Showing posts with label Area: Cyber. Show all posts
Showing posts with label Area: Cyber. Show all posts

March 9, 2012

Cyberweapons move a step forward


An interesting article on Aviation Week illustrates how cyber and network weapons could be used in the near future to execute air-to-air attacks. Electronic warfare specialists and senior U.S. service officials are saying that U.S. Air Force is developing network weapons to attack aircrafts, but at the same time also Chinese Armed Forces are already fielding advanced cyberweapons to attack high-value aircrafts used for early warning, electronic surveillance, command & control, and intelligence.

As reported on the article. Lt. Gen. Herbert Carlisle, the deputy chief of staff for operations, recently said that “the Russians and the Chinese have designed specific electronic warfare platforms to go after all our high-value assets. Electronic attack can be the method of penetrating a system to implant viruses. You’ve got to find a way into the workings of that target system, and generally that’s through some sort of emitted signal. The Chinese have electronic attack means — both ground-based and aircraft-mounted — specifically designed to attack E-3 AWACS, E-8 Joint Stars and P-8 maritime patrol aircraft".

In such a context, Northrop Grumman (that was recently awarded of two important contracts in the domain of Cyber Security) has just issued a 136-page report to the US-China Economic and Security Review Commission, suggesting China is adamant in creating diverse and technically advanced cyberspace abilities, and specifying that Chinese military also has close relationships with large Chinese telecommunications firms, creating a path for China to penetrate supply networks for commodities used by the U.S. government, military and the private sector.

China’s cyber capabilities appear advanced enough to disrupt U.S. military operations in case of a conflict. “A few weeks before a potential conflict over Taiwan, the People’s Liberation Army of China may mount a computer network attack on systems operated by the U.S. Pacific Command and Transportation Command to confuse the U.S. command and control picture,” the report from the U.S.-China Economic and Security Review Commission found.

According to the report, "computer network operations (attack, defense, and exploitation) have become fundamental to the People’s Liberation Army’s strategic campaign goals for seizing information dominance early and using it to enable and support other PLA operations throughout a conflict. During peacetime, computer network exploitation has likely become a cornerstone of PLA and civilian intelligence collection operations supporting national military and civilian strategic goals"

"Military operations have benefitted from the unlimited range and precision of network based weapons and intelligence collection opportunities. Holding an adversary’s logistics and communications capabilities at risk previously required kinetic options (accurate missiles, quiet submarines, special operations forces, or advanced maritime strike aircraft) to physically target key communications nodes. PLA leaders understand now that tactical level employment of computer network attack tools used with sufficient precision can achieve dramatic strategic outcomes with the potential to alter a campaign"

Reference: Aviation Week (1), TheNewNewInternet (2), China Defense Mashup (3), USCC.gov (4)

March 7, 2012

Contract Award: Northrop Grumman to implement Cyber Protection for U.S. DoD


News Report

Just a few days after being awarded the NATO NCIRC contract in partnership with Finmeccanica, Northrop Grumman announced the acquisition of a cybersecurity task order by the U.S. Defense Information Systems Agency (DISA) to strengthen cybersecurity protections across all Department of Defense (DoD) and Intelligence Community networks by implementing the Host Based Security System (HBSS) as part of the U.S. DoD Information Assurance and Computer Network Defense contract.

The task order was competitively awarded under the Encore 2 contract vehicle and is valued at $189 million over a three-year base period with two one-year options. As prime integrator, Northrop Grumman will provide software license maintenance support, training, help desk and architectural infrastructure support personnel.

Under the terms of the contract, Northrop Grumman will provide support in architecting, engineering, maintaining, deploying and implementing the HBSS solution. This includes but is not limited to the Combatant Commanders, Services, Field Activities and Agencies and the intelligence community's networks and associated host platforms.

The Technology

HBSS is the U.S. DoD's commercial-off-the-shelf suite of automated and standardized software used to provide enhanced host based security – security on desktops and laptops versus at the boundary such as routers and switches – against both inside and external threats.

HBSS monitors, detects, and counters against known cyber-threats to U.S. DoD Enterprise. Under the sponsorship of the Enterprise-wide Information Assurance and computer Network Defense Solutions Steering Group (ESSG), the HBSS solution will be attached to each host (server, desktop, and laptop) in DoD. The system will be managed by local administrators and configured to address known exploit traffic using an Intrusion Prevention System (IPS) and host firewall. DISA PEO-MA is providing the program management and supporting the deployment of this solution.

Comments

 "Cybersecurity is one of Northrop Grumman's four core businesses due to its vital role in our nation's defense," said Karen Williams, vice president of Northrop Grumman's Defense Technologies Division. "The HBSS award reinforces Northrop Grumman's position as a top provider of defense-in-depth cybersecurity solutions across the DoD and intelligence domains."

"Our Northrop Grumman team brings a wealth of cybersecurity integration experience and capabilities to help ensure that all five million end-points are protected across the DoD and intelligence community," said Sam Abbate, vice president of defense enterprise solutions for Northrop Grumman. "We look forward to working with DISA to continue our support to these communities in this critical cybersecurity function."

The Context

The U.S. Defense Information Systems Agency (DISA), at the request of the United States Strategic Command (USSTRATCOM) and in support of National Security goals established by the President; started the acquisition from industry of a capability that will develop and deploy an automated Host-Based Security System (HBSS) solution, that will provide network administrators and security personnel with mechanisms to prevent, detect, track, report, and remediate malicious computer-related activities and incidents across all U.S. DoD networks and information systems.

In October 2007, U.S. DoD mandated HBSS for eventual installation on all unclassified and classified networks. Full implementation of HBSS is critical to defending government networks from an increasing number of sophisticated cyber attacks. HBSS provides system administrators significant improvements in situational awareness and drastically reduces or eliminates the effectiveness of cyber attacks, ensuring vital network capabilities are available to warfighters.

Back in 2010, Mark Orndorff, director of PEO MA/NetOps, wrote that DISA was attempting to transform HBSS into a tool for continuous monitoring of DOD networks. “We’re building out an enterprise architecture to take what was originally designed to improve the security of end-points but then pull information from a system and correlate it to a DOD enterprise level so that commanders operating and defending the network will know the status of their security posture, giving us a readiness report card that’s machine-generated. It will give us the ability to collect and correlate alarms as attacks propagate around the network — essentially letting us know what’s on the network. It will also give us the ability to look for what we call rogue systems.

Northrop Grumman has been working on the deployment of HBSS since 2008. The company recently completed deployment of HBSS 3.0 across 263 active duty U.S. Air Force bases and Air National Guard sites around the world.

Currently, DISA is looking beyond HBSS for ways to more closely monitor DOD networks. One solution involves network appliances that perform deep packet inspection on data that crosses DISA’s networks. That capability allows DISA to move toward its goal of full situational awareness for traffic traveling along the Global Information Grid.

