DefenseTech Military.com
  • Categories
  • Full Archives
  • Monthly Archives
  • About Defense Tech
Subscribe to RSS

About Defense Tech

Defense Tech examines the intersection of technology and defense from every angle and provides analysis on what’s ahead.

Tip Us Off

Tip for Defense Tech?

SEND IT!

It’s Confidential!

Categories

  • ‘Canes
  • Af-Cam
  • Afghan Update
  • Ammo and Munitions
  • Armor
  • Around the Globe
  • Av Week Extra
  • Axe in Iraq (and Elsewhere)
  • Bizarro
  • Blimps
  • Blog Bidness
  • Body Armor Blues
  • Bomb Squad
  • Brownshoes in Action
  • Bubbleheads, etc.
  • Cammo Green
  • Catch the “Buzz”
  • Chem-Bio
  • Civilian Apps
  • Cloak and Dagger
  • Commandos
  • Comms
  • Contingency Ops
  • Cops and Robbers
  • Crazy Ivan
  • Cyber-warfare
  • Data Diving
  • Defense Tech Poll
  • Defense Tech Radio
  • Dissent Tech
  • Door Kickers
  • Drones
  • DT Administrivia
  • Eat DT’s Dust
  • Extra! Extra!
  • Eye on China
  • F-35 Watch
  • Fast Movers
  • FCS Watch
  • Fire for Effect
  • FOS Files
  • Friday Funnies
  • Gadgets and Gear
  • Going Green
  • Grand Ole Osprey
  • Ground Vehicles
  • Guns
  • Homeland Security
  • In the Bubble with Joe Buff
  • In the Weeds with Eric
  • Info War
  • Iraq Diary
  • Jarhead Jazz
  • JSF Watch
  • Just War Theories
  • Lasers and Ray Guns
  • Less-lethal
  • Logistics
  • Los Alamos and Labs
  • M4 Monopoly
  • Medic!
  • Mercs
  • Missiles
  • Money Money Money
  • Most Wanted
  • MRAP Edge
  • Net-Centric
  • Nukes
  • Old Skool
  • Our Shrinking Planet
  • PEO Soldier
  • Planes, Copters, Blimps
  • Podcast
  • Politricks
  • Polmar’s Perspective
  • Popular Mechanics
  • Rapid Fire
  • Raptor Watch
  • Red Team
  • Retro-Futuro
  • Robots
  • Roll Your Own
  • Sabra Tech
  • Ships and Subs
  • Snipertech
  • Soldier Systems
  • Space
  • Special Ops
  • Star Wars
  • Strategery
  • Stray Trons
  • Tactical Development
  • Terror Tech
  • The Deadlies
  • The Defense Biz
  • The Peoples’ Site
  • The Sunday Paper
  • The Tanker Tango
  • The View from Av Week
  • Those Nutty Norks
  • Training and Sims
  • Trimble on the Case
  • Uncategorized
  • Video Lounge
  • War Update
  • Ward’z Wonderz
  • You can run…

Archives

  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003
  • August 2003
  • July 2003
  • June 2003
  • May 2003
  • April 2003
  • March 2003
  • February 2003
  • January 2003

Home » Cyber-warfare » A Ship Without a Captain

A Ship Without a Captain

cyberspace-command.jpg

We have been covering cyber now for several months and my work in cyber defense and security has been going on for over a decade. In that period of time the U.S. government has failed to establish the command authority needed to protect the nation. Critical questions have gone unanswered for months or even years. One of those questions deals with where the cyber command operation headquarters will be located. The physical location for cyber command is not yet decided. This has been a hot topic now for the last ten months and multiple states are jockeying for position.

If that is not bad enough, the government has failed to establish a command and control structure and authorities for offensive cyber capabilities, defensive cyber capabilities and cyber intelligence. With billions of dollars of budget at stake, the amount of political posturing and verbal war has risen to heights not seen before. The level of infighting became un-tolerable for Rod Beckstrm, Director of the National Cyber Security Center (NCSC) at the Department of Homeland Security. This past weekend he resigned. So what should we do?

I have given this much thought over the past decade and occasionally been asked by those looking into this what I would do. So here it is…

Recommendations:

1. Department of Defense (DoD) Secretary Robert Gates owns the offensive capabilities to fight a cyber war and defenses against cyber attack that originate outside the United States.

2. Homeland Defense (DHS) Secretary Janet Napolitano owns offensive and defensive cyber capabilities for activities within the United States. (Remember a significant number of compromised computers within the U.S. were used in the DDoS attacks against Estonia and Georgia and the uniformed military cannot be used against it own citizens!) U.S. Strategic Command would include cyber in their unified command structure. In addition, DoD must appoint a liason/coordinator to NATO given their role in cyber peace keeping and response to cyber attacks.

