DOD tests new machine learning capabilities for JADC2

The Department of Defense recently concluded a round of tests of new machine learning technology that aims to increase data sharing between combatant commands.

The North American Aerospace Defense Command and Northern Command’s Global Information Dominance Experiment 3 (GIDE 3) brought 11 combatant commands, the Joint Artificial Intelligence Center (JAIC) and other tech leaders together July 8-15 at Peterson Air Force Base in Colorado to test the use AI in warfare.

The GIDE experiments aim to advance tech that will enable the DOD’s new concept of how it will fight in the future, where data from across military domains will be shared between machines and AI will assist commanders in their decision-making. The idea is captured in the department’s larger strategy of Joint All Domain Command and Control (JADC2), which is a guiding framework for many experiments like GIDE 3 and others across the services.

The GIDE 3 experiment showcased how the software tools designed for cross-combatant command collaboration, assessment, and decision-making can be used to enable more effective global logistics coordination, intelligence sharing and operations planning,” said Gen. Glen VanHerck, NORAD and NORTHCOM commander.

The third phase of the GIDE experiments focused on testing the JAIC’s new Matchmaker tool, designed to create defensive options by reading real-time data from the field and analysis assessments from analysts, according to a release from the Air Force. The tool is meant to provide a core capability within JADC2 of linking and analyzing data from across domains, replacing the current process of human analysts talking over radios with data often siloed between domains.

“By integrating more information from a global network of sensors and sources, using the power of AI and machine-learning techniques to identify the important trends within the data, and making both current and predictive information available to commanders, NORAD and USNORTHCOM are giving leaders around the globe more time to make decisions and choose the best options available, whether in competition, crisis or conflict,” VanHerck said. 

The first two GIDE experiments focused on how to coordinate early warning alerts between a handful of commands using AI and how to collaborate on logistics during war. The third test in mid-July was the final GIDE experiments hosted by Northern Command and NORAD, which has been an early adopter of AI and JADC2-related tech.

The two homeland defense commands also run the Pathfinder program, which uses AI to detect air threats like incoming missiles or even small drones.

TTS awards 4 contracts for governmentwide agile services

The General Services Administration’s Technology Transformation Services awarded blanket purchase agreements (BPAs) to four tech companies to streamline governmentwide procurement of agile development and IT support services.

Together the BPAs comprise the TTS Organization’s Transformation Agile Lifecycle (TOTAL) and allow TTS to issue task orders on behalf of other agencies.

TOTAL is part of a federal push to accelerate digital transformation through shared services at the same time the Technology Modernization Fund prioritizes investments in cybersecurity and IT modernization.

“Outside GSA, TTS will be able to rapidly implement contracts for Agile Delivery at the speed of need,” said Greg Godbout, director of digital services and business development at Fearless, which won one of the BPAs on July 15. “Inside GSA, TTS will use the same advantages to support and scale internal shared services like Login.gov.”

Fearless’ BPA alone is worth up to $120 million over the next five years and covers TOTAL’s Functional Area 3: lifecycle agile development focused on applications, data science, product delivery and quality assurance.

The other BPAs went to minority- and women-owned firms SemanticBits, Bixal and Amivero across three other functional areas:

  • Lifecycle agile development for infrastructure, security, system architecture, DevSecOps, and security assessments;
  • Lifecycle agile development for design, user research, user interface/user experience, information architecture, content strategy, accessibility, and prototyping and modeling; and
  • IT program support for customer account management, outreach, acquisitions, finance, operations, and project and program management.

Congressional report calls for DOD tech to be built at home

A congressional task force is urging the Department of Defense to better work with its partners to bring tech supply chains back within the U.S. and its allied nations.

The report from the Defense Critical Supply Chain Task Force points to protecting DOD’s supply chains as a critical but overlooked defense objective. The task force’s leaders Reps. Elissa Slotkin, D-Mich., and Mike Gallagher, R-Wisc., said the supply chain disruption caused by the coronavirus pandemic was a motivator behind the investigation into how DOD buys its critical supplies, including tech, during war.

“Last year, we all saw how the shortages of PPE cost American lives. We struggled to get things like masks and gloves for our healthcare workers, and it was obvious that our supply chains had failed,” Slotkin said.

