GCN Home > 04/14/08 issue
Countdown to 50
Agencies hustle to prepare their networks for a drastic reduction of Internet gateways
By John Rendleman
Federal civilian agencies are under the gun to re-engineer their networks by June 30 to comply with an ambitious Office of Management and Budget plan to improve information technology security through a dramatic reduction of Internet connections.

The Trusted Internet Connection (TIC) plan also includes an April 15 deadline for agencies government wide to declare their capabilities and requirements to carry out the overhaul.

TIC requires the federal government to winnow its array of about 4,000 Internet connections to roughly 50 highly secure gateways. OMB, which launched TIC in November 2007 in response to the surging frequency and sophistication of online assaults against federal systems, first estimated the number of Internet connections to be about 1,000. After gathering information from agencies, that number grew fourfold.

The TIC plan to create a more secure perimeter between Uncle Sams internal networks and the free-fire zone that dominates the external Internet echoes a project that the Defense Department launched seven years ago.

The new, secure perimeter, sometimes referred to as a demilitarized zone, would help federal IT managers improve their network traffic monitor capabilities.

Agencies also would be able to reduce the number of security appliances they use to filter data crossing into or out of federal networks.

The OMB proposal calls for the Homeland Security Departments U.S. Computer Emergency Readiness Team to implement pivotal TIC operations.

For years US-CERT has operated a 24-hour operations center that monitors network activity across the federal government. Under TIC, the center will enforce network security via its suite of Einstein packet-filtering devices. USCERT uses the Einstein systems to keep malware out of federal networks and prevent sensitive government information from leaving.

The DHS network security response team built the Einstein systems using commercial and government software and hardware. The Einstein devices sit outside government firewalls to detect all traffic that affects federal systems, DHS officials said last year (GCN.com, Quickfind 1022).

Most security experts said the risks involved in the ambitious TIC deployment schedule and the difficulties posed by the network re-engineering plan would be more than offset by its likely effectiveness.

Many of the IT security analysts contacted for this article emphasized the urgent need for security upgrades to protect the federal governments data infrastructure. Most security professionals agreed that the TIC security improvements and similar measures are long overdue.

We should have done this five years ago, but there wasnt the heart or the will then like there is now, said Howard Schmidt, a former White House cyber security adviser. The timetable is aggressive, he said, but now there is a sense of urgency behind the program.

The concept is very sound, Schmidt said.

You can easily monitor whats going on, you can react more quickly, and you have greater visibility of threats. If done correctly, this can achieve a lot.

Small agencies that wont qualify for their own connections under TIC must subcontract their Internet services to larger agencies.

Coordinated efforts OMB timed the TIC migration deadline to coincide with the governments other major computer security and network security projects.

The coordinated schedule will allow agencies to capture the improvements all at once and launch the security upgrades simultaneously, said Karen Evans, OMBs administrator for e-government and IT.

Were trying to make sure that everything is raised to the same level, and weve picked these dates because all the efforts align, Evans said.

OMB early this month sent a memo to all federal departments and agencies asking them by April 15 to submit their proposed solutions for implementing TIC and how they would prefer to receive service from a Trusted Internet Connection Access Provider.

OMB gave agencies three options: be a single- service provider that serves only its own internal customers and has its own TIC; be a multiservice provider that offers services to more than one agency or bureau and shares a TIC with others; or be an agency that connects to a TIC via an approved provider. For agencies that want to be their own TIC provider, OMB asked for extensive supporting data on the agencies technical ability to monitor traffic and enforce security policies on network links.

OMB will use agencies submissions in deciding how to allocate the targeted 50 TICs.

Evans said TICs goal of reducing the number of connections to 50 is ambitious, but added that it is a well thought-out target. She said although some agencies might believe that the goal of 50 Internet links and the June 30 timetable are unrealistic, theres no technical reason this cant be done.

OMB modeled TIC after the network security methods developed for use by banks, brokerage houses and similar financial institutions, said Scott Bradner, technology security officer at Harvard University. Bradner helped OMB plan TIC.

TIC is not a magic bullet; [but] it will help, Bradner said. It will help by consolidating the Internet connections enough so that they may be reasonably monitored.

In the governments existing network structure, there are too many Internet connections to be reasonably monitored, Bradner said.

TIC is a resizing, or a right-sizing.

Bradner said reducing the Internet links to 50 will leave large federal agencies with two or three portals. He noted that its impossible to guarantee service reliability from a single portal.

Meanwhile, smaller agencies will share portals or connect to larger agencies portals via Internet service providers networks.

The connection from an agency to a portal is where Einstein appliances will be placed to monitor traffic, and layers of firewalls will insulate an agencys internal network from the Internet, Bradner said.

Typically, an agencys network will consist of sub-networks. Those segments will include a front-end network to provide Web services to agency customers or constituents. Each agency also will operate a back-end network to maintain its databases.

Because the back-end databases contain proprietary information that could be private or even classified, the back-end networks need additional protection to fend off hacking attempts from outside. A separate layer of firewalls inside each agencys network will provide security by insulating the back-end systems from the rest of the network, Bradner said.

Federal agencies should be able to meet the TIC requirement fairly easily by updating their routing tables so that traffic to and from the Internet travels across the agencies designated portals, he said.

The reconfiguration shouldnt slow down the performance of an agency network if the agency engineers the transition properly, Bradner said.

He emphasized that federal network administrators must pay special attention to assuring adequate capacity at their agencys portals to the Internet. Network planners will have to vet the equipment used in the portals and scrutinize the circuits that shunt traffic to and from back-end networks, Bradner said.

Federal network planners said smaller agencies, in particular, will find their path to TIC compliance eased by the pending transition from the governments FTS 2000 telecommunications service contracts to their Networx successors.

The five telecom providers that won places on the Networx schedule have said they would help agencies use standard Networx offering packages to meet the TIC mandate.

Based on what they know, the Networx providers believe that the Networx contracts could satisfy the TIC requirement, said John Johnson, the GSA Federal Acquisition Services assistant commissioner for integrated technology services.

Johnson said GSA might have to modify the Networx contracts in some cases for example, to accommodate TICs provisions for co-located and dedicated data hosting services, content delivery services and IP virtual private network services.

We dont see those modifications as significant activities, Johnson said.

More news on related topics: Communications / Networks, IT Security, IT Management, Web Strategies