Infrastructure bill amendment includes $2.5B for 5G wireless rollout at military bases
Republican lawmakers have put forward an amendment to the bipartisan infrastructure bill that includes $2.5 billion in funding for the installation of 5G wireless technology at Department of Defense facilities.
Senate Appropriations committee ranking member Richard Shelby, R-Ala., proposed the amendment, which is focused broadly on boosting defense funding. It is supported also by fellow Republican Sens. Jim Inhofe, Okla., Roger Wicker, Miss., Mike Rounds, S.D., and Thom Tillis, N.C.
The amendment was not adopted prior to a vote by Senate lawmakers Sunday evening to end debate over the infrastructure bill. The bill text theoretically could still be altered, however, this is unlikely because it would require cooperation from all 100 senators.
Rolling out secure 5G technology across military installations is a core element of the Department of Defense’s plan to create a joined-up battlefield, in which soldiers and military vehicles have access to real-time data.
The revision would also allocate $3.8 billion for construction at the Department of Energy’s national labs. This includes projects at the National Nuclear Security Administration, the Los Alamos National Laboratory, the Savannah River nuclear facility, and additional projects.
If enacted, it would also add $4 billion across military services and the Pentagon for infrastructure maintenance projects, and set aside another $2 billion for high priority military construction projects.
Lawmakers are expected to take a final vote on the passage of the $1 trillion infrastructure bill this weekend, after the Senate moved through a series of amendments to the legislation on Wednesday.
Negotiators are working on a final iteration of the bill, and Senate majority leader Chuck Schumer, D-N.Y., has called for the chamber to move quickly, as it passes through the final stages of the legislative process.
Speaking at an industry association event last year, the Air Force’s chief of staff, Gen. Charles Q. Brown said the services would “most definitely” need to rework its networks in order to facilitate the rollout of 5G.
Following a Senate cloture vote on Sunday evening, the infrastructure bill is expected to clear the upper chamber either late Monday or early Tuesday.
Unisys ‘doubling down’ on public sector cloud business, CEO says
Unisys is “doubling down” on public sector cloud business and is focused on growing its digital workplace services division, according to CEO Peter Altabef.
Speaking on the company’s second-quarter earnings call, Altabef said the company would compete hard to outgrow market peers and to take market share.
As part of a restructure earlier this year, the company sold its U.S. federal services arm to SAIC and launched two new business segments: Digital Workplace Services and Infrastructure and Cloud services. Its digital workplace arm is focused on consultancy and the sale of communications-as-a-service systems.
Unisys expects the $17 billion public sector cloud services market to grow by about 15% to 18% each year, according to an investor presentation published in January.
During the second quarter of 2021, Unisys swung to an operating profit of $49.3 million compared with a $8.5 million loss in the second quarter of 2020. Within its cloud and infrastructure business segment, revenue grew 9.9% year-over-year to $124.4 million
CISA issues cyber training guide for federal employees
The Cybersecurity and Infrastructure Security Agency on Thursday published a new training guide to help federal employees improve their cybersecurity skills and create a cyber-focused career plan.
The new document includes clear career pathways for staff within agencies such as CISA to follow. It is intended also to codify new points of entry into government cybersecurity, including through internships.
Commenting on the launch of the guidance at the Black Hat conference in Las Vegas, CISA Director Jen Easterly said it would help with identifying “no-cost opportunities that fit [employees’] professional development schedule.”
The publication of the guide comes amid a push to fast-track new cyber talent into government and follows calls for greater flexibility over hiring rules to allow new staff to be brought into agencies more quicky.
In particular, the White House is focused on bringing in new talent through more direct authority hiring and by establishing partnerships with colleges and universities.
CISA is also providing grants for nonprofits focused on identifying and developing unrealized cybersecurity talent within underserved communities, in a bid to increase workforce diversity.
It follows an executive order signed last month by the Biden administration that mandates agencies to adopt new measures to increase equity and diversity within the workforce.
