Sponsored by Spectra Group
————————————————————————
10 Aug 23. New Zealand to create intel agency recommended over two years ago.
New Zealand plans to create another intelligence agency to help the government more rapidly react to and better coordinate its response to security threats.
The Royal Commission, charged with looking into the March 2019 Christchurch mosque attacks, recommended the formation of a new agency in its report presented to Parliament in December 2020.
“We recommend that the Government: Establish a new national intelligence and security agency that is well-resourced and legislatively mandated to be responsible for strategic intelligence and security leadership functions,” the commission wrote.
In June 2022, New Zealand Defence Minister Andrew Little said it was too early to do so. But earlier this month, while introducing the government’s defense and security policy, he announced the nation’s first national security system.
“It commits us to acting early, working together and having an integrated approach,” Little said Aug. 4.
“When [in 2017] we came to government, the priorities for the national security system were highly classified,” he noted. “If the public didn’t even know what the priorities were, then how could they … contribute to improving the security of the country?”
Although Little described the formation of a national intelligence and security agency, or NISA, as a “priority task,” it wasn’t mentioned in any of the supporting documents unveiled this month.
The next day, Aug. 5, the government announced NISA would be over and above the Security Intelligence Service and the Government Communications Security Bureau, rather than replacing them. In this role, NISA would take a higher-level view of the “threat horizon.”
New Zealand has several intelligence agencies. Currently, the Department of the Prime Minister and Cabinet includes the National Security Group, the National Assessments Bureau, the National Security Systems Directorate, and the National Intelligence and Risk Coordination directorate.
Other intelligence agencies include the Government Communications Security Bureau, the Security Intelligence Service, a police-run special investigations group, and the military’s Directorate of Defence Intelligence and Security.
David Capie, director of the Centre for Strategic Studies at the Victoria University of Wellington, questioned the eventual formation of NISA.
“I think you might be reading a bit much into … a brief comment Minister Little made,” Capie told Defense News. “A ‘NISA’ is not mentioned in the NSS [National Security Strategy document]. He was fairly equivocal in his comment, and of course we have an election on 14 October, so who knows what will happen after that.”
For Robert Patman, a professor of politics at the University of Otago, NISA should come with oversight and coordinate with other agencies, but also avoid the “danger of groupthink.”
“NISA, in the form it was envisaged by the Royal Commission, has not yet emerged as an independent oversight agency, and it seems that some of the functions that were going to be taken on by NISA have actually been taken on by other agencies,” Patman told Defense News.
“Can they exercise oversight over themselves? We’ve always had a problem in this country with having stand-alone, independent oversight teams,” he added. “I think it does make sense when you’re dealing with something as potentially dangerous as national security, that you do have an agency that coordinates, sits above them, and it shouldn’t just be another group of public servants.”
On whether the nation will form NISA, Patman said it’s unclear why there’s been a delay given “the government’s gone on record as accepting all [the commission’s] recommendations.”
Defense News approach Little for comment, but was referred to the minister for national security and intelligence — traditionally the prime minister — who was unavailable. (Source: Defense News)
10 Aug 23. DOD Announces Establishment of Generative AI Task Force.
Today, the Department of Defense (DoD) announced the establishment of a generative artificial intelligence (AI) task force, an initiative that reflects the DoD’s commitment to harnessing the power of artificial intelligence in a responsible and strategic manner.
Deputy Secretary of Defense Dr. Kathleen Hicks directed the organization of Task Force Lima; it will play a pivotal role in analyzing and integrating generative AI tools, such as large language models (LLMs), across the DoD.
“The establishment of Task Force Lima underlines the Department of Defense’s unwavering commitment to leading the charge in AI innovation,” Hicks said. “As we navigate the transformative power of generative AI, our focus remains steadfast on ensuring national security, minimizing risks, and responsibly integrating these technologies. The future of defense is not just about adopting cutting-edge technologies, but doing so with foresight, responsibility, and a deep understanding of the broader implications for our nation.”
Led by the Chief Digital and Artificial Intelligence Office (CDAO), Task Force Lima will assess, synchronize, and employ generative AI capabilities across the DoD, ensuring the Department remains at the forefront of cutting-edge technologies while safeguarding national security.
“The DoD has an imperative to responsibly pursue the adoption of generative AI models while identifying proper protective measures and mitigating national security risks that may result from issues such as poorly managed training data,” said Dr. Craig Martell, the DoD Chief Digital and Artificial Intelligence Officer. “We must also consider the extent to which our adversaries will employ this technology and seek to disrupt our own use of AI-based solutions.”
