Hearing Of The Senate Homeland Security And Governmental Affairs Committee - Cybersecurity: Developing A National Strategy

Statement

Date: April 28, 2009
Location: Washington, DC

Copyright ©2009 by Federal News Service, Inc., Ste. 500, 1000 Vermont Ave, Washington, DC 20005 USA. Federal News Service is a private firm not affiliated with the federal government. No portion of this transcript may be copied, sold or retransmitted without the written authority of Federal News Service, Inc. Copyright is not claimed as to any part of the original work prepared by a United States government officer or employee as a part of that person's official duties. For information on subscribing to the FNS Internet Service at www.fednews.com, please email Carina Nyberg at cnyberg@fednews.com or call 1-202-216-2706.

SEN. LIEBERMAN: Good morning. The hearing will come to order. Thanks to the witnesses and others who are here. The topic of this hearing is our national strategy for cybersecurity.

I'm going to put my statement in the record and just speak for a few moments. It's a series of facts that brings the committee here and why we're grateful to a very distinguished and informed group of witnesses for helping us.

The first fact is that America's cyberspace is constantly under attack. The second is -- the best that I can determine -- our defenses to those attacks are inadequate. The third fact is that the Obama administration, building on work done by the Bush administration, has just completed a 60-day review of our cyber policy and structures and we expect soon to see a release of that report. The fourth fact is that the Department of Homeland Security, which was created out of this committee and over which we maintain oversight and monitoring responsibility, has unique authorities given to it under the statute with regard to cybersecurity.

And probably the fifth fact, maybe a probability, is that I believe that as part of the reaction to the report that Melissa Hathaway is doing for President Obama, we will be asked to consider -- and should consider -- some legislative changes or authorizations regarding the role of the Homeland Security Department and its responsibility to protect critical parts of our -- of America's cyberspace, particularly, obviously the nondefense governmental cyberspace, and to coordinate, to be the main point of coordination, with the private sector.

So this hearing is really an opportunity for us to learn from the four of you at this quite significant, potentially transformational moment in the history of America's relationship to cyberwarfare, really. I want to just briefly develop a few of those realities.

First, it's very clear -- if I can use a harsh word, but I'll use it because it's relevant -- our enemies in cyberspace, whether they are individual hackers or foreign governments or business competitors or organized crime groups or terrorists, seem too often to be one step ahead of our efforts to deter them, and that gap must be closed. From 2003's SQL slammer to the most recent Conficker worm, thousands of worms, viruses and so-called malware have infected and disabled computers around the world and put sensitive data at risk of loss, theft or improper disclosure.

Privacy breaches are a regular occurrence with identity theft, stolen credit cards, or exposure of financial information. Within the federal government millions of dollars worth of equipment has been lost and the personal information -- one example -- of millions of veterans compromised.

In a speech last week, Melissa Hathaway, who is the acting senior director for cyberspace at the -- both for the National and Homeland Security Councils, told of an incident in which 130 automatic teller machines, ATMs, in 49 cities around the world were illicitly emptied by cyber theft over a single 30-minute period. I mean, that is a stunning reality. The Wall Street Journal reported last week that operational information for the joint strike fighter, our advanced stealth capable tactical air fighter, was breached, making a number of things possible, including making it easier for enemies to defend against it, if not to steal some of the highly classified systems within it.

We know that there are severe vulnerabilities in our electricity grid and that foreign governments seeking to map our infrastructures have intruded into our electricity systems on a very large scale. So there's all too much evidence that our cyber infrastructure is insecure -- unfortunately, a lot of evidence that our security capabilities are inadequate to the challenge. GAO and various inspectors general have been repeatedly reporting on these weaknesses. Last December the Center for Strategic and International Studies issued a report listing the vulnerability of cyber networks as one of our nation's major security vulnerabilities -- risks.

Let me now focus just for a moment for the record on the Department of Homeland Security. The cybersecurity authorities of the Department of Homeland Security are not just general under the rubric of homeland security, but they are clearly outlined in statute and presidential directives. Title 2 of the Homeland Security Act directs DHS to lead critical infrastructure protection efforts, which by definition include cybersecurity. Critical infrastructure was defined in that act as, quote, "systems and assets, whether physical or virtual, so vital to the United States that the capacity or destruction of such systems and assets would have a debilitating affect on security, national economic security, national public health or safety, or any combination of these matters," end of quote.

In 2003, President Bush released the National Strategy to Secure Cyberspace, which stated that the Department of Homeland Security would be, quote, "the focal point for the federal government to manage cybersecurity," unquote. Later that year the White House issued Homeland Security Presidential Directive 7 to implement the critical infrastructure responsibilities laid out in the Homeland Security Act. HSPD-7 reinforced the leadership role of the Department of Homeland Security on cybersecurity, stating, and I quote, "The secretary of Homeland Security will continue to maintain an organization to serve as a focal point for the security of cyberspace," unquote.

In 2008, President Bush issued Homeland Security Presidential Directive 23 to implement the Comprehensive National Cybersecurity Initiative which focused on the protection of federal networks. The exact language used in HSPD-3 (sic) is classified; however, I can say that the directive affirmed that the Department of Homeland Security serves as the lead federal agency for the protection of federal civilian networks, that is to say all unclassified networks, and for coordinating private cyber -- private sector cybersecurity efforts.

