Showing posts with label Australian Government Digital White Paper. Show all posts
Showing posts with label Australian Government Digital White Paper. Show all posts

Friday, August 18, 2017

Australian Joint Cyber Reserve Force


Tom Worthington aboard USS Blue Ridge
Tom Worthington
on USS Blue Ridge
Cyber commandos for defence reserve" 16 August 2017). The UK Joint Cyber Reserve Force. was stood up in May 2013 and I suggested Australia do some thing similar in August 2013.

These reservists would be similar to medical specialists who can apply their civilian skills in the military. This allows the military to use personnel who they could not afford to train and retain full time. It also provides a link between those running critical national infrastructure in the civilian sector and the government organizations tasked to protect it.

As I see it, members of the Cyber Reserve Force should be issued with secure communications equipment which they keep with them during their civilian job. The members would be in constant contact about threats and ready to act on them within minutes. This contrasts with a conventional reserve, where it takes days, weeks, or months for activation.

Saturday, July 01, 2017

Australian Defence Force Information Warfare Division


Head Military Strategic Commitments Division Major General PW 'GUS' GilmoreAn Information Warfare Division (IWD), has just been formed in Australian Defence Force Headquarters (July 2017). There are four branches: Information Warfare Capability, C4 and Battle Management Capability, Capability Support Directorate and the Joint Cyber Unit. The division is headed by MAJGEN Marcus Thompson as Deputy Chief Information Warfare. MAJGEN Thompson has a PhD in Cyber Security from the University of New South Wales. He is the author of "The cyber threat to Australia" . (Australian Defence Force Journal, 2012) and other papers on cyber security.

RAAF P-3 Orion Aircraft, photo by 'Timothy' CC BY 2.0, via Wikimedia CommonsThe ABC has speculated that one target for the new unit will be the Chinese South Sea Fleet, in the South China Sea.

It happens I have been teaching Australian National University IT students using a scenario about cyber-warfare over the South China Sea. In this hypothetical, students are asked to consider the use of information warfare as an alternative to conventional military action.

 As the ABC report notes, one of the problems with a cyber-warfare unit will be attracting, retaining and paying highly skilled personnel in competition with the private sector. An option I proposed in 2013 was the use of civilian computer professionals who are military reserve officers. After brief military training these personnel would return to their day jobs, but be ready to be instantly mobilized.

Sunday, August 04, 2013

Australian CyberWarfare Battalion


Tom Worthington aboard USS Blue Ridge
Tom Worthington
on USS Blue Ridge
This is to propose the Australian Defence Force (ADF) raise an Australian CyberWarfare Battalion (ACWB) of 300 personnel, to protect Australia's national information infrastructure. All but a small cadre would be reserve military personnel who have full time jobs as computer security professionals.

After very basic military training, personnel would be issued with secure communications and return to their workplace. Personnel would remain in touch with each other monitoring computer security threats. In the event of a large scale attack, most of the Battalion would stay in their workplaces to protect  infrastructure,  while a small number would deploy to industry, government and military centers (including any Cyber Security Operations Centre) to coordinate operations.

Compared to an infantry battalion,  a cyberwarfare battalion would be fast to raise and inexpensive to maintain. Personnel would receive the minimum of military training, sufficient for them to be able to work alongside regular personnel in a headquarters. Use would be made of the facilities and expertise in Australia's universities, including the University of NSW Cyber Range and the Queensland University of Technology Industrial Control System Security Course.

There is provision for the ADF to work alongside the civilian administration, as described in: "Civil-Military Operations", Australian Defence Doctrine Publication (ADDP) 3.11, 1 April 2009.

Without an effective form of cyber-defence Australia could expect its government and civilian infrastructure to be crippled within a few hours of the commencement of a major on-line attack. The ADF would then be required concentrate on aid to the community, with a reduction in its capacity to undertake conventional military operations.

Tuesday, July 02, 2013

Current trends in Cyber Security

Greetings from the CSIRO Discovery Centre in Canberra, where Asher Jamieson from CERT Australia is speaking on current and emerging threats in the Cyber Security landscape.

Mr. Jamieson pointed out that more than half of compromised systems are not detected by the organization itself but by someone else. He also mentioned that the amount of Spam being sent has reduced in the last year, not because of measures against spammers, but because they have found more targeted messages to be more effective.  Also hackers are persistent and will continue to attack the same organization, even when countermeasures are put in place, because the risk of being caught is so low.A recent trend has been extortion, using the threat of a Denial of Service Attack (DoS).

Mr. Jamieson described "Watering Hole Attacks", where a trusted third party's website is compromised, such as a service supplier.

Mr. Jamieson  pointed out that there had been attacks on SCADA industrial control computer systems. He ended with the worrying consequences of poor security in medical devices.