Leveraging partnerships across the Department, Intelligence Community and other government agencies, the task force will help minimize risk and redundancy while pursuing generative AI initiatives across the Department.
Artificial intelligence has emerged as a transformative technology with the potential to revolutionize various sectors, including defense. By leveraging generative AI models, which can use vast datasets to train algorithms and generate products efficiently, the Department aims to enhance its operations in areas such as warfighting, business affairs, health, readiness, and policy.
“The adoption of artificial intelligence in defense is not solely about innovative technology but also about enhancing national security,” said U.S. Navy Capt. M. Xavier Lugo, Task Force Lima mission commander and member of the CDAO’s Algorithmic Warfare Directorate. “The DoD recognizes the potential of generative AI to significantly improve intelligence, operational planning, and administrative and business processes. However, responsible implementation is key to managing associated risks effectively.”
The CDAO became operational in June 2022 and is dedicated to integrating and optimizing artificial intelligence capabilities across the DoD. The office is responsible for accelerating the DoD’s adoption of data, analytics, and AI, enabling the Department’s digital infrastructure and policy adoption to deliver scalable AI-driven solutions for enterprise and joint use cases, safeguarding the nation against current and emerging threats.
For more information about Task Force Lima, please visit the CDAO website at ai.mil. You can also connect with the CDAO on LinkedIn (@ DoD Chief Digital and Artificial Intelligence Office) and Twitter (@dodcdao). Additional updates and news can be found on the CDAO Unit Page on DVIDS. (Source: U.S. DoD)
08 Aug 23. Point Break. Both Ukrainian and Russian troops use civilian standard radios for tactical communications employing AES-256 encryption. How much credence should be given to reports that Russian communications intelligence experts have cracked the AES-256 standard?
Do claims that Russian COMINT experts have cracked the AES-256 encryption standard, and are exploiting this achievement to support military operations in Ukraine, hold up?
The US government adopted the AES-256 (Advanced Encryption Standard-256) electronic data encryption protocol from the early 2000s. It replaced what was known as the Data Encryption Standard developed by IBM in the early 1970s, and adopted by the US government in 1977, according to histories of US encryption. The use of AES-256 to secure US governmental data is enshrined in Federal Information Processing Standards. Known as FIPS, these are published by the US National Institute of Standards and Technology.
It would take a whole series of articles to clearly explain AES-256 encryption and how it works. If this is your thing, Armada highly recommends checking out this excellent online guide. This guide says that AES-256 is a “virtually impenetrable symmetric encryption algorithm.” Its robust nature has seen it not only used extensively by the US government, but also in military and business communities. The article continues that it is not impossible to crack AES encryption with “(a) combination of the perfect brains, the most powerful computer and sheer hacking talent,” although it argues such a process may take a long time.
Several of the Motorola handheld Ultra High Frequency (UHF: 300 megahertz to three gigahertz) handheld radios deployed by the Ukrainian military use AES-256 encryption according to open sources. These radios, Armada understands, are primarily used for tactical squad-level communications. We recently heard claims that Russian Communications Intelligence (COMINT) experts can perform real-time decryption of AES-256 encoded traffic. What do these claims mean, and how likely is it that they are true?
Keepers of the Keys
Whether the encryption itself has been broken is a moot point. Another good article, this one by electronic warfare expert James Spriet, argues that Russian COMINT experts may have instead obtained the relevant AES-256 encryption keys. Once these keys are in their possession, they can be used to decrypt AES-256-protected communications. This is akin to burgling the house after stealing the key, rather than prising open a window to enter. As Mr. Spriet sagely notes “the security of the encryption is only as robust as the management of its keys.” If Russian spies found some way of stealing the keys, they effectively gain entry to the house. Likewise, what if Russian COMINT cadres had obtained one or more of the Ukrainian Motorola radios using this encryption. Hardly impossible given the detritus that litters a battlefield. It might simply be a matter of listening to the traffic on the network that radio inhabits so long as they stay in range.
Discussions in open sources keep returning to claims that AES-256 is effectively unbreakable. Does this claim hold water? COMINT Consulting told Armada via a written statement that “once a key is broken, you can decode anything using that key in real time.” It added that COMINT Consulting’s own Krypto1000 Keyfinder software can recover and then solve some 256-bit encryption keys, but not all cryptographic systems are created equally. For higher-end encryption, specialised hardware is used. A specialised server decrypting the traffic needs to be optimised to do this, “but then (the decryption) is done as close to real time as possible.”
