Lolita C. Baldor
US wants privacy in new cyber security system
WASHINGTON — The Obama administration is moving cautiously on a new pilot program that would both detect and stop cyber attacks against government computers, while trying to ensure citizen privacy protections.
The pilot program, known as Einstein 3, was supposed to launch in February. But the Department of Homeland Security is still pulling the plan together, according to senior administration officials.
Einstein 3 has triggered debate and privacy concerns because the program will use National Security Agency technology, which is already being employed on military networks.
Any involvement of the NSA — the agency oversees electronic intelligence-gathering — in protecting domestic computer networks worries privacy and civil liberties groups who oppose giving such control to U.S. spy agencies.
Officials, who spoke on condition of anonymity because the program is still being finalized, said that while the technology will come from the NSA, the program will be managed and run by the Department of Homeland Security. The monitoring would be limited to government systems and any Internet traffic moving in and out of them.
The latest developments in the Einstein 3 program were first reported Thursday on The Washington Post’s Web site.
“The NSA will provide technical assistance,” Homeland Security Secretary Janet Napolitano told reporters. “We absolutely intend to use the technical resources, the substantial ones that NSA has.”
Einstein 1, which is currently in use by DHS, is an automated program designed to detect intrusions into government networks, and Einstein 2, which is now being put in place, is a more advanced system for detection. It is being used now by about five of the higher risk government agencies, one senior official said.
Einstein 3 would be designed to not only detect intrusions, but to stop them — preventing any malicious computer codes from getting into government networks and stopping any data theft from those systems. The key, said officials, is that the focus of the monitoring and prevention program is not the content of e-mails, but any codes attached to e-mails that could infect the system or steal information.
Ari Schwartz, a vice president of the Center for Democracy and Technology, said Thursday that privacy advocates want to ensure that as the government begins to more aggressively protect its computer systems, it follows the law, and does not look into private systems.
“There are a number of concerns that come with this process, the main one being how do you go about protecting the system in a way that insures you’re not monitoring private systems,” said Schwartz. “I don’t have a full answer to that question. But the president made that pledge. That makes me more comfortable that it won’t happen.”
The planned deployment of the new Einstein 3 program was noted in the administration’s recently released cyber security review. The 60-day review said the government would continue to consult with privacy and civil liberties groups as the program moves forward.
Obama released the review saying that cyber threats are one of the most serious economic and national security challenges faced by the nation. And he said he will name a new cyber coordinator for the federal government.
On the Net: www.whitehouse.gov/assets/documents/Cyberspace(underscore)Policy(underscore)Review(underscore)final.pdf
Related News
Homeland Security says it will be 'competitive' in hiring up to 1,000 cyber security expertsOctober 1st, 2009 Homeland Security to hire up to 1K cyber expertsWASHINGTON — The Obama administration has given a green light to the Homeland Security Department to be more competitive and choosey as it hires up to 1,000 new cyber experts over the next three years, the first major personnel move to fulfill its vow to bolster security of the nation's computer networks. The announcement follows a wave of cyber attacks on federal agencies, including a July assault that knocked government Web sites off the Internet and earlier intrusions into the country's electrical grid.
Feds give Homeland Security OK to retain up to 1,000 new cyber security expertsOctober 1st, 2009 Homeland Security to hire cyber expertsWASHINGTON — The Obama administration has given a green light to the Department of Homeland Security to hire up to 1,000 new cyber experts over the next three years, the first major personnel move to fulfill its vow to bolster security of the nation's computer networks. The announcement follows a wave of cyber attacks on federal agencies, including a July assault that knocked government Web sites off the Internet and earlier intrusions into the country's electrical grid.
Cyber criminals increasingly target small businesses; Feds beef up private cooperationSeptember 14th, 2009 Cyber criminals targeting small businessesWASHINGTON — Cyber criminals are increasingly targeting small and medium-sized businesses that don't have the resources to keep updating their computer security, according to federal authorities. Many of the attacks are being waged by organized cyber groups that are based abroad, and they are able to steal not only credit card numbers, but personal information — including Social Security numbers — of the card holders, said Michael Merritt, assistant director of the U.S.
