• On GameSpot: So-called 'Halo killer' gets 23 to life
February 28, 2008 11:38 AM PST

Congress worries that .gov monitoring will spy on Americans

by Anne Broache

WASHINGTON--A new Bush administration plan to capture and analyze traffic on all federal government networks in real time is generating privacy worries from congressional Democrats and Republicans alike.

At a hearing convened here Thursday by the U.S. House of Representatives Homeland Security Committee, politicians directed pointed questions to Department of Homeland Security officials about their plans to expand an existing "intrusion detection" system known as Einstein. Among other things, the system will monitor visits from Americans--and foreigners--visiting .gov Web sites.

Einstein, which DHS calls an "early warning system" for cyber-incidents, is described in a Homeland Security document from September 2004 as "an automated process for collecting, correlating, analyzing, and sharing computer security information across the federal civilian government." It's still only in place at 15 federal agencies, but Homeland Security Secretary Michael Chertoff requesting $293.5 million from Congress in next year's budget to roll it out government-wide.

The round-the-clock system captures traffic flow data, which currently includes source and destination IP addresses and ports, Internet Control Message Protocol data, and the length of data packets. According to an internal 2004 privacy impact assessment (PDF), "the program is not intended to collect information that will be retrieved by name or personal identifier." Members of the U.S. Computer Emergency Readiness Team, which coordinates federal responses to cyber attacks, analyze the downloaded records once per day in hopes of detecting worms and other "anomalous activity," pinpointing trends, and advising agencies on how best to configure their systems.

Homeland Security says the setup has helped reduce the time it takes for agencies to share such data from four to five days to four to five hours. The next step is to hire more analysts and enable the analysis to occur in real time, DHS says.

Beyond that, it's not exactly clear what will change, including whether the system will gather more information than before, or what will be done with it. But some politicians said they're already apprehensive about the new plans.

"I encourage you to try to find something beyond Einstein that's going to be focusing on bad guys, not just focusing on the general public but finding some way to protect the privacy of American citizens," said Rep. Paul Broun (R-Ga.).

Rep. Jane Harman (D-Calif.) criticized the department on one hand for treating cyber threats with sufficient urgency--a common refrain from members of both parties ever since the sprawling government agency's inception. But she also questioned the new approach being offered.

"I can assure you constituents of mine listening to this hearing are thinking about this as the government sets up a new spy network," she said. "What would you advise me to tell my constituents (who want to know) how I'm going to stop this latest government spy network?"

Homeland Security under secretary Robert Jamison presides over an agency division that's responsible for coordinating all federal cybersecurity activities.

(Credit: U.S. Department of Homeland Security)

Robert Jamison, a Homeland Security undersecretary whose division oversees cybersecurity activities, declined to talk specifics, saying details must be reserved for a classified session.

"We have privacy and civil rights folks involved in this," he said. "We're in the process doing a privacy impact assessment for the new capability as we move forward."

Government agencies are required by law to produce such a report whenever they're planning to use a new technology that could involve collection of personally identifiable information. The goal is to ensure that no information is collected, stored, or accessed either unnecessarily or unlawfully.

The fact that Homeland Security officials are drawing up a new privacy impact assessment for the expansion of the Einstein project would seem to indicate they're considering gathering additional information, although it was unclear after Thursday's hearing whether that's the case.

Jamison, for one, claimed Einstein's new capabilities will be "no different" from those in commercial products used to detect worms or other malware. He indicated, however, that the government has no intention of scaling back the scope of its network monitoring.

"Adversaries are very adept at hiding their attacks in normal traffic--normal, everyday traffic that comes across the network that very well could be disguised and could be malicious," Jamison told the committee.

Einstein is just one part of Homeland Security's attempts to revamp its cybersecurity reputation. It's also working with the Office of Management and Budget on a project that would reduce the number of points at which all federal agency networks connect to the Internet--which right now numbers around 4,000--and thus encounter vulnerabilities from outside their realms.

