Kinda ignoring some basics here, but what can we expect (government-defined reality and all).
See The Heimat Formulation in XXXXXXXXXXXX and Influence Operations [S/NF]
And while we're checked in here at the shack of ill repute, a tribute: Robert Morris, Pioneer in Computer Security, Dies at 78
His son's case was all over the media, I'm sure y'all recall.
"Best IO-blog ever" -- You gets no bread with one meatball (pNSFW)
Showing posts with label C4I. Show all posts
Showing posts with label C4I. Show all posts
Jun 30, 2011
Nov 8, 2007
Building Partner Capabilities for Coalition Operations

From a new RAND paper, Building Partner Capabilities for Coalition Operations [124-page pdf]:
Ongoing operations and emerging missions create competing demands for the Army’s capabilities, resulting in requirement gaps that the Army is unable to fill by itself. Although there are other ways to fill capability gaps (e.g., with other Services, contractors, or increased Army end-strength), national and Department of Defense (DoD) strategic guidance emphasizes the need to leverage the capabilities of allies and partners to fill these gaps. Thus, this monograph is concerned with how the Army should focus its security cooperation activities to build the most appropriate capabilities in partner armies.
(...)
The monograph ... identifies U.S. Army capability gaps through a review of strategic and operational guidance documents and relevant Army and Joint studies. Because the Army is a supporting entity, its capability gaps reflect Combatant Command (COCOM) requirements, taking into account Integrated Priority Lists (IPLs), Joint Operating Concepts (JOCs), and COCOM Theater Security Cooperation (TSC) strategies. The result of the review is a set of relevant capability gaps that may be appropriate for building in partner armies and that form the analytic basis for subsequent chapters.
Next, the monograph provides a five-step process for matching U.S. Army capability gaps with candidate partner armies. It presents a set of criteria to help Army planners select candidate partner armies for training or equipping programs. The five steps are (1) determine the relative importance of capability gaps to the U.S. Army in specific situations, (2) consider the level of effort required to build the capability in a partner army, (3) identify capabilities of shared interest to the U.S. Army and the partner army, (4) identify candidate partner armies based on past participation in U.S.-led operations, and (5) determine existing partner army capabilities. The process aims to help Army planners identify which capabilities are of mutual benefit to the United States and partner nations. Finally, the study team applied the five-step process to the data available for one illustrative TEP [Train and Equip Program] to gauge its predictive ability.
(...)
The study team reviewed studies conducted by Training and Doctrine Command’s (TRADOC) Army Capabilities Integration Center (ARCIC) and the G-3. In addition, the study team consulted with experts from the Joint Staff to determine if there are additional capability gaps not identified by the Army. The ARCIC, part of TRADOC, produced two of the four studies used by the study team. These two studies—the Capability Needs Analysis (CNA) and the Capability Gap Analysis (CGA)—speak directly to current Army capability gaps. It is important to note that the studies used the Combatant Commanders’ IPLs and the JOpsC as primary sources for identifying these gaps.
(...)
This appendix provides the definitions for the capability gaps identified in Chapter Three. Reproduced here verbatim are the definitions for each capability gap as specified in the three Army studies. ...
C4 and Information Operations
CGA Study
Defined as voice, data, and video communication support to the tactical fight and the capacity and ability to communicate dismounted-to-dismounted, dismounted-to-mounted at a tactical level in all environments. Focused on, but not limited to, battalion level and below. Includes the ability to analyze intelligence and other information and provide that information to units to permit the conduct of operations. Also includes the delivery of timely intelligence information to tactical units or the accessibility by tactical units to this information.
CNA Study
Defined as open architecture C4 systems that are reliable under all circumstances and that operate at extended ranges from deployment through operations in theater and through redeployment. These systems of systems will readily share information throughout the force.
Workshop Discussion
Not discussed. Determined to be for high-end allies or remain organic to the U.S. Army.
Sep 28, 2007
Byting Back — Regaining Information Superiority Against 21st-Century Insurgents
A new RAND paper proposes the creation of an Integrated Counterinsurgency Operating Network (ICON) to better handle information requirements for battlespace awareness in an amorphous environment.
Byting Back — Regaining Information Superiority Against 21st-Century Insurgents. (195-page pdf)
U.S. counterinsurgency efforts in Iraq and Afghanistan have failed to exploit information power, which could be a U.S. advantage but instead is being used advantageously by insurgents. Because insurgency and counterinsurgency involve a battle for the allegiance of a population between a government and an armed opposition movement, the key to exploiting information power is to connect with and learn from the population itself, increasing the effectiveness of both the local government and the U.S. military and civilian services engaged in supporting it.
Utilizing mostly available networking technology, the United States could achieve early, affordable, and substantial gains in the effectiveness of counterinsurgency by more open, integrated, and inclusive information networking with the population, local authorities, and coalition partners.
The most basic information link with the population would be an information technology (IT)-enhanced, fraud-resistant registry-census. The most promising link would come from utilizing local cell phone networks, which are proliferating even among poor countries. Access to data routinely collected by such networks can form the basis for security services such as enhanced-911 and forensics. The cell phones of a well-wired citizenry can be made tantamount to sensor fields in settled areas. They can link indigenous forces with each other and with U.S. forces without interoperability problems; they can also track the responses of such forces to emergencies.
Going further, outfitting weaponry with video cameras would bolster surveillance, provide lessons learned, and guard against operator misconduct.
Establishing a national Wiki can help citizens describe their neighborhoods to familiarize U.S. forces with them and can promote accountable service delivery.
All such information can improve counterinsurgency operations by making U.S. forces and agencies far better informed than they are at present. The authors argue that today’s military and intelligence networks — being closed, compartmentalized, controlled by information providers instead of users, and limited to U.S. war fighters — hamper counterinsurgency and deprive the United States of what ought to be a strategic advantage.
In contrast, based on a review of 160 requirements for counterinsurgency, the authors call for current networks to be replaced by an integrated counterinsurgency operating network (ICON) linking U.S. and indigenous operators, based on principles of inclusiveness, integration, and user preeminence.
