Showing posts with label Cybercom. Show all posts
Showing posts with label Cybercom. Show all posts

Saturday, July 3, 2021

NSA, Cybercom Leader Says Efforts Have Expanded

 David Vergun at the DOD News offers the below piece: 

Adversaries have heavily invested in cyberspace operations and capabilities. As such, cyber operations, cybersecurity and information operations are increasingly important to the joint force, said the commander of U.S. Cyber Command, who's also the director of the National Security Agency. 

"The scope of what we need to defend and protect has dramatically expanded," Army Gen. Paul M. Nakasone said today during a virtual address to the U.S Naval Institute and Armed Forces Communications and Electronics Association's WEST Conference. 

The Defense Department's information network is composed of 15,000 sub-networks, 3 million users, 4 million computers, 180,000 mobility devices and 605 million website requests a day, he said.  

"We used to think about cyberspace as merely the need to protect these computer networks. And while it's a good place to start, the attack surface is much broader," Nakasone said. 

For example, protecting weapons systems is a related but distinct challenge compared to networks, he said. They require software updates and patches. In the case of the Navy, they're onboard ships that don't return to port for months at a time, making it even more challenging to provide timely updates. 

Another challenge with weapons systems is ensuring that cybersecurity considerations are implemented in the earliest phases of the acquisition cycle, he said. 

Protecting DOD's data is also a major challenge, he said. 

Understanding how state and non-state adversaries are able to successfully carry out cyberattacks is important, he said. "They learn over time in terms of what they can do. They're not static in the terms of how they approach cyberspace." 

In about the past 150 days, adversaries have successfully conducted supply chain attacks, particularly ransomware attacks, he said. In the last several years, election cybersecurity has taken on an increasingly important role. 

Terrorist groups are also mounting cyberattacks, he said. In response, the department has emphasized close teamwork between the NSA, Cybercom, and other commands — U.S. Special Operations Command, in particular. 

"We learned how to work closely with U.S. Special Operations Command, both to support their efforts against kinetic targets and to leverage their capabilities against virtual ones," he said. 

Nakasone also emphasized the importance of working with industry, academia, interagency partners like the FBI and the Department of Homeland Security, as well as with allies and partners. 

Having a skilled and motivated workforce is also critically important, he said. They need to have the right training and career paths and professional development opportunities, and the DOD must be open to their new ideas.

Thursday, May 25, 2017

Cybercom: Pace of Cyberattacks Have Consequences For Military, Nation


Cheryl Pellerin at the DoD News offers the below report:

WASHINGTON, May 24, 2017 — The intensifying pace of international conflict and cyber events has consequences for the U.S. military and for the nation at large, Navy Adm. Michael S. Rogers (seen in the below photo), commander of U.S. Cyber Command, told a House panel yesterday.

Rogers, also director of the National Security Agency, testified before the House Armed Services Emerging Threats and Capabilities Subcommittee on the fiscal year 2018 Defense Department budget request for Cybercom and its Cyber Mission Force support for defense operations.


Facing Advanced Cyber Threats

“Hardly a day has gone by during my tenure at Cyber Command that we have not seen at least one significant cybersecurity event occurring somewhere in the world,” said Rogers, adding, “We face a growing variety of advanced threats from actors who operate with ever-more sophistication and precision.”

In his written testimony, the admiral said that cyber-enabled destructive and disruptive attacks now have the potential to affect the property, rights and daily lives of Americans.

“We are particularly concerned as adversaries probe and even exploit systems used by government, law enforcement, military, intelligence and critical infrastructure in the United States and abroad,” Rogers said.

“We have seen states seeking to shape the policies and attitudes of democratic peoples,” he added, “and we are convinced such behavior will continue for as long as autocratic regimes believe they have more to gain than to lose by challenging their opponents in cyberspace.”

Lines of Operation

Cybercom tracks state and nonstate adversaries as they expand their capabilities to advance their interests in cyberspace and try to undermine U.S. national interests and those of the nation’s allies, the admiral said.

Conflict in the cyber domain is unfolding according to its own logic, he added, “which we continue to better understand. And we're using this understanding to enhance the department's and the nation's situational awareness and to manage risk in the cyber arena.”

