Largest Simulated Cyber Attack To Date 71
Orome1 noted that the government will be running
simulated cyber attacks as part of the Department of Homeland Security's Cyber Storm III exercise. It says "The exercise will be controlled from the Secret Service headquarters, where organizers from various agencies will be sending out 'exercise injects,' information that a player will receive that indicates that a certain event has taken place as part of the narrative set up by the organizers. This goes a bit beyond a paper narrative, including fake log data, drives that may contain fake malware, and fake event history, and is dynamic, meaning that it can change dependent on the actions the players take." ...which makes me wonder how effective this test would actually be.
Obligatory (Score:4, Funny)
The only winning move is not to play. Now get me a WOPR with cheese!
Re: (Score:2)
This sounds like the perfect oppty for Catering, Coffee, and Donuts. I wonder if that is their true motivation.
Re: (Score:2)
cast firewall spell, roll 3d10 (Score:2)
Re: (Score:1)
Uh Oh (Score:3, Interesting)
Should we expect a real attack at the same time?
Re: (Score:2)
Re:Uh Oh (Score:4, Funny)
Re: (Score:1)
Don't give people ideas. They might use them.
External & Internal attacks? (Score:1, Interesting)
I hope they're not just testing over the wire attacks, that new janitor with the thumb drive could do some damage...
Re: (Score:2, Interesting)
Re: (Score:2)
Re: (Score:2)
"I invoke... Internet Killswitch."
"Why are you invoking the Killswitch? There's nothing to stop here."
"I'm stopping the HACKERS."
[Situation Room laughter]
Re: (Score:2)
"Hey, uh, your intranet's DNS servers are under DDoS attack."
"How could they be attacking our servers? I had Mordenpyren's Magical Firewall installed!"
I wonder if it is possible to subvert this sim (Score:2, Interesting)
Re: (Score:2)
Um, shouldn't.
In the real world there is a helpdesk code for 'only an exercise' that was created years ago.
The only thing more dangerous about an exercise is distribution of security resources themselves, and it would be the same on exercise day as training day as Security Conference(Black Hat DC, FOSE) as $NationalHoliday.
Re: (Score:2)
Re: (Score:2)
From the article:
Now's the time (Score:3, Interesting)
Can anyone think of a good time to run a real cyber attack against DHS?
Let me guess the results in advance (Score:5, Informative)
I can guess the results in advance of this pointless "test".
We did well enough that none of us should be fired. Or we selected a fall guy months ago whom is not playing along, and I guess with "great shock" at the result its time for him to "spend more time with his family".
We did poorly enough that we all need more money. Conveniently I happen to have a brother-in-law in sales at a contractor that provides a magic bullet that claims to do everything we need...
There has never been a public "test" like this with any other result. Therefore its not even "news".
I have participated in things like this (not in this situation or field) and the primary reason they occur is someone wants to send cash to a buddy at a contractor, and everyone else wants a day off eating catered food and enjoying some business travel.
Re: (Score:2)
best. summary. ever.
Anyone care to bet against this being the approximate result?
Re: (Score:2)
Re: (Score:3, Interesting)
Oh..., wait.
Re: (Score:1)
Re: (Score:2)
Which is why these types of exercises are very carefully framed and preplanned to get the desired result.
Don't forget, carefully planned and orchestrated failure, resulting in a live-fire FUD attack against the general public with the aid of some friendly journalists, might be the goal. Especially if the "ideal solution" happens to be taking away our rights, more laws, more regulation, etc.
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
Tell that to that cat in the box! (He's getting hungry, please visit him! I can't take the wailing.)
Re: (Score:2)
Re: (Score:2)
The prediction was not one or the other, but both.
Re: (Score:2)
The result of most army training exercises is OPFOR wrecking the home team. Then after lessons learned and experiences build up, the OPFOR can be beaten. I don't understand why a civilian organization would be different? It should really be a matter of reorganizing and retraining the assets they already have.. not purchasing new stuff. If their planning and expectations were so terrible that they need new equipment, then by all means they should buy it.
Nobody should be fired because of a test, what a wa
Re: (Score:2)
Kudos. Wish you were modded 5 instead of parent. Per my too-long rant above, you're far more right about this stuff than parent is.
Incidentally, the stuff that bit us on the ass last year tended to be much smaller than in our first such exercises. The most notable was a panicked boss overruling his techs and causing minor damage. But all in all, team members come away calmer, surer, more familiar with procedure (and more engaged when asked to edit procedure), and with relationships with CERT and peers at
The Government (Score:1, Offtopic)
I'm going to go ahead and preempt all the non USians here...
What government is "The Government"? Eh? The government of Moldova? Argentina? Kajikisitkishtanz? Tatooine?
Why do you Imperialists pigs thing that only US people visit this site? How do you know that the government of Romulus doesn't have it's own Department of Homeland Security?
Ok, sorry, had to get that out.
Disclaimer, I'm not in the US. I live in Dixie.
Re: (Score:2)
Disclaimer, I'm not in the US. I live in Dixie.
Help me find that one on a map. Is that the place that got its ass kicked by the U.S. about 150 years ago? The place that has been totally pacified with NASCAR, pickled pigs feet, cheap alcohol and the SEC?
Re: (Score:2)
http://lmgtfy.com/?q=dixie [lmgtfy.com]
kicked by the U.S. about 150 years ago
See what I mean? Imperialists pigs. I'm still living under their oppressive regime.
