Showing posts with label Navy Admiral Michael S. Rogers Commander U.S. Cyber Command Director National Security Agency. Show all posts
Showing posts with label Navy Admiral Michael S. Rogers Commander U.S. Cyber Command Director National Security Agency. Show all posts

Thursday, May 25, 2017

Cybercom: Pace of Cyberattacks Have Consequences For Military, Nation


Cheryl Pellerin at the DoD News offers the below report:

WASHINGTON, May 24, 2017 — The intensifying pace of international conflict and cyber events has consequences for the U.S. military and for the nation at large, Navy Adm. Michael S. Rogers (seen in the below photo), commander of U.S. Cyber Command, told a House panel yesterday.

Rogers, also director of the National Security Agency, testified before the House Armed Services Emerging Threats and Capabilities Subcommittee on the fiscal year 2018 Defense Department budget request for Cybercom and its Cyber Mission Force support for defense operations.


Facing Advanced Cyber Threats

“Hardly a day has gone by during my tenure at Cyber Command that we have not seen at least one significant cybersecurity event occurring somewhere in the world,” said Rogers, adding, “We face a growing variety of advanced threats from actors who operate with ever-more sophistication and precision.”

In his written testimony, the admiral said that cyber-enabled destructive and disruptive attacks now have the potential to affect the property, rights and daily lives of Americans.

“We are particularly concerned as adversaries probe and even exploit systems used by government, law enforcement, military, intelligence and critical infrastructure in the United States and abroad,” Rogers said.

“We have seen states seeking to shape the policies and attitudes of democratic peoples,” he added, “and we are convinced such behavior will continue for as long as autocratic regimes believe they have more to gain than to lose by challenging their opponents in cyberspace.”

Lines of Operation

Cybercom tracks state and nonstate adversaries as they expand their capabilities to advance their interests in cyberspace and try to undermine U.S. national interests and those of the nation’s allies, the admiral said.

Conflict in the cyber domain is unfolding according to its own logic, he added, “which we continue to better understand. And we're using this understanding to enhance the department's and the nation's situational awareness and to manage risk in the cyber arena.”

Cybercom forces conduct full-spectrum military cyberspace operations to enable actions in all domains, he told the panel.

The command’s three lines of operation are to provide mission assurance for DoD operations and defend the DoD information environment, called the DoDIN, to support joint force commander objectives globally and deter or defeat strategic threats to U.S. interests and critical infrastructure, Rogers said.

Enhanced Authorities

Rogers requested a budget of about $647 million for Cybercom for fiscal 2018, a nearly 16 percent increase from fiscal 2017 to fund Cybercom's elevation from a subcommand of U.S. Strategic Command to a full unified combatant command, as directed by the 2017 NDAA.

The enhanced budget will be used, in part, to continue building out the cyber mission force and adding cyber-specific capabilities and tools, and funding Joint Task Force Ares and the Cyber Combat Mission Force to support the fight against the Islamic State of Iraq and Syria.

Rogers created JTF-Ares after receiving an execute order in 2016 from then-Defense Secretary Ash Carter authorizing Cybercom to "task organize" for specific missions that could last to last weeks, months or longer, the admiral said in written testimony.

He established the new organization to coordinate cyberspace operations against ISIS, providing unity of command and effort for Cybercom and coalition forces working to counter ISIS in cyberspace.

Rogers said the JTF-model has helped Cybercom direct operations in support of Centcom operations, and “marks an evolution in the command-and-control structure in response to urgent operational needs.”

He told the panel that all cyber mission force teams are scheduled to be fully operational by the end of fiscal 2018, and named some of the enhancement of command responsibilities and authorities Cybercom expects in 2018.

These include increasing cyber manpower, enhancing professionalization of the cyber workforce, building defensive and offensive capability and capacity, and streamlining what Rogers called “cyber-operations-peculiar” acquisition capabilities.

“These are critical enablers for cyber space operations in a dynamically changing global environment,” the admiral said, “and most or all of these particulars have been directed in recent National Defense Authorization Acts.”

Operational Successes

Rogers told the panel that Cybercom’s operational successes have validated concepts for creating cyber effects on the battlefield and beyond.

“Innovations are constantly emerging out of operational necessity and real-world experiences,” he said, “and meeting the requirements of national decision makers and joint force commanders continues to mature our operational approaches and effectiveness over time.”

Cybersecurity is a national security issue requiring a whole-of-nation approach that brings together public and private sectors of U.S. society, Rogers said, noting that the Cybercom Point of Partnership program in Silicon Valley, California, and Boston has proven successful.