Utilizing the proposed ways of gathering information from the population, ICON would improve the timeliness, reliability, and relevance of information, while focusing security restrictions on truly sensitive information. The complexity and sensitivity of counterinsurgency call for vastly better use of IT than has been seen in Iraq and Afghanistan.
Labels:
Afghanistan,
C4I,
COIN,
Information Operation,
Iraq,
Irregular Intelligence,
pdf
Sep 15, 2007
People's Information War

As a follow-up to yesterday's China Info War post, we bring you the gist of a pretty decent piece by a Hong Kong-based defense analyst.
A careful look at articles and seminars on the topic of "information warfare" from within the People's Liberation Army reveals that the PLA is now placing high priority on this type of computer warfare. A top-level information warfare command has been established under the Fourth Department of the PLA General Staff Headquarters.
At previous conferences and seminars on this subject, Chinese military experts have put forward the concept that information warfare should include a peacetime "information struggle" in the political, diplomatic, financial, cultural and economic areas. At one such conference, the Fourth Department of the PLA raised the idea of establishing the information warfare leadership group at the top level of the Chinese military.
The PLA is also carefully researching U.S. military strategies in this field. Most textbooks on computer warfare used by the U.S. military have been translated into the Chinese language, including "FM 100-6 Information Operations" and "JP 3-13 Joint Doctrine for Information Operations" compiled by the Pentagon. Meanwhile, the PLA has also published two textbooks on information operations. At the level of research institutes, the PLA has established two centers for information operations.
Experts from the 81178 Unit of the PLA believe that a future information war will require combined offensive and defensive tactics. Their offensive tactics include electronic attacks, network attacks and military deception; defensive tactics include information counterattacks, information protection and recovery. This yields insight into how the Chinese military views the relationship between military deception and network attacks.
As for information warfare in joint landing operations, experts from the Command Headquarters of the Jinan Military Region said in an article that an enemy's C3I system should be a prominent target of attack, and emphasis should be placed on disabling the whole network of the adversary, training and employing "cyber warriors" (hackers) and establishing a "Special Cyber Force."
Experts from the Chinese National Defense University also stressed in a report that cyber attacks would become the greatest threat in future warfare. As a consequence, "cyber warriors, cyber spies, cyber propaganda teams and cyber hacker teams" should be employed to crack the enemy's military intelligence and disrupt its computer network and intelligence systems, the report said.
It also put forward the concept of a "people's information war" for the first time, describing this as a form of national non-symmetric warfare, with the people at the core, computers as the weapons, knowledge as the ammunition and the enemy's information network as the battlefield. These experts believe that ordinary people can be mobilized to provide global information support, spread global propaganda and conduct global psychological warfare. Such attacks could be launched from anywhere in the world at the enemy's military, political and economic information systems. If necessary, the experts suggested, computers currently under the control of Chinese enterprises could be dispersed among the people and connected to volunteer Web portals around the world, which would become a combined strategic cyber attack force. The article concluded by emphasizing that training "hacker warriors" should be a priority within the Chinese military.
The Chinese military has also started applying so-called "human wave" tactics to establish its cyber war network, which is internally referred to as the information network squad. The first such cyber operation unit to be set up was the Shandong Zaozhuang Municipal Militia Information Network Squad, with members comprising staff from the Zaozhuang Municipal Telecommunications Bureau. The 48 members of the squad all hold professional titles in computer technology.
The hacker attacks upon overseas Web sites were quite likely launched by similar military cyber operation squads. The establishment of this "information militia" warfare network means that the concept of a "people's war" has been officially introduced in the realm of information warfare.
The Chinese military has paid high attention to computer warfare over the years, and its capability to engage in information operations is now taken as an important benchmark in the improvement of the overall "soft combat power" of the Chinese armed forces. As a result, the PLA has introduced such slogans as "control information" and "information is combat strength."
After the Chinese Embassy in Belgrade was mistakenly bombarded by NATO aircraft in 1999 during the Kosovo conflict, Chinese hackers launched waves of attacks upon U.S. networks. Most of these attacks were from the "information militia" -- who claim to have set a record of successfully invading 10 U.S. government Web sites each hour.
In a strategy aimed at attacking the enemy from the rear, China is already launching an information World War, a new type of People's Information War.
Sep 14, 2007
China's Cyber Probes -- Test of Disruption Tactic?

China's current military doctrine stresses "information dominance", achieved not necessarily through advances in technology, but instead by tactical innovations in the operational sphere.
We have likely been seeing one of these tactical gambits in practice lately.
When suspected Chinese hackers penetrated the Pentagon this summer, reports downplayed the cyberattack. The hackers hit a secure Pentagon system known as NIPRNet – but it only carries unclassified information and general e-mail, Department of Defense officials said.
Yet a central aim of the Chinese hackers may not have been top secrets, but a probe of the Pentagon network structure itself, some analysts argue. The NIPRNet (Non-classified Internet Protocol Router Network) is crucial in the quick deployment of US forces should China attack Taiwan. By crippling a Pentagon Net used to call US forces, China gains crucial hours and minutes in a lightning attack designed to force a Taiwan surrender, experts say.
China's presumed infiltration underscores an ever bolder and more advanced capability by its cybershock troops. Today, of an estimated 120 countries working on cyberwarfare, China, seeking great power status, has emerged as a leader.
"The Chinese are the first to use cyberattacks for political and military goals," says James Mulvenon, an expert on China's military and director of the Center for Intelligence and Research in Washington. "Whether it is battlefield preparation or hacking networks connected to the German chancellor, they are the first state actor to jump feet first into 21st-century cyberwarfare technology. This is clearly becoming a more serious and open problem."
China is hardly the only state conducting cyberespionage. "Everybody is hacking everybody," says Johannes Ullrich, an expert with the SANS Technology Institute, pointing to Israeli hacks against the US, and French hacks against European Union partners. But aspects of the Chinese approach worry him. "The part I am most afraid of is … staging probes inside key industries. It's almost like sleeper cells, having ways to [disrupt] systems when you need to if it ever came to war." ...
Probes of the Pentagon system that would bring US intervention should China attack Taiwan are part of a program dating to the 1990s that links cyberwarfare to real-world military action by China's People's Liberation Army. The very probe shows success in China's long-term program, experts say.