Is this cyber war? Response possibilities limited _ and nobody's talking about bombsJuly 10th, 2009 Is this cyber war? Possible U.S responses limitedWASHINGTON — A lot of people are saying this is cyber war. But if the Internet attack on U.S.
Experts work to untangle US, South Korea cyber attack, disagree over extent of Pyongyang tiesJuly 10th, 2009 Experts work to untangle US, Korea cyber attackWASHINGTON — U.S. authorities trying to unravel the widespread cyber attacks against government Web sites in the United States and South Korea this week are facing a lengthy, complex investigation that may never identify a culprit, at least not one they would be willing to reveal.
US suspects North Korea was behind cyber attacksJuly 8th, 2009 WASHINGTON - The US believes North Korea was responsible for a massive cyber attack on government and other websites during the past week, Fox News reported Wednesday. An unnamed US defence official told Fox the attack targeted dozens of websites, including the ones for the US Defence Department and the Department of State.
Report: New radiation detection machines government's been developing not worth the moneyJune 24th, 2009 Study: New radiation detectors not worth the costWASHINGTON — The government shouldn't buy more of the new radiation detection machines it's been developing to look for smuggled nuclear materials at ports, a report from the National Research Council says. The new machines are only marginally better at detecting hidden nuclear material than monitors already at U.S.
Gates approves Pentagon's creation of new cyber command, asks for plans by fallJune 23rd, 2009 Gates approves creation of new cyber commandWASHINGTON — Defense Secretary Robert Gates formally ordered the creation Tuesday of a new military cyber command that will coordinate the Pentagon's efforts to defend its networks and conduct cyberwarfare. A three-page memo signed by Gates orders U.S.
Cyber security agency ties up with British firmJune 23rd, 2009 NEW DELHI - The government agency in charge of cyber security Tuesday signed an agreement with British IT and communication solutions provider BT for enhancing computer security and technology sharing. "This MoU (memorandum of understanding) will help in capacity development, particularly in training our manpower for implementing the best security practices," said Gulshan Rai, director of the Indian Computer Emergency Response Team (CERT-In).
Homeland secretary kills Bush administration's domestic satellite programJune 23rd, 2009 Homeland security kills domestic satellite programWASHINGTON — Homeland Security Secretary Janet Napolitano killed a program begun by the Bush administration that would use U.S. spy satellites for domestic security and law enforcement.
Officials debate how the US should retaliate against cyber criminalsJune 3rd, 2009 US grapples with how to retaliate in cyber attacksWASHINGTON — In the murky world of computer espionage, the U.S. faces hard choices on how to retaliate when government or privately owned networks come under cyber attack, senior military and intelligence officials said Tuesday.
Citing Mumbai, Obama creates top job for cyber security (Lead)May 30th, 2009 WASHINGTON - Citing the use of GPS and internet phones in the Mumbai terror attack as "the future face of war", President Barack Obama has created a cyber security czar to secure America's digital infrastructure. "Our technological advantage is a key to America's military dominance.
Obama's Day: Obama to address cyber security, attend FEMA hurricane preparedness meetingMay 29th, 2009 Cyber security, FEMA meeting on Obama's agendaWASHINGTON — President Barack Obama is to address a 21st century defense threat — protecting the nation against a cyber attack. Obama is scheduled to deliver remarks Friday morning on how the government plans to better secure the nation's computer infrastructure.
Sources say Pentagon planning special command to focus on protecting against cyber attacksApril 22nd, 2009 Sources: Pentagon planning new cyber commandWASHINGTON — The Pentagon is planning to create a new military command to focus on cyberspace and protect its computer networks from cyber attacks, U.S. officials said Wednesday.
Cyber hackers breached Lockheed Martin fighter program, but no secret data compromisedApril 21st, 2009 Cyber hackers breached jet fighter programWASHINGTON — Cyber hackers nearly two years ago breached a high-tech jet fighter program developed for the Pentagon by Lockheed Martin Corp., but classified information was not compromised, a senior defense official said Tuesday. No details about the attacks were provided.