Disinformation
COMINT Consulting does not rule out the expertise of Russia’s COMINT practitioners to break AES-256 encryption. A report by London’s Royal United Services Institute thinktank on Western components in Russian equipment highlighted the Russian Army’s Torn COMINT system as one platform that might be able to break AES-256. Torn has come under Armada’s spotlight in the past. We assessed Torn as one of the army’s more advanced COMINT systems, noting that it is deployed slightly back from the tactical edge to support tactical/operational electronic warfare. “What the Russians have/don’t have is a matter of speculation, but given their mathematical prowess it’s certainly plausible,” COMINT Consulting’s statement adds.
It is also entirely possible that reports of AES-256 vulnerability are a red herring. Are Russian information warriors putting this story into the ether to dissuade their adversaries from using AES-256 radios? Would such disinformation be intended to harm Ukrainian morale or hamper battlefield communications by sowing distrust? Breaking AES-256 encryption would be an intelligence bonus for Russian COMINT experts. Surely such an achievement would be a zealously guarded secret? As usual, there’s much about the conduct of the Russo-Ukrainian War in the electromagnetic spectrum which remains mysterious. We may not have many answers, but inevitably, we have many questions. (Source: Armada)
10 Aug 23. Five Alive. 5G networks may have important contributions to make in enhancing tactical communications but they are not without accompanying risks. It may have passed you by, but in January the European Defence Fund (EDF) launched a new project called 5G COMPAD (5G Communications for Peacekeeping and Defence). The EDF is an annual disbursement by the European Union (EU) to foster research, development and innovation in Europe’s defence sector. 5G COMPAD “will demonstrate the relevance of 5G (fifth-generation) mobile communications technology in support of sustained information superiority” according to the project’s documentation. The project’s deliverables include the design, prototyping and testing of a “reference architecture for a 5G-based robust and resilient multi-dimensional communications system to demonstrate (the) operation capabilities” of 5G technologies in defence applications. A raft of European companies and research institutes are involved in 5G COMPAD.
Just what is 5G?
Put simply, 5G is a catch-all term for a new set of cellular telecommunications protocols being introduced globally. These new protocols use low- and mid-band, and Millimetre Wave (MMW), segments of the radio spectrum. Low-band frequencies are akin to those used by 4G, typically 400 megahertz/MHz to 3.4 gigahertz/GHz. Mid-band encompasses frequencies of 2.4GHz to 4.2GHz while MMW inhabits 24GHz up to 72GHz. 5G promises significant increases in data rates compared to current 4G protocols which could reach 20 gigabits-per-second. Latency could fall from circa 20 to 30 milliseconds for 4G, to under ten milliseconds for 5G. More subscribers can be hosted on a single 5G node than on its existing 4G equivalent. Current 4G cellular protocols support circa 4,000 devices per square kilometre (0.38 square miles). This increases to circa one million when using 5G MMW frequencies.
These new protocols are integral to the forthcoming Internet of Things (IOT). Oracle describes the IOT as a network of physical objects embedded with sensors, software and technologies. Such networking allows these objects to exchange data with other devices and systems over the internet. The defence world is embracing this technology via the Internet of Military Things (IOMT). The IOMT follows a similar methodology to the IOT. It emphasises the connection of every platform, sensor, weapons system, warfighter, base and military capability, henceforth known as assets. The IOMT will enable continuous exchanges of data including everything from intelligence, surveillance and reconnaissance to health and usage monitoring information. Data will be uploaded to cloud computing applications where it will be stored and accessed.
Militarised 5G forms a key part of the US Department of Defence’s (DOD) Joint All-Domain Command and Control (JADC2) architecture. JADC2 is being implemented across the DOD and is the materiel aspiration of the US DOD’s Multi-Domain Operations (MDO) philosophy. MDO fosters the full connectivity of all military assets at all levels, and across all domains, of war. The aim of MDO is to facilitate better and faster decision-making vis-à-vis one’s adversary. To this end, it is instructive that 5G will be one of the technologies underpinning the US Army’s Integrated Tactical Network (ITN).
Applications
Michael Rowe, vice president of Frost & Sullivan’s advisory business and global practice leader for aerospace, space and defence argues that 5G potentially provides “a single architecture capable of offering ‘broadband speed’ connectivity across forces.” This is particularly important given the DOD’s multi-domain operations doctrine discussed above. Mr. Rowe continues that 5G will be an invaluable technology for connectivity-intense and dependent assets like uninhabited systems.