"The Chinese want to disrupt that unofficial network in a crucial time-frame inside a Taiwan scenario," says Mr. Mulvenon. "It is something they've written about. When you read what Chinese strategists say, it is the unclassified network they will go after … to delay deployment. China is developing tremendous capability." ...
Of particular alarm for Washington and other world capitals are so-called "zero-day attacks" – cyberpenetrations that look for software flaws to exploit. This is not an uncommon pastime for hackers. But in China's case, suspicion falls on professional hackers, says Sami Saydjari, a Defense Department computer-security veteran who now heads a firm called Cyber Defense Agency in Wisconsin. ...
For several years, China has focused most of its military research and production on a high-tech air and missile-attack force – to overwhelm Taiwan. Hence, China's probe of the Pentagon NIPRNet. "They want to be able to attack the Net. They don't need a supersexy penetration program," Mulvenon argues. "They just bomb the Net itself. They disrupt the deployment of our military, simultaneously saturate Taiwan, delay the US arrival, and Taiwan capitulates. It's what they talk about."
Labels:
C4I,
China,
Espionage,
Information Operation,
Irregular Intelligence
Sep 10, 2007
DOD Global Information Grid Architectural Vision
As a follow-up to our July piece on the IPv6 (and beyond)-based U.S. military Global Information Grid (see A New GIG in Town), we draw your attention to a newly released paper, the DOD's GIG Architectural Vision statement.Department of Defense Global Information Grid Architectural Vision (39-page PDF)
Information is the key commodity in the target GIG, and vast amounts of data are available in near-real time to information consumers. This includes intelligence, business process, logistics, status, Radio Frequency Identification Device (RFID), sensor, raw, processed, structured, unstructured, and multi-media data. Recognition of information as a strategic, enterprise asset, coupled with significant improvements in IA and IT capabilities, underlie the willingness of information producers and providers to share information. Data capture, retention, and sharing are key requirements for all new GIG capabilities. Using automated tools, information providers ‘post’ information to the GIG (so that it is visible, accessible, and understandable to others) as soon as it becomes available. For example, streaming video from an unmanned sensor is ‘posted’ to the net as it is produced. It is then available to multiple users such as the local tactical Commander and CONUS-based intelligence analysts.h/t Bob Brewin
Sharing information is enhanced through a set of automated activities and capabilities including the tagging of information with discovery, semantic, syntax, access control, and other metadata. Metadata is cataloged and discoverable allowing even unanticipated information consumers to find and access the information they need. It is also enhanced by the formation of ad hoc Communities of Interest (COIs) focused on sharing information for specific joint missions/tasks. At a minimum, these COIs agree on a common language and structure for data, and identify relevant information sources. Users can find and access the information they require by advanced search and retrieval methods (pull) or by identifying, in advance, their information requirements (smart pull). Rapidly developed and fielded applications and services (discussed in more detail in Section 4) support advanced, automated methods to fuse, process, visualize, and exploit information in ways tailored to the user needs.
Finally, users explicitly trust the availability, authenticity, confidentiality, non-repudiation, integrity, and survivability of the information, assets, and services of the assured target GIG. They also trust the resources that users need to access, share, and use, are not static but can be adjusted to support changing priorities and requirements. GIG NetOps is an enterprise-wide construct that includes procedural and technological elements including doctrine, organization, training, materiel, leadership and education, personnel, and facilities (DOTMLPF). It is used to operate and defend the GIG in support of timely and secure operations and information sharing throughout the DoD and with mission partners. The target GIG is operated and defended as a unified, agile, end-to-end information enterprise that is protected, optimized, and responsive to user needs. Operational GIG capabilities are continually analyzed and provisioned; configurations are controlled; performance is monitored and anticipated; vulnerabilities are mitigated; and resource allocations (including spectrum) are dynamically adjusted to optimize the performance and security of the GIG and meet specific mission demands and priorities. (...)
All services and information in the target GIG are published to the enterprise (i.e., visible) and are accessible and understandable to the user independent of geography or organization. In addition, all GIG services are assured, which means that the design and implementation of the functionality provided by services provide confidence that security features, practices, procedures, and architecture mediates and enforces the security policy. Assured also means that the provider of the service is validated and that the consumer of the service: can trust the use of services from many different providers, can obtain validated information on the identity of providers, and may be able to negotiate specific performance guarantees in service level agreements. All service providers use a common set of service description information to enable consistent discovery and use of the services.
Services are monitored and managed as part of NetOps. Service consumers will have access to real-time reliability, maintainability, and availability metrics in order to make informed decisions on the reliability of the service for use in mission capabilities. Service providers provide real-time operational status and long-term service-level performance.
Jul 24, 2007
Deep Green

DARPA (The Defense Advanced Research Projects Agency) is asking the IT world for proposals to create a state-of-the-art automated battlefield decision-making system. (50 page pdf)
The scene in Dr. Strangelove where Gen. Ripper and Group Captain Mandrake discuss the mid-20th century paradigm shift from the politicians to the generals vis à vis the capability of and responsibility for strategic military thought comes to mind.
The implication of the envisioned new system (called "Deep Green" by DARPA) is that it is time now for the generals to pass the baton to the computers.
The Defense Advanced Research Projects Agency (DARPA) Information Processing Technology Office (IPTO) seeks strong, responsive proposals from well-qualified sources for a new technology program called Deep Green. Deep Green will build a battle command decision support system that interleaves anticipatory planning with adaptive execution. Deep Green must be capable of addressing the full spectrum of joint and combined arms capabilities available to the modular brigade commander, drastically increasing the option and future space. This will allow the commander to think ahead, identify when a plan is going awry, and help develop alternatives "ahead of real time." The commander (and his support staff) is involved in essentially two major asynchronous functions: generating options and making decisions. The goal of this program is to create a commander-driven system to assist the commander and his support staff in generating options or Courses of Action (COAs).
