Coker: Agencies flooded with cyberattacks, beset with complex problems can’t always innovate
Full article591 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It’s why his Office of the National Cyber Director is taking on challenges like BGP security, he said.
Listen to this article
0:00
Learn more.
A deluge of cyberattacks on federal agencies, and the complexity of the challenges they face, makes it hard for them to advance new approaches to defending their networks, National Cyber Director Harry Coker Jr. said Wednesday.
Speaking at CyberTalks, hosted by CyberScoop, Coker said that’s why his White House office focuses on strategy and policy to tackle complex problems like secure internet routing, which is both increasingly vulnerable and a fundamental component of basic interactions on the web.
“Unfortunately, most of our departments and agencies are dealing with day-to-day operational attacks,” Coker said. “Or in some cases, these entities have shied away from developing or proposing solutions because of the perceived degree of difficulty.”
Border Gateway Protocol (BGP) is one of the “foundational protocols” that lets over 70,000 independent networks operate together as the internet and allow IP addresses to exchange routing information to reach each other across the globe, he said.
But attackers can reroute — or hijack — internet traffic, exploiting a BGP system that is built on trust, Coker said.
“More recently we have seen sophisticated attacks, BGP hijacks, increase,” he said. “Recent incidents have resulted in the loss of millions of dollars.”
A roadmap produced by Coker’s office last month promoted the adoption of Resource Public Key Infrastructure (RPKI), which can ensure BGP routing information is authentic, but there’s a necessary registration process.
“Although that technology has existed for a dozen years, it was only recently that a bare majority of global internet addresses were appropriately registered in RPKI to allow internet service providers to filter all surrounding advertisements and prevent attacks to hijack,” he said.
Furthermore, federal agencies have been running behind on that process, Coker said. But that’s beginning to change, he added.
“By the end of this year, we expect over 60% of the federal IP space to be covered by registered service agreements, paving the way to establish route origin authorizations for federal networks,” he said.
A group of researchers recently said RPKI has vulnerabilities of its own.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/harry-coker-agencies-cyberattacks-bgp-security/