Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

U.S. gets new cyberterrorism security center

Its goal is to better protect critical private industries

April 21, 2005 12:00 PM ET

Computerworld - PHILADELPHIA -- A new private-sector cyberterrorism security center that aims to watch over much of the nation's critical business infrastructure with its own real-time cyberthreat-detection network opened here today at the University of Pennsylvania.
The Cyber Incident Detection Data Analysis Center (CIDDAC) was unveiled as a real-time defense against cybercrime and cyberterrorism for key businesses in the U.S. that could be targeted by terrorists.
Charles "Buck" Fleming, executive director of CIDDAC, said the organization is believed to be the first private, nonprofit group to set up a cybercrime-detection network outside of the government's own efforts to watch over critical business operations. The group's concern, he said, is that without constant monitoring, critical U.S. industries such as banking, transportation, energy, 911 services and water supply systems could be disrupted by terrorists or criminals -- with disastrous results for the country and the U.S. economy.
While government agencies such as the FBI and the Department of Homeland Security already get reports of cybercrime and cyberterrorism, the agencies aren't always able to respond to threats immediately because of red tape. And companies that are victims aren't always happy to share their information with the government, Fleming said.
"Eighty-five percent of all the [nation's] data is in the private sector, so we realized this has to be a private sector operation," he said. "Companies don't want the FBI looking at their information, even if they're not doing something wrong."
Fleming added, "We realized that coming down the road there are major potential problems that are not being addressed right now."
Under a pilot project, CIDDAC is offering its intrusion-detection services to critical industries using specially built Remote Cyber Attack Detection Sensor (RCADS) appliances that will be installed by the group outside of a business' corporate network, he said. The RCADS will be able to instantaneously and automatically report any attacks to the CIDDAC center, where the intrusion data can immediately be evaluated and quickly passed on to law enforcement agencies. The sensors are not connected to any actual corporate production systems but appear to intruders as just another machine on the network.
Law enforcement officials will be able to use the intrusion data to compile attack signatures, which provide government investigators with data so they can more quickly identify, locate and neutralize cyberthreats, according to the group.
John Chesson, a special agent at the FBI in Philadelphia, said the RCADS are essentially "hardened honeypots" that look like they are part of the network an intruder is trying to enter. When the RCADS are attacked, CIDDAC



Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Mitigating Litigation Risk with Email Management Tools
Does your company have an email retention policy that protects it when litigation occurs? IDC discusses effective email retention policies and the role...  

Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....

Protecting Content During Business Disruption: Are You Covered?
Learn how ECM is helping Tulane University and the 13th Judicial Circuit Court implement disaster readiness programs....  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

Beyond PCI Checklists: Securing Cardholder Data with Tripwire's Enhanced File Integrity Monitoring
How do organizations pass their PCI DSS audits yet still suffer security breaches? Paying attention to PCI DSS checklists only partially secures the...  

Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...

Authentication as a Service by Forrester Research
Authentication-as-a-Service: understand the benefits of two factor authentication and the best ways to implement it....  

Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...

Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...  

Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...