Deep Green will aid in battle command and commander’s visualization by creating technologies that make it easier for the commander to articulate options to consider and anticipate the possible futures that result from those options. This proactive analysis will help predict which possible futures are becoming more likely – before they occur. Given that information, the commander can make better decisions and focus planning efforts (the generation of future branches and sequels) on where they can be the most useful. To accomplish this, Deep Green will focus on the following functional components: The Commander’s Associate (which consists of Sketch to Plan and Sketch to Decide), Crystal Ball, and Blitzkrieg.
There are six (6) tasks under the envisioned Deep Green program:Task 1: Commander’s Associate (Sketch to Plan and Sketch to Decide)
Task 2: Blitzkrieg
Task 3: Crystal Ball
Task 4: Automated COA Generation
Task 5: Integration
Task 6: Test and Evaluation
(...)
The United States has a compelling need for reliable information affecting military command, soldiers in the field, and national security.
Today’s technical barriers include the following issues:■ New technology is needed for machine induction of intuitively expressed plans.■ Multi-modal (sketch and speech) collaborative technologies must be extended to incorporate modern learning technology that induces plans and the user’s intent from intuitive, coarse-grained plan descriptions.
■ Existing AI planning & monitoring systems■ are largely deterministic in nature, while the battlefield is inherently stochastic;
■ focus on full automation rather than commander-driven plan generation; and
■ are reactive in nature, re-planning after the plan has broken
■ The current generation of combat models■ run slowly,
■ generate a narrow spread of possible outcomes, and
■ require significant manual intervention.
The overall goal of Deep Green is to provide a technology that allows the commander
to:■ generate and analyze options quickly, including generating the many possible futures that may result from a combination of friendly, enemy, and other coursesof action;
■ use information from the current operation to assess which futures are becoming more likely in order to focus the development of more branches and sequels; and
■ make decisions cognizant of the second- and third-order effects of those decisions.
Deep Green is composed of tools to help the commander rapidly generate courses of action (options) through multimodal sketch and speech recognition technologies. Deep Green will develop technologies to help the commander create courses of action (options), fill in details for the commander, evaluate the options, develop alternatives, and evaluate the impact of decisions on other parts of the plan. The permutations of these option sketches for all sides and forces are assembled and passed to a new kind of combat model which generates many qualitatively different possible futures. These possible futures are organized into a graph-like structure. The commander can explore the space of possible futures, conducting “what-if” drills and generating branch and sequel options. Deep Green will take information from the ongoing, current operation to estimate the likelihood that the various possible futures may occur. Using this information, Deep Green will prune futures that are becoming very improbable and ask the commander to generate options for futures that are becoming more likely. In this way, Deep Green will ensure that the commander rarely reaches a point in the operation at which he has no options. This will keep the enemy firmly inside our decision cycle.
(...)
Security classification guidance on a DD Form 254 (DoD Contract Security Classification Specification) will not be provided at this time since DARPA is soliciting ideas only and does not encourage classified proposals in response to this announcement. However, after reviewing incoming proposals, if a determination is made that contract award may result in access to classified information, a DD Form 254 will be issued upon contract award. If you choose to submit a classified proposal you must first receive the permission of the Original Classification Authority to use its information in replying to this announcement.
Jul 12, 2007
A New GIG In Town

The Global Information Grid (GIG), an open-yet-secure mega-Internet in which all soldiers may have their own IPv6 address, is moving from the concept phase and into the hardware/software development phase (see the figure). In a sense, it's ironic that the defense and intelligence establishment is reinventing what it helped to create in the first place, but the commercial Internet is too vulnerable to be a military asset.
The Internet itself is the offspring of the military's ARPANET. FidoNet, UUCP, and other networks soon followed. Over time, TCP/IP made all of these systems interoperable. That ad-hoc development allowed for too many weakpoints and hidey-holes in the Internet and the World Wide Web, making it unacceptable for battlefield command and control operations. So, it was back to the drawing board.
GENESIS
GIG was born on Sept. 19, 2002 when a directive from the Deputy Secretary of Defense titled "Global Information Grid Overarching Policy" spelled out its definition: "The globally interconnected, end-to-end set of information capabilities, associated processes, and personnel for collecting, processing, storing, disseminating and managing information on demand to warfighters, policy makers, and support personnel."
The paper mandated that the GIG include all owned and leased communications and computing systems and services, software, applications, data, security services, and other associated services like National Security Systems.
Its purpose would be to support all Department of Defense (DoD), national security, and related intelligence community missions and functions—"in war and in peace"—from any operating location: bases, posts, camps, stations, etc. Additionally, it would provide interfaces to coalition, allied, and non-DoD users and systems.
That's the top-level definition from a long document, so naturally, it's nebulous. To brief Congress, the General Accounting office published an assessment, The Global Information Grid and Challenges Facing Its Implementation. Running only 37 pages, it's one of the clearest overviews, summarizing how the GIG is intended to upgrade military operations (see the table). If you download it, scroll down to page 31 for a bibliography of relevant documents (see "Use The Net To Learn More About The Grid,").
The GIG has its roots in the concept of network-centric warfare, which is now more often called network-centric operations. Sources on the Web point to Admiral William Owens' description of a "system of systems" in a 1996 paper for the Institute of National Security Studies as a seminal event. Owens wrote of a potential system of intelligence sensors, command and control systems, and precision weapons for enhanced situational awareness, rapid target assessment, and distributed weapon assignment.
Also in 1996, the Joint Chiefs of Staff released a paper on "full-spectrum dominance." Subsequently, John Gartska, David Alberts, and Fred Stein wrote a book called Network Centric Warfare for the Command and Control Research Program (CCRP) that related a number of business case studies to a new theory of warfare based on a military network.
Toward the end of 2003, John Osterholz, the Pentagon's director of architecture and interoperability, addressed the top Internet hardware companies at an IPv6 Summit. (The GIG was going to use version 6 of the Internet Protocol, with its vastly larger capacity for IP addresses and improved security over IPv4, by sometime this year.) Osterholz said the military wanted to digitize every individual soldier and push data to the "very edges of the network," including sensors, remote platforms, and mobile force structures."
In support of the Pentagon's efforts, the North American IPv6 Task Force announced in October the launch of North America's largest IPv6 pilot network. Known as Moonv6 and taking place across the U.S. at multiple locations, the project is the largest permanently deployed multivendor IPv6 network in the world. The next Moonv6 Project will get under way the week of June 18, focusing on end-to-end secure network demonstrations, including rich media, voice, and software applications. This will hopefully validate real peer-to-peer applications without the need of a central authority.
