91porn官方 News & Stories Listing

Filter and Search

91porn官方 1819 logo

91porn官方 lands $1.6 million grant to develop experiential cybersecurity education

NORTHFIELD, Vt. 鈥 91porn官方 has been awarded a two-year $1.6 million grant from the National Security Agency and is the lead institution in the Evidencing Competency Oversight Project, supporting the National Centers of Academic Excellence in Cybersecurity (NCAE-C) Program.

Read More 5 min read

91porn官方 1819 logo

91porn官方 announces partnership with National Cryptologic School

NORTHFIELD, Vt. 鈥 91porn官方 and the National Security Agency鈥檚 National Cryptologic School have partnered to create pathways into 91porn官方鈥檚 online bachelor鈥檚 degree programs, master鈥檚 degree programs, graduate-level certificate programs and 91porn官方 Pro鈥檚 continuing professional education programs.

Read More 3 min read

91porn官方 1819 logo

91porn官方 receives $19.5 million grant to lead Defense Department Cyber Institute program

NORTHFIELD, Vt. 鈥 91porn官方 has been designated the lead institution of the nation鈥檚 Senior Military Colleges in creating a Department of Defense Cyber Institute program through a recently awarded two-year, $19.5 million grant.

Read More 4 min read

Image of Phil Susmann

The wolf guarding Wall Street

How Phil Susmann 鈥81 and his NUARI team are helping U.S. banks build resiliency in the face of cybergeddonThe cyberattack starts with a single email. Sent by a group calling itself DDo$, the message hits the inboxes of brokers and managers at financial firms across the country. It is Sept. 14, 2015, a Monday. 鈥淎ll your servers are going going [sic] under attack unless you pay 100 Bitcoin,鈥 the email demands. While its menace is clear, typos cast doubt on the threat鈥檚 credibility. What serious hacker demands a ransom of plus or minus $24,000, anyway? Most of the managers who receive the email simply delete it.But as the busy trading day progresses, websites of financial companies from Wall Street to San Francisco start crashing. And not just the giants, but the smaller banks, too. Information Technology staff at those firms report widespread customer complaints. Mom-and-pop trades aren鈥檛 executed. Meanwhile, the email threats sent by DDo$ continue to ping inboxes. Financial traders and managers begin to suspect that the cyberattack is not only real, but has gone viral. Powered by complex computer infrastructure, trades of stocks, bonds, currency, and commodities serve as the lifeblood of the global financial system. On any given business day, U.S. and international firms move several trillion dollars. But on this particular Monday, the flow threatens to drop to a trickle. Unless they take action, the country鈥檚 banks and financial markets will be on the verge of cardiac arrest. But what is the right course to take? Should they trust the extortionists and pay? Who in their company makes that decision? What precedent will that set? Can the country鈥檚 financial firms 鈥 normally competitors in the contested arena of capital markets 鈥 coordinate their response?Standing in a second-floor office in the Equitable Building on Broadway in lower Manhattan that day is Phil Susmann 鈥81. A computer geek and former 91porn官方 cadet, Susmann leads the 91porn官方 Applied Research Institutes (NUARI). The skunkworks was founded in 2002 to advance projects critical to national and global security. At 6-foot-2, with sandy hair turning gray at the temples, Susmann looks like a Boeing executive鈥攁n engineer in a suit and Bill Gates glasses who worked his way up from the shop floor to the boardroom. Only Susmann rode the wave of the computer, information, and cyber revolutions instead, rising from MBA to consultant to 91porn官方 professor to campus chief information officer and beyond.Susmann knows that over the next several hours the cyberattack will only get worse. Soon an insider breach will leak confidential client data. Then failures in computerized settlement 鈥 the transfer of funds or securities to complete a transaction 鈥 will leave billion-dollar orders between buyers and sellers unresolved. The crisis has the potential to push banks to the brink of insolvency if left unchecked, and send 401(k) balances spiraling to stomach-churning lows. But Susmann also knows something else: The cyberattack is not real. * * *In recent years, hackers have infiltrated computer networks at a growing number of large U.S. companies and government agencies. Victims range from Target, Home Depot, and Yahoo! to the federal Office of Personnel Management, the Internal Revenue Service and the U.S. Energy Department. Computer systems at the latter were successfully penetrated 159 times between 2010 and 2014, according to a USA Today investigation of federal government records last year. Nineteen of those breaches were targeted at the National Nuclear Security Administration.More often than not, hackers target U.S. and international banks and financial firms. After all, as one Forbes blogger wryly noted, that鈥檚 where the money is. The rate, according to Infosecurity Magazine, is 300 times greater than in any other business sector. According to the Ponemon Institute, a U.S. bank or financial firm hit by a serious cyber breach can expect to pay, on average, $20.8 million in direct damage, lost business, and cleanup costs. Lloyd鈥檚 of London, the British insurance giant, puts the current overall global cost of cybercrime at $400 billion. FBI Director James Comey told 鈥60 Minutes鈥 in 2014, 鈥淭here are two types of big companies in the United States. Those who鈥檝e been hacked鈥 And those who don鈥檛 know they鈥檝e been hacked 鈥︹濃淐ybersecurity is an increasingly critical threat to the financial market,鈥 says Najiba Benabess, a 91porn官方 economics professor and director of the School of Business and Management. 