3. The National Security Agency (NSA) Director LTG Keith B. Alexander owns cyber intelligence and espionage activities both inside and outside the United States. They continue to collect, analyze and disseminate cyber intelligence as well as any and all counter cyber intelligence activities.

4. A National Cyber Security Executive is added to the Presidential Staff and coordinates all the efforts of DoD, DHS and NSA. Given the civilian, government, business, education interrelationship that cyber has, this matrixed organizational structure is necessary to fully protect and defend our nation (internally and externally).

5. A National Cyber Attach would be appointed by President Obama and serve as special liaison to the United Nations and other countries in pursuit of international cyber relations.

Until the leadership is established and these questions, and other, are answered cyber defense is like a ship without a captain! That is the current situation when it comes to cyber defense in the United States. As long as these questions linger without answers, our nation remains at great risk!

– Kevin Coleman

Share |

March 10th, 2009 | Cyber-warfare | 438115 Comments »http://defensetech.org/2009/03/10/a-ship-without-a-captain/A+Ship+Without+a+Captain2009-03-10+12%3A49%3A15Ward You can skip to the end and leave a response. Pinging is currently not allowed.

« « Polmar on the C-130 | Boots on the Ground — The Taliban Surge » »

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

  1. Eddie V. says:
    March 10, 2009 at 4:23 pm

    Kevin;
    I very much like the last two points of your recommendation, but I have some issues with the first three, issues which rise from the inherent nature of cyberwarfare and which you obviously have a knowledge of.
    The spectrum of aggressive actions that actors can take seems to range from probing to active intelligence gathering to brute force attacks ala DDoS. Further, like you mention, these attacks are incredibly difficult to attribute and the workstation making the attack may or may not be in charge.
    This causes two issues. First, both state and nonstate actors have an incredible flexibility across that spectrum. Under your situation, who makes the call when an action crosses from DoD’s responsibility to repel “cyber attack” and NSAs responsibility to counter intelligence gathering? And how does the DoD respond?
    Second, when botnets can include both foreign and domestic computers, who decides if it’s DHS or DoD which takes responsibility? You say, quite rightly, that DoD can’t operate in the States or against its own citizens, but how do we know where the attack originated?
    To my mind, splitting up the responsibility geographically is inefficient and dangerous. I would feel much more comfortable if one agency had full responsibility for cyberdefense. Centralization allows for the coordination and (if done correctly) flexibility which is necessary. That, or every agency needs to be responsible for safeguarding its own systems, including civilian corporations. Either a top-down centralized clearinghouse or a cell-based resilient approach. I would think anything else is asking for trouble.
    You’ve obviously put more study into this then I have, however, and I greatly appreciate the thought you’ve put in. Perhaps you see something I don’t?

    Reply
  2. Carl says:
    March 11, 2009 at 5:55 pm

    Tim
    Perhaps you should relook at the law!!! Because of Posi Comitatus the Army (military) is not allowed to be used on US soil for these matters — thats what the National Guard are for.

    Reply
  3. pedestrian says:
    March 12, 2009 at 12:55 pm

    Kevin, what do you think about this, your point of view within a new article if you don’t mind.
    http://​www​.spacewar​.com/​r​e​p​o​r​t​s​/​U​S​_​C​y​b​e​r​_​H​e​a​d​_​Q​u​i​t​s​_​O​v​e​r​_​T​h​r​e​a​t​s​_​T​o​_​D​e​m​o​c​r​a​c​y​_​9​9​9​.​h​tml

    Reply
  4. Kevin says:
    March 12, 2009 at 5:37 pm

    Eddie V
    I wanted to address your comment — How then would putting responsibility in their (DoD) hands be an effective tool?
    When I worked primarily with the private sector (business) I use to think that the public sector (government including DoD)did not really get it and was behind as you kind of hinted at in your posting. I agree monitoring on both the public and private sector is critical. I must tell you after a significant amount of interaction with the defense and intelligence community as well as DHS they see so many highly sophisticated attacks and the frequency of the attacks are so great, they are much further ahead in their thinking, knowledge and capabilities it is unreal. The private sector has a role but not leadership.