Cybercom forces conduct full-spectrum military cyberspace operations to enable actions in all domains, he told the panel.

The command’s three lines of operation are to provide mission assurance for DoD operations and defend the DoD information environment, called the DoDIN, to support joint force commander objectives globally and deter or defeat strategic threats to U.S. interests and critical infrastructure, Rogers said.

Enhanced Authorities

Rogers requested a budget of about $647 million for Cybercom for fiscal 2018, a nearly 16 percent increase from fiscal 2017 to fund Cybercom's elevation from a subcommand of U.S. Strategic Command to a full unified combatant command, as directed by the 2017 NDAA.

The enhanced budget will be used, in part, to continue building out the cyber mission force and adding cyber-specific capabilities and tools, and funding Joint Task Force Ares and the Cyber Combat Mission Force to support the fight against the Islamic State of Iraq and Syria.

Rogers created JTF-Ares after receiving an execute order in 2016 from then-Defense Secretary Ash Carter authorizing Cybercom to "task organize" for specific missions that could last to last weeks, months or longer, the admiral said in written testimony.

He established the new organization to coordinate cyberspace operations against ISIS, providing unity of command and effort for Cybercom and coalition forces working to counter ISIS in cyberspace.

Rogers said the JTF-model has helped Cybercom direct operations in support of Centcom operations, and “marks an evolution in the command-and-control structure in response to urgent operational needs.”

He told the panel that all cyber mission force teams are scheduled to be fully operational by the end of fiscal 2018, and named some of the enhancement of command responsibilities and authorities Cybercom expects in 2018.

These include increasing cyber manpower, enhancing professionalization of the cyber workforce, building defensive and offensive capability and capacity, and streamlining what Rogers called “cyber-operations-peculiar” acquisition capabilities.

“These are critical enablers for cyber space operations in a dynamically changing global environment,” the admiral said, “and most or all of these particulars have been directed in recent National Defense Authorization Acts.”

Operational Successes

Rogers told the panel that Cybercom’s operational successes have validated concepts for creating cyber effects on the battlefield and beyond.

“Innovations are constantly emerging out of operational necessity and real-world experiences,” he said, “and meeting the requirements of national decision makers and joint force commanders continues to mature our operational approaches and effectiveness over time.”

Cybersecurity is a national security issue requiring a whole-of-nation approach that brings together public and private sectors of U.S. society, Rogers said, noting that the Cybercom Point of Partnership program in Silicon Valley, California, and Boston has proven successful.

The initiative, he told the panel, “link[s] our command to some of the most innovative minds from industry, working together on cybersecurity as we face 21st Century threats together in the private and public sectors.”

This, Rogers added, “combined with agile policies, decision-making processes, capabilities and command-and-control structures will ensure that Cyber Command attains its potential to counter our adversaries.”

Monday, August 18, 2014

Admiral Rogers: Cybercom Defending Networks, Nation


Cheryl Pellerin at the DoD News offers the below piece:

FORT MEADE, Md., Aug. 18, 2014 - U.S. Cyber Command continues to expand its capabilities and capacity, Navy Adm. Mike Rogers said Aug. 14.

The U.S. Cyber Command commander and director of the National Security Agency was speaking during an interview at the NSA headquarters building here.

"The decision to create [U.S. Cyber Command] was a ... recognition of a couple things. No. 1, the increasing importance of the cyber domain and the cyber mission set in Department of Defense operations in the 21st century," Rogers said.

Such a command would add to the department's ability to protect and defend its networks, and give policymakers and operational commanders a broader range of options, he said.

The second consideration involved DoD's mission to defend the nation, coupled with the potential of nation-states, groups and individuals to conduct offensive cyber activities against critical U.S. infrastructure.

In that scenario, the admiral said, defense officials thought it was likely the president would "turn to the secretary of defense and say, 'In your mission to defend the nation, I need you to do the same thing here in the cyber arena against this mission set critical to U.S. infrastructure, and I need an organization capable of doing that.'"

These conditions led the department to realize the need to create a traditional warfighting organization capable of executing a spectrum of cyberspace missions, Rogers said.

