A U.S. government computer security system that can detect and prevent cyber attacks should be extended to private businesses that operate critical utilities and financial services, a top Pentagon official said Wednesday.
William J. Lynn III, the deputy defense secretary, said discussions are in the very early stages and participation in the program would be voluntary. The idea, he said, would allow businesses to take advantage of the Einstein 2 and Einstein 3 defensive technologies that are being developed to put in place on government computer networks.
Extending the program to the private sector raises a myriad of legal, policy and privacy questions, including how it would work and what information — if any — companies would share with the government about any attacks or intrusions they detect.
Businesses that opt not the participate could “stay in the wild, wild west of the unprotected Internet,” Lynn told a small group of reporters during a cybersecurity conference.
And in the case of Einstein 2 — an automated system that monitors federal Internet and e-mail traffic for malicious activity — companies already may have equal or superior protections on their networks.
“Einstein 2 is like a 1999 Mustang with a little rust,” said James Lewis, a cybersecurity expert and senior fellow at the Washington-based Center for Strategic and International Studies. “For some companies it isn’t a big deal. But for others who haven’t done much (to secure their networks) it would be a good idea.”
Lewis said the larger challenges would come with Einstein 3, a separate program being developed which would detect and actively block or prevent cyber intrusions.
Einstein 2 is in place in at least 11 of the 21 government agencies that police their own networks. The other 89 federal agencies will go through one of four major technology contractors for the Einstein monitoring. Einstein 3…