Showing posts with label cyber warfare. Show all posts
Showing posts with label cyber warfare. Show all posts

April 21, 2014

Cyber Warfare, Sigint "Maturity" in Some Asia-Pacific Countries


To an extent Chinese state media revealed some of the PLA's cyber warfare capabilities. Its unlikely the cyber warriors depicted above would regularly wear their helmets to work. China may have the 2nd to 4th largest cyber warfare capability in the world.
--
In pursuit of Australia by the Indian Ocean’s (a non-profit nor revenue, educational site’s) interest in  non-“Five Eyes” sigint-cyber issues the following is of interest.

On April 15, 2014, ASPI’s International Cyber Policy Centre released its inaugural Cyber Maturity in the Asia-Pacific Region 2014 report (PDF). To read the complete ASPI Report see https://www.aspi.org.au/publications/cyber-maturity-in-the-asia-pacific-region-2014/ASPI_cyber_maturity_2014.pdf  

This Report analyses the ‘cyber maturity’ of some countries in the Asia–Pacific region. Cyber indicators cover whole-of-government policy and legislative structures, military organisation, business and digital economic strength and levels of cyber social awareness. The research base underpinning each of these indicator groups has collated exclusively from information in the public domain and as such this report’s conclusions are based solely on open-source material.

Page 9 of the report explains: “Military uses of cyberspace, particularly national capabilities, are a sensitive topic for all regional states, and this area requires careful consideration before engagement is sought or agreed to. What is the military’s role in cyberspace, cyber policy and cybersecurity?

Under the section What is the military’s role in cyberspace, cyber policy  and cybersecurity? for each country area the Report’s descriptions are as follows:

(page 19) Cambodia
While it appears that the Cambodian Armed Forces have at least a superficial involvement with cyber policy and security, the extent and detail of that involvement remain unclear in open-source material. Regardless of the level of defence force involvement, it’s understood that Cambodia has a ‘very limited’ capability to defend against cyberattacks.
  
(page 22) China
Open-source reporting indicates that the PLA has several bureaus that actively conduct cyber-espionage operations. The PLA has also published several doctrinal information and development articles and monographs on information warfare and the role of cyber capabilities in military operations. China’s score is reduced by the apparent lack of coordination of these activities within the PLA.

[For a long Australia by the Indian Ocean article concerning China's sigint-cyber capabilities see New US Paper on China's Defence Sigint and Infosec Service (aka PLA GSD Third Department), July 16, 2012 at http://gentleseas.blogspot.com.au/2011/11/new-us-paper-on-chinas-defence-sigint.html ]

(page 22) India
The Indian military is aware of cyber threats and has established several organs to address them, including Defence CERT, the Army Cyber Security Establishment, the Defence Information Warfare Agency, the Cyber Security Laboratory and the Military College of Telecommunication Engineering. The establishment of a Cyber Command has also been announced, although it’s unclear whether this has been implemented. India’s score reflects the Indian Defence Force’s awareness of cyber threats, but also its slow implementation and a lack of stated policy direction for military cyber capabilities.

(page 28) Indonesia
The Indonesian Defence Minister has announced the planned establishment of the Cyber Defence Operations Centre to coordinate national cybersecurity efforts, including service-specific work by the Indonesian military on cybersecurity. The centre is also slated to draft a national doctrine on cybersecurity and conduct implementation strategies across defence and other departments. The creation of a dedicated ‘cyber army’ has also been proposed. The Defence Minister explained that the force would consist of elite membership embedded in the various branches of the Indonesian military to protect domestic networks against cyberattack. It’s unclear what progress has been made on this initiative. This announcement shows that there’s awareness of cyber threats in the Indonesian military, but the response is unclear.

(page 31) Japan
The recent Japanese National Security Strategy clearly outlines Japan’s interests in cyberspace, including means to address current limitations in Japanese cyber capabilities. The Japan Self-Defense Force (JSDF) Command, Control, Communications and Computer Systems Command is charged with the development of national cyberdefence capabilities. Under the command, the JSDF established a Cyber Defense Unit. The defence force is seen to have the necessary structures in place for cyber operations. The JSDF is working to improve its capability, especially through cooperation with the US, but a shortage of qualified personnel, an inability to respond to attacks, weak capabilities and problems in information sharing within the force remain areas of concern.

(page 34) Malaysia
Reports indicate that the Malaysian Armed Forces have begun to develop capabilities to protect national assets, including from cyber threats, and the Malaysian Defence Minister has publicly supported the development of an ASEAN master plan for Southeast Asia’s cybersecurity. Malaysia’s score reflects an awareness of cyber risks within the armed forces, but is reduced by the lack of clear policy direction for the development of cyber capabilities.

