Showing posts with label S 3712. Show all posts
Showing posts with label S 3712. Show all posts

Tuesday, June 23, 2020

S 3712 Introduced – Cybersecurity Grand Challenges


Last month Sen Wicker (R,MS) introduced S 3712, the Cyber Leap Act of 2020. The bill would require the Department of Commerce to establish five cybersecurity grand challenges. The bill was approved by the Senate Commerce, Science, and Transportation Committee with two amendments on May 20th, 2020.

Grand Challenges


The bill would add a new section 205 to the Cybersecurity Enhancement Act of 2014 (15 USC 7431 et seq.). It would require DOC to establish grand challenge competitions using the processes outlined in 15 USC 3719 in order to “achieve high-priority breakthroughs in cybersecurity by 2028” {§205(a)(1)}. The challenges would address:

• Economics of a cyber-attack,
• Cyber training,
• Emerging technology,
• Reimagining digital identity, and
• Federal agency resilience

A sixth, general ‘other challenges’ category was removed in Committee by an amendment proposed by Sen Lee (R,UT).

The Department would be required to “request and accept funds from other Federal agencies, State, United States territory, local, or tribal government agencies, private sector for-profit entities, and nonprofit entities to support efforts to pursue a national cybersecurity grand challenge under this section” {§205(b)(5)}. There are no other funding provisions within the bill.

To aid in carrying out these grand challenge authorities DOC is required to establish an advisory committee. A second amendment by Lee would specifically prohibit paying committee members for anything beyond travel expenses.

Moving Forward


As mentioned above, the bill was adopted in Committee where it did receive a measure of bipartisan support with one Democratic cosponsor {Sen Rosen (D,NV)} and it was adopted by a voice vote, a sign of the lack of serious opposition to the bill. If this bill is to be considered in the Senate this session, it would have to be taken up under the unanimous consent process. With the lack of any spending authority, that remains a possibility.

Monday, May 18, 2020

Committee Hearings – Week of 5-17-20


This week with the Senate in Washington and the House continuing to meet in pro forma sessions there are relatively few hearings scheduled. There is one markup hearing that addresses cybersecurity.

Cybersecurity Markup


The Senate Commerce, Science, and Transportation Committee will hold an executive session on Wednesday that will include markups of ten bills and 17 nominations. One of the bills, S 3712, the Cybersecurity Competitions to Yield Better Efforts to Research the Latest Exceptionally Advanced Problems (CYBER LEAP) Act of 2020, addresses cybersecurity concerns.

The official copy of the bill has yet to be published, but the Hearing website contains a link to a committee print of the bill. The bill would direct the Commerce Department to establish at least five separate “national cybersecurity grand challenges”. None of the listed challenges would address control system security issues.

Related Issues


There is one other bill being considered at the same hearing that may be of interest; S 2904, the Identifying Outputs of Generative Adversarial Networks Act. While a main focus of the bill is to direct NIST to conduct and support “research on technical tools for identifying manipulated or synthesized content” {§3(2)}, there is also similar directed interest in generative adversarial networks. The ‘adversarial networks’ would consist of competing artificial intelligence networks that would alternatively generate and detect “increasingly higher-quality artificial outputs” {§6}.

The idea of competing networks certainly seems to be an interesting way of advancing capabilities. There is an important ethical problem here though. The production of advanced networks to identify ‘manipulated or synthesized content’ would certainly be an increasingly important forensic tool, but a the simultaneous improvement of manipulation and content synthesis capability will just make the problem more intractable. Even if the legislation required the generation tool research to be classified (which the bill does not even attempt to address), the recent escape of NSA hacking tools points out that security classification only provides limited protection of potential attack tools.

I do not think that I will be providing any additional coverage of S 2904.

Thursday, May 14, 2020

Bills Introduced – 05-13-20


Yesterday with the Senate in Washington and the House meeting in an unusual Wednesday pro forma session, there were 47 bills introduced. Of these two may receive additional attention in this blog:

H Res 965 Authorizing remote voting by proxy in the House of Representatives and providing for official remote committee proceedings during a public health emergency due to a novel coronavirus, and for other purposes. Rep. McGovern, James P. [D-MA-2]

S 3712 A bill to require the Secretary of Commerce to establish national cybersecurity grand challenges, and for other purposes. Sen. Wicker, Roger F. [R-MS]

The remote operations resolution would temporarily change the rules of the House to allow for proxy voting on the floor of the House and remote operations of Committee hearings. There is no cybersecurity language in the bill with regards to the remote hearing provisions, even given the rise of the new terminology ‘Zoom Bombing’. The House Rules Committee is currently scheduled to hold a live markup hearing on this bill later today.

I will be watching S 3712 for language specifically including control system security competitions.


 
/* Use this with templates/template-twocol.html */