Network World

research center:

Security

Search / DocFinder:
Advanced search
Research Centers
Vendor Solutions
Site Resources
Special Issues

Signature SeriesEnterprise All-Stars
Enterprise All-Stars NEW

You in action
You in action

New Data Center The New Data Center: Wireless & Mobility
Wireless & Mobility NEW

The New Data Center: Server Virtualization
Server Virtualization

Military clamping down on security

By Ellen Messmer, Network World, 01/16/06

PALM HARBOR, Fla. - Amid growing concern about hacker infiltrations into military computers, the top commander for the Department of Defense network operations has ordered a crackdown on security.

Advertisement:

Lt. Gen. Charles Croom, commander of the Joint Task Force on Global Network Operations (JTF-GNO) and director of the Defense Information Systems Agency (DISA), last week said a sweep is under way of all Defense Department networks to uncover security holes amid a get-tough policy.

"The attacks are coming from everywhere and they're getting better," said Croom in his keynote address at the Department of Defense Cyber Crime Conference in Palm Harbor, Fla., last week. "They're exploiting weaknesses in our detection tools."

The discovery of a botnet last November in Defense Department networks contributed to the decision to clamp down security. Jeanson James Ancheta, 20, was arrested by the FBI for allegedly implanting and running the remotely controlled spyware inside the department and elsewhere.

"It started on Nov. 5 with an information assurance stand-down day," Croom told the roughly 500 conference attendees. The military stand-down - a cessation of regular activities in order to probe security problems - is ongoing as DISA attempts to verify the tens of thousands of user accounts for Army, Navy and Air Force personnel.

No good news

So far, the results are troubling.

"Almost 20% of our accounts are unauthorized or had expired," Croom said, noting that military personnel tend to move every two or three years and accounts are sometimes left open. The exact tally of improper accounts won't be known until March, he said.

In addition, the military is increasingly fending off targeted phishing attempts in which attackers try to spoof victims into giving up passwords.

Back doors left open by not properly shutting down network circuits also are of concern to Croom, who has held the top job in Defense Department network operations since July, when he succeeded Lt. Gen. Harry Raduege. Croom said the paperwork for circuits must be in order or the circuit will be shut down.

"Last week we closed down four circuits to users," Croom said, though not identifying the exact locations. "Now I get an e-mail saying the paperwork will be in today." This get-tough approach is needed to put teeth into already existing policy.

A united front

The biggest changes to come may be in the next six months as the JTF-GNO, the organization set up to centralize decisions about security and operations in the Army, Navy Air Force and Marines, evaluates a possible redesign of its two primary, global, IP-based, military networks.

Network World's Hot seat with John Gallant. Five minutes. Unscripted. Unexpected.

Interview: Keeping insider information inside
PortAuthority's appliance-based approach to data protection helps keep company secrets from getting out. PortAuthority President and CEO Pete Foley explains how it all works on this week's Network World Hot Seat.Watch it now

All Hot Seat videos

TOP STORIES | MOST DUGG STORIES

  1. FBI warns Hit Man e-mail scammer back
  2. 20 tech habits to improve your life
  3. Industry mourns slain Cisco exec
  4. 10 Firefox add-ons for better browsing
  5. Wireless LANs face scaling challenges
  6. Will CCIE count predict world power?
  7. Cisco buys PostPath
  8. New security rules for credit-card handlers
  9. Malware infects space station laptops
  10. IBM flash memory breaks 1 million IOPS

  11. MOST-WATCHED VIDEO:
    Omega keeping time at the Olympics

Related Links


US border agency says it can seize laptops 8/1/2008
US Air Force lets Web 2.0 flourish behind walls 7/17/2008
ACLU files lawsuit to challenge surveillance law 7/10/2008
Powered by Inform

Newsletters
Sign up for one of NWW's Network Security newsletters.

Security in Practice
Virus and Bug Patch Alert
Security Strategies
Security News Alert
VPNs
Messaging
View all newsletters

Email Address:
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Vendor Solutions

White Papers

Advancing the Economics of Networking
- Juniper Networks

Implementing HA at the Enterprise Data Center Edge to Connect to a Large Number of Branch Offices
- Juniper Networks

Enterprise Data Center Network Reference Architecture
- Juniper Networks

More...

Special Report

IT Buyer's Guide to Security Information Management - Open Service
Discover how Security Information Management and Security Event Management products have seen much improvement of late. This gear lets IT professionals automate the manual process of collecting security-specific event-log data. Learn about performance and reporting enhancements that simplify and improve this task. Get all of the details today.


Research Centers: Applications | Application Development | Applications-Standards | Applications Vendor Solutions | Collaboration | CRM / ERP | Databases | Directories | Grid Computing | Java | Messaging | .Net | RFID | SOAP | Web Services | XML | Convergence & VoIP | Convergence Regulatory | Convergence Services | Convergence Standards | Convergence VoIP Vendor Solutions | Video | IP PBX | SIP | VoIP | VoIP Services | E-Business | DNS | RFID | Supply Chain | Web security LANs & Routers | Acceleration | Gigabit Ethernet | Lans-Standards | Routers | Wireless LANs | Network Management | Application Management | Desktop Management | Management Test Patch Management | Operating Systems | Linux | NetWare | Unix | Windows Outsourcing | Managed Services | Offshoring Security | Firewalls - VPN - Intrusion | Identity management | Patch Management | Microsoft Security | Privacy | Security Standards | Spam & Phishing | Viruses & worms | Web Security | Wireless Security | Servers & Desktop | Backup-Recovery | DataCenter | Desktops | Desktop Management | Grid | Servers | Server Blades | Servers Desktops | Utility Computing | Small & Medium Business | Broadband | Telework | Handhelds & PDAs | Home Networking | Security | Storage | Compliance | Infiniband | Network-Attached Storage | SANs | Storage Management | Storage Virtualization | Virtualization | Vendor News | Bankruptcy | Earnings | Lawsuits | Layoffs | Standards | Start Ups | Vendor Markets | Education | Financial | Healthcare | HIPAA | Manufacturing | Retail | Wide Area Network | Broadband | Carriers | Frame Relay | Metro Ethernet | MPLS | Service providers | Wireless services | Wireless & Mobile | Wireless LANs | PDAs & handhelds | Wireless Security | Wireless Services | Wireless Standards | Wireless Switches | All Company Profiles