9 septembre 2019 | Local, C4ISR

Norad asked Canada to 'identify and mitigate' cyber threats to critical civilian sites

by Murray Brewster

The U.S.-led North American Aerospace Defence Command (Norad) asked the Canadian military to do an inventory of its bases and the surrounding civilian infrastructure, looking for critical systems vulnerable to a cyberattack.

The letter to Canada's chief of the defence staff, written by then-Norad commander U.S. Admiral William Gourtney just over three years ago, was obtained by CBC News under access to information legislation.

Despite the passage of time, two leading cyber experts said the request highlights an enduring concern of both defence planners and people in high-tech industries.

The notion that a cyberattack could shut down civilian infrastructure — such as power grids, water treatment plants or traffic systems — in the vicinity of a military base is nothing new.

What is unusual is that Norad sought reassurance, at the highest levels of the military, that Canada was on top of the evolving threat.

The Norad commander asked Gen. Jonathan Vance to "identify and mitigate" Infrastructure Control Systems (ICS) vulnerabilities on Canadian military bases, particularly at "installations that are critical for accomplishing Norad missions."

The March 24, 2016 letter also urged Canada's top military commander to "advocate developing capabilities to respond to cyber incidents on CAF [infrastructure control systems] and defend CAF [infrastructure control systems] if required."

Gourtney's concern was not limited to defence installations; he asked Vance to "work with Public Safety Canada to identify civilian infrastructure that is critical to CAF and Norad missions. This includes developing processes for reporting cyber incidents on the identified civilian infrastructure."

Vance responded to Gourtney (who has since retired and was replaced by U.S. Air Force Gen. Terrence O'Shaughnessy) three months later and directed the military to hunt for vulnerabilities.

"I share Norad's concerns for the cybersecurity" of critical defence infrastructure, Vance wrote on June 10, 2016, in a letter obtained by CBC News under access to information legislation.

He noted that the Canadian government has identified "adversaries" that pose "a significant threat and efforts have been made to identify and develop protective strategies for Canadian critical infrastructure."

The Liberal government — through its defence strategy and overhaul of security legislation — tackled some of the concerns raised by Norad.

It gave the Communications Security Establishment (CSE) and the military new powers to conduct offensive cyber operations. Perhaps more importantly, it set up the Canadian Centre for Cyber Security for civilian infrastructure, which — according to CSE — aims to "be a place where private and public sectors work side-by-side to solve Canada's most complex cyber issues."

David Masson, a cyber expert, said minimizing the vulnerability of civilian, privately operated infrastructure continues to be an extraordinarily complex task.

The major vulnerability is in what's known as operational technology systems, the kind of computer-driven tasks in utilities and other infrastructure that open and close valves or perform remote functions.

The task of securing them is made extraordinary difficult in part by the wide variety of operating systems out there.

"There's lots of them," said Masson, the director of technology at Darktrace, a leading cybersecurity company. "Look at it as 50, 60, 70 different bespoke communications systems. There's no real standardization because they're so old. Many of them were never expected to be connected to the internet."

He pointed to the 2015 and 2016 cyberattacks on Ukraine's power grid, which in one instance cut electricity to 225,000 people, as examples of what's possible when hackers go after operational technology systems.

It is also the kind of event that Norad is concerned about.

"The kinds of equipment and machinery that supports the transport of natural gas or the provision of air conditioned services, or our water supply — all of those are critical to Canadians and our militaries," Lt.-Gen.Christopher Coates, the Canadian deputy commander, said in a recent interview with CBC News.

He said Norad is focused on the capabilities that are essential to doing its job of defending North America against attack, and they try to "minimize those vulnerabilities where we can."

There is, Coates said, an interesting discussion taking place at many levels of the military about what constitutes critical infrastructure.

"You asked if we're satisfied. I get paid to be concerned about the defences and security of our nations. I don't think I should ever be satisfied," he added.