Nascar... Never sat through a race.
Pickled Pigs feet... That stereo type may have worked 149 years ago.
SEC? Yeah, you got me, roll tide.
I do have a Gadsden flag on my SUV. This one was almost lost to history but Obama has renewed our interest in it.
Re: (Score:2)
Fine, pork rinds, then. :-)
Tide? TIDE?!
GO GATORS!
Re: (Score:2)
Gators? Isn't that one of the teams we rolled over last year? Oh yeah, I forgot... The one where Teebow cried. (http://www.youtube.com/watch?v=qBO1LHUqD_0)
I'll be watching for a replay (sans Teebow) this weekend in Mobile. Beautiful weather for the game this weekend. Think we may just move the big screen outside ;)
You're welcome to join us. We're in Mobile. We're planning on having a house full.
Re: (Score:2)
Thanks, and have fun. Honestly, I'm one of those people who believe college is for education, not sports. I'll also be in Chicago this weekend, listening to people try and explain how it isn't the Bears' weak opening schedule, they're just good. :-)
Re: (Score:2)
Tide 31, Gators 6
I bow before your superior college football program!
Congrats.
Re: (Score:2)
http://slashdot.org/faq/editorial.shtml#ed850 [slashdot.org]
Re: (Score:2)
See my UID, it's really small. I've been around here for a while. It was a joke to preempt the whiners.
As far as I'm concerned we can firewall off the rest of the world ;)
Ok, not really.
Re: (Score:2)
Translating from memory...
Eh, Crazy! Here in Argentina we don't have cyber attacks. (We almost have no internet)
Re: (Score:2)
Why do you Imperialists pigs [...]?
Why is it always "[whatever]ist pigs"? Incidentally, I don't think the US has actively sought to colonize existing small countries for a very long time (ostensibly Iraq/the entire Middle East doesn't count since it is supposed to eventually "stabilize" at which point it will be freed, or whatever).
Dynamic != Static? (Score:3, Interesting)
"This goes a bit beyond a paper narrative, including fake log data, drives that may contain fake malware, and fake event history, and is dynamic, meaning that it can change dependent on the actions the players take." which makes me wonder how effective this test would actually be."
Why shouldn't the test adapt to moves the player's make, do you think a hacker is going to keep running off the same script when he knows he's been noticed?
Some of the worst botnets move their Command and controls nodes around and the people behind them release new code to adapt to what security researchers are doing to stop them. Including DoSing the researchers.
What idiot thinks we can fight a changing landscape of threats with a static defense?
No Really I can't tell from the context if that's Taco or the submitter, but paper narrative tests that the author mentions basically are just there to make sure you know your job or have memorized your DR plan, but they don't make you think.
I'd be more worried if all facets of the scenario didn't get played out because nobody said "I image the hard drive" and so they skip that part of the test. In that case it would be up to the folks running the exercise to move the scenario along by saying someone at another agency imaged the drive, here is a copy, maybe you should look at it.
It's a lot like preparing for a D&D game and having the players ignore half the story/encounters you wrote up.
Re: (Score:2)
It's a lot like preparing for a D&D game and having the players ignore half the story/encounters you wrote up.
Oh, there's several ways around that, for sure:
"Despite all agreeing not to open the trapdoor to the dungeon, you have an uncontrollable urge and open it anyway."
"As you step away from my favorite trapdoor, you spy a giant, angry, immortal dragon heading your way. Care to reconsider that trapdoor?"
etc etc. I suspect the whole thing has been scripted out. Basically "high school musical" for nerdy govt MBAs, probably with less dancing and music. I hope.
Re: (Score:2)
I cast Magic Missile on the Sharepoint server!
Re: (Score:2)
I suspect you haven't ever taken part in a large scale simulation like this. I have. Short (and long) version: you're wrong.
Not that there's anything wrong with ensuring that the participants know their jobs and/or have memorized their disaster recovery plan.
Re: (Score:2)
Of Man's reach exceeding his grasp...
No big sims are multi-agency and have casts of thousands, even single agency drills can be enourmous and complicated. Just getting through the phone tree for a single angency is more complicated than running a "I call Iron Mountain to locate my backups" test or restoring the last good backup for real on one of the test boxes.
But for the submitter who fails to see the value of a dynamic exercise, should I talk to him about planning a mini-D-Day invasion of Normandy? Becau
Cyber Attack = ? (Score:1)
More Info (Score:2)
Dynamic as is in... (Score:1)
{
player.loseAnyway();
scaryPressRelease(REALLY_SCARY);
Legislation* cyberRegulation = new Legislation;
cyberRegulation->ramThroughCongress();
Bureau bigBrother = cyberRegulation->biggerGovernment()
}
No longer the largest simulated exercise (Score:1)
Aw, dating. (Score:1)
The World's Largest Simulated Cyber Attack is really growing up.
Don't do anything that makes you feel uncomfortable.
Frankenstein Complex (Score:1)
Hmmm.... So exactly when does this stop being a simulation? :P
Wouldn't a better test be something like... (Score:1)
"it can change dependent on the actions the player (Score:2)
Am I the only one hoping that Obama exercises his "internet kill switch" option?
What happens then?
"Good job Mr. President. Now our game is over. Way to ruin it for EVERYONE!"