Back to news

September 16, 2020 | International, Naval, Other Defence

Fewer Threats, More Bandwidth: DISA Awards $199M For Cloud Browsing

Leaving the browser and its history in a virtual environment spread across any number of servers makes it harder for adversaries to target the military's actual computers or tablets.

ALBUQUERQUE: The Defense Information Systems Agency awarded $198.9 million for a Cloud Based Internet Isolation contract to Menlo Security and By Light, the agency announced today. DISA hopes Menlo Security's tech can, by keeping downloads in the cloud, reduce harmful downloads across the entire Pentagon workforce. By keeping browsing inside the cloud, the program will save on bandwidth, and protect against the department's 3.5 million users accidentally downloading malware.

It is a kind of “air-gapping,” the style of computer security that keeps networks safe by making sure that computers are not physically connected at all times. Leaving the browser, and all its contained history, in a virtual environment in any of a number of servers makes it harder for adversaries, be they criminals, nonstate actors, or nations, to target the actual computers or tablets used by the military.

Internet browsing is mostly downloading files directly to the end-user's computer or mobile device. What the Cloud Based Internet Isolation (CBII) does is make sure that all that downloading happens, not on the end user's computer, but instead in a remotely secured server.

“The remote worker will perform the task of going to their net or an Internet based application, that fetch and execute,” Menlo Security VP Mike Fraga says. What is different is that, instead of downloading directly onto the user's device, “getting the information and actually queuing is done in a disposable container in Menlo cloud. And so then we replicate what's happening on the application or the internet down on a remote workers device.”

In essence, CBII promises to do all this while making the user experience virtually indistinguishable from having the browser directly running on the computer. Users are functionally interacting with an image of a browser window, instead of the browser itself, but that illusion should be imperceptible.

“That's going to significantly reduce the risk in the attack surface,” said By Light VP Jason Cole, “alleviating all the congestion at those Internet access points.”

For security purposes, this means that instead of monitoring all traffic for harm on every device, the Pentagon can instead look at the connection between computers and clouds. If a piece of malware was downloaded, it becomes a much smaller haystack of files for the forensics team to go through, since downloading to a computer becomes an active choice, instead of the passive function of browsing.

Many of the normal conveniences of browser-based functionality are continued within Menlo's cloud-based environment.

Instead of users having to log in anew to every site they visit every time they load the remote cloud, the software “maintains an encrypted cookie-jar in our cloud for each user that largely mirrors how the user's native browser handles cookies,” said Kowsik Guruswamy, Menlo Security CTO.

“When a user navigates to a site, Menlo injects the user's site-specific cookies into the isolated browser so they can stay logged in,” Guruswamy continued. “The encryption key for each user's cookie jar is stored in their own browser, such that only they can unlock the contents.”

Beyond the security of the environment, the move to cloud-based browsing also promises an overall savings in data use.

“We're estimating about a 20% bandwidth reduction for any general web browsing, but then a 50 to 70% bandwidth reduction for streaming media,” said Cole.

That savings is valuable everywhere, and is especially valuable in areas where bandwidth is already constrained, like on ships underway or at remote bases with low connectivity. Even in more domestic settings, the pandemic-induced shift to remote work often means users have to send data back through company-owned network infrastructure for security reasons, which eats up time in the process, and comes with risks.

“I think companies overall are struggling with not only the latency so that their end users can have a good experience to accomplish their job, but gaps in security based on all that backhauling, and there's some blind spots there,” said Fraga.

The servers are, like much of the cloud infrastructure available today, provided through Amazon Web Services. Menlo's approach is already in use with banks like JPMorgan Chase, HSBC, and AmEx.

“Isolation overall is an innovative technology,” said Fraga. Isolation, in the fashion promised by cloud-based browsing, is a preventative technology. It reduces the number of paths into computers, making it easier for other detection solutions to find the fewer threats that might slip through.

https://breakingdefense.com/2020/09/fewer-threats-more-bandwidth-disa-awards-199m-for-cloud-browsing/

On the same subject

  • Opinion: The Right Defense Budget Debate Is About Strategy Not Inflation

    April 24, 2022 | International, Aerospace, Naval, Land, C4ISR, Security

    Opinion: The Right Defense Budget Debate Is About Strategy Not Inflation

  • Boeing begins 3D-printing Apache helicopter parts

    October 18, 2023 | International, Aerospace, Land

    Boeing begins 3D-printing Apache helicopter parts

    Boeing has teamed up with ASTRO America to 3D-print parts for its Apache attack helicopter as a way to potentially improve supply chains and manufacturing.

  • Airbus wins DARPA contract to develop small constellation satellite bus for Blackjack program

    January 17, 2019 | International, Aerospace

    Airbus wins DARPA contract to develop small constellation satellite bus for Blackjack program

    HERNDON, Va., USA, 14 January 2019 - Airbus Defense and Space Inc. has been awarded a contract from the Defense Advanced Research Projects Agency (DARPA) to develop a satellite bus in support of the Blackjack program. DARPA describes the Blackjack program as an architecture demonstration intending to show the military utility of global low-earth orbit constellations and mesh networks of lower size, weight and cost. DARPA wants to buy commercial satellite buses and pair them with military sensors and payloads. The bus drives each satellite by generating power, controlling attitude, providing propulsion, transmitting spacecraft telemetry, and providing general payload accommodation including mounting locations for the military sensors. “Airbus has previously co-invested hundreds of millions of dollars in high-rate manufacturing technology and supply chain logistics to build large constellations of small satellites,” said Tim Deaver, Director of US Space Programs at Airbus Defense and Space, Inc. “Airbus is committed to growing manufacturing capability in the US and our government customers can leverage this commercial capability to develop low-earth orbit constellations to complement large existing systems.” This contract positions Airbus Defense and Space, Inc., of Herndon, Va., and its strategic joint venture partner, OneWeb Satellites, of Exploration Park, Fl., as the ideal service providers for Blackjack. High production rates and design-to-cost management techniques enable OneWeb Satellites to offer low cost constellation solutions for the U.S. government and current customers. Constellations of inexpensive satellites permit wide scale disaggregated architectures enhancing survivability across many different mission areas. OneWeb Satellites is pioneering new value propositions in space. They are leading the design and manufacturing of ultra-high performing satellites at high-volumes. “We have created a game changer with our overall design, supply chain and production system,” said Tony Gingiss, CEO, OneWeb Satellites. “Our team is transforming the space industry and we are in the midst of demonstrating we can deliver on our promises.” OneWeb Satellites brings to bear capabilities which dramatically lower the cost and shorten acquisition timelines for customers thanks to a modular design and agile serial production of satellites. The OneWeb Satellites satellite manufacturing facility in Florida is the latest step in Airbus' continued and long-standing commitment to growth in U.S. manufacturing, job creation and investment. This facility, which will ultimately support thousands of jobs and follows the opening of our U.S. Manufacturing Facility for A320 aircraft in Mobile, Alabama, from which we delivered our first aircraft in 2016. An A220 assembly line on the same site in Alabama will break ground in January of 2019. With our extensive network of U.S. suppliers, Airbus is the largest consumer of U.S. aerospace and defense goods in the world – buying more than any other company or even country. Airbus invested $16.5 billion with U.S. companies in 2017, supporting 275,000 American jobs. https://www.airbus.com/newsroom/press-releases/en/2019/01/Airbus-wins-DARPA-contract-to-develop-small-constellation-satellite-bus-for-Blackjack-program.html

All news