(page 37) Myanmar-Burma
The Defence Services Computer Directorate, under the Army Chief of Staff, encompasses network centric warfare, military-oriented cyber capabilities and electronic warfare. The Army’s military strategy has been expanded to include cyberwarfare as part of ‘people’s war under modern conditions’. Military Affairs Security (formerly the Directorate of Defense Services Intelligence) also possesses a cyber unit, but is more politically focused, carrying out monitoring both domestically and internationally. There are suggestions that the unit’s capability has grown exponentially in recent years with the assistance of other countries in the region. Russia and China have provided training to officers, and Singapore and China have both provided physical infrastructure support.

 (page 40) North Korea
The North Korean military is believed to have highly developed cyber capabilities and a well-organised and extensive education and research program to support future operations. Unit 121 is believed to be its primary offensive cyber force; personnel estimates range from 300 to  3,000 people. It’s believed that North Korea’s military has successfully infiltrated South Korean government and private sector systems, but  there’s little understanding of the military’s defensive capabilities.

(page 43) PNG
Despite recent attempts to bolster the strength of the PNG Defence Force, which has limited capabilities and resources, cyber issues have traditionally not been a priority for the country. The 2013 Defence White Paper made reference to establishing a defensive ‘Cyber Cell’ to protect a yet to be developed ‘Integrated ICT Network’, but outlined no timelines or implementation strategies. Clear evidence of military cyber policy and capacity in cyber operations remains limited.

(page 46) Philippines
The Armed Forces of the Philippines have created a Security Operation Center with a primarily defensive role, protecting military systems. However, a higher score wasn’t given because it’s unclear to what extent the centre has been implemented.

(page 49) Singapore
The Singaporean Armed Forces have established a Cyber Defence Operations Hub, aimed at protecting domestic military networks. This indicates that there’s an awareness of cyber risks and that work is underway to address them. Singapore’s score would be higher if there were a publicly available Singaporean Armed Forces strategy or policy on how the armed forces will engage with cyber threats.

(page 52) South Korea
South Korea has a capable military cyber capacity. The Defense Information Warfare Response Center of the Defense Security Command protects military networks, while the Cyber Command unit handles wider online security. South Korea has both defensive and offensive capabilities and in February 2014 announced its intention to develop offensive cyber capabilities specifically to target North Korea’s nuclear program. However, recent allegations of military cyber unit interference in national elections reduce the country’s score for this indicator. A new Cyber Defence Department, set to be launched in May 2014, aims to halt these domestic interference issues. The new command is to be established under the Joint Chiefs of Staff, with responsibility for all cyberwarfare missions. It will also include an oversight committee and a whistleblower program.

(page 55) Thailand
The Thai military currently has limited capability and authority on cyber issues, but its leadership has expressed an interest in developing legislation to legalise the operation of a cyber army. Thailand hosted the 2013 USPACOM Cyber Endeavour program, which focused on communications and IT interoperability."


Pete

February 16, 2012

Suter EW Jamming for Israel's Operation Orchid


An Israeli F-15I used for air-superiority and, in Operation Orchid, an airstrike in September 2007.
---


Update at 6 March 2017

Israeli "Suter" jet based and other jamming made  possible Operation Orchard, an Israeli airstrike on a suspected nuclear reactor  in the Deir ez-Zor region of Syria, which occurred just after midnight (local time) on September 6, 2007. The Israeli and U.S. governments imposed virtually total news blackouts immediately after the raid that held for seven months. This Operation played a part in the thinking behind combining EA-18G "Growler" aerial jamming future attacks by F-35s.

See Submarine Matters 6 March 2017 article on Australian Growler Jamming Aircraft to Work With Australian F-35s.

--------------------------------------------------------------------------------------------------------
Originally written by Pete in 2007. Several of these Israeli F-15Is ("Ra'am" in Hebrew or "Thunder") conducted the strike on the Syrian site. The F-15I's modifications from the standard F-15E include the Israeli Elisra SPS-2110 Integrated Electronic Warfare System (its likely Suter jamming package).

Western cyber warfare against other countries wins wars and the peace. In serious military operations tactical hacking, better known as jamming, is a highly respected art and science practiced by the US and its allies, including Israel.

Israel's curious airstrike on a Syrian "military building site" in early September 2007 has thrown the spotlight on a little known jamming technology known as "Suter".