For tech, like the microchips that power everything from computers to weapon systems, many of the base materials come from abroad. Some, like rare earth elements, come mostly from China — a situation that could snarl supply chains for DOD if it ends up in a war with the country.

“Throughout the pandemic, U.S. adversaries like China weaponized supply chain vulnerabilities in a way that threatened Americans’ health and security,” Gallagher said. “Our Defense Critical Supply Chain faces similar weaknesses that, if exploited, would impair our ability to compete with our adversaries and respond to crises. This problem will not age well.”

One of the key recommendations for how to work with allies to reshore critical tech capability supply chains is to use the National Technology and Industrial Base (NTIB) Council and create an international council. The councils should be used as forum to coordinate industrial policy among allies, the report recommends.

“The NTIB is an underutilized forum and should be leveraged to shape policy and partnerships with allies,” the report states. “To reduce reliance on adversaries and expand partnerships, the NTIB will need to help shape global policy.”

Shield AI buys company whose AI beat a fighter pilot in a dogfight

The company that built an artificial intelligence system advanced enough to beat a fighter pilot in a simulated dogfight has been acquired by defense tech startup Shield AI.

Heron Systems is a small team of researchers based around the Beltway that develops multi-agent deep reinforcement learning AI for defense applications. Shield focuses on “AI for maneuver,” selling AI-enabled drones and robots aimed at helping to keep troops out of harm’s way.

Purchasing Heron Systems will expand Shield’s business portfolio into the cockpits of the military’s airplanes.

“Truly special AI companies are incredibly rare assets in the defense market,” Shield AI co-founder and CEO Ryan Tseng said in a statement. “Heron has developed the most advanced AI-pilot for fighter aircraft in the United States.”

Shield did not disclose how much it paid for Heron, but the company will continue to operate as a wholly owned subsidiary of Shield.

“Shield AI enables us the opportunity and scale to accelerate the integration of our AI-pilot on a next generation fighter and UAS,” Brett Darcey, Heron Systems general manager, said in a statement. “What stood out about Shield AI for us – is that they’re really the only ones who have an operational AI pilot that can operate on the edge without GPS or comms, and this has been proven on combat operations.”

Heron put its AI to the test in the Defense Advanced Research Project Agency’s  AlphaDogfight, which pitted a trained F-16 pilot against several companies’ AI systems in a simulated dogfight. The event was set up as a contest, with Heron coming out on top beating the human pilot 5-0. While some were impressed by the results, others saw the tests as “AI theater,” showing off interesting technical achievements that won’t necessarily translate to real world applications.

NIST selects 18 tech companies for zero-trust demos

The National Institute of Standards and Technology selected 18 tech companies to demonstrate zero-trust security architectures as it drafts guidance for agencies and industry.

Companies will work with NIST‘s National Cybersecurity Center of Excellence to design and deploy architectures in accordance with Special Publication (SP) 800-207, as part of the Zero-Trust Architecture Project.

The project comes after the Biden administration issued a cybersecurity executive order in May requiring agencies to create plans to implement zero-trust security within 60 days.

“Implementing a zero-trust architecture has become a federal cybersecurity mandate and a business imperative,” said Natalia Martin, acting director of the NCCoE, in an announcement. “We are excited to work with industry demonstrating various approaches to implementing a zero-trust architecture using a diverse mix of vendor products and capabilities and share ‘how to’ guidance and lessons learned from the experience.”

The NCCoE plans to publish a NIST Cybersecurity Practice Guide in the SP 1800 series detailing the steps needed to implement reference designs at the end of the project.

Participating companies include: Amazon Web Services, Appgate, Cisco Systems, F5 Networks, FireEye, Forescout Technologies, IBM, McAfee, Microsoft, MobileIron, Okta, Palo Alto Networks, PC Matic, Radiant Logic, SailPoint Technologies, Symantec, Tenable, and Zscaler.

The selected vendors responded to a Federal Register notice to submit capabilities that aligned with the project’s desired solution characteristics. Each one was extended a cooperative research and development agreement, enabling them to participate in the consortium.

