Air Force To Rewrite the Rules of the Internet
meridiangod writes "The Air Force is fed up with a seemingly endless barrage of attacks on its computer networks from stealthy adversaries whose motives and even locations are unclear. So now the service is looking to restore its advantage on the virtual battlefield by doing nothing less than the rewriting the 'laws of cyberspace.'" I'm sure that'll work out really well for them.
If they were smart, they would disconnect their computers from the public internet. People can't access hardware they can't access.
The government is not your daddy. Its purpose is not to raid middle-class neighbors' wallets and give it to you.
actually there is a very simple measure ISPs can take to prevent many attacks.
and that is to prevent their customers from spoofing the source IP in their IP packets.
If governments (starting with the US) would pressure(force by law) ISPs to do this, it can be done with out much technological difficulties.
This anti-spoofing measure can be implemented on many levels, so that even if a certain ISP does not co-operate other ISPs could prevent its customers from spoofing any IP which does not belong to the problematic ISP. This in itself helps protect against IP spoofing.
Without IP spoofing attackers are more easily identified and blocked.
I would have more faith in this endeavor if it were the NSA implementing it rather than the air force, although the air force is the second most likely agency/group to pull it off. From what I've seen and heard, the air force has a lot of technically skilled people in programming and hardware that would be able to pull this off.
VPN?
How bout a private network.
Which is what all secret and above classifications use.
Physically disconnected from the internet.
Physically inaccessible by the plebes.
Code auditing, memory wiping, classification-based job scheduling (a machine works only on secret defense or only on top secret or only on top secret nuclear, or etc. jobs at a time, never mixing), secure attention keys, custom hardware, physical security, surveillance, custom hardware, etc.
I'd say that, for the shit that matters, they've got a pretty good setup. But let's listen to the internet nerds who think they know everything. They'll tell us how to fix it.
The Air Force excels at just about everything they do. But for the past decade or two, their Achilles Heel has been computing technology because it moves faster than anything else they're used to.
The Air Force is a very old organization and although they can generally respond to most anything quickly, overall change tends to happen very very slowly. Not long after I enlisted in 1998, there were rumors that the uniform was going to change from the classic camouflage pattern to a kind of pixellated-marble look. Based on what recent photos I can find, they're still only about halfway through getting the new uniform out to everyone.
Also, I know for a fact we're still flying some planes with vacuum tubes in the autopilot computer even though upgrades for all airframes have been around since at least the 80's. Most of the technical manuals that I used to repair avionics were between 25-40 years old and still had technical errors in them. (We weren't able to make corrections to technical manuals any more than you'd be allowed to make pen-and-ink corrections to a federal law.)
Computer use only became common in most squadrons about 10 years ago and even then, they were not really used for the correct purposes. Some captain would get the bright idea that somebody should use a spreadsheet program instead of a paper form for some menial task, force everybody to use it, ignore the pleas from his subordinates that it tripled the effort required to perform the task, and then make up some elaborate report for his commander about how he just saved the Air Force $358,000.
While I was in the service, the Air Force never really caught on that you had to hire and train smart people who know about computers if you wanted to make the most of them. Some squadrons took young administrative airman fresh out of tech school and sat them down in front of the admin console and said, "All right, it's your job now to make sure this doesn't break." This is very uncharacteristic of the Air Force as you normally need at least several weeks of training before you can be trusted to mop the floor correctly. But when a commander has something that needs to be done and he doesn't know how to do it, it's not at all uncommon for him to assign someone to it while implying that they should be rather quiet about it.
Others units farmed out network administration to government contractors like Lockheed Martin which wasn't any better because most of their employees are old military retirees who thought they were going to get paid more as a civilian for doing the same thing they did in the military and ended up being wrong on both counts. (Got seven stripes and an MSCE? Then they're hiring!)
I guess this long-winded point it that it doesn't surprise me that high-level Air Force officers are saying, "Hey, who says we can't control this thing? We're the Air Force, after all." They're used to having fine-grained control over everything in their view and a high degree of security surrounding it.
In other words, the Air Force is still nowhere near where they need to be in terms of network security. The only encouraging part of this is that they finally realize it.
The AF can deal with someone in a nearby van, but not easily deal with someone anonymously using a free wifi connection in Europe that is bounced through 5 different servers. Even if they were able to completely track an attacker, how do they deal with multiple international jurisdictions?
Kindness is the language which the deaf can hear and the blind can see. - Mark Twain
The headline here says 'rewrite the rules of the internet', whereas the Wired article talks about 'rewriting the rules of cyberspace.' Subtle difference here.
The internet exists as it is--fundamentally an IP-based network connected in all the ways we know about, routing, addressing, etc.
The thing is, there's no reason that the Air Force (or anyone else) couldn't create their own, entirely incompatible version. Start with something that has guaranteed QoS, hard-wired source addressing, encryption at the equivalent of the transport layer, content-metadata in the packets (or equivalent to packets--it doesn't have to be a packet protocol at all), etc..
If you need to connect it to the internet, create a tunneling protocol, or a translating switch. Make it different. Make it incompatible. Make it rigid in its requirements. You CAN create a secure network, but not if it's based on the same technology that makes up the existing internet.
"People who do stupid things with hazardous materials often die." -- Jim Davidson on alt.folklore.urban
I am a Liberal.
I believe in the Constitution which contains the right to bear arms and seperation of church and state.
I believe in the United States of America, not Jesusland.
When the American Right stops trying to destroy the First Amendment, which incidentally comes before the Second Amendment, I will consider it.
Until then, you're welcome to relocate to a country more amiable to your theocratic oligarchy: I think Iran would suit you nicely.
If someone is passing you on the right, you are an asshole for driving in the wrong lane.
I couldn't have said it better.
Except I am neither liberal nor conservative. I am an American patriot and believe in the Declaration of Independence, the Constitution and the Bill of Rights. I also believe in capitalism and separation of church and state.
But, I will never again vote for any republican since they began their campaign to destroy the foundations of American democracy and switch the country to capitalistic dictatorship and the military industrial complex.
I have NO fear of Obama. And contrary to the neocon rhetoric, I have no doubt he will uphold the principals of democracy, unlike the last 2 douch bags he and Biden will be replacing shortly. I am also a gun owner and support the right for all Americans to form Militia to defend our land and freedoms.
Actually it's the neocon side of the isle that will seek to take our guns from us. Dictatorship is easier when the masses cannot shoot back.
Bush & Cheney have done more damage to the country and world than should have been allowed. I hold all republicans and their supporters guilty of high treason for this. Now they have 2 more whacked out fruit cakes, John McBush & Sarah McCheney they want in there to continue the destruction.
Isn't it obvious that McBush & McCheney, as people, are just as stupid as George W. Bush? Cheney is not stupid, he is just pure evil.
"Our enemies are innovative and resourceful, and so are we. They never stop thinking about new ways to harm our country and our people, and neither do we." George W. Bush
"Suppose you were an idiot...and suppose you were a member of Congress...but I repeat myself." Mark Twain