Showing posts with label Cyberspace. Show all posts
Showing posts with label Cyberspace. Show all posts

Saturday, January 24, 2009

Waiting For Cybergeddon

In the United States, the FBI (which is responsible for detecting and investigating Internet based crime) is warning that America is becoming ever more vulnerable to "cybergeddon" (a massive attack via the Internet that would cripple the economy, government and military.)
The FBI admits that it has a hard time getting more money for their Internet security efforts. And reason is because the threat is largely invisible. A picture of a nuclear bomb going off, or of enemy tanks and warships ready to attack, makes a much more effective impression on the politicians who dole out the money.
The FBI also wants to get the Department of Defense Internet defense operations more involved in national level defense against network based attacks. But the four services have a hard time agreeing to coordinate their efforts to defend military use of the Internet when under massive hacker attack. Thus the FBI plea for help sort of falls on distracted ears.

There hasn't been a proper, all-out Cyber War yet. There have been lots of skirmishes, but nothing approaching what an all out battle, via the Internet, would be. What would the first Cyber War be like? Let's be blunt, no one really knows. But based on the cyber weapons that are known to exist, and the ones that are theoretically possible, one can come up with a rough idea.
First, there are three kinds of Cyber War possible. Right now, we have limited stealth operations (LSO), as Chinese, Russian, and others, use Cyber War techniques to support espionage efforts. China is the biggest practitioner, or at least they have been caught most often.

Next comes Cyber War only (CWO). This is open use of a full range of Cyber War weapons. No one has done this yet, but it's potentially less dangerous than firing missiles and unleashing tank divisions. It is believed that Russia indulged in this in 2007, when Estonia infuriated the Russians by moving a World War II statute memorializing the Soviet "liberation" of Estonia (which didn't want to be liberated by the Soviet Union.) Russia denied responsibility for the massive Cyber War assaults on Estonia, which nearly shut down the nations Internet infrastructure. Estonia accused Russia of being responsible, and tried to invoke the NATO mutual-defense pact. NATO Cyber War experts went to Estonia, and shortly thereafter the attacks stopped. Apparently Russia got the message that this sort of thing could escalate in something more conventional, and deadly.

Then we have Cyber War in support of a conventional war. Technically, we have had this sort of thing for decades. It has been called "electronic warfare" and has been around since World War II. But the development of the Internet into a major part of the planets commercial infrastructure, takes "electronic warfare" to a whole other level. Cyber War goes after strategic targets, not just the electronic weapons and communications of the combat forces.
A successful Cyber War depends on two things; means and vulnerability. The "means" are the people, tools and cyberweapons available to the attacker. The vulnerability is the extent to which the enemy economy and military use the Internet and networks in general. We don't know who has what Cyber War capabilities exactly, although China and the U.S. have openly organized Cyber War units, and both nations have lots of skilled Internet experts.

Vulnerability is another matter. The United States is the most exposed to Cyber War attack because, as a nation, we use the Internet more than any other country. That's the bad news. The good news is that if an attacker ever tried to launch a Cyber War by assaulting the U.S., it could backfire. This risk has to be kept in mind when considering what a Cyber War might do. Recall military history. The Pearl Harbor attack in 1941 actually backfired on the Japanese, by enraging Americans and unleashing a bloodthirsty response that left Japan in ruins. The lesson of the original Pearl Harbor is, if you're going to hit someone this way, better make it count. If your opponent is bigger than you, and gets back up, you could be in some serious trouble.
The big problem with Cyber War is that there has not been a lot of experience with it. Without that, no one is really sure what will happen when someone attempts to use it at maximum strength. But unlike nuclear weapons, there is far less inhibition about going all-out with Cyber War weapons. That is the biggest danger. Cyber War is a weapon of growing might, and little restraint by those who wield it. Things are going to get a lot worse.

Wednesday, December 31, 2008

U.S.A.F. Gen. Lorenz on leadership: At war in cyberspace

Hat Tip to AFPAA off twitter
Commentary by
Gen. Stephen R. Lorenz
Air Education and Training Command commander

12/23/2008 - RANDOLPH AIR FORCE BASE, Texas (AFNS) --

"The stark reality is that the bad guys are winning and our nation is at risk."


That's what retired Air Force Lieutenant General Harry Raduege, Jr., writes in an insightful article about cyberspace titled, "Evolving Cybersecurity Faces a New Dawn."

As he describes our many challenges in cyberspace, General Raduege observes that "the list of concerns is growing and endless: rampant cybercrime, increasing identity theft, sophisticated social engineering techniques, relentless intrusions into government networks, and widespread vulnerabilities continuously exploited by a variety of entities ranging from criminal organizations and entrepreneurial hackers to well-resourced espionage actors."

Over the last few weeks, we have focused on the security of our computer networks, and we have found that we have big challenges.

The bottom line is that we are at war in cyberspace...today...all the time.

Our enemies are attacking our network -- the same network you use to send e-mails, share documents and access the internet. They are using stealth and surprise to insert malicious code into our network in order to gain intelligence. What is our enemy's intention? We don't know, but it's not friendly.

Chief Master Sergeant Rob Tappana, our command chief, said something that caught my attention. He observed that if our front gate was under attack, we would do something about it. We would reinforce the guards with our security forces, convene the battle staff, increase patrols and raise awareness levels throughout the base. Chief Tappana then pointed at the computer on a nearby desk and said, "We must realize that that's our front gate too."

He is right. We need to think and act like warriors in cyberspace. That's where leadership is essential.
General Raduege describes four stages in our journey to secure cyberspace. The first stage is ignorance. We don't know what we don't know about cyberspace attacks. We are past that stage now. If you didn't know about our vulnerability in cyberspace, you do now.

The second stage is awareness. We now realize that we are at war in cyberspace, and we are vulnerable. We no longer take access to the network for granted -- we realize that it can be taken away unless we take steps to defend it.

The third stage is actualization. We share a sense of urgency that we need to do something about the attacks on our network. We will learn more and more about cybersecurity. We will all work together to reduce our vulnerability and defend the network from attack.

The final stage is the "cyber mindset," where we think and act as warriors in cyberspace just as we do in air and space. We will train to protect ourselves and our networks from attack. We will all be "on patrol" as we look for new threats. Leaders at all levels will measure our vulnerability and direct defensive actions to counter the enemy.
To get to the fourth stage, we are going to have to work through a paradigm shift about security in cyberspace. Many of us, including me in the past, have taken the network for granted. We can't do that anymore. Every computer connected to the network is part of the battlespace. Every person that has access to the network is operating in a combat environment. Everyone must act responsibly, or it opens a hole in our defense.

