Einstein (US-CERT program)

For other uses, see Einstein (disambiguation).
EINSTEIN
Developer(s) US-CERT
Initial release 2004
Type network security and computer security
Website Analytical Tools and Programs at US-CERT for government users

Einstein (also known as the EINSTEIN Program) is an intrusion detection system that monitors the network gateways of government departments and agencies in the United States for unauthorized traffic. The software was developed by the United States Computer Emergency Readiness Team (US-CERT),[1] which is the operational arm of the National Cyber Security Division[2] (NCSD) of the United States Department of Homeland Security (DHS).[3] The program was originally developed to provide "situational awareness" for the civilian agencies. The first version examined network traffic while the expansion in development could look at content.[4]

Mandate

red white and blue striped booklet cover
The National Strategy to Secure Cyberspace (February 2003) featured the new cabinet-level United States Department of Homeland Security as the lead agency protecting IT.[5]

Einstein is the product of U.S. congressional and presidential actions of the early 2000s including the E-Government Act of 2002 which sought to improve U.S. government services on the Internet.

Einstein's mandate originated in the Homeland Security Act and the Federal Information Security Management Act, both in 2002, and the Homeland Security Presidential Directive (HSPD) 7,[1] which was issued on December 17, 2003.[6]

The Federal Computer Incident Response Capability (FedCIRC) was one of four watch centers that were protecting federal information technology[7] when the E-Government Act of 2002 designated it the primary incident response center.[8] With FedCIRC at its core, US-CERT was formed in 2003 as a partnership between the newly created DHS and the CERT Coordination Center which is at Carnegie Mellon University and funded by the U.S. Department of Defense.[7] US-CERT delivered Einstein to meet statutory and administrative requirements that DHS help protect federal computer networks and the delivery of essential government services.[1] Einstein was implemented to determine if the government was under cyber attack. Einstein did this by collecting flow data from all civilian agencies and compared that flow data to a baseline.

  1. If one Agency reported a cyber event, the 24/7 Watch at US-CERT could look at the incoming flow data and assist resolution.
  2. If one Agency was under attack, US-CERT Watch could quickly look at other Agency feeds to determine if was across the board or isolated.

On November 20, 2007, "in accordance with" an Office of Management and Budget (OMB) memo,[9] Einstein version 2 was required for all federal agencies, except the Department of Defense and United States Intelligence Community agencies in the executive branch.[10]

Adoption

Einstein was deployed in 2004[1] and until 2008 was voluntary.[11] By 2005, three federal agencies participated and funding was available for six additional deployments. By December 2006, eight agencies participated in Einstein and by 2007, DHS itself was adopting the program department-wide.[12] By 2008, Einstein was deployed at fifteen[13] of the nearly six hundred agencies, departments and Web resources in the U.S. government.[14]

Features

When it was created, Einstein was "an automated process for collecting, correlating, analyzing, and sharing computer security information across the Federal civilian government."[1] Einstein does not protect the network infrastructure of the private sector.[15] As described in 2004, its purpose is to "facilitate identifying and responding to cyber threats and attacks, improve network security, increase the resiliency of critical, electronically delivered government services, and enhance the survivability of the Internet."[1]

Einstein was designed to resolve the six common security weaknesses[1] that were collected from federal agency reports and identified by the OMB in or before its report for 2001 to the U.S. Congress.[16] In addition, the program addresses detection of computer worms, anomalies in inbound and outbound traffic, configuration management as well as real-time trends analysis which US-CERT offers to U.S. departments and agencies on the "health of the Federal.gov domain".[1] Einstein was designed to collect session data including:[1]

US-CERT may ask for additional information in order to find the cause of anomalies Einstein finds. The results of US-CERT's analysis are then given to the agency for disposition.[1]

Einstein 2

During Einstein 1, it was determined that the civilian agencies did not know what their IP space was. This was obviously a security concern. Once it was determined what an Agency's IP looked like, it was immediately clear that the Agency had more IP Gateways than could be reasonably instrumented and protected. This gave birth to the OMB's TIC, Trusted Internet Connections" Initiative. Three constraints on Einstein that the DHS is trying to address are the large number of access points to U.S. agencies, the low number of agencies participating, and the program's "backward-looking architecture".[17] An OMB "Trusted Internet Connections" initiative[9] was expected to reduce the government's 4,300 access points to 50 or fewer by June 2008.[18][19] After agencies reduced access points by over 60% and requested more than their target, OMB reset their goal to the latter part of 2009 with the number to be determined.[19] A new version of Einstein was planned to "collect network traffic flow data in real time and also analyze the content of some communications, looking for malicious code, for example in e-mail attachments."[20] The expansion is known to be one of at least nine measures to protect federal networks.[21]

The new version, called EINSTEIN 2, will have a "system to automatically detect malicious network activity, creating alerts when it is triggered".[22] Einstein 2 will use "the minimal amount" necessary of predefined attack signatures which will come from internal, commercial and public sources. The Einstein 2 sensor monitors each participating agency's Internet access point, "not strictly...limited to" Trusted Internet Connections, using both commercial and government-developed software.[23] Einstein could be enhanced to create an early warning system to predict intrusions.[17]