The initiative, he told the panel, “link[s] our command to some of the most innovative minds from industry, working together on cybersecurity as we face 21st Century threats together in the private and public sectors.”

This, Rogers added, “combined with agile policies, decision-making processes, capabilities and command-and-control structures will ensure that Cyber Command attains its potential to counter our adversaries.”

Friday, February 24, 2017

Admiral Rogers Discusses Near Future Of U.S. Cyber Command


Cheryl Pellerin at the DoD News offers the below report:

WASHINGTON, Feb. 24, 2017 — Navy Adm. Mike Rogers, the chief of U.S. Cyber Command, discussed the command’s future over the next five to 10 years yesterday at West 2017, a sea services event in San Diego co-sponsored by AFCEA International and the U.S. Naval Institute.

AFCEA is the international information technology, communications and electronics association for professionals in government, industry and academia.

Rogers, also director of the National Security Agency, fielded questions from moderator retired Navy Adm. James G. Stavridis, who’s now dean of the Fletcher School of Law and Diplomacy at Tufts University. He’s also chairman of the board of the U.S. Naval Institute and a senior fellow at the Johns Hopkins University Applied Physics Laboratory.

Topics included integrating cyber at the tactical level of warfare, modeling Cybercom after the structure used by the Special Operations Command, the Cybercom workforce, and the relationship between Cybercom and the private sector, all in the five-to 10-year horizon.

“Here's what we need to build toward -- in the immediate near term, elevating Cyber Command to a combatant command,” Rogers said, adding, “I think the potential for that happening in the near term is high.”

Cybercom today is a component of U.S. Strategic Command.


Tactical Cyber

Over the next five to 10 years the admiral said he would like to see cyber integrated offensively and defensively “down to the operational tactical level.”

Offensive cyber in some ways is treated like nuclear weapons, he added, “in the sense that their application outside a defined area of hostilities is controlled at the chief-executive level and is not delegated down.”

Rogers said he hopes that over the next five to 10 years Cybercom can engender enough confidence in decision makers and policymakers that they feel comfortable pushing offensive cyber activities to the tactical level.

“We should be integrating [cyber] into the strike group and on the amphibious expeditionary side. We should view this as another toolkit that's available … as a commander is coming up with a broad schema of maneuver to achieve a desired outcome or end state. That’s what I hope,” the admiral said.

Special Operations Model

Rogers and Stavridis likened the journey of cyber to that of special forces, whose members in earlier times were called in only for special occasions and their use was highly controlled. Today, they said, combatant commanders have component commands from each service and from special operations.

“I would create Cyber Command much in the image of [U.S. Special Operations Command],” Rogers said. “Give it that broad set of responsibilities where it not only is taking forces fielded by the services and employing them; it's articulating the requirement and the vision and you're giving it the resources to create the capacity and then employ it.”

SOF also provides a theater special operations commander across all nine combatant commands, said Rogers, adding, -- that’s “a model I think we should drive to.”

Fighting for Talent

The cyber force, based on Cybercom billet structure, is about 80 percent military, 20 percent civilian, Rogers said. On the NSA side, he added, it’s 60 percent civilian, 40 percent military. Recruiting and retention, he said, is “a little bit harder on the civilian side.”

On the military side, the Cybercom leadership is finding that what motivates a young man or woman to be a Marine Corps rifleman, to work the flightline in the Air Force or to be a deck seaman in the Navy also motivates cyber warriors.

They want to be part of something bigger than themselves, they like the ethos and culture of the military, he said.

“That's a real selling point for us right now,” the admiral said. “The self-image of this workforce is that they are the digital warriors of the 21st century. The way they look at themselves -- we're in the future, we're the cutting edge, we're doing something new, we're blazing a path.”

As a leader, Rogers said, “you cannot underestimate the value of that.”

Rogers says he reminds recruits that as cyber warriors they’ll be able to do things in uniform, within the defense and Law of Armed Conflict application, that they can’t do anywhere else, and they’ll gain responsibility as they show proficiency in the job.

“Everybody responds well to that,” he said. “Retention is good right now.”

Public-Private Cooperation

In its work with the private sector over the next five to 10 years, Rogers said he would like to see Cybercom and tech companies “get to a level of integration where we have actual physical collocation with each other.”