“We are all committed to collaborating and demonstrating different, practical approaches to implement a zero-trust architecture,” said Stephen Kovac, vice president of global government at Zscaler, in a statement. “As we know, no one solution fits every situation.”

VA won’t deploy EHR to more sites until 2022

The Department of Veterans Affairs won’t continue rolling out its new electronic health records (EHR) program to any new sites until 2022, a top VA official told Congress Wednesday.

Dr. Carolyn Clancy, deputy undersecretary for health at the VA, said a new schedule to deploy the system across the country won’t be ready until the end of the year. This comes after the VA’s recent strategic review of the program led the department to restructure the EHR’s rollout schedule to be based on which medical centers have the infrastructure ready.

The program was initially paused for the review in March, resulting in eight recommendations to improve the $16 billion, 10-year program. The cloud-based system from Cerner is designed to be interoperable with the Department of Defense’s new EHR platform and replace the legacy Veterans Health Information System Technology Architecture (VistA).

“We will not be scheduling any deployments in the next six months; the secretary is optimistic that end of this calendar year he will be able to discern a new deployment schedule,” Clancy told the House Veterans Affairs Committee.

That news was received well by some committee members who remain skeptical about the new system and want to see more proof that it can improve health outcomes.

“It would be irresponsible to deploy the Cerner system … until the bugs are worked out,” ranking member Rep. Mike Bost, R-Ill., said.

The VA is also re-working the cost estimates for the program after its inspector general found the initial estimates were as much as $2.6 billion short of what could be needed.

“We should have been far more transparent,” Clancy said about the initial cost estimate for the program.

Following the hearing, full committee Chair Rep. Mark Takano, D-Calif., and Bost announced a new bill that would require the VA report on the EHR’s costs every three months. Names the VA Electronic Health Record Transparency Act of 2021, the bill would require the reports to include all expenses in the program include infrastructure upgrade costs, which had been counted separately.

“Given this month’s Inspector General reports and what we heard at today’s hearing, it’s clear we need a full accounting of all costs associated with VA’s EHRM project,” Takano said in a statement. “I’ve heard some concerning information about the state of the EHRM project, and I’m worried that the total cost estimate was vastly underestimated by the previous administration.”

NASA won’t rush Mars mission over U.S. ‘space race’ with China

NASA won’t rush its planned mission to Mars in the late 2030s and risk human life, despite being in a “space race” with China, said Administrator Bill Nelson on Wednesday.

The agency awarded a now-contested contract to SpaceX in February to launch the initial components of the Gateway lunar outpost, where the rocket and supplies for the Mars mission will eventually be assembled.

NASA expects a decision from the Government Accountability Office in the next few weeks and to launch by the end of 2021, but China announced an ambitious plan to send astronauts to Mars by 2033 in June.

“The Chinese space program is also a military space program,” Nelson said, during a live interview with the Washington Post. “They are very aggressive and very good, and a lot of that success has come in the last few years.”

China was the second country to land a rover on Mars after the U.S. with plans to return samples from the planet to Earth “probably within the same timeframe,” Nelson said.

But the Pentagon has also reported Chinese development of anti-satellite weapons that threaten global communications and space exploration.

“The Chinese are very intolerant of any examination of their space program,” Nelson said. “They are very inflexible; they are not very transparent.”

Nelson contrasted that with Russia, which began cooperating with the U.S. on space missions during the Cold War and launched another “major component” of the International Space Station (ISS) from the Baikonur Cosmodrome in Kazakhstan on Wednesday.

NASA’s administrator said he’d support cooperation with China on space missions if they’d “open up,” but in the meantime, one of their satellites exploded in low-Earth orbit near the ISS and one of their rockets landed in the Indian Ocean without a controlled reentry.

“Space is the high ground and the important ground in trying to protect the interests of our country and the free world,” Nelson said.

Nelson said he also supported expanding public-private partnerships in space exploration. Commercial 3D printing of rockets will reduce the cost of space travel and make it more “accessible,” while SpaceX’s fixed-price contract to deliver cargo and crew to the ISS is enabling commercial space efforts, he said.

NASA will require that any space tourists going to the ISS endure the same training and medical and psychological training as its own astronauts so as not to interfere with their research, Nelson said.

