ellen_messmer
Senior Editor, Network World

DISA fortifying military’s IT defenses

News
Jun 2, 20033 mins

The Defense Information Systems Agency, which provides the military with technical help on software and telecom projects around the world, is taking new steps to improve network security at bases and in the field.

The Defense Information Systems Agency, which provides the military with technical help on software and telecom projects around the world, is taking new steps to improve network security at bases and in the field.

DISA last week announced it has signed a three-year agreement to make use of the real-time IT security threat and vulnerability intelligence reports issued by Symantec’s DeepSight Threat Management System. This service picks up early signs of attacks or computer worms based on input from 19,000 firewalls and intrusion-detection systems in 180 countries.

DISA also will get advice on the latest software vulnerabilities – and recommendations on how to deal with them – from a separate Symantec offering called DeepSign Alert Services, which tracks vulnerabilities in more than 3,200 products.

The military’s prime interest is in gaining “early-warning notifications” to factor into its understanding of how to manage “risks posed by novel and sophisticated threats,” says DISA Contracting Officer Mark Bogart. While DISA isn’t releasing the financial terms under which it will use the services, they typically start at $60,000 annually.

DISA plans to have its Department of Defense CERT group receive the Symantec alert reports as part of its ongoing effort to keep military branches apprised of security threats.

PROFILE: DEFENSE INFOR-MATION SYSTEMS AGENCY
Headquarters: Arlington, Va., with offices at McDill Air Force Base in Florida and the Joint Spectrum Center in Annapolis, Md.
Founded:May 12, 1960
Employees:8,200
Mission: Software and telecom support for the U.S. military and its warfighters.

DISA has operational responsibility for a variety of communications resources, including the military’s IP-based network called the Non-classified Internet Protocol Router Network. The military faces the same problems as the commercial world in combating hackers, worms and patching for software vulnerabilities. DISA fell victim to hackers two years ago when its Web sites were defaced.

In addition to making use of new early-warning services, DISA has deployed a LAN-based security-monitoring product from Securify at military bases worldwide to detect possible hacker incursions or unauthorized insider use of military campus networks.

Securify’s SecurVantage Enterprise Global features a Windows 2000-based monitor that can be plugged into an Ethernet switch for real-time traffic analysis. Network managers can set up role-based security policies based on IP source and destination address, Web-based transactions and other application use to determine whether network activity might constitute a breach of correct behavior. A single Securify management console can be used to aggregate information from up to 280 Securify monitors and to manage them.

DISA has deployed the Securify monitoring system at its headquarters in Arlington, Va.,as well as in DISA office locations and Army and Navy bases in Okinawa, Tokyo, Pearl Harbor, San Diego and in undisclosed locations in Iraq, sources close to the project say.