And, he added, they knew they needed to do so "with a dedicated professionalized workforce. This is not a pickup game where you just come casually to it."

Rogers said he focuses on five priorities for Cybercom.

These are to build a trained and ready cyber force, put tools in place that create true situational awareness in cyberspace, create command-and-control and operational concepts to execute the mission, build a joint defensible network, and ensure Cybercom has the right policies and authorities that allow it to execute full-spectrum operations in cyberspace.

Making progress is important to Rogers, who characterized his ultimate goal as bringing U.S. Cyber Command to a level where it's every bit as trained and ready as any carrier strike group in the U.S. Central Command area of responsibility or any brigade combat team on the ground in Afghanistan.

"My objective during my time as the commander, first and foremost," the admiral said, "is to ensure that we have brought to fruition the operational vision in cyber ... [to make sure] it's something real, it's something tangible, and it is operationally ready to execute its assigned missions."

That is happening as Cybercom brings its warfighting capability online, with the services generating a total cyber mission force of about 6,000 people by 2016, all trained to the same high standard and aligned in 133 teams with three core missions:

-- The Cyber National Mission Force, when directed, is responsible for defending the nation's critical infrastructure and key resources.

-- The Cyber Combat Mission Force provides cyber support to combatant commanders across the globe; and

-- The Cyber Protection Force operates and defends the DoD information network, or DoDIN.

Defending the DoDIN is the focus of a partnership in progress with the Defense Information Systems Agency, or DISA.

The agency provides command and control and information-sharing capabilities and a globally accessible enterprise information infrastructure to warfighters, the president and national leaders, and other mission and coalition partners. DISA, Rogers points out, is also a combat support agency.

The agency reports to acting DoD Chief Information Officer Terry Halvorsen, and its director is Air Force Lt. Gen. Ronnie D. Hawkins Jr. "I have always believed ... that we need to integrate operations and networks and our defensive workforce into one team," Rogers said, "and that you are more effective in operating a network and in defending a network when you do it with one integrated approach."

As a result, Rogers' team decided they needed to create a relationship with DISA, he said, adding, "At the moment there's no formal [command and control] line between us, but we're in the process of creating one." As part of that process Rogers collaborates with Halvorsen and Hawkins. "What I think we need to do," he said during their meeting, "is create an operational construct that creates a direct linkage [between] U.S. Cyber Command, DISA and U.S. Cyber Command service components." It's critical that the relationship includes the service components, Rogers said,

"Because, under the current network structure today, those networks are largely run by [the] services. So we've got to create a relationship between DISA and the services that is very operational because you've got to maneuver networks, you've got to react to changes, and you can't do that in a static kind of environment." He added,

"We're in the process of doing that and I expect to roll it out in the fall. ... You'll hear it referred to as JFHQ DoDIN," he said, or Joint Force Headquarters DoD Information Networks. Rogers said that he, Halvorsen and Hawkins agree, this is the future of DISA. "[DISA] will operate on the networks.

They'll be part of our defensive effort so they will be out operating on the networks just like us," he added. "One of the core missions is the defense of the DoDIN," Rogers said. "The forces associated with that mission will be assigned to DISA, to the services [and] to the combatant commanders." So, he added, DISA will have some operational control over the cyber mission force to help execute their mission. Another of Rogers' priorities for Cybercom is to help develop a common situational awareness of "what's happening in DoD networks," he said.

The commander highlighted the need for speed and agility in the cyber arena, adding, "If you can't visualize what you're doing ... you're not going to be fast or as agile, and thus arguably not as effective as you need to be." Rogers said, "As an operational commander I am used to the idea of walking into a command center, looking at a visual depiction that through symbology, color and geography enables me to very quickly come to a sense of what's happening in this space. We are not there yet in the cyber arena."

Establishing situational awareness in the cyber realm is a combination of technology and capability, the admiral said, and determining what knowledge is needed and what elements contribute to that. "Is what U.S. Cyber Command needs to know about what's going on in the network world the same thing as a strike group commander needs in the Western Pacific?