References: Northrop Grumman (1), DISA (2), DefenseSystems (3)

Contract Award: General Dynamics to enhance U.S. Air Force Cyber Network Defense

News Report

As announced in a recent press release, General Dynamics Advanced Information Systems was awarded a contract to continue its cyber network defense, operations and exploitation support of the U.S. Air Force’s 35th Intelligence Squadron (35IS) Cyberspace Operations program Sensor Shadow.

The contract has a maximum value of $5 million over three years if all options are exercised. Through this contract General Dynamics’ analysts and engineers help to collect, analyze, produce and disseminate vital cyber intelligence to ensure the warfighter maintains information dominance in the cyber domain. This includes supporting the U.S. Cyber Command and other Department of Defense customers.

The Context

The 31st Intelligence Squadron is the United States Air Force component of the National Security Agency/Central Security Service-Georgia field site and subordinate to the Air Force Intelligence, Surveillance and Reconnaissance Agency. It conducts both national and tactical intelligence operations in support of combat operations, plans and forces for three joint combatant commands. The unit also conducts intelligence operations in support of the air component commanders, air forces and Airmen of those combatant commands.

The Sensor Shadow program team conducts in-depth analysis of network intrusions, threat profiling, all source intelligence analysis and long-term analysis of stored network connection data and supports operations across the globe.

Comments

The Sensor Shadow program is representative of our cyber security heritage. For two decades General Dynamics has been providing leading-edge cyber intelligence support to the Air Force through Sensor Shadow, dating back to Operation Desert Storm,” said John Jolly, vice president and general manager of General Dynamics Advanced Information Systems’ Cyber Systems division. “Our close partnership with the 35IS allows us to effectively apply our mission understanding and in-depth expertise in the cyber domain to bring more capability to the cyber analyst toolset for more effective and timely analysis.

References: General Dynamics (1), Gordon.Army (2)

March 2, 2012

Contract Award: Finmeccanica and Northrop Grumman to enhance NATO Computer Incident Response Capability (NCIRC)

News Report

As announced in a recent press relase, Finmeccanica, through its controlled operating companies SELEX Elsag and SELEX Sistemi Integrati's VEGA, together with its partner Northrop Grumman, has been awarded a contract by the NATO Consultation, Command and Control (NATO C3) Agency to develop, implement and support the NATO Computer Incident Response Capability (NCIRC) - Full Operating Capability (FOC).

The contract, worth around EUR 50 million, is for an extensive managed service which will provide information assurance to around 50 NATO sites and headquarters throughout 28 countries worldwide. The NCIRC will provide the capability to detect and respond to cyber security threats and vulnerabilities rapidly and effectively. The project is intended to meet the level of ambition of NATO Head of States as set out during the Lisbon Summit in November 2010.

This award is result of a competitive selection process for which NATO collected bids from more than 300 companies across its 28 member nations. The list of the bidders included some of the world's top defense companies, such as Lockheed Martin, IBM and SAIC.

The Context

Today, the NCIRC - Initial Operating Capability (IOC) already provides NATO’s Cyber Defence capability to respond to computer security threats and vulnerabilities rapidly and effectively. It provides the means for handling and reporting incidents as well as disseminating important incident-related information to system and security management. It concentrates incident handling into one centralised and co-ordinated effort, thereby eliminating duplication of effort. However, it does not yet protect all the networks within NATO.

The upcoming NCIRC - Full Operating Capability (FOC) aims not only at a technology refresh of the existing NCIRC IOC capability but will also introduce new technologies to improve cyber defence situational awareness and enhance NATO’s ability to respond to evolving cyber-threats.This upgraded capability, which will be implemented by the end of 2012, will lay out a strong foundation for cyber defence information sharing in a federated environment.

Later increments of the NCIRC FOC project will provide NATO with the means to further develop cyber defence situational awareness by dynamically assessing and managing the level of risk in its CIS thus providing the Alliance greater flexibility in its conduct of network centric warfare.

Comments

This outcome clearly demonstrates the ability of Finmeccanica to draw on leading capabilities across its group to provide leading-edge Cyber Solutions to such an important international organisation. We are delighted that this strong partnership, combining the capabilities, resources and expertise of both organisations spanning the UK, US and Italy has been selected to offer what we believe is the superior solution best meeting the requirements of this key NATO Programme which Finmeccanica is fully committed to delivering successfully” said Giuseppe Orsi, Chairman and CEO of Finmeccanica.

We are pleased to be part of the team selected for this strategically important NATO programme,” said Mike Papay, Vice President Cyber Initiatives of Northrop Grumman Information Systems. “Northrop Grumman looks forward to bringing its talent, resources and decades-long expertise in building and operating national-level cyber security management centres, both in the U.S and U.K., to this programme to help protect NATO’s networks from advanced cyber threats.

References: Finmeccanica (1), C4I Technology News (2)

February 20, 2012

U.S. reshape their spending on Cyber Warfare

News Report

An interesting post on Military.com illustrates how the Pentagon spending on cybersecurity would largely remain flat under the U.S. Defense Department's budget proposal, in contrast with the global reduction of U.S. military budget, and in line with the fact that the cyber threat is escalating at a dramatic rate, and terror groups and rogue nations are trying to acquire the ability to breach, destroy or take control of critical networks and military systems.

"We are in the 21st century and we have to use 21st century capabilities," Defense Secretary Leon Panetta told senators this week. "That's the reason this budget invests in space, in cyberspace, in long-range precision strike, and in the continued growth of special operations forces to ensure that we can still confront and defeat multiple adversaries even with the force structure reductions."

Spending on cybersecurity programs to $3.4 billion, roughly what it was last year. In this context, there will be added funding for U.S. Cyber Command, largely for operations and research into how the military should respond to the persistent cyberattacks and probes of its networks. And the budget for the Defense Advanced Research Projects Agency, or DARPA, will also increase as the department invests more in high-tech research and equipment.

"We've identified efficiencies and redirected resources to better match mission-critical needs," said Pentagon spokesman George Little. "We're using our cyber dollars more wisely, and as a result, we believe this budget will allow us to further boost our cyber capabilities."

References: Military.com (1)

February 6, 2012

U.S. DARPA's program on High-Assurance Cyber-Secured Military Vehicles

News Report

As announced by Fbo.Gov, the U.S. Defense Advanced Research Projects Agency (DARPA) will conduct on February 21st a dedicated briefing in support of the High-Assurance Cyber Military Systems (HACMS) program. The objectives of the event are to familiarize participants with DARPA’s interest in innovative approaches to high-assurance cyber military systems, and to promote discussion of synergistic capabilities among potential program participants.