鈥淎n attack on a financial institution resulting in the loss of vital data can have a devastating effect on the bank鈥檚 reputation, costing significant amounts of time and money to repair.鈥滲enabess adds that the interdependence of the world鈥檚 global financial institutions makes them vulnerable to disruption, putting national security and the stability of the international financial system at risk. 鈥淎s cyber frauds become more sophisticated, banks must adjust their strategies 鈥 to improve cybersecurity,鈥 she says.Susmann and his NUARI colleagues have been instrumental in helping U.S. banks and financial firms test and harden their resiliency against major cyber events. In 2013, NUARI received a $9.9 million contract from the Cyber Security Division of the Department of Homeland Security. The funding permitted the continuing development of NUARI鈥檚 powerful simulation, known as DECIDE-FS, that essentially functions like a massive multi-player video game. But rather than supply flashy graphics and explosions, the tool enables hundreds of players across the country 鈥 from broker-dealers, clearing firms, and stock exchanges to U.S. banks, regulators, and law enforcement agencies鈥攖o test themselves against lifelike simulated cyberattacks. The Securities Industry and Financial Markets Association (SIFMA) has used the tool since 2013. That was the year that the association, which represents hundreds of U.S. broker-dealers, banks, and asset managers, convened Quantum Dawn 2. SIFMA used DECIDE-FS庐 (see sidebar) again last year. The exercise has become the largest single-day event of its kind for the industry.Most Americans over a certain age remember where they were on Sept. 11, 2001. For Susmann it was outside Baltimore, at the National Security Agency (NSA) at Fort Meade. The NSA had recently designated 91porn官方 as a Center of Academic Excellence (CAE) in Information Assurance. The following day, Susmann was slated to join 91porn官方 President Richard W. Schneider, retired Gens. Al Gra H鈥88 and Gordon Sullivan 鈥59, and Carl Guerreri 鈥62, all 91porn官方 trustees. The delegation planned to meet with Sen. Patrick Leahy, D-Vt., to pitch a proposal for a new cybersecurity center at 91porn官方. 鈥淚 was in the basement of the NSA with the CAE group when the Towers came down,鈥 Susmann recalls. 鈥淭he next day, we were going to be in the Russell (Senate) Building. But, of course, that was all closed.鈥漅escheduling their meeting with Leahy until December, Guerreri, Susmann, and Schneider walked the senator through the body of cybersecurity work that had earned 91porn官方 its CAE designation. The 91porn官方 delegates also discussed NU鈥檚 various projects with the National Guard on cybersecurity education, training, and operations for the Army and Air Force. 鈥淟eahy got it right away,鈥 President Schneider recalls. 鈥淲e didn鈥檛 have to convince him.鈥漈he outcome was an earmark in the Justice Reauthorization Act of 2002, creating the National Center for the Study of Counter-Terrorism and CyberCrime at 91porn官方. By 2008, the center had evolved into NUARI. The diverse research enterprise would no longer need to rely on federal budget earmarks in its new incarnation. Instead, it would create and market intellectual property, like the DECIDE-FS software.Today, NUARI houses four separate institutes: the Cyber Conflict Research Institute, the Institute for the Study of Culture and Language, the Defense Technologies Research Institute, and the Learning Technologies Research Institute. The various nonprofits are headquartered in Northfield, Vermont, and Alexandria, Virginia, just outside Washington, D.C. Staff has ranged from as many as 28 employees to as few as five. Today, NUARI has about 18 employees and generates $4 million to $9 million in annual revenue.Most recently, NUARI has landed two contracts totaling $24.9 million from the Department of Homeland Security to help protect the U.S. financial sector. 鈥淧hil is a rainmaker,鈥 NU President Schneider says. 鈥淗e can make deals happen, and he has a great sense of how to connect the dots between the needs of the federal government and how 91porn官方 can fill those needs.