Defense Department Confirms Critical Cyber-attack | eWeek

Defense Department Confirms Critical Cyber-attack

Written By
Brian Prince
Brian Prince
Aug 25, 2010
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A senior Pentagon official has revealed details of a previously classified malware attack he declared “the most significant breach of U.S. military computers ever.”

In an article for Foreign Affairs, Deputy Defense Secretary William J. Lynn III writes that in 2008 a flash drive believed to have been infected by a foreign intelligence agency uploaded malicious code onto a network run by the military’s Central Command.

“That code spread undetected on both classified and unclassified systems, establishing what amounted to a digital beachhead, from which data could be transferred to servers under foreign control,” Lynn writes. “It was a network administrator’s worst fear: a rogue program operating silently, poised to deliver operational plans into the hands of an unknown adversary.”

In response to the incident, the military implemented a ban on USB devices, a prohibition that has since been modified.

“USB devices as an attack vector have significant advantages over e-mail, Web or other network-based attacks,” said Richard Wang, manager of Sophos’ lab operations in the United States. “The focus for most network attacks is the perimeter, wherever the contact between the outside world and your network first happens. However, USB devices can appear anywhere on a network because they bypass the network perimeter defenses simply by sitting in someone’s pocket.”

In addition to details on the attack, Lynn discusses the Department of Defense’s cyber-security strategy, including partnerships between the private and public sector as well as what he termed “active defenses.”

“The National Security Agency has pioneered systems that, using warnings provided by U.S. intelligence capabilities, automatically deploy defenses to counter intrusions in real time,” he writes. “Part sensor, part sentry, part sharpshooter, these active defense systems represent a fundamental shift in the U.S. approach to network defense. They work by placing scanning technology at the interface of military networks and the open Internet to detect and stop malicious code before it passes into military networks. Active defenses now protect all defense and intelligence networks in the ‘.mil’ domain.”

The goal of these strategies, he concluded, “is to make cyberspace safe so that its revolutionary innovations can enhance both the United States’ national security and its economic security.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.