So as we come to this transitional point, I think we on this committee feel strongly that the Department of Homeland Security has, under statute and presidential directive, a central and critically important role to play. And this committee, in a sense, is here to ask you how you think DHS has carried out that responsibility -- I know you'll testify to much else -- and also, what we can do to help DHS do the better job that we all acknowledge we need it to do. Thank you very much for being here.

Senator Collins.

SEN. SUSAN COLLINS (R-ME): Thank you, Mr. Chairman.

The information and communication networks that we refer to as cyberspace have become critical to our economy, our national defense and our homeland security, yet every week we learn of more threats to our cyber infrastructure. The specter of our adversaries disrupting our telecommunication systems, shutting down our electric power, or freezing our financial markets is no longer the stuff of science fiction, rather it is a very real possibility as thousands of cyber attacks are launched every day.

For example, intelligence officials tell us that China and Russia have attempted to map the American electrical grid and have left behind software that could be activated later, perhaps to disrupt or destroy components. The Washington Post has reported that hackers broke into the Pentagon's Joint Strike Fighter project and stole information. And last year, as the chairman alluded to, cyber thieves secretly implanted circuitry into keypads sold to British supermarkets which were then used to steal account information and pin numbers. As these numerous intrusions demonstrate, the cybersecurity threat is real, dangerous and accelerating.

Today this committee will examine the practical issues of how the federal government should best be organized to counter this threat. An effective response to cyber threats will require coordination among law enforcement, intelligence agencies and private owners of critical infrastructure. The Department of Homeland Security is the crucial nexus of these realms.

Bringing together these three worlds is precisely the reason that Congress created DHS following the terrorist attacks of 9/11. The Comprehensive National Cybersecurity Initiative, started last January -- and the chairman referred to it -- recognized the value of the department's unique perspective by placing the National Cyber Security Center at DHS and charging the department with the responsibility for advancing coordination and consultation among the many federal entities with cybersecurity missions. And following up on this directive, last year Senator Lieberman and I introduced a homeland security reauthorization bill that included cybersecurity provisions that would have increased the responsibilities of the center at DHS.

We also need to determine what specific authorities are necessary for DHS to undertake the mission of better securing federal networks and our nation's critical cyber infrastructure as the department works with -- but does not supplant -- the important roles played by the Department of Defense, the intelligence community, federal law enforcement officials and other agencies.

These authorities must allow DHS to address many of the most pressing cybersecurity issues, including how do you share critical infrastructure on threats and vulnerabilities, particularly with the private sector, since 85 percent of critical infrastructure is privately owned? How do you encourage the adoption of best practices and standards not only across government but throughout our nation's critical infrastructure?

How do we best generate a strategy that deters terrorists and hostile nation states from executing cyber attacks that potentially devastate our critical infrastructure? How do we best go after cyber criminals, not necessarily from other countries but within our own country? Sometimes that part is overlooked as we discuss the threat.

How do we secure the supply chain to ensure that systems we purchase are free from malicious code? And how do we best establish standards and performance metrics that can guide government procurement so to encourage manufacturers to incorporate better security into their products for the benefits of both government and the public at large?

Finally, as we consider the reorganization of cybersecurity activities, I would note that this new administration has shown a tendency to appoint special assistants and czars within the White House for virtually every important issue that we're confronting. While I understand the need to shine a spotlight on critical problems, the creation of numerous czars or special assistants usually leads to conflict, turf battles and confusing lines of authority.

Moreover, Congress's ability to effectively oversee activities directed from the executive office of the president are severely limited. Typically we cannot call upon those in the White House to come testify before us and their budget requests are presented with very limited detail. So the issue of reorganization of cybersecurity efforts necessarily involves the discussion of accountability and oversight by Congress as well.

On an issue as pressing and as complex as cybersecurity, congressional oversight is critical to making real progress. I look forward to exploring these issues with our witnesses today.

Mr. Chairman, you've assembled the top experts, and it's a pleasure to welcome back to the committee, of course, Mr. Baker who's been here many times. Thank you for holding this important hearing.

SEN. LIEBERMAN: Thanks, Senator Collins. Thanks for the very thoughtful statement; I appreciate it.

Stewart Baker, good to see you again. Welcome back. You graduate from line authority to elder statesman at an early age.

MR. BAKER: It's a pleasure to be home again. Thank you, Chairman Lieberman and Ranking Member Collins.

It's also a pleasure to graduate. I served on a commission once and one of the old hands on the commission said, yes, they brought back all the people who couldn't do the job to tell us why we should do it -- the things they couldn't do. (Laughter.) And in that spirit, I'd like to talk a little bit about the cyberspace crisis that we face.

You both have laid out the problem quite eloquently and I won't try to repeat that. I would like to explain why I think this problem persists and continues to grow worse, and I would use an example that I've laid out in my testimony.

