
John E. Savage, a computer science professor at Brown University, testified before the U.S. Senate Committee on the Judiciary, Subcommittee on Crime and Terrorism on April 12 on “Cyber Security: Responding to the Threat of Cyber Crime and Terrorism.”
PBN: In your testimony, you highlighted statistics such as: “in 2009 U.S. citizens lost $560 million to computer fraud” and a report by PandaLabs which said 46.8 percent of computers worldwide were compromised.
For an expert in cybersecurity like yourself, you must be terrified to conduct even banking transactions online… are things really this bad? How has the situation gotten so dire?
SAVAGE: I am not terrified, but, yes, things are really this bad. Financial information, identities and corporate secrets are being stolen. The problem arose because security was not a primary concern when commercial software was first being written and computer networks designed and assembled. Once an industry has started to mature it is difficult to introduce a new element, such as security. To the credit of many companies, including those who are members of BSIMM (The Building in Security by Maturity
Model) they now recognize the importance of building in security and have instituted new practices to make their systems more secure.
Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting
Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…
Learn More
PBN: On your panel, Phyllis Schneck, chief technology officer McAfee Inc., and Stewart Baker Steptoe & Johnson LLP, also testified. What did you find most interesting about their presentations?
SAVAGE: In her testimony, Dr. Schneck drew our attention to her long history of involvement in cybersecurity. This shows that some farsighted computer scientists have long been concerned with this topic. However, the rest of us, including the computer industry, have been relatively slow in changing their practices to take security into account. Only when the problem became serious did they start to make changes. One can argue, as I did in my Congressional testimony, that not enough is being done, the reason being primarily cost. Security is not cheap. Vendors naturally make estimates of how much to spend on security based on the risks they incur by not doing more. An educated public, elected officials and businesses need to participate in a dialogue concerning the importance of providing high levels of security. Then, legislators should draft legislation to help reach that level of security.
I also found it interesting to learn about the two technologies that McAfee has developed, whitelisting and global threat intelligence. The former is a tool that an administrator deploys to allow only pre-approved applications to run on a computer. The latter is a system to collect reputational information about web sites globally and then use it in a browser to warn users when they are about to visit a dangerous site.
In his testimony, Mr. Baker highlights the seriousness of the cybersecurity problem by presenting and then addressing a set of myths that many of us hold about computing, such as, that a) security is just a Microsoft problem (he cites a recently-discovered, eight-year old security flaw in Linux), b) really important transactions can be confirmed offline (air-gapped computers have also been penetrated), c) if things get bad, we can just disconnect our computers (if the infected computers are needed to download flight plans, an air force cannot fly), and d) they are not looking for me (malware can detect if you have more than a minimum net worth). Mr. Baker is more pessimistic than I am about finding solutions to the cybersecurity problem. I also found myself disagreeing with a key element in his proposed approach, namely reducing or eliminating anonymity in cyberspace. We do need e-cash, the equivalent of cash on the Internet, which allows transactions to occur via a third party who hides the identity of the purchaser from the vendor. This would not be possible if there was no anonymity.
PBN: What do you hope will result from the hearing?
SAVAGE: I am hopeful that hearing will raise the awareness of the severity of the cybersecurity problem and will lead to legislation that will begin to address it.
PBN: You also spoke about the importance about putting together software standards that large vendors should be required to meet. What kind of role do you think government should ideally play in enforcing cybersecurity measures in private sectors?
SAVAGE: The government can serve as a facilitator in developing cybersecurity standards. It may be necessary for government to be somewhat coercive in bringing the private sector to the table. However, setting detailed standards should be done with the involvement of the private sector. Governments lackthe expertise to set such standards themselves.
PBN: As a computer science professor at Brown University, you work with students that could one day be the future “cyber guardians” of the U.S. How would we stack up internationally? Should we be investing more resources in recruiting and educating a larger work force for this task?
SAVAGE: Although the programmable computer, a mechanical machine, was invented by Babbage, an English scientist, the U.S. did invent the electronic digital computer and has played the leading role in its development and commercialization. The Internet was invented and developed in the U.S. by the Defense Advanced Research Agency, a DoD research arm, during the Vietnamese War. The elegance of its design and its ease of deployment led to rapid adoption of the technology worldwide. With the development of the browser in Switzerland, the World Wide Web emerged which led to the creation of an enormous amount of web-based material and its universal adoption.
The U.S. continues to lead in understanding, developing and deploying computer and networking technology worldwide. However, experts in these technologies exist all over the world. In fact, China now has the world’s second largest electronics company, Huawei Electronics, founded as recently as 1987.
The U.S. must increase its investment in the science and engineering of computer and network security. We must deploy proven methods of making our systems secure while at the same time we conduct research to address the hard problems for which we don’t have solutions.
We must also educate generations of students who understand both the technology and policy issues of cyberspace. The cybersecurity problems that are faced by all nations are serious and require new international commitments to find solutions to them.












