Audit: DHS Cyber Defense Fails to Detect 94 Percent of Hacks

Tags: ,

By Steve King, LifeZette:

Federal agencies remain extremely vulnerable cyber targets two years after OPM breach

According to a sanitized version of a secret federal audit, the firewalls operated by the Department of Homeland Security, meant to detect and prevent nation-state attacks, are completely ineffective. The audit found the federal government’s primary perimeter defense system, known as EINSTEIN, depends only on known patterns of attack (signature detection) to spot suspicious traffic and fails to detect 94 percent of commonly known vulnerabilities — or even check web traffic for malicious content.

In addition, the audit discovered that the prevention feature of the system is only deployed at five of the 23 major nondefense agencies, one of which was the Office of Personnel Management.

The auditors’ findings included the conclusion the $6 billion DHS system does not combat hackers, nor “should it be relied on to provide effective cybersecurity-related support to federal agencies.” They went on to say that “The overall intent of the system was to protect against nation-state level threat actors,” yet EINSTEIN completely missed these so-called advanced persistent threats, which are commonly used by nation-state actors.

EINSTEIN “did not possess intrusion-detection signatures that fully addressed all the advanced persistent threats we reviewed,” the authors of the audit said.

Even though the Department of Homeland Security sponsors the standard national database of security flaws (CVEs) maintained by the National Institute of Standards and Technology, EINSTEIN does not sync with that database and consequently failed to flag more than six percent of the 489 vulnerabilities identified. That means that even if the CIA were not hoarding these known vulnerabilities in Adobe Acrobat, Flash, Internet Explorer, Java and Microsoft Office, our own national cyber-defense system failed to detect 94 percent of their exploits anyway.

The zero-day attack that blew through EINSTEIN’s defenses at the Office of Personnel Management in 2015 is a classic example of the type of attack that our current federal government defenses cannot handle. News flash: Zero-day attacks are the only attacks that the private sector is concerned with today. All of the “signature-based” attacks are already handled by various cybersecurity technologies. Someone at DHS might want to look outside the confines of the Washington swamp.

Most of today’s advanced cyber-attacks hide in network flows and cannot be seen or detected by EINSTEIN because the system instead relies on manual intervention by way of adding signatures after a malicious attempt is unearthed. This cave-dwelling approach guarantees that zero-day attacks by definition will always be successful against our national cyber defense system.

To make matters worse, the Obama administration’s vaunted information sharing-initiatives are now found to be essentially worthless, according to GAO officials. The IT infrastructures at each agency differ, and EINSTEIN apparently must be tailored to each separate environment. One complaint held that EINSTEIN would disrupt their agency’s email system.

DHS’s information-sharing initiatives have met with frequent disagreements among agencies about the number of notifications sent and received and their usefulness,” according to the GAO auditors.

The agencies claim they received only a quarter of the notifications Homeland Security said it had sent in the audited period, and the ones that did reach them served no purpose, according to the audit. Of the alerts that were communicated successfully, almost half were too slow, useless, false alarms, or unrelated to intrusion detection.

Meanwhile, as seasoned Washington observers might have guessed, the DHS has created a variety of metrics related to EINSTEIN, but “none provide insight into the value derived from the functions of the system,” the auditors said.

I don’t have to tell anyone reading this that if only a tiny bit of this incompetence occurred in the private sector, even at non-profits, heads would roll. It may be understandable if we shrugged if a government agency screwed up dealing with say, climate change, but are we really going to ignore this level of dangerous disregard for our national defense? What if our military started to behave like the troops in Stripes or Down Periscope? Would that be funny?

This is not funny. Heads should roll. And, this President needs to quickly understand that the vast government under his charge is protected by antiquated technology and failed detection and prevention techniques, surrounded by bureaucrats who make a living covering their own interests while the rest of ours are hung out as targets.

Homeland Security now says they weren’t required to link up the signatures with the vulnerability database but that they acknowledge the deficiency and plan to address it soon in the future, according to the audit response. Soon, but in the future. Sometime. Later. Maybe. Because, you know. They weren’t required.

Read related content at LifeZette.

