HACKERS BOOST MINDEF CYBER DEFENCES

21feb18_news-1 https://www.defencepioneer.sg/images/default-source/_migrated_english/21feb18_news-1.jpg?sfvrsn=5090e0f9_2 https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
HACKERS BOOST MINDEF CYBER DEFENCES
21 Feb 2018 | TECHNOLOGY

HACKERS BOOST MINDEF CYBER DEFENCES

// STORY Thrina Tham
// PHOTOS Tan Yong Quan

A total of 35 vulnerabilities, or bugs, were uncovered across eight of its major Internet-facing systems, with a total bounty payout of US$14,750 (S$19,500).

"Hackers are very innovative, so MINDEF has to be equally innovative in defending our systems. That's why we ran the Bug Bounty Programme," said Defence Cyber Chief David Koh, who announced programme's results on 21 Feb.

"The programme has met our intended objectives and allowed MINDEF to find previously unidentified vulnerabilities quickly and effectively, and consequently strengthen our defence systems," he added.

The three-week programme saw 264 white hat hackers invited to look for security flaws in MINDEF's systems including the MINDEF, Central Manpower Base, and Defence Science and Technology Agency websites, as well as NS Portal.

These ethical hackers are from around the world, hailing from countries such as India, Romania, Russia, Sweden and the United States. They also included 100 hackers from the local white hat community in Singapore.

Held from 15 Jan to 4 Feb, the programme saw the first vulnerability report submitted 83 minutes after its launch. At the end of the three-week hackathon, a total of 34 participants had reported 97 vulnerabilities, of which 35 were valid.

The initiative is a first for a government agency in Asia, according to HackerOne, the international bug bounty company engaged to run the programme. In a statement, HackerOne said that MINDEF responded quickly to the vulnerability reports, responding within five hours on average. The company has run similar programmes for the US Department of Defence, as well as tech giants Google and Twitter.

Explaining the process, Mr Koh said that each reported bug has to meet certain criteria before it is further verified by MINDEF.

"(Each time a vulnerability is found), we fix the vulnerability immediately (to) mitigate the risk as quickly as possible," he said.

Of all the validated bugs reported, no critical vulnerabilities were found. Two were of high severity, 10 were medium and 23 were low.

The biggest bounty of US$2,000 went to local white hat hacker Mr Darrel for uncovering one of the high-severity bugs.

The cyber security manager at consultancy firm Ernst & Young said that participating in the programme helped him sharpen his skills.

Going by the moniker Shivadagger, he said: "For this programme, you're expected to have a foolproof report they want to know that you can actually go in and exploit (the vulnerability)."

Mr Darrel reported 14 vulnerabilities, of which nine were deemed valid - earning him a total bounty of US$5,000.

The Bug Bounty Programme is part of MINDEF's continuous efforts to build up its capabilities in the cyber arena, which includes the setting up of the Cyber Test and Evaluation Centre (CyTEC) where servicemen train against simulated cyber attacks.

Suggested Reading
DEFENCE IS EVERYONE’S BUSINESS
PEOPLE
06 Nov 2025

Whether it’s supporting NSmen in their NS commitments or volunteering in the SAF and empowering youths, 2SG (NS) Elliot Ang and SV2 Sheila Manokaran support our nation’s defence in their own ways.

Feature
FIRST IN, LAST OUT AT EX WALLABY 2025
OPS & TRAINING
06 Nov 2025

Meet the teams who toil behind the scenes to enable the smooth conduct of the SAF’s biggest unilateral overseas exercise.

Cover story
EXERCISE WALLABY 2025: TO SEE BETTER, SHOOT FASTER
OPS & TRAINING
31 Oct 2025

The SAF focuses on complex strike missions and multi-domain integration in Exercise Wallaby 2025, the 35th edition of its largest unilateral overseas exercise.

Feature
EX WALLABY 25 – GREATER INTEGRATION AND COMPLEXITY
OPS & TRAINING
25 Oct 2025

The 35th edition of the SAF’s largest unilateral overseas exercise is an opportunity for expanded scale and deeper integration towards an effective, networked fighting force.

COMMAND & STAFF COLLEGE GRADUANDS READY FOR NEW CHALLENGES
PEOPLE
23 Oct 2025

Family, work and studies – having to manage these demands is tough, but all the hard work was worth it for both MAJ Ikhtiaruddin Iman Bin Mustafa and SWO Seck Wai Kong, two recent graduates of the Goh Keng Swee Command and Staff College.

NAVY LAUNCHES 1ST MULTI-ROLE COMBAT VESSEL
MILESTONES
21 Oct 2025

The Multi-Role Combat Vessel will function as a mothership for the command and conduct of unmanned naval operations.

WHAT YOU NEED TO KNOW ABOUT THE NEW CMPB
MILESTONES
14 Oct 2025

The new Central Manpower Base (CMPB) at Bukit Gombak officially opened its doors on 14 Oct, welcoming pre-enlistees, servicemen and the public alike to a state-of-the-art, one-stop hub for all things National Service (NS).

Feature
FATHER & SON DOCTOR DUO
PEOPLE
13 Oct 2025

COL (Dr) (Ret) Tan Peng Hui was a pioneering figure in the SAF Medical Corps. Now, decades later, son CPT (Dr) Caleb Tan follows in his footsteps as part of the 100th Medical Officer Cadet Course. 

Cover story
WHAT IT TAKES TO BECOME A MEDICAL OFFICER
MILESTONES
07 Oct 2025

This October, we celebrate the 100th batch of graduates from the Medical Officer Cadet Course. What does it take to become a military doctor? We uncover the highlights!

DAY OUT WITH MY ARMY DAD
PEOPLE
06 Oct 2025

In this year’s PIONEER Kids special, Rayyan, Rizqi and Raissa spend a special day at Nee Soon Camp Shooting Range with dad 3WO Muhamed Firdaus.