USA advanced weapons systems vulnerable to attack over Internet, weak cybersecurity

By: (plus.google.com) +David Herron; Date: October 11, 2018

Tags: Department of Defense » Cybersecurity » Weapons Systems

It's a brave new world. Consider a military warplane flying into battle, or a warship engaged in a sea battle, or a tank battle. In the past that military equipment was standalone, with communications limited to voices speaking over the radio. Now such equipment is connected in a digital communications network using the same technology as the Internet. A recent US Government Accountability Office report found these systems are vulnerable to attacks due to weak cybersecurity. One wonders if the result might be an airplane plummeting out of the sky, or a tank stopping in its tracks, or the guns on a warship going silent, during combat, because the adversary hacked into critical systems.

Over the past few years Internet-connected equipment has grown more common. The phrase "Internet of Things" (IoT) applies not just to consumer gizmos like WiFi-connected security cameras or baby monitors, but to all kinds of critical infrastructure. Some of that critical infrastructure is in the military.

Remember that the US Department of Defense funded the development of the technologies underlying the Internet. That project began in the 1960's and was tasked, in part, with developing a command and control system for the Military that could withstand a nuclear attack. Fast forward 50 years, and the US Military has a few decades of experience with using the Internet in the conduct of its business.

Historically the US Military had a parallel Internet called MILNET. When I got on the Internet in 1986 or thereabouts, "The Internet" had yet not been coined and instead you had ARPANET (the open public TCP/IP based Internet primarily for Universities) and MILNET (the semi-closed TCP/IP based Internet for the US Military). Access to MILNET was always semi-closed just as today every large corporation has a private TCP/IP based network that is closed to access by the general public. Therefore the military systems we're about to describe are not on the open public Internet, but they are still connected to a wide area TCP/IP-based communications system.

The (www.gao.gov) GAO Report is based on classified research, with the public report having various details obscured. We don't know the precise weapons systems etc, just that GAO researchers were able to hack into various weapons systems while they were in use without knowledge of the operators.

The communications architecture used by the US Department of Defense

As one might expect, US military equipment around the world partakes in a global communications system. The US Military has an extensive satellite network that not only serves as a communications backbone, but contains imaging and other sensors. Communications through this system is ubiquitous in the military. Because it is a TCP/IP-based digital network, it doesn't just carry voice communications but any kind of data service you can imagine.

The report says:

These connections help facilitate information exchanges that benefit weapon systems and their operators in many ways—such as command and control of the weapons, communications, and battlespace awareness. If attackers can access one of those systems, they may be able to reach any of the others through the connecting networks. Many officials we met with stated that including weapon systems on the same networks with less protected systems puts those weapon systems at risk. Furthermore, the networks themselves are vulnerable. DOT&E found that some networks were not survivable in a cyber-contested environment and the DSB reported in 2013 that “the adversary is in our networks.”2

A key observation is this:

For example, many weapon systems use industrial control systems to monitor and control equipment, and like computers, they include software. Many weapon systems use such systems to carry out essential functions. For example, a ship may use industrial control systems to control engines and fire suppression systems. According to NIST, industrial control systems were originally designed for use in trusted environments, so many did not incorporate security controls. Government and industry reports state that attacks on these systems are increasing. However, DOD officials said that program offices may not know which industrial control systems are embedded in their weapons or what the security implications of using them are.

I believe this is referring to the equipment used in SCADA systems - for example to implement factory automation, warehouse automation, or utility company automation. The typical communication protocols (DNP3, MODBUS, etc) were designed in the 1960's and 1970's and simply do not have a security model. The assumption was the control system would be on a network not connected to anything else, and therefore physical access would be required, and therefore preventing physical access is a sufficient level of security.

In the modern age all systems are being connected to each other and therefore those assumptions are ...er... quaint.

