DOD may pull key net from the Internet

In an effort to secure one of its most widely used Internet networks, the Defense Department is considering constructing something more akin to an intranet.

The Non-Classified Internet Protocol Router Network (NIPRNET) was created in 1995 as a network of government-owned IP routers used to exchange sensitive information.

But DOD officials, increasingly uncomfortable with having NIPRNET reside on the Internet, want to put the network behind firewalls and create a "demilitarized zone" for services that need public access, said Keith Fuller, the Defense Information Systems Agency's chief engineer for information security, speaking last week at the Government Symposium on Information Sharing and Homeland Security in Philadelphia.

Some military services and Defense agencies need public access to the Internet, he said. That was evident when DOD shut down access to the Internet as part of its effort to protect the agency from the "Code Red" worm that was proliferating across the Web.

In conjunction with the efforts to secure NIPRNET, DISA is creating a database that will contain the ports and protocols for DOD systems to identify what would be affected if DOD had to pull the plug on its Internet connection, he said.

The efforts are part of a long-term goal to plug security holes on NIPRNET. "The long and the short of it [is] that it was, in all practical terms, just an extension" of the Internet with "little additional controls," said retired Col. John Thomas, former chief of DISA's Global Operations and Security Office and now director of strategic programs at EMC Corp.

NIPRNET has some "significant" security controls but is still largely an open network, he said, because NIPRNET was developed before there were significant threats.

In 1999, DISA sought to plug some of those holes by cracking down on unofficial connections. "Positive control of all NIPRNET/Internet connections is an absolute requirement," according to an Aug. 22, 1999, policy issued by then-DOD chief information officer Art Money.

That policy, however, failed to plug the holes. A December 2000 report from the DOD inspector general was critical of the efforts and concluded that NIPRNET's security policy was never incorporated into overall DOD policy.

Furthermore, the IG report noted that the policy "lacked visibility" because it did not clearly define the process for connecting services nor did it require regular status reports on the progress made in securing the NIPRNET/Internet connections.

Whenever DISA attempted to push greater security, there was always resistance, Thomas said. He said the military "has an absolute need to be able to transit the Internet."

The DOD IG report noted that 70 percent of the traffic on NIPRNET is directed toward the Internet. "As the growth and usage of the Internet surge, so do the dangers of intrusion into sensitive networks," the report concluded.

Thomas stressed that the difficulty has always been in finding the right balance between security and open lines of communication.

About the Authors

Christopher J. Dorobek is the co-anchor of Federal News Radio’s afternoon drive program, The Daily Debrief with Chris Dorobek and Amy Morris, and the founder, publisher and editor of the DorobekInsider.com, a leading blog for the Federal IT community.

Dorobek joined Federal News Radio in 2008 with 16 years of experience covering government issues with an emphasis on government information technology. Prior to joining Federal News Radio, Dorobek was editor-in-chief of Federal Computer Week, the leading news magazine for government IT decision-makers and the flagship of the 1105 Government Information Group portfolio of publications. As editor-in-chief, Dorobek served as a member of the senior leadership team at 1105 Government Information Group, providing daily editorial direction and management for FCW magazine, FCW.com, Government Health IT and its other editorial products.

Dorobek joined FCW in 2001 as a senior reporter and assumed increasing responsibilities, becoming managing editor and executive editor before being named editor-in-chief in 2006. Prior to joining FCW, Dorobek was a technology reporter at PlanetGov.com, one of the first online community centers for current and former government employees. He also spent five years at Government Computer News, another leading industry publication, covering a variety of federal IT-related issues.

Dorobek is a frequent speaker on issues involving the government IT industry, and has appeared as a frequent contributor to NewsChannel 8’s Federal News Today program. He began his career as a reporter at the Foster’s Daily Democrat, a daily newspaper in Dover, N.H. He is a graduate of the University of Southern California. He lives in Washington, DC.



Featured

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.