Dr. Raymond Shen, director of 5G/6G government solutions at Keysight Technologies sees other applications where 5G could have relevance. The IOMT depends on connectivity. Military assets need networking and Dr. Shen sees 5G as a useful way to connect these assets to one another. 5G networks provide low latency while handling both low and high data rates. He believes that 5G could be beneficial in assisting augmented reality technologies and telemedicine, in addition to its potential for uninhabited vehicle connectivity.
Risks
Is 5G technology a panacea for military tactical communications or a niche application? Mr. Rowe emphasises that 5G has risks. Like all cellular communications protocols 5G depends on line-of-sight communications. As anyone who has tried to use their cellphone in the countryside can attest, if there is not a cellphone mast in range of your phone, connections become difficult. Armies may need to physically deploy 5G infrastructure into theatre if local networks cannot be relied upon or are unavailable. Deploying 5G infrastructure can translate into “more masts that need protecting on the ground.” One way around this challenge, argues Dr. Shen, will be to host 5G services on satellite networks. Low earth orbit satellite communications networks like SpaceX’s Starlink have potential. Satellite-hosted 5G networks may provide alternatives to terrestrial 5G infrastructure which risks being “non-existent, downed or denied.” However, whether an army is deploying a 5G network on the ground, or accessing one in space, both potentially have significant financial costs.
A further issue is whether enough spectrum is available in theatre for deployed 5G to serve its full potential? Despite the 5G bandwidths mentioned above will these always be available in their entirety? Are these bandwidths hosting other users, limiting how much spectrum is available for a deployed 5G system? “Oftentimes there are trade-offs,” says Dr. Shen, “and no easy solutions since spectrum is so widely used and available spectrum is scarce.” From a military perspective, appropriating a local 5G network, but then saturating it with traffic could restrict 5G bandwidth to local civilian users. From a ‘hearts and minds’ perspective, denying local users’ bandwidth could be detrimental.
Other risks cited by Dr. Shen include 5G services being at risk from cyberattack as “malware could potential be introduced to data networks.” Cybersecurity can be used to mitigate risks but may not be able to eliminate them. Several organisations are developing the technical standards for 5G. These organisations have “working groups to increase security, and academia performs a plethora of security research” says Dr. Shen. He adds that the private sector is playing an important role in testing and monitoring 5G networks “to prevent or detect security breaches.”
5G networks are also at risk of jamming, argues Dr. Shen. Russian land forces electronic warfare assets include several capabilities targeting the frequencies used by 5G networks. Furthermore, “5G is poor at penetrating physical objects like walls,” says Mr. Rowe. This could have an impact for the technology’s utility in urban warfare, for example. Ultimately, Mr. Rowe does not see a mass uptake of 5G by militaries for tactical communications. Nonetheless, initiatives like 5G COMPAD and ITN show that 5G has a role to play in tactical communications, provided stakeholders are aware of the accompanying risks. (Source: Armada)
09 Aug 23. UK Digital Developments. British Army plans to develop a digital ecosystem across the force feed into wider UK multi-domain integration goals. The British Army’s Digital and Data Plan 2023 – 2025 is an instructive document. The publication outlines how the force will exploit advances in digital and data technology. It is the first such publication of its kind but unlikely to be the last. The United Kingdom’s Ministry of Defence (MOD) is embracing the Multi-Domain Integration (MDI) philosophy. In the ministry’s own words, MDI is about “ensuring that every part of defence can work seamlessly together, and with other government departments and the UK’s allies, to deliver a desired outcome.”
This goal rests on improving the synergies between all parts of the UK’s defence enterprise. The defence enterprise is not only the MOD and the UK’s armed forces. The enterprise embraces all parts of government, industry, academia and the country at large involved in the UK’s defence and security posture. MDI is like the US Department of Defence’s Multi-Domain Operations (MDO) philosophy. Armada defines MDO as the total integration of all military capabilities across all domains and all levels of war to perform synchronous operations informed by better quality and faster-paced decision-making vis-à-vis one’s adversary.
Concepts and Strategies
The UK’s MDI vision rests on its Integrated Operating Concept and Defence Digital Strategy. The MOD says the Integrated Operating Concept “sets out a new approach to the utility of armed force in an era of strategic competition and a rapidly evolving character of warfare.” Integral to this is driving “the conditions and tempo of strategic activity, rather than responding to the actions of others from a static, home-based posture of contingent response.”