    Reply
  5. Eddie V. says:
    March 12, 2009 at 8:14 pm

    Kevin;
    I’m afraid that’s not what I meant at all. I’m quite aware that the DoD is working overtime on determining what, exactly, cyberwarfare means. I know that it has some of the best defensive cyber tools and systems in operation today.
    What I meant by questioning its effectiveness was this: There are so many points of entry that it seems a waste of resources–indeed, beyond the logistical capability of the DoD–to monitor _all_ data traffic entering and leaving the United States. And yet, if they are to be aware of any attack with time enough to prevent/defend/retaliate, they must do exactly that.
    To my mind, a resilient, cell-based defense network would be much better. Don’t give corporate America the ability to retaliate (that’s just asking for trouble), but set up programs which encourage them to build security architectures that can withstand vigorous attack. Then, they can inform each other and the government of attacks and leave the deliberate retaliation to whichever agency ends up bearing the responsibility.
    What we really have here is the tragedy of the commons–our infrastructure as a whole is no one agency or company’s responsibility, and thus gets left by the wayside. One way to correct this is to make it the government’s responsibility, as you have suggested. Another solution is to create externalities which drive normal citizens to remember the commons. Wouldn’t this method be more effective in this case?

    Reply
  6. Kevin says:
    March 12, 2009 at 8:38 pm

    Eddie V
    2 things
    From an un biased semi insider view DoD is HIGHLY Effective!!!!!!
    As for the cellular network architecture and building them right from the start. You have to defend what we already have invested in while highly resilient, cell-based defense network are developed, procured, installed, validated and implemented and with the government procurement process that could be a decade!
    PS I love this type of interaction!!!!

    Reply
  7. Dusitn L. Fritz says:
    March 14, 2009 at 6:56 pm

    All,
    We need to create a non-profit organization to start developing solutions and legislation now. Submit to congress ASAP. Contact me if you are interested! Kevin I have emailed you my number.
    Dustin L. Fritz
    CEO | The Computer Network Defense Group LLC

    Reply
  8. Jim says:
    March 16, 2009 at 9:54 am

    The National Security Agency is part of the Department of Defense. Please do not double-count them. And they are legally prohibited from taking action inside the United States wothout appropriate Attorney General/Court action.
    Opinion: Homeland Defense should handle Defense and the (renamed) Department of War should handle offense.

    Reply

Leave a Reply

Click here to cancel reply.

Spam Protection by WP-SpamFree

NOTE: Comments are limited to 2500 characters and spaces.

By commenting on this topic you agree to the terms and conditions of our User Agreement

    Recent Articles
    • JSF Price Tag Jumps to $135 Million
    • EADS Tanker, Not Dead Yet
    • JFCOM’s Mattis Pushes Light IW Aircraft
    • And, the Vertical Landing
    • NLOS-LS Missile Fail Could Impact Navy’s LCS
    • JFCOM’s JOE Whacks Defense Industry
    • New F-35B Hover Video
    • China’s Shipbuilding in a Regional Context
    • Debating the Pros and Cons of LCS
    • Bigger, Badder IEDs in Afghanistan
    Recent Comments
    • JSF Price Tag Jumps to $135 Million
      The rest of the world must be laughing their asses off...
      BILL D
    • JSF Price Tag Jumps to $135 Million
      Got a program question for you Mac. What is the definition...
      TMB
    • JSF Price Tag Jumps to $135 Million
      Re: #3 While maintaining that cutting edge is great, let us...
      TMB
    • JSF Price Tag Jumps to $135 Million
      It lowers the overall price tag though. It was done...
      STemplar
    • JFCOM’s Mattis Pushes Light IW Aircraft
      This is a great, fiscally sound, idea and it is...
      mr5t3v3n
    • EADS Tanker, Not Dead Yet
      Alright then good sir, fair enough. I just don't want...
      american1776
    • JSF Price Tag Jumps to $135 Million
      I think the best option would be to scrap the JSF, AF...
      Benjamin
    • JFCOM’s Mattis Pushes Light IW Aircraft
      Every person posting here has made good points,...
      eyes_up
    • JFCOM’s Mattis Pushes Light IW Aircraft
      Re: LAAR–just expand the UAV programs
      bjackson
    • JSF Price Tag Jumps to $135 Million
      Good Morning Folks, LM to DoD: ” Stick...
      Byron Skinner
  • Channels:Military.com | Military Benefits | Military News | Off Duty |Join the Military | Military Education | Veteran Jobs | Military Money |Military Deals | Military Family | Military Community
  • Military.com Network:Military.com | MilBlogging | Defense Tech | DoD Buzz |SpouseBuzz | Fred's Place | GI Bill Express
  • Services: Army | Navy | Air Force | Marine Corps |Coast Guard | National Guard | Military Spouse
  • About Military.com About Us | Advertise With Us | Press | Affiliate Program |Monster Network | Help | Feedback | Privacy Policy |User Agreement| © 2010 Military Advantage