Defense Attacks Essay

The Department of Defense (DoD) manages one of the largest and most targeted networks, up to 250,000 attacks per day. (Daniel Gouré, 2015) As a member of this organization, I see the low level applications set forth by the strategic minds of the DoD Chief Information Officer and Secretary of Defense. As the organization that laid the foundation for the internet, the DoD has evolved over the years reacting to the vulnerabilities and threats to their vast information systems. Past breaches have illustrated how vulnerable the networks are, and we can look at history to see the development of the defense networks and security.
As civilian organizations adopted this handbook, it was evident that heavy emphasis on preventing the disclosure of classified data dominates the security requirements, and there is a lack of business-minded requirements such as availability and integrity. This is due to the fact that the document was organic to defense and government organizations. The document has a strict guide of security demands, but does not go further to link them to specific security features. This model has been revisited and refined to the current governing document “DoD 8500.01,” for the security of the information systems used by the Department of Defense. (Claudio Agostino Ardagna, 2008)
One of the historical cyber events that affected the modern cyber strategy was the Morris worm. The worm was released November 1988, and was intended to gauge the size of the internet; however, it replicated itself and subsequently turned into one of the first denial of service attacks. The creator, a Cornell University graduate student, became the first prosecuted under the Federal Computer Fraud and Abuse Act of 1986. (Markoff, 1990) The reaction from the government was the creation of a computer emergency response team coordination center (CERT-CC) by the Defense Advanced Research Projects Agency (DARPA). The mission of the CERT-CC is to work with computer and software developers and government agencies to improve security and improve incident response. This was a major event setting the precedence for future cyber incidents, where the government turns to experts to analyze and respond. The CERT-CC falls under the Software Engineering Institute of Carnegie Mellon University, and has grown to over 150 cybersecurity professionals. Today it works closely with the Department of Homeland Security. (Kelty, 2011; CERT Division, n.d.)
In 2015, The DoD published the “The Department of Defense Cyber Strategy”, defining the strategic level goals for the organization going forward. The document defines three main goals for cyberspace: to defend the networks and information, to protect U.S. interests against cyber attacks, and to be prepared to conduct supporting or offensive operations. (Department of Defense, 2015) What makes the Department of Defense unique is that they need to be capable of offensive operations both unilaterally, and in support of other units across the DoD, Department of State, and Intelligence Communities. Building both offense and defense capabilities at the same time will prove challenging, as the recent breaches have exposed. (Department of Defense, 2015)
