Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

US Military Roadmap: 'Fight the Net'

Declassified Defense Department document reveals US military's strategy for using information as a weapon

Jan 30, 2007 | 07:00 AM

By Kelly Jackson Higgins
DarkReading

Ground operations, air operations, maritime operations -- and now, information operations?

That's right -- the U.S. military wants to add information operations as a new military core competency, according to a newly declassified Defense Department document called the "Information Operations Roadmap." The 78-page document, written in October 2003 and signed by former Defense Secretary Donald Rumsfeld (complete with blacked-out blocks of classified text), was obtained via the Freedom of Information Act by the National Security Archive at George Washington University and reported by BBC News.

It provides a sneak-peek into the military's ambitious goals for information operations: using/fighting the Internet, improving psychological operations (psyops), and dominating the electromagnetic spectrum. Bottom line: Information is crucial to the military's success.

"Fight the Net" is a major recurring theme of the document. Given the rise in hacker and cybercrime risks to U.S. businesses, the military should fight the Internet as if it were an "enemy weapons system," the document says. It also points out that networks are becoming more vulnerable and calls for a defense-in-depth strategy for "providing Combatant Commanders with the tools necessary to preserve warfighting capability."

The document hints about the use of "offensive cyber tools" and computer network attacks as well as integrated weapons systems, but much of that section is classified, and therefore sketchy.

Sean Kelly, business technology consultant with Consilium1, says the "fight the net" campaign is the wrong approach.

"I agree that our Defense Department needs to have strong security strategies for defending our information systems -- especially intelligence databases, as well as key communications channels," Kelly says. "I would hope that our Defense Department would employ some of the best and brightest network security professionals to develop a strategy that identifies and protects -- through monitoring and taking action where necessary, [a] good old fashioned incident response program -- high-risk areas of its own networks as well as on the Internet."

The military's IO Roadmap also includes improving psyops, which today are more "reactive" and "not well organized," according to the document, including better using technology -- radio, television, print, and Web -- to spread the word.

But one of the most compelling issues in the roadmap was the military's interest in getting control of the electromagnetic spectrum. "To prevail in an information-centric fight, it is increasingly important that our forces dominate the electromagnetic spectrum with attack capabilities," according to the document.

Kelly says controlling the electromagnetic spectrum is extreme. "Instead of taking an 'us against the world' approach, we should be collaborating with other nations to identify threats and develop a plan address known vulnerabilities," he says. "We can decide how we want to defend our internal interests and network infrastructure, but we should not be seeking the ability to have full control over the electromagnetic spectrum."

Defense Department officials were not available for comment in time for this posting.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • Consilium1, LLC


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)