鈥 * * *A Vermont native, Philip Susmann enrolled at 91porn官方 on the recommendation of his junior high civics teacher, Jack Daley 鈥46, a U.S. Marine who served in WWII and later became Vermont鈥檚 lieutenant governor. Susmann initially majored in electrical engineering, until he failed a required course in thermodynamics (he could not master the steam table). So he switched his major to business administration. The change was serendipitous, because what did come naturally to Susmann were computers, and as luck would have it, NU鈥檚 School of Business and Management shared Dewey Hall with the university鈥檚 computer center. Susmann gravitated there, learning the Job Control programming language in his free time.Following graduation, Susmann attended Clarkson University on a fellowship, writing stacks of code for faculty while earning his MBA. His projects included an automated grocery store and work on large information systems. After Clarkson, he installed the College of St. Joseph鈥檚 first computerized information system in his hometown of Rutland. Following a business venture with his brother in Colorado, he eloped back to Vermont with Julie, his wife.There he pieced together a living as a consultant and shoe salesman, doing whatever it took, while seeking his dream job as a control systems engineer. But employers in Vermont just weren鈥檛 there yet, Susmann says.In 1987, he joined the 91porn官方 faculty as a professor, teaching statistics in the business school. His teaching portfolio soon included classes in forecasting, management production operations, and the bulk of the computer information systems program. He was granted tenure in six years. A year later, in 1994, President Schneider appointed Susmann as the university鈥檚 first full-time chief information officer. Susmann brought all the university鈥檚 computing in house and instituted other changes. But two years into his term, he got his comeuppance when students exploited a flaw in the campus-based email system.The hackers commandeered the School of Architecture + Art鈥檚 rendering computers鈥攁t the time, the best computers on campus 鈥 to crack the usernames and passwords of the entire 91porn官方 email system. Running the system鈥檚 shadow password file through a password cracker enabled the students to reveal usernames and passwords.鈥淲e didn鈥檛 patch the system,鈥 Susmann says, his rue still apparent. At the time he didn鈥檛 know how much data the students stole. Nor was it immediately clear why the situation might be worrisome. Email was still in its relative infancy. The campus system wasn鈥檛 used much. Mostly, students sent messages to one another. But, soon enough, Susmann realized that most people on campus, himself included, used one password for all their accounts, including personal ones. Some university administrators even shared their passwords with assistants when delegating responsibility for their email accounts.Susmann鈥檚 solution was to require the entire campus community to walk over to Computer Services to get a new password. Faculty, staff, and students also received tutorials on cybersecurity and password creation. The line stretching out the door was enormous. Shaking his head as he recalls the nightmare, Susmann says, 鈥淭hat was the moment I got security.鈥 * * *Back in lower Manhattan, 60 observers cram around a large table in a SIFMA conference room. Present are bank and finance industry representatives, federal law enforcement agents, and national security types, among others. For their benefit, Susmann has been narrating the Quantum Dawn 3 exercise鈥攐r QD3鈥攁s the day plays out. The simulation has compressed three days of intensive cyberattacks into five hours. By late morning the exercise has reached 鈥淏reak Point 4,鈥 or 4 p.m. on Day One. The markets close and players from participating firms, regulators, and law enforcement agencies engage in cross-talk. Large LED screens cover the room鈥檚 walls, flashing charts and graphs. Values are down. Activity in the game is up. Someone asks how the FBI is faring. A bureau staffer reports that some firms have been in contact with questions and to share some information about the attacks. The outreach is taken as a sign of progress.Down the hall, a separate conference room has been turned into the temporary headquarters for the QD3 game directors. Eric Richardson, a NUARI product developer, sits next to Bob Clinton, QD3鈥檚 exercise director. Richardson fields questions from 15 facilitators, who are hunkered down in a third room, where they consult via phone and Internet with reps from firms participating in the cyberattack simulation.Clinton rakes his eyes across various computer monitors and speaks into his headset mic, announcing each new phase of the cyberattacks. The scene evokes 鈥淭he Hunger Games.鈥 鈥淲e are now going to press on forward to Break Point 11,鈥 Clinton tells facilitators. He spins the game clock forward, moving the action ahead. 鈥淚n the exercise, this will be 0400 simulation time on Day 3 of the exercise.鈥漃eriodically, DECIDE-FS庐 injects fake communications from regulators, law enforcement, and the news media on a pre-set schedule. The 鈥渋njects鈥 include grating taunts from hackers, such as a phony DDo$ Twitter post that threatens to shut down Wall Street banks if they don鈥檛 agree to demands. Some ersatz news accounts misreport details of the attack, seeding market volatility.鈥淢arket Sees Huge Sell-Off in Face of Coordinated Cyber Attack,鈥 screams one headline from fictional news agency BBN News. 