The admiral says that in his military experience, “when we create [command-and-control] structures, when we create analytic and command-and-control nodes … we try to bring all together as much data, as many different perspectives and as many different elements in the broad enterprise that are necessary to achieve the outcome. I think we need to do the same thing” with the tech sector.

Rogers said he’d like to see Cybercom, for one thing, take advantage of the sector constructs that are in place for the 16 segments in private industry that Presidential Policy Directive 21 designates as infrastructure critical to the nation.

These sectors are chemicals, commercial facilities, communications, critical manufacturing, dams, defense industrial base, emergency services, energy, financial services, food and agriculture, government facilities, health care and public health, information technology, nuclear reactors and materials, transportation systems and water and wastewater.

“How do we take advantage of that and integrate at that level? Because as an execution guy, my experience teaches me that you want to train, you want to exercise, you want to simulate as many conditions as you can before you actually come into contact with an opponent,” Rogers said.

Help from the Tech Sector

On the cyber defense side, the admiral said, he’d like help from the technology sector to get to machine learning at speed and automation, and through this technology to help Cybercom free-up human capital. He’d also like the sector’s help with human capital development.

“People love to talk about the technology, but our greatest edge isn't technology; our greatest edge is that motivated man or woman with the intellectual capacity to anticipate, to be innovative and to be agile,” Rogers said. “Because ... what we’re dealing with is driven by a man or woman somewhere in the world sitting at a keyboard. There's a human dimension in all of this. It's not just about the machine.”

On the offensive side -- speaking for himself rather than the department, he said -- there are things Rogers is trying to come to grips with.

“In the application of kinetic functionality -- weapons -- we go to the private sector and say, ‘Build this thing we call a [joint directed-attack munition], a [Tomahawk land-attack munition].’ Fill in the blank,” he said.

“On the offensive side, to date, we have done almost all of our weapons development internally,” Rogers said. “And part of me goes -- five to 10 years from now is that a long-term sustainable model? Does that enable you to access fully the capabilities resident in the private sector? I'm still trying to work my way through that, intellectually.”

Note: You can click on the above DoD photos to enlarge.

Saturday, September 26, 2015

Admiral Rogers Discusses NSA Reorganization, National Security Threats


Cheryl Pellerin at the DoD News offers the below report:

WASHINGTON September 25, 2015 — Navy Adm. Michael S. Rogers, director of the National Security Agency, previewed an upcoming NSA reorganization and discussed a range of national security threats with members of a Senate panel here yesterday.

Rogers, also commander of U.S. Cyber Command, testified before the Senate Select Committee on Intelligence.
Rogers began his testimony by describing the work of “the nation’s cryptologic arm” and its 40,000 civilian and military employees in 31 states and worldwide.
“NSA now plays a key role in cyberspace, assisting U.S. government efforts to see, mitigate and deter cyber security threats. In concert with public, private and foreign partners, our work helps to ensure that users, operators and administrators maintain control of their systems and data,” Rogers said.
“NSA also gives our leaders unique insights into the hostile activities of foreign powers and their agents,” he added.
Reorganizing NSA
The agency does its work in accordance with the law and within strict guidelines, Rogers said, and only by collecting foreign intelligence in response to specific requirements from U.S. policymakers and senior U.S. commanders.
Rogers has been in the job at NSA and Cybercom for 18 months, the first part of that time spent focused on the aftermath of the Edward Snowden media leaks and ensuring that NSA’s collected data was secure, he told the panel.
Over many months, Rogers and the NSA workforce have been crafting a strategy for reorganizing the agency for a changing world.
“Our structure reflects a series of changes and choices that have been made over the last 20 years. The last major organizational change at NSA on a wide swath was 1999 or 1998 … and I want to make sure we're optimized to meet the future,” the admiral said.
Optimized for the Future
Rogers posed questions to the workforce about NSA capabilities and its evolving mission, and received more than 200 recommendations. From those, Rogers said he chose three areas on which he asked them to spend more time.
These included the military part of the workforce, a more far-reaching view of cyber, and the NSA organizational structure, he explained, adding that he would receive final input back on those areas by Oct. 1.
In his testimony on national security challenges for NSA and the nation, Rogers mentioned the Islamic State in Iraq and the Levant and similar groups, their technology capabilities and an issue known as “going dark,” and the potential Oct. 1 government shutdown.
On the shutdown, Rogers answered yes to a question from the panel: Would a shutdown of the federal government next week compromise national security?
Retaining the Workforce
“And if I could just go beyond that -- in the last five days or so, as we now are publicly talking about this possibility,” Rogers said, the reaction of the workforce at NSA and U.S. Cyber Command, who could easily get jobs on the outside and earn significantly more money there, is one of real concern.
“This instability [is a] message to the workforce that … you are a secondary consideration in a much larger game,” Rogers added, noting that he spoke this week to the leadership about how to “figure out how we're going to keep these men and women.”
On another national security issue, without going into the details of NSA’s work, Rogers said the agency broadly uses its ability to work communications in the foreign space to generate insights [about] what ISIL and other groups are doing largely through NSA’s cyber and signals intelligence expertise.
In the counterterrorism mission set, whether it's ISIL, al-Qaida or al-Qaida in the Arabian Peninsula, Rogers said, “I've seen more changes in their behavior in the last two years probably than any other target.”
They actively reference some of the data compromises that have occurred over the past couple of years, he added, “and we know that they have achieved a level of insight as to what we do, how we do it, and the capabilities we have that … they didn't have in the past.”
Going Dark
Rogers said that, as a result, combined with broader changes in technology, it has become harder to achieve insight into what such groups are doing.
“The nation's networks, communications and data are increasingly at risk from diverse and persistent threats,” he said.
“These include rogue states, organized criminal enterprises and terrorists who are showing a willingness and an aptitude to employ sophisticated capabilities against us, our allies and indeed anyone who they perceive as a threat or lucrative target,” the admiral added.
Such capabilities include going dark, or the use of encrypted communications by terrorists and criminals, the use of apps that offer end-to-end encryption, and more complicated attempts to hide in the “broader set of noise out there,” Rogers said, adding that the motivated men and women of NSA are the nation’s edge.
Working Together
This also poses a national security threat, Rogers told the panel.
“I am concerned that the direction we're going -- if we make no changes -- effectively represents a significant challenge for us in terms of our ability to generate insight that the nation is counting on,” the admiral said.