As I've written before, I believe you are all leaders, because you all have influence over other people in your workplaces, your families and your communities. It's going to take your leadership to help us make this paradigm shift. How do you lead others through change? You work through the stages of change faster than the people around you.

So, as leaders, I ask that you move from awareness to actualization as quickly as possible. Talk to our experts, beginning with our communication professionals. Set the right example by following the procedures and not taking shortcuts. Learn about and use the tools we have today. I promise that more tools are on the way.

I am working through the stages as fast as I can. We are improving the security of our computers at our headquarters, and I have directed that no one is exempt from security measures, including me. If my computer has to restart while I'm in the middle of something, so be it. We must be willing to accept a moderate amount of mission degradation to secure ourselves against the enemy "at the gate."

General Raduege writes that, despite the challenges facing us in cyberspace, he is optimistic that we are "on the verge of a new dawn for cybersecurity." I am optimistic as well, because we are fortunate to have you to help lead us through this change in our mindset. We are at war in cyberspace and we will all need to apply our warrior skills to prevail. Fight's on!

Wednesday, October 15, 2008

Cyber-Battlespace: Navy vs Air Force


Battlespace
By Bob Brewin

The Navy, according to an internal document that came my way thanks to an Air Force reader, plans to rebrand its Naval Network Warfare Command as the Naval Cyber Forces Command, reflecting the fact that "cyberspace is increasingly important and inseparable from our national defense interests," the internal document stated.

That document, The Naval Network Warfare Command, Command Renaming Communications Plan, said, "Cyberspace has become the global battlespace. According to Adm. Gary Roughhead, the chief of naval operations, the next battle is the information domain and the first shots have already been fired."

The Navy seems to have taken a page from the original Air Force Cyber Command playbook by viewing cyberspace as "a domain like land, sea, air and space and it must be defended," according to the brief.

Just like the Air Force, the Navy views the best defense is a good offense, with offensive cyberspace operations as part of the Cyber Forces Command's portfolio. "The effects we can produce in and through cyberspace range from simple deterrence to destruction and defeat of any adversary -- the full range of operational effects," the brief said.

Cyber Forces Command and Fleet Intelligence

The Cyber Forces Command will be built around the existing Naval Network Warfare Command, which was formed in 2002 from 23 organizations, including the former Naval Space Command, the Naval Computer and Telecommunications Command, the Fleet Information Warfare Center, and the Navy Component Task Force-Computer Network Defense. In 2005, the Naval Network Warfare Command absorbed the Naval Security Group, which handled signals intelligence and cryptography.

These organizations already provide the Naval Network Warfare Command with building blocks for a cyber command, including network operations, but the Navy also plans to add fleet intelligence to the Cyber Forces Command mix, along with surveillance and reconnaissance.
These additional missions will give the Cyber Forces Command a lot more clout than the Air Force ever imagined for its Cyber Command.

The fleet intelligence part of the Cyber Forces Command will do just what its name implies: focus on providing intelligence to commanders at the operational fleet or aircraft squadron level. The Office of Naval Intelligence, which deals with global maritime intelligence, will not come under the Cyber Forces Command, according to the internal paper.

The internal paper said this change needed to be made because "the current fleet organizational structure process for gathering intelligence and intelligence, surveillance and reconnaissance is less than optimal and lacks coherence across all naval warfare areas." The current, somewhat disjointed structure for fleet intelligence and ISR "lacks coherence" and impedes the Navy's ability to deal with increasingly complex threat environments in the future, the paper added.

A Navy source told me that the intel folks appear less than pleased with this realignment and "may have to be dragged kicking and screaming" into the Cyber Forces Command future.

Three-Star Clout

When the Air Force kicked off its grand Cyber Command plan, it was a three-star job, but now that it will come under the Air Force Space Command, as I reported last week, it most likely will be a two-star job.

But the Cyber Forces Command will have three-star clout, with the head of the Naval Network Warfare Command, Vice Adm. H. Denby Starling II, tapped to run the new command.

Rear Adm. Sam Cox, who currently serves as fleet intelligence director and director for plans and policy for the Naval Network Warfare Command, will take on the same jobs in the Cyber Forces Command.

You Can Keep Your Rating

While the Air Force will continue to rebrand its computer and communications technicians with a new cyber moniker, the Navy has no similar plans to merge computer, communications or electronic technicians into one career field, according to the internal paper. The Navy does not plan to merge its intelligence or information and warfare communities either, the paper said.

The Cyber Forces Command will not result in any reduction in the number of personnel in the Navy intelligence community or in officer or enlisted ranks in the network, gadget or gizmo fields.

No Blaze of Publicity

The Navy has worked quietly on the formation of the Cyber Forces Command for about a year, an approach that stands in stark contrast to the Air Force, which ran TV and Web advertisements for the Cyber Command.

Maybe that's why the Cyber Forces Command will emerge unscathed from bureaucratic battles over the cyber domain thing inside the Pentagon.

The Gordon England Decision


The Navy planned to announce the stand-up of the Cyber Forces Command at the start of October, but now awaits a decision from Deputy Secretary of Defense Gordon England on how the cyber mission will be sliced and diced among the three service branches, a source told me.

That Navy source added that the Omaha, Neb.-based U.S. Strategic Command will have overall responsibility for the cyber units, with an announcement planned for the end of this month.

Wednesday, October 8, 2008

Air Force pursues Cyber Command again

Top Air Force leadership has decided to pursue forming Cyber Command to defend Defense Department networks and to launch cyberattacks against foes after putting the project on hold in August.

The service's leadership, including Air Force Secretary Michael Donley and Chief of Staff Gen. Norton Schwartz, made the decision last week at the Corona senior leadership conference in Colorado Springs, Colo., to continue its effort to stand up the command, said Capt. Michael Andrews, an Air Force spokesman.

The service put Cyber Command on hold in August, saying it wanted to delay the program until new senior Air Force leaders, including Schwartz, had time to make a final decision on the scope and mission of the command. Last month, sources said the Pentagon decided that the U.S. Strategic Command in Omaha, Neb., should create and run a joint Cyber Command, a move that seemingly dashed any hopes the Air Force had to own Defense's cyber responsibilities.

In May, Deputy Secretary of Defense Gordon England wrote in a memo,
"Because all the combatant commands, military departments and other defense components need the ability to work unhindered in cyberspace, the domain does not fall within the purview of any particular department or component."

The service originally had decided to establish the Cyber Command as a separate unit within Air Force Space Command, and during the Corona conference, leadership "discussed how the Air Force will continue to develop capabilities in this new domain and train personnel to execute this new mission." "The conduct of cyber operations is a complex issue, as [Defense] and other interagency partners have substantial equity in the cyber arena," Donley said. "We will continue to do our part to increase Air Force cyber capabilities and institutionalize our cyber mission."