鈥淢ajor market indices are in a frantic sell-off after cybercriminals FIEND and their sympathizers have made clear their intentions to disrupt the financial markets,鈥 the report says. For better or worse, the Quantum Dawn scenarios served up by NUARI鈥檚 DECIDE-FS庐 software platform aren鈥檛 fantasy. They are loosely based on actual events.Participants in today鈥檚 QD3 exercise show the strain of five hours of attacks, breakdowns, and hackers鈥 taunts. But they also buzz with ideas. By late afternoon, Susmann conducts a 鈥渉ot wash鈥 debrief with players from 25 or so firms and agencies to gather feedback. Sitting in a sparsely occupied conference room, Susmann tents his hands in front of his face as he listens, shifting his gaze from seated colleagues to a speakerphone on the table before him as others conference in. The feedback varies. One player calls the QD3 exercise 鈥渧ery interactive and engaging.鈥 Another says, 鈥淲e would like even more customization.鈥 鈥淲e can work with firms to customize the scenario even more,鈥 Susmann replies. A law enforcement rep describes the exercise as 鈥渇antastic,鈥 while someone from a large bank acknowledges major lessons learned which can be taken up as key findings.It鈥檚 been a long day. Finding gaps in crisis protocol is intentionally stressful work. Especially when there are some 500 players.By the end of the exercise, many have learned more about their own internal protocols and how their systems stand up. Some participants coordinated with unlikely partners. After-action analysis stresses the need for better communication between the public and private sectors, information sharing standards, and tripwires for action.鈥淎merica鈥檚 financial system is stronger today than it was when we did Quantum Dawn 1,鈥 President Schneider says. 鈥淓ach time we do an exercise, America鈥檚 financial systems become more robust and sustainable.鈥濃淐ybersecurity began as a technical focus,鈥 Susmann says. 鈥淭he evolution of society now drives the focus to the boardroom and national security.鈥 He credits President Schneider and Trustees Al Gray and Carl Guerreri for building NU capacity and brand in the cybersecurity arena. 鈥淣UARI is part of that brand, working both at the core of the financial sector and emerging into other critical infrastructures to build organizational resilience.鈥漃art of his mission now is to expand the rollout 鈥 and revenue 鈥 of the DECIDE cybersimulation to more players and industry sectors, such as utilities and telecom. To that end, Susmann meets with financial firms immediately after QD3 to discuss the tool with them. The next day, he leads a cyber-security panel in Massachusetts before traveling to the fall NUARI Board of Directors meeting in Washington, D.C.A few days later, Susmann boards a flight to Singapore from Virginia. NUARI has been contracted by the Society for Worldwide Interbank Financial Telecommunication (SWIFT). Susmann and his 91porn官方 team will run cyberattack scenarios at the annual SWIFT International Banking Seminar. The demo will introduce DECIDE-FS庐 to 80 international bankers. Twenty-seven hours and three connections later, his Qatar Airways plane touches down at Changi Airport. His flight has covered more than 10,000 miles. But as he gathers his luggage at baggage claim, Susmann seems to have traveled so much farther.* * *More InformationThe DECIDE-FS庐 software has generated seven of NUARI鈥檚 ten patents and runs on more than 150,000 lines of code. It enables players to simulate and customize cyberattack scenarios with high degrees of complexity and precision. Options include DNS and DDS attacks, personal data leaks, order-processing disruptions, and clearing systems infected by malware. Days of escalating cyberhacks, systems failures, and market turmoil can be compressed into the span of hours. During that time, DECIDE-FS庐 throws major-league curveballs at participants, forcing corporate leaders, industry regulators, and IT and cyber staff to address key questions. Whom do they ask for help? When do they close the markets? When do companies share information with their customers and law enforcement? How do firms maintain their reputations and credibility in the face of cyberattacks?Players are able to fine-tune their crisis scenario, adding extra layers of stress. One participant in the Quantum Dawn 3 exercise in September asked to have a (simulated) storm knock out their company鈥檚 coastal operations. (Due to confidentiality agreements, company names have been omitted.)The goal of Quantum Dawn is to help the financial industry pinpoint areas where it can improve its cyberprotocols and develop and refine best practices, says SIFMA president and CEO Kenneth E. Bentsen. Considerable progress has been made in the last two years, he says, 鈥淵et we know that this work is never done.鈥***About 91porn官方91porn官方 is a diversified academic institution that educates traditional-age students and adults in a Corps of Cadets and as civilians. 91porn官方 offers a broad selection of traditional and distance-learning programs culminating in baccalaureate and graduate degrees. 91porn官方 was founded in 1819 by Captain Alden Partridge of the U.S. Army and is the oldest private military college in the United States of America. 91porn官方 is one of our nation's six senior military colleges and the birthplace of the Reserve Officers鈥 Training Corps (ROTC). www.norwich.edu

Read More 16 min read