Back to news

February 4, 2021 | International, C4ISR, Security

Qatari research center chooses Leonardo for cyber range

BEIRUT — A Qatari cyber research center has selected Leonardo to provide a cyber range and training system to support security operations, the Italian firm announced Feb. 3.

The Qatar Computing Research Institute, or QCRI, was established by the Qatar Foundation for Education, Science and Community Development. The training platform ordered by the QCRI is capable of simulating cyberattacks so users can assess the resilience of digital infrastructure.

“The training is completely to be performed in Qatar, and it is expected, through an approach oriented to ‘train the trainers,' to provide courses to a significant number of operators involved in the cybersecurity framework,” Tommaso Profeta, managing director of Leonardo's Cyber Security Division, told Defense News.

He noted that training and exercise scenarios can be customized using a drag-and-drop graphical interface. The platform can also analyze and classify the results of simulated attacks based on data collected during real-world offensive campaigns. Scenarios can be used for individual training or classroom experiences, and they provide practice for security operations centers and incident response activities.

This training tool “will allow the QCRI to deliver a complete cyber training process, from the design of the learning path to specific training sessions. Users will be able to practice their skills in simulated attack and defense scenarios, employing both information technology (IT) and operational technology (OT). The training will produce qualified teams of operators equipped with up-to-date knowledge and techniques, ready to face ever-evolving cyber threats,” according to a company statement.

“The best cyber training/testing environments are in theory real production systems. But in practice for such environments, institutions, enterprises and organizations cannot easily experience critical situations without paying high, sometime unaffordable prices,” Profeta said. “Training and testing are therefore the two essential, human-driven processes that can effectively support the overall cyber ‘protection' loop, but only if they can cope with real threats and highly realistic systems in highly realistic situations.”

Cyber ranges provide a controlled environment where cybersecurity experts can practice their technical and soft skills in emulated complex networks and infrastructures to learn how to respond to real-world cyberattacks. In these environments, cyber tools can be stressed to reveal their limits and vulnerabilities before deployment into cyberspace. Leonardo's platform challenges such assets and provides digital twin environments for predeployment testing.

Asked whether other Gulf countries have expressed interest in this training system, Profeta said it “has already been presented to other high-level Middle East stakeholders, and a significant level of interest has been registered for the platform.”

What scenarios are available?

Those using the cyber range will try to defend against simulated but realistic cyberattacks. According to Profeta, these include:

  • Man-in-the-middle attacks.
  • Botnets.
  • Exploitation of client and server vulnerabilities with lateral movements in search of sensitive data.
  • Distributed denial-of-service attacks (HTTP flooding or domain name system reflection) designed to disrupt connections to a targeted server.
  • Ransomware via multiple vectors, such as spear-phishing via email or drive-by downloads, relying on DNS-based covert channels.
  • Data exfiltration of personally identifiable information and intellectual property.

Though it's difficult to measure the potential effectiveness of this platform for Qatar, the company official predicted the system will reduce the cost of and improve the user experience in cyber training.

Leonardo also supplies the NATO Computer Incident Response Capability, a cyber defense product.

https://www.c4isrnet.com/cyber/2021/02/03/qatari-research-center-chooses-leonardo-for-cyber-range

On the same subject

  • The unlikely way to improve Air Force information warfare: forums

    July 24, 2020 | International, Aerospace

    The unlikely way to improve Air Force information warfare: forums

    Mark Pomerleau One way the Air Force's new information warfare command is trying to bring together the disparate parts of the organization is through forums where leaders put representatives from different components in the same room. Sixteenth Air Force/Air Forces Cyber, created in October, combined what was previously known as 24th and 25th Air Force. The move placed cyber, intelligence, surveillance and reconnaissance, electronic warfare and weather capabilities under one commander, serving as the Air Force's first information warfare entity. With all these new wings and capabilities now under a single unit, they need to understand what everyone is doing and how it can feed together. “How do we bring forums together where all of our wings that are focused on a problem can be in the same room and we start to build out what things are they all contributing,” Lt. Gen. Timothy Haugh, 16th Air Force's commander, told a webcast hosted by the Mitchell Institute. “Then taking it to the next layer, so all the weapons and tactics teams are talking. That simple act of creating a forum was built largely on our component responsibilities. We have very good forums ... for how do we support and produce cyber outcomes. We expanded that forum into an information warfare environment.” Some of this integration is already taking hold. Haugh explained he received a positive update earlier this month about how one meeting had led to fewer stovepipes and more data sharing. In addition, he said he'd like to see more components share intelligence as a way to enable others within the enterprise. For example, if a portion of the ISR enterprise, be it analysis or exploitation, in support of Air Forces Africa, discovers a Russian private military corporation conducting malign activities in Africa, they can pass that to the cyber enterprise to potentially pursue the adversary. Then the cyber element can feed their information or operation back to the ISR enterprise to produce better intelligence for the air component. “This is where for us, that art is starting to come together. Right now, it's very manual, and we're seeing the processes and the data flows start to fall in place that that will become a more automated and routine function that now becomes mutually supportive across our enterprise,” Haugh said. https://www.c4isrnet.com/smr/information-warfare/2020/07/22/the-unlikely-way-to-improve-air-force-information-warfare-forums/

  • How are the US Army’s modernization plans faring under a pandemic?

    April 7, 2020 | International, Land

    How are the US Army’s modernization plans faring under a pandemic?