The Defence Digital Strategy outlines how the UK will “enable seamless access to … data by delivering a secure, singular modern Digital Backbone.” Essentially, the Digital Backbone is the secure data networking and exploitation facilities that will envelop the UK’s defence enterprise. The army will form part of the Digital Backbone. The Digital and Data Plan explains how “the army will deliver and meet the vision of a data centric and digitally optimised (force) to counter challenges in an everchanging and complex environment.”
Project Theia will ensure data sharing across all army capabilities within the force and outwards to the defence enterprise and UK allies. As the MOD makes clear, digitisation and deeper connectivity will be enhanced across the entirety of the army. Of interest to this article is how the digitisation and associated connectivity of the army’s manoeuvre force will be improved.
LETACCIS
The army has a wider plan, known as Project Wavell, focusing on how the force will fight in a multi-domain context alongside the UK’s allies in the 2025 to 2035 timeframe. Key to the digitisation of the army is the Land Environment Tactical Communications and Information Systems (LETACCIS) programme. LETACCIS is an overarching term for several programmes enhancing army connectivity. These include the Bowman Combat Infrastructure and Platform (BCIP 5.6), Project MORPHEUS, Trinity, JCRVT (Joint Common Remote Viewing Terminal), Dismounted Soldier Awareness (DSA), Falcon and Niobe.
BCIP 5.6 covers the army’s existing tactical communications and battle management system. Morpheus represents the technologies that will replace BCIP 5.6. Trinity is providing a deployable wide area network to replace the existing Falcon operational/tactical level trunk communications network. Niobe delivers a multi-platform common, mission configurable communications information system. JCRVT is a modular remote viewing system receiving and transmitting real time video. DSA will provide dismounted troops with improved voice and data communications services at company level.
In a written statement supplied to Armada, the MOD said that several disparate army digital networks and capabilities covering logistics, medical services, ground-based air defence, human-machine teaming, robotics and autonomous systems, and artificial intelligence “will exist together within a digital ecosystem with common governance rules and standards.” The statement continued that the capabilities discussed above, alongside technologies like fifth-generation cellular networks will form the digital ecosystem’s networks.
The MOD’s statement continued that army digital networks will link outwards to other government organisations involved in defence and security, but which are not part of the MOD. An example given was the emergency services networks that are the responsibility of the UK’s Home Office interior ministry. Linking out to these networks chimes with the MOD’s multi-domain integration approach. Likewise, the digital ecosystem will link outwards to allies. LETACCIS has specific interoperability requirements to this end.
Wider Efforts
The MOD stresses that the digital ecosystem is a constantly evolving concept. As a result, it is difficult to give specific dates on when the concept will reach initial and full operational capability. The MOD’s statement emphasised that LETACCIS is funded and moving forward. The statement added that DSA and Trinity should reach initial operational capability in 2025 and 2026 respectively.
The Digital and Data Plan underscores the army’s commitment to digitisation, in turn forming a key part of the UK MOD’s wider multi-domain integration approach. This approach dovetails with US MDO efforts and similar initiatives by UK allies such as France. The work of the British Army and MOD in general shows that MDI is not just an aspiration but a tangible goal to which both are committed.
(Source: Armada)
09 Aug 23. August Radio Roundup. The US Army is receiving new Comtech troposcatter communications equipment which will improve army beyond line-of-sight communications and integrate seamlessly with other army communications systems.
Armada’s monthly round-up of all the latest military communications news in the product, programme and operational domains.
New US Army Troposcatter Communications
Comtech announced in a press release in mid-July it had won a $30m contract to provide its Troposcatter Family of Systems (FOS) to the US Army. A recent Radioflash! podcast from Armada provided a detailed discussion of troposcatter communications. These new troposcatter systems will support US Army beyond-line-of-sight tactical communications. Daniel Gizinski, Comtech’s chief strategy officer, told Armada that “Comtech’s next generation Troposcatter FOS are delivering performance enhancements that represent up to a one-thousand-fold increase over former generations of troposcatter radios.” The new systems the company is delivering have capabilities “beyond just long range fixed backhaul to small form factor tactical systems that can be set up in a matter of minutes, and even potentially translate to on-the-move communications as we recently demonstrated. This capability allows customers to deploy troposcatter down to lower echelons and provide a rapidly deployable extension capability.” Mr. Gizinski continued that Comtech’s troposcatter apparatus works seamlessly with other US Army communications. He added that the company’s products can be easily updated. New software applications can enhance performance and meet emerging mission needs as and when these become available.