A fellow named Howard Crank, a Vietnam vet suffering from diabetes, at home got an Internet connection and the world opened up to him. He could interact with the world. It was a wonderful thing for him until, essentially, scam artists found him and induced him to provide -- to mortgage his house twice, to max out his credit cards, to go into bankruptcy trying to recover the lottery proceeds he was told he had won. Right up until that moment I think he would have said the Internet had done a great thing for him, but interacting with the world, having the world interact with him turned out to be a disaster because not all of the world intended him well, and we are all in that position.

We are all getting benefits today from hooking up to the Internet, from using Internet protocols. They're making our lives easier and they're making the delivery of services and goods cheaper. And yet, every time we hook up to the Internet and expand the scope of those networks to other parts of our lives, we're creating greater risks that at some point the ice will give way and we will be dropped into the lake and lose everything. That is the greatest concern, but the fact that today we're not seeing any damage, any obvious harm to our networks or to our way of life is what has led to our continuing to ignore the problem or to minimize the problem.

I think it's a tribute to both this administration and to the last that we're finally beginning to look at the ways in which we can address this problem more seriously. And I would also like to give credit to Jim Lewis for the CSIS report, which I think very profoundly raised all of the issues that have to be addressed if we're going to successfully defend ourselves in cyberspace. That raises then, I think -- as Senator Lieberman and Senator Collins both suggested -- the question of how to organize ourselves to defend cyberspace.

And here I would like to draw on my experience.

I realized as I was preparing for this that I've helped to start two of the last three departments -- Cabinet departments and I've served on a commission that recommended extensive organizational changes in the federal government, and if I had to do it over again I'm not sure I'd do any of that.

I would say that there is almost a predictable pattern in the reorganization of government. You start with a failure. You say this is not working. We should create another organization to solve the problem, and that organization, since I've just dreamed it up, doesn't have any flaws at all and it will do everything I want done and much better than the obviously failed institution that I'm looking at today.

So comparing a failed institution where we have real failures to an imaginary institution that has no flaws, the imaginary institution always looks better.

Then, of course, once you actually try to start the imaginary organization, the imaginary organization discovers that it doesn't have a budget. It doesn't have staff. It doesn't have an exec sec. It doesn't have a human relations department to begin the hiring of people. And pretty soon that new institution is deep into a cycle of failure of its own, which then leads people to say well, that's a failure, we should reorganize; maybe we should have this new imaginary organization to do the job of the last imaginary organization.

I say that because I fear that the one recommendation of the CSIS report that I disagree with most strongly is the one that says DHS is not doing everything it should, consequently we should dream up a new organization, network -- a national cyberspace office that will perform all of the functions that DHS should be performing perfectly and is not performing perfectly.

The recourse to an imaginary organization, in my view, is precisely the problem with the CSIS report. We would be much better, in my view, taking DHS, which of course was given many of these authorities when it was an imaginary organization and now is deep into the second cycle where people find that it isn't doing the job perfectly -- we'd be much better off building DHS and its capabilities, something that has begun, I think seriously for the first time in the last year or two.

They are launched on the job of building a genuinely strong cybersecurity office that can provide guidance across the government, provide services and detailed capabilities to the president. If they are given the opportunity to do that, they will succeed.

If they are kicked aside because they can't perform every -- haven't performed every job that they've been given in the last five years, I think that we'll be making the mistake that we made with other organizations where we've said since we don't have a perfect job being done by the existing agencies, let's make up a new agency, hand them the responsibility.

I don't think we want to be in a position two years from now looking at a new organization that's been created to carry this out in the executive office of the president and say well, gee, they've just hired their staff; they've just begun to organize their budget; they've just determined who their exec sec should be, and so for two years we've been treading water and there have been a lot of failures since then.

That's a recipe for treading water and not for making improvements. I think we would be better off if we took the capabilities that DHS has and fund them, provide the responsibilities and the staff that they need and let them carry out those responsibilities under guidance from a very strong national security office that can provide the muscle interagency that's necessary to actually achieve coordination across the government.

Very briefly, I will also talk about the question of regulation. I think it's clear that some form of regulation is necessary in this area. No private sector agency can be expected to fend off state actors who are bent on infiltrating its network. We don't expect Citibank to fight our wars for us and if Citibank finds itself on the front lines of a war, we should be providing assistance to them at the federal level.

In fact, there is regulatory authority in many of these areas -- the Gramm-Leach-Bliley and the financial regulators have substantial authorities over cybersecurity. The FCC has provided and certainly has substantial authority over cybersecurity if we choose to use all of their authority. FERC has some authority

What's probably missing is some coordination and some what I would describe as nimbleness in responding to new threats. And that, I think, is something that DHS can do if it is given clear authority and clear -- not authority. They have the authority. They need a mandate from the administration, from the president and perhaps from this committee.

Thank you very much.

SEN. LIEBERMAN: Thanks, Mr. Baker. That was very interesting testimony, very helpful and has a certain healthy degree of skepticism that comes with having had considerable governmental experience. It's a longer view, but it's one that's very valuable to us.

Next we're going to hear from the -- previously mentioned and saluted James Lewis, director, senior fellow, Technology and Public Policy Program at the Center for Strategic and International Studies, which did the report that both Mr. Baker and I referred to.

Thanks for being here.

MR. LEWIS: Thanks very much and I thank the committee for the opportunity to testify, and also I applaud your efforts to try and deal with the new security challenges we face, so glad to be here.