'Inauthentic activity' in Alberta election a possible preview of tactics in the federal campaign, report warns
Privacy commissioner launches investigation into licence plate breach
With ransomware on the rise, RCMP urging victims to 'be patient with police'
Christian Leuprecht, a defence expert at Queen's University in Kingston, Ont., said defining critical infrastructure is a complex and evolving task.

He pointed to Russian interference in the 2016 U.S. presidential election; prior to that event, he said, the definition of critical infrastructure was limited to power plants, electricity grids and even the financial system.

"A lot of things people are wrestling with the question of what institutions — take, for example, democratic institutions — become critical infrastructure," said Leuprecht.

The Ukrainian attacks, in the view of many defence experts, are a blueprint of what the opening shots of a future war would look like.

"There's a considerable and growing awareness that our defence and critical infrastructure systems are closely tied together because countries, such as China, preserve cyberattack as a first-strike option," Leuprecht said.

Masson said there are ways to limit the vulnerability of operational technology systems. Not connecting them to the internet would be a start, but many companies are choosing not to do that for efficiency reasons.

He said they also can be protected with "robust" security systems.

https://www.cbc.ca/news/politics/norad-cyber-civilian-1.5273917

Sur le même sujet

  • May 2 is the last day to register for Canadian Defence Marketplace

    27 avril 2021 | Local, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    May 2 is the last day to register for Canadian Defence Marketplace

    Don't miss your opportunity to conduct private and secure 1-on-1 meetings with over 200 government representatives and hundreds of industry leaders – all looking to connect and generate mutual growth. Here are just some of the Featured Companies attending Canadian Defence Marketplace on May 6 and November 4, 2021. Hurry, event registration closes May 2, 2021! Link to register: defenceandsecurity.ca/events/functionReg&eventID=454 Register today to start connecting – your ticket includes access to BOTH the May 6 and November 4, 2021 Canadian Defence Marketplace B2B/B2G events. Plus, receive access to our bonus speakers event – Canadian Defence Exchange – on May 5, 2021*. Already registered for Canadian Defence Marketplace? Congratulations, you have earned COMPLIMENTARY access to Canadian Defence Exchange! Please keep your eye on your inbox for an email to RSVP to save your seat. * Access to Canadian Defence Exchange is included in all Canadian Defence Marketplace registrations. Individuals who are already registered for Canadian Defence Marketplace will automatically earn access to Canadian Defence Exchange but will need to RSVP for the event through a link emailed to them. ​ ​ This eBlast is brought to you by Microsoft Discover Microsoft AI and cloud computing solutions for improved military operations. Download the white paper (Link: info.microsoft.com/ww-landing-Government-AI-and-Cloud-Computing-for-Defense.html?lcid=EN-CA&wt.mc_id=AID3022199_QSG_522768&ocid=AID3022199_QSG_522768 )

  • Eurosatory: This navigation system by Safran doesn’t need GPS

    12 juin 2018 | Local, Terrestre, C4ISR

    Eurosatory: This navigation system by Safran doesn’t need GPS

    PARIS ― Safran Electronics & Defense unveiled June 12 at the Eurosatory trade show a range of military inertial navigation systems, dubbed Geonyx, aimed at equipping armored vehicles, target acquisition systems and artillery. The Geonyx INS range is a navigation tool designed to allow operators to find their position and aim weapons, a Safran ED executive told journalists. The system is intended to be highly reliable and independent of GPS, which can be jammed. Safran ED presented its Geonyx system to the Direction Générale de l'Armement procurement office and the French Army's Stat equipment assessment department on May 30. Geonyx could be fitted as a replacement of the Safran Sigma 30, which is fitted on the Nexter Caesar 155mm artillery. The resonance technology in the new INS range is “extremely disruptive,” the executive said. The Geonyx is smaller, highly reliable and at “a much lower price” than the Sigma 30, he added, however no price details were available. The three Geonyx models ― SP, HP and XP ― offer a rising level of performance, reflecting a range of operational requirements for an army. The systems are intended to be highly robust to withstand shock from artillery fire. An operational life of 10-15 years is expected, the executive said. Geonyx draws on technology developed on its Crystal gyroscope, an advanced hemispherical resonator gyroscope. The resonance technology will be applied to equipment for space, air, land and sea, both civil and military, Safran ED said in a statement. Northrop Grumman has developed its HRG system, which can be deployed in space. https://www.defensenews.com/digital-show-dailies/eurosatory/2018/06/08/eurosatory-this-navigation-system-by-safran-doesnt-need-gps/

  • LE MARCHÉ MILITAIRE À LA PORTÉE DES PME RÉGIONALES

    23 janvier 2020 | Local, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    LE MARCHÉ MILITAIRE À LA PORTÉE DES PME RÉGIONALES

    SAGUENAY – La plupart des PME croient que le marché de la défense et des équipements militaires est complexe et inaccessible. En réalité, ce n'est pas le cas. C'est ce qu'ont expliqué Rock Lemay et Patrick Sirois de la firme Triodeaux quelque 40 entrepreneurs de la région lors d'un déjeuner-conférence organisé par la Société de la Vallée de l'Aluminium(SVA), ce matin, au Manoir du Saguenay. « Il est important pour les PME de comprendre que les contrats ne concernent pas les armements et les avions, par exemple. Il y a plein de petites et grandes entreprises qui ont découvert le marché militaire. Ce marché de la défense et des équipements militaires qui avait été délaissé pendant plusieurs années au Canada, connaît une recrudescence dans les investissements afin de renouveler les équipements nécessaires aux soldats. Il ne s'agit pas seulement des produits de haute technologie, mais également de produits et de l'équipement communs tels que les bateaux, les camions, les plateformes, les uniformes et bien d'autres. Par exemple, l'entreprise d'autobus Prévost a une division militaire. L'armée a acheté 1 500 camions en France et Prévost doit les habiller avec des équipements adaptés. C'est là que les sous-traitants rentrent en ligne de compte et peut fournir des équipements comme des coffres, échelle, pièces de métal, plateforme, etc. », explique Patrick Sirois, président de Triode. Forte croissance Au cours des 10 prochaines années, les besoins du marché de la défense connaîtront une forte croissance. Les budgets pour le renouvellement des équipements sont déjà votés et alloués et les différents départements de l'armée s'affairent à déterminer leurs besoins avant d'aller en appel d'offres. « Autre facteur intéressant, Développement économique Canada (DEC) a mis en place au cours des dernières années une politique de retombées industrielles et technologiques qui favorisent les PME et les régions. En gros, cette politique assure que même si le contrat est octroyé à des entreprises étrangères, celles-ci n'auront d'autre choix que de travailler avec des fournisseurs ou des partenaires locaux pour faire de la recherche ou de l'assemblage de produits. » En fait, les prochaines années promettent d'être très intéressantes dans ce marché. Nul besoin d'être impliqué dans des projets d'armement. « Il y a beaucoup d'équipements pour lesquels la défense canadienne cherchera des fournisseurs, tels que des remorques, des ponts, des ponceaux, des équipements logistiques, des conteneurs ainsi que l'ensemble de l'équipement nécessaire à installer et soutenir des campements temporaires. Tous ces projets représentent de belles opportunités pour les entreprises de la région », affirment M. Sirois et son collègue Rock Lemay en précisant que le marché de la défense et des équipements militaires est de plus en plus accessible pour les PME qui savent se préparer et qui ont un minimum de processus déployés dans leur organisation. Enfin, soulignons que ce déjeuner-conférence servait à démystifier le processus et de permettre aux PME qui le désirent d'êtres accompagnées tout au long de la démarche par la SVA et son créneau d'excellence. (Texte en collaboration avec Guy Bouchard) https://informeaffaires.com/regional/manufacturier-et-fournisseur/le-marche-militaire-a-la-portee-des-pme-regionales

Toutes les nouvelles