Federal NOC To Be Modeled After Incidents.org / DS
An anonymous reader writes "Computerworld is covering in more detail the
new Federal 'Cybersecurity Center.' The article explains that unlike some earlier rumors indicated, the center will not try to build a super-carnivore, but instead use voluntary reports. It will be similar to the SANS Institute's Internet Storm Center, which summarizes contributions submitted to DShield.org.
This system of voluntary contributors has been shown to be effective in the past by issuing early warning for a number of major Internet worms, like
Code Red, Ramen and SQLSnake. Unlike Symantec's 'for pay ' Deep Sight service, which publishes alerts only to paying members, Incidents.org is a free service."
The problem with doing this is that you are committing a criminal offence by doing so. You are effectively, and wilfully commiting a breach of some computer law in your country.
It's one of those long discussions for a rainy afternoon, but IMHO you need to be careful doing that. After all, code red/nimda is just a worm, but if someone catches you hacking their server, then it'll be you in trouble.
Some discussion occured on various securityfocus mailing lists regarding this point. (I haven't posted a link, because the load on the security focus website is too high at the moment.)