To summarize the state of cybersecurity, our networks are vulnerable. Our opponents are inventive and energetic, and we are disorganized. Many people have worked hard in recent years but the U.S. is late and we're not doing enough.

As a nation, we've been slow to realize how important cyberspace has become for economic and national security and therefore slow to give it the priority it requires. The United States is being dragged down by weak cybersecurity, losing its edge in commerce, innovation and defense.

The problems we face -- espionage, crime and risk to critical infrastructure -- will never go away, but they can be reduced by coordinated government action. Put bluntly, we need a comprehensive strategy and somebody in charge of it.

To date, the U.S. has been unable to produce either leadership or a strategy. The 1998 Presidential Directive 63 still shapes policy, but it was overly fond of czars. The 2003 National Strategy to Secure Cyberspace was neutered by ideology and internal conflict.

The 2008 Comprehensive National Cybersecurity Initiative, CNCI, it has some valuable elements, but it was not comprehensive. It was also hobbled by infighting and it came far too late.

So in 2008, CSIS, as you've heard, put out a report that recommended a comprehensive national approach. We called for the creation of a strong White House cyber adviser with clear authorities and a comprehensive national strategy that would use all the tools of U.S. power, international engagement, military activity, economic policy and regulation.

Our report contained other important recommendations that I'm sure some of my fellow witnesses will mention, including the need for increased education, modernization of outdated laws and other activities.

While policy must be led from the White House, agencies must carry out implementation and operational activities. Operational responsibility for cybersecurity falls on three agencies: NSA, FBI and DHS. The previous administration assigned DHS the lead role for cybersecurity, but this was beyond its competencies. DHS is not the agency to lead intelligence, military, diplomatic or law enforcement efforts.

This does not mean that DHS does not have an important role and it's time for that agency to begin to perform it. DHS is responsible for protecting critical infrastructure and for securing the civilian government networks. It is beginning to build the capabilities needed to carry out these missions, but this will require sustained investment in facilities, technology and DHS's cyber workforce.

To date, cybersecurity at DHS does not have the resources it needs. DHS needs better technologies to secure civilian networks, government networks. The CNCI had a program named Einstein. Einstein is inadequate, whether it's Einstein 1, 2, 3 -- who knows, maybe 4 will work.

The real question is whether there's a way for DHS to work with NSA to secure all government networks. This is, or course, a sensitive topic. NSA has the capabilities. DHS has the responsibility, but there are compelling constitutional reasons for restricting NSA's role.

However, it would be a serious error not to take advantage of NSA at a time when our government networks are under sustained and successful attack.

DHS might also want to consider some reorganization within the National Cybersecurity Division. Perhaps a first step would be to merge US-CERT and the national communication systems and its component into a single entity inside of NCSD.

DHS's cyber functions are part of its National Protection and Programs Directorate. This directorate needs better plans to merge physical infrastructure and cyber infrastructure protection.

The National Infrastructure Protection Plan is more like a dictionary than a plan. DHS needs short, "implementable" plans on how to protect critical infrastructure and assure the delivery of critical services in the face of cyber attack.

As part of its critical infrastructure responsibilities, DHS is the interface, the federal interface with critical infrastructure owners and operators. This is an important role, but the current partnerships are inadequate, and DHS might want to look at the DOD defense industrial-based initiative as a model for partnership and information sharing.

DHS must be part of the larger regulatory effort to improve cybersecurity. To date, the U.S. has relied on market forces and voluntary action, but to quote the former chairman of the Securities and Exchange Commission, "The last six months have made it abundantly clear that voluntary regulation does not work." Much of the opposition to regulation involves the replay of warmed-over dot-com ideology and a strong desire by the private sector to escape liability. I'm very sympathetic to that.

As with any complex issue, there is no black or white answer. Too much regulation will damage the economy. Too little regulation will damage the economy and also harm national security. We need to find a middle course that balances commercial and national security interests. A new federal approach to cybersecurity must elicit action from the private sector that it will not otherwise perform. DHS does not have the regulatory authority for most critical infrastructure when it comes to cyberspace.

One thing to consider is whether to give DHS new and expansive authorities or whether to use existing authorities with current regulatory agencies like the FCC, FERC, NRC, FDIC and the many others.

As you know, the administration has recently concluded a 60-day review of cybersecurity policy. This was a spectacular effort most of us didn't think they would be able to finish on time. And while few public details have been released, it appears the White House will play a greater role in organizing and leading cybersecurity policy. There will be greater attention to international engagement and to relations with the private sector, and there will be closer coordination among agencies.

My hope is that the 60-day review leads to a strong White House cyber adviser with clear authority to set policy and guide budgets. More fumbling among agencies will only lead to disaster. But with so many different equities involved in cybersecurity, we face gridlock.

There is a regrettable debate over how much authority the White House cyber adviser should have over policy and how strenuously the U.S. should protect its cyber networks. There's a trade-off some say between security and innovation. I say this debate is regrettable because our opponents are not waiting 60 days to attack us.