Andrews said the Air Force will provide more details on the Cyber Command later in October after discussions with Pentagon and congressional leadership.

Tuesday, September 23, 2008

Lock down your systems

Information security experts keep harping on it: The most effective way to lock down systems is to follow some of the most simple security procedures (the kind that have been around for years but those that many organizations rarely do).

Driving that point home is yet another report on security breaches, this one coming from Verizon Business Risk Team, which studied 500 security breaches that occurred between 2004 and 2007.

According to its 2008 Data Breach Investigations Report, 87 percent of all security breaches could have been avoided "if reasonable security controls had been in place at the time of the incident." The team called this conclusion "perhaps the most significant statistic coming out of this historical analysis . . . ." (Unfortunately, Verizon waited until page 26 of the 27-page report to make this observation.)

Verizon Business recommended organizations make sure they follow already-established security policies and procedures (59 percent of all breaches occurred at organizations that had security policies but for whatever reason did not follow them), implement the most obvious controls first (83 percent of all attacks were not considered very sophisticated) and monitor your logs (82 percent of all attacks could be seen coming due to events listed in the logs).

As Verizon Business reported, these recommendations aren't sophisticated and "lack the panache of new gizmos," but they work.

Saturday, August 30, 2008

Lights Are Going Out All Over Europe

European nations are alarmed at the recent increase in probes, via the Internet, of public utilities (electricity, water, sewage, transportation). Cyber War experts are divided on whether this is just the next big thing in criminal activity (finding out how to shut down utilities via the Internet, then using the threat of that to extort money), or military Cyber War operations, scouting utilities in anticipation of damaging them in wartime or a time of crises.

A lot of these probes can be traced back to the usual sources (China, Eastern Europe and the Middle East), the places where many of the Internet based criminal gangs hide out. So far this year, there has been an increase in probes, but not attacks. At least as far as anyone knows. However, the most professional Internet attacks are unnoticed (as the intruder gets away with data, or a deep understanding of how the target site operates, and thus a good knowledge of how to take it down.) Utilities, and large corporations in general, are being urged (and sometimes ordered) to check, and double check, the adequacy of their Internet defenses.

Thursday, August 14, 2008

Air Force suspends Cyber Command program

The Air Force on Monday suspended all efforts related to development of a program to become the dominant service in cyberspace, according to knowledgeable sources. Top Air Force officials put a halt to all activities related to the establishment of the Cyber Command, a provisional unit that is currently part of the 8th Air Force at Barksdale Air Force Base in Louisiana.

An internal Air Force e-mail said, “Transfers of manpower and resources, including activation and reassignment of units, shall be halted.”

Establishment of the Cyber Command will be delayed until new senior Air Force leaders, including Chief of Staff Norton Schwartz, sworn in today, have time to make a final decision on the scope and mission of the command.

The Cyber Command, headed by Maj. Gen. William Lord, touted on its Web site its capabilities to “secure our nation by employing world-class cyberspace capabilities” and had ambitious plans to have a cyber command presence in all 50 states.

The Cyber Command hyped its capabilities on TV, in Web video advertisements and in a series of high-profile presentations conducted by Lord.

The hard sell may have been the undoing of the Cyber Command, which seemed to be a grab by the Air Force to take the lead role in cyberspace. Both the Army and Navy have similar expertise in cyber operations, service sources said.

Philip Coyle, senior adviser with the Center for Defense Information, a security policy research group in Washington, said he believes the Navy’s Network Warfare Command and the Space and Naval Warfare Systems Center have led the way in cyberspace. The Army engages in cyberspace operations daily in Afghanistan and Iraq, said Coyle, who served as assistant secretary of Defense and director of its operational test and evaluation office from 1994 to 2001.

The decision to ratchet back the Cyber Command may have come from Adm. Mike Mullen, chairman of the Joint Chiefs of Staff, who wants to see a greater role for the Navy in cyberspace, said an Air Force source. Coyle speculated that the Air Force may have been too public in pushing the Cyber Command and is now suffering from its own hubris.

The decision to pull the plug on the Cyber Command – even temporarily – is just the latest in a string of bad news for the service, Coyle said. This includes Defense Secretary Robert Gates' request in June for the resignations of Air Force Chief of Staff T. Michael “Buzz” Moseley and Air Force Secretary Michael Wynne because of the service’s poor management of nuclear weapons. Also in June, the Government Accountability Office questioned the Air Force’s selection of Northrop Grumman over Boeing for a multibillion-dollar aerial refueling contract and recommended that the service reopen the competition. It did so in July.

Sunday, July 13, 2008

Hoo-ah: 741st Network Warfare Battalion, U.S. Army

The U.S. Army has activated its first Network Warfare Battalion (741st Network Warfare Battalion). The unit will not operate together, but mostly as many detachments, supporting combat forces in Iraq and Afghanistan, counter-terror operations throughout the world, as well as in joint Cyber War operations with other services and foreign countries. The battalion belongs to the 704th Military Intelligence Brigade, which is in turn subordinate to INSCOM (the U.S. Army Intelligence and Security Command).

All the services are making a major effort to develop defensive and offensive Cyber War weapons. The U.S. Air Force has established a major command (involving over 20,000 specialists) for this, and is attempting to become the lead for all Department of Defense Cyber War activities. The other services oppose this attempt to take over, although they appreciate air force efforts to develop new tools and capabilities. The army and navy both have thousands of troops, in many different units, working on Cyber War activities. Creating major units (battalions and larger) dedicated to Cyber War, is a new development.

Monday, June 16, 2008

Hoo-ah: The 50-State Strategy to Sell Cyber Command

The 50-State Strategy
to Sell Cyber Command
BY BOB BREWN, BBREWIN@GOVEXEC.COM

One way to secure the Hill's backing -- and bucks -- for any new program is to spread it over as many states and congressional districts as possible. The new Air Force Cyber Command takes this approach to its ultimate limit: The service plans a cyber unit in every state, according to a briefing given in April by Maj. Gen. William Lord, the Cyber Command chief. The briefing was sent to me by a source who chooses to remain anonymous.

The very crowded slide of the 50 states that Lord presented at the Scope Warrior Spring Symposium, a gathering of top Air Force communications and information technology folks, looks like a bit of cyber-rebranding of the service's existing IT functions.

The majority of the sites, which will come under the Cyber Command umbrella, are designated as so-called network operations, a fancy way to describe the circuits and connections that already exist to serve those bases. While this is just putting a new name on old operations, it helps to include all 50 states in the count, which then bolsters the sales job.

The real centers of power, in what Lord called in his slides “AF Distributed Cyber Enterprise,” are eight bases located in the East, Midwest and South:

Networked Computer Operations:
Bolling Air Force Base, Washington

Theater Operations Integration:
Langley Air Force Base, Va.