COMING TO GRIPS WITH REALITY
The early days of the GIG were all about how the grid would transform military operations and make information instantly available across the battlefield. But now, as it gains traction, recent documents freely available on the Web deal with more practical issues.
In 2006, the GAO published DOD Management Approach and Processes Not Well Suited To Support Development of Global Information Grid. The report found DoD's management approaches too decentralized for an effort like the GIG, which depends on a high degree of coordination and cooperation.
The document recommended that DoD rework its leadership, investment decisions, accountability, and interorganization interaction policies. The DoD ultimately concurred.
Keeping the foxes out of the henhouse is another issue. Thomas Reardon, chief of the Intelligence Division for the Army Network Enterprise Technology Command/9th Army Signal Command, presented "Threats And Risks In Information Technology (IT) Acquisition And Software Assurance" at the 2006 LandWarNet Conference in Fort Lauderdale last August. Much of his talk focused on the "insider threat."
Compromised insiders could be acquisition officials, contracting officials, vendor-selection officials, or program managers. He pointed in particular to potential security problems with the commercial-off-the-shelf (COTS) components of network-centric operations systems. COTS has been a byword in military procurement since Defense Secretary William Perry's memorandum in 1994.
Reardon quoted a 2005 Defense Intelligence Agency report—Asian Telecommunications Companies Pose Potential Threat to US C4I Interests— which warned that foreign ownership of communications infrastructure can create vulnerabilities if the foreign company "can be influenced through direct ties to a potentially adversarial or economically competitive government." Systems administrators control priority information exchange and have the power to "monitor, disrupt, delay, exploit, and deny transit of communications on their networks."
The problem, as he put it, is that DoD policy does not preclude use of foreign commercial vendors. In fact, U.S. companies are becoming increasingly multinational and rely on foreign components and labor for IT products and services.
WHAT ABOUT IRAQ?
But how well can a military network deal with a guerrilla insurgency? The pieces of the military's data network that were in place for Operation Iraqi Freedom in the spring of 2003 successfully directed the almost 300,000 troops engaged in the "shock and awe" assault. From Afghanistan came success stories of drone-directed airstrikes in support of troops involved in skirmishes and against truck convoys.
But does the GIG have anything to do with improvised explosive devices and suicide bombers? Those questions fall under the subject of counter-insurgency, which has been a problem for conventional military forces since biblical times.
The GIG is only a partial bulwark against insurgents. "The people are like water and the army is like fish," Mao Zedong once said in reference to Chinese guerrilla tactics against their Japanese invaders. However, today's insurgents swim in the sea of the Internet. The military hopes the GIG will be a better and more private Internet.
-Excerpt From Electronic Design
Jul 11, 2007
Would You Like To Swing On a STAR?

The Federal Bureau of Investigations is developing a computer-profiling system that would enable investigators to target possible terror suspects, according to a Justice Department report submitted to Congress yesterday [to the Senate Judiciary Committee].
The System to Assess Risk, or STAR, assigns risk scores to possible suspects based on a variety of information, similar to the way a credit bureau assigns a rating based on a consumer's spending behavior and debt. The program focuses on foreign suspects but also includes data about some U.S. residents. A prototype is expected to be tested this year.
Justice Department officials said the system offers analysts a powerful new tool for finding possible terrorists. They said it is an effort to automate what analysts have been doing manually. ...
STAR is being developed by the FBI's Foreign Terrorist Tracking Task Force, which tracks suspected terrorists inside the country or as they enter. ...
After STAR has received the names of persons of interest, it runs them through an FBI "data mart" that includes classified and unclassified information from the government, airlines and commercial data brokers such as ChoicePoint. Then it runs them through the terrorist screening center database, which contains hundreds of thousands of names, as well as through a database containing information on non-citizens who enter the country. It also runs the names against information provided by data broker Accurint, which tracks addresses, phone numbers and driver's licenses.
The report said access to STAR would be limited to trained users and that data would be obtained lawfully. Results would be kept within the FBI's terrorist task force, the report said.
Jul 4, 2007
CRS Report: Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues
Here's a copy of the new 17 page (pdf) CRS Report for Congress: Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues.Not much new, except a short discussion of the new USAF Cyber Command.
Happy Independence Day.
Labels:
101,
C4I,
Information Operation,
pdf
Domestic Political Cyberwar in Russia

A political battle is raging in Russian cyberspace.
Opposition parties and independent media say murky forces have committed vast resources to hacking and crippling their Web sites in attacks similar to those that hit tech-savvy Estonia as the Baltic nation sparred with Russia over a Soviet war memorial.
While they offer no proof, the groups all point the finger at the Kremlin, calling the electronic siege an attempt to stifle Russia's last source of free, unfiltered information.
The victims, who range from liberal democrats to ultranationalists, allege that their hacker adversaries hope to harass the opposition with the approach of parliamentary balloting in December and presidential elections in March.
Some independent experts agree.
"A huge information war awaits Russia before the elections," said Oleg Panfilov of the Center for Journalism in Extreme Situations.
The groups claim the attackers use vast, online networks of computers infected with malicious software — whose owners probably aren't aware they are involved — to paralyze or erase targeted Web sites.
Stanislav Belkovsky, a political analyst believed to have close ties to Kremlin insiders, said a senior associate of President Vladimir Putin is leading the cyber assault. The government denies it and insists it has nothing to do with the onslaught. The Kremlin said hackers could easily forge Internet Protocol addresses registered to government offices.
Belkovsky, founder of the Moscow-based National Strategy Institute, said the Kremlin is upset that it has been unable to control the political content of online media. "The Kremlin can't just tell their editors to remove an unwanted publication," he said.
The attacks are similar to assaults — sometimes a million computers strong — unleashed in April and early May against Web sites in Estonia. Officials there say waves of attacks crashed dozens of government, corporate and media Web sites.
The cyber warfare included computer-generated spam and so-called Distributed Denial-of-Service, or DDoS, attacks. It erupted during violent protests by ethnic Russians against the decision to move a Soviet-era Red Army monument out of downtown Tallinn, the Estonian capital.