The Context

Embedded systems form a ubiquitous, networked, computing substrate that underlies much of modern technological society. Embedded systems have been networked for a variety of reasons, including the ability to conveniently access diagnostic information, perform software updates, provide innovative features, lower costs, and improve ease of use. To a first approximation, air-gapped systems no longer exist. Researchers and hackers have shown that these kinds of networked, embedded systems are vulnerable to remote attack and that such attacks can cause physical damage while hiding the effects from monitors.

The goal of the DARPA's HACMS program is to create technology for the construction of high-assurance cyber-physical systems, with a special focus on the vehicle space. HACMS will produce a set of publicly available tools integrated into a high-assurance software workbench, which will be widely distributed for use in both the commercial and defense software sectors. HACMS will use these tools to generate open-source, high-assurance operating system and control system components, and then will use these components to construct high-assurance military vehicles.

Achieving this goal requires a fundamentally different approach from what the software community has taken to date. HACMS will adopt a clean-slate, formal methods-based approach that enables semi-automated code synthesis from executable, formal specifications. In addition to generating code, such a synthesizer will produce a machine-checkable proof that the generated code satisfies the functional specification as well as appropriate security and safety policies.

Key HACMS technologies include interactive software synthesis systems, verification tools such as theorem provers and model checkers, and specification languages. Recent fundamental advances in the formal methods community, including advances in satisfiability (SAT) and satisfiability modulo theories (SMT) solvers, separation logic, theorem provers, model checkers, domain-specific languages, and code synthesis engines suggest that this approach is feasible.

References: Fbo.gov (1)

January 26, 2012

Israel Defense Forces are engaging hackers to protect their network-centric systems


News Report

As recently reported by The Jerusalem Post, Israel Defence Forces (IDF) are assembling elite teams of computer hackers to lead the nation’s cyber-warfare efforts, in a move that responds to the increasing concern over the growing threat to Israel’s civilian and military networks from Iran.

The new soldiers will serve in Military Intelligence as well as in the C4I Directorate, i.e. the two military branches responsible for cyber-warfare in the IDF, with the first one more focused on cyber offense and the second one dedicated to cyber defense.

One of the IDF’s primary concerns is the possibility that an enemy will topple military networks during a war. In recent years, the military has invested heavily in digitizing its ground forces, for example with the Tzayad digital army program that allows units to share information on the location of friendly and hostile units.

The Context

Developed by Elbit Systems, the Tzayad – recently installed in several IDF units – connects all land assets together by enabling every tank to see where the artillery and infantry units are located and vice versa.

Built around a wireless backbone supported by software programmable radios, Tsayad architecture is basically composed of a SW layer called TIGER (Tactical Intranet Geographic dissEmination) that ties the system into legacy systems; a blue force tracker (the TORC2H system), a lightweight tactical operations center, plus a number of other command and communications applications.

Tzayad technologies are aimed to provide enhanced situational awareness and ad hoc networking for voice, data and video transmissions between the various branches of Israel’s Defense Forces. Basically, the goal is to reduce sensor-to-shooter cycles by streaming real-time data to commanders, and allowing direct re-transmission of the consolidated data picture back to the field. This enables force coordination at all levels, access to updated situational pictures, improved overall operational capabilities, survivability and accuracy, and more efficient utilization of personnel and other resources.

The program fits within the modernization strategy that was included since 2005 in the doctrine of Israel Armed Forces. Military confidence in fully-networked systems received a severe blow, however, during the the Israel-Hezbollah War of 2006, when Hezbollah commandos penetrated the high-tech barrier on the Lebanese border and "a semi-military organization of a few thousand men resisted, for a few weeks, the strongest army in the Middle East, which enjoyed full air superiority and size and technology advantages" (as illustrated by the Winograd Commission Report).

Reference: The Jerusalem Post (1,2), Defense Industry Daily (3), DefenceTech (4), DefenceNews.com (5)

January 24, 2012

Brazilian Army's incremental steps for the development of a National Cyber Defence Capability


News Report

An interesting entry in Forcas Terrestres provides some insight into the activities undergoing in Brazil for creating a national Cyber Defense capability.

As illustrated by the blog, and confirmed by other sources, the Brazilian Army awarded two contracts in 2011 for acquiring a new antivirus system and a cyber-warfare simulator. The contracts were assigned to two different brazilian companies, i.e. BluePex and HP's brazilian partner Decatron. Both the two contracts have been managed by the Brazilian Army's Centre for Communications and Electronic Warfare (CCOMGEX, Centro de Comunicações e Guerra Eletrônica do Exército), which is the same military organization that is leading and coordinating the activities for the two transformation programs that will re-shape brazilian land armed forces, namely the SISFRON (Sistema Integrado de Monitoramento de Fronteiras) and the Projeto Brigada Braço Forte.

Under the terms of the first contract, which has an approximate value of 450 k$, BluePex will install its antivirus into the Brazilian Army's network (EBnet), which comprises more the 60000 computers, and will provide training and services to the Army. The BluePex antivirus will replace the one already provided by the spanish company Panda Securitywhich signed in 2010 an agreement with the CCOMGEX to support the professionalization of its operational agents involved in the fight against cyber-terrorism, digital crime and strategic intervention in the event of cyber-warfare.

Under the terms of the second contract, which has an approximate value of 1,2 M$, Decatron will develop a SW environment aimed at training army personnel in the surveillance and defence of network and systems against cyber attacks and cyber incidents. The contract was awarded on last November through an electronic auction in which only Brazilian companies were admitted to bid, according to a strategy of nationalization that puzzled all those international companies that during 2011 had been called by CCOMGEX to present their solutions in the field of cyber warfare simulation.

The Context

The two awards assigned by CCOMGEX are part of a bigger plan undertaken by the Brazilian Government to allow the country’s military, law enforcement agencies and private sector to start performing a collaborative and preventive work against cyber threats. In this framework, the Presidential Institutional Security Cabinet (GSI) published in 2010 its so-called Green Book of Brazil’s Cyber Security, intended as a starter to define the parameters of a collaborative national policy which includes symmetric cryptography, asymmetric techniques, security protocols, techniques for secure implementation, high-performance data processing, computation and quantum cryptography, project management and collaborative infrastructure, and human resources development.

Brazilian Armed Forces are a key component of this plan. Last year, Brazilian Army launched the Center for Cyber Defense (CDCiber) in Brasília. As military-led enterprise, "the Center is a step in the development of doctrines for the coordination of cyber security among all the branches of the Armed Forces and with other sectors of society,” said Army Lt. Gen. José Carlos dos Santos, commander of CDCiber. All the branches of Brazil’s Armed Forces have programs of cyber defense, but the new center will integrate leadership of those programs.