The U.S. sits in a very unfortunate situation. We have made better use of cyberspace than our competitors, and this has provided real economic benefits. Our reliance on cyberspace holds the potential for innovation and future growth. However, the combination of greater reliance and inadequate attention to security has left us more vulnerable than our opponents. If we cannot change this, the power and influence of the United States will shrink and our prosperity and security will be damaged. Congress and the executive branch have the opportunity to avert this damage if we can act decisively.

I thank you for the opportunity to testify. I'll be happy to take your questions. Let me say it's always better -- it was more fun to testify against Stewart when he was in the government because he was a little more constrained. But -- (laughter) -- I welcome the opportunity to take your questions.

SEN. LIEBERMAN: Thank you. Well, we like Stewart in both roles. It's more unpredictable in this one. Both of you, though, have portrayed a crisis, which this is. And the question is what we can do together about it. Thanks for your testimony.

Next, we're going to hear from Alan Paller. Is it "Pollar," do you say?

MR. PALLER: "Paller."

SEN. LIEBERMAN: Paller -- director of research at the SANS Institute. Thanks very much for being here.

MR. PALLER: Good morning, Senator Lieberman, Senator Collins, Senator Carper, Senator Landrieu. Taking on this issue is really impressive. It's a complex issue; the language is arcane; it's just a pain. It turns out that you in your opening statement talked about what is really the central problem, which is that there is a gap between the attackers and our defenses. What is problematic is that the gap is increasing at an increasing rate. So all this discussion is important, but we are falling behind at an increasing rate.

Let me give you just one simple example. There's a young man named Tan Dailin who is a graduate student at Sichuan University. In 2005 the PLA, the People's Liberation Army, noticed he was hacking into a computer in Japan, so they picked him up and said wouldn't you like to be a contestant in our annual competition for who the best hackers are in Chengdu province? That's a southwest province of China.

He entered the competition. His team actually won, won 10,000 RMB. They put him through a 30-day, 16-hour-a-day workshop, where he learned to develop really high-end attacks and honed his skills. And then they put him in competition with teams from all over the rest of the military subunits in the Chengdu Military District, and his team won that. They won 20,000 RMB, he was famous and important.

He set up a little company; no one's exactly sure where all the money came from. But that company created the hacks that were found inside -- this was September 2005 when he won it. By December, his -- he was found inside DOD computers, well inside DOD computers.

By summer, the summer of 2006 was a particularly bad summer for the United States because there were a lot of what are called zero-day attacks, which are attacks that happen using vulnerabilities that the vendor hasn't patched yet. So there is no defense. And his team was found to have been the team that built six of those 30 or so zero-day vulnerabilities.

And what I'm trying to say is that other nations are investing heavily in creating massive new technologies, and our defenses are child-like. What we've done under the FISMA regulations, FISMA law, just embarrassing. And the result is much more than the public knows. You've had, you haven't, but the House has had testimony saying Commerce and the State Department have been deeply penetrated. What hasn't been told is that every other major department has been equally or more deeply penetrated, one so greatly that NSA had to bring their blue teams in just to find all of the problems. We don't tell the public that because it's embarrassing. But it's just a symptom of what's happening.

Eastern Europe has organized crime groups that recruit developers.

But the way they recruit them is with lies and money, and then when they find out that they're working for organized crime, and they don't want to, they, the crime groups use terror. They threaten their families, they kill their families if they don't want to work. So it's a world where they have -- you've talked about the $10 million that was obtained from -- in 30 minutes. What was interesting about that is the recent (stop ?) was the ATMs ran out of money. It was the only -- they were just emptied.

SEN. LIEBERMAN: Just take a moment to explain why the 30 minutes. Was that thought to be a period of vulnerability in the systems?

MR. PALLER: They thought they wouldn't get caught. Well, I didn't talk to them. The FBI thinks they assumed they wouldn't get caught doing it if it was short enough, that the triggers wouldn't happen.

SEN. LIEBERMAN: Right.

MR. PALLER: What was fascinating is you say how can they get that much money out? The attackers actually had control of the computers in the bank and were raising the limits of how much each of the cards could take out of the ATM as the ATMs were being emptied. So, you know, you normally have ($)100 or ($)300 or $500 limit. Those limits just kept growing and it was because the attackers had control of the computers as well as they'd made all these white, white cards.

But that's $10 million; it's one of thousands of attacks. You heard about the multicity outage of, power outage, that hackers did? You say why did they do that? Well, it's all extortion. If I have control of your computers and I say I'm going to take the power out, and you say no, you won't, well all I have to do is take the power out for two days and every other utility will pay.

It's a massive money-making scheme, and that money can be used to buy extremely advanced technologies. Our defenses, the way we've built them under the FISMA legislation, are just -- they're antagonistic to improve security. They're not just not improving, they're actually working against it.

But there's a wonderful story I want to share with you. It's why I was happy to come today. It's the one huge success; it's a federal success. It shows not only the federal government can radically improve security but that the effect can spill over into the defense industrial base and into the critical infrastructure. It started when NSA was briefing John Gilligan, who was the CIO at the Air Force, and they told him they could get into their systems in 30 minutes. And he said to them, you're not helping us. Tony Sager was the briefer from NSA.