 Wikipedia, reveals the following short description:


"Suter is a military computer program developed by BAE Systems that attacks computer networks and communications systems belonging to an enemy. Development of the program has been managed by Big Safari, a secret unit of the United States Air Force. It is specialised to interfere with the computers of integrated air defence systems.[1]

Three generations of Suter have been developed:

-  Suter 1 allows its operators to monitor what enemy radar operators can see. 

-  Suter 2 lets them take control of the enemy's networks and direct their sensors, and 

-  Suter 3, tested in summer 2006, enables the invasion of links to time-critical targets such as
   battlefield ballistic missile launchers or mobile surface-to-air missile launchers.

The program has been tested with aircraft such as the EC-130, RC-135, and F-16CJ.[1] It has been used in Iraq and Afghanistan since 2006.[2][3]

U.S. Air Force officials have speculated that a technology similar to Suter was used by the Israeli Air Force to thwart Syrian radars and sneak into their airspace undetected in Operation Orchard on September 6, 2006.

The evasion of air defence radar was otherwise unlikely because the F-15s and F-16s used by the IAF were not equipped with stealth technology.

Footnotes

1 a b David A. Fulghum, Michael A. Dornheim, and William B. Scott. Black Surprises. Aviation Week and Space Technology. Retrieved on 2007-10-05.

2
a b David A. Fulghum (October 3, 2007). Why Syria's Air Defenses Failed to Detect Israelis. Aviation Week and Space Technology. Retrieved on 2007-10-05.3 David A. Fulghum (January 14, 2007). Technology Will Be Key to Iraq Buildup. Aviation Week and Space Technology.4 John Leyden (October 4, 2007). Israel suspected of 'hacking' Syrian air defences. The Register. Retrieved on 2007-10-05."
-
Update - April 2009 - FA-18G Growler - Latest EW Jammer for US Navy and probably the Australian Air Force (RAAF)
-
From Aviation Week, April 13, 2009 comes:
-
NAS PATUXENT RIVER, Md. -- The brand-new EA-18G Growler has additional advances for airborne electronic attack (AEA) already on the way.
-
High on the list is the Next Generation Jammer (NGJ), which is to add even longer-range electronic attack, spoofing and advanced information and network attack options. With the new digital telecommunications used by opponents, U.S. planners have to be much more detailed about how electronic attack is conducted against networked, computer-controlled threats such as integrated air defenses.
-
Part of the new threat involves commercially available communications. GSM, Satphone, Bluetooth, 80211G and 80216 technologies are all built into one handset. It switches the user through all the options to find a usable route when being jammed. That type of connection technology is available and cheap.
-
New special-purpose electronic attack involves attacking more than external emissions. It goes after the digital instructions, called protocols, that run a network. It's electronic warfare against a computer network and not just a radar or radio signal. The goal is controlling communications more than preventing them. Nontraditional electronic attack involves producing long-lasting instead of temporary effects on enemy electronics.
-
Navy officials are a bit more circumspect and focused on incremental, near-term improvements.
"A much better jammer than the ALQ-99 [jamming pods that now equip both the Growler and Prowler] is part of the Growler roadmap," says Commander Frank Morley, program manager for the EA-18G. There are areas that could profit significantly from improvements "including the number and size of antennas and the small number of bands that can be attacked."
-
There also are issues with in-flight flexibility. Once the aircraft takes off, there is a limited, fixed configuration for electronic attack. NGJ is expected to offer more flexibility once airborne, and more band coverage that also can be adjusted in flight. ICAP III has already added information on board, networking capability and information from off-board sources to the older Prowler. NGJ is expected to allow even greater in-flight reactive capability.
-
"An EA-6B Prowler [in contrast] doesn't have a radar so it can defend itself only by running away," Morley says. "With the Growler's AESA radar, the crew can see what's going on. They know if there are fighters that have leaked through the front wall of the strike package. Situational awareness and the ability to defend themselves in an offensive manner is a first step that will make a difference. Now you don't have to put it in the back of the strike package with a section of fighters. [The Growler] may be able to hang around longer, planners may not have to put up as many assets to protect it and it may be able to make some of its own tactical decisions."
-
Comments

Suter appears to be an umbrella term for high level software and hardware jamming equipment in the USAF - also transferred or sold to allied air forces like Israel's. The Suter effort is part of a jamming network that doesn't exist in isolation.

The EA-18G "Growler" is a US Navy (and from 2017 Australian Air Force) platform that is a dedicated EW jamming aircraft - not just retrofitted like EW podded F-15s, F-16s or Tornados etc.

Pete