“Yes there may be Bezos ideas of colonies out in space; yes there may be colonizing of Mars,” he said. “But we need to have the vision to get there and develop the technologies in order to sustain human life.”

NASA will “aggressively” look for evidence of life in samples returned from Mars and Venus, and a new space telescope will launch at the end of 2021 designed to look at the source of light 13.35 billion years ago, shortly after the Big Bang, in a search for other planets that might support life, Nelson said.

Closer to home NASA deployed a “phalanx” of satellites measuring climate effects, he said.

“In the next 10 years we’re going to put up five great observatories, and we’re going to look at oceans and land and ice and the atmosphere,” Nelson said. “And we’re going to compile a 3D composite of the minute changes that are occurring so that we can better project what we’ve got to do in order to save our planet by saving our climate.”

Air Force inks new ABMS concept document

The Air Force signed a new document solidifying the foundational concepts that underpin one of its highest priority technology modernization programs, the Advanced Battle Management System (ABMS).

The “JADC2 Supporting Concept” document will guide changes the Air Force will make in how it is connecting data from sensors across a battlefield through the Advanced Battle Management System.  ABMS is essentially the Air Force’s internet of things for war, made within the broader framework of Joint All-Domain Command and Control (JADC2) that aims to get the entire military to link its sensors and platforms across all domains of battle.

“[W]e just got the JADC2 Supporting Concept signed. The document guides the USAF concept-driven, threat-informed JADC2 capability development to include doctrine, training materiel and personnel,” an Air Force spokesperson told FedScoop in response to inquiries about the document.

The document was created by the cross-functional team working on ABMS led by Brig. Gen. Jeffery Valenzia. 

The ABMS family of technologies aims to improve the data linkage and overall connectivity of weapons systems and platforms the Air Force uses. Currently, the Air Force uses a construct and technology that rely on both legacy systems and processes. For example, in surveilling targets, an airman often has to watch a drone feed and manually count how many people appear on screen, instead of the drone feeding its data directly to a computer-vision algorithm and that data then sent to fighter jets with payloads, as is the intent with ABMS and JADC2.

The Supporting Concept document is more foundational work that is specific to the Air Force, though it has JADC2 in its name, the spokesperson said.

Other services have their own programs that follow the JADC2 framework recently spelled out in a new strategy document approved by Defense Secretary Lloyd Austin.  The Army has Project Convergence and the Navy runs Project Overmatch as their contributions to JADC2. Each of the three follows the general framework of JADC2 and works with a JADC2 cross-functional team on the Joint Staff to coordinate their efforts.

Agency reuse of FedRAMP-approved cloud products climbs with automation

Agency reuse of cloud products authorized by the Federal Risk and Authorization Management Program (FedRAMP) continues to increase, with the program management office (PMO) automating parts of the process in fiscal 2021.

Reuse of security authorization packages is up 85% compared to pre-pandemic levels, and agency demand for cloud products grew 60% in the first half of fiscal 2021 compared to the first half of fiscal 2020.

Increases in reuse and demand coincide with the FedRAMP PMO’s work with the National Institute of Standards and Technology to standardize authorization packages and automate their review with the Open Security Controls Assessment Language (OSCAL).

“NIST recently released OSCAL Version 1, which is the first major release of OSCAL and provides a stable OSCAL platform for wide-scale implementation,” said Brian Conrad, acting FedRAMP director and program manager for cybersecurity at the General Services Administration, during a Carahsoft virtual event Tuesday. “And this release also marks an important milestone for the OSCAL project and for early adopters and implementers of security automation with OSCAL.”

Machine-readable authorization packages will allow cloud service providers (CSPs) to create system security plans faster and validate much of the content before submitting it for government review. Meanwhile, agencies can expedite their reviews, and third-party assessment organizations (3PAOs) can automate planning, execution and reporting of their activities.

The FedRAMP PMO is developing conversion tools that will reduce review times further and hopefully increase OSCAL adoption.

“We’re really excited about the next step in that we’re going to pilot some of these validation tools with users,” Conrad said. “We have cloud service providers and 3PAOs and agencies, for that matter, stepping up — willing to take part in those pilot programs.”