“I believe we need to do everything we can to ensure our cyber workforce reflects the diversity of America because diversity of gender, ethnicity, education, sexual orientation, neurodiversity – all of that translates into diversity of thought and enables better problem-solving,” said Easterly.
DOD CIO to implement new electromagnetic spectrum strategy
The job of implementing a strategy to modernize how the Department of Defense uses electromagnetic spectrum (EMS) will now fall to the office of the Chief Information Officer, the DOD announced Thursday.
Implementation and creation of the current strategy has been overseen by the vice chairman of the Joint Chiefs of Staff who leads an EMSs cross-functional team, but that authority will transfer to the CIO in the fall. The change was triggered by a new implementation plan for the EMS Superiority Strategy signed by the secretary of defense in July but announced Thursday.
“The enterprise approach in the [implementation plan] reaches beyond the traditional ‘silos’ and drives the Department to act in a more integrated fashion, mirroring the shared nature of the EMS,” Acting DOD CIO John Sherman said in a statement.
The change was ordered as the CIO already oversees EMS activities, which include a range of operations from radio communications and anti jamming. The implementation plan calls on the CIO’s office to oversee creating and managing an EMS workforce and ensuring the bureaucratic processes properly resource EMS tasks.
The strategy was born out of a Government Accountability Office report that found insufficient leadership on how the DOD handles EMS. For the past two decades the military had little need to focus on EMS as it has been fighting insurgencies with limited tech capabilities, but as it prepares for a possible war with high-tech nations like Russia or China, the services have increased their spectrum activities. The Air Force recently stood up its first EMS wing, and other services have established similar groups to focus on activities.
The military plans to rely even more heavily on spectrum communications systems to facilitate new strategies like Joint All Domain Command and Control (JADC2). That is the new framework where the military wants to be able to transmit data between all platforms in battle, creating a military internet-of-things. Transmitting data will require ample access to the spectrum, including the use of new tech like 5G that use lower frequencies to communicate more data.
“The success of JADC2 relies on our ability to have control of the electromagnetic spectrum,” Brig. Gen. AnnMarie Anthony, deputy director for operations for Joint Electromagnetic Spectrum Operations and Mobilization at Strategic Command, told reporters.
NIST revises flagship cyber resiliency guidance
The National Institute of Standards and Technology released the first-ever revision to its flagship cyber resiliency guidance with updated controls and a single threat taxonomy Thursday.
NIST updated Special Publication (SP) 800-160 Vol. 2 to align cyber resilience controls with SP 800-53 Rev. 5 security and privacy controls for agencies’ and industry’s IT systems, as well as map it to MITRE’s ATT&CK threat framework.
A product of the NIST Systems Security Engineering initiative, the guidance reflects the latest cyber resiliency implementation approaches for engineers to address known hacker tactics laid out in the ATT&CK framework.
“The goal of the NIST Systems Security Engineering initiative is to address security, safety and resiliency issues from the perspective of stakeholder requirements and protection needs, using established engineering processes to ensure that those requirements and needs are addressed across the entire system life cycle to develop more trustworthy systems,” reads the revised guidance.
Cyber resiliency engineers design and maintain systems that anticipate, withstand, recover from and adapt to stresses, attacks and compromises — thereby reducing risk to agencies.
The guidance provides a cyber resiliency engineering framework complete with a tailorable analysis agencies can use to determine whether a system of theirs, no matter how old, is at risk of being compromised by advanced persistent threats.
Technical appendices supplement that framework with:
- background and contextual information on cyber resiliency;
- detailed descriptions of goals, objectives, techniques, implementation approaches, and design principles;
- mutually beneficial controls in corresponding the SP 800-53; and
- language used to describe the effects of current threat mitigations.
CISA chief: Risk management agencies key to addressing sector-specific cyberthreats
Cybersecurity and Infrastructure Security Agency Director Jen Easterly has said her agency will work closely with federal risk management agencies to enhance cybersecurity practices within their own sectors such as energy and transportation.
