Feds' math is fuzzy on computer crime

Be the first to comment | 1I like it!
April 25, 2001, 08:28 AM —  Computerworld — 

The federal government can report in exacting detail the number of bank robberies committed in any given year. But when it comes to computer crimes against government agencies, it's close to clueless.

Government officials estimate that only 20% of computer crime incidents are being reported because the agencies either don't have the technical sophistication to discover the crimes or they want to keep bad news quiet. It's for those reasons that the 155 root compromises to federal computers reported last year likely represent a fraction of the actual number.

"It's a serious issue," said Jim Craft, information security officer at the U.S. Agency for International Development and head of the CIO Council's best practices subcommittee on security.

Lack of Resources, Teamwork

Craft said senior managers fear the unwelcome attention that computer crime reports bring and in many cases lack the money and tools to detect or fight computer crime. But there's also an ingrained reluctance for agencies to work together, he said.

"We don't have a culture of collaboration in the federal government," said Craft. "We can't even get people sometimes to share good news."

For the first three months of this year, the government's central crime data repository, the Federal Computer Incident Response Center (FedCIRC), recorded 55 root compromises at civilian nondefense federal agencies -- putting it on pace to exceed last year's total. A root compromise occurs when an intruder gains systems administration privileges, such as the ability to copy documents, alter data or plant malicious code.

Still, it's impossible to gauge just what the first-quarter increase means, say experts.

"We don't know whether we're seeing a change in the rate of reporting, a change in the rate of detection or a change in the rate of penetration," said Michel E. Kabay, a computer security expert at consulting firm Atomic Tangerine Inc. in Menlo Park, Calif., who has done research on computer crime statistics.

For its part, the Bush administration has begun to take steps to improve compliance by federal agencies in reporting and responding to security breaches, including recommending a 38% boost in funding, from $8 million to $11 million, for FedCIRC. Agencies are already required by law to report to FedCIRC as a result of the Government Security Reform Act approved last year.

But Sallie McDonald, an assistant commissioner at the General Services Administration, which runs FedCIRC, said she recognizes that it takes time to gain agency cooperation.

Nonetheless, "I would hope that we don't have to go through a tremendous [data] loss in order to start complying with the things that we should be doing," she said.






Believe It or Not

Federal officials believe that root compromises of government systems are on the rise. One reason for this is the increase in available tools used by intruders. But accurate statistics on break-ins aren’t available.














The Law: Federal agencies are required to report computer break-ins.

The Reality: For the same reasons as in the private sector, many agencies don’t report break-ins. Some don’t know they have been hacked. Others fear negative attention.

The Plan: The Bush administration is boosting security funding and requiring agencies to give the White House their security statistics as part of their budget requests.

What’s at Risk: With few exceptions, federal officials won’t reveal which agencies are being hacked and what’s going out the door.

» posted by ITworld staff

Computerworld

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Free books

Essential JavaFX
Get started building rich Web apps quickly with an introduction to the power of JavaFX key features -- scene node graphs, nodes as components, the coordinate system, layout options, colors and gradients, custom classes with inheritance, animation, binding, and event handlers.Enter now!

The Nomadic Developer
Consulting can be hugely rewarding, but it's easy to fail if you are unprepared. To succeed, you need a mentor who knows the lay of the land. Aaron Erickson is your mentor, and this is your guidebook. Enter now!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace