22 avril 2020 | International, Naval, C4ISR

For the Navy’s hospital ships, networking is yet another challenge

Andrew Eversden

When the Navy hospital ship Comfort deployed to Haiti in 2010 following devastating earthquakes, media organizations broadcasting in the area ate up so much satellite bandwidth that the ship had to revert to paper processes and adjust its satellite communications for some ship-to-shore messaging.

While the outages weren't a widespread issue, said Sean Kelley, who served as the ship's top IT officer at the time, the problem highlighted a challenge these ships face: broadband.

Now, the hospital ships Mercy and Comfort are deployed to Los Angeles and New York, respectively, and are in the national spotlight as symbols of the coronavirus pandemic relief effort. But security and IT experts say the ships' mission presents the Navy with distinct networking problems, from cybersecurity to network connection for patients.

Onboard devices

When disaster strikes, the Navy's hospital ships deploy in a matter of days, mobilizing with a crew of about 100-1,200 personnel. But the influx of staff also leads to an incursion of devices, all of which must be secure and require bandwidth.

“You have a lot of different people going to a lot of different places that now have to be acclimated to this environment,” said Kelley, now executive vice president at Unissant, an IT and cybersecurity company. “So that's really one of the biggest challenges, is getting all those things turned on, all those things activated, making sure that they are all compliant with the latest patches and fixes, and making sure they're good.”

This process can be a “nightmare,” said retired Rear Adm. Danelle Barrett, former deputy chief information officer of the Navy and cybersecurity division director.

“The challenging part is always in the first couple days whenever this happens,” said Barrett, who oversaw communications and cyberspace for Operation Unified Response, the U.S. military's mission in Haiti following the 2010 earthquake. “The team is coalescing about how they want to operate, and they're getting their feet wet, getting new accounts on networks ... [getting] their logins.”

Cybersecurity aboard the ships is also complex. Both ships have 1,000 beds, 12 operating rooms, blood banks, labs, medical devices and a multitude of other “internet of things” devices connected to hospital beds. According to a 2018 survey by health care IoT security company Zingbox, each bed can have as many as 10-15 IoT devices.

“They have to be cyber-ready, or the mission of the Mercy is considered [degraded],” said Dean Hullings, global defense solutions strategist at Forescout, which handles Comply to Connect — a Defense Department framework created to ensure the cybersecurity of new devices — for the USNS Mercy.

Ensuring connectivity

For the devices to function, they need connectivity. When the ships arrived in ports in late March, technology firm CenturyLink “donated” connectivity to the Mercy, while Verizon provided connectivity to the Comfort.

Former and current Navy officials told C4ISRNET that adequate broadband is the most challenging IT consideration faced by these ships.

“Obviously you're going to be transferring imagery of X-rays or things like that that are more dense and require a ... higher data rate, so that bandwidth in port is important,” Barrett said.

And with the introduction of patients, bandwidth needs become more complex.

“The greatest communications challenge we are going to face during this deployment is the increased need for patients to communicate off the ship during their stay,” Tom Van Leunen, a spokesman for Military Sealift Command, told C4ISRNET. “Our hospital ships are designed to support official communication for the ship's crew and embarked medical community to complete their job. Adding a capability for patients to reach loved ones increases the risk of saturating the bandwidth off the ship.”

Aboard both ships, the Navy doubled the bandwidth, he said, adding that Navy personnel also set up separate networks for patients' communications.

While this solves one networking problem, it can also create an increased cybersecurity risk.

Securing the ships

Cybersecurity on the hospital ships follows the same standard practices as the rest of the Navy fleet. Since those aboard are largely Navy medical staff and personnel, they know what activities are acceptable on the network, Barrett said.

“You can't just go and plug anything into that network because of potential vulnerabilities that that system may bring that could affect not just the ship, but remember, the ship is then connected to the rest of the [Department of Defense Information Network],” Barrett said. “So risk by one is shared by all.”

ForeScout's Hullings said a hospital environment “epitomizes” why the Comply to Connect program is necessary. The ship has desktops, servers, routers, printers and other networks equipment, as well as mobile devices, such as tablets, that health care providers use to track patient care.

“The truly unique stuff is the mission systems of the hospital, like X-ray machines, MRI machines, the beds themselves in the post-operative recovery rooms, that are all sensors. And they are all passing data. They have to be protected,” Hullings said.

A spokesperson for the Navy told C4ISRNET that the ships are prepared for the cybersecurity challenges associated with their missions, but declined to address what additional cybersecurity challenges are introduced with the addition of private citizens.

“These ships have routinely deployed in humanitarian assistance missions such as Pacific Partnership (USNS Mercy) and Continuing Promise (USNS Comfort) that required them to operate in partner nation ports, with foreign national patients being brought to and from the ship,” said Cmdr. Dave Benham, a spokesman for the Navy's 10th Fleet. “In all operating locations, we take appropriate precautions to keep our networks secure, and we do not discuss specific measures in order to protect operational security.”

Cybersecurity on the hospital ships follow the same protocols as any other Military Sealift Command ship, said Benham.

“Protecting our networks is a continuous challenge, and the overarching concern is to ensure that the right information gets to the right place at the right time with the right level of protection,” he explained.

Cybersecurity aboard the hospital ships follow similar efforts to those recommendations made by the Centers for Disease Control and Prevention: Wash your hands.

“It's ‘wash your hands' with your computer, too,” Barrett said. “Do good hygiene with your computer.”

https://www.c4isrnet.com/it-networks/2020/04/21/for-the-navys-hospital-ships-networking-is-yet-another-challenge/

Sur le même sujet

  • How COVID-19 Is Affecting The Defense Industrial Base

    6 novembre 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    How COVID-19 Is Affecting The Defense Industrial Base

    Jen DiMascio The COVID-19 pandemic has exacerbated some of the risks that have always existed in the defense industrial base. Although government assistance and a robust Pentagon budget have helped offset initial trials, more challenges are looming. One of the biggest risks to the defense industrial base is that some companies serving the military are too heavily leveraged toward the commercial sector or too reliant on international companies, financial analysts told Aviation Week's DefenseChain Conference. “Some of these places are two weeks from bankruptcy,” says Chris Celtruda, managing principal at Destiny Equity Partners, says. Suppliers are beginning to falter because of a combination of factors, including the need to comply with cybersecurity standards, the pressure that prime contractors such as Boeing and Lockheed Martin have applied to them and their reliance on commercial business. A prime example is the recent bankruptcy of Impresa Aerospace, a Wichita-based company that made parts using computer numerical control machines as well as sheet metal parts and assemblies for Boeing and Lockheed military aircraft but was highly dependent on its work for the commercial Boeing 737 MAX. The U.S. federal Paycheck Protection Program helped delay some business failures, but others are inevitable, says Rick Nagel, managing partner of Acorn Growth. “The Impresa bankruptcy is an example of a lot more insolvencies we may see,” he adds. Weakness among niche companies could pose a problem for the Defense Department in the future. “I'm always amazed at how many critical systems have multiple single points of failure on major programs,” he says. At the Pentagon, officials have been working to keep essential suppliers afloat and to keep production moving through its sprawling international industrial base. For the U.S. Army, that has meant initial disruptions to Apache fuselage production in India and to the flow of generators from Mexico. The Pentagon and the State Department helped ease the stoppage, but the incident has caused them to review the full range of risks to its international supply chain. “I think that we can navigate through this, though it's certainly always going to be complex in today's global economy,” says Patrick Mason, deputy program executive officer for U.S. Army Aviation, adding that he is in the position of putting pressure on vendors to reduce cost, particularly to provide savings on multiyear aircraft contracts. One trend emerging along with the pandemic is a movement toward onshoring or reshoring overseas business for reasons of cybersecurity and the protection of the U.S. industrial base. As that happens, and as the commercial aviation market sags, Raanan Horowitz, president and CEO of Elbit Systems of America sees opportunity. “We are trying to position ourselves around some of those discontinuities,” Horowitz says, adding that the company likes going after opportunities that are not necessarily glitzy but hold value. “We are intensifying efforts toward looking at licensing, taking over orphan product lines and positioning ourselves to be part of the long-term solution.” Horowitz says Elbit is investing in U.S. infrastructure to capture new business. Industry officials see broad support for bringing more of the defense supply chain back to the U.S. The shift stems in part from the COVID-19-related economic downturn but also from longstanding concerns about China. In the fiscal 2020 National Defense Authorization Act, Congress passed restrictions on contracting with companies that use Chinese telecommunications equipment. Though companies first look for the best value, the threat posed by Chinese parts that either do not work or could transmit classified information back to China is an ongoing concern, says John Luddy, vice president for national security policy at the Aerospace Industries Association. “The concept of reshoring of supplies to better connect our allies and friends, both from a production standpoint and from an operational functionality and alliance standpoint, I think the volume is getting turned up on that a little bit,” he says. “There's also a strong impetus in Congress to look at exactly how vulnerable we are. That's going to be a more intense discussion in the year to come than it has been.” And that trend toward reshoring could have unintended consequences, warns Steve Grundman, founder and principal of Grundman Advisory. “I'm genuinely concerned that benign moves to secure our supply chain to prevent nefarious supplies and code [coming] into particularly our defense supply chain or commercial aerospace supply chain could slip very easily into protectionism,” Grundman says. “If you want to really put pressure on the defense budget, ask the defense industry to reshore the supply chain. https://aviationweek.com/defense-space/supply-chain/how-covid-19-affecting-defense-industrial-base

  • Raytheon Technologies awarded $619 million US Navy contract for SPY-6 family of radars

    31 mars 2023 | International, Naval, C4ISR

    Raytheon Technologies awarded $619 million US Navy contract for SPY-6 family of radars

    SPY-6 is the most advanced naval radar in the world providing unprecedented integrated air and missile defense capabilities

  • Northrop test fires rocket motor for new nuclear missile

    16 janvier 2024 | International, Aérospatial

    Northrop test fires rocket motor for new nuclear missile

    Northrop Grumman aims to rein in the risks facing the Sentinel ICBM program, which Air Force Secretary Frank Kendall has said is "struggling."

Toutes les nouvelles