References: Forte.Jor.br (1), Panda Security (2), Diàlogo (3)

January 23, 2012

Command and Control and Cyber Warfare in U.S. Joint Operational Access Concept


News Report

U.S. DoD has just released a Joint Operational Access Concept (JOAC) which describes how future U.S. joint forces will operate in response to emerging antiaccess and area-denial security challenges. Due to three major trends, i.e. 1) the growth of antiaccess and area-denial capabilities around the globe, 2) the changing U.S. overseas defense posture, and 3) the emergence of space and cyberspace as contested domains - future enemies, both states and nonstates, see the adoption of anti-access and area-denial strategies against the United States as a favorable course of action for them.

Within this context, the released document proposes a concept for how U.S. joint forces will achieve operational access in the face of armed opposition by a variety of potential enemies and under a variety of conditions, as part of a broader national approach.

Antiaccess and Area-Denial

In military terms, antiaccess refers to those actions and capabilities, usually long-range, designed to prevent an opposing force from entering an operational area, while area-denial refers to those actions and capabilities, usually of shorter range, designed not to keep an opposing force out, but to limit its freedom of action within the operational area.

As a global power with global interests, the United States want maintain the credible capability to project military force into any region of the world in support of those interests and, as such, a specific strategy for counter-acting antiaccess and area-denial activities in the face of armed opposition becomes crucial.

This is not a new challenge, but it is one that U.S. joint forces have not been called upon to face in recent decades. Even if in the recent past U.S. operational access was essentially unopposed, the combination of the three above mentioned major trends has altered the situation dramatically. Increasingly capable future enemies could see the adoption of an antiaccess and area-denial strategy against the United States as a favorable course of action for them, and consequently the ability to ensure operational access in the future may well be one of the most difficult operational challenges U.S. forces could face over the coming decades.

Cyberspace

The JOAC highlights that cyberspace provides the information infrastructure upon which the command and control of practically all military operations rests. This is especially true for U.S. forces projecting military force globally, but it is increasingly true for practically all modern militaries, especially since capabilities can be purchased commercially and relatively cheaply. In fact, U.S. cyberspace capabilities depend significantly on commercial systems and adversaries in some cases will purchase that capabilities on the same platforms used by U.S. joint forces.

Because of that increased importance, U.S. future enemies could seek to contest cyberspace superiority as means to denying operational access to U.S. joint forces. Cyberspace could easily become a priority domain for U.S. future adversaries, both state and nonstate, because U.S. forces critically depend on them, because the capabilities are readily available and relatively affordable, and because the effects of operations can be difficult to trace and even perceive.

In such context, it will become essential for U.S. forces to protect cyber assets while attacking the enemy’s cyber capabilities. U.S. cyber assets already support an increasing proportion of joint command and control and logistics functions. For just this reason, most U.S. enemies adopting an antiaccess/area-denial strategy will attempt to attack joint cyberspace operations in an attempt to disrupt force projection efforts, well before the onset of lethal combat. The same can be said about the electromagnetic spectrum generally, which is especially critical in the context of force projection given the distances involved—although that is hardly a new phenomenon.

The JOAC calls for early preparatory actions in the space and cyberspace domains, but under current U.S. policy, authorization for such actions might not be forthcoming, especially in pre-crisis stages.

Command and Control

The JOAC states that those command and control systems that will be employed in response to antiaccess and area-denial security challenges must support forces operating at global distances, deploying and maneuvering independently on multiples lines of operations from multiple points of origin, and concentrating fluidly as required. They must support an operating tempo the enemy cannot match and facilitate integration across multiple domains simultaneously and at lower echelons. An efficient joint command and control system will have to include techniques, procedures, and technologies that enable commanders to integrate operations across domains in innovative ways.

To support such objectives, the JOAC envisions decentralized command and control to the extent possible in both planning and execution. Such mission command enables subordinate commanders to act independently in consonance with the higher commander’s intent and effect the necessary cross-domain integration laterally at the required echelon.

While distributed-collaboration technologies can facilitate this effort, commanders also must be prepared to operate effectively in a degraded environment. The ability to do so has implications for doctrine, training, and education. The adversary will deliberately attempt to degrade friendly use of the electromagnetic spectrum, to include disruption of space and cyber systems. Due to heavy joint reliance on advanced communications systems, such an attack will be a central element of any enemy antiaccess/area-denial strategy, requiring a higher degree of protection for friendly command and control systems.

Especially with respect to incorporating space and cyberspace operations in a joint access campaign, new and adaptable relationships and authorities may be required to better integrate the capabilities of geographic and functional combatant commands with overlapping responsibilities.

Specifically, the abilities that are required for guaranteeing an efficient exercise of Command and Control in the intended operations are reported as follows:
  • The ability to maintain reliable connectivity and interoperability among major warfighting headquarters and supported/supporting forces while en route.
  • The ability to perform effective command and control in a degraded and/or austere communications environment.
  • The ability to create sharable, user-defined operating pictures from a common database to provide situational awareness (including friendly, enemy and neutral situations) across the domains.
  • The ability to integrate cross-domain operations, to include at lower echelons, with the full integration of space and cyberspace operations.
  • The ability to employ mission command to enable subordinate commanders to act independently in consonance with the higher commander's intent and effect the necessary crossdomain integration laterally at the required echelon.

References: U.S. DoD (1)

January 19, 2012

Information Assurance, Network Defense and Interoperability of U.S. Armed Forces, as reported by DOT&E Annual Assessment


News Report

The U.S. DoD has recently published the Defense Department's Director, Operational Test and Evaluation FY2011 Annual Report. The document reports the findings of a systematic review by the Office of Director, Operational Test & Evaluation (DOT&E) of recent major U.S. acquisition programs that experienced delays. These programs were examined to determine the causes and lengths of program delays, and the marginal cost of operational test and evaluation.

The report emphasizes that each U.S. Service operational test agency has developed methods for rapidly evaluating systems fulfilling urgent operational needs, including combining testing with the training of the first unit to be equipped and conducting quick reaction assessments. A typical example of such approach is the Network Integration Evaluation (that has been extensively covered by this blog, and that resulted one of the key C4I trends of the last period). Network Integration Evaluations (NIEs) are executed twice a year at Fort Bliss, Texas, and White Sands Missile Range, New Mexico, in order to provide a venue for operational testing of U.S. Army acquisition programs with a particular focus on the integrated testing of programs related to tactical communications networks supporting command and control. The exercises are also intended to provide an operationally realistic environment to evaluate new emerging capabilities that are not formal acquisition programs.

