Corero response to the Joint Committee on the National Security Strategy’s inquiry ‘Cyber Security: UK National Security in a Digital World’

 

About Corero

Corero Network Security plc (“Corero”) is a leading UK cyber-security SME that provides specialist real-time, automatic Distributed Denial of Service (DDoS) mitigation and protection solutions. Organisations that rely on Internet availability to conduct business use Corero’s award-winning technology to protect themselves against DDoS attacks – in many cases mitigating threats in less than a second.

 

Introduction

  1. Corero welcomes the opportunity to respond to the Joint Committee on the National Security Strategy’s inquiry into cyber-security and UK critical national infrastructure (CNI), and welcomes the Committee’s focus on this important area. As a leading and specialist provider of real-time, automated DDoS mitigation technologies, Corero is well placed to inform the Committee of the nature of the DDoS threat facing the UK’s CNI. Unlike many cyber-security companies, Corero focuses exclusively on providing DDoS mitigation solutions and therefore has a high level of expertise on this form of threat to CNI. Furthermore, as a company that has engaged previously with Government bodies (e.g. NCSC, NCA) and Parliament on cyber-security issues (including through offering free use of Corero’s DDoS mitigation technologies at the time of the 2017 General Election), we have several recommendations on the UK Government’s approach to the protection of CNI from cyber-threats and its approach to cyber-security more broadly.
  2. Before referring to the terms of reference set out by the Committee, this response will provide some background on the evolving nature of DDoS attacks, as observed by Corero, and set out the findings of a series of recent FoI requests issued by Corero to a large number of critical infrastructure organisations.

 

About DDoS – An evolving threat

  1. Distributed Denial of Service attacks come in various forms, all of which are highly disruptive to the victim organisation and negatively impact the ability to deliver critical services.
  2. The most common form of DDoS attack is the volumetric attack. This typically consists of an attacker overloading a website with unwanted traffic, often through a network of compromised computers (known as a botnet) or through leveraging existing services that are part of the Internet. The overwhelming volume of requests then forces a website or network offline.
  3. The broad range of motivations for executing a DDoS attack, coupled with the relative ease with which they can be performed, means that they are carried out by a variety of actors, including criminal gangs, activists, terrorist groups and nation state “bad actors”. Aside from those who are focused purely on disrupting services, many of those who carry out DDoS attacks do so as a form of extortion or as a smokescreen to steal data, map other vulnerabilities, or plant malware or ransomware.
  4. Both businesses and public-sector organisations are vulnerable to DDoS attacks and recent years have seen some of the world’s best-known companies fall victim, with notable UK examples including TalkTalk, BBC and HSBC. Similarly, the vulnerability of Government services was highlighted in October 2016 when Dyn, a company that provides DNS services to some of the world’s largest digital brands was subject to a DDoS attack, resulting in downtime for a range of Government services.
  5. Corero continues to observe an increase in the level of DDoS attacks. Our latest trends report observed a jump in the frequency of attack attempts of 35% in Q3 2017 when compared with Q2 2017[1]. Whilst the increased frequency of attempted attacks is concerning, it is important also to recognise the evolving nature of DDoS attack in terms of volume and duration. Whilst large volume attacks tend to gather a great deal of press attention, these are atypical and Corero would like to highlight to the Committee the level of the threat posed to CNI from frequent, modest-sized, short duration attacks. This form of attack often goes undetected and unmitigated by organisations causing service outages, and leaving the victim vulnerable to other forms of cyber-threat. In Q3 2017, Corero found that 96% of DDoS attacks were less than 5Gbps in volume and 71% were 10 minutes or less in duration (up from 65% in Q2).

 

Freedom of Information requests reveal inadequate DDoS protections amongst CNI operators

  1. In summer 2017, Corero published the findings of a series of 338 Freedom of Information (FoI) requests to UK critical infrastructure organisations, ranging from fire and rescue services, police forces, ambulance trusts, energy suppliers and transport organisations. The data obtained revealed a significant lack of preparedness, with 39% of organisations revealing they had not completed the National Cyber Security Centre’s ’10 Steps to Cyber Security’ programme – among responses from NHS Trusts, this figure rose to 42%. Even more alarmingly, the requests found that 51% of critical infrastructure organisations are potentially vulnerable to short duration, low volume ‘stealth’ DDoS attacks due to failures to deploy technology which can detect or mitigate such attacks.
  2. Both as a general point and specifically in relation to the implementation of the Network and Information Systems (NIS) Directive, Corero would urge the Committee to explore what steps the Government is taking to ensure CNI operators are deploying appropriate technologies to mitigate stealth DDoS attacks.