John said to Tony: "You're just not helping us. You show us how you break in, we fix everything, a few months later you're going to come in and break in again. Can you get all your" -- this is the key statement -- "Can you get all your attackers together and tell us what the critical things are we should have done, that we should do to protect ourselves?"

That's -- if you hear Melissa Hathaway talking about offense must inform defense -- the fundamental error under FISMA was that we asked the people who didn't know about offense to tell us how to do defense. Can't do that, just can't do that.

So Tony went back and got the attackers together, showed John how to configure the systems, and they implemented those better configurations on a half a million computers. But they had to -- this is the -- you talk about -- this is from your opening statement, Senator Collins -- you talked about the key role that the private sector plays using procurement. That's the one huge lever you have. There's nothing close to it. If you want to change this, the lever you have is procurement.

So what John did is he went to Microsoft. Microsoft said, no, we're not going to give you a different configuration than what we give everybody else. One size fits all. You have to take the one we give you. And he went to see Ballmer and talked them into giving them a more secure configuration. They implemented across a half a million machines. Here's the results.

One, it used to take 57 days, on average, to patch the machines. That's a good number in the federal government -- 57 days -- way too long. Now it's 72 hours and heading down toward 24. So they were able to change the way they manage computers because they had these good configurations.

Two, they saved $100 million on procurement. They saved more than $100 million every year because they don't have to test the patches on every one of their different configurations and they save $30 million on energy because the settings actually were energy saving settings.

But most importantly, because all the experts said this wouldn't happen, the users were significantly happier. The help desk director at the Air Force reported that their help desk calls were down by 50 percent because the users actually were better.

So here you have much better security -- much, much better security, much lower costs, happier users. And Karen Evans, to her credit, actually took that and said to the rest of the government, let's do that, as a government.

The challenge right now is that the attackers have gotten so far ahead that that's only one piece of what has to be done. So John actually went back to Tony and said what are the rest of the things that have to be done? And he's actually created a new list of the critical things. But what I -- the one most important thing in all of that lesson is the federal government has the big lever and it's the $70 billion in IT procurement that you use each year. When we talk about a public-private partnership, those are meetings -- endless meetings -- I'm sure you've sat in on some of them. They go completely differently if you're about to spend a half a billion dollars, which is what John Gilligan did.

The great partnership is let's spend little pieces of that money. I don't -- saying increase the money. These commercial organizations are more than willing to do the more secure system. They actually like it if you'll tell them what secure is. That's where NSA comes in. You can't ask NIST to do that. They don't know what the attacks are. You have to get it from NSA and US-CERT. But once you know what the defenses are, you can use the procurement dollars to actually spend less money to have more secure systems.

And what I like most about that -- that story is that it trickled down. Microsoft now sells that more secure configuration to the defense industrial base, to the utilities, so you, using your procurement power, actually -- the nature of software and hardware is once it's been built more securely, there's nothing to stop them from selling that more secure version to everyone.

So the idea of leadership to me isn't whether it's a White House or a DHS leadership. It's whether you use the $70 billion a year that you spend to make the nation safer.

Thanks.

SEN. LIEBERMAN: Thanks very much, Mr. Paller. That was really riveting testimony and the story -- it's very important to tell these stories to help lay people, if you will, get into this.

Take a moment -- really, I mean no more than a moment -- and just -- I will enter it in the record along with your statement and everybody's statement, but what the SANS Institute is and what -- therefore what credibility you bring to this task.

MR. PALLER: We're the main teachers. We have about 100,000 alumni in 60 countries. We train the FBI guys, the NSA guys, the Brits, the Japanese, the Indonesians. We teach the very advanced cybersecurity courses -- forensics, intrusion detection -- and we also run the Internet Storm Center, which is an early warning system -- the Internet.

SEN. LIEBERMAN: That's great. Thank you.

Tom Kellermann is the vice president of security awareness -- pretty good title -- for Core Security Technologies; brings another unique perspective to assist the committee as we undertake this responsibility.

So we thank you for being here and welcome your testimony now.

MR. KELLERMANN: Thank you, Senator. I greatly appreciate the opportunity to debrief this committee on the serious economic and national security risk that we're facing today from a cyber perspective.

Much of my experience comes from my days at the World Bank treasury on the security team there. And I will caveat that with the need for all of us to appreciate "The Art of War" by Sun Tzu. We need to really appreciate how offense informs defense, but not only that, how we can better layer security and implement policies and programs to create defense in depth across not just the federal government but critical infrastructures.

The horrible events of 9/11 should have taught us a fundamental lesson, which was that non-state actors will use technology against our critical infrastructures. More importantly, it's obvious from 9/11 since that terrorist financing has been directly related to the proceeds of cybercrime, and the modern day Silk Road directly relates to those bank accounts that were pilfered in that case that Melissa Hathaway spoke of at RSA.

The DHS has done a successful job, I think, regarding increasing the federal standing per cyber attacks; however, there are some challenges that do detract from these efforts.

First of all: the lack of management continuity. Many of DHS's senior cybersecurity leadership positions are political appointments by nature and the resultant frequent turnover of management personnel and changes in priorities and focus of an organization's mission.

