HACKERS BOOST MINDEF CYBER DEFENCES

21feb18_news-1 https://www.defencepioneer.sg/images/default-source/_migrated_english/21feb18_news-1.jpg?sfvrsn=5090e0f9_2 https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
HACKERS BOOST MINDEF CYBER DEFENCES
21 Feb 2018 | TECHNOLOGY

HACKERS BOOST MINDEF CYBER DEFENCES

// STORY Thrina Tham
// PHOTOS Tan Yong Quan

A total of 35 vulnerabilities, or bugs, were uncovered across eight of its major Internet-facing systems, with a total bounty payout of US$14,750 (S$19,500).

"Hackers are very innovative, so MINDEF has to be equally innovative in defending our systems. That's why we ran the Bug Bounty Programme," said Defence Cyber Chief David Koh, who announced programme's results on 21 Feb.

"The programme has met our intended objectives and allowed MINDEF to find previously unidentified vulnerabilities quickly and effectively, and consequently strengthen our defence systems," he added.

The three-week programme saw 264 white hat hackers invited to look for security flaws in MINDEF's systems including the MINDEF, Central Manpower Base, and Defence Science and Technology Agency websites, as well as NS Portal.

These ethical hackers are from around the world, hailing from countries such as India, Romania, Russia, Sweden and the United States. They also included 100 hackers from the local white hat community in Singapore.

Held from 15 Jan to 4 Feb, the programme saw the first vulnerability report submitted 83 minutes after its launch. At the end of the three-week hackathon, a total of 34 participants had reported 97 vulnerabilities, of which 35 were valid.

The initiative is a first for a government agency in Asia, according to HackerOne, the international bug bounty company engaged to run the programme. In a statement, HackerOne said that MINDEF responded quickly to the vulnerability reports, responding within five hours on average. The company has run similar programmes for the US Department of Defence, as well as tech giants Google and Twitter.

Explaining the process, Mr Koh said that each reported bug has to meet certain criteria before it is further verified by MINDEF.

"(Each time a vulnerability is found), we fix the vulnerability immediately (to) mitigate the risk as quickly as possible," he said.

Of all the validated bugs reported, no critical vulnerabilities were found. Two were of high severity, 10 were medium and 23 were low.

The biggest bounty of US$2,000 went to local white hat hacker Mr Darrel for uncovering one of the high-severity bugs.

The cyber security manager at consultancy firm Ernst & Young said that participating in the programme helped him sharpen his skills.

Going by the moniker Shivadagger, he said: "For this programme, you're expected to have a foolproof report they want to know that you can actually go in and exploit (the vulnerability)."

Mr Darrel reported 14 vulnerabilities, of which nine were deemed valid - earning him a total bounty of US$5,000.

The Bug Bounty Programme is part of MINDEF's continuous efforts to build up its capabilities in the cyber arena, which includes the setting up of the Cyber Test and Evaluation Centre (CyTEC) where servicemen train against simulated cyber attacks.

Suggested Reading
Cover story
SISTERS IN ARMS
TECHNOLOGY
21 Feb 2018

One's got her feet firmly on the ground, the other's hungry for adventure – CPT Rebekah Abbott and CPT (Dr) Hannah Abbott share the joys of growing up and signing on with the military.

Cover story
FOUR WOMEN, 4 SERVICES, 19 YEARS OF SISTERHOOD
TECHNOLOGY
21 Feb 2018

Meet ME6 Toh Bao-En, LTC Nah Jinping, LTC Tong Wei Lynn and SLTC Tung Wanling.

Feature
NS ALLOWANCE TO INCREASE FROM 1 JULY 2025
TECHNOLOGY
21 Feb 2018

The increase is among a series of various measures to enhance the National Service (NS) experience and recognise servicemen’s contributions. 

Cover story
SAF TO GET NEW INFANTRY FIGHTING VEHICLE, 2 MORE SUBMARINES; BUILD UP UNMANNED CAPABILITIES
TECHNOLOGY
21 Feb 2018

Defence Minister Dr Ng Eng Hen highlighted the SAF’s long-term approach to building a next-generation fighting force, during the Committee of Supply debates on the defence budget. 

Feature
SAF SET TO EXPAND PULAU TEKONG TRAINING AREAS; SAFTI CITY OPEN FOR TRAINING
TECHNOLOGY
21 Feb 2018

Pulau Tekong will be expanded to stretch 10km, and is part of the SAF’s investments in training infrastructure for more effective and realistic training.

Combat medic learns to save lives in SAF-SCDF attachment
TECHNOLOGY
21 Feb 2018

LCP Chen Anhong stepped up to treat patients and provide emergency medical services during his six months with the SCDF.

Feature
MATCH MADE IN THE SAF
TECHNOLOGY
21 Feb 2018

MAJ Jayaram Venugobalan Naidu and Kasturibai Athmaram went from schoolmates to soulmates after a chance posting to the same unit reconnected the two.

HE STRUCK (DIVERS’) GOLD
TECHNOLOGY
21 Feb 2018

Inspired by his father who was a Commando NSman, 3SG Fong Zheng Wei went from failing IPPT to achieving Divers’ Gold.

TWICE THE STRENGTH, DOUBLE THE PRIDE
TECHNOLOGY
21 Feb 2018

3SG Irfan and 3SG Iryan Hidayat have walked almost identical paths all their lives —from attending the same schools to enlisting for NS and, now, graduating as newly minted sergeants together.  

Feature
AFTER “EVER AFTER”
TECHNOLOGY
21 Feb 2018

From best friends to lovers, and now parents of two (with a third on the way!): Army couple CPT Nuraishah and 3WO Shahibul share how their love is still going strong.