Together with NIESs, a substancial effort was dedicated by U.S. DoD to assess the situation concerning Cyber Warfare, Information Assurance and Interoperability. U.S. DoD recognizes the importance of applying the same approach of the NIE to these domains, and in fact it is planned that by the end of 2014 the Department should have in place all the capabilities and processes to perform selected evaluations of offensive and defensive cyber-warfighting capabilities in representative cyber‑threat environments. This will allow to assess how well U.S. fighting forces can defend against or fight through the most serious cyber attacks, as well as perform defensive and appropriate response. In order to apply these enhanced capabilities across all major exercises and acquisition programs, the Department will need to identify additional resources to expand the capacity and capabilities of the Red Teams who portray advanced cyber adversaries. This would include funding the cyber-ranges and modeling and simulation capabilities that provide operationally realistic environments for those activities inappropriate for live networks, as well as assessment teams to develop rigorous plans to ensure the cyber adversary is accurately portrayed, and assess the effects of representative cyber adversary activities.

According to the DOT&E report, hoevewev, important analyeses and assessments on cyber, interoperability and information assurance have been carried out already in 2011. In February 2011, the Chairman of the Joint Chiefs issued an Executive Order directing that all major exercises include realistic cyber-adversary elements as a training objective to ensure critical missions can be accomplished in cyber-contested environments. During 2011, the DOT&E Information Assurance (IA) and Interoperability (IOP) Assessment Program performed 23 assessments during combatant command and Service exercises; four of these assessments involved units preparing to deploy (or already deployed) to Iraq or Afghanistan.

The results were not so good...

Information Assurance and Network Defense

The IA posture observed during the assessed exercises was considered not sufficient to prevent an advanced adversary from adversely affecting the missions that were being exercised. DOT&E also observed modest improvements in certain areas of network defense, but there were also several areas in which prior progress has declined. In general, information technology and personnel were not fully prepared to operate in realistic and contested cyberspace conditions. Red Teams generally overcame defenses during exercises by only moderately increasing their level of effort over previous years.

Specifically, most Red Teams reported increased difficulty in penetrating network defenses, but results show that with sufficient time, Red Teams routinely managed to penetrate networks and systems. Detection rates of network intrusions remained low, and the ability of network defenders to detect subsequent exploitations of network data was minimal; most assessments witnessed large exfiltrations of operationally significant data. The extracted data was available, in only a few cases, to the exercise opposition force for tactical/strategic exploitation, which in effect created a more benign exercise environment than postulated by DIA and the intelligence community.

The assessments also showed a decrease in the use of backup files and systems, proper audit logging and reviews, logical access controls, incident planning, and vulnerability management. There was an overall increase in high-risk vulnerabilities observed (indicating a decrease in effective patch management), as well as a decrease in effective use of anti-virus tools and software (including failures to routinely update virus signatures). Although the ongoing fielding of the Host Based Security System (HBSS) has resulted in many local improvements in network protection from intrusion as well as intrusion detection, the majority of HBSS suites observed were found to be incorrectly or ineffectively configured.

Interoperability

The 2011 assessments found that interoperability issues encountered by the training audience typically hindered, but rarely prevented, mission accomplishment; this is due primarily to operators who developed and executed workarounds that may have preserved the timeliness and accuracy of mission data at the cost of the efficiency or level of effort required. Even though missions were generally accomplished, the workarounds usually increased operator workload, and often resulted in degraded effectiveness in completing mission tasks. Assessment teams documented measurable impacts to the timeliness, accuracy, and efficiency of operational data handling in these assessments.

A major source of poor interoperability was often found to be an incomplete set of interface requirements, or uncoordinated upgrades and updates to interdependent systems. Some of the observed mission impacts include: delays in critical battlefield situational awareness, reductions in forces available for operational tasking due to delays or inaccuracies in planning systems, re-allocation of personnel from less critical tasks to support increased manual efforts for critical ones, large-scale exfiltration of operationally significant data from force planning systems, modification of blue-force operational data by opposition force actors, manual transfers of information between systems unable to automatically interoperate.

It was also found that less than one-third of all systems observed during assessments had been fully certified for interoperability, although configuration management and documentation was satisfactory in almost 9 of 10 systems reviewed. Despite the lack of interoperability testing/certification, local authorities certified these systems for network operation. In some instances, major software suites were found to be in operational use despite having not completed operational testing or interoperability certification.

Unresolved interoperability issues, coupled with low-to-moderate level threats, were observed to be sufficient to adversely affect the quality and security of mission critical information in a way that could, and did degrade, mission accomplishment. Interoperability and IA problems are rarely observed in isolation from each other, but are frequently interrelated.

In 2012, DOT&E will continue to support the implementation of more realistic cyber threats in exercises and will report both the IA and IOP results of these assessments.

References: U.S. DoD (1)

January 13, 2012

The Cyber Power Index


News Report

Booz Allen, in partnership with the Economist Intelligence Unit, has published the results of an interesting research devoted to understand how the business community is responding to the opportunities and challenges offered by cyber. The investigation started with an exploration of how organizations and government authorities can build cyber resilience. It then focused on the specific challenges created by an increasingly mobile workforce.

One of the results of this effort is shaped in the form of a Cyber Power Index, which aims to benchmark the ability of the G20 countries to withstand cyber attacks and to deploy the digital infrastructure needed for a productive economy. In doing so, the index measures both the success of digital uptake and the degree to which the economic and regulatory environment promotes national cyber power.

The index is developed as an interactive quantitative and qualitative scoring model constructed from the following categories: Legal and Regulatory Framework, Economic and Social Context, Technology Infrastructure, Industry Application. The index is a dynamic quantitative and qualitative model, constructed from 39 indicators and sub-indicators that measure specific attributes of the cyber environment across the above mentioned drivers of cyber power.

This benchmarking exercise covers 19 countries of the Group of 20 (G20), excluding its last member, the EU. Each country was evaluated relative to others by an Economist Intelligence Unit analyst; categories and individual indicators are weighted according to assumptions of their relative importance. Details on the methodology, including weighting, can be found in the appendix of this paper.

Overall, the top five countries exhibiting cyber power, as measured by the index (the UK; the US; Australia; Germany; and Canada) illustrate that developed Western countries are leading the way into the digital era. One reason for this is the depth of Internet penetration in these countries. In 2010, the percentage of households with access to the Internet in the developed world stood at 65.6%, over four times the penetration in the developing world. The top five performers also rate highly across the board, ranking in the top seven in all four categories.

The leading emerging market countries, Brazil, Russia, India and China (the BRICs), have some room for improvement; out of the 19 economies, they rank 10th, 14th, 17th, and 13th, respectively. There is also a wide discrepancy between the top and the bottom of the index. The UK, the top performer, scores around three times the amount of points on a scale of 0 to 100 as the worst performer, Saudi Arabia.

References: Booz Allen (1)

January 12, 2012

The transformation of Command and Control in U.S. Air Force Cyber Vision


News Report

An interesting entry appeared on National Defense, discussing the approach undertaken by U.S. AirForce on cyber warfare. The article illustrates how the U.S. Air Force is working toward an Air Force Cyber Vision 2025 study that will look at state-of-the-art and best practices in the near term (2012-2015) to the long term in 2025.