The main message from tonight's talk was to install security patches on package software. That is good advice, but in my view is no substitute for an Australian cyber security strategy. The Australian government abandoned work on a cyber security white paper and no effective strategy has been put in its place. As a result Australia's national infrastructure is at risk.

Attorney General's Department is hosting Security in Government Conference in Canberra, 12 - 14 Aug, 2013. This will include a Panoply "capture the flag" cyber-security competition, where teams will compete for control of a system.
Current trends in Cyber Security
CERT Australia’s views on current and emerging threats in the Cyber Security landscape, and what ICT Professionals can do to combat them. The last 12 months have clearly shown that no company can assume that they are immune to ICT Security threats, or assume that they will not be a target. While the focus of security is usually on preventing a threat from causing damage, having effective plans to deal with the aftermath of an incident is critical to maintaining security. Topics covered will include targeted intrusions, 2nd tier targeting, industrial control systems, Distributed Denial of Service attacks (DDOS), and will include several Australian case studies.

Asher Jamieson Technical Advisor, CERT Australia Asher Jamieson has worked in ICT Security in a number of different environments and is currently working as part of the Operations team in CERT Australia. He enjoys the variety and complexity of problems that the ICT Security field offers, and doesn’t see the rate of new challenges slowing down any time soon.

ps: Due to the topic, there was a strong presence from the defence community at the meeting. One informal discussion before the meeting was about if the China Houbei-class missile boat  was based on the Australian AMD design.

Wednesday, May 29, 2013

ABC Four Corners on Cyber-attacks in Australia

ABC Four Corners report "Hacked!" (27th May at 8.30pm on ABC1), alleged that Chinese military hackers were targeting Australian Government departments and corporations to steal secrets and business information. The program contained little hard evidence or new information. One allegation, that the plans to the new ASIO headquarters had been stolen to assist penetration of the building was new, but not particularly significant. However, the program will be useful if it prompts the Australian Government to restart its dormant work on public cyber security policy.

One curious segment of the program had a private security consultant asked if the Australia was preparing for offensive cyber-warfare, that is preparing to attack,. not just defence. The consultant hedged around the question, hinting but not answering clearly.

This reluctance to answer the question is at odds with a media release from Northrop Grumman in 2012 which announced it was building a cyber test range at the Australian Defence Force Academy (ADFA) in Canberra, to train defence force personnel. A cyber range is analogous to a test range for conventional weapons: the cyber range is used to test cyber warfare techniques, which can be both defensive and offensive. I attended a presentation to the Australian Computer Society, 13 March 2013, where one of the staff from Northrop Grumman gave a presentation on the cyber range.

Thursday, May 23, 2013

Need for Australian Cyber Security White-paper

The Australian Government released a Defence White Paper 2013 (May 2013). This highlights the risk of cyber attacks on defence, government and  commercial information networks. The paper claims that the Cyber Security Operations Centre (CSOC) has "allowed the development of a comprehensive understanding of the cyber threat environment and coordinated responses to malicious cyber events that target government networks". However, this addresses only government networks, not essential services provided by the private sector and on which government and defence depend. The paper envisages participation of key industry and private sector partners, but no further details are provided.

In September 2011 the Australian Department of Prime Minister and Cabinet (PM&C) issued a discussion paper “Connecting with Confidence, Optimising Australia’s Digital Future” , with the aim of releasing a cyber security policy white paper in mid 2012. The Australian Computer Society assisted PM&C with consultations, including arranging a meeting in Canberra, 18 October 2011. The ACS released a Submission for the Australian Cyber Policy White Paper. But in a speech October 2011, the Prime Minister said that she thought the Cyber White Paper should be broadened to a "digital White Paper" ("Closing Remarks to the Digital Economy Forum", Speech, Julia Gillard, Prime Minister of Australia, 5 October 2012). No Cyber White Paper has been released. As a result Australia's national infrastructure remains vulnerable to cyber attack. The Australian government needs to revive the cyber security white paper process.

Cyber

2.82 The 2009 Defence White Paper acknowledged that national security could be compromised by cyber attacks on defence, government or commercial information networks. Cyber security continues to be a serious and pressing national security challenge. The seriousness of the cyber threat was affirmed in 2011 when Australia and the US confirmed the applicability of the ANZUS Treaty to cyber attacks. This further emphasised the need for capabilities that allow us to gain an advantage in cyberspace, guard the integrity of our information, and ensure the successful conduct of operations.

2.83 Australia, advantaged by the cyber dimension of our international strategic partnerships, should find that the rise of cyber power has at least as many pluses as minuses. But the net effect on Australia’s position will depend on how well we exploit cyber power, including working with partners and integrating cyber power into national strategy and a whole-of-nation effort.

