How to Secure Supporting Election Technology

532 views
β€’
February 27, 2020
by
RSAC Cybersecurity
YouTube video player
How to Secure Supporting Election Technology

TL;DR

Supporting election technology should be protected by reducing attack surfaces, assigning security responsibilities, maintaining complete offline backups, and preparing specifically for service disruptions. Electronic poll books, voter registration systems, election-night reporting platforms, and electronic ballot delivery services are often internet-connected, widely trusted, and exposed to denial-of-service and ransomware threats during predictable periods of critical demand.

Transcript

So this next topic is a subject really near and dear to my heart, obviously. It has to do with our election security here in the United States, and also the really important, uh, topic of the back end, not just the tabulation, not just the voting machine, that, you know, tend to get all the kinda sexy coverage. So again, thank you for coming out fo... Read More

Key Insights

  • Supporting election technology is an umbrella category covering election-related systems that are not voting systems, including electronic poll books, voter registration systems, election-night reporting platforms, and electronic ballot delivery services used by overseas military personnel and civilians.
  • Supporting election technology has a large attack surface because its components are frequently connected to the internet. Voters also depend on these systems for check-in, ballot selection, registration services, ballot delivery, and access to reported election results.
  • Security governance is distributed because one company may develop an election application while a state or county hosts it. The best-practices framework therefore separates controls into administration, data, software applications, servers and workstations, and network architecture.
  • The security guide contains 160 best practices designed primarily for technology providers. Many of these providers are small companies, ranging from four or five people to approximately 40 or 50 people, so applying every recommendation to every component is not considered reasonable.
  • The three security profile levels support incremental implementation. Level one covers easier and broadly applicable measures that address most threats, while levels two and three introduce progressively more restrictive or expensive controls for components requiring additional protection.
  • Denial of service is especially concerning for elections because attackers know when essential services face their most critical demand. Disrupting availability during that narrow, public period can affect election administration and undermine confidence in how the election is being conducted.
  • DDoS preparation includes partnerships with upstream network providers, out-of-band response communications, clearly assigned incident-response duties, mitigation services, and web application firewalls. Some mitigation providers offer free services to election offices, although those services are not free to vendors.
  • Ransomware resilience depends on blocking known malicious IP addresses, creating complete system backups, storing backups at an offline destination, and removing unnecessary data or functions from internet-connected systems. Network segmentation based on the sensitivity of data or functions provides an additional level of protection.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is supporting election technology?

Supporting election technology refers broadly to systems involved in conducting elections that are not voting systems themselves. The category includes electronic poll books used to check voters in, voter registration systems, election-night reporting platforms that distribute results, and electronic ballot delivery services commonly provided to overseas military personnel and overseas civilians. These systems support election officials throughout the election process.

Q: Why is supporting election technology at risk?

Supporting election technology presents a substantial attack surface because many of its components are connected to the internet in some way. It also lacks extensive standards and regulations, according to the presentation. The risk is especially consequential because voters and officials implicitly trust these systems to provide correct ballot styles, support voter check-in, deliver ballots, and publish results without tampering.

Q: How are security responsibilities divided for election systems?

Security responsibilities are divided across five technology areas: administration, data, software applications, servers and workstations, and network architecture. Administration covers users and user management, while data can involve shared responsibility between a provider and an election official. This structure reflects systems in which a software provider develops an application but a state or county supplies the hosting environment.

Q: What are the three election security profile levels?

The profile levels organize the 160 best practices by practicality and security need. Level one contains easier measures that address most security threats and should apply to most components. Level two introduces more restrictive controls. Level three contains the most expensive measures, which address a smaller portion of threats and may be necessary only for selected components requiring stronger protection.

Q: Why are denial-of-service attacks dangerous to elections?

Denial-of-service attacks are particularly dangerous because election schedules reveal exactly when services will be most critical. An attacker can target that narrow period to disrupt a necessary system when officials and voters most need it. Such an outage can affect election administration directly and can also damage public confidence, which the presentation identifies as an objective pursued by many adversaries.

Q: How can election offices prepare for DDoS attacks?

Election offices can prepare by building effective relationships with upstream network providers and establishing out-of-band communications for DDoS response. Organizations should also assign incident-response duties so every person understands their role. More advanced protections include establishing a DDoS mitigation service and deploying web application firewalls. Some providers make mitigation services available to election offices at no cost.

Q: How can supporting election systems reduce ransomware risk?

Ransomware defenses include blocking known malicious IP addresses, performing complete system backups, and ensuring that every backup has an offline destination. The guidance emphasizes complete system backups rather than backups containing only data. It also recommends removing unnecessary data and functionality from internet-connected systems, following the broader principle that anything not required to be online should be taken offline.

Q: Why was the election security guidance designed for small providers?

The guidance primarily targets the relatively small companies that produce supporting election technology. The presentation describes many providers as having only four or five people, with the largest approximately 40 to 50 people. Because applying all 160 practices to every application would be unreasonable, the guidance uses profile levels that let providers begin with broadly applicable measures and add stricter controls where needed.

Summary & Key Takeaways

  • Supporting election technology includes electronic poll books, voter registration systems, election-night reporting platforms, and electronic ballot delivery services. Voters interact with these systems directly or depend on their outputs, often trusting that they receive the correct ballot style and that published results remain unchanged after leaving tabulation equipment.

  • The Center for Internet Security developed 160 security best practices primarily for the small technology providers that build supporting election systems. The guidance divides responsibility across administration, data, software applications, servers and workstations, and network architecture because providers, election officials, states, counties, and hosting organizations may control different components.

  • The guidance uses three profile levels to make adoption practical. Level one addresses common threats with broadly applicable measures, while later levels become more restrictive and expensive. Recommended defenses include coordinated DDoS response, assigned incident duties, mitigation services, web application firewalls, malicious-IP blocking, complete offline backups, removing unnecessary functions and data, and network segmentation.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š