U.S. Intel May Have Access to Half of Networked Devices 

Government Can’t Tackle New-Age Cybersecurity Alone

  • RSS WND

    • For WND, it's 'Judea and Samaria' – not 'West Bank'
      Under the leadership of its founders Joseph and Elizabeth Farah, WND has committed to adhering to the "Biblical Heartland Resolution" passed recently by the National Religious Broadcasters convention, whereby participants pledge to use the terms "Judea and Samaria" when referring to the region in eastern central Israel, rather than the ubiquitous but misleading term "West… […]
    • Anti-Zionists occupy condemned university building, vandalize it with antisemitic graffiti
      (JERUSALEM WEEKLY) – Two blocks south of U.C. Berkeley’s campus, anti-Zionist protesters took over a vacant building owned by the university on Wednesday morning, vandalizing it with swastikas and antisemitic language. “Zionism is Nazism” was spray-painted in black letters on several walls inside the condemned building, which was destroyed in a 2022 fire. Several dozen… […]
    • Hotel abruptly cancels pro-Israel event over 'credible threats'
      (THE BLAZE) – A Nashville hotel is being accused of religious discrimination after abruptly canceling a pro-Israel event. The Israel Summit — a "gathering of pro-Israel supporters who unconditionally support Israel’s right to be sovereign in the entirety of the land of Israel, including Jerusalem, Judea and Samaria, and the Gaza Strip," according to the… […]
    • Aid flows into Gaza over massive U.S. pier
      (NBC NEWS) – Trucks carrying humanitarian aid began moving ashore into Gaza Friday using a temporary pier built by the United States, delivering desperately needed supplies to the besieged Palestinian enclave. The floating dock is part of a makeshift effort to stave off a possible famine in Gaza, where Israel’s military assault has shut off… […]
    • Former Trump attorney, ex-fed prosecutor duke it out over whether Michael Cohen is 'worst witness ever'
      Jason Cohen Daily Caller News Foundation Criminal defense attorney Bill Brennan, who previously represented former President Donald Trump, and former federal prosecutor Shan Wu on Thursday sparred over whether Michael Cohen is a bad witness. Cohen faced cross-examination again on Thursday, with even CNN pundits questioning whether the jury will buy the admitted liar’s testimony… […]
    • Biden policy is reason illegal immigrant accused of murdering teen was out free
      Jason Hopkins Daily Caller News Foundation Federal immigration authorities cited a Department of Homeland Security (DHS) policy directive when explaining their handling of an illegal immigrant who is now charged with the murder of a teenager. Antonio Antonio-Rodas, an illegal immigrant from Guatemala, was arrested and charged with murder last week for a fatal car… […]
    • Top Fauci aide allegedly learned to make 'smoking gun' emails 'disappear'
      Jason Cohen Daily Caller News Foundation National Institutes of Health (NIH) Principal Deputy Director Lawrence Tabak testified on Thursday that a former aide to Dr. Anthony Fauci allegedly violated the agency’s public records policy by disposing of certain emails. Fauci’s senior advisor at the NIH Dr. David Morens allegedly intentionally obstructed the House Select Subcommittee… […]
    • Rudy Giuliani's birthday bash ends in chaos when he's served papers for 'fake electors case'
      (NEW YORK POST) – Rudy Giuliani got more than cake and presents for his 80th birthday bash – he was also served justice. The former New York City mayor was tripping the light fantastic with pals in Palm Springs Friday night when he was intercepted outside the party at the home of top GOP consultant… […]
    • Inflation, not a bug but a feature, of government policies
      [Editor's note: This story originally was published by Real Clear Wire.] By J. Kennerly Davis Real Clear Wire May brings more bad economic news for hard-pressed American households. “Transitory” inflation remains firmly entrenched at rates equal to or higher than those reported at the start of 2024. The Labor Department reports this week that the Consumer… […]
    • State sued for embedding racism in its 'social work' board
      The state of Minnesota has been sued for embedding a racist demand in the qualifications for members of its "Board of Social Work." That group issues licenses to qualified social workers and then takes disciplinary action against those who violate its standards. It has 15 members appointed by the governor, including five who are vetted… […]
  • Enter My WorldView