Information Systems:
Rome Laboratory, N.Y.

Cyber Operations Integration:
Barksdale Air Force, La.

Information Operations:
Lackland Air Force Base, Texas

Space Operations Integration:
Peterson Air Force Base, Colo.

Global Operations Integration:
Offutt Air Force Base, Neb.

Global Networks:
Scott Air Force Base, Ill.

Then there’s the command's new headquarters, which has sparked a sweepstakes that at least 18 states have entered. The Air Force plans to announce in September 2009 its decision on where to locate the headquarters.

I guess the consolation prize will be one of the smaller, rebranded cyber units the command has decided to sprinkle around the country.

It’s About Network Attack

During the past year, the Air Force has made it clear that the primary focus of the new Cyber Command will be the ability to attack an enemy’s networks, and Lord’s presentation reinforces this point.

In a slide under the heading of "Global Power," network and electronic attack capabilities take precedence over cyber deterrence. Lord emphasized that the command’s mission is to “provide robust, survivable access to cyberspace, with offensive and defensive capabilities.”

I'm hopeful that the Cyber Command can work out a way to conduct these attack missions without knocking out the 6 million Web pages linked to Paris Hilton and the 2 million or so Web pages dedicated to tracking the ups and downs of Britney Spears.

New Jobs, New Slogan, New Badge

It’s hard to have a cyber command without cyber warriors. To that end, Lord disclosed that the Air Force plans to develop a cyber career field for officer, enlisted and civilian personnel that will subsume venerable specialties in the communications and electronics field under the new cyber brand.

Lord also floated what could be a new slogan for the Cyber Command: "Transforming Warfare . . . Byte By Byte." I love it. It's punchy, to the point and better than a mission statement.

But you can’t set up a new command without a new badge, and Lord unveiled the cyber operator badge, which has what looks like four satellite orbits spaced evenly around the globe on what is the original Air Force badge.

Sunday, June 15, 2008

Cyberattack Gets Worse

Many U.S. legislators have complained that their computers were infected by eavesdropping software inserted by hackers traced back to China.

There was a similar flap over two years ago. Back then, there was enough proof to know that China was behind the increasing number of Internet based attacks, but not enough to call China out on it.

This all began about eight years ago, with an increasing number of very well executed Internet attacks hitting U.S. government (especially Department of Defense) computers. Analysis of these attacks indicated that the hackers appeared to be coming from China. At first, it was thought to be adventurous computer science students, or criminals out to steal something they could sell.

Then, in 2003, came the "Titan Rain" incident. This was a massive and well organized attack on American military networks. The people carrying out the attack really knew what they were doing, and thousands of military and industrial documents were sent back to China. The attackers were not able to cover their trail completely, and some of the attackers were traced back to a Chinese government facility in southern China. The Chinese government denied all, and the vast amounts of technical data American researchers had as proof was not considered compelling enough for the event to be turned into a major media or diplomatic episode.

In the wake of Titan Rain, governments around the world began to improve their Internet security. But not enough. The attacks kept coming. Out of China. And the attackers were getting better. In 2005, a well
organized attack was made on the networks of the British parliament. This time, the defense won the battle. Mostly. The carefully prepared emails (with virus attached), would have fooled many recipients, because they were personalized, and this helped prevent network defenses from detecting the true nature of these messages. These targeted emails from hackers were very successful. If the recipient tried to open the attached file, their computer who have hacking software secretly installed. This software would basically give the hacker control of that PC, making it possible to monitor what the user does on the computer, and have access to whatever is on that machine.

While many recipients sense that the "spear fishing" (or "phishing") attack is just that, some don't, and it only takes a few compromised PCs to give someone access to a lot of secret information. This would be the case even if it is home PCs that are being infected. The recent complaints from American legislators is all about that, as they have discovered office and personal PCs of themselves and their staffers infected.

But many other attacks are only discovered when they are over, or nearly so. The attackers are very well prepared, and usually first make probes and trial run attacks on target systems. When the attackers come in force,
they don't want to be interrupted. And usually they aren't. The Chinese attackers use techniques similar to those employed by criminal gangs trying to get into banks, brokerages and big businesses in general. Thus it is believed that the Chinese hackers try, as much as possible, to appear like just another gang of cyber criminals. But the Chinese have certain traits that appear more military than gangster.

The Chinese cyber army keeps getting better, and that includes covering their tracks. It may take a defector or three to make it definite that China is waging a stealthy war over the Internet. Meanwhile, the Chinese reap enormous economic and political benefits from their raids on economic and technical secrets in the West.

Friday, June 6, 2008

Info security chiefs weigh new approaches to looming threats





Info security chiefs
weigh new approaches to looming threats

BY TOM SHOOP 06/05/08

What federal agencies don’t know about protecting their data and computer systems could really hurt them, senior federal information security professionals said on Thursday.

“It’s like the days prior to Pearl Harbor and 9/11,” said Daniel Galik, chief information security officer at the Health and Human Services Department, at a breakfast seminar sponsored by Government Executive. “We have some very serious challenges. The attacker is several steps ahead of us across the board.”

Bruce McConnell, former chief of information and technology policy at the Office of Management and Budget who currently runs a consulting firm (and contributes to the Tech Insider blog at Nextgov), called the situation an “invisible crisis.” Agencies, he said, have long been operating in an “inherently insecure environment,” and “the sheriff has not shown up yet.”

“There’s so much we don’t know” about threats to federal systems, added Marian Cody, CISO at the Environmental Protection Agency. Cody added that at one point, her agency’s systems were taken offline for a week after an audit showed vulnerabilities. It took more than a year, she said, to completely restore the systems.

Galik said the 2002 Federal Information Security Management Act, under which agencies are issued grades based on their level of compliance with security directives, “set a good foundation,” but is “very labor-intensive on the administrative side.” He argued for the creation of a governmentwide operational security report card, detailing information on incidents across agencies to give an overall security picture.

Cody defended the FISMA process, saying, “we’ve got that part down pat. I don’t want to see it changed.” Her office, she said, has forged a strong working relationship with the agency’s inspector general, giving officials in the IG’s office open access to EPA’s security information system so they can work cooperatively with managers to assess threats and identify vulnerabilities.

But, Cody said, “I’m not a proponent of sending operational security reports to OMB.”

Both Cody and Galik expressed concern over user behavior that jeopardizes security. When it comes to weighing the threat inherent in actions such as clicking on links in e-mail messages, “many users are not wrestling with it at all,” Galik said.

Cody said many EPA employees assume that when they access the agency’s network, their actions are private. “That’s completely shocking to me,” she said.