Flexible Response
FlexRadio announced on 10th July that it had commenced shipments of its ML-9600 series High Frequency (HF: three megahertz/MHz to 30MHz) transceivers. A company press release said that the radios meet the US Department of Defence’s MIL-STD-188-110 stipulations for HF communications protocols. The radios can also perform second-, third- and fourth-generation automatic link establishment. Although ML-9600 series radios can support military operations Stephen Hicks, FlexRadio’s chief technology officer, told Armada that initial customers “are primarily government and university laboratories and research organisations who are utilising the highly adaptable software defined radio architecture for testing and waveform development, particularly those requiring wideband transmit and receive capabilities.” Mr. Hicks added that deliveries of the first ML-9600 radios commenced in June. Deliveries were made to research and development organisation customers. Mr. Hicks added that FlexRadio is “in discussions with various government agencies about operational fielding.”
FlexRadio’s new ML-9600W HF radio is part of the company’s overall ML-9600 series. Initial deliveries have been made to research and development organisations, with government sales expected to follow soon.
PacStar Evolves
Curtiss-Wright has launched its PacStar SMCP (Secure Mesh Command Post) member of its PacStar product series for unified network communications management, the company announced in a press release. The document said that the PacStar SMCP design provides two-layer CSFC (Commercial Solutions for Classified) encryption to protect data. PacStar SMCP provides a secure vehicle-to-vehicle tactical communications architecture for use in expeditionary environments, the press release continued. The new product uses Curtiss-Wright’s PacStar-400 deployable communications hardware at its core and PacStar SMCP can support any wired or wireless network. Curtiss-Wright told Armada in a written statement that the new product also uses its PacStar-444 switches and PacStar-451 servers. The CSFC “multi-site connectivity capability package (allows) customers wireless access to networks up to Top Secret across the meshed environment.” In addition, the company “has already provided integrated PacStar SMCP hardware to customers and is currently working collaboratively under contract with them on the integration and NSA (US National Security Agency) registration of these solutions. We are actively supporting test and deployment of these solutions during current and ongoing lab and deployment exercises.” (Source: Armada)
09 Aug 23. White House and DARPA challenge innovators to bring AI tools to cyber defense. The AI Cyber Challenge asks leading companies to develop advanced AI systems that will contribute to critical infrastructure cybersecurity — with nearly $20m available in prizes. In the latest step towards harnessing the power of artificial intelligence for public good, the Biden administration is launching a new, two-year competition between some of the leading AI software companies to develop new code to protect the digital networks of critical infrastructures nationwide.
Led by the Defense Advanced Research Projects Agency, the “AI Cyber Challenge” competition partners with companies — including Google, Microsoft, Anthropic and OpenAI — to leverage advanced AI algorithmic capabilities for national cybersecurity.
The prizes for this competition total about $20m, and will be awarded to the teams with the best systems.
“AI is the most powerful technology of our time, and we have to get it right for the American people,” Arati Prabharker, director of the White House Office of Science and Technology Policy, told reporters on Tuesday. “That means managing its risks and it means harnessing its tremendous potential.”
Prabharker added that this is a pivotal example of how the public and private sectors can collaborate on national security projects for mutual benefit. Ann Neuberger, the deputy national security advisor for cyber and emerging technology, added this challenge is “critical” and marries automatic software security with AI to quickly identify and remedy network vulnerabilities.
“With this new challenge, teams will now have the power of modern AI to work through these complicated problems in support of our national security,” she said. “This challenge will help us stay ahead in the race against our adversaries’ cyber offensive capabilities. Because fundamentally, there is no national security without cybersecurity.”
While the competition involves larger tech firms, DARPA will also fund seven small businesses with up to $1m to participate in the competition’s initial phase. Perri Adams, the DARPA program manager for the AI Cyber Challenge, confirmed that the qualifying event will take place in spring 2024, with the top 20 candidates participating.
From there, the remaining top five semi-finalists will be chosen to participate in the final competition at DEFCON in 2025.
“This is a chance to explore what’s possible when experts in cybersecurity and AI have access to a suite of cross-company resources of combined, unprecedented caliber,” Adams said.
The AICC will collaborate with the Open Source Security Foundation, the latter of whom will serve as a challenge advisor. Adams said the collaboration is due to the importance of open source software’s role in the democratization of cybersecurity.