There's an insufficient support structure within DHS to provide fundamental functions to support cybersecurity needs, particularly the needs of what I consider to be the three most functional aspects of the National Cybersecurity Division, which are the Electronic Crimes Task Force, the Secret Service, the US-CERT, and the federal network security branch.

Specifically, as I relate to this, the federal network security branch is no longer the lead when it comes to establishing the standards of cybersecurity and computing across civilian agencies, and many times it has to defer to OMB. So that leadership position should be increased, not only I think that they should have the capacity to conduct red-teaming exercises against civilian agencies to determine where these vulnerabilities are to determine where their priorities should be for IT spending.

And this is a common problem across the federal government, where you have CIOs and CTOs leading the way vis-a-vis what should be spend on IT and IT security. CIOs mind-sets are much about productivity efficiencies, access to services and culturally differ from the defensive perspective of CISO community. And I think that it's important from a governance perspective that that perspective be raised to the top, particularly vis-a-vis the allocation of budgets and the expenditures of funds necessary to secure systems.

To this point, as evidenced by specific campaigns carried out against federal agencies in recent years and further illustrated by recent trends emerging in the larger cybercrime landscape, a true lack of situational awareness and an inability to predict the specific methods being utilized by electronic assailants is pervasive throughout the federal government, particularly as it relates to the recognition that the enemy no longer wants to disrupt service. The enemy wants to remain persistent and clandestine. The enemy, in fact, wants to launch a cyber insurgency or a cyber infiltration against your systems. And in the end, if they give in command and control, they want to remain omniscient but also be able to control the integrity of your data to manipulate it -- you in any which way they should feel necessary.

To address this dire reality, which has been highlighted most recently by the publicly -- incidence of energy hacking across the grid, not only in the U.S. but overseas, and the Heartland Payment Systems breach, which was one of the most massive financial breaches in the past 50 years. To that note, you know, over 200 banks were impacted by the Heartland breach, not just the cards themselves but those bank systems that were connected to those systems.

We need to represent the reality here that cyberspace is an aquatic environment and if you can attack one segment of the water you can affect the entire environment.

It's important that because of this reality that the Federal Information Security Management Act compels agencies to undergo more frequent internal assessments to gauge their risk to cyber attacks and not just check-the-box exercises for compliance but really using the dynamic guidance given that's being sponsored by Tony Sager and John Gilligan vis-a-vis the common audit guidelines. And specifically agencies should be required to conduct regularly extensive security audits of their IT systems using the red-team mentality and best practice identified by folks like Tony Sager and John Gilligan and the (CAG ?).

In addition, I would ask this committee to consider the creation of systems of accountability, including penalties for those organizations and civilian agencies who are not properly addressing those critical vulnerabilities and are tailoring their IT budgets to addressing those critical vulnerabilities.

There's too much plausible deniability in the system right now. People do not actually undergo this type of red teaming or penetration testing because they want to maintain plausible deniability to insulate themselves from not only the cleanup but also the criminal negligence that would come had they not addressed and remediated the problems that were found.

In addition, we must use these benchmarks to extrapolate this phenomenon to third-party outsourcing. The infamous breach of DHS three years ago was based on a lack of a standard of care and due diligence enforced on third-party managed service provider. The previously noted Verizon Data Breach Report noted that 39 percent of breaches were directly related to strategic partners.

This wasn't -- weren't cases of strategic partners attacking systems but those systems of the strategic partners being compromised and used as island hops to transit and attack those primary systems. It is imperative that we grapple with this systemic risk posed by the outsourcing and offshoring of not only American jobs but the digital ecosystem on which we are heavily dependent.

In order to promote and create a secure U.S. cyber ecosystem this committee should consider mandating that all entities who provide managed information security services of any sort to the U.S. government or providers of such services to critical infrastructures as defined by the NIPP, at the very least, enter into information security service-level agreements which go beyond the service level agreements today which are essentially contracts -- (inaudible) -- that have mediocre terms of liability and recourse and are far too focused on resiliency and uptime of the data versus the integrity and confidentiality of (set ?) data.

The agreements must require that these service providers at a minimum have the same standards of legal and layered security as defined by NIST-853 but also move forward and allow that entity -- the primary consumer of those services to conduct audits based on things like the (CAG ?) of those systems and mandate remediation timetables of those systems.

We must use federal acquisitions policy to require that these service providers comply with all these individual requirements. Those organizations who already are compliant with FISMA, who are being proactive, should inherently receive tax credits or some sort of benefit from the system for being good Samaritans in the cyber landscape.

In summary, while the national and worldwide cyber crime pandemic is currently scaling in an exponential manner, I would submit that the significant gains can be realized through the federal government today, via the political application of more aggressive attention to these issues. In this dark hour we need strong bipartisan leadership. The dramatic increase in cyber attacks necessitates action.

The recent 60-day cyber review developed by Melissa Hathaway represents a great starting point for real policy and strategic leadership, but it cannot be operational without the good work of DHS and this committee. It is paramount that this committee understands that it too can serve a fundamental role of change in defending our nation's critical infrastructures from this pervasive phenomenon.

I appreciate your consideration of my statement and, of course, your public service.

SEN. LIEBERMAN: Thanks very much, Mr. Kellermann.

That sets it right up for the question period. We'll do seven- minute rounds of questions.

