{"id":204946,"date":"2017-07-11T22:03:39","date_gmt":"2017-07-12T02:03:39","guid":{"rendered":"http:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/expert-battling-botnets-requires-standards-and-automation-fcw-com\/"},"modified":"2017-07-11T22:03:39","modified_gmt":"2017-07-12T02:03:39","slug":"expert-battling-botnets-requires-standards-and-automation-fcw-com","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/automation\/expert-battling-botnets-requires-standards-and-automation-fcw-com\/","title":{"rendered":"Expert: Battling botnets requires standards and automation &#8211; FCW.com"},"content":{"rendered":"<p><p>    Cybersecurity  <\/p>\n<p>    The Trump administration's cyber executive order has tasked the    departments of Commerce and Homeland Security with a year-long    study of how to reduce botnets, but one former official says    the immediate focus should be on standards and automation.  <\/p>\n<p>    Ari Schwartz, former senior director for cybersecurity at the    National Security Council and now with Venable LLP, said at a    July 11 resilience workshop hosted by the National Institute    for Standards and Technology that the proliferation of    internet-connected devices -- many of which are insecure or    can't be updated -- and increasing bandwidth of internet    systems are leading to more, and more powerful, distributed    denial of service attacks. Repeaters and other technology    are making attacks increasingly complex.  <\/p>\n<p>    Schwartz said that there were a variety of successes in the    battle against bots over the last decade,    including the FBI's Bot Roast and DNSChanger operations and the    Federal Communications Commission Communications Security,    Reliability and Interoperability Council's Anti Bot Code of    Conduct for ISPs.  <\/p>\n<p>    But he said the government failed to build on the momentum.  <\/p>\n<p>    \"The fact that you need a botnet report and we're not at the    point of saying 'here is the whole of government approach to    this issue' and that the Trump administration needed this    report,\" demonstrates that more could have been done, he said.  <\/p>\n<p>    Going forward, Schwartz told FCW the first priority is speeding    up the development of standards, especially for device    manufacturers.  <\/p>\n<p>    \"We're just starting to see the standards be put in place for    what they are supposed to do, so I'm worried that it's a long    process to get to that point,\" he said. Schwartz warned that    standards need to be put in place before any regulation comes    down to avoid ending up \"with things locked into place in    2017.\"  <\/p>\n<p>    He said NIST and National Telecommunications and Information    Agency are playing important roles in developing standards and    facilitating public-private partnership.  <\/p>\n<p>    \"There needs to be sustained follow up and sustained    participation,\" he said. \"Government is part of that. Industry    is part of that, and it's different parts of industry too.\"  <\/p>\n<p>    Schwartz stressed that the government needs to hold off on    regulations for now.  <\/p>\n<p>    \"You've got to get the standards in place,\" he said. \"You've    got to get people doing it voluntarily and see how that goes    for some period of time and then start mandating it as people    are not doing it or in the areas they're not doing it.\"  <\/p>\n<p>    One of the key standards is automated device updating, Schwartz    said.  <\/p>\n<p>    \"Education works to some extent, notification works to some    extent, but the scale we're talking about, it's not going to be    the answer,\" he said. \"So it needs to be more of automated    patching in this space.\"  <\/p>\n<p>    \"How do we make sure that we can update things and the user    doesn't have to be involved in that discussion, but yet we're    not invading their privacy, we're not breaking stuff on their    side, right?\" he said. \"That's the key.\"  <\/p>\n<p>    Schwartz and other panelists at the workshop acknowledged there    will be an ongoing challenge posed by expired devices that are    still connected but are no longer supported or being updated.  <\/p>\n<p>      About the Author    <\/p>\n<p>       Sean      Carberry is an FCW staff writer covering defense,      cybersecurity and intelligence. Prior to joining FCW, he was      Kabul Correspondent for NPR, and also served as an      international producer for NPR covering the war in Libya and      the Arab Spring. He has reported from more than two-dozen      countries including Iraq, Yemen, DRC, and South Sudan. In      addition to numerous public radio programs, he has reported      for Reuters, PBS NewsHour, The Diplomat, and The Atlantic.    <\/p>\n<p>      Carberry earned a Master of Public Administration from the      Harvard Kennedy School, and has a B.A. in Urban Studies from      Lehigh University.    <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read this article:<\/p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/fcw.com\/articles\/2017\/07\/11\/botnets-standards-dhs-study.aspx\" title=\"Expert: Battling botnets requires standards and automation - FCW.com\">Expert: Battling botnets requires standards and automation - FCW.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Cybersecurity The Trump administration's cyber executive order has tasked the departments of Commerce and Homeland Security with a year-long study of how to reduce botnets, but one former official says the immediate focus should be on standards and automation. Ari Schwartz, former senior director for cybersecurity at the National Security Council and now with Venable LLP, said at a July 11 resilience workshop hosted by the National Institute for Standards and Technology that the proliferation of internet-connected devices -- many of which are insecure or can't be updated -- and increasing bandwidth of internet systems are leading to more, and more powerful, distributed denial of service attacks.  <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/automation\/expert-battling-botnets-requires-standards-and-automation-fcw-com\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[187732],"tags":[],"class_list":["post-204946","post","type-post","status-publish","format-standard","hentry","category-automation"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/204946"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=204946"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/204946\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=204946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=204946"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=204946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}