The Air Force wants to improve its cyber defense by going on offense.

Tired of waiting to respond until hackers breach its systems, the service has put out two new contract requests that would allow the Air Force to pro-actively defend itself.

Officials hope the improvements will actively delay and deny hackers, or provide them with false information to make them believe they actually have breached cybersecurity defenses.

"The DoD needs new tools and technologies to reverse the current asymmetry that favors DoD cyber adversaries," said a statement from the Pentagon in one of the contract announcements.

The military is hoping to force cyber opponents to "spend more, cope with greater levels of complexity and uncertainty, and accept greater risks of exposure and detection due to the significantly increased requirements for reconnaissance and intelligence collection on DoD networks."

Experts have long warned that the government is lagging behind when it comes to cybersecurity. But the issue made national headlines this month when the Office of Personnel Management announced that millions of federal employees' personal records had been hacked.

Fingers have pointed towards the Chinese government. OPM officials said they still aren't certain how many current and former employees were affected, but estimates have ranged from four million to 32 million people.

In the meantime, the Air Force is trying to bolster its own cyber defenses, including putting out calls for technology that could deceive hackers trying to reach sensitive information.

"Military forces have historically used techniques such as camouflage, feints, chaff, jammers, fake equipment, false messages or traffic to alter an enemy's perception of reality," a statement from the Air Force said in the contract. "Modern day military planners need a capability that goes beyond the current state-of-the-art in cyber deception."

The Pentagon hopes to deploy technology that could be used to "provide false information, confuse, delay, or otherwise impede cyber attackers."

But the devil's in the details, and the DoD has put a lot of caveats on the new technology. First off, any false information supplied to cyber attackers has to appear real so that, obviously, they don't know they're being deceived. Secondly, the new cyber protections should have a minimal impact on current digital operations – and also the Pentagon's budget. And finally, officials want to make sure there's security in place so that the new defense capabilities can't themselves be hacked and turned against the U.S.

"The security of such mechanisms is also paramount, so that their power is not co-opted by attackers against us for their own purposes," the contract stated.

The Air Force hopes to have a prototype system ready within two years for possible integration into existing military networks, and is offering $49 million for the contract.

A second $49 million contract is seeking to improve general cybersecurity protection, with the Air Force hoping it can get out in front of any potential threats.

"Many cyber solutions currently focus on detecting attacks after they occur and then attempt to apply security mechanisms to existing hardware and software," the contract said. "This type of solution is inefficient and keeps systems and networks in a constant state of 'react.' A more proactive approach is preventing and avoiding rather than detecting after the fact."

The Air Force also noted that they would like to improve autonomy in the cybersecurity system, and try to remove some of the work-load from personnel.

"Precluding areas where human-in-the-loop decision-making is required by statute or policy, this area will seek to…implement machine-learning and other artificial intelligence technologies," the contract said.

But it isn't simply desktop computers that need to be protected. The Air Force said there are a number of "mobile" systems that will need cybersecurity safeguards as well, and specifically named unmanned aerial vehicles as one such area of concern.

Share:
In Other News
Load More