RIYADH, 22 November 2005 — Bringing one’s children to the workplace has long been a tradition among private firms in Saudi Arabia. In many of the largest family businesses, the next generation are frequently assigned jobs to be accomplished on the weekends and during school vacations. That’s why it was hardly unusual for Mirza Asrar Baig, CEO of IT Matrix, to consider the best ways to interest his children in the work done by his own Saudi network security firm.

During the summer vacation, Baig decided that it was time for his youngsters to begin building upon the talks about information and network security that they frequently heard at the dinner table. He assigned the three siblings, Sana (11th Grade), Abdullah (7th Grade) and Yousef (6th Grade) Asrar Mirza, the task of learning about what the Kingdom was doing at a national level to protect and secure Saudi Arabia’s computer networks.

“My father asked us to look into what means other nations were using to protect their national networks and then examine what steps the authorities in Saudi Arabia were taking to protect the Saudi network,” said Sana. “Basically, we needed to build a global database of Computer Security Incident Response Teams (CSIRTs). After we understood the global situation in regards to network security, then it would be time to consider the Middle East and Saudi Arabia’s response to the national IT network security issue. There was a reward for our excellent performance, of course. After completing our research successfully, our father would take us on vacation to Singapore, where we would tour a CSIRT facility as part of our visit.”

CSIRTs have become important organizations around the world. CSIRTs are groups of people or organizations who coordinate the response to breaches of security or other major computer emergencies. The first CSIRT was the CERT Coordination Center (CERT/CC), one component of the larger CERT Program located at the Software Engineering Institute (SEI), operated by Carnegie Mellon University, USA.

The CERT/CC, a major center for Internet security problems, was established in November 1988, after the “Morris Worm” brought down much of the Internet and demonstrated the growing network’s susceptibility to attack. Shortly after that, the US Defense Advanced Research Projects Agency (DARPA) charged the SEI with both establishing a capability to quickly and effectively coordinate communication among experts during security emergencies in order to prevent future incidents and building awareness of security issues across the Internet community. CERT/CC staff members provide technical advice and coordinate responses to security compromises, identify trends in intruder activity, analyze product vulnerabilities, work with other security experts to identify solutions to security problems and disseminate information to the broad community.

The growth and reliance on the Internet, coupled with the increasing sophistication of intruder techniques, created a need for additional resources and capabilities. To address this need, the CERT/CC became part of the CERT Program. Other areas of work within the program include education and training, research and development, situational awareness and global relationships. Overall, the CERT organization is devoted to ensuring that appropriate technology and systems management practices are used to resist attacks on networked systems and to limiting damage and ensuring continuity of critical services in spite of successful attacks, accidents or failures.

“Globally there is only one CERT Program and one CERT/CC but now there are many other CSIRTs,” said Sana. “We found that there are lots of other CSIRTs all over the world who coordinate with CERT for incident response. Many of these teams are members of the Forum of Incident Response and Security Teams (FIRST), of which the CERT/CC is a founding member.”

After completing their research the youngsters discovered that all together there are 170 CSIRTs in 36 countries.

“The United States has 69 CSIRTs, clearly demonstrating that the USA is the most prepared nation in regards to dealing with threats or disasters to its national network infrastructure,” Yousef remarked. “There are 46 national level CSIRTs in 28 countries. There are 53 commercial CSIRTs all across the globe providing this service against a fee. There are 71 private CSIRTs in 17 countries with 40 of them alone in the USA.”

The youngsters found that the CSIRTs serve many different interests. Some CSIRTs support the network security needs of an entire country, for example, the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC); others may provide assistance to a particular region, such as AusCERT does for the Asia-Pacific area; still others may provide support to a particular university or commercial organization. There are also corporate groups who provide CSIRT services to clients for a fee.

“The worst thing we found in all our research is that there is only one CSIRT in the entire Arab world. It belongs to the UAE telecom provider Etisalat and serves as an internal CSIRT for Etisalat alone,” Abdullah said. “Saudi Arabia doesn’t have any CSIRTs at all. This means that all the computer networks in the Kingdom whether national, such as the Saudi Internet, or commercial, such as those belonging to large companies, are completely unprepared to handle a national level security breach or network disaster. This is really bad.”

The youngsters went on to explain that almost everything in our modern world depends upon information and communications technologies. Our electricity, telephone, traffic signals, banking and many other essential services depend on IT networks.

“The reality is that the concept of Cyber War is being studied and prepared for in other nations. Those countries are already having simulations and drills so they will be able to cope if their national networks are hit,” emphasized Sana. “All over the world there are many special interest groups who would like to harm Saudi Arabia. These days criminals don’t need guns or bombs to attack the Kingdom. All they need is the ability to effectively attack our network infrastructure. How would Saudi Arabia function without electricity or telephones? The thought of it frightens me.”

“We don’t know when such a national network security breach might happen,” added Abdullah, “but people should be aware that network security organizations in developed countries consider major cyber attacks to be a certainty.”

This is an issue that should terrify everyone in the Kingdom. Right now criminals are probably making maps of the Saudi national network infrastructure. Disgruntled staff of major firms could be providing detailed information about the IT network infrastructure of those companies to outsiders intent on doing harm. There is some evidence of this activity and the government is currently in the process of creating a national CSIRT, but nothing will be up and running for some time.

Meanwhile, neighbors of the Kingdom are also targets of cyber criminals and many of them have made no moves to establish a national CSIRT, which could coordinate with the Saudi CSIRT to work towards regional cyber safety. There is an urgent need for the GCC countries to wake up and get their national network security in order before it is too late. Otherwise, we all could be returning shortly to a dependence on camels and smoke signals.

* * *

(Comments to: [email protected].)