 


The opportunity for the UK to lead the world in its approach to the cyber-security of CNI

  1. In March 2017, the Government’s Digital Strategy was published and included a chapter on how the Government intends to make the UK ‘the safest place in the world to live and work online’. Corero welcomes the Government’s admirable ambition in this space but would urge further action to ensure that this is ambition becomes a reality.
  2. More specifically, Corero would like to highlight the opportunity provided by the UK’s implementation of the Network and Information Systems (NIS) Directive. Corero believes that the Government must use this opportunity to set out a framework of minimum standards for CNI that should be met. However, Corero would encourage Government not to view the implementation of the Directive as a mere tick box exercise where the bare minimum is done, and instead embrace the opportunity for the UK to set world leading standards in this area. Almost by definition, these standards should be at a sufficient level such that CNI organisations can remain fully operational during all but the most extreme cyber-attacks. It is also essential that measured, but robust, enforcement of penalties is adopted to ensure that cyber-security standards are improved and, more broadly, the UK's cyber-security culture is improved. Furthermore, given the growing cyber-threat facing the nation, it is important that such an enforcement regime is adopted as quickly as possible.
  3. As a company with a significant presence in the United States of America, Corero is well placed to highlight how the UK Government could learn from the approach adopted by the US Government. Corero believes that the UK Government should consider the US’ adoption of a more attack-specific and specialist-led approach.
  4. To provide an example of this, in May 2017, the US President issued Executive Order 13800 “Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure,” calling for “resilience against botnets and other automated, distributed threats” and directing the US Secretary of Commerce and the US Secretary of Homeland Security to lead in identifying and promoting actions to reduce threats perpetrated by automated and distributed attacks. The Departments have subsequently begun drafting a report for the President through an open and consultative process which draws on a range of expert stakeholders from industry, academia and civil society[2]. The draft report - which was produced following a workshop, request for comment and an inquiry through the US President’s National Security Telecommunications Advisory Committee (NSTAC) - explores the nature of the automated and distributed threat to US infrastructure in depth, before then setting out detailed recommendations on how to boost resilience and ensure suitable protections and mitigation systems are deployed. Corero urges the Government to perform similar in-depth reviews of the threat posed to UK CNI by specific types of cyber-attack, including DDoS, and to adopt a process for doing so which is similarly consultative and draws from a wide range of expertise.

 


The effectiveness of Government strategy, Departments and agencies

  1. Corero enthusiastically welcomes the Government’s increased focus on cyber-security in recent years, including the publication of the new Cyber Security Strategy in 2016, which included the foundation of the National Cyber Security Centre and was accompanied by significant investment.
  2. Corero does, however, feel that departmental responsibility for cyber-security needs to be clearer. Whilst it is understandable - given the nature of both 21st Century life and the threat facing the UK - that all government departments and agencies want a role in the cyber-security landscape, industry currently lacks clarity on which bodies to liaise with when attempting to share expertise. Corero would urge Government to set out with more clarity how departmental responsibility is divided and make sure these divisions are adhered to.
  3. Regarding the work of the National Cyber Security Centre, Corero believes the NCSC is well placed to act as a single point of contact with industry on cyber-security matters and is pleased to have engaged with the body and developed a strong working relationship. Corero would encourage Government to allocate further resource to the NCSC to ensure they can build on the excellent work they have completed since their foundation and ensure that they can continue to draw on the expertise of the UK’s cyber-security industry. 

 

Recommendations and conclusion

  1. In summary, Corero welcomes the investment and attention that the Government is committing to the cyber-security of CNI, but would recommend the following actions are taken to ensure the UK leads the world in this area:

 

  1. Corero would welcome the opportunity to provide further information to the Committee in the form of either written or oral evidence.

[1] Corero, Corero DDoS Trends Report Q2-Q3 2017

[2] United States Department of Commerce and Department of Homeland Security, Draft Report to the President on Botnets and Other Automated, Distributed Threats, 2018