Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Govt, Enterprise Data Sharing Efforts Crumbling

    Written by

    Dennis Fisher
    Published August 9, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Several years after the beginning of a widespread effort between public and private parties to create an environment that would allow broader dissemination of vulnerability information, friction among the players is now scuttling such efforts.

      The federal government, a key promoter of numerous information-sharing programs, announced last week it wants even more information from private network operators on vulnerabilities, infrastructure, traffic routing, disruptions and outages. At the same time, government officials and quasi-government agencies such as CERT have been making less and less information available to the private sector.

      In response, many network operators and private security researchers, the sources of much of the data now available, have recently announced plans to take their information about viruses and worms and other hacks back underground, where, they said, it improves overall security and represents a lucrative revenue stream.

      This reversal of efforts to create open exchanges of security data comes at a time when government agencies are being urged to change their secretive ways. In the short term, at least, the struggle will mean less free information available to the thousands of enterprises that depend on existing information-sharing programs to stay current on security and vulnerability matters, insiders said.

      “I know Id be angry if Id been sitting on a potential breach for days without knowing,” said Jacob Bresciani, systems analyst at the University of Alberta, in Edmonton. “I should at least be aware of the problem and, at the very least, increase monitoring.”

      Still, the industry seems intent on keeping vulnerability data under wraps.

      “The security industry is very competitive, [and] to give full information on such issues loses your competitive edge,” said Mark Litchfield, co-founder of Next Generation Security Software Ltd., in Surrey, England. Litchfield, along with his brother David, is one of the more prolific and respected researchers in the security community.

      Indeed, at the recent Black Hat conference in Las Vegas, David Litchfield discussed a slew of new holes NGSS has found in some of Oracle Corp.s products but gave few details on the actual vulnerabilities.

      After CERT last year decided to distribute research to a paid mailing list and, later, to partner with the Department of Homeland Security to create US-CERT, which distributes information to other government agencies, NGSS stopped providing data to the organization.

      For its part, CERT this spring closed its public mailing list and no longer shares technical advisories with the public, even though nearly all its bulletins are based on information provided by the private sector.

      Next Page: CERTs loss is U.K.s gain.

      Page 2

      CERTs loss is the United Kingdoms gain. NGSS two weeks ago inked a deal with the British government to provide that countrys top cyber-security office with access to NGSS research on an advance basis, something the Litchfields said they will not offer CERT or the DHS.

      CERT joins a growing list of agencies close to, and within, the U.S. government that, while demanding rising volumes of data from the private sector, have not set an example for an efficient flow of information, experts say.

      Still, the thirst for increased data, even to a government body reluctant to share it, could hinder security efforts, according to Bob Collet, vice president for engineering at AT&T Corp.s Government Solutions division, in Washington.

      “In the wrong hands, this compilation of critical infrastructure assets only increases vulnerability,” Collet told the House Government Reform committee last week. Collet added that sensitive network data should be closely guarded by individual providers.

      /zimages/4/28571.gifFor insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzers Weblog.

      That attitude has the owners of the popular Zone-h.org security portal taking a similar tack. Two weeks ago, the group announced plans to set up a private, restricted-access repository for exploit code. Also under development is a companion forum, which will be open to the public. No time frame was announced, however.

      “We decided to use this scheme so that our exploit database will not be used by crackers or defacers to get access to other systems. Basically, we want to know whos who before granting access,” said Roberto Preatoni, administrator at Zone-h, based in Tallinn, Estonia. “Only when we trust somebody will we let him in. Everybody will have the possibility to gain our trust and get access, but it will not be an easy task.”

      Next Page: Show me the money.

      Page 3

      Another big part of the disclosure issue causing discontent among cyber-security players is compensation. Vulnerability information and exploit code have become valuable commodities, and many companies, including Internet Security Systems Inc., iDefense Inc. and others, provide some of their customers with prerelease versions of their research for a fee. As such, giving that data away to the government, or anyone else, is of very little interest.

      “Our value proposition to customers is that they have advance notification of problems before the public does,” said John Watters, CEO of iDefense, based in Reston, Va. “People are not inclined to do things unless theres an economic incentive.”

      /zimages/4/28571.gifCheck out eWEEK.coms Government Center at http://government.eweek.com for the latest news and analysis of technologys impact on government practices and regulations, as well as coverage of the government IT sector.

      Faced with the loss of security sources, state and federal agencies are gradually tightening the screws on the industries they hold regulatory sway over—mainly network operators—to turn over more data and keep the intragovernmental information-sharing programs vital.

      Last week, the Federal Communications Commission imposed new mandatory outage reporting requirements, despite months of protest from AT&T and other major carriers. While the FCC assured the industry that sensitive information will be kept from public disclosure, some said they are not convinced.

      Illustrating the waning leverage that the industry wields in the information-sharing struggle, FCC Commissioner Kevin Martin conceded last week that he is impressed with the carriers voluntary reporting initiatives and said he agrees that sensitive network information must be protected but that he voted for the new mandates because the DHS identified the outage information as critical to national security.

      /zimages/4/28571.gifCheck out eWEEK.coms Security Center at http://security.eweek.com for the latest security news, reviews and analysis.

      /zimages/4/77042.gif

      Be sure to add our eWEEK.com developer and Web services news feed to your RSS newsreader or My Yahoo page

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×