Speaking Thursday at the Black Hat conference in Las Vegas, Easterly underscored the importance of using federal departments’ sector knowledge to help improve cybersecurity standards across every area of society in the U.S. To do so, CISA will step up its close work with departments responsible for managing risks in key areas of U.S. infrastructure, including the Department of Energy, the Environmental Protection Agency, and the Department of Transportation, she said.
“Critical infrastructure owners and operations, as well as state and local governments will play a similar role – bringing expertise to the discussion and a unique ability to drive cyber defense activities in their jurisdictions,” said Easterly.
CISA today announced its new Joint Cyber Defense Collaborative strategy for enhanced information sharing between industry, government and academia. It is hoped the scheme will allow federal agencies, lawmakers and the private sector to react faster and more effectively to ransomware attacks and other digital threats.
The agency has obtained buy-in for the new center from technology giants including CrowdStrike, Palo Alto, FireEye, Amazon Web Services, Google, Microsoft, AT&T, Verizon and Lumen, she said. Through JCDC, the member organizations will take part in two cyber sprints: one to combat ransomware, and the second to develop a planning framework for coordinating incidents that affect cloud providers.
In her keynote speech at the conference, Easterly also called on industry to support the federal government’s focus on rapidly growing the U.S.’s cybersecurity workforce, including through new relationships with universities and colleges and at the K-12 level.
The CISA director also issued a wider call for companies and technology experts to join CISA’s community of information sharing and to become evangelists for cybersecurity within their own organizations.
Logistics a prime target for the Marine Corps’ AI, commandant says
The commandant of the Marine Corps wants the service to focus on logistics as a prime use case for artificial intelligence, he said at the Navy League’s Sea-Air-Space conference.
Gen. David Berger, the Marine Corps’ top officer, said that logistics is both an area of extreme importance in a potential future war and one where AI can be helpful. He told the audience at Sea-Air-Space 2021 he wants industry to bring advanced data analytics tools to the USMC to assist in its modernization.
“Look at an area like logistics…if you assume you need to be capable of operating distributed then logistics [comes] to the foreground,” he said.
Military planners assume a potential war with Russia or China would involve logistics being targeted by adversaries to try and stop the resupplying of troops. Marines on the front lines can’t fight with out the ability to refuel vehicles or get more ammunition, Berger added. Using emerging tech to make more resilient resupplies and harden their infrastructure would go a long way in preparing for any potential war, he said.
“If you think we are going to be able to that in a human mind … that is not going to work,” he said of relying just on humans to manage complex supply chains in a battle.
He said that much of the tech to assist marine logisticians is available today in commercial industry, but not to the corps yet. He added that he wants younger officers to be the ones testing and evaluating new tools form industry since they grew up using tech.
“The tools are there now,” he said.
The Marine Corps is already testing fifth generation telecommunication tech in logistics centers to improve warehouse operations. But the commandant want the corps to expand the use of emerging technology in the delivery of supplies in potential battles, not just on bases.
The USMC also recently started building a new wargaming center that will use AI to test its self against potential adversaries.
NASA could take months to respond to $2.5B IT contract protest — Leidos CEO
NASA might not award its $2.5 billion, next-generation enterprise IT contract again for months following a bid protest Science Applications International Corp., said Leidos CEO Roger Krone, on the company’s earnings call Tuesday.
The agency is taking corrective action over the 10-year Advanced Enterprise Global IT Solutions (AEGIS) contract, which could take until the third or fourth quarter of 2021, Krone said.
SAIC held the NASA Integrated Communications Services (NICS) contract, AEGIS’s predecessor, prior to its split with Leidos and protested its now competitor’s win with the Government Accountability Office on July 6. The new contract adds zero-trust security, data center and cloud computing services and is integral to NASA’s Artemis program aiming to send astronauts to Mars, but now it’s in limbo.
“History has told us NASA takes corrective action, they make another award decision and then, of course, usually that is followed by another protest, and those tend to last kind of 100 days,” Krone said. “And so it may take them another three, four weeks to do their corrective action, and then you tack another three months on the back of that.”