    By: Jen Judson WASHINGTON — The Army commands in charge of acquisition and modernization are taking it day-by-day as the COVID-19 pandemic worsens in the United States, but so far see minimal impact to production lines and modernization efforts underway. “The Army has been very carefully looking at our industrial base and our ability to maintain programs, both for continued readiness and continued modernization, and, in general, we are still remaining fairly close to being on track,” Bruce Jette, the Army's acquisition chief, told reports in an April 3 teleconference. “That doesn't mean that individual programs or individual issues haven't arisen, but, at this point, we have, we think, in the long run, we can resolve any of the challenges we have at hand,” he added. Jette said he has sent letters out to contracting officers, program managers and program executive officers as well as industry providing them guidance and insight “into how we want to work together as a team, through good constructive and continuous and transparent communications, make sure that we know what's going on in each other's camp well enough that we can respond quickly.” One major point of concern is what might happen with sub-tier suppliers to the bigger prime contractors, Jette said, so the Army is doing what it can to understand challenges that these suppliers might be experiencing if they have to shut down production to keep employees safe and healthy should cases of coronavirus crop up. “We are still working various individual issues,” Jette said. “I track, on a daily basis, about 21 pages... on suppliers down to those lower levels.” That list provides projection for 30, 60 and 90 days, but are updated all the time. So far, Boeing is the only major defense contractor to shut down an Army production line, according to Jette. The company reported late in the evening on April 2 that it would have to halt its H-47 Chinook production line in Ridley Park, Pennsylvania, for 10 days to better prevent the spread of the coronavirus after some employees tested positive for the virus. Jette said he didn't believe the work stopping at the Boeing plant would affect the delivery schedule for the H-47s to the force. All other lines are delivering on schedule including the newest version of the Bradley Infantry Fighting Vehicle — the A4 — he said. The fielding of the Joint Light Tactical Vehicle, Jette said, will be delivered at a “lower density,” but added, “it doesn't mean we won't catch up, it just means that we're slowing down.” Jette also said testing would likely be difficult in the coming months due to “the density packing necessary in some cases and how that puts a lot of people at risk.” The Joint Assault Bridge that was already delayed due to other issues was supposed to go into testing, but that will have to be rescheduled, Jette said. “It became a concern about moving the unit, moving the equipment together, getting all the testers,” he said, “and again, I go back to this issue that sometimes military operations require you to be in very close quarters for extended periods of time and that kind of violates our desire to keep people social distancing at this point.” The 2020 calendar year is also packed with major milestones for the Army's ambitious modernization plans. And as the country's citizens continue to self-isolate, avoid travel and work from home as much as possible, it becomes hard to conduct various tests or prototyping activities to move major programs along. “It's a changing situation, it changes pretty much daily,” Gen. Mike Murray, the Army Futures Command commander, told reporters on the same call. "It is very much a running estimate because it does change each and every day and we're not in control of this timeline, so in many ways, we are adjusting to the timeline to try to keep everything on track as best we The Army is having to take a “slight pause” in some activities, Murray said, such as briefly stopping some testing at Aberdeen Proving Ground, Maryland. “It's not because of a system,” he said. “It's based upon the maintenance of the systems as you test them. ... All the vehicles we're testing have to, daily, go into the maintenance bay to be maintained and so the interaction and the proximity, we just have to work through some mitigation strategies, we should have that done very quickly.” The Army's Interim Mobile Short-Range Air Defense System (IM-SHORAD) is one of the vehicles affected by the pause at APG. The system was undergoing automotive testing. The Army's plan to get to a critical soldier touchpoint or evaluation of the Integrated Visual Augmentation System this summer may be interrupted, Murray said, based on how long social distancing will be needed. “It's not Microsoft itself,” as the company is completely teleworking, but the IVAS deliveries could be affected by sub-suppliers, for example, he said. But, according to Murray, even if the touchpoint is delayed, he said the Army would do what is possible to avoid delaying the first unit equipped and believes, at this time, that the service will stay on schedule for t he initial fielding. The Army also has several major tests and evaluations coming up including a long-awaited Limited User Test (LUT) for its Integrated Air-and-Missile Defense Battle Command System (IBCS). A delay on the LUT would pile onto years of delays for the troubled program meant to serve as the brains of the Army's future air and missile defense system. And the Army is planning on another flight test of Lockheed Martin's Precision Strike Munition (PrSM) later this month, which will deliver a new long-range precision fires capability to the battlefield. LRPF is the Army's number one modernization priority. “We are working through mitigation strategies to keep both of those on track,” Murray said. “Every day we're readjusting and reevaluating whether we can physically do that or not.” The IBCS LUT and the PrSM test involve an entire community of representatives coming together, he said, but “I'm not ready to say today that either one of those are slipping; those are closer in and we'll work them through to keep them on schedule as best we possibly can. And if the analysis proves that we can't, there's a lot of sequential things that happen in a program; we may have to look at some concurrency.” Murray noted there are plenty of modernization programs that so far remain unaffected and likely will stay on track, such as Future Vertical Lift efforts to bring two future aircraft online in the mid 2030s, the Army's new network and initial work to restart the Optionally Manned Fighting Vehicle program to replace the Bradley. The Army and the Navy were also able to execute a major hypersonic missile test in March. For now, Murray said, he is focused not on alternative strategies, but how to mitigate impact to current ones. “I'm looking as far out as this fall just to make sure that we can get ahead of it with mitigation strategies," Murray said. https://www.defensenews.com/land/2020/04/06/can-the-army-stay-on-top-of-modernization-plans-during-covid-pandemic/

  • Exclusive: European regulator says it would pull Boeing approval if needed
All news