It’s no secret cyberthreats are becoming more sophisticated and tenacious in nature. Several high-level officials recently offered, from their perspectives, how these threats are evolving and how quickly they’re evolved at the seventh annual AFCEA Cybersecurity Summit in Washington on Tuesday.
Curtis Dukes, director of the Information Assurance Directorate at the National Security Agency provided three examples of growing challenges in cyberspace. First, there is an increased level of diversity in what adversaries are doing, he said. These threats have evolved from purely intelligence gathering to destructive in nature, to most recently theft of personally identifiable information. Most recently, he said, actors are now moving to interfering in political parties.
He also described how adversaries have not had to use so-called zero-day exploits in the past 24 months, or exploits previously unknown. Rather, adversaries have exploited publicly available vulnerabilities, leading him to assert that there must be a doubling down of cyber hygiene.
Third, he noted that industrial control systems, SCADA systems and the colloquial Internet of Things will be the new security front as security is not baked into these systems. The community must think about security from the sensor to the management console, he said, as these supply an easy access point for adversaries to gain entry.
For Marianne Bailey, principle director in the office of the deputy chief information officer for cybersecurity at the Pentagon, cyberthreats are more sophisticated, though not in the technology used. Rather, there has been an increased sophistication from a research and planning perspective as adversaries have intently studied what they want. They then figure out the entry points — though not necessarily from a network perspective — such as who the contractors are and who is working on certain systems. They then exploit the weakest link in the chain. The Department of Defense has observed a much more thorough adversary in terms of accessing areas they want to access, she said.
Similarly, Richard Ledgett, deputy director of the NSA, noted that the days of Nigerian princes and misspelled emails to coerce unsuspecting victims at the other end of the keyboard are over. Today, adversaries “do extensive research on social media, open source and they learn about you and your interests” and tailor spear-phishing emails, he said.
This professionalism has been observed from the Navy’s perspective as well. Rear Adm. Gene Price, deputy commander of Fleet Cyber Command, said the professionalism of adversaries has advanced.
“We don’t worry about someone sitting in their parent’s basement anymore,” Price said. Now there are adversaries that are conducting more advanced campaigns with better training, he added.
Price also said the Navy has noticed within the last three or four years that what used to take an adversary days or weeks to achieve can be done in hours. This activity is automated and preplanned, he said, with little human interaction. The Navy’s response time must increase exponentially just to keep up, he asserted.