The DDoS attacks involve a flood of computers all trying to connect to a single site at the same time, overwhelming the computer server that handles the traffic. Estonian authorities claimed they traced the attacks to Kremlin IP addresses.
Outside experts say blocking this type of Web assault is difficult or impossible because the host server has no way of distinguishing between legitimate and bogus requests for access.
Government security services have long been suspected of engaging in hacking. In 1999, an unidentified hacker in Moscow penetrated U.S. Defense Department computers for more than a year, copying classified naval codes and data on missile systems. The Kremlin denied involvement. ...
Mainstream media have also come under cyber-assault, especially when they carry information likely to draw the attention of the government.
Kommersant's Web editor, Pavel Chernikov, said the major daily newspaper's site was attacked in early May. He called it retaliation for publishing a transcript of the interrogation of Boris Berezovsky — a self-exiled oligarch who lives in London — by Russian investigators.
While British prosecutors have identified a former KGB agent living in Moscow as the prime suspect in the murder of Russian spy Alexander Litvinenko, Russian authorities have focused on Berezovsky, Putin's political foe.
On the same morning, the Web site of Ekho Moskvy, a liberal Moscow radio station where criticism of Kremlin policies can often be heard, was brought down by a DDoS attack.
The United States — especially the government sector — was the target of more than a half of DDoS attacks worldwide, according to Symantec. The FBI recently arrested several DDoS hackers as part of "Operation Bot Roast" sting.
Nothing of the kind is happening in Russia.
Labels:
C4I,
Information Operation,
perception management,
Russia
Jun 14, 2007
Cyberattack Solicitations
In an unusual act of candor, both the Army and Air Force in the past two months have issued solicitations asking the computer industry to provide technologies the services can use to wage offensive cyberattacks against enemy computer systems.
The Army's Communication and Electronics Command last month released an announcement asking the IT industry to present technologies that it could use to infiltrate enemy computer networks and communications systems. The military refers to such cyberattacks as "offensive information operations," or OIO.
The Army acknowledged in the announcement that it already has waged cyberattacks on enemy networks and communications platforms, but provided no details. But it wants to "leverage innovative technologies" to improve its cyberattacks "and prevent enemy forces from detecting and countering efforts directed against them," according to the announcement. "Technologies designed to interrupt these modern networks must use subtle, less obvious methodology that disguises the technique used, protecting the ability whenever possible to permit future use."
The Air Force also is seeking offensive cyber warfare capabilities, according to an announcement and a request for information released in April. The Air Force's 950th Electronic Systems Group said it is seeking industry help to define technologies and capabilities "associated with computer network attack." The technologies would be used to "disrupt, deny, degrade or deceive an adversary's information system," according to the request for information.
The Air Force wants technology that will help it map data and voice networks, provide it with access to those networks, conduct denial-of-service attacks on current and future network operating systems and network devices and engage in data manipulation on enemy networks.
The Air Force Electronic Systems Center declined to classify potential targets of the offensive cyber operations, such as nations, terrorists, rogue groups or individuals. "Specific capabilities or procedures cannot be discussed for security reasons," said Monica Morales, a spokeswoman for the Electronic Systems Center, the parent command of the 950th Electronic Systems Group. ...
Steven Aftergood, director of the Project on Government Secrecy for the Federation of American Scientists, described the release of the Army and Air Force offensive cyberattack solicitations as significant, because the services have only released limited information on their cyberattack plans, operations or technologies. These solicitations are more detailed.
May 18, 2007
SIPRNet To Be Opened To Key Allies
Can't help but notice that we aren't sharing JWICS. Smart move.The National Security Agency is working to open classified Defense Department communications networks to key allies, a move that the U.S. intelligence community has resisted for years, according to an internal NSA briefing presentation obtained by Government Executive.
NSA and Defense plan to open a classified network known as the Secret Internet Protocol Router Network (SIPRNet), to a small pool of trusted allies, including Australia, Canada, the United Kingdom and New Zealand, according to PowerPoint briefing slides dated April 27, 2007, and prepared by NSA's Office of Assured Information Sharing Technologies and Products.
SIPRNet, a closed system with no access to the Internet, is the primary means by which commanders communicate secret military strategies worldwide. It hosts a wide range of applications and systems, including classified e-mail and search capabilities. Core Defense systems, such as the Global Command and Control System and the Defense Message System, run over SIPRNet. Classified portals, such as Defense Knowledge Online and Army Knowledge Online, both of which serve as jumping-off points to classified military databases, also are hosted on SIPRNet.
Military and security analysts said the move to open the secret network to allies is a significant but necessary step to cement military partnerships with those countries, which have engaged in operations in Afghanistan and Iraq and have participated in maritime patrols in the Pacific.
"Warfare has become more coalition-centric, and more than ever we need to trust and rely on our partners," said Bernie Skoch, a consultant with Suss Consulting in Jenkintown, Pa.. Skoch, a retired Air Force brigadier general whose experience in military communications includes a stint as director of customer advocacy at the Defense Information Systems Agency, said NSA's plans represent "a significant change in the management of the SIPRNet."
For years, the four countries listed in the NSA briefing, along with other U.S. allies, have petitioned Defense to open SIPRNet to them so that they could have access to classified information they believed would help their militaries better coordinate operations with the United States. The Pentagon has resisted these requests.
"Foreign access to SIPRNet is, quite understandably, very limited," according to a document on the NATO Parliamentary Assembly Web site that explains how information technology is transforming warfare. "Only America's closest allies, the British and Australians, were granted access, albeit temporary and limited, in certain joint missions . . . .. ... In some cases in Iraq, the British could not even see or copy intelligence data gathered by British operatives themselves, when it fused with the Americans' own data stored on the SIPRNet ...."
But broadening access has its engineering challenges, said Skoch. Because SIPRNet has no access to the Internet, it has remained free of the cyberattacks that plague Defense's unclassified network -- called the Non-classified Internet Protocol Network, or NIPRNet -- which does connect with the Internet.