The same thing an Air Force air wing needs in Minot, North Dakota? The same thing a brigade combat team needs in Afghanistan? It will vary, so we've got to create a system that you can tailor to the needs of each commander," he said. Rogers noted there are many ongoing efforts to improve situational awareness, pointing out the need to work collaboratively to fix the problem. "We do have some tools right now," he added. "They're just not as mature and comprehensive as I'd like them to be."

Cyber is foundational to the future, the admiral said, and he often comments to his fellow operational commanders that cyber is a mission they have to own. "The wars of the 20th century taught most warfighting professionals that, no matter what you do, a good foundational knowledge of logistics is probably going to stand you in good stead," Rogers explained.

In the 21st century, he added, operational commanders may find that, regardless of their mission, they will need a sense of what's going on in their networks, where they're taking risk, and the impact of network structure and activities on their ability to execute the mission. "It's not something you turn to your communications officer ... or your CIO and say, 'I don't really understand this. Go out and do some of that for me.' That isn't going to get us where we need to go," the admiral said.

Rogers elaborated on the need for Cybercom to be ready. During his time as Cybercom commander, he said he expects that a nation-state, group or individual will attempt to engage in offensive, destructive capability against critical U.S. infrastructure, from the power grid to the financial sector.

The Presidential Policy Directive for Critical Infrastructure Security and Resilience outlines 16 designated U.S. Critical Infrastructure sectors. Rogers says he tells his team they have to be ready to respond to such a call. But for an attack on the United States, Cybercom will support the Department of Homeland Security, which is the lead agency for broader security protections associated with critical infrastructure, and partner with the FBI, which is the lead agency for domestic attacks and law enforcement.

"Our biggest focus really is going to be bringing our capabilities to bear to attempt to interdict the attack before it ever gets to us," the admiral said. "Failing that," he continued, "we'll probably also have some measure of capability that we can provide to work directly with those critical infrastructure networks to help address the critical vulnerabilities and where the networks could use stronger defensive capability."

To prepare for such interagency collaboration in the event of a domestic cyberattack, the command trains as it will fight, Rogers said. "In the military I'm used to the idea that you train like you fight. So we exercise [and] we replicate the things we think are going to occur in a combat scenario," the admiral said. "I want to do the exact same thing with the same set of teammates I'm going to operate with if we get the order to do so." The department and Cybercom already do internal exercises, he said, as well as ongoing interagency exercises such as Cyber Guard, in which elements of the National Guard, reserves, NSA and Cybercom exercise their support to DHS and FBI responses to foreign-based attacks on simulated critical infrastructure networks.

The whole-of-government exercise, completed June 17, was designed to test operational and interagency coordination and tactical-level operations to prevent, mitigate and recover from a domestic cyber incident.

Cyber Guard is a good example, Rogers said, "but I want to build on that. DHS and FBI were there but I think we can do even more." Information sharing and partnerships with the critical infrastructure sectors is an important aspect of enabling Cybercom to more effectively interdict and stop an attack, if directed to do so by the president and defense secretary, he added. The cyber threat is growing increasingly complex, the Cybercom commander said, and a more diverse set of actors is involved in the mission set, "from nation-states that continue to increase their capabilities, to groups, to individuals." In broad terms, he added, "you don't see a crisis in the world today that doesn't have a cyber aspect to it." For that reason and others, the ultimate construct of U.S. Cyber Command must be flexible, the admiral said.

"If you want to develop full-range capabilities and generate the maximum flexibility for their application, you've got to build a construct that recognizes we're going to be supported sometimes, we're going to be supporting other times, and sometimes we're going to be doing both simultaneously," Rogers said.

In one scenario Cybercom might be helping the commander in the Pacific, he said, and "at the same time we might be driving efforts to secure the U.S. financial infrastructure ... and trying to support U.S. Central Command. "It's just the nature of things," Rogers said, "because cyber is so global and so foundational." 

Friday, September 24, 2010

Cybercom Chief Details Cyberspace Defense

By Jim Garamone American Forces Press Service

WASHINGTON, Sept. 23, 2010 - U.S. Cyber Command stands ready to defend Defense Department networks, but laws and policies must be updated to protect the nation, the organization's commander said yesterday.