Such initiative is linked with a specific Request for Information, issued on last January 11th by the U.S. Department of the Air Force, in which the interested parties are asked to submit all the information that is required to support the U.S. service in shaping the needs that will be required for cyberspace exploitation, defense, and operations.

Command and Control in the Cybersphere

According to the above mentioned RFI, U.S. Air Force is seeking information on revolutionary hardware and software cyber technology and systems as well as innovative Tactics, Techniques, and Procedures (TTP) that will support, augment and in some cases extend mission range and scope. In addition, U.S. Air Force is interested in operational innovations that provide immediate and long-term applicable, cost-effective operational capability and technological superiority for Air Force operations. Also of interest are enabling mission support elements and supporting best practices that provide the foundation for cyber capabilities across the other domains.

In such context, a special interest for U.S. Air Force is related on how the exercise of Command and Control is conducted in and through cyberspace. It appears in fact that the practice of procedural versus positive control over air assets and the time scales of the C2 planning and execution cycles do not translate well to cyberspace where decision cycles hover around a fraction of a second. Conversely, placing cyber assets under procedural control requires the incorporation of a set of previously agreed upon rules for a broad range of future scenarios.

Integrated planning must take into consideration the challenges of cyberspace deconfliction, Identification of Friend or Foe (IFF) procedures and the potential of cyber fratricide and cross-domain (air/space/cyber) fratricide. The ability to tag and identify cyber assets and to continuously ascertain their status and integrity creates technical challenges unique to cyberspace.

Simply porting technologies developed for C2ISR in the air and space domain may not be directly applicable or useful in the cyber domain. At the same time, today cyber defense philosophies make little use of military strategy and tactics. Military commanders know that there are times when the best defensive strategy is to take the offensive. They also know the value of the tactics of deception and maneuver. The fact that cyber defense philosophies, such as the defense-in-depth philosophy, do not take advantage of offensive operations, or use the tactics of deception and maneuver, inhibits the defenders from being as effective as the attackers. Current cyber defense strategies tend to be static and their tactics tend to be reactive. The trend is to build layers of static defenses in the hope that every attack will be defeated by at least one of the layers. When this fails, there is a reaction that consists of determining where and how the defenses were penetrated, patching the defenses to stop future similar penetrations, and restoring the system to a coherent state.

The integration of kinetic assets and the effects they produce are also at a formative stage. C2 capabilities for monitoring, assessing, planning, and executing cyber operations need to be designed, developed, and implemented to be interoperable with existing air and space capabilities. The U.S. Air Force is thus interested in novel and unique approaches to enable C2ISR in an environment that is not constrained by time, distance, and geographical boundaries.

In this framework, new modeling and simulation (M&S) approaches appear critical to integrating cyber techniques into military operations. M&S tools need to assess effectiveness of cyber capabilities and actions for operations, planning, acquisition, and testing. together with evaluation tools that can capture the effects of combined kinetic and non-kinetic operations.

References: National Defense (1), FBO.gov (2), DoDCCRP (3)

December 20, 2011

Iran to boost its offensive and defensive cyber-warfare capabilities


News Report

As reported by The Jerusalem PostIran has embarked on an ambitious plan to boost its offensive and defensive cyber-warfare capabilities and is investing $1 billion in developing new technology and hiring new computer experts.

Iran has been the victim of a number of cyber attacks in recent years, including the famous Stuxnet attack which is believed, at its prime, to have destroyed 1,000 centrifuges at the Natanz fuel enrichment facility by sabotaging their motors. Iran recently confirmed that a new virus called Duqu had been detected in its computer systems, although the extent of the damage is unknown. While Stuxnet was aimed at crippling industrial control systems and may have destroyed some of the centrifuges Iran uses to enrich uranium, experts say Duqu appeared designed to gather data to make it easier to launch future cyber attacks.

References: The Jerusalem Post (1)

NATO activites and planned acquisition in the Cyberspace (second part)


News Report

Yesterday we focused our attention on the important developments that are occurring in the area of cyber defence within the NATO. By reporting the speech of NC3A's General Manager Mr Georges D’hollander (at the last AFCEA Cyber Security Defence Conference), we introduced the key activities that are under development within the Alliance for supporting member and partner Nations in the possible event of a significant cyber attack.

In this context, The NATO Computer Incident Response Capability (NCIRC) appears as the basic program that will increase NATO’s Cyber Defence capability to respond to computer security threats and vulnerabilities. NCIRC is expected to provide the means for handling and reporting incidents as well as disseminating important incident-related information to system and security management. It concentrates incident handling into one centralised and co-ordinated effort, thereby eliminating duplication of effort.

As reported by The Wall Street Journal and other news sources, NATO is starting to collect bids from more than 300 companies across its 28 member nations for the NCIRC. The list of the bidders includes some of the world's top defense companies, such as Lockheed Martin, Northrop Grumman, Finmeccanica, IBM and SAIC.

Finmeccaninca and Northrop Grumman, in particular, announced the signing of a cooperation agreement for bidding on the NCIRC. The agreement - which does not indicate timing or potential value - should meet the requirements for NCIRC Full Operational Capability (FOC). Finmeccanica will participate in the program through its Cyber ​​Solutions unit, a new brand which is responsible in for all the activites of the Group dealing with the Cybersphere. "This is an intense collaboration that combines the power, resources and expertise of both companies in the United Kingdom, the United States and Italy, which led to an offer capable of satisfying the requirements of this major program of NATO," said Alberto de Benedictis, CEO of Finmeccanica UK.

The €32 million ($42 million) contract for NCIRC, although valued at less than the price of one fighter jet, holds great significance because it cements the alliance's role in protecting cutting-edge infrastructure, say NATO officials.

In the meantime, NATO conducted from 13 to 15 December a cyber defence exercise in order to test technical and operational Alliance cyber defence capabilities. The exercise, called Cyber Coalition 2011, was an opportunity to test Alliance working procedures for responding to large scale cyber attacks targeting information infra-structures of NATO and individual countries. The exercise was based  on a fictitious crisis in which all participant nations had to deal with simulated cyber attacks. The scenario of the exercise required action, coordination and collaboration from cyber defence specialists and management bodies. A total of 23 NATO and six partner nations nations were involved in the exercise. Around 100 specialists took part in the exercise from locations in the Alliance’s SHAPE Headquarters in Mons and the NATO Headquarters in Brussels. A similar number of national experts participated from national cyber defence facilities in their respective countries. 