US-CERT may share Einstein 2 information with "federal executive agencies" according to "written standard operating procedures" and only "in a summary form". Because US-CERT has no intelligence or law enforcement mission it will notify and provide contact information to "law enforcement, intelligence, and other agencies" when an event occurs that falls under their responsibility.[23]

Einstein 3

Version 3.0 of Einstein has been discussed to prevent attacks by "shoot[ing] down an attack before it hits its target."[24] The NSA is moving forward to begin a program known as “Einstein 3,” which will monitor “government computer traffic on private sector sites.” (AT&T is being considered as the first private sector site.) The program plan, which was devised under the Bush administration, is controversial, given the history of the NSA and the warrantless wiretapping scandal. Many DHS officials fear that the program should not move forward because of “uncertainty about whether private data can be shielded from unauthorized scrutiny.”[25] Some believe the program will invade the privacy of individuals too much.[26]

Privacy

screenshot of a booklet PDF with seal and lettering
The Privacy Impact Assessment for Einstein version 2 describes the program in detail.[23]

In the Privacy Impact Assessment (PIA) for Einstein 2 published in 2008, DHS gave a general notice to people who use U.S. federal networks.[23] DHS assumes that Internet users do not expect privacy in the "To" and "From" addresses of their email or in the "IP addresses of the websites they visit" because their service providers use that information for routing. DHS also assumes that people have at least a basic understanding of how computers communicate and know the limits of their privacy rights when they choose to access federal networks.[23] The Privacy Act of 1974 does not apply to Einstein 2 data because its system of records generally do not contain personal information and so are not indexed or queried by the names of individual persons.[23] A PIA for the first version is also available from 2004.[1]

DHS is seeking approval for an Einstein 2 retention schedule in which flow records, alerts, and specific network traffic related to an alert may be maintained for up to three years, and if, for example in the case of a false alert, data is deemed unrelated or potentially collected in error, it can be deleted.[23] According to the DHS privacy assessment for US-CERT's 24x7 Incident Handling and Response Center in 2007, US-CERT data is provided only to those authorized users who "need to know such data for business and security purposes" including security analysts, system administrators and certain DHS contractors. Incident data and contact information are never shared outside of US-CERT and contact information is not analyzed. To secure its data, US-CERT's center began a DHS certification and accreditation process in May 2006 and expected to complete it by the first quarter of fiscal year 2007. As of March 2007, the center had no retention schedule approved by the National Archives and Records Administration and until it does, has no "disposition schedule"—its "records must be considered permanent and nothing may be deleted".[27] As of April 2013, DHS still had no retention schedule but was working "with the NPPD records manager to develop disposition schedules".[28]

It has been proposed that some privacy concerns might be mitigated if certain steps to bolster confidence are taken. For instance, through the creation of an independent committee to conduct, or be a party to, weekly summaries and periodic reviews, the improper handling of PII would be limited. Additionally, the incorporation of remedial action procedures based on the Department of the Navy’s (DON) PII breach reporting procedures, and the publication of a redacted, classified PIA, would remove many concerns about PII being improperly handled. New legal opinions, based on current EINSTEIN III program capabilities would also strengthen public belief that 1st, 4th and 5th amendment rights are being protected, and the use of exemptions found in the, Federal Communications Act, Title III, and FISA can be used to form the legal basis for the employment of EINSTEIN III.[29]

Additionally, the SECURE IT Act, and the Cybersecurity Act of 2012, could be modified to better define, cybersecurity threat indicators and/or cyber threat information, and provision within them that allows noncybersecurity information to be disclosed for law enforcement and national security purposes could be removed. Also, the Acts should include literature that states that all information obtained be used for cybersecurity related issues only, and that the NSA is prohibited from accepting and/or soliciting Cybersecurity information form private organizations and individuals. By doing so, the Department of Homeland Security would strengthen public confidence in their ability to moderate the trade-off between defending the nation’s system of computer networks, and protecting individual rights.[29]

