Defensive CYBER Operations
Abstract
Defensive Cyber Operations (DCO) falls within Line of Effort (LOE) 1 of the Network Modernization Strategy framework, which incorporates cyber capabilities that support the employment of the network as a weapon system. FY 2020 RDTE DCO efforts consists of the following critical capabilities: -Tactical DCO Infrastructure (TDI): System (automated on boot infrastructure to deploy DCO Tools on the Tactical Server Infrastructure (TSI)) which resides within the Command Post, at Brigade through Corps, for both organic Cyber Network Defenders as well as remote access by CPT to support defense of the tactical network (PEO C3T) -Cyberspace Analytics (CA): Identification of threat trends, behavior patterns, and Techniques Tactics and Procedures (TTPs) relative to associated portions of the information environment. The cyberspace analytics capability offers an integrated platform that can be leveraged across all security enclaves (NIPRNET, SIPRNET, and JWICS) to enhance both DCO and Department of Defense Information Network (DODIN) operations (PEO EIS) -Mission Planning (MP): An application-based, scalable warfighting capability for Army DCO mission command and planning at the global, regional, and local levels. DCO MP enables integration, coordination, and synchronization of supported and supporting cyberspace defenders (PEO EIS) -Tools Suite: Flexible and dynamic suite of warfighting capabilities that enable Cyber Mission Forces and other cyberspace defenders to perform functional categories consisting of site survey; risk assessment; observation; intel support; counter-mobility; developer/operator (DEVOPS), event correlation, and command and control (PEO EIS) -Garrison DCO Platform (GDP): Prepositioned, dedicated compute and storage resources residing at high/extremely high risk installations. Provides cyberspace defenders a remote maneuver capability in order to augment and/or support cyberspace defenders existing at designated bases, posts, camps, or stations by preserving an organization's ability to utilize mission critical data, networks, net-centric capabilities, and other designated systems (PEO EIS) -Deployable DCO System (DDS): A deployable kit, with dedicated compute and storage for austere environments that do not have prepositioned infrastructure or locations for which prepositioned DCO resources do not provide adequate capacity. The DDS allows global cyberspace defenders (e.g. CPTs) the ability to jump into a network, physically, onsite and gain a position of advantage to augmenting organic local and/or regional cyberspace defenders (PEO EIS) -User Activity Monitoring (UAM): The primary capability within the Army's overall insider threat detection (InT) program. UAM is a software-based, scalable solution that proactively identifies and mitigates internal risks associated with the theft and misuse of critical, mission essential data. UAM utilizes full-spectrum solutions to assess, deter, deny, defend, defeat, and evolve against the insider threat hub (PEO EIS) -Forensics and Malware Analysis (F&MA): Warfighting capability adheres to the global standard in digital investigation technology for global or regional cyberspace defenders who need to conduct efficient, forensically-sound, data collection and examination either remotely or locally using a repeatable and defensible process. Forensics gives cyberspace defenders the ability to triage by quickly viewing and searching potential evidence in order to determine whether further examination is warranted (PEO EIS) -Advanced Sensors: Real-time discovery of specific advanced or sophisticated cyber threats and vulnerabilities on a critical system or segment of the network. Advanced sensors provides an automated monitoring and incident handling capability lower in the network architecture (access layer) to conduct over-watch for high-risk units or systems that normally operate out of view ("last mile") from traditional security or DCO measures (PEO EIS) -Threat Emulation: Software and hardware based suite of tools used by a Cyber OPFOR to gain access to evaluated networks and systems using multi-vectors of unknown ("blackbox"), partially known ("graybox"), or known ("whitebox") access methods. Enables the implementation of real world threat tactics, techniques, and procedures against risk areas in order to reveal extremely high-risk security exposures and demonstrate the operational impact of a potential attack (PEO EIS) -Counter Infiltration: Software/hardware array of components that retrogrades mission critical assets from virtual areas under a cyber threat actor's control using stealth, deception, surprise, or clandestine movements. The capability allows commanders and leaders to trade space for time by slowing down the advanced persistent threat's without becoming decisively engaged (PEO EIS) -Forge: Provides integration and assessment capabilities during the development and integration phases of operations. DCO program will leverage non-FAR based Other Transaction Authorities (OTA) to solicit prototype/new technologies for consideration of procurement decisions. -Rapid Cyber Prototyping: Rapidly develops cyber capabilities identified by the Cyber Mission Forces (CMF) in order to counter advanced, persistent, and sophisticated cyber threats (ARCYBER)
Document Details
- Document Type
- Project
- Publication Date
- Oct 01, 2020
- Source ID
- EV5_0605041A_5_2040_PB_2020
Related Documents
- Root: Defensive CYBER Tool Development
- Child Accomplishment: Defensive Cyber Operations (DCO) - Tactical DCO Infrastructure (TDI) - (PEO C3T)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Cyberspace Analytics - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Mission Planning - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Tools Suite - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Garrison DCO Platform - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Deployable DCO System - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - User Activity Monitoring - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Forensics and Malware Analysis - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Advanced Sensors - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Threat Emulation - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Counter Infiltration - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Forge (Integration) - (PEO EIS)
- Child Accomplishment: Defensive Cyber Operations (DCO) - Rapid Cyber Prototyping - (ARCYBER)
- Child Cost Item: e7ab697ef1250385fd7a871ae3f1de7b
- Child Cost Item: 5abc6e52f731ada0790bbd195b5d84b6
- Child Cost Item: f566411f69e6753d69b78b9490608132
- Child Cost Item: 268eb8623dc1011406ae5bf79869591e
- Child Cost Item: 6a4a7d309e64f7ca07c0ccac61c5e734
- Child Cost Item: cb494c490058220a2cacadc6f5d22331
- Child Cost Item: bb35a12823b37fda7a61503bced704e6
- Child Cost Item: d2d4d9c66c8a524ee798100999e9a824
- Child Cost Item: 04fdc9dbd3ded3050945168f6aceb0e7
- Child Cost Item: e74835c690ea4c691d1f97e4185a30a2
- Child Cost Item: a90c23167b73fc92ee1a6ad6a4fdca47
- Child Cost Item: 5fe1ca98f6d9d218a5f0061ba7e59653
- Child Cost Item: 3868e2c40ae211e18c9a4398a69f9d8a
- Child Cost Item: 15d590e33e69df17c8ad07cb9e9e3e7d
- Child Cost Item: b30e2a2e34055e5b3dc4e6e088847d64
- Child Cost Item: 7066181210b25c0f55f97404228fa8b8
- Child Cost Item: b43106bf413a85e5289b5405a62413ea
- Child Cost Item: 0ac20915de81f2d9ebf78e7dbc524c87
- Child Cost Item: eefff63f1fae2f28d687fd45021de16c
- Child Cost Item: 6085c6d00c44ff3334d8e4c27ae41a40
- Child Cost Item: d873bcdbdd116861e6a22d06b547b120
- Child Cost Item: 7a177c9ad98a92d4ad354bd484e5c5b0
- Child Cost Item: 70a33637a021e6d63789440c5bf9464d
- Child Cost Item: fd0d945ec14917beb106877b16a30955
- Child Cost Item: ee8650d123374e5eb7fde18432bed859
- Child Cost Item: 1faca28fe4b035deb96505c1ce06984a
- Child Cost Item: 88700a198b04f8245609a76039c20049
- Child Cost Item: 9eccc0559a3090dc19e18a596f70cade
- Child Cost Item: e41d90d5f4787143fd33fff332776d83