References: C4I Technology News (1), The Wall Street Journal (2), GovconWire (3), DedaloNews (4), NATO (5)

December 19, 2011

NATO developments in the area of Cyber Defence


News Report

On last 7 December 2011, NC3A's General Manager Mr Georges D’hollander, spoke at the AFCEA Cyber Security Defence Conference presenting some important development in the area of cyber defence in NATO.

Here we report a few excerpts of his speech.

The Key Role of Intelligence

When we talk of cyber defence, we often jump straight away to new capabilities and technologies that the Alliance is developing. This is certainly important. But we should not forget about NATO’s traditional capabilities such as intelligence-sharing, defence planning or exercises. A cyber attack is in many ways similar to a ballistic missile attack. When the attack is launched, you only have minutes to respond. The warhead is not physical one, but it can be equally devastating. This is why you want as much intelligence as you can beforehand, to predict a potential threat. This is also why you want your response to be as well rehearsed as possible. One of my messages to the national representatives here is – do not treat cyber defence purely as a matter of technology.

NATO NCIRC

The NATO Computer Incident Response Capability (NCIRC) IOC (Initial Operating Capability) currently provides NATO’s Cyber Defence capability to respond to computer security threats and vulnerabilities rapidly and effectively. It provides the means for handling and reporting incidents as well as disseminating important incident-related information to system and security management. It concentrates incident handling into one centralised and co-ordinated effort, thereby eliminating duplication of effort. However, it does not yet protect all the networks within NATO. The upcoming NCIRC Full Operating Capability (FOC) project, for which my Agency is the procurement agent, aims not only at a technology refresh of the existing NCIRC IOC capability but will also introduce new technologies to improve cyber defence situational awareness and enhance NATO’s ability to respond to evolving cyber-threats.This upgraded capability, which will be implemented by the end of 2012, will lay out a strong foundation for cyber defence information sharing in a federated environment. Later increments of the NCIRC FOC project will provide NATO with the means to further develop cyber defence situational awareness by dynamically assessing and managing the level of risk in its CIS thus providing the Alliance greater flexibility in its conduct of network centric warfare. In any case, the term ‘Full operational Capability’ is quite a misnomer since, given the evolution of cyber threats, it is unlikely that any capability to counter them could ever be final or full. The project will, however, significantly boost NATO’s capability to face the evolving threat.

Coordination between NATO and National Cyber Authorities

To reap full benefit of the common interests in achieving cyber defence capabilities, a greater effort is required to align national activities in addition to coordination. This requires a dedicated structure to continually monitor national requirements and efforts and to coordinate and strategize on the way forward so as to ensure that there is no dispersion of efforts and that the tempo of research and development activities is in line with the assessment of the risks against NATO and national CIS. Establishing this structure and facilitating the coordinated development of cyber defence capabilities is the purpose of the MNCD programme (Multinational Cyber Defence Capability Development) initiated by NC3A.

Through an informal analysis of existing capabilities and needs, the following three areas have been identified as possible initial targets for MNCD: 1) cyber defence information sharing, 2) cyber situational awareness, and 3) a distributed multi-sensor collection and correlation capability.

The development of an initial cyber-defence information sharing capability, would enable efficient exchange of cyber defence information such as incident information, attack signatures, and threat assessments, between national Computer Emergency Response Teams (CERTs) including the NATO Computer Incident Response Capability (NCIRC).

Concerning cyber situational awareness, for most NATO Nations operational cyber defence is performed using a variety of tools and products including Intrusion Detection System (IDS) and other sensors, Security Incident and Event Managers (SIEM), vulnerability databases, and network monitoring software. These tools typically operate individually and there is no overall view. Cyber defence situational awareness is, therefore, achieved by experts manually consulting and consolidating a variety of feeds. Significant competency and a lot of manual effort are required. The joint development of this capability would simplify and enable quick decision making in the cyber domain, especially in a coalition environment, by providing a flexible set of visual interfaces (e.g. dashboards, dynamic views, and reporting features).

Distributed Multi-sensor Collection and Correlation Infrastructure capability would provide the means to coherently collect and correlate data from multiple sensors in an efficient and distributed manner so as to enable flexible management of sensor data storage and run a variety of correlation algorithms against the collected data.


Read the Full Speech

December 15, 2011

Learning to Hack


An interesting article is available on National Defence Magazine, addressing the shortage of personnel skilled enough to protect critical government and military networks against cyber attacks and cyber incidents. In order to overcome the problem, the U.S. Defense Department is looking at recruiting Internet security experts from military academies, and then putting these young men and women in pertinent roles when they enter their respective services.
We’ve been doing this longer than the Army has thought it important,” said Lt. Col. David Raymond, who teaches a senior cybersecurity capstone course at the U.S. Military Academy at West Point, N.Y. About 30 information technology, computer science and electrical engineering majors take the course each year. “But very few of these guys go into cybersecurity positions,” Raymond said. “The Army is just now trying to figure out what the right career path is for someone who graduates with a cybersecurity focus. That may be changing in the near future,” he said. Officials at U.S. Army Cyber Command are investigating if there should be a branch or functional area that allows the service to take a newly minted lieutenant with a suitable background and place him in a cybersecurity role immediately, he explained.
From a classroom on their Annapolis campus, a group of freshmen “plebes” and their professor recently sniffed out open computer ports around the world to take control of webcams, moving them around and peering into lives of strangers thousands of miles away. Far from a primer on voyeurism, these students were being taught a lesson about the dangers of the Internet and how keeping a port open is like leaving a backdoor unlocked for a burglar. If they want to learn how to protect critical networks, these future sailors and Marines have to know what it takes to bring them down, said their instructor Navy Capt. Steven “Doc” Simon.
These kids grew up with smartphones and computers in their houses. One school of thought says we aren’t going to be able to teach these kids anything, because they know it all already,” Simon said. “What we came to find out was these guys are outstanding computer users. They know Facebook, they know Google, they can do stuff with their phones . . . But they don’t really know, with the exception of a very small number, what’s going on behind the curtain.
Read the Full Story

Secure Cross Domain Data Transfers with Raytheon's High Speed Guard


News Report

As announced in a recent press release, Rayheon's High Speed Guard cross domain technology (HSG) is now commercially available as an off-the-shelf product. High Speed Guard, previously offered as a service, has been on the U.S. Department of Defense's Unified Cross Domain Management Office baseline list of approved solutions since May of 2010.

The new HSG 3.0.3 release lowers data center maintenance cost and improves monitoring by enabling consolidated network management. Previously, customers would pay for each additional feature that was added to the product. Now, through commercialization of HSG, customers can benefit from product enhancements at no charge as part of a standard maintenance agreement. Another advantage of commercialization is that HSG will no longer be sold as an appliance. This allows customers' freedom of choice in selecting a hardware platform on which to run HSG

The Technology

The sharing and movement of data from a wide variety of sources is essential to the rapid, accurate, and precise execution of almost all applications. Modern military, intelligence, and law enforcement operations, in particular, critically depend on a timely sharing of information. Data collected at higher security levels is typically processed into intelligence meant to be shared at lower security levels, including releasable data for coalition partners. Command and control systems in the field require automated access to higher security level tasking and reporting systems.