He added, “We have got to collectively get together among the private sector, government, industry, policy, and the technical side, and sit down and figure out how we're going to work our way through this.”

Note: In the top photo by Army Sgt. 1st Class Jeremy Bunkley Navy Admiral Michael S. Rogers, the commander of the U.S. Cyber Command and director of the National Security Agency, speaks to cadets and faculty at the U.S. Military Academy at West Point, N.Y. on Jan. 9, 2015. 

Friday, November 21, 2014

Cybercom Chief Details U.S. Cyber Threats, Trends


Cheryl Pellerin at DoD News offers the below piece:

WASHINGTON, Nov. 21, 2014 - Cyber threats are real, hurting the nation and its allies and partners, costing hundreds of billions, and potentially leading to a catastrophic failure if not addressed, Navy Adm. Michael S. Rogers told a House panel yesterday.

Rogers, the commander of U.S. Cyber Command, director of the National Security Agency and chief of the Central Security Service, testified before members of the House Permanent Select Committee on Intelligence on advanced cybersecurity threats facing the United States.

Cyber Challenges 'Not Theoretical'

"There should be [no] doubt in anybody's mind that the cyber challenges we're talking about are not theoretical. This is something real that is impacting our nation and those of our allies and friends every day," Rogers said. Such incidents are costing hundreds of billions of dollars, leading to a reduced sense of security and potentially to "some truly significant, almost catastrophic failures if we don't take action," the admiral added.

In recent weeks, cyber-related incidents have struck the White House, the State Department, the U.S. Postal Service and the National Oceanic and Atmospheric Administration.

The Defense Department, the U.S. Sentencing Commission and the U.S. Treasury also have had cyber intrusions. Sophisticated malware has been found on industrial control systems used to operate U.S. critical infrastructure, and other major intrusions have been reported by J.P. Morgan Chase, Target, Neiman Marcus, Michaels, Yahoo! Mail, AT&T, Google, Apple and many more companies.

Intrusions Seek to Acquire Capability

"We have ... observed intrusions into industrial control systems," Rogers said. "What concerns us is that ... capability can be used by nation-states, groups or individuals to take down" the capability of the control systems. And "we clearly are seeing instances where nation-states, groups and individuals are aggressively looking to acquire that capability," he added.

Rogers said his team thinks they're seeing reconnaissance by many actors to ensure they understand U.S. systems in advance of exploiting vulnerabilities in the control systems. "We see them attempting to steal information on how our systems are configured, the specific schematics of most of our control systems down to the engineering level of detail so they [see] ... the vulnerabilities, how they are constructed [and] how [to] get in and defeat them," the admiral said. "Those control systems are fundamental to how we work most of our infrastructure across this nation," Rogers added, "and it's not just the United States -- it's on a global basis."