Let me make a statement based on what you've said and what I've learned here on this committee but also in the Armed Services Committee -- we've got a lot of overlap between the two committees.

For a number of years we have been warned in the Armed Services Committee of the threat of asymmetrical warfare, which is to say we -- the United States has become so strong in what might be called conventional warfare that it would be natural for somebody wanting to do us ill to choose not to try to compete with us on that level but to look for the weakness -- the vulnerability and to attack us, in that sense, asymmetrically.

The second reality that we're dealing with, of course, is that after 9/11 we are involved with Islamist terrorists in a world -- a global conflict in which some of the old -- the traditional rules of warfare are gone, which is to say this is not planes against planes, ships against ships, armies against armies in conventional battlefields. People strike it as from the dark and have no hesitancy to strike civilian populations as we saw here, painfully, on 9/11/01.

So you put both those together -- both the warnings that we got about asymmetrical warfare and this -- the new rules of a conflict we're in, particularly in which civilian targets are open targets -- cyber attacks just jumps right out at you, doesn't it, as a major threat to the security of the United States and makes relevant not just the defense that the Department of Defense must provide to defense cyber systems but all of the privately controlled cyber systems in our country that really are in control of our financial system, our power-generating system -- you could go on and on. A lot of our health care system could be incapacitated.

So I want to invite a reaction. To me this is a real crisis, but I invite you if you think I am overstating it, state it. But here's my concern, if I were an enemy -- either a state enemy or a non-state enemy, like a terrorist group wanting to do us harm, it seems to me that one of the first most attractive ways to attack us would be a cyber attack, both because of the difficulty of finding me -- the enemy -- but also of the tremendous damage I could do at this point in our -- in the status of our cyber defenses. True?

Mr. Paller?

MR. PALLER: I think you're absolutely right, but I don't think that the time is yet.

SEN. LIEBERMAN: Okay.

MR. PALLER: Meaning, I think right now it's easier to bring a bomb across the border and blow somebody up, and if you're going to do terror right now, that simply works.

SEN. LIEBERMAN: Right.

MR. PALLER: As we strengthen the borders, as we make it harder and harder and harder to do kinetic attacks, this kind of attack will become the attack of choice. And the reason that it's such a challenge that you have to act right now is that there -- the asymmetric warfare means pre-establishing control. So when the Chinese or another nation gets into a Senate committee, they don't get in to steal the data, they get in to steal the data and to leave something so that they can change information at critical moments.

SEN. LIEBERMAN: Correct.

MR. PALLER: So it's now that we have to fix cybersecurity in government and the commercial sector because the war will come later that is fought in cyberspace. But I don't think we're sitting here waiting for a new attack against the power plants of America in the next six months.

SEN. LIEBERMAN: Okay, you, in your testimony, Mr. Kellermann, made some references as how these will come together. Organized criminal groups see an opportunity to hold up private entities for money by threatening cyber attack or actually carrying them out. You raised the question of whether that clearing of the $10 million from the ATMs -- some of that money may have ended up -- although it may have started with organized crime, maybe not -- in terrorism usage.

But in your written testimony you use the example of the Bali bombings in 2005 as an example of a terrorist attack that was funded by cyber crime. Just take a quick moment and tell us about that.

MR. KELLERMANN: What's interesting about the Bali bomber, (Abraham ?) Samudra was that he not only financed the attack through credit card fraud precipitated through cyber crime, but he wrote a manifesto of sorts while imprisoned in Indonesian prison stressing that jihad could best be waged by using the money of the infidels to finance the physical acts of terror against the infidels.

And you'll see actually a spike -- and I'm sure Alan can speak to this with Internet Storm Center -- you've seen a spike since in the number of hack attacks emanating out of Indonesia. There's a realization of sorts that this Robin Hood mentality that the lack of resources that these communities traditionally have can be acquired through cyber means because the financial sector is so porous and too over-reliant on perimeter defenses.

But more importantly, vis-a-vis the different types of non-state actors, you have a Dark Ages mentality now in the underground where you literally have communities that are assisting other communities without ever meeting them -- in a very ephemeral sense -- and acquiring the weapons-grade technologies to attack systems, whether or not they have computer skill sets, as well as the sale of owned systems -- systems that have already been compromised is widespread, as well as financial details and bank accounts and credit card numbers can be sold for $40 a pop in this system to any actor so long as they're not considered a "ripper," which is someone who's untrustworthy, that they don't follow through with deals.

SEN. LIEBERMAN: Okay. I have very little time left, but I want to just draw out Mr. Baker and Mr. Lewis on the debate you have about how we should best organize to respond to this.

Am I right that both of you agree that the Department of Homeland Security should have primary responsibility for nondefense federal government computers and for the interaction between the federal government and the private sector in regard to cyber defenses, is that right?

MR. : Yeah.

SEN. LIEBERMAN: So okay, I want to say for the record that both are nodding affirmatively.

So let me understand, Mr. Lewis, you've been very clear. You think there ought to be an office in the White House to coordinate everybody involved -- DHS, NSA, DOD.

But, Stewart, let me understand what you're suggesting. Do you think the Department of Homeland Security --


Source
arrow_upward