Wednesday, 11 September 2013

Detica armours critical infrastructure against military hack attacks

Tilbury power station - photo RWE npower
BAE Systems Detica has unveiled its IndustrialProtect cyber-defence tool, promising that it will protect critical infrastructure areas from the latest wave of targeted attacks.
Detica lists IndustrialProtect as being tailor-made to protect the industrial control systems of critical infrastructure organisations, such as power plants, oil refineries and automated manufacturing plants, from hackers. IndustrialProtect is different to most protection tools as it integrates into the systems at a component level, being physically built into the hardware.
Detica claims the hardware integration makes IndustrialProtect significantly more effective against sophisticated attacks, offering IT managers a host of advanced powers. These include the ability to segment parts of the network without breaking critical business processes, and the power to block unauthorised systems from exchanging information.
The tool will also offer enhanced monitoring powers to IT administrators, allowing them to check that the integrity of information is preserved from source to destination. It also gives wider transparency of other systems connecting to the industrial controls.
Using these capabilities Detica claims IndustrialProtect is able to verify the identity of the individual or system that is sending information. It can also confirm the information received has not been tampered with while in transit, ensuring any attempt at cyber sabotage is blocked.
David Garfield, managing director of cyber security at Detica, said businesses involved in critical infrastructure areas need upgraded cyber defences to ward off the recent influx of sophisticated, targeted attacks active in the wild.
"National Critical Infrastructure organisations are increasingly concerned about securing their business critical operations. The larger and more diverse the organisation, the greater the number of network vulnerabilities for cyber attackers to exploit. IndustrialProtect addresses key areas where traditional approaches are proving ineffective, simultaneously enabling efficient business processes and protecting against the modern cyber threat," he said.
"This is the first time this type of solution has been available for organisations in the critical national infrastructure. It provides a means to enable information flows that greatly increase business efficiency and operational effectiveness while protecting critical operational networks from attack."
Attacks on critical infrastructure have been a growing concern within the security community. The concerns reached boiling point in 2010 when the Stuxnet worm was discovered attempting to physically sabotage Iranian nuclear power plants. Since then numerous government agencies have warned about the inevitable emergence of further cyber-sabotage tools. Most recently the US Department of Defense issued a public report warning that Chinese hackers have the skills and tools to take down critical infrastructure.

GCHQ begins search for next Alan Turing with code-tracking ‘Can You Find it' race

detective-footprints
The UK GCHQ has launched a Can You Find It challenge designed to help the government agency find and recruit the next generation of cyber security code experts.
The initiative is set to launch on Wednesday on the official Can You Find It website. The race will task participants to crack a series of cryptic codes to find and follow clues littered around the internet to find "the ultimate final answer".
The challenge is open to anyone and offers a variety of prizes to those who solve the riddle. These include the chance to enter a prize draw for a Google Nexus 7 or Raspberry Pi and, for very skilled participants, a potential job offer from a security agency with a salary between £26,000 and £60,000.
Can You Find It is part of the UK's wider cyber security strategy and follows on from 2012's Can You Crack It campaign. The Can You Crack It campaign ran throughout 2012 and attracted over 95 million hits to its website from over 3.2 million unique users. The campaign also resulted in 170 participants being considered for roles within intelligence agencies.
GCHQ's head of resourcing, Jane Jones, said initiatives like Can You Find it and Can You Crack it are essential steps in the UK's ongoing bid to recruit the next generation of security professionals.
"The twenty-first century is confronting us with online threats that are difficult and dangerous, so we want employees who have evolved with the ever-changing digital world and therefore have the right skills to combat these challenges. It's a puzzle but it's also a serious test – the jobs on offer here are vital to protecting national security," she said.
Recruiting skilled cyber professionals has been an ongoing goal of the UK government since it launched its cyber strategy in 2011. Despite the success of cyber strategy initiatives, many private and public sector bodies have warned that the UK is still suffering a major cyber skills shortage. The UK National Audit Office (NAO) issued a report warning despite the government's efforts, the skills gap will last a further 20 years and cost the nation £27bn per annum.