пятница, 2 марта 2012 г.

TRAINING ON THE Cyber Security Frontlines

Organizations need more well-trained experts to defend against cyber threats.

Cyber security continues to be on the top of the agenda for CEOs and high-ranking government officials because they know that online security can no longer be partially addressed or uncomfortably ignored. However, according to a Booz Allen Hamilton survey, the nation's cyber defense is seriously challenged by shortages of highly skilled cyber-security experts.

The report notes that 40 percent of chief information officers, chief information security officers, and IT managers are unsatisfied with the quality of cyber-security job applicants, and according to SANS Institute Research Director Alan Palier, more than 30,000 specialists are needed today. However, he claims that "only about 1 ,000 to 2,000 have the necessary skills" to combat the numerous real-life scenarios happening in today's organizations.

A network administrator at a Fortune 100 company is tasked by her superior to order a specific router required for a time- and budget-sensitive systems upgrade. She searches the Internet for the most cost-effective solution and finds it at a fraction of its list price on several sites, guaranteeing delivery and warrantees for the life of the product.

She places her order, and the box arrives, with name, serial number, and installation directions intact. The upgrade could not have gone more smoothly. But unbeknownst to her and others responsible for the network's integrity, she has just installed an innocent-looking piece of hardware, embedded with stealth malware that will provide access to a rogue invader to virtually any file or electronic communication on her company's network.

Totally unaware, she purchased it from an illegal, but legitimate-looking website, from a company that manufactures and sells equipment illegally, branded under well-known industry names. If she had called the real company's customer service, she might have discovered her mistake.

Difficult and expensive talent search

While cyber security is emerging as a high-demand career, the problem, SAICs Vice President for Cyber Programs Robert Giesler discovered, is that finding qualified people today is difficult and expensive. "U.S. graduation rates for four-year degrees are declining, and of those graduating, many are not in a science, math, or engineering program. Of those in technical programs, only a third qualify for top-secret clearance; which makes for a small pool of applicants for the federal market," Giesler laments. SAICs need for cyber personnel is aimed at providing cyber-security specialists under contract to the federal government and, increasingly, to the industry.

The U.S. military also is running into the same problem, prompting Giesler to propose that SAIC make a strategic decision to educate from within, rather than struggle to fill the company's cyber-security slots with experts from outside the firm. Mounting an internal campaign to raise the technical level of highly motivated employees, SAIC partnered with NYU -Polytechnic Institute to send more than 600 staff through the school's prestigious online cybersecurity master's program over the next several years.

New hires versus promoting from within

Matthew Bidwell at University of Pennsylvania's Wharton School of Business substantiates SAICs decision. "Despite the fact that external hires underperformed those who are promoted, they were also paid around 15 percent more," Bidwell explains, based on his recent research. "In part, this difference reflected the hiring of more experienced and educated workers than those who were promoted."

"The less that you know about a potential employee, the stronger the curriculum vitae you are likely to demand," Bidwell acknowledges. "The difference between hires and promotes likely reflects new hires concerns about the job. They know less about what they are getting themselves into, as evidenced by their higher rates of voluntary and involuntary turnover.

"Either way," Bidwell concludes, "compensation of external hires is substantially more than for workers promoted from within the firm. And that gap declines very slowly. There is also evidence that the increased pay of new hires ultimately leads firms to raise the pay of all workers in the group, further raising costs to the firm."

Bidwell's research also showed that performance evaluations for external hires were lower than those promoted into the same jobs for up to three years after they started the job, even taking supervisor bias into account.

By recognizing resource constraints and the timeframe in which they need to bring employees up to speed, Giesler found that by educating existing employees, the company would alleviate the problems of finding top-secret-eligible candidates to emerge as strong cyber cops at a digestible cost.

SAIC has introduced a two-tiered approach. Those with the right skills are enrolled in top-ranked graduate programs. For others, the company engages commercial vendors such as the computer-security training company SANS Institute with classes for personnel in niche areas. For the near and long term, SAICs objective - and equally the goal at other organizations whose business depends on protecting client networks - is to build an army of cyber warriors.

Negligent employees

Most of us are unaware that the biggest and most pervasive attacks are caused by negligent employees clicking on invasive files embedded in messages from beyond company firewalls. Despite strenuous efforts by most companies to alert personnel to email and Internet behavior that opens up firms to invasion, employees continue to do foolish things.