“AICC will also ask the prize winners to open source their system such that the innovations produced by AICC can be used by everyone, from volunteer open source developers to commercial industry,” Adams said. “If we’re successful, I hope to see AICC not only produce the next generation of cybersecurity tools in this space, but show how AI can be used to better society.”
A priority for this challenge will be keeping the winning software products agnostic to all sectors and applicable to a large swath of digital networks.
“We’re trying to design tools that can secure as much software as possible throughout society,” a DARPA official said on Tuesday’s press call.
President Joe Biden has focused his executive efforts on cultivating a level of public and private partnerships amid the growing — and unregulated — anthropomorphic AI industry. With participation from agencies like the National Institute of Security and Technology, Biden has put forward several guidance documents like the AI Bill of Rights and AI Risk Management Framework to bring more oversight and accountability into AI systems.
Moving forward, Biden has said he will continue working with Congress to push bipartisan regulations forward, as well as release an executive order on responsible AI innovation. (Source: Nextgov/FCW)
09 Aug 23. Ransomware will remain a key threat to business operations over long term. On 7 August, cyber security company, Akamai, released a new report with an analysis of ransomware attacks between Q1 2022 and Q1 2023. The investigation found that the use of zero-day and one-day vulnerabilities resulted in a 143% rise in total ransomware victims during that timeframe, with ransomware groups increasingly using exfiltration of files as the primary source of extortion. This shift highlights threat actors’ evolution away from encryption as the main means of generating illicit profit, meaning that organisations can no longer solely rely on file backup solutions as a sufficient mitigating strategy against ransomware. The manufacturing sector experienced a 42% increase in victimisation, while healthcare had a 39% increase in victimisation, indicating particularly high operational and security risks to entities in those industries. For organisations that had experienced multiple ransomware attacks, the report highlighted that they were six times more likely to be targeted in a second attack within three months of the first one. This finding underscores threat actors’ ability to re-target and re-infect entities at a rapid rate despite victims’ remediation efforts. Ransomware will remain a persistent threat to global organisations and their operations as cyber criminal groups continue to evolve their tactics to sustain profitable campaigns. (Source: Sibylline)
09 Aug 23. Northrop Grumman Corporation (NYSE: NOC), in partnership with the U.S. Air Force, successfully completed an integrated airborne mission transfer (IAMT) demonstration with the B-2 Spirit at Whiteman Air Force Base as part of the ongoing modernization efforts incorporating digital engineering. IAMT delivers an advanced capability that enables the B-2 to complete a digital, machine-to-machine transfer of new missions received in flight directly into the aircraft. IAMT is part of Northrop Grumman’s B-2 Collaborative Combat Communication (B2C3) Spiral 1 program that digitally enhances the B-2’s communications capabilities in today’s battlespace.
“We are providing the B-2 with the capabilities to communicate and operate in advanced battle management systems and the joint all-domain command and control environment, keeping B-2 ahead of evolving threats,” said Nikki Kodama, vice president and B-2 program manager, Northrop Grumman. “The integration of this digital software with our weapon system will further enhance the connectivity and survivability in highly contested environments as part of our ongoing modernization effort.”
The demonstration included approximately 50 mission transfers during a two-day period in partnership with the Air Force. Aircraft vehicle 1086, the Spirit of Kitty Hawk, was configured with Northrop Grumman’s Multi Mission Domain (MMD) architecture. MMD is an open mission system architecture for the B-2 that allows rapid and affordable fielding of modern mission capabilities. The mission transfers utilized MMD to integrate with the B-2 Adaptable Communications Suite (ACS).
In the demonstration, the aircrew received an incoming transmission from the ACS ground station, which loaded the mission directly through MMD interfaces to the B-2 Disk Drive Unit. B-2 flight crews can now focus more on mission execution in today’s dynamic battlespace thanks to progressive digital technology.