Army Gen. Keith B. Alexander (seen in the above official DoD photo) is the first commander of Cybercom, which stood up under U.S. Strategic Command in May, merging DOD's defensive and offensive cyber arms into one command.

The command operates in a new domain for the military – the man-made domain of cyberspace. The domain is just as important for military operations as land, sea, air and space, defense officials said. Cybercom directs military operations in cyberspace and is responsible for defense of crucial military networks.

The threat is real and continuing, Alexander said.

"The more you learn, the more you say we have to come together to protect this," the general said during a roundtable with reporters at the National Cryptologic Museum. Noting that Defense Department networks are scanned or probed 250,000 times an hour, Alexander said, "we have to do a better job defending it."

The networks are the lifeblood of commerce, power, finance and many other aspects of life today. There are 1.9 billion Internet users in the world today, Alexander said, and 4.6 billion cellular phone subscribers. The number of e-mails each day this year is around 247 billion, with 90 trillion e-mails sent in 2009. The Internet is a tremendous capability, Alexander said, but it also is an enormous vulnerability.

"Our intellectual property here is about $5 trillion," he said. "Of that, approximately $300 billion is stolen over the networks per year."

Cybercom's three main missions are to defend the defense information grid, launch the full spectrum of cyber operations on command, and to stand prepared to defend the nation's freedom of action in cyberspace, Alexander said.

The command has a budget of $120 million for this year and has about 1,000 military and civilian employees. Included in this is a 24/7 joint operations center that monitors the grid, detects attacks and neutralizes them. The command works with the Air Force, Navy, Army and Marine Corps cyber commands to parcel out how to defend the networks and who has responsibility for the specific nets.

Assigning responsibility needs to happen throughout the government, the general said, noting that technology has outpaced policy and law. The government, he added, still is dealing with laws that came out when the nation relied on rotary phones.

"The laws we did 35, 40 years ago are what we have to update," he said.

Alexander put two issues on the table. "First, we can protect civil liberties and privacy and still do our mission," he said. "There can be mistakes, but we can protect the First Amendment."
The second issue, he said, is that Cyber Command is defending the DOD networks now, and as directed, can help the Homeland Security Department defend its networks.

There is confusion over who does what, the general acknowledged, so White House officials are leading an effort to sort through the needs of cybersecurity and update the policies and issues. "They are looking at the policies and authorities that need [re-]doing, and what's the right way to approach it," he said.

Once the review is finished, he explained, the president must determine how the federal government will be organized to handle this.

Congress is also looking at the problems. "From my perspective," Alexander said, "I would like to war-game it and hypothesize what could happen and ensure the policies, laws and authorities allow us to do what people expect us to do. I don't want to fail in meeting the expectations of the American people, the White House and Congress."

Changing the policy is complex, and will take time and several tries to do it right, Alexander said. The general said he envisions a team handling things in cyberspace. The DHS, the FBI, other government agencies and private stakeholders – along with Cybercom – all have a role, he said, and getting the disparate agencies and entities to work together will be a priority for cyber defense.

Some questions still need to be answered, and policy makers need to take them into consideration, Alexander said.

They include:

-- What constitutes a cyber attack?

-- How do the laws of war pertain to operations in cyberspace?

-- What does deterrence look like in the cyber world, where it can take months to determine attack perpetrators and the cyber defense group may have nothing to strike back at?

These questions are valid, the general emphasized. In 2007, Estonia was hit by a cyber attack that crippled that nation's grid for weeks, he said, and a foreign intelligence agency compromised a classified U.S. military system in 2008.

The attacks can be disruptive, like the Estonia attack, or destructive, with lives lost and equipment and networks destroyed, Alexander said.

"Those are the kind of rules that have to be weighed and discussed," he added. "It's good to have that debate, and from my perspective, it is important that it is clear who has the responsibility to defend in that kind of requirement."

Note:

You can read the two Counterterrorism magazine pieces I wrote on cyber security and cyber warfare via the below link:

http://pauldavisoncrime.blogspot.com/2010/03/weapons-of-mass-disruption-cyber.html