Mobile devices make networks particularly vulnerable. "As more access is given to the end user by means of mobile computing, cyber-crime prevention has to be a top priority. The corporate landscape requiring protection is multiplying at very quick pace," cautions Marc Sachs, vice president of National Security Policy at Verizon.

Sachs has also seen a significant increase in embedded malware within hardware equipment purchased by U.S. companies. "Many companies just don't understand how vulnerable they are in areas they never would expect there to be flaws, such as hardware purchasing," says Sachs. Inadvertent mistakes are better avoided when consistent and specific training is given to non-IT staff regarding the dangers their everyday activity can incur.

Online learning as global bonding

A major global financial institution also has made the strategic decision to educate its worldwide IT global workforce with graduate degrees to ensure protection against threats. "We decided to enroll key employees in NVTJ-PoIy 's cyber-security' graduate program because of the global nature of cyber within our firm," remarks the chief information security officer. "We see this program as a bonding experience among global executives - one that will connect them through online collaboration long after they've earned their degrees."

NYU-Poly's cyber program is delivered online, allowing global companies to enroll its worldwide security staff without disrupting work and family responsibilities. Professor Nasir Memon, head of NYU-Poly's security program, is alarmed by the increasing sophistication of attacks as well as the speed at which they occur.

"It is not uncommon for large organizations to receive thousands of attacks each day," says Memon. "Our program is aimed, not only at dealing with attacks as they occur, but equally with how a cyber specialist can be proactive in this invisible warfare."

SAIC and other company employees enrolled in NYU-Poly's cyber courses enter the school's virtual lab, where they safely simulate attacks and defenses in an exact replica, mirroring an actual network. At the conclusion of their rigorous online coursework, they earn full master's degrees, typically in two to three years, depending on their dayto-day workload and how quickly the company needs them in place.

No company can be passive

As pervasive as cyber attacks now are, no company can be passive. Attacks are targeted at utilities, banking and financial services, healthcare, insurance, chemical, telecommunications, and many other industries, even your local the supermarket s supply chain at a nearby mall.

Bank of America/Merrill Lynch's Vice President of Securities Fraud Cassandra Chandler knows this all too well. "As cyber criminals continue to expand and gain access to even more financial information, we continue to evolve our capabilities and expertise to ensure that our customers are protected," says Chandler. "We continue to make tremendous strides in this area."

A recently published study by computer security firm McAfee and Purdue University reported that in 2008, cyber meft topped $1 trillion. The study was based on responses from 800 CIOs worldwide. McAffee CEO David DeWaIt says, "The report is a wake-up call, and the trillion-dollar figure is actually a conservative estimate."

Organizations must provide sophisticated training to in-house experts to ensure the integrity of internal and client systems. They must also offer instruction to their entire workforce to avoid cyber minefields surrounding us all.

Simple, yet effective, training must be provided to personnel for general awareness, while graduate education is now globally available to specialists to gain the high level of expertise your company requires. As long as there are cyber criminals ready to strike, your company remains vulnerable. Vigilant cyber-security training and education must be your company's top priority.

[Sidebar]

LISTEN TO THIS FEATURE at www.astd.org/TD/TDpodcasts.htm

[Sidebar]

Inadvertent mistakes are better avoided when consistent and specific training is given to non-IT staff regarding the dangers their everyday activity can incur.

[Sidebar]

Evolving Cyber Threats

1986-1995

Local area networks

First PC virus

Boot sector viruses

Result in notoriety or system/user havoc

Slow propagation

16-bit DOS

1995-2000

Internet era

Macro viruses

Script viruses

Result in notoriety or system/user havoc

Faster propagation

32-bit Windows

2000-2007

Broadband prevalent

Spyware, span

Phising

Botnets

Rootkits

Financial motivation

Internet-wide impact

32-bit Windows

2007-Beyond

Peer-to-peer

Social engineering

Application attacks

Financial motivation

Targeted attacks

64-bit Windows

State-sponsored cyber terrorism

Correlation between office, ISP, and home computers

Mobile device attacks

Courtesy Robert J. Giesler. SAIC

[Sidebar]

The Numbers Behind the Threats

The Booz Allen Hamilton study "Cyber IN-security: Strengthening the Federal Cybersecurity Workforce" recommends that agencies adopt the following best practices for onboarding and successful retention:

* Develop onboarding programs for all new employees, but also have special programs for new cyber-security employees to acclimate them, introduce them to colleagues and immediately familiarize them with the agency's cyber-security work.