07 Aug 23. Finland: Ransomware attacks increased following NATO accession; sustained impact on public, private sector operations. Cyber security company Recorded Future released a report on 3 August stating that ransomware attacks against Finnish organisations increased four-fold since the country began the NATO accession process. In October 2022 alone, the country faced as many distributed-denial-of-service (DDoS) attacks as it previously averaged over a three-month period. Simultaneously, ransomware attacks increased substantially, possibly as a result of Finland having abandoned its previously neutral stance vis-à-vis Russia. In September 2022, the Finnish Security Intelligence Service published its annual National Security Overview, which underscored that Russia would likely pursue the cyber space as a primary means of espionage after authorities expelled nine suspected intelligence officers from the Russian embassy in the capital Helsinki. At the same time, the country’s National Cyber Security Centre (NCSC) issued an alert warning organisations of possible cyber incidents, however senior Finnish security officials have said the risk of a paralysing cyber attack against the country’s critical infrastructure (food, water, electricity distribution) is unlikely in the near term. Nonetheless, public and private organisations in Finland continue to face an elevated risk of cyber attacks and other disruptive operations, particularly from Russian state-sponsored or affiliated actors. (Source: Sibylline)
04 Aug 23. AFRL Artificial Intelligence Agents Successfully Pilot XQ-58A Valkyrie Uncrewed Jet Aircraft. To reduce risk to aircrews by integrating their activities with uncrewed aerial vehicles with artificial intelligence capabilities, the Air Force Research Laboratory led a successful three-hour sortie, July 25, 2023, demonstrating the first-ever flight of artificial intelligence agents (algorithms) controlling an uncrewed jet aircraft – the XQ-58A Valkyrie.
Test units executed the flight in the Eglin Test and Training Complex. The flight was the culmination of the previous two years of partnership that began with the Skyborg Vanguard program.
“The mission proved out a multi-layer safety framework on an AI/ML-flown uncrewed aircraft and demonstrated an AI/ML agent solving a tactically relevant “challenge problem” during airborne operations,” said Col. Tucker Hamilton, chief, AI Test and Operations, for the Department of the Air Force. “This sortie officially enables the ability to develop AI/ML agents that will execute modern air-to-air and air-to-surface skills that are immediately transferrable to the CCA program.”
The algorithms were developed by AFRL’s Autonomous Air Combat Operations team. The algorithms matured during millions of hours in high fidelity simulation events, sorties on the X-62 VISTA, Hardware-in-the-Loop events with the XQ-58A, and ground test operations, as depicted in the video at the link below.
“AACO has taken a multi-pronged approach to uncrewed flight testing of machine learning Artificial Intelligence and has met operational experimentation objectives by using a combination of High-performance computing, modeling and simulation, and hardware in the loop testing to train an AI agent to safely fly the XQ-58 uncrewed aircraft,” said AACO Program Manager, Dr. Terry Wilson.
DOD is committed to the responsible employment of AI. To achieve responsible use of AI requires teaming of developers and users of AI enabled autonomy working in collaboration with acquisition specialists.
“AI will be a critical element to future warfighting and the speed at which we’re going to have to understand the operational picture and make decisions,” said Brig. Gen. Scott Cain, AFRL commander. “AI, Autonomous Operations, and Human-Machine Teaming continue to evolve at an unprecedented pace and we need the coordinated efforts of our government, academia, and industry partners to keep pace.”
The Air Force Research Laboratory is the primary scientific research and development center for the Department of the Air Force. AFRL plays an integral role in leading the discovery, development and integration of affordable warfighting technologies for our air, space and cyberspace force. With a workforce of more than 11,500 across nine technology areas and 40 other operations across the globe, AFRL provides a diverse portfolio of science and technology ranging from fundamental to advanced research and technology development. (Source: https://www.defense-aerospace.com/ Air Force Research Laboratory)
04 Aug 23. Ransomware groups primarily target France, Germany, UK and US; sustained risk to business continuity, government services. On 3 August, cyber security company Malwarebytes released a report on global ransomware trends between July 2022 and June 2023, underscoring that four countries were the predominant victims of 1,900 total ransomware attacks. The four countries most affected were France, Germany, the UK and the US. Of all global ransomware attacks, the US accounted for 43%. Attacks targeting France also doubled between February and June 2023, with the country experiencing a disproportionately high number of attacks against government entities. Government entities are a more lucrative target for ransomware campaigns since their operations must be sustained at all times, enabling groups to demand a high ransom payment to regain access. The prominent ransomware group ‘Lockbit’ remained an active provider of ransomware-as-a-service (RaaS), conducting approximately 24 attacks each month. Since March 2023, another well-known ransomware group – ‘Cl0p’ – significantly increased their attacks by exploiting zero-day vulnerabilities in target organisations. The use of zero-day vulnerabilities as an attack vector indicates a significant shift in tactics by ransomware groups, which is likely to alter the threat landscape to a more aggressive exploitation model. Security and operational risks posed by ransomware and zero-day vulnerabilities will remain heightened in the long term. (Source: Sibylline)
————————————————————————-
Spectra Group Plc
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————-

