News Analysis: DDoS Attacks Highlight Need to Reduce Government Internet Access Points
The network attacks that severely disrupted several federal agency Web sites this week highlights the need for the government to quickly finish implementing its ongoing consolidation of Internet access points, the former de facto CIO of the federal government and others said today.
Thu, July 09, 2009
Computerworld — The network attacks that severely disrupted several federal agency Web sites this week highlights the need for the government to quickly finish implementing its ongoing consolidation of Internet access points, the former de facto CIO of the federal government and others said today.
Online Attack Hits US Government Web Sites
The Botnet World is a Booming World
Multiple government Web sites, including that of the Federal Trade Commission (FTC), the Federal Aviation Administration (FAA) and Department of the Treasury, were temporarily knocked out or slowed down earlier this week by a wave of distributed denial of service attacks.
The attacks were launched from a botnet believed to comprise of nearly 50,000 infected computers, and were designed to render Web sites inaccessible by inundating them with useless traffic.
Security researchers have described the attacks as being relatively unsophisticated. Even so, the attacks still managed to totally shut down the Web sites of the FTC and Department of Transportation for several hours over the weekend, according to statistics available from Internet monitoring firm Keynote Systems.
The most important lesson learned is that many federal agency security people did not know which network service provider connected their Web sites to the Internet, said Alan Paller, director of research the SANS Institute. "So they could not get the network service provider to filter traffic," Paller said.
The problem has to do with that federal agencies have more access points to the Internet than they know how to monitor or to manage, said Karen Evans, former de facto CIO of the federal government during the Bush administration.
An initiative called the Trusted Internet Connections (TIC) program, which was launched in November 2007, is designed to tackle this issue by getting agencies to drastically reduce the number of individual external network connections, including those to the Internet.
Since the effort was launched, the number of access points across government has been reduced from more than 4,300 to about 2,750, per the last time data on the effort was publicly released in June 2008. The goal is to whittle that number down to about 80.
Instead of having each individual agency manage its own connections, the plan is to have a small group of TIC access providers offering centralized connectivity and gateway-monitoring services to a majority of civilian federal agencies. While 16 agencies will act as their own access providers, 121 others will have their connections managed via a U.S. General Services Administration-approved service provider.
Such a consolidation of access points and management functions would allow for much better network monitoring, filtering and incident response than is possible today across civilian government, Evans said.


