FAS

Sequester May Slow Pentagon Response to WikiLeaks

02.25.13 | 2 min read | Text by Steven Aftergood

The across-the-board budget cuts known as sequestration that are expected to take effect on March 1 could impede the government’s ability to respond to WikiLeaks and to rectify the flaws in information security that it exposed, a Pentagon official told Congress recently.

Zachary J. Lemnios, the assistant secretary of defense for research and engineering, was asked by Sen. Rob Portman (R-Ohio) to describe the “most significant” impacts on cybersecurity that could follow from the anticipated cuts to the Pentagon’s budget.

Mr. Lemnios replied that “cuts under sequestration could hurt efforts to fight cyber threats, including […] improving the security of our classified Federal networks and addressing WikiLeaks.”

The sequester could also interfere with the Comprehensive National Cybersecurity Initiative that began under President Bush, he said, and could hold up plans to “initiat[e] continuous monitoring of unclassified networks at all Federal agencies.”

Mr. Lemnios’ response to Sen. Portman’s question for the record (which had not specifically mentioned WikiLeaks) followed a March 2012 Senate Armed Services Committee hearing on Emerging Threats and Capabilities that was published in December 2012 (at page 42).

Generally speaking, computer security within the military is a daunting problem, Mr. Lemnios told the Committee, particularly since “The Department operates over 15,000 networks and 7 million computing devices across hundreds of installations in dozens of countries around the globe.”

The challenge of cybersecurity cannot be fully described in public, said Dr. Kaigham J. Gabriel of DARPA. “The complete picture requires a discussion at the special access level.”  But he told the Committee last year that several basic points can be openly acknowledged:

“Attackers can penetrate our networks:  In just 3 days and at a cost of only $18,000, the Host-Based Security System” — the Pentagon’s baseline computer security system — “was penetrated.”

“User authentication is a weak link: 53,000 passwords were provided to teams at Defcon; within 48 hours, 38,000 were cracked.”

“The Defense supply chain is at risk: More than two-thirds of electronics in U.S. advanced fighter aircraft are fabricated in off-shore foundries.”

“Physical systems are at risk: A smartphone hundreds of miles away took control of a car’s drive system through an exploit in a wireless interface.”

“The United States continues to spend on cybersecurity with limited increase in security: The Federal Government expended billions of dollars in 2010, but the number of malicious cyber intrusions has increased.”

Though it was presumably not intentional, the WikiLeaks project galvanized government information security programs and accelerated efforts to devise “insider threat” detection mechanisms, along with intensified surveillance of classified and unclassified government computer networks.

“New classes of anomaly detection methods have been developed and are based on aggregating events across time and multiple sources to identify network and host-based behavior that might be malicious,” James S. Peery of Sandia National Laboratories told the Senate Armed Services Committee at last year’s hearing.  “These approaches and behavioral-based methods have been successful in finding previously undiscovered malware.”

“One drawback of this technology, though, is that it has a very high false positive rate,” he said.

publications
See all publications
Government Capacity
Blog
Everything You Need to Know (and Ask!) About OPM’s New Schedule Policy/Career Role: Oversight Resource for OPM’s Schedule Policy/Career Rule

This rule gives agencies significantly more authority over certain career policy roles. Whether that authority improves accountability or creates new risks depends almost entirely on how agencies interrupt and apply it. 

02.13.26 | 8 min read
read more
Government Capacity
Policy Memo
Report
Rebuilding Environmental Governance: Understanding the Foundations

Our environmental system was built for 1970s-era pollution control, but today it needs stable, integrated, multi-level governance that can make tradeoffs, share and use evidence, and deliver infrastructure while demonstrating that improved trust and participation are essential to future progress.

02.12.26 | 26 min read
read more
Government Capacity
Policy Memo
Report
Costs Come First in a Reset Climate Agenda

Durable and legitimate climate action requires a government capable of clearly weighting, explaining, and managing cost tradeoffs to the widest away of audiences, which in turn requires strong technocratic competency.

02.12.26 | 41 min read
read more
Environment
Press release
FAS Launches New “Center for Regulatory Ingenuity” to Modernize American Governance, Drive Durable Climate Progress

FAS is launching the Center for Regulatory Ingenuity (CRI) to build a new, transpartisan vision of government that works – that has the capacity to achieve ambitious goals while adeptly responding to people’s basic needs.

02.12.26 | 4 min read
read more