See also

Notes

  1. 1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.8 1.9 1.10 US-CERT (September 2004). "Privacy Impact Assessment: EINSTEIN Program" (PDF). U.S. Department of Homeland Security, National Cyber Security Division. Retrieved 2008-05-13.
  2. "About US-CERT". U.S. Department of Homeland Security. Retrieved 2008-05-18.
  3. Miller, Jason (May 21, 2007). "Einstein keeps an eye on agency networks". Federal Computer Week (1105 Media, Inc.). Retrieved 2008-05-13.
  4. Lieberman, Joe and Susan Collins (May 2, 2008). "Lieberman and Collins Step Up Scrutiny of Cyber Security Initiative". U.S. Senate Homeland Security and Governmental Affairs Committee. Retrieved 2008-05-14.
  5. "The National Strategy to Secure Cyberspace" (PDF). U.S. government via Department of Homeland Security. February 2003. p. 16. Retrieved 2008-05-18.
  6. Bush, George W. (December 17, 2003). "Homeland Security Presidential Directive/Hspd-7" (Press release). Office of the Press Secretary via whitehouse.gov. Retrieved 2008-05-18.
  7. 7.0 7.1 Gail Repsher Emery and Wilson P. Dizard III (September 15, 2003). "Homeland Security unveils new IT security team". Government Computer News (1105 Media, Inc.). Retrieved 2008-05-16.
  8. "About E-GOV: The E-Government Act of 2002". U.S. Office of Management and Budget. Retrieved 2008-05-16.
  9. 9.0 9.1 Johnson, Clay III (November 20, 2007). "Implementation of Trusted Internet Connections (TIC), Memorandum for the Heads of Executive Departments and Agencies (M-08-05)" (PDF). Office of Management and Budget. Retrieved 2010-10-18.
  10. US-CERT (May 19, 2008). "Privacy Impact Assessment for EINSTEIN 2" (PDF). U.S. Department of Homeland Security. p. 4. Retrieved 2008-06-12.
  11. Vijayan, Jaikumar (February 29, 2008). "Q&A: Evans says feds steaming ahead on cybersecurity plan, but with privacy in mind". Computerworld (IDG). Retrieved 2008-05-13.
  12. Office of the Inspector General (June 2007). "Challenges Remain in Securing the Nation’s Cyber Infrastructure" (PDF). U.S. Department of Homeland Security. p. 12. Retrieved 2008-05-18.
  13. "Fact Sheet: U.S. Department of Homeland Security Five-Year Anniversary Progress and Priorities" (Press release). U.S. Department of Homeland Security. March 6, 2008. Retrieved 2008-05-18.
  14. Apart from 106 listings for "Website" or "Home Page", 486 listings appear in "A-Z Index of U.S. Government Departments and Agencies". U.S. General Services Administration. Retrieved 2008-05-18.
  15. Nakashima, Ellen (January 26, 2008). "Bush Order Expands Network Monitoring: Intelligence Agencies to Track Intrusions". The Washington Post (The Washington Post Company). Retrieved 2008-05-18.
  16. Office of Management and Budget (n.d.). "FY 2001 Report to Congress on Federal Government Information Security Reform" (PDF). Office of Information and Regulatory Affairs. p. 11. Retrieved 2008-05-14.
  17. 17.0 17.1 "Remarks by Homeland Security Secretary Michael Chertoff to the 2008 RSA Conference" (Press release). U.S. Department of Homeland Security. April 8, 2008. Retrieved 2008-05-13.
  18. Vijayan, Jaikumar (February 28, 2008). "Feds downplay privacy fears on plan to expand monitoring of government networks". Computerworld (IDG). Retrieved 2008-05-13.
  19. 19.0 19.1 Mosquera, Mary (July 10, 2008). "OMB: Agencies must shed more gateways". Federal Computer Week (Media, Inc.). Retrieved 2008-07-10.
  20. Waterman, Shaun (March 8, 2008). "Analysis: Einstein and U.S. cybersecurity". United Press International. Retrieved 2008-05-13.
  21. "Fact Sheet: Protecting Our Federal Networks Against Cyber Attacks" (Press release). U.S. Department of Homeland Security. April 8, 2008. Retrieved 2008-05-13.
  22. "E P I C A l e r t". 15.11. Electronic Privacy Information Center. May 30, 2008. Retrieved 2008-06-13.
  23. 23.0 23.1 23.2 23.3 23.4 23.5 23.6 US-CERT (May 19, 2008). "Privacy Impact Assessment for EINSTEIN 2" (PDF). U.S. Department of Homeland Security. Retrieved 2008-06-12.
  24. "Homeland Security seeks cyber counterattack system". CNN (Turner Broadcasting System). October 4, 2008. Retrieved 2008-10-07.
  25. Nakashima, Ellen (2009-07-03). "DHS Cybersecurity Plan Will Involve NSA, Telecoms". The Washington Post. Retrieved 2010-05-01.
  26. Radack, Jesselyn (2009-07-14). "NSA's Cyber Overkill: A Project to Safeguard Governmental Computers, Run by the NSA, is too Big a Threat to Americans' Privacy". Los Angeles Times.
  27. "Privacy Impact Assessment for the 24x7 Incident Handling and Response Center" (PDF). U.S. Department of Homeland Security. March 29, 2007. Retrieved 2008-05-14.
  28. "Privacy Impact Assessment for EINSTEIN 3 - Accelerated (E3A)" (PDF). U.S. Department of Homeland Security. April 19, 2013. Retrieved 2013-12-29.
  29. 29.0 29.1 Monterey, California. Naval Postgraduate School (March 2013). "Analysis of the United States Computer Emergency Readiness Team's (U.S. CERT) Einstein III intrusion detection system, and its impact on privacy" Oree, W.L.