NASA did not respond to a request for comment on the corrective action it’s taking by publication time.
The agency plans to use the contract to move to modern identity and access management through network automation. AEGIS also covers wide area networking, center local area networking, telecommunications, online collaboration tools, cable plant, emergency and early warning notification systems, telephony, and radio systems.
White House nominates Biniam Gebre as chief of federal procurement policy
The Biden administration has nominated Biniam Gebre as the administrator of the Office of Federal Procurement Policy within the Office of Management and Budget.
If confirmed by the Senate, he will rejoin government from Accenture, where he is a senior managing director and head of management consulting for Accenture Federal Services.
The OFPP sets overall policy direction for governmentwide procurement procedures and is focused on promoting efficiency and effectiveness. Previously, it was led by Michael Wooten, who was nominated by former President Donald Trump and confirmed to the role in 2019.
Gebre has previously also worked at consulting firms Mckinsey & Co. and Oliver Wyman. He served in the Obama administration at the Department of Housing and Urban Development, where his work focused on access to credit for low-income families, FHA’s financial health, and revamping public housing.
DOE uses firmware machine learning to bolster electric grid cybersecurity
The Department of Energy is integrating machine learning (ML) with a threat information-sharing tool it developed to find cybersecurity adversaries embedded in electric grid control systems.
DOE‘s Grid Modernization Laboratory Consortium (GMLC) consists of the Idaho, Argonne and Sandia national labs and the National Renewable Energy Laboratory — all working together on the Firmware Command and Control (FC2) project.
Firmware is often vulnerable, permanent software present in industrial control systems and operational technology (OT), and INL partnered with software company Forescout to ensure FC2’s cyber data analytics could detect firmware-centric vulnerabilities with ML.
“Embedded systems are black boxes with little insight on what subcomponents make up the code underneath, preventing protection and potentially rendering the system vulnerable,” said Rita Foster, infrastructure advisor at INL, in commentary. “Emerging machine-learning techniques enable the identification of ubiquitous libraries, which may contain known potential vulnerabilities.”
INL further developed the Structured Threat Intelligence Graph (STIG) for sharing of actionable threat information among grid utilities and OT vendors, who are notoriously stingy with such information. Rather than having threat analysts read thousands of lines of code, STIG visualizes relationships between attack patterns, compromise indicators and exploits and presents mitigations.
FC2, and GMLC more broadly, are helping utilities like Southern California Edison and Detroit Energies — which serve as large, expensive testbeds — augment their grid architectures. Meanwhile OT manufacturer partners like Siemens, Rockwell Automation, Eaton, GE, and Hitachi can develop better cyber protections.
“The need for an analysis tool to share security threat information and intelligence has escalated, and existing tools have proven to be inadequate,” Foster said.
A number of big-name OT manufacturers the government employs — Emerson, Honeywell, Mitsubishi Electric, Rockwell Automation, and Schneider Electric — do business with InterNiche, whose stack was revealed to have 14 newly discovered vulnerabilities Wednesday.
Forescout Research Labs and JFrog Security Research disclosed set, dubbed INFRA:HALT, as part of the former’s Project Memoria. The vulnerabilities allow for remote code execution, denial of service, information leaking, transmission control protocol spoofing, and Domain Name System cache poisoning, which could compromise OT and critical infrastructure like the electric grid.
Forescout’s report recommends utilities limit the network exposure of critical vulnerable devices through network segmentation, apply patches once vendors release them, and block or disable support for unused protocols like HTTP.
The 14 vulnerabilities were discovered using cutting-edge automate binary analysis for large-scale vulnerability finding.
“We believe that the cybersecurity community is at a turning point, and soon automated vulnerability discovery techniques will become more common, which should make finding very large-scale vulnerabilities, such as those affecting TCP/IP stacks, faster and more frequent,” reads the report. “All these vulnerabilities, however, will have to be disclosed, mapped to affected devices and mitigated.”