Allowing allies access to SIPRNet involves weighing the risks of cyberattacks and unauthorized users gaining access to classified information against the military benefits of sharing the information, Skoch said. In this case, he said, the benefits are "equally significant" to the risks.
Information sharing is an essential ingredient to any close partnership, said Alan Paller, director of research at the SANS Institute, a security training and certification organization in Bethesda, Md., which trains federal information security officials. The biggest obstacle to opening the SIPRNet to allies, Paller said, will be to "do so in a way that doesn't give away the jewels."
The briefing slides outline the strategy to obtain approval for opening SIPRNet, recommending that NSA leverage its position on the Defense Information Systems Flag Panel -- whose membership includes admirals, generals and civilian Senior Executive Service leaders in all four military services -- to change the policy. NSA intends to brief senior Defense leadership, ask for their approval and then work with DISA on the technical details, according to the briefing.
NSA did not respond to queries for comments on this article. The NSA public affairs office asked Government Executive not to run any article based on the briefing slides, which were marked unclassified, "For Official Use Only."
May 14, 2007
Swabbuckling Cuz's Control Grid
A new operational HQ for the U.K.'s National DNA Database (NDNAD) custodian unit has been officially opened by Joan Ryan MP, Under Secretary of State for nationality, citizenship and immigration.Commenting on the database, U.K. MP Joan Ryan said, "It is fascinating to see how the National DNA Database links to so many other tools[.]
Since first created in 1995, the NDNAD has become a key investigation tool which has revolutionized the way British police can identify targets for investigation and prosecution. No other police force has greater freedom to obtain, use and store genetic information from its citizens.
The Database, which links up with the national automated fingerprinting platform (IDENT1) and the Police National Computer (PNC), currently includes:
- 3.8 million individuals on the Database
- 300,000 crime scene profiles on the Database
In addition:
-Approximately 900 scene of crime to subject matches are reported per week
-Around 55,000 subject sample profiles are loaded to the Database per month
-Around 4,500 crime scene profiles are loaded to the Database per month
Taking a DNA sample (and fingerprints) from someone who has been arrested for a recordable offense and detained in a police station is now part of the normal process of a police arrest. It is no different to recording other forms of information such as photographs or witness statements.
-Jumbled & Rehashed Excerpts From Security Park
May 10, 2007
Target Estonia - Russians Coordinate World's Largest Internet Attack
Russia's slamming Estonia with the world's largest internet attack - ever!Estonia has faced down Russian rioters. But its websites are still under attack
For a small, high-tech country such as Estonia, the internet is vital. But for the past two weeks Estonia's state websites (and some private ones) have been hit by “denial of service” attacks, in which a target site is bombarded with so many bogus requests for information that it crashes.
The internet warfare broke out on April 27th, amid a furious row between Estonia and Russia over the removal of a Soviet war monument from the center of the capital, Tallinn, to a military cemetery. The move sparked rioting and looting by several thousand protesters from Estonia's large population of ethnic Russians, who tend to see the statue as a cherished memorial to wartime sacrifice. Estonians mostly see it rather as a symbol of a hated foreign occupation.
The unrest, Estonia says, was orchestrated by Russia, which termed the relocation “blasphemy” and called for the government's resignation. In Moscow, a Kremlin-run youth movement sealed off and attacked Estonia's embassy, prompting protests from America, NATO and the European Union. Perhaps taken aback by the belated but firm Western support for Estonia, Russia has back-pedalled. Following a deal brokered by Germany, Estonia's ambassador left for a “holiday” and the blockade ended as abruptly as it began.
But the internet attacks have continued. Some have involved defacing Estonian websites, replacing the pages with Russian propaganda or bogus apologies. Most have concentrated on shutting them down. The attacks are intensifying. The number on May 9th—the day when Russia and its allies commemorate Hitler's defeat in Europe—was the biggest yet, says Hillar Aarelaid, who runs Estonia's cyber-warfare defenses. At least six sites were all but inaccessible, including those of the foreign and justice ministries. Such stunts happen at the murkier end of internet commerce: for instance, to extort money from an online casino. But no country has experienced anything on this scale.
The alarm is sounding well beyond Estonia. NATO has been paying special attention. “If a member state's communications center is attacked with a missile, you call it an act of war. So what do you call it if the same installation is disabled with a cyber-attack?” asks a senior official in Brussels. Estonia's defense ministry goes further: a spokesman compares the attacks to those launched against America on September 11th 2001. Two of NATO's top specialists in internet warfare, plus an American colleague, have hurried to Tallinn to observe the onslaught. But international law is of little help, complains Rein Lang, Estonia's justice minister.
The crudest attacks come with the culprit's electronic fingerprints. The Estonians say that some of the earliest salvoes came from computers linked to the Russian government. But most of them come from many thousands of ordinary computers, all over the world. Some of these are run by private citizens angry with Estonia. Anonymously posted instructions on how to launch denial-of-service attacks have been sprouting on Russian-language internet sites. Many others come from “botnets”—chains of computers that have been hijacked by viruses to take part in such raids without their owners knowing. Such botnets can be created, or simply rented from cyber-criminals.
To remain open to local users, Estonia has had to cut access to its sites from abroad. That is potentially more damaging to the country's economy than the limited Russian sanctions announced so far, such as cutting passenger rail services between Tallinn and St Petersburg. It certainly hampers Estonia's efforts to counter Russian propaganda that portrays the country as a fascist hellhole. “We are back to the stone age, telling the world what is going on with phone and fax,” says an Estonian internet expert.
Mikko Hyppönen of F-Secure, a Finnish internet security company that has been monitoring the attacks, says the best defense is to have strong networks of servers in many countries. That is not yet NATO's job. But it may be soon.
-Edward Lucas
Labels:
C4I,
Information Operation,
propaganda,
Russia
May 4, 2007
Bush Trying To Immunize Telecos Over CATCH-ALL
The White House is still playing CYA on the CATCH-ALL program.The Bush administration is urging Congress to pass a law that would halt dozens of lawsuits charging phone companies with invading ordinary citizens' privacy through a post-Sept. 11 warrantless surveillance program.