At the same time, the FedRAMP PMO has teamed with the Department of Homeland Security, Cybersecurity and Infrastructure Security Agency, and .govCAR to score security controls based on how well they detect and respond to real-world threats. The threat-based authorization approach speeds up the process further by using fewer resources and focusing control implementations on the current threat landscape, Conrad said.

The FedRAMP PMO is currently considering new baselines using the NIST Special Publication 800-53 Rev. 5 security and privacy controls.

Another area the FedRAMP PMO wants to automate is continuous monitoring, having developed a web services application programming interface (API) specification allowing CSPs already using OSCAL to push and pull data to and from a secure repository — eliminating manual processes.

President Biden‘s cybersecurity executive order issued in May has the FedRAMP PMO reevaluating its business processes and automating routine messages to CSPs at every stage of authorization.

The office also recently released guidance on Incident Communications Procedures; Vulnerability Scanning Requirements for Containers; and updated low, moderate and high baselines for System Services & Acquisition-4 (SA-4) and Incident Response-3 (IR-3) controls.

More guidance is on the way.

“FedRAMP is releasing an Authorization Boundary Guidance for public comment in July,” Conrad said. “This one is really critical; we get a lot of questions from stakeholders on this.”

Rep. Gerry Connolly, D-Va., provided an update Tuesday on his FedRAMP Authorization Act, which would codify the program. Introduced for the third time in a year in January, the bill was the first to pass the House in the 117th Congress and passed unanimously.

The legislation would reduce duplication of security assessments by establishing a “presumption of adequacy” if an agency already authorized a particular cloud product, require agencies to prioritize reusing products, establish a Federal Secure Cloud Advisory Committee, and fund the program at $20 million annually.

“While this has been a long journey, I’m happy to say that, with new leadership in the Senate, we’re working in lockstep with our colleagues over there to try and finally get this bill for a markup in the Senate or attached to this year’s Defense Authorization Act,” Connolly said.

Coast Guard ‘lacks control’ over telework data, GAO finds

The U.S. Coast Guard‘s plans to continue using telework could be derailed by weak data verification of how many of its members are still working remotely, the Government Accountability Office found in a new report. 

The maritime service might not be conducting its needed weekly audits of the surveys it collects on who is teleworking, potentially clouding the picture of how many people need tech to support their connectivity outside of Coast Guard offices. Working with inaccurate data could lead to poor planning for future technical requirements and budgeting to support the Coast Guard’s IT, the report found.

“Coast Guard officials could not provide assurance or evidence that weekly audits purposefully designed to verify the accuracy and completeness of these data were being conducted,” the report states. “Without such assurance, the Coast Guard may be relying on inaccurate and incomplete information when making decisions that rely on these data, such as for assessing its operational readiness.”

The Coast Guard, a part of the Department of Homeland Security, also could not confirm how many telework agreements it had signed with employees and guardsmen, further obfuscating the telework picture. The GAO recommended the service remedy the situation by implementing plans to ensure everyone working remotely has a teleworking agreement, auditing telework survey data and put in place additional controls to ensure supervisors review telework agreements at least annually.

“GAO found that the Coast Guard lacks controls over telework documentation and its personnel data are not reliable,” the report stated.

Coast Guard officials want many employees and guardsmen to continue to telework for the foreseeable future, a prospect the GAO warns requires careful analysis of its telework data to ensure it has enough back-end tech to support.

Interviews the GAO conducted also showed that at the beginning of the pandemic, the service lacked bandwidth and laptops to support its staff working from home. Money from the CARES Act provided the Coast Guard with the needed equipment, but how it is being used and in what capacity is not apparent due to the lack of data audits on its telework surveys.

“During the pandemic, the Coast Guard has faced challenges in balancing the need to safeguard its personnel with its responsibility to continue missions and operations,” according to the report.

The Coast Guard has been on a “tech revolution” since 2020 to modernize its aging systems and migrate its tech to the cloud. Commandant Karl Schultz said the service needed to dig itself out of the ’90s to improve connectivity on both its cutters and offices ashore. During that time, the service has added Wi-Fi to some cutters and replaced outdated desktops with “two-in-one tablets.”