Monday, May 19, 2008

Why is Oklahoma/Tinker NOT going after this Cyber Command Sweepstakes !

One has to ask why Oklahoma/Tinker is not going after this ?

Eighteen states are vying to become the home of the headquarters for the coveted Air Force Cyber Command. So, on May 15, William Anderson, assistant secretary of the Air Force for installations, environment and logistics, sent a letter to the governors, asking them to provide details that will help the service make its decision.

The letter, which a source was kind enough to send me, notes that the unique nature of the cyber domain dictates that the candidates have a complete understanding of the supporting capabilities of headquarters bases and their surrounding communities. Anderson included in the letter a checklist of requirements.

These included the ability of the new HQ to work easily with other Air Force commands near the Cyber Command that are engaged in activities such as intelligence and space operations. The new Cyber Command HQ also will require an extensive high-speed network, including state-of-art secure fiber networks and connections to unclassified and classified Defense networks.

The Air Force wants to locate the HQ in a low-threat environment that's close to new technology corridors and IT centers of excellence.

Anderson asked the governors to reply by July 1. The Air Force intends to tour cyber HQ sites this summer and to draw up a short list of locations by November. The process then will slow down (probably to hear from aggrieved members of Congress whose states did not make the short list), with a final selection made in September 2009.

States competing for the Cyber Command HQ are: Alabama, Arkansas, California, Colorado, Iowa, Louisiana, Massachusetts, Michigan, Mississippi, Missouri, Nebraska, New Jersey, New Mexico, Ohio, Pennsylvania, Texas, Utah and Virginia.












It's About Cyber Attack,

Not Cyber Defend

The attachments to Anderson's letter make it clear that the key mission of the Cyber Command will be to cyber attack, not cyber defend -- a position the Air Force has emphasized during the past year. A paper, titled "Proposed Purpose and Need for Air Force Cyber Command," which Anderson sent to the governors, said the command will work to "influence, disrupt, corrupt or usurp adversarial human and automated decision-making while protecting our own."

You can't set up a new command without doing the vision thing, and the vision for the Cyber Command is to "help secure our nation by employing world-class cyber capabilities to dominate the cyberspace domain, [and] create effects worldwide," the paper noted.

And, if you're doing the vision thing, make sure it's "through a holistic, agile and evolutionary approach to science and technology, research and development, systems acquisition, operations, force structure" etc. etc. I could really score high on buzzword bingo with these two paragraphs.



Saturday, May 17, 2008

Analysis: USAF's cyber offense capability

Procurement documents from the U.S. Air Force give a rare glimpse into the Pentagon's plans for developing an offensive cyberwar capacity that can infiltrate, steal data from and if necessary take down enemy information technology networks.

The Broad Area Announcement, posted Monday by the Air Force Research Laboratory's Information Directorate in Rome, N.Y., outlines a two-year, $11 million effort to develop "access to any remotely located open or closed computer information systems," lurk on them "completely undetected," "stealthily exfiltrate information" from them and ultimately "be able to affect computer information systems through Deceive, Deny, Disrupt, Degrade, Destroy (D5) effects."

"Of interest," continues the announcement, "are any and all techniques to enable user and/or root level access to both fixed (and) mobile computing platforms ¿¿ (and) methodologies to enable access to any and all operating systems, patch levels, applications and hardware."

The announcement "reflects the fact that the Department of Defense views information operations as critical to success in modern warfare," Air Force spokeswoman Larine Barr told United Press International, and is designed to "ensure that Air Force Cyber Command stands up on the leading edge of technology and expertise."

The announcement is the latest stage in the Air Force's effort to develop a cyberwar capability and establish itself as the service that delivers U.S. military power in cyberspace. Last year the Air Force announced it was setting up a Cyber Command, alongside its Space and Air Commands, and was developing military doctrine for the prosecution of cyberwar operations.

The United States is not alone in thinking along these lines, and NATO announced Wednesday that seven European nations had signed up to participate in a cyberdefense Center of Excellence in Tallinn, Estonia, which suffered a cyberattack last year that many officials believe was orchestrated by Russia.

The center will conduct research and training on cyberwarfare and include a staff of 30 persons, half of them specialists from the sponsoring countries of Estonia, Germany, Italy, Latvia, Lithuania, Slovakia and Spain, according to a statement from NATO.

The developments highlight the murky legal territory on which the cyberwars of the future will be fought: terrain on which attackers can cloak their identity and use as weapons the home computers of unsuspecting Web surfers that have been recruited to so-called botnets -- networks of PCs that unbeknownst to their owners have been compromised by hackers.

The cyberattack on Estonia last year, for instance, was carried out by botnets, and Russian officials have denied any involvement.

In a recent article for the Armed Forces Journal, Col. Charles Williamson, a staff judge advocate for the USAF Intelligence, Surveillance and Reconnaissance Agency, argued that computer users whose equipment was recruited to botnets because they failed to patch their systems could not properly be considered innocent bystanders.

"If the United States is defending itself against an attack that originates from a computer which was co-opted by an attacker, then there are real questions about whether the owner of that computer is truly innocent. At the least, the owner may be culpably negligent, and that does not, in fairness or law, prevent America from defending itself if the harm (from an attack) is sufficiently grave," wrote Williamson in the article, which officials were keen to stress does not represent U.S. policy.

More importantly, because of the difficulties in identifying attackers and immediately quantifying damage from a cyberattack, it can be hard to determine when such attacks constitute an act of war -- as opposed to crime or even vandalism.

"The speed and anonymity of cyberattacks makes it very hard to distinguish what actions would be those of terrorists, criminals, nation states or just some lone prankster," said Gen. William Lord, who heads up the new Cyber Command.

The legal minefield that U.S. cyberwarriors must negotiate was spelled out in an analysis prepared by the Defense Department general counsel.

"It would be useful to create a process for determining when the response to a computer intrusion should shift from the customary law enforcement and counterintelligence modes to a national defense mode," reads the analysis.

"No one's come out and defined that yet," Cyber Command spokeswoman Karen Petitt told UPI, adding that the Air Force saw its role as developing capabilities for cyberwar, but that the decision about when and how to use those capabilities would be one for the national leadership.

Wednesday, April 9, 2008

The Rising Internal Threat





The Rising Internal Threat
By ALLAN HOLMES

News that hospital workers viewed more than 60 patients' health records at the University of California, Los Angeles, Medical Center is another reminder that employees and contractors pose the greatest security threats to personal information, as security experts point out. Last month, the State Department announced that the passport files of the three presidential hopefuls had been accessed by contractors working for the department but who did not have authorization to access the files. State acknowledged that the files had been breached after a reporter contacted the department inquiring about a possible breach.