« Microsoft throws its patent library behind Linux, not quite open-sourcing its patents Revisiting the Trump server communications with Russia's Alpha Bank »
2016 Election 2018 Elections Acer C720 Ad block Air Filters Air Quality Air Quality Monitoring AkashaCMS Amazon Amazon Kindle Amazon Web Services America Amiga and Jon Pertwee Android Anti-Fascism AntiVirus Software Apple Apple Hardware History Apple iPhone Apple iPhone Hardware April 1st Arduino ARM Compilation Artificial Intelligence Astronomy Astrophotography Asynchronous Programming Authoritarianism Automated Social Posting AWS DynamoDB AWS Lambda Ayo.JS Bells Law Big Brother Big Data Big Finish Big Science Bitcoin Mining Black Holes Blade Runner Blockchain Blogger Blogging Books Botnets Cassette Tapes Cellphones China China Manufacturing Christopher Eccleston Chrome Chrome Apps Chromebook Chromebox ChromeOS CIA CitiCards Citizen Journalism Civil Liberties Climate Change Clinton Cluster Computing Command Line Tools Comment Systems Computer Accessories Computer Hardware Computer Repair Computers Conservatives Cross Compilation Crouton Cryptocurrency Curiosity Rover Currencies Cyber Security Cybermen Cybersecurity Daleks Darth Vader Data backup Data Formats Data Storage Database Database Backup Databases David Tenant DDoS Botnet Department of Defense Department of Justice Detect Adblocker Developers Editors Digital Nomad Digital Photography Diskless Booting Disqus DIY DIY Repair DNP3 Do it yourself Docker Docker MAMP Docker Swarm Doctor Who Doctor Who Paradox Doctor Who Review Drobo Drupal Drupal Themes DVD E-Books E-Readers Early Computers eGPU Election Hacks Electric Bicycles Electric Vehicles Electron Eliminating Jobs for Human Emdebian Encabulators Energy Efficiency Enterprise Node EPUB ESP8266 Ethical Curation Eurovision Event Driven Asynchronous Express Face Recognition Facebook Fake News Fedora VirtualBox Fifth Doctor File transfer without iTunes FireFly Flash Flickr Fraud Freedom of Speech Front-end Development G Suite Gallifrey Gig Economy git Github GitKraken Gitlab GMAIL Google Google Chrome Google Gnome Google+ Government Spying Great Britain Green Transportation Hate Speech Heat Loss Hibernate High Technology Hoax Science Home Automation HTTP Security HTTPS Human ID I2C Protocol Image Analysis Image Conversion Image Processing ImageMagick In-memory Computing InfluxDB Infrared Thermometers Insulation Internet Internet Advertising Internet Law Internet of Things Internet Policy Internet Privacy iOS iOS Devices iPad iPhone iPhone hacking Iron Man iShowU Audio Capture iTunes Janet Fielding Java JavaFX JavaScript JavaScript Injection JDBC John Simms Journalism Joyent Kaspersky Labs Kext Kindle Kindle Marketplace Large Hadron Collider Lets Encrypt LibreOffice Linux Linux Hints Linux Single Board Computers Logging Mac Mini Mac OS Mac OS X MacBook Pro Machine Learning Machine Readable ID Macintosh macOS macOS High Sierra macOS Kext MacOS X setup Make Money Online Make Money with Gigs March For Our Lives MariaDB Mars Mass Violence Matt Lucas MEADS Anti-Missile Mercurial MERN Stack Michele Gomez Micro Apartments Microsoft Military AI Military Hardware Minification Minimized CSS Minimized HTML Minimized JavaScript Missy Mobile Applications Mobile Computers MODBUS Mondas Monetary System MongoDB Mongoose Monty Python MQTT Music Player Music Streaming MySQL NanoPi Nardole NASA Net Neutrality Network Attached Storage Node Web Development Node.js Node.js Database Node.js Performance Node.js Testing Node.JS Web Development Node.x North Korea npm NVIDIA NY Times Online advertising Online Community Online Fraud Online Journalism Online Photography Online Video Open Media Vault Open Source Open Source and Patents Open Source Governance Open Source Licenses Open Source Software OpenAPI OpenJDK OpenVPN Palmtop PDA Patrick Troughton PayPal Paywalls Personal Flight Peter Capaldi Peter Davison Phishing Photography PHP Plex Plex Media Server Political Protest Politics Postal Service Power Control President Trump Privacy Private E-mail server Production use Public Violence Raspberry Pi Raspberry Pi 3 Raspberry Pi Zero ReactJS Recaptcha Recycling Refurbished Computers Remote Desktop Removable Storage Republicans Retro Computing Retro-Technology Reviews RFID Rich Internet Applications Right to Repair River Song Robotics Robots Rocket Ships RSS News Readers rsync Russia Russia Troll Factory Russian Hacking Rust SCADA Scheme Science Fiction SD Cards Search Engine Ranking Season 1 Season 10 Season 11 Security Security Cameras Server-side JavaScript Serverless Framework Servers Shell Scripts Silence Simsimi Skype SmugMug Social Media Social Media Networks Social Media Warfare Social Network Management Social Networks Software Development Software Patents Space Flight Space Ship Reuse Space Ships SpaceX Spear Phishing Spring Spring Boot Spy Satellites SQLite3 SSD Drives SSD upgrade SSH SSH Key SSL Stand For Truth Strange Parts Swagger Synchronizing Files Tegan Jovanka Telescopes Terrorism The Cybermen The Daleks The Master Time-Series Database Tom Baker Torchwood Total Information Awareness Trump Trump Administration Trump Campaign Twitter Ubuntu Udemy UDOO US Department of Defense Video editing Virtual Private Networks VirtualBox VLC VNC VOIP Vue.js Walmart Weapons Systems Web Applications Web Developer Resources Web Development Web Development Tools Web Marketing Webpack Website Advertising Weeping Angels WhatsApp William Hartnell Window Insulation Windows Windows Alternatives Wordpress World Wide Web Yahoo YouTube YouTube Monetization