One of, if not the most, important aspects of cybersecurity is resilience — the ability to continue fighting through an attack. Within this construct, there is also an intelligence aspect, which is the ability to observe adversaries’ behavior inside one’s network to gain insights on their tactics, techniques and procedures.
“One of the things that is of interest lately is — I don’t know what we call it [today], it used to be called honeypots — now it’s really more just kind of a general obfuscation, right? Where can you have sections of your network that are supposed to be completely transparent to the everyday user but serve as almost kind of a trip wire,” Giorgio Bertoli, senior science and technology manager at the Intelligence and Information Warfare Directorate of the Army’s Communications-Electronics Research, Development and Engineering Center (CERDEC), told C4ISRNET at the annual MilCom conference in Baltimore, Maryland, on Wednesday. “The fundamental issue is your intrusion detection system is only as good as the signature attached. Yes, anomaly detection is always something that’s been promised, but it always has a fundamental flaw of false positive rates.”
The question, he said, then becomes: Can software silently run on a network until something abnormal is noticed via a trip wire of sorts? This “could also help with how were they tripped, what techniques did somebody use to get to those systems in the first place and help in that regard,” he said.
This notion of observation to gain greater insight is also something that’s taught and exercised by the military in large-scale training exercises. Previously, where traffic may have simply been blocked, portions of the network are cordoned off as a means of learning about malware.
“Let’s be able to cordon off an element of the network to see the malware develop,” Lt. Gen. Paul Nakasone, then-commander of the Cyber National Mission Force, told reporters regarding participant actions during the annual Cyber Flag exercise. “What’s the malware actually like? … This is a maneuver force and we are a learning organization. So how do we learn? We learn based upon being able to replicate the threat and then be able to maneuver our forces to see what type of effect we can achieve.”
Nakasone is now the commander of Army Cyber Command.
Network segmentation, or the ability to separate portions of a network that become infected from an attack, are a fundamental strategy, Bertoli said. “Quarantining we call it. One of the big challenges is figuring out what is actually critical within your network. What are the true, critical systems that you can try to cordon off? The question becomes: The moment you know that something has been compromised, can you quarantine those core systems from the rest of the networks so that they are protected” from an attack?
It’s not feasible to simply unplug our devices when something goes wrong, said Donald Coulter, Space and Terrestrial Communications Directorate team lead at CERDEC, during a panel at MilCom.
The force must continue to “fight the fight,” he said, by looking at technology that focuses on obfuscation, deception and evasion of cyber activities as well as leverage artificial intelligence to more effectively analyze behavior and activity on the network to better respond to incidents on the network.
Certain automation methods along these lines, including integrated adaptive cyber defense — which, among other things, creates the ability to quickly and automatically share information — can literally take the place of a honeypot.
“I won’t need a honeypot anymore because this actually happened in another section or another network somewhere, and that information is now being shared across all these other networks,” Ryan Gunst, program manager at Space and Naval Warfare Systems Command, said during a panel discussion at MilCom regarding what an integrated, automated cyber defense approach brings. “There is a real honeypot; it is the actual network, and then all the mitigation activities that we did to mitigate that are also now being translated across the enterprise and put in place so that if you do see it somewhere else you don’t have to go manually take those actions anymore.”
However, purposely sitting back to observe adversarial behavior on one’s network for intelligence purposes must be properly coordinated, said Neal Ziring, technical director for the U.S. National Security Agency’s capabilities division, said during the same panel. If done manually without orchestration “there’s human error, and then you might tip off your adversary that you’re watching,” he said.




