government to become more involved in the development of Internet protocols, security and standards -- a role currently assumed by the Internet Engineering Task Force.

Government, it says, must "conduct research and development for the collective good. This is a role that the government played during the founding of the Internet... The federal government, without regulating or controlling the Internet, should systematically ensure that necessary research and similar activities are conducted to insure the security and reliability of the Internet."

Brad Jansen, an adjunct fellow at the free-market Competitive Enterprise Institute who is familiar with the report, said: "I found it encouraging that the report recognised the importance of training and implementation beyond just grand plans. There are systems within the government's sphere that it should not ignore. But there's little recognition of cost-benefit analysis throughout the report, and much emphasis on how we can spend money."

Future directions
One section, part of the "National Priorities" chapter, is forward-looking. It says that the government should closely monitor progress in quantum computing, intelligent agents and nanotechnology: "For example, the development of intelligent nanodevices could cause massive growth in the numbers of connected devices on the Internet and the locations and uses in which these devices are deployed."

Quantum computing, which could bring systems so powerful that they could render current encryption technologies obsolete, poses a threat as well. "Backup planning for the unexpected -- the secret breakthrough by an unfriendly country -- should be considered. How would such an advance be used against us? How would we detect if our cryptography is compromised? A watchful eye should also be kept on foreign research."

The White House is also worried about attackers employing intelligent agents, smart computer programs that can search for information or carry out tasks on their own. "Adversaries using agents would have the distinct advantage of being able to attempt many variations on many themes either over a very short period of time, since they can operate at digital speeds, or over an extended period of time without losing focus, since they are computer programs."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
48 out of 86 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Systems Administrator/ Server2003/ AD/ SW/London/ DNS/DHCP/40K

Additionally you must be proficient with networking protocols including TCP/IP, DNS, DHCP. Systems Administrator/ MCSE/ Server2003/ Active Directory/ ...

Support Engineer/ XP/ 2000/ Office/ AD/ SE.London Exchange/ 25k

You must have excellent communication skills and solid working knowledge of Windows 2000/ XP, MS Office, Server 2000/3, Exchange 2000/3, as well as ...

Content Solutions Architect London 70,000 + Package London

You will also have very strong knowledge of the internet protocols : DNS, routing, ftp, HTTP, SMTP, TCP/IP. Content Solutions Architect. News ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains