R E L A T E D   C O N T E N T
ADVERTISEMENT

How vulnerable are we to a cyber attack?

Is Armageddon just around the corner, or is 'cyber-terrorism' over-hyped? Emma Nash reports.

Emma Nash, Computing 15 Apr 2004
ADVERTISEMENT

The Eastern seaboard was thrown into panic last August when it was hit by a massive power cut which caused widespread disruption. Traffic lights failed, trains stopped running, people were trapped in lifts and business ground to a halt.

Mass panic was caused by the initial belief that the power failure was the result of a terrorist attack.

This was discovered not to be the case, but when the possible implications were combined with memories of the 9/11 attacks on Washington and New York, it's understandable why the possibility of 'cyber-terrorism' entered people's minds.

The term has been thrown around for some time now, with varying degrees of associated doom and gloom, but its definition is far from uniform.

"Cyber attacks target the computer or telecoms networks of critical infrastructures, such as power systems, traffic control systems or financial systems," is the official US government definition.

"Cyber attacks target IT in three different ways. First is a direct attack against an information system 'through the wires' alone [i.e. hacking].

"Second, the attack can be a physical assault against a critical IT element. Third, the attack can be from the inside as a result of compromising a trusted party with access to the system."

The White House is treating the threat seriously, advising citizens to be prepared to do without services they depend on that could be disrupted, such as electricity, telephones, natural gas, fuel, tills, cash machines and internet transactions.

But the White House definition is only one of many. And that's causing confusion, according to Symantec Security Response senior research fellow Sarah Gordon.

"If you ask 10 people what cyber-terrorism is, you will receive at least nine different answers," she explained. "When those 10 people are computer security experts, the discrepancy moves from being comedic to rather worrisome."

The UK government has set up the National Infrastructure Security Co-ordination Centre (NISCC), a cross-government and industry body intended to protect the "critical national infrastructure" from electronic attack. But it is slightly less alarmist than its US counterpart about the threats posed.

"In terms of the current threat, we consider the chances of a serious denial-of-service attack to be low. That's been the case since the NISCC has been in existence," stated a Home Office spokesman.

If you believe the doom-mongers, electronic Armageddon is just around the corner. But those in the know are less convinced about the threat.

"The former White House advisor Richard Clarke said that cyber-terrorism attacks are very, very bad and we should prepare for them," said Forrester Research vice president and research director Steve Hunt.

"It's not very, very possible because we don't see any indications that there is a probability that they will occur."

Fellow analyst Gartner holds a similar view. "There is scant evidence of true cyber-terrorism, which I would define as using networks and computers to cause physical harm, kill people, and cause a loss of confidence in institutions such as banks," maintained Victor Wheatman, managing vice president at Gartner.

"Terrorists know that bombing and blowing up buildings and killing people is more effective than even shutting down the internet would be, if one could actually do that for more than a few hours.

"The internet was designed to survive nuclear attack. If your home banking system or amazon.com went down it might be an inconvenience, but I'm not going to be quaking in my boots in fear."

Along with the hype has come the message that organisations need to make special efforts to defend themselves.

Malcolm Hutty, regulation officer at the London Internet Exchange (Linx), advises businesses to remain vigilant and third parties to be more proactive. "There are things that the major ISPs and networks can do," he said.

"If people are concerned about cyber-terrorism there is something they can do about it: make sure they're not part of the problem.

"Make sure machines are updated with patches and antivirus software and follow best practice security."

Forrester's Hunt believes that best practice activities will suffice. "Companies can prepare without doing anything special. Do security responsibly and effectively, and you will be protected," he said.

At worst, cyber-terrorism would be inconvenient, according to the experts. In fact, Gartner's Wheatman believes that too much hype could be dangerous.

"I would argue that those who hype cyber-terrorism do more to create fear and a loss of confidence than any actual cyber-terrorist has to date," he said.

"Yes, there is 'hactivism', and worms and viruses are being pushed out by some with a political agenda, but I would not associate the word 'terror' with these activities, vexing as they may be."

See also:

SecuritySecurity has moved from the IT department and into the boardroom  22 Apr 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004
Time to take security to the board  24 Mar 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S
M A R K E T P L A C E
Learn how to break software security in a two day training course aimed at software testers and software managers. Courses are being held throughout the UK in 2006.
V-SOL: Supply Premium Vehicle Tracking Systems to MOD, TRansport for LONDON and EDF-CHANNEL RELEASE!
Get your free demo of Numara Track-It! 8 - the leading help desk solution for IT related issues.
V-SOL: Supply Premium Vehicle Tracking Systems to MOD, TRansport for LONDON and EDF-CHANNEL RELEASE!
Apply ITIL best practices at your service desk while eliminating integration cost. Learn more here.
Have your product or service listed here >   
Sponsored links
F E A T U R E D   J O B S
TWICKENHAM, United Kingdom | Rugby Football Union
RUGBYFIRST PROJECT MANAGER, TWICKENHAM, c. £40,000 per annum   12 month fixed term RugbyFirst, the most modern administration system in British sport, is a game-wide internet-based tool to help run rugby at all levels, with the ... more >
West Midlands, Warwickshire, United Kingdom | Latham
System Tester/Test Analyst £27K-£32K + bonus, flexitime, 35 hour week, South Warwickshire, West Midlands. System Tester, Test Analyst, Systems Tester. Large financial services company looking for proven Testers and Test Analysts. Do you have at least ... more >
United Kingdom | MI5 Security Service
Network Analysts Working for MI5 you will use your expertise to protect the UK from terrorism, espionage and other threats to national security. You'll be joining a team that provides essential technical analysis and capability ... more >
Newcastle, Tyne And Wear, United Kingdom | EDS
About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve their business performance. EDS' core portfolio comprises information-technology and business process outsourcing services, as well as information-technology ... more >
More job opportunities