• Comment (12)

U.S. Nukes Face Up to 10 Million Cyber Attacks Daily

The head of the National Nuclear Security Administration is calling for a budget increase in order to enhance security

March 20, 2012 RSS Feed Print
Thomas D'Agostino of the National Nuclear Security Administration looks at a device that detects radiation at the Yangshan Port in Shanghai.

Thomas D'Agostino of the National Nuclear Security Administration looks at a device that detects radiation at the Yangshan Port in Shanghai.

The computer systems of the agency in charge of America's nuclear weapons stockpile are "under constant attack" and face millions of hacking attempts daily, according to officials at the National Nuclear Security Administration.

Thomas D'Agostino, head of the agency, says the agency faces cyber attacks from a "full spectrum" of hackers.

[READ: Scientists With Nuclear Testing Experience Rapidly Dwindling]

"They're from other countries' [governments], but we also get fairly sophisticated non-state actors as well," he said. "The [nuclear] labs are under constant attack, the Department of Energy is under constant attack."

A spokesman for the agency says the Nuclear Security Enterprise experiences up to 10 million "security significant cyber security events" each day.

"Of the security significant events, less than one hundredth of a percent can be categorized as successful attacks against the Nuclear Security Enterprise computing infrastructure," the spokesman said—which puts the maximum number at about 1,000 daily.

The agency wants to beef up its cybersecurity budget from about $126 million in 2012 to about $155 million in 2013 and has developed an "incident response center" responsible for identifying and mitigating cyber security attacks.

In April of last year, the Department of Energy's Oak Ridge National Laboratory was successfully hacked and several megabytes of data were stolen, D'Agostino said. Internet access for workers at the lab was disconnected following the breach.

[PHOTOS: Iran Participates in War Games]

Adam Segal, a cybersecurity expert with the Council on Foreign Relations, says it's likely that a majority of those 10 million daily attacks are automated bots that "are constantly scanning the Internet looking for vulnerabilities."

"The numbers are kind of inflated on that front," Segal says, adding that it's extremely unlikely that hackers would be able to remotely launch a nuclear warhead, because those systems are "airgapped" or disconnected from standard internet systems. But the Stuxnet computer worm, discovered in 2010, was widely spread to supposedly-secure uranium enrichment plants in Iran, Indonesia and India, shutting those systems down.

[DEBATE: Should the U.S. Use Military Action to Hinder Iran's Nuclear Plan?]

The NNSA says they are not aware of any viruses or malware that could remotely launch a nuclear warhead, but the "Stuxnet worm is a very real example of how sophisticated malware can cause physical damage to industrial systems."

Segal says Stuxnet was a lesson—no matter how secure a computer system appears to be, it can be breached. Many experts said the worm was so sophisticated that it had to have been developed by a team of hackers associated with a national government.

"Stuxnet showed that airgapping is not a perfect defense," Segal says. "Even in secure systems, people stick in their thumb drives, they go back and forth between computers. They can find vulnerabilities that way. If people put enough attention to it, they can possibly be penetrated."

D'Agostino said with the agency facing so many hacking attempts, its employees have to remain vigilant.

"All it takes is one person to let their guard down," he said. "This is going to be, in my view, an ever-growing area of concern."

Segal says any successful hackers would likely have to have an intimate knowledge of the programming languages used by the Department of Energy.

"There'd probably have to be a state-based actor behind it. You have to understand a lot about the systems," he says. "Hacking into the Department of Energy and looking for nuclear secrets—how to build a bomb, is probably much easier than trying to take over a bomb or a launch code, and probably of more interest to the Russians or the Chinese or the Iranians."

 

Tags:
nuclear weapons,
computers

Reader Comments Read all comments (12)

Add Your Thoughts
Your comment will be posted immediately, unless it is spam or contains profanity. For more information, please see our Comments FAQ.

I see so many flags in all these US Government related stories. For instance, in this particular case AND the North Korea nuclear weapons case it would not surprise me if the United States government is attempting to pre-plant the idea that we could be attacked into the people's heads. They then would proceed to attack us, and all the while, hide it and make it seem like it's a foreign threat. They would declare Marshall Law to "protect us", then push their gun ban agenda and so forth. I may sound like a nut... but trust me.. I know how these tyrant American leaders these days are. I've had experience with this. They'll do ANYTHING for control and power.

Anonymous of WA 3:38PM February 05, 2013

There is no need for these systems to be connected to the internet. No connection eliminates most if not all of these attacks, it is not rocket science.

-BTW I am not just some schmoe chiming in either I have a great deal of experience in Info Sec. at the federal and international level.

Mike of MD 8:29AM April 05, 2012

Um they are asking for these kind of hacks. Wth would they even connect servers with this kind of information to the world wide web? that makes no sense at all...

Adam of OH 12:54PM March 28, 2012

Photo Galleries

Women on Death Row

Only 12 women have been executed on death row in the U.S. since 1976.

advertisement

Latest Videos