“This page provides information on the NCSC’s scanning activities. You may have been referred here by information left by one of our scanning probes if a system you own or administer has been scanned.”
So begins the UK’s National Cyber Security Center information page describing their new scanning program. In a blog post entitled “Scanning the Internet for Fun and Profit,” the NCSC describes the rationale for their program.
As part of an intelligence agency, the NCSC has to answer what they call “Grand Challenges”:
But the analyses we’ve published don’t answer the really hard questions, like ‘How vulnerable is the UK to cyber attack?’ or ‘Does HMG policy X have any impact on our security?’. Internally, we have a small number of ‘Grand Challenges’; research projects trying to find solutions to these really hard cyber security problems.
To answer these questions, they need better tools. As they put it, just “running regex over Shodan” isn’t enough. So they’re initiating their own scans:
During the 18 months or so that challenge has been running, we’ve made good progress using existing sources of data (including data from the ACD [Active Cyber Defense] services), but we’ve reached the limit of the utility of the commercial internet-scanning data we procure. Sometimes they don’t have the detail we need, or they’re not timely enough, or they don’t include specific IP ranges we need to look at.
Their scanning program is designed to overcome these deficiencies and help “respond to shocks” (a zero day).
It’s possible to opt out of scanning – see the information page.
What do you think about this kind of white hat scanning? I have to think that various intrusion detection systems are going to be firing alerts as a consequence which is noise that system owners need to deal with. Please share your thoughts in the comments below!
Related Posts:
- MetWeb has a 30% Off Deal on Cheap VPS Offers in Utah for Our Readers! - December 21, 2024
- Is Your Soul as Dark as a Christmas Stocking’s Coal?Make Your Online World Match - December 20, 2024
- Hosteroid has a HOT, Limited Stock Offer in Vienna or Amsterdam! - December 19, 2024
Leave a Reply