January 25, 2013

VIEW FROM AWAY: Banks cyber attacks show new level of skill

The Wasington Post

These have not been been easy days for cyber security experts at some of the nation's leading banks. A barrage of attacks on bank networks has intensified since September, clogging websites with traffic, slowing or crashing them. The banks have not lost data, but their online services have been interrupted.

The onslaughts are known as distributed-denial-of-service attacks, and the attackers apparently have reached a new level of skill and destructive power.

Radware, a network security firm, reports that they are now harnessing powerful servers into destructive "botnets," or chains of computers that have been infected by malware and ordered to swarm a target. The botnet technique has been around for a while, but the use of servers to generate the stream of pings gives the attackers unprecedented power.

According to a report by Ellen Nakashima in The Washington Post, the banks have now turned to the National Security Agency for help in protecting their systems. The super-secret electronic surveillance agency has been at the forefront of defending U.S. government networks from intrusion; its director, Gen. Keith Alexander, also serves as chief of U.S. Cyber Command.

What's happening now is something that Alexander and other cyber experts have warned about for a long time: attacks aimed at the soft underbelly of American society, our wired but vulnerable private sector.

Several news reports have identified the assault on U.S. banks as the work of Iran, perhaps in retaliation for Stuxnet, the computer worm designed to wreak havoc on Iran's nuclear equipment that was apparently developed by the United States as part of a covert intelligence operation.

Out of concern for attacks on U.S. companies, Congress last year wrestled with legislation that would have allowed the NSA to share its sophisticated cyber security tools with the corporate sector. Sens. Joseph I. Lieberman, I-Conn., and Susan Collins, R-Maine, championed a bill that would have eased the way for the government to enter company networks. The legislation, however, was opposed by the U.S. Chamber of Commerce, which warned of heavy-handed government regulation and bureaucracy, and it died.

Now, just months later, who's knocking on the government's door, demanding help? According to news reports, the attacks have stricken Bank of America, PNC Bank, Wells Fargo, Citigroup, HSBC and SunTrust. Perhaps they should tell the Chamber of Commerce a little about the experience.

The business lobby's approach to cyber security legislation was myopic last year. The chamber should face the reality that corporate America is seriously vulnerable to attack.

Congress would be well advised to focus early on this topic. The private sector remains unprepared for the kind of massive botnet assaults being aimed at the banks. The U.S. government can offer an important line of defense. Congress ought to lay down a foundation for this cooperation in new legislation and without delay.

Editorial by The Washington Post

Were you interviewed for this story? If so, please fill out our accuracy form

Send question/comment to the editors




Further Discussion

Here at OnlineSentinel.com we value our readers and are committed to growing our community by encouraging you to add to the discussion. To ensure conscientious dialogue we have implemented a strict no-bullying policy. To participate, you must follow our Terms of Use.

Questions about the article? Add them below and we’ll try to answer them or do a follow-up post as soon as we can. Technical problems? Email them to us with an exact description of the problem. Make sure to include:
  • Type of computer or mobile device your are using
  • Exact operating system and browser you are viewing the site on (TIP: You can easily determine your operating system here.)