In the Medical Center's case, hospital officials did not realize the files had been accessed until lawyers for actress Farrah Fawcett, who had been treated at the center, contacted hospital officials after an article appeared in The National Enquirer about the recurrence of Fawcett's cancer. After an investigation, the hospital found that 61 patient records -- about half celebrities and politicians -- had been opened by one unauthorized user.

Stories like this may explain why information technology managers have put identity management, the ability to control who accesses what data, at the top of their to-do lists, according to an annual information security survey conducted by CIO Magazine. The survey also notes that for the first time in its five year history, IT managers say that employees were more likely the source of a security incident than hackers. In fact, the switch was dramatic, from 51 percent of IT managers saying employees were the source of cyberattacks in 2006 (while 54 percent said attacks came from hackers) to 64 percent in 2007 (with 41 percent saying attacks came from hackers).

Army must develop process to wage war in cyberspace





Army must develop process to
wage war in cyberspace

By Greg Grant
ggrant@govexec.com


With wars increasingly fought among the people, information is now an element of combat power as important as lethal action in determining a conflict's eventual outcome, said an Army officer who heads the services computer warfare efforts.

The battle for a population's state of mind demands a sophisticated information operations campaign that responds more rapidly than terrorists and insurgent groups to exploit the virtual battlefield. "There was a day when we were operating at foot speed," said Army Col. Wayne Parks, who directs the service's Computer Network Operations and Electronic Warfare at Fort Leavenworth, Kan. "Now we're moving at cyber speed.

Digitization has dramatically increased the speed at which information moves about the battlefield, he said. Unlike the air and space domains, the Army operates on the ground, which means among the people, Parks said in a conference call with reporters. America's enemies influence a populations' mind-set by using Web sites and chat rooms to spread propaganda that casts the U.S. military in a bad light.

"We have to pick up the pace, ... respond, react, be proactive enough to stay out ahead of the speed of megabytes," he said.

The Army has turned to academia for expertise in the humanities and social sciences to better understand foreign cultures and how to influence societies with information operations.

The service now must find a way to "maneuver around" a potential enemy's information campaign, Parks said. Being proactive, rather than simply reacting to an enemy's misinformation, is of utmost importance, he said, because members of the public often believe the first thing they hear, even if it's not true. In addition, the military also "hacks" into jihadi Web sites to try to stop the spread of enemy propaganda.

Recent surveys conducted by the Center for Army Lessons Learned at Fort Leavenworth on operations in Iraq and Afghanistan found that the service's training and officers' past combat experience left them "ill-prepared" for the "interactive complexity" of information operations. Operating with the speed and agility that the 21st century information age demands is "not part of their DNA," and the Army "continues to grope for a staff process" to best leverage the power of information, according to a discussion paper e-mailed to reporters.

Rather than the ad hoc approach to information operations the Army has pursued, the paper designated specific staff responsibilities for everything from informing and educating the public (delegated to the public affairs and psychological operations staff) to hacking into enemy computer networks (a task for intelligence officers). The service is recruiting a younger generation of hackers, Parks said, for, as the Army puts it, "computer network attack and computer network defend."

The United States finds itself more often fighting small, distributed terrorist and insurgent cells that are able to communicate and coordinate attacks using cell phones and that can share on Web sites lessons on the best way to attack U.S. forces. The challenge is finding weaknesses in the enemy's computer network that can be hacked, Parks said.

Sunday, March 23, 2008

Techno-savvy Iraqis surf the cyber wave

Saddam Hussein deemed Iraqis could live without modern technology such as mobile phones and the Internet. Now that his regime has been swept away, they are finding they just can't get enough of it.
"The Internet is indispensable for us," said a Baghdad mobile phone vendor, who gave his name only as Sajjad.

"I download songs, pictures of actresses and video clips," added the 25-year-old salesman, who admitted that he then loads these, with a few modifications, into the phones he sells.

"My clients ask for a lot for songs, pictures and weird and funny video clips which I usually download from YouTube.com," said Sajjad.

"Some of my clients have no money to buy credit so they cannot speak on their phones. But their handsets are filled with video clips, songs and pictures."

Another mobile phone dealer, Ali Adel, 31, said trade in cellphones had become brisk business since Saddam was toppled in the US-led invasion five years ago.

"Second-hand phones are especially popular and we make most of our money from them," he added.

Prior to the invasion, no mobile phone network existed in Iraq and even private satellite phones were banned.

Since March 2003, however, there has been an explosion in telephony, with three mobile networks and dozens of Internet service providers operating.

This month, wireless fixed voice and data operator Itisaluna began rolling out Internet and modern telephony systems into homes across the war-battered country, with customers paying for the services using scratch cards priced at five, 10, 20 and 30 dollars.

With Itisaluna and other providers bringing Internet into the home, Iraq's cyberface has changed dramatically.

"In the days of the former regime, there were only a few Internet cafes in hotels," said the owner of "Centre Baghdad" cybercafe, who would be named only as Ali.

"All of them were subject to monitoring and some websites were blocked," he added.

Iraqis recall the days during Saddam's rule when their emails would be sent to a central monitoring unit which would decide whether it could be onpassed to the intended recipient.

Replies to those mails and other incoming messages were equally censored, and could take weeks to get through, if ever.

Today these restrictions are gone and Iraqis in their millions are using the Internet for chatting, doing research, dating, keeping abreast of current affairs and to access social networking sites such as Facebook and Hi5.

"I go to Internet cafes every Friday," said a 20-year-old Christian man who gave his name as Bassam.

"I spend more than two hours on the net, using Yahoo or MSN messenger or just going to Hi5.com website."

However, he said, he had stopped communicating with his relatives abroad.

"Eighteen months ago the brother of my friend was kidnapped by unidentified people who heard him talking by microphone (through Skype) to his relatives in the US. They waited for him at the gate, kidnapped him and finally released him once ransom had been paid."

Cybercafe owner Ali said most of those using his 16 PCs were young people aged between 17 and 35.

"They mostly use Yahoo Messenger for chatting or checking their emails but some download antivirus updates or do research for their studies.

"Our peak hours are from 4:30 pm to 7:00 pm, but the cafe is open until 10:00 pm," said Ali.

High school student Abdul Rahman Omar said he visits a cybercafe every day.

"I like chatting. Some friends advised me to go to the 'Arab Chat' website. I spend one or two hours a day there."

Mobile phone users, meanwhile, use their handsets for more than just talking, with the sharing of video clips the most popular activity.

"I like belly-dancing video clips," said a 22-year-old student named Bassem. "I buy them and share them with my friends. In return they send me comic video clips via Bluetooth," he said.

