GAO Report: EINSTEIN not meeting stated objectives

Robinson+Cole Data Privacy + Security Insider
Contact

According to a recent GAO report, the Department of Homeland Security’s (DHS) National Cybersecurity Protection System, commonly referred to as EINSTEIN, is not meeting its stated objectives. The purpose of EINSTEIN is to protect federal civilian executive branch agencies from cyber attacks. EINSTEIN monitors traffic to and from these agencies to identify malicious activity, serves as an intrusion detection system, and provides DHS with threat information that can be used to help both the government and the private sector to manage cyber risk. EINSTEIN uses a signature-based intrusion detection system that compares network traffic to known malicious behavior (signatures). The GAO report noted that while a signature-based system is capable of preventing attacks from known threats, it is not structured to prevent against unknown attacks, such as “zero days” that exploit an existing vulnerability in a product. The GAO report also noted that DHS had not yet fully developed the tools for information sharing, such as tools that will notify affected entities of suspected malicious activity.  In response to the GAO report, representatives from DHS stated that the program has been effective in identifying significant incidents and has improved detection of hackers within the system. DHS representatives also emphasized that EINSTEIN is intended to be one of many tools used by the federal government to prevent and detect against cyber attacks.  In his recent budget proposal, President Obama requested $471.1 million for EINSTEIN to enable the system to maintain its current capabilities and invest in new technologies and analytics.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide