The Navy is thinking differently about its approach to cybersecurity, according to a top official. Rear Adm. Nancy Norton, director of warfare integration for information warfare and deputy director for Navy cybersecurity, said the efforts of Task Force Cyber Awakening, which was undertaken as a response to various breaches of Navy networks, are changing the way the Navy thinks about cyber security, moving to a much broader approach than merely enterprise IT.
Speaking to an audience at an AFCEA-NOVA hosted luncheon Oct. 21 in Vienna, Virginia, Norton described how the Navy must understand its cyber platforms as it understands its other warfighting platforms. “How do we really think of cyber and what is the Navy’s cyber platform? So we very much understand what a ship platform looks like [be it] a submarine or an aircraft, what those platforms do and how we manage them, but we’ve not thought of the cyber platform in that same way as one of our warfighting systems that we have to have an understanding of and how we control that,” she said.
She explained that the Navy is taking a different approach to all of its platforms – not just standard IT systems – but control systems, security systems and ensuring better understanding of the network and its vulnerabilities.
Many of the services have experienced growing pains with operationalizing the cyber domain – moving from what was a traditional IT space to a warfighting platform and capability. The Navy is no different, Norton told C4ISRNET following her remarks, but assured that the Navy is well under way in these efforts, spending the last few years operationalizing cyber.
Within this new cybersecurity approach, she said the Navy is really thinking about cyber resiliency much more than cyber protection. “It’s about how do we maintain mission assurance, what is the risk to the mission and what is the risk to the force?” she said. It’s “not just understanding our networks, which is the baseline we have to do that, not just protecting our networks…but then also being able to detect any issues that come in through our networks and a much more robust ability to do that across the networks and on all parts of the networks.”
How Navy forces react is the most important part, she said. How does it fight through any network events, can it maintain the ability to conduct its mission and what does it need to do this as quickly as possible?
The Navy last year asked for $88 million dollars in research and development for cyber resiliency. As part of R&D in this space, Norton told C4ISRNET the Navy is undertaking several efforts. They are “mostly focused on understanding how we segment the networks, how we [put] control points in our networks to reduce the flow of traffic to reduce the actual amount of data we have to worry about,” she said. “Things like whitelisting…particularly in the systems that don’t have any need to have lots of different protocols being used in their data flows. As we connect that down we actually understand more and more” about data flows and how to segment those.
Norton also noted during her remarks that the Navy must leverage the power of analytics to be more predictive in the future. Predictive analytics are a critical capability the Navy needs, she said, to understand what’s likely to happen on networks in the future as opposed to what is happening now.
She said Hurricane Matthew was a great example of this: They knew as the hurricane was coming in the networks would be under significant bandwidth constraints, because everyone would want to see what’s happening. As a result, they put in place various filtering measures to restrict this so only the most important operations could get through on the Navy networks and support the ships.
“I think there’s a lot more we need to be doing in understanding what is likely to happen,” she said. “A lot of that is looking at past patterns but analytics plays a big role in this as well.”
Norton also said she absolutely sees hunt capabilities becoming part of Navy networks in the future. They have already established the need to do hunt to be able to know what is happening on networks and have that expertise within the service. Many others in the Defense Department, such as the Defense Information Systems Agency, as well as the NSA have looked to these hunt teams, employing an offensive mindset to defense to improve network defense.
The Navy, Norton said, has shifted from a signature-based detection capability to approaches that will find new threats and zero-day vulnerabilities. This hunt capability is part of moving into a different arch to detect unusual behavior on networks, she continued.