Saturday, March 15, 2008

USAF Details Cyber Command Organization

The U.S. Air Force plans to anoint its new Cyber Command the 24th Air Force and attach to it four wings, including new ones for electronic warfare and cyberspace.

The service on March 14 announced it will create the 450th Electronic Warfare at Lackland Air Force Base, Texas, and Scott Air Force Base, Ill., the latest developments in the Air Force's plan to create a new command focused on expanding its activities in the cyber and electronic spectrums.

The 450th will handle "various electronic attack and protection units," while also supporting EC-130J and EA-6B aircraft missions, according to a March 14 service statement. The EC-130J flies above-ground units and gives them an electronic shield that prohibits enemy forces from using EW tools.

The 689th will be composed mostly of communications and information functions, as well as "deployable communications capabilities," according to the service.

Both homes for those new wings are interim ones, with the service continuing efforts to meet the Air Force Cyber Command's initial operational milestone by Oct. 1.

"We are aggressively moving forward with plans for having initial operating capability by the Oct. 1 deadline mandated for us by the Secretary of the Air Force," Maj. Gen. William Lord, the provisional commander of the 24th Air Force, said in the statement. "That means we will have a portion of the staffing we need and the organizational structure in place to continue to build the command until we reach full operational status."

The service has established a list of criteria the 24th must meet before initial operating capability will be declared, including "establishing a budget, articulating details of organizational realignments, developing and assigning manpower requirements, and establishing policies and procedures for daily operations," the statement said.

Along with the two new wings, the 24th will feature the Air Force Information Operations Center at Lackland, which will be renamed the 688th Information Operations Wing, and the Lackland-based 67th Network Warfare Wing.

While Air Force Secretary Michael Wynne has directed the command's headquarters be established at Barksdale Air Force Base, La., the service is planning a "distributed headquarters." That means because many of the functions and jobs the headquarters staff will carry out are spread across the nation, its 541 employees will be scattered at bases across the U.S.

"We've asked [the command] to become virtual. In other words, we've said, we don't want you to be a standard … command as you might see from the Napoleonic era," Wynne said. "We asked them to look [into commercial] companies [to] see how they operate and minimize the headquarters. [Many of our units are] already located in the various states around the country, so our first inclination is to leave those in place."


Tuesday, March 11, 2008

DHS stages cyberwar exercise

DHS stages cyberwar exercise
by Shaun Waterman
Washington


Officials from 18 federal agencies, nine states, four foreign governments and more than three dozen private companies will take part in a cyberwar exercise staged by the U.S. Department of Homeland Security this week.

The war game, codenamed Cyber Storm II, will run Monday to Thursday, based at U.S. Secret Service headquarters in Washington. It is the second DHS biannual cyber-exercise, designed to test the ability of federal agencies and their partners in state, local and foreign governments and the private sector to respond to and recover from cyberattacks on their computer networks.

"The goal of Cyber Storm II is to examine the processes, procedures, tools, and organizational response to a multi-sector coordinated attack through, and on, the global cyber infrastructure," says a fact sheet from the department.

Details of the planning for the event are closely held, in part to avoid tipping off participants. The fact sheet says only that the exercise -- the culmination of more than 18 months of planning led by DHS' National Cyber Security Division -- will simulate a series of coordinated physical and cyberattacks on IT and communications systems and chemical, rail and pipeline infrastructure.

The attacker is not identified, but has "a specific political and economic agenda," says the fact sheet. In the last Cyber Storm exercise in 2006, the enemy was an anarchistic coalition of "hacktivists" -- politically motivated hackers -- called the Worldwide Anti-Globalization Alliance, joined by a number of "independent actors."

In the scenario, the attackers penetrated state health records' databases, attacked Federal Aviation Administration systems and defaced newspaper sites.

"Key elements of the hacker attack plan were to strike at trusted cyber systems that were used to control both physical infrastructures and digital commerce and services," says the DHS' after-action report, released in September 2006. "The attackers focused on maximizing economic harm and fomenting general distrust of big business and government by disrupting services and misleading news media and other information outlets."

The choice of adversary -- which the report stressed "was neither a forecast of any particular threats currently existing nor an expression of any specific concerns" -- raised some eyebrows. Among U.S. military planners, nation states, and in particular China, are considered the actually existing adversaries with the most significant capabilities to launch attacks on, or through, the Internet.

One report, by Washington Post blogger Brian Krebs, said Cyber Storm II will feature a nation-state attacker, but a DHS official familiar with the planning said only that this was "a possibility."

The official added that the adversary was "more sophisticated" than in 2006. The scenario was "designed to examine the response to some of the threats that are out there in the real world," he said.

Having a nation-state adversary would make sense, former DHS preparedness chief George Foresman told UPI.

"The top candidates for adversaries would be states, terrorist groups and criminal enterprises" as they were in the real world, said Foresman, who was only involved in the very early stages of planning the event.

As in 2006, the attacks this week will be simulated on special systems set up for the exercise "and will not impact any live networks," says the fact sheet.

Participants in the exercise, which consists of a series of detailed scenarios unfolding according to a strict timetable, will learn of developments via more than 1,700 pre-scripted "injects" in the form of phone calls or e-mails from exercise managers, or through a mock TV news channel set up for the event.

But some of what players will learn from the channel will be bogus, former DHS official Jerry Dixon told Krebs' Security Fix blog.

"They'll inject some red herring attacks and information to throw intelligence analysts and companies off the trail of the real attackers," said Dixon, who helped plan the exercise.

The $6 million event will involve thousands of participants across the world, including from departments of the Australian, British, Canadian and New Zealand governments, and from U.S. agencies including the Department of Defense, CIA, National Security Agency and FBI.

Foresman said the foreign countries participating, all signatories to the 1947 UKUSA intelligence-sharing accords with the United States, were chosen because "there is a shared basis by which you can deal with classified information."

In Australia, which has ramped up its level of participation since the last exercise in 2006, officials from the federal police, Attorney General's Department and AUSCERT -- the Australian national Computer Emergency Response Team -- will all take part, Attorney General Robert McClelland told a news conference Friday.

In New Zealand, participating agencies include the Ministry of Foreign Affairs and Trade, the Ministry of Health, the Customs Service and the New Zealand Defense Forces, according to ComputerWorld.co.nz.

Companies taking part include ANZ National Bank, Cisco Systems Inc., which owns much U.S. Internet infrastructure, Dow Chemical, IBM, computer security firm McAfee, software giant Microsoft and Verizon.

International and private-sector participation is essential, said Foresman. "A cyberattack against the United States with real-world effects inside our borders can be launched from anywhere in the world," he said, adding that the attacks would target or utilize infrastructure owned by the private sector.

Cyber-warfare is "inherently international and inherently private (sector)," he said.

The 2006 after-action report said Cyber Storm I was designed to test basic elements of communication and decision-making in a complex environment of interdependent systems and multiple stakeholders.

"Effective response to the scenario was designed to require rapid communications and de-confliction of critical information between players in all sectors and organizations, as well as strategic integration of information to gain accurate situational awareness," it said.

"It's all about the information," Foresman said, adding that "the ability to communicate highly technical information in real-time" between government officials without a common vocabulary had been a major challenge identified by Cyber Storm I.

"Collaboration between the government and the private sector" was something planners continued to wrestle with. "We haven't mastered that piece yet," he said.

Monday, March 10, 2008

China in Cyberspace




China in Cyberspace
By Bob Brewin

Last September, Huawei Technologies, a network equipment manufacturer headed by Ren Zhengfei, a former officer in China's People's Liberation Army, cut a deal with Bain Capital to acquire an interest in 3Com, which among other things, makes network hardware and software that's widely used by the Defense Department and other federal agencies.

This includes, according to 3Com, Voice over Internet Protocol systems deployed by the Defense Information Systems Agency and the Social Security Administration. 3Com also sells software that detects network attacks to the government.

In addition, the company has provided local area network hardware used in the Joint Worldwide Intelligence Communications System, a network that operates at the Top Secret/Sensitive Compartmented Information level.

Considering the security implications of a Chinese company acquiring even a passive interest in 3Com, members of Congress viewed the takeover with alarm.
Rep. Thaddeus McCotter, R-Mich., chairman of the House Republican Policy Committee, called it a "stealth assault on America's national security."

Last month, Rep. John Dingell, D-Mich., chairman of the House Energy and Commerce Committee, and Rep. Joe Barton, R-Texas, the committee's ranking Republican, sent a letter to Treasury Secretary Henry Paulson saying there was a "growing apprehension in the Congress" about the security implications of the transaction. Paulson chairs the Committee on Foreign Investment in the United States, which examines the national security implications of such investments.

Shortly after Dingell and Barton raised their concerns, Xu Zhijun, chief marketing officer at Huawei Technologies, told the Financial Times that the views on the deal expressed by some U.S. lawmakers were "bullshit." Huawei, he said, only intended to take a 16.5 per cent investment in 3Com.

Zhijun's blast wasn't exactly well-timed. Last week, the Pentagon released a report concluding -- surprise -- that a series of attacks against U.S. government networks appear to emanate from China.

I wonder if these attacks were discovered by 3Com intrusiondetection software?

The Pentagon noted in its report that Huawei is one of a group of Chinese IT companies that serve both military and commercial users in the country. The report said such companies have "close commercial ties with the [People's Liberation Army] and collaborate [with the PLA] on research and development."

Zhijun tried to deflect criticism of the 3Com deal by telling the Financial Times that China is a big customer for network gear made by Cisco, so maybe the Chinese should worry about that company and its software. "Cisco is everywhere within China," he said. "Who should be more concerned?"

Zhijun has a good point. If Cisco gear is all over China, does this mean it could be used to mount attacks against U.S. networks? I posed this question to a Cisco representative, but have not heard back from her.

Marlboro, Not Marlborough


3Com is headquartered in what is now known as Marlborough, Mass. But when my grandfather built a summer lake cottage there in the early 1900s, it was known simply as Marlboro, an appellation gussied up to the tonier name sometime in the early 1980s.

Though Marlboro now is replete with tech and IT companies, it ironically was the home of the last operator-based telephone exchange in New England, which finally converted to dial tone in the late 1960s.

I spent my summers in Marlboro with a bevy of aunts, uncles and cousins, and always marveled at the ease of use of that system -- you just picked up the phone, told the operator who you wanted to talk with, and she connected the call without even asking for a number.

You can't do that with an iPhone.

Hey, Let's Track Supplies Over a 49-Percent Chinese-Owned Network

This may sound loopy now that the Pentagon has all but pinned a series of cyberattacks on China, but it's true.

Last June, I wrote an article that detailed plans by the Army's Program Manager, Joint-Automatic Identification Technology to use a radio frequency identification network in Pakistan partially owned by a Chinese company to track supplies shipped from ports in Pakistan to U.S. forces in Afghanistan.

That RFID network is owned and operated by Savi Networks LLC, a joint venture between Lockheed Martin subsidiary Savi Technology and Hutchinson Port Holdings, a subsidiary of Hutchison Whampoa Limited of Hong Kong, controlled by Chinese billionaire Li Ka Shing. Savi Technology owns 51 per cent of Savi Networks and Hutchison 49 per cent, according to a 2005 press release from the partnership.

Considering the sensitivity of logistics and supply chain data -- we all know generals win battles and logisticians win wars, right? -- Air Force Maj. Patrick Ryder, a Pentagon spokesman, told me last June that Defense "is still assessing whether to utilize a commercial solution for Pakistan ... in accordance with DoD information assurance policy."

Last December, Ryder sent me an e-mail saying that Defense had decided to use the RFID network after a risk assessment conducted the Army's Information Assurance Security Engineering Directorate concluded that "DoD's use of Savi Technology's commercial RFID reader network in Pakistan does not increase the operational risk to U.S. forces or the [Global Information Grid]."

This statement did not address the fact that the network in Pakistan is not operated by Savi Technology, but Savi Networks, and so flummoxed me I did nothing with it until now.

I have a new query in to Ryder asking if Defense intends to continue to use this network considering that China now appears to be very busy doing bad things to us in cyberspace, and Ryder said he is working on it. Mark Nelson, a Savi Technology spokesman, said he would get back to me this week with a response.

Good News: The Air Force Is Ready to Fight the Cyber War

New threats mean new organizations -- and even better, new funding. So the Air Force has been positioning itself during the past year to manage and run the cyber war.

Until recently, Air Force leaders have relied on speeches and briefings to try to make sure the service gains the lead role in cyberspace. But last week, I stumbled over a very slick Air Force video that takes this approach to a new level. "It takes cyber dominance to defend America in a changing world," the ad says, plugging a new "elite" Air Force organization that "defends us from millions of cyber threats every day."

Cue the "Battle Hymn of the Republic" and "Off We Go Into the Wild Blue Yonder."

The Space Race

The Pentagon's China report also singled out the country as a new and potent adversary in space, with the ability to attack satellites.

Gen. Robert Kehler, commander of Air Force Space Command, recently told the Strategic Forces subcommittee of the House Armed Services Committee that unnamed adversaries are "actively pursuing" space dominance. U.S. space efforts, he said, face a range of threats, including jamming of radio frequencies and the Global Positioning System, as well as anti-satellite attacks and laser blinding of sensor systems.

The good news is the Air Force also has produced a slick video ad informing viewers that the service has the space dominance thing down.