Growth Areas of Vulnerability

When he's asked about coming trends, Rogers said, industry control systems and supervisory control and data acquisition systems, called SCADA systems, come to mind as "big growth areas of vulnerability and action that we're going to see in the coming 12 months." "It's among the things that concern me the most," he added, "because this will be truly destructive if someone decides that's what they want to do."

What it means, he said, is that malware is on some of those systems and attackers may already have the capability to flip a switch and disrupt the activity the switch controls. "Once you're into the system ... it enables you to do things like, if I want to tell power turbines to go offline and stop generating power, you can do that," he explained. "If I want to segment the transmission system so you couldn't distribute the power coming out of power stations, this would enable you to do that."

Criminals as Surrogates for Nation-states

The next trend Rogers sees near-term is for some criminal actors now stealing information designed to generate revenue to begin acting as surrogates for other groups or nations. "I'm watching nation-states attempt to obscure, if you will, their fingerprints," he said. "And one way to do that is to use surrogate groups to attempt to execute these things for you." That's one reason criminal actors are starting to use tools that only nation-states historically have used, the admiral said. "Now you're starting to see criminal gangs in some instances using those tools," he added, "which suggests to us that increasingly in some scenarios we're going to see more linkages between the nation-state and some of these groups. That's a troubling development for us."

Such activities across the cyberscape, he said, make it difficult for private-sector companies to try to defend themselves against rapidly changing threats.

A Legal Framework for Cyber Sharing

But before Cybercom can help commercial companies deal with cyber criminals and adversarial nation-states, Rogers said the command needs a legal framework "that enables us to rapidly share information, machine-to-machine and at machine speed, between the private sector and the government."

The framework, he added, must be fashioned in a way that provides liability protection for the corporate sector and addresses valid concerns about privacy and civil liberties. Such legislation has passed in the House but not in the Senate, and the Senate has created its own similar legislation that has not yet passed the full Senate.

Rogers says there are several ways Cybercom can share what it knows about malicious source code with the private sector so companies can protect their own networks, and assure Americans that NSA isn't collecting or using their personal information while sharing information with private companies.

What the Private Sector Needs

With private-sector companies, Cybercom and NSA must publicly "sit down and define just what elements of information we want to pass to each other," he said, specifying what the private sector needs and what the government needs, and also areas that neither wants to talk about. "I'm not in that private-sector network, therefore I am counting on the private sector to share with us," the admiral said. What he thinks the government owes the private sector is this -- Here are the specifics of the threats we think are coming at you. Here's what it's going to look like. Here's the precursor kinds of activities we think you're going to see before the actual attack. Here's the composition of the malware we think you're going to see. Here's how we think you can defeat it.

What Rogers says he's interested in learning from the private sector is this -- Tell me what you actually saw. Was the malware you detected written along the lines that we anticipated? Was it different and how was it different? When you responded to this, what worked for you and what didn't? How did you configure your networks? What was effective? What can we share with others so the insights of one come to the aid of many? "That's the kind of back-and-forth we need with each other," Rogers said, and legislation is the only thing that will make it happen.

Helping Defend Critical Infrastructure

Rogers says he tells his organization that he fully expects during his time as Cybercom commander to be tasked to help defend critical infrastructure in the United States because it is under attack by some foreign nation or some individual or group. "I say that because we see multiple nation-states and in some cases individuals in groups that have the capability to engage in this behavior," the admiral said, adding that the United States has seen this destructive behavior acted on and observed physical destruction within the corporate sector, although largely outside the nation's borders. "We have seen individuals, groups inside critical U.S. infrastructure. That suggests to us that this vulnerability is an area others want to exploit," the admiral said. "All of that leads me to believe it is only a matter of time when, not if, we are going to see something traumatic." Rogers says he's "pretty comfortable" that there is broad agreement and good delineation within the federal government as to who has what responsibilities if Cybercom is called on during a major cyberattack in the United States.

"The challenge to me is we've got to ... get down to the execution level of detail," he said. "I come from a military culture [which] teaches us to take those broad concepts and agreements and then you train and you exercise. And you do it over and over. That's what we've got to do next."

Note: The above U.S. Navy photo shows sailors assigned to the Navy Cyber Defense Operations Command. The photo was taken by Petty Officer 2nd Class Joshua J. Wahl.