HACKERS BOOST MINDEF CYBER DEFENCES

21feb18_news-1 https://www.defencepioneer.sg/images/default-source/_migrated_english/21feb18_news-1.jpg?sfvrsn=5090e0f9_2 https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
HACKERS BOOST MINDEF CYBER DEFENCES
21 Feb 2018 | TECHNOLOGY

HACKERS BOOST MINDEF CYBER DEFENCES

// STORY Thrina Tham
// PHOTOS Tan Yong Quan

A total of 35 vulnerabilities, or bugs, were uncovered across eight of its major Internet-facing systems, with a total bounty payout of US$14,750 (S$19,500).

"Hackers are very innovative, so MINDEF has to be equally innovative in defending our systems. That's why we ran the Bug Bounty Programme," said Defence Cyber Chief David Koh, who announced programme's results on 21 Feb.

"The programme has met our intended objectives and allowed MINDEF to find previously unidentified vulnerabilities quickly and effectively, and consequently strengthen our defence systems," he added.

The three-week programme saw 264 white hat hackers invited to look for security flaws in MINDEF's systems including the MINDEF, Central Manpower Base, and Defence Science and Technology Agency websites, as well as NS Portal.

These ethical hackers are from around the world, hailing from countries such as India, Romania, Russia, Sweden and the United States. They also included 100 hackers from the local white hat community in Singapore.

Held from 15 Jan to 4 Feb, the programme saw the first vulnerability report submitted 83 minutes after its launch. At the end of the three-week hackathon, a total of 34 participants had reported 97 vulnerabilities, of which 35 were valid.

The initiative is a first for a government agency in Asia, according to HackerOne, the international bug bounty company engaged to run the programme. In a statement, HackerOne said that MINDEF responded quickly to the vulnerability reports, responding within five hours on average. The company has run similar programmes for the US Department of Defence, as well as tech giants Google and Twitter.

Explaining the process, Mr Koh said that each reported bug has to meet certain criteria before it is further verified by MINDEF.

"(Each time a vulnerability is found), we fix the vulnerability immediately (to) mitigate the risk as quickly as possible," he said.

Of all the validated bugs reported, no critical vulnerabilities were found. Two were of high severity, 10 were medium and 23 were low.

The biggest bounty of US$2,000 went to local white hat hacker Mr Darrel for uncovering one of the high-severity bugs.

The cyber security manager at consultancy firm Ernst & Young said that participating in the programme helped him sharpen his skills.

Going by the moniker Shivadagger, he said: "For this programme, you're expected to have a foolproof report they want to know that you can actually go in and exploit (the vulnerability)."

Mr Darrel reported 14 vulnerabilities, of which nine were deemed valid - earning him a total bounty of US$5,000.

The Bug Bounty Programme is part of MINDEF's continuous efforts to build up its capabilities in the cyber arena, which includes the setting up of the Cyber Test and Evaluation Centre (CyTEC) where servicemen train against simulated cyber attacks.

Suggested Reading
Feature
CHAMPIONS FOR INNOVATION
TECHNOLOGY
30 Jul 2025

Eleven Minister for Defence Awards (MDA) were given out this year, for innovations by MINDEF and SAF personnel that led to improved efficiency and safer working conditions.

Feature
GIANT LEAPS INTO NEW BOOTS
PEOPLE
29 Jul 2025

A career change is never easy, but a jump out of their comfort zones into the SAF is just what mid-careerists ME4 Jessica Ho and ME4 V. Yoginita wanted.

Feature
BEHIND THE PARADE
COMMUNITY
28 Jul 2025

Months of hard work and burnt weekends, all for Singapore’s biggest birthday bash. Here’s your backstage pass to this year’s National Day Parade!

MINDEF VOLUNTEERS HONOURED FOR CONTRIBUTIONS TO S’PORE’S DEFENCE
COMMUNITY
24 Jul 2025

These volunteers play a key role in promoting public awareness on defence matters and inspiring support for National Service.

FROM AUDITOR TO AIR WARFARE OFFICER
PEOPLE
23 Jul 2025

LTA Liz Voon swapped financial audits for air defence missions. Meet this mid-careerist who left one of the “Big 4” accounting firms to pursue her purpose in the RSAF, in PIONEER’s “From Desk to Field” series!

SHIP-TACULAR NDP 2025 DISPLAY AT MARINA BAY
COMMUNITY
19 Jul 2025

The maritime display is part of this year’s special NDP mobile column, joining the aerial flypast over the Padang and the drive-past along St Andrew’s Road.

Cover story
COMMITMENT IS OUR GREATEST DETERRENCE: MR CHAN
OPS & TRAINING
19 Jul 2025

Minister for Defence Chan Chun Sing witnessed the commitment of NSmen to Singapore’s defence, during his visit to a mobilisation exercise involving over 2,000 soldiers.

WHEN ENGINEERING INNOVATION MEETS NATIONAL DEFENCE
PEOPLE
16 Jul 2025

ME5 Joshua Tay brings 18 years of expertise in many different fields to the Digital and Intelligence Service (DIS). Meet this mid-careerist in the latest of PIONEER’s “From Desk to Field” series!

Cover story
FLYING HIGH FOR SG60
COMMUNITY
10 Jul 2025

The sky’s the limit when it comes to putting on a spectacular National Day Parade (NDP) aerial display for Singapore’s Diamond Jubilee. 

From hospital ward to hyperbaric chamber
PEOPLE
09 Jul 2025

ME1 Kaitlynn Arumugam shares why she made the switch from nursing to joining the Republic of Singapore Navy (RSN), in the latest of PIONEER’s From Desk to Field series.