Whenever a system monitors users' communications, privacy concerns naturally arise, said James Lewis, who runs the technology policy wing of the Center for Strategic and International Studies, a Washington think tank, and is working with members of Congress to devise cybersecurity policy recommendations for the next president. In this case, however, he said he didn't see any reason to be alarmed about Einstein quite yet.

"For Einstein to really affect privacy, you'd need to monitor and collect the communications, store them, and analyze them (e.g. have somebody actually read the content)," he said in an e-mail interview after Thursday's hearing. "I'm told that DHS won't store Einstein data and won't be analyzing it, which greatly reduces any risk to privacy."

Committee leaders warned that they'd be watching closely to see whether the plans pan out.

"It's hard to believe this administration now believes it has the answers to secure our federal networks and critical infrastructure," said Committee Chairman Bennie Thompson (D-Miss.).

Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (8 Comments)
  • prev
  • 1
  • next
Sleep tight America
by rcrusoe February 28, 2008 12:32 PM PST
your government is rummaging through your underwear drawer to
keep you safe from terrorists. ;)

Sounds like it's time to start using TOR.
Reply to this comment
America...
by rocketjam--2008 February 28, 2008 2:29 PM PST
Land of the free (at one time).
Reply to this comment
just more proof
by Dalkorian February 28, 2008 4:42 PM PST
The East German stasi didn't disband, they were simply acquired by
fuhrer bushit!

Sieg heil!

:-(
Reply to this comment
Yawn
by talk2farley February 28, 2008 6:01 PM PST
When using a network owned and operated by the federal government, federal employees have zero expectation of privacy. This is elementary. Monitoring the traffic on such networks is a common sense and fool proff mechanism for maintaining information security and preventing unauthorized use of government resources. This is also elementary. The private sector already does this pretty much universally, and they have been for years. That's why we don't look at porn from work.

The only reason congressmen are objecting to this proposal is that they DO look at porn at work.
Reply to this comment
This isn't about just Federal Employees
by PzkwVIb February 29, 2008 9:43 AM PST
The public has access to certain federal systems like Websites for the various Federal Agencies! Perhaps you check the TSA pages on acceptable carryons and forbidden items a few times more often than some profiling tool thinks you should. Congratulations you go on a secret watch list.

Think befire you post.
Gov't Spying via Einstein
by Bill Cropley March 8, 2008 6:32 AM PST
The comments "not as of yet" and so on are all gov't gobbldey **** for"not yet but we will get to it soon!" These people stay awake nights drean=ming of how to become legal voyeurs. It must be a requirement to have a Master's degree in lying and obfuscation to work for the gov't.
Reply to this comment
by rahuldravid October 13, 2008 9:58 PM PDT
this article is good and nice.it is very useful to us.The East German stasi didn't disband, they were simply acquired by fuhrer bushit!.
===============================================
rahul
<a href=http://mls.fastrealestate.net> Multi List Service</a>
Reply to this comment
by Isaac_U April 22, 2009 10:06 PM PDT
The Payday Loan Reform Act is now in getting infamous and well reported by those who have knowledge about the news, definitely with banks that will have market share on short-term credit and online cash advances. However, the Payday Loan Reform Act, currently making its way through Congress, has some critics, some of which are respectable business authorities, who insist that it will leave consumers with alternatives that aren't exactly palatable. Studies have indicated that at least 50% of payday loan users considered credit cards and other options first. This means that the same banks responsible for the financial collapse and recession stand to gain a monopoly through the <a rev="Vote for" title="Payday Loan Reform Act Leaves Customers with Bad Alternatives" href="http://personalmoneystore.com/moneyblog/2009/04/14/payday-loan-reform-act-leaves-customers-bad-alternatives/">Payday Loan Reform Act</a>, which is not a reform most people would be for if they thought about it.
Reply to this comment
(8 Comments)
  • prev
  • 1
  • next
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right