* Implement training and development programs, including rotations to different parts of the agency that do cyber-security work, to grow skills and knowledge, and include a career path with opportunities to earn appropriate certifications.

* Make new employees feel connected to the mission by using them in recruiting and outreach programs at universities and high schools.

* Identify financial and nonfinancial incentives to help retain employees, including student loan repayment and tuition reimbursement for continuing education.

* Encourage networking across the agency's cyber-security workforce (including field locations) to build loyalty and help create a framework where all cyber-security resources can be mobilized if needed.

Source: Booz Allen Hamilton. http://bit.ly/k2Zlxa

[Sidebar]

As long as there are cyber criminals ready to strike, your company remains vulnerable. Vigilant cyber-security training and education must be your company's top priority.

[Sidebar]

INTERESTED IN ORDERING E-PRINTS?

Would a digital version of this article be a great fit for your next course, presentation, or event? Are you interested in e-pnnts of several T+D articles on a specific topic9

Visit astd.org/TD/eprints for more information.

Cyber security continues to be on the top of the agenda for CEOs and high-ranking government officials because they know that online security can no longer be partially addressed or uncomfortably ignored. However, according to a Booz Allen Hamilton survey, the nation's cyber defense is seriously challenged by shortages of highly skilled cyber-security experts.

The report notes that 40 percent of chief information officers, chief information security officers, and IT managers are unsatisfied with the quality of cyber-security job applicants, and according to SANS Institute Research Director Alan Paller, more than 30,000 specialists are needed today. However, he claims that "only about 1,000 to 2,000 have the necessary skills" to combat the numerous real-life scenarios happening in today's organizations.

Organizations must provide sophisticated training to in-house experts to ensure the integrity of internal and client systems. They must also offer instruction to their entire workforce to avoid cyber minefields surrounding us all.

Simple, yet effective, training must be provided to personnel for general awareness, while graduate education is now globally available to specialists to gain the high level of expertise your company requires. As long as there are cyber criminals ready to strike, your company remains vulnerable. Vigilant cyber-security training and education must be your company's top priority.

[Author Affiliation]

Jay VanDerwerken is managing director of business development at NYU Polytechnic Inst itute;jvanderwerken@poly. edu. Robert Ubell is vice president of enterprise learning at NYU Polytechnic Institute; rubell@poly.edu.

Ex-city couple worried about Egyptian friends

Former Winnipegger Jim McEachern and his wife Karen are watching the unfolding crisis in Egypt with horror made personal. The news reports, the images of chaos in familiar streets and the names of the areas where protestors gather are snapshots of their former home.

In 2009, Jim McEachern left his job as director of sales and marketing at the Fairmont Winnipeg and transferred to a post with the Fairmont Nile City hotel in Cairo.

The couple spent a happy year in Egypt. They made lifelong friends, something this globe-trotting couple does wherever they live and work.

They got to know ordinary Egyptians as well as expatriates. They travelled the country by car, unfettered by a tourist's schedule. The job was demanding but McEachern says the country and its people marked them indelibly.

His Facebook photos show the pair riding on camels and beaming at the camera.

McEachern says armchair quarterbacks are trying to make sense of the explosion of protest and the continuing calls for political change. An outsider would have a difficult time understanding the nuances, he says.

"I can't say there were signs," he says, speaking from Alberta's Fairmont Jasper Park Lodge, where he now works. "I think every single broadcaster has said this is a consequence of what is happening in Tunisia. I think you have to be there for awhile before you get under the layers, the way everything works.

"You only begin to understand much later as to how it really works."

As in most countries, tourists only scratch the surface of life in Egypt, he says.

"They have tourist police," he says. "They work two or three jobs and that's why you sometimes see them sleeping on the job. There are rumours they don't have bullets in their guns. But they make the tourist feel safe."