The measure is part of a legislative package drafted by the Justice Department to relax provisions in the 1978 Foreign Intelligence Surveillance Act (FISA) that restrict the administration's ability to intercept electronic communications in the United States. If passed, the proposed changes would forestall efforts to compel disclosure of the program's details through Congress or the court system.
The proposal states that "no action shall lie . . . in any court, and no penalty . . . shall be imposed . . . against any person" for giving the government information, including customer records, in connection with alleged intelligence activity the attorney general certifies "is, was, would be or would have been" intended to protect the United States from terrorist attack. The measure, which has not yet been filed, is contained in a proposed amendment to the fiscal 2008 intelligence authorization bill. ...
Though laws exist that could immunize companies against civil and criminal liability in surveillance cases, invoking them would acknowledge that the firm cooperated with the government. Such knowledge could allow a terrorist to adjust tactics, the government argues.
Government lawyers crafted the immunity bill using terms deliberately vague in referring to activity that "would be or would have been" aimed at protecting the country from attack to avoid indicating whether a company cooperated.
But civil libertarians charged that blanket immunity would amount to a legislative pardon to telecommunications companies and others that have aided the government's warrantless surveillance, without explaining the pardon's basis. ...
The measure would gut Congress's efforts to conduct inquiries into the administration's surveillance program because a subpoenaed company or government official could invoke immunity, said Tim Sparapani, legislative counsel for the American Civil Liberties Union, which has sued the government to force a halt to its wiretapping program.
"The end result is not only will the Bush administration continue to stonewall Congress in its request for information on warrantless wiretapping, but no one who participated will have any threat above their head," Sparapani said. "You could just face a congressional subpoena and say, 'I'm sorry, I'm immunized.' "
May 2, 2007
USAF Cyberwar Prospectus

A new irregular warfare doctrine document working its way through the U.S. Air Force spells out how air power can aid U.S. and coalition forces in nontraditional fights, and says that disrupting adversaries' actions in cyberspace is increasingly important.
"The cyberspace domain may present numerous opportunities to directly target insurgents or to positively influence the population. Like air operations, cyber operations can strike directly at the node of interest, without first defeating 'fielded forces,'" says a draft version of the service's irregular warfare doctrine document. "For example, computer network attack may hinder or disrupt insurgent operations, or at least require them to expend resources defending their cyberspace assets."
The document, dated March 21 and stamped, "Draft – Not For Implementation," was obtained by Defense News this week. Gen. T. Michael Moseley, the Air Force chief of staff, has approved the draft document, it says.
During an irregular fight, coalition air commanders are more often using cyberspace to target the enemy, says the document.
"Critical to strategy development is the integration of cyberspace capabilities. Due to the political and operational sensitivity, some capabilities may not be viable," says the draft doctrine.
Moseley and service Secretary Michael Wynne have sought to elevate the service's actions in cyberspace. ...
"Degrading the adversary's use of cyberspace can prove detrimental to their operations. Network attack destroys, disrupts, corrupts, denies, delays or degrades information that resides in telephone and data service networks," says the document. "Attacking the networks will not only influence the adversary's decision making, but can also affect the target audience of the networked information."
Apr 23, 2007
Monday Morning Quarterbacking Over China Anti-Satellite Test

China has been the one pushing for a ban on space weapons. Maybe they needed to prove that they have a good bargaining chip.
After a Chinese interceptor smashed into a target satellite in January, Bush administration officials criticized the test as a destabilizing development.
It was the first successful demonstration of an antisatellite missile by any country in more than 20 years. Pentagon officials warned that the test had increased the threat to American satellites. Space experts fretted that it had spawned a cloud of orbiting debris. American diplomats complained to their counterparts in Beijing.
What administration officials did not say is that as the Chinese were preparing to launch their antisatellite weapon, American intelligence agencies had issued reports about the preparations being made at the Songlin test facility. In high-level discussions, senior Bush administration officials debated how to respond and even began to draft a protest, but ultimately decided to say nothing to Beijing until after the test.
Three months after the Chinese launching, a new debate has developed as to whether the administration properly handled the episode or missed an opportunity to discourage the Chinese from crossing a new military threshold.
The events show that the administration felt constrained in its dealings with China because of its view that it had little leverage to stop an important Chinese military program, and because it did not want to let Beijing know how much the United States knew about its space launching activities.
Labels:
C4I,
China,
Information Operation,
perception management
Mar 22, 2007
Résumé Building 101

George P. Bush, the son of former Florida Gov. Jeb Bush and nephew of President Bush, has been selected as one of 15 prospective ensigns for the intelligence unit of the Navy reserves.
He and the other members of the Class of 2007 will be sworn in this year, Lt. Cmdr. Bill Schroeder of the Navy Reserve Intelligence Command in Fort Worth said Wednesday. They will go through a two-week officer indoctrination school, a year of Navy basic intelligence training and be assigned to Navy reserve intelligence units close to their homes.
Navy intelligence officers collect and analyze information and provide guidance to help war fighters make decisions critical on the battlefield, Schroeder said.
Bush, a 30-year-old graduate of the University of Texas School of Law, will get no special treatment, he said.
"He will be held to the same standards as all of his other shipmates," Schroeder said. "He will go through the same training. He will have the same duties and responsibilities and have to display the same commitment as the rest of his shipmates."
The 15 were selected in February by a panel of Navy officers who considered their qualifications, skills and education.
Feb 26, 2007
The Best Laid Plans...

The first brigade of 2,700 American reinforcements is patrolling the capital, bringing the total U.S. troop presence in Baghdad to 40,000, and members of three additional Iraqi military brigades have entered the city, though not at full strength. Soldiers have opened 14 of the estimated 30 joint policing stations they will operate in the capital. ...
The so-called joint security stations envisioned under the plan are intended not only to generate intelligence about insurgents and militias but also to bring together Iraqi military and police personnel, who often fail to communicate, as well as U.S. troops. The stations will be scattered throughout the city's 10 newly designated security districts. ...
Lt. Col. Christopher C. Garver, a U.S. military spokesman, said that although part of the stations' function is to encourage Iraqis to visit, their locations would not be disclosed because of concern within the Iraqi government that such information would facilitate attacks.
Subscribe to:
Posts (Atom)