Unfortunately, the persistent threat of cyber attack, penetration, and data loss requires that only the most secure methods are utilized to allow information sharing and transfer.

Cross domain solutions provide the ability to manually or automatically access or transfer between two or more differing security domains and thus enable transfer of information among incompatible security domains or levels of classification. Current security policies require a trusted entity to independently validate data being moved between top secret, secret, releasable and unclassified networks. These products are commonly known as trusted guards, high assurance guards, or just guards. Guards typically function as proxies, providing network separation between the two systems being connected.

High Speed Guard™ (HSG) is an accredited software solution that enables highly complex, bi-directional, automated data transfers between multiple domains. HSG has demonstrated the fastest bi-directional transfer rates of more than 9 gigabits per second (Gb/s) on dual processor commodity servers, running a hardened Red Hat® Enterprise Linux® operating system with a strict Security Enhanced Linux (SELinux) policy.

HSG supports a wide variety of data transfer scenarios through the use of flexible transfer mechanisms and extensive data support. These include web services, flow real-time Moving Pictures Experts Group (MPEG2 and MPEG4) video, transfer imagery of multiple formats, imagery metadata files, eXtensible Markup Language (XML), inter-system messaging, Ground Moving Target Indicator (GMTI) data, and a wide variety of proprietary data formats.

Multiple accredited transfer mechanisms provide a variety of fixed security protections and secure transfer methods. These mechanisms include:
  • Streaming Video. High-Speed Guard enables real-time video streaming while providing unparalleled control and auditing of video streams through its MPEG2 parsing capability. This validates key metadata fields, including classification and release caveats. The High-Speed Guard provides the same validation capability for video clip files.
  • Service-Oriented Architecture (SOA) Web Services. High-Speed Guard includes built-in support forWeb services utilizing HTTP. In addition to providing complete inspection of all HTTP headers, the XML parsing capabilities provide full validation support for SOAP based services. Complete support is also provided for SOAP attachments, enabling product retrieval services with multi-gigabyte payloads, while enforcing complete data inspection routines.
  • High Performance Transfer. High-Speed Guard delivers data transactions through simultaneous, bi-directional information transfers using separate transmission sockets. This allows it to sustain rates of more than 9Gb/s on two CPU commodity commercial off-the-shelf servers running Red Hat Enterprise Linux 5 with a Strict SELinux policy.
  • Automated Secure Transfer (AST). High-Speed Guard supports file “drop box” transfers utilizing Secure Shell’s Secure Copy or FTP. AST validates files using the same rule engine as other High-Speed Guard services, a COTS virus scanner, digital signatures, or any combination thereof. Interaction with remote systems is highly customizable, including the mechanism used to indicate files are ready for transfer. Failed files can automatically be re-directed to a HRM. AST supports a “one-to-many” capability for copying files to multiple destinations in a single transaction.
High Speed Guard is deployed with an audit configuration that meets standard requirements across the cross domain community. Each deployment is enhanced with auditing specific to the data flows and security policies for that deployment. This unique auditing is driven by the Rule Engine, permitting the security policy to send any data deemed appropriate to the audit trail at any time. HSG supports local and remote log consolidation of the standard operating system syslog, binary auditing, and data transfer logging. All log and audit data is actively collected, parsed and reduced for immediate administrator notification of security eventsƒ.

High Speed Guard is engineered to satisfy cross domain security requirements for Top Secret/SCI and Below Interoperability (TSABI) and Secret and Below Interoperability (SABI) C&A processes. Multiple customers, including NGA, Federal Bureau of Investigation (FBI), Missile Defense Agency (MDA), and several classified customers have deployed HSG and received accreditation under Director of Central Intelligence Directive (DCID) 6/3, National Institute of 800-53 and 8500.2 security controls.

The Context

High-Speed Guard received its first certification and accreditation in 1998. Since then, it has been fielded to the National Geospatial - Intelligence Agency, Air Force and several other agencies that require critical infrastructures that guard U.S. classified information.

In 2002, High-Speed Guard became certified against Director of Central Intelligence Directive 6/3, Protection Level 4 - Integrity and Availability High, and Appendix E requirements.

In 2010, High-Speed Guard was added to the Unified Cross Domain Management Office (UCDMO) Baseline. UCDMO is the U.S. DoD office that provides centralized coordination and oversight of all cross domain initiatives across the U.S. DoD and the Intelligence Community.

Comments

"The commercialization of HSG provides significant advantages to customers," stated Ed Hammersla, chief operating officer for Raytheon Trusted Computer Solutions. "Now they can purchase a product license and maintenance contract and will receive all new product enhancements as well as customer support."

References: Raytheon (1,2,3,4), UCDMO (5)

December 13, 2011

U.S. Army's Cyber Brigade


News Report

As announced in the U.S. Army's website, the U.S. Department of Defense recently activated its first computer network operations brigade, specifically the 780th Military Intelligence Brigade, to support U.S. and Army Cyber Commands with their missions to provide a proactive cyber defense. In an event that marked the culmination of years of preparation, the colors of the 780th MI Brigade were unfurled for the first time during an activation ceremony at NSA's Friedman Auditorium, Fort Meade, Md., on Decemeber 1st, 2011.


"While normally it is enough to gather in time-honored tradition to pass unit colors to mark the transition of commanders and continuity of mission, on really rare occasions like today we have the opportunity to activate a new unit -- hand-picked, specifically recruited and purpose built, which has and will continue to contribute to a complex fight against those who present a clear and present danger to our nation's security, while providing new and breathtaking capabilities to our Army's already impressive portfolio of war fighting capabilities," said Maj. Gen. Mary A. Legere, INSCOM commanding general (Intelligence and Security Command).

The brigade's 781st MI Battalion and Headquarters and Headquarters Company, at Fort Meade, and the 782nd MI Battalion, located at Fort Gordon, Ga., will collectively enable the unit's mission to conduct signals intelligence, computer network operations, and when directed, offensive operations, in support of U.S. DOD, U.S. Army and interagency operations worldwide, while denying the same to its adversaries.

"This activation is a tribute to the belief in the notion that our nation requires assured freedom of maneuver in cyberspace in this era of persistent conflict and the advent of the increasingly more sophisticated threats to our security," Legere added.

"The challenge to our nation in this domain is upon us. You see this every day. The future danger that you envisioned has arrived," said Legere. "And the time for the men and women of the 780th to take your place in the Army's long gray operational line as a fully resourced operational unit ready for action is now."

References: U.S. Army (1)