2.84 The potential impact of malicious cyber activity has grown with Defence’s increasing reliance on networked operations. Reducing Defence’s vulnerability to cyber attacks or intrusions in a crisis or conflict will remain a high priority. This includes protection of deployed networks and information systems. In a future conflict or escalation to conflict, an adversary could use a cyber attack against Australia to deter, delay or prevent Australia’s response or the ADF’s deployment of forces. This would probably include the targeting of information systems, networks and broader support infrastructure perceived to be integral to the ADF’s decision-making and war-fighting capabilities. Once deployed, our forces will need to operate as a networked force in a contested environment.

2.85 It is equally important to protect information in peacetime. Australia’s national security, economic prosperity and social wellbeing now depend on the internet and the security of information. Compromise of Australian Government information could allow an adversary to gain economic, diplomatic or political advantage over us. Compromise of commercial, government or private citizens’ information would undermine public and international confidence in Australia as a secure digital environment.

2.86 Defence capability would be seriously undermined by compromised sensitive information on command and control, operational planning, platform design or weapon system performance. Additionally, without effective mitigation and protection measures in place, the costs to Defence of addressing cyber intrusions could far outweigh the effort expended by an adversary.

2.87 Understanding of the cyber threat has increased markedly since the 2009 Defence White Paper.

The establishment of the Cyber Security Operations Centre (CSOC) within the Defence Signals Directorate (DSD) – to be renamed the Australian Signals Directorate – has allowed the development of a comprehensive understanding of the cyber threat environment and coordinated responses to malicious cyber events that target government networks. Through the CSOC, Australia has increased its intrusion detection, analytic and threat assessment capabilities, and improved its capacity to respond to cyber security incidents.

2.88 Within Defence, there is also a significant body of work to be done to ensure the security and resilience of defence systems in this environment. Network and system management, along with personnel and physical security need to be strengthened as part of our response.

2.89 Australia works within the framework of its traditional defence and intelligence and broader national security relationships to counter cyber threats. More broadly, Australia believes that the existing framework of international law, including the UN Charter and international humanitarian law, applies to cyberspace. Australia is participating in international efforts to achieve a common understanding of these laws.

2.90 In January 2013, the Prime Minister announced the establishment of a new Australian Cyber Security Centre to improve partnerships between government Agencies and with industry. The Centre will bring together cyber security capabilities from across the national security community, fully located in one facility. DSD’s CSOC, other elements of DSD’s Cyber Security Branch, the Attorney-General’s Computer Emergency Response Team Australia, the Australian Security Intelligence Organisation’s Cyber Espionage Branch, elements of the Australian Federal Police’s High-Tech Crime Operations capability and all-source-assessment analysts from the Australian Crime Commission will be co-located. This will facilitate faster and more effective responses to serious cyber incidents, and provide a comprehensive understanding of the threat to Australian Government networks and systems of national interest. The Centre will be overseen by a Board, led by the Secretary of the Attorney-General’s Department, with a mandate to report regularly to the National Security Committee of Cabinet.

2.91 Additional capability will be enhanced through participation of key industry and other private sector partners. Defence will play the principal role in the operation of the Centre and will continue to dedicate significant expertise to this important national capability.

From Defence White Paper 2013, Pages 20 and 21, Australian Government, May 2013

Monday, January 21, 2013

Australian Government Digital White Paper

Is the Australian Government preparing a Digital White Paper? Who is preparing it, how are they consulting interested parties and when is it to be released?

The Australian Department of Prime Minister and Cabinet (PM&C) issued a discussion paper “Connecting with Confidence, Optimising Australia’s Digital Future”, 15 September 2011, with the aim of releasing a policy white paper in mid 2012. The Australian Computer Society assisted PM&C with consultations, including arranging a meeting in Canberra, 18 October 2011. The ACS released a Submission for the Australian Cyber Policy White Paper. But in a speech October 2011, the Prime Minister said that she thought the Cyber White Paper should be broadened to a "digital White Paper" ("Closing Remarks to the Digital Economy Forum", Speech, Julia Gillard, Prime Minister of Australia, 5 October 2012). No Cyber White Paper has been released.

The only mention of preparation of a "Digital White Paper" from government I could find was from the Australian Information Commissioner ("Review of freedom of information legislation, Submission to the Hawke Review", December 2012). The Australian Council of Deans of ICT (ACDICT) issued a "Digital White Paper Submission" (Professor  Leon Sterling, President ACDICT, 9 January 2013). This quotes from "Digital White Paper", Key Themes: "The information and communications technology (ICT) skills and training required to sustain the digital economy now and into the future ... The development of collaborative partnerships between governments, industry and community". However, there is no formal reference for the document and I was not able to find the document this quote is taken from.