It's sometimes a false sense of security, he says. There are also police, secret police, an army and a massive fleet of palace guards. When President Hosni Mubarak travels, eight-lane roads are shut for kilometres. There's sharpshooters on roofs, armed police every 50 metres.

"You don't see it as an armed state," he says matter of factly. "There are certainly armed police."

As he watches the news McEachern says his concern is not for tourists or expatriates. It's for his Egyptian friends and co-workers. The Fairmont he worked at is in the epicentre of the unrest. A note on the hotel's website assures those abroad that visitors are safe.

"All guests and colleagues of the Fairmont Nile City are safe."

McEachern agrees foreigners don't appear to be in much danger.

"You're extremely privileged as a traveller. You can leave. Egyptians can't just leave."

The images of thousands of people begging to be allowed on planes, the reports of bribes being demanded for a seat, the efforts by foreign governments to evacuate their people are startling and brutal. But most who want to leave, will.

McEachern's last communication with Egyptian friends was a simple "stay well" message he sent before the government shut down the Internet. He still has means of gathering some information. Friends and colleagues in the United Arab Emirates (where he once worked) and in Britain have been receiving messages and rerouting them.

While the rest of the world watches to see if the protests will remain peaceful and if Mubarak will continue to cling to power, the McEacherns watch the news obsessively.

"The visuals of Cairo have been flooding back to us. That year we spent in Egypt was a huge wake-up call for us. We were changed."

Now they wait to see how Egypt will change and how that change will affect their faraway friends.

lindor.reynolds@freepress.mb.ca

INFORMATION ISSUED BY U.S. ATTORNEY'S OFFICE FOR DISTRICT OF COLUMBIA ON MARCH 23: DC TASK FORCE ACHIEVES 100 PERCENT CONVICTION RATE IN CASES INVOLVING INTERNET CRIMES AGAINST CHILDREN

The U.S. Department of Justice's U.S. Attorney's office for District of Columbia issued the following press release:

Since last summer, the Project Safe Childhood Initiative, led by the Metropolitan Police Department, has conducted a series of internet investigations, leading to the arrest and conviction of 15 online child predators. In addition, four other individuals have been indicted on charges, including sexual exploitation of minors and/or child pornography. A fifth person also was recently arrested.

The defendants in these cases range in ages from 20 - 56. Occupations of these 15 individuals include students, members of the military, employees of the media, and a contract engineer with NASA. Once sentenced, all defendants will be required by law to register as sex offenders.

The successful results of the special joint task force's investigations were announced today by Acting Chief Cathy L. Lanier, Metropolitan Police Department (MPD); Jeffrey A. Taylor, United States Attorney for the District of Columbia; Special Agent In Charge Jennifer Love, Federal Bureau of Investigation; Special Agent In Charge William Reid, U.S. Immigration and Customs Enforcement(ICE); and Assistant Special Agent in Charge Mark Hughes, U.S. Secret Service.

"The Internet can be a tremendous resource for our children, but at the same time, expose them to dangers of online child predators," said U.S. Attorney Taylor. "Through our Project Safe Childhood initiative, federal and local law enforcement are fully committed to tracking down and prosecuting those who would use the Internet to sexually exploit our children."

In addition to aggressive law enforcement, the Task Force unveiled two new Public Service Advertisements (PSAs) aimed at educating young people about the dangers of Internet predators. The PSAs, which will be televised nationally, were produced by the Department of Justice, in coordination with the Center for Missing and Exploited Children and the Ad Council. They highlight the fact that nothing online is private, and children should be careful about posting personal information online.

"Public education and parental involvement are two of the most powerful tools to help combat online sexual exploitation," said MPD Acting Chief Lanier. "The Metropolitan Police Department is committed to working to protect our children and appreciates the cooperation and support that we have received from our fellow partners in law enforcement and the Washington DC Police Foundation."

The Task Force has also received significant support from the Washington DC Police Foundation, which provided MPD with a $50,000 grant to assist with start-up costs, including technology and training. Funded by the business community, the Police Foundation marshals financial resources from the private sector to support public safety initiatives in the District of Columbia.

