When it comes to the Army’s defensive cyber operations, getting to a more global remote capability is important. Russell Fenton, an Army training and doctrine command capability manager in the defensive cyberspace operations branch, said at the TechNet Augusta conference that “to provide the quick reaction security enhancement reinforcement at the time of need, global cyberspace defenders must have the ability to maneuver remotely or on site.”
Fenton discussed the desire for a forensics malware tool, with forthcoming testing of this capability on the defensive cyber operations maneuver baseline at the Network Integration Evaluation 17.2.
While the Army has several forensic tools, Fenton told C4ISRNET that the forensics malware tool would be “for a more enterprisewide capability,” and that “just like we’re trying to remotely do things for other actions, [it] may allow for like a regional cyber center to reach in, grab the artifacts using this capability and then that unit can put the system in.”
Fenton noted this is not a current capability gap, per se. “It is a capability gap from how we want to employ it at the end of the day,” he told C4ISRNET. “I mean, we have forensics tools … but, again, all that has to be done on site, and more times than not you don’t really have the skill set down at that level in order for them to be able to conduct those tasks; and then they have to ship those systems back somewhere else.”
The remote capability is what he said the Army is trying to reach, but added that legal issues play a role.
“From the legal standpoint, are we able to do that? Because, again, you want to make sure that the evidence is not tainted or that its integrity is jeopardized in a way that an analyst can go in and actually find out what the heck happened,” he said.
Planners and trainers from Cyber Command have worked to integrate greater remote capabilities during exercises. At this year’s Cyber Guard and Cyber Flag, physically hosted at a secured Joint Staff facility in Suffolk, Virginia, teams were remotely playing from CYBERCOM headquarters at Fort Meade, Maryland.
Calling it a “distributed capability,” Maj. Gen. Paul Nakasone, CYBERCOM Cyber National Mission Force commander, said last year he had roughly 40 of his staff and a majority of his teams on site at Suffolk. This year, by contrast, he had four people and one team in Suffolk with several teams playing from Fort Meade.
While the new cyber forces are still getting used to the command structure and mission, so too are commanders. Nakasone said updates were coming in via video teleconference, which was a change for him. “It’s a little bit different, to be honest, as a commander to get updates over the VTC daily and really get a sense of what is happening,” he told reporters during a briefing at Fort Meade following the conclusion of Cyber Flag this summer.
Fenton said he could not discuss what’s coming down the pipe for this capability as the Army is still in the process of choosing a viable option.
During his prepared presentation, he did discuss how certain acquisition authorities can be leveraged to help field some capabilities faster than the traditional process. Other transaction authorities, he said, can be used by the Army to “request vendor ideas to meet real-time problems and conduct demonstrations and technical exchanges and ultimately select a candidate for delivery of a prototype in as little as 75 days.”
This concept is not a panacea, however, and will not take the place of the enduring acquisition process. “We just can’t continue to do this and just do it in enough time where we actively purchase enough capability and field it to the force,” he said. “But what we want to do is, again, quicken that flash to bang time for those real-time problems and then bring these things within the enduring process.”
Fenton also discussed how, as part of the Army’s defensive cyber operations requirements strategy, the force is looking for a DCO planning capability. This capability, he said, is part of TRADOC’s partnership with Army Cyber Command and the Defense Advanced Research Projects Agency’s Plan X project. Plan X is a visual environment meant to provide instantaneous knowledge of a network attack.
Plan X, Fenton said, has been demonstrated “a few times now at Cyber Guard and Cyber Flag but they — DARPA — have about 18 months right now in order to continue development of this to bring it up to a technology readiness level six in order to transition” it to the next steps.
“And so we will continue to work with them to make sure that that’s ready for transition sometime early ’18.”