Launched in February 2006, Project Safe Childhood is a national initiative designed to protect children from online exploitation and abuse. Project Safe Childhood brings federal, state and local resources together in an effort to locate, apprehend and prosecute individuals who seek to exploit children via the Internet, as well as identify and rescue victims. The Washington, D.C. Internet Crimes Against Children Task Force is one of 46 regional task forces funded by the U.S. Department of Justice.Contact: Channing Phillips, 202/514-6933.

Channing Phillips, 202/514-6933.

High jinks and low politics in Tehran

International Studies

Fun and games in Tehran. While the rest of the Middle East isgrappling with the "Arab Spring", Iran has been indulging in its ownbitter battle for pre-eminence between the President, MahmoudAhmadinejad, and the Supreme Leader, Ayatollah Ali Khamenei.

The battle has been raging over the past three weeks after MrAhmadinejad's decision to fire the head of intelligence, HaidarMoslehi. Khamenei intervened to insist the man be reinstated andpublished the letter telling him to do so. Ahmadinejad then threw ahissy fit and refused to attend cabinet meetings for 11 days, untilthe stand-off was finally resolved on Sunday, when the sour-facedAhmadinejad returned to cabinet, spoke in praise of the SupremeLeader but continued to fire off darts at those around him.

It's the kind of spat that the Iranians, indeed the whole MiddleEast, love to retell in the cafs and bazaars, tales of who's in andwho's out, not very different from the days of the Shah. Compared tothis, today's tensions between Nick Clegg and David Cameron are butchild acting.

And before anyone gets too excited - as Washington is - aboutwhat the struggle will mean for the outside world, it is worthremembering that it is as much as anything a court struggle, a spatover precedence with few direct implications for any fundamentalchange in Iran.

This, is after all, a fight for power within the system.Ahmadinejad has offended not just Khamenei but parliament andconservatives by pursuing a policy of putting his own men inpositions of power and promoting, in particular, the position of hischief of staff (rejected for ministerial position by Khamenei)Esfandiar Rahim Mashaei.

Khamenei has responded by gathering clerics and conservativesalike to defend his constitutionally established position as finalarbiter of affairs, civil as religious, in the country.

In terms of internal politics, Ahmadinejad's challenge totheocratic rule (the velyat) and his attempt to wrestle power awayfrom the clerics to presidential government is not an inconsiderableone. In terms of the future of the country it doesn't really resolvemuch. President Ahmadinejad has clearly been weakened and may nowend up as a lame-duck leader with two years to go before thepresidential elections of 2013. But he still has a lot of energy andsome support from his generation of war veterans. Khamenei hasasserted his authority but may also have weakened it by having todemonstrate it so publicly and with such effort. The liberals, stillcowed by determined oppression, have no say in the fight.

Does that mean an Iran stuck in a convoluted and fractioustheocratic rut for the foreseeable future? Not necessarily. So far,it has managed to avoid getting sucked into the uprisings sweepingthe rest of the Middle East, partly by acclaiming them as fulfillingits long-term calls for the overthrow of western-supportedautocracies.

The uprisings in its ally Syria and its support for Assad rulethere, has badly undermined its right to moral leadership in theMiddle East (which matters to it) and threatened its most importantally in the Arab world as well as its avenue of influence inPalestine and Lebanon.

At the same time, in today's world of social networks andinternet communication, it's difficult to believe that people inIran, and especially the young, aren't influenced by what ishappening elsewhere in the region. After all, the frustrations whichhave impelled so many to take to the streets elsewhere - corruption,political oppression and economic sclerosis -are mirrored in Irantoo.

While the big beasts fight it out at the top in Iran, there aredeeper social forces moving below.

It's too early to write off the revolutions

It was inevitable that people would start pointing out thefrailties of the revolution that so quickly overturned the regimesof Tunisia and Egypt and threatened to upend so many others. And sothey have. The latest outburst of sectarian killing between Muslimsand Coptic Christians in Egypt has set off a barrage of despairingpredictions of what will come and could, it is claimed moreinsidiously, occur in Syria were the Assad rule to be ended. EvenTunisia, where it all started and the revolt triumphed so quickly,has been picked apart for signs of fracturing before the electionsthere in July.

That may be fair comment. But to criticise the uprisings fortheir amorphous nature is to denigrate them for the quality thatmakes them so important and so heartening. It is precisely becausethey are a movement of rejection of oppressive political andeconomic structures, a demand for freedom rather than a transfer ofpower to themselves, that the protests have managed to garner suchwide support. And it is because they are so unformed that a power-vacuum has resulted.

It is a vacuum that is bound to attract the most aggressiveelements in society and, over time, foreign meddling. In the case ofEgypt, the violence against Christians seems to have been largelystirred up by extreme Salafi groups. Those within Egypt accuse themof being orchestrated by pro-Mubarak forces trying to stir up chaos.That may or may not be true although, given the past of attacks onCopts, it is not a necessary explanation.

The encouraging factor in Egypt is that almost every newspaperand public voice has condemned the violence absolutely. Before wewrite off the country's prospects, or overstate the risk of afundamentalist challenge in Tunisia, let's trust their people towant the right thing and support them in gaining it.

a.hamilton@independent.co.uk

Students adopt philosophical approach

STUDENTS at Chester's Queen's School are taking part in a projectwith international significance.

University College London (UCL)'s Transcribe Bentham aims totranscribe the hand-written works of the famous philosopher andsocial reformer Jeremy Bentham for the internet.

There are 60,000 of Bentham's papers in UCL's library but severalthousands have yet to be transcribed and studied. The Queen's Schoolpupils were the first people outside UCL to have access to thewritings as they helped Dr ValerieWallace, research associate of theUCL Bentham Project, to test the online transcription system. Whileat UCL they also attended a lecture on Bentham and viewed hispreserved skeleton, dressed in his own clothes, in a wooden box inthe South Cloisters.

Jenny Cumiskey, one of the students who took part in the event,said: "This project allowed us not only to engage with our ownheritage through access to original historical manuscripts , butalso to contribute to the documentation of the nation's history."Transcribe Bentham is free and easy to take part in. Project detailscan be found at http://www.ucl.ac.uk/transcribe-bentham/.

Fed: Survivors tell of 'children overboard' rescue


AAP General News (Australia)
08-28-2004
Fed: Survivors tell of 'children overboard' rescue

Survivors of the so-called children overboard incident have for the first time given
their accounts of what happened after their refugee boat sank in late 2001.

An Iraqi mother of two who almost drowned has told Melbourne's Herald Sun newspaper
that she thought she was going to die and her two children were already lost when Australian
Navy sailors saved them off Christmas Island.

SABRIYAH AL RAHEEMY, who now lives in Sydney, has spoken of her disbelief that Australian
voters were told by the federal government that the asylum seekers deliberately threw
their children into the sea.

FADELLAH AL HUSSANI, another survivor who was photographed being rescued along with
her then eight-year-old son, says she was surprised to see her rescue portrayed as having
thrown her children into the sea.

She's told the newspaper they waited with their children until the very last moment
to leave the sinking boat.

Prime Minister JOHN HOWARD is facing renewed pressure over the children overboard affair,
with claims he misled voters in the 2001 election and ignored advice that the incident
never happened.

AAP RTV mp/rp

KEYWORD: OVERBOARD FAMILY (MELBOURNE)

2004 AAP Information Services Pty Limited (AAP) or its Licensors.

TAS: Mother gives emotional evidence at Senate inquiry


AAP General News (Australia)
04-21-2004
TAS: Mother gives emotional evidence at Senate inquiry

A Tasmanian woman has choked back tears as she told an inquiry about the disappearance
of her only son at sea nearly two years ago.

JOAN GURR was one of two grieving mothers to give evidence before the Senate inquiry
into the effectiveness of Australia's military justice system.

Her son, Leading Seaman CAMERON GURR, was two months shy of his 21st birthday when
he was lost overboard from HMAS Darwin off Christmas Island in May 2002.

On the night he vanished, he'd been drinking with mates after being promoted.

A subsequent naval board of inquiry was told of illicit drinking sessions aboard the
ship, with seven members of the Darwin crew punished as a result.

Mrs GURR has told inquiry she believes the naval probe focused more on broken rules
and punishment than what happened to her son.

The inquiry has also heard from SUSAN CAMPBELL, whose 15-year-old daughter ELEANORE
TIBBLE killed herself in November 2000.

AAP RTV las/jo/rp

KEYWORD: MILITARY (HOBART)

2004 AAP Information Services Pty Limited (AAP) or its Licensors.