14 août 2018 | International, C4ISR

Pentagon invites researchers to hack the Marine Corps

By:

The Department of Defense kicked off its sixth bug bounty program Aug.12 with Hack the Marine Corps, a challenge focusing on the Corps' public-facing websites and services.

“Hack the Marine Corps allows us to leverage the talents of the global ethical hacker community to take an honest, hard look at our current cybersecurity posture," said Maj.Gen. Matthew Glavy, the head of the U.S. Marine Corps Forces Cyberspace Command, in a news release.

“Our Marines need to operate against the best. What we learn from this program will assist the Marine Corps in improving our war-fighting platform, the Marine Corps Enterprise Network. Working with the ethical hacker community provides us with a large return on investment to identify and mitigate current critical vulnerabilities, reduce attack surfaces and minimize future vulnerabilities. It will make us more combat ready.”

The DoD launched its first bug bounty, Hack the Pentagon, in May 2016, which was considered one of the first major successes for the then-newly minted Defense Digital Service. Since then the DoD has held bug bounties for the Army, the Air Force, the Air Force again and the Defense Travel System.

The combined programs resulted in over 600 resolved vulnerabilities with approximately $500,000 awarded to the ethical hackers participating in the program.

“Information security is a challenge unlike any other for our military. Our adversaries are working to exploit networks and cripple our operations without ever firing a weapon," said Chris Lynch, the director of the Defense Digital Service.

"Sometimes, the best line of defense is a skilled hacker working together with our men and women in uniform to better secure our systems. We're excited to see Hack the Pentagon continue to build momentum and bring together nerds who want to make a difference and help protect our nation.”

Hack the Marine Corps was launched with HackerOne, which partners with the hacker community to help businesses and government conduct bug bounties, and kicked off with a live hacking event coinciding with the Black Hat USA, DefCon and BSides conferences in Las Vegas.

The live hack resulted in 75 unique vulnerability reports and more than $80,000 in awards.

“Success in cybersecurity is about harnessing human ingenuity,” said Marten Mickos, CEO at HackerOne.

“There is no tool, scanner or software that detects critical security vulnerabilities faster or more completely than hackers. The Marine Corps, one of the most secure organizations in the world, is the latest government agency to benefit from diverse hacker perspectives to protect Americans on and off the battlefield.”

The bug bounty program ends Aug. 26.

https://www.fifthdomain.com/dod/marine-corps/2018/08/13/pentagon-invites-researchers-to-hack-the-marine-corps/

Sur le même sujet

  • La Malaisie renoncerait-elle à l’achat de chasseurs européens au profit de chinois?

    26 mars 2019 | International, Aérospatial

    La Malaisie renoncerait-elle à l’achat de chasseurs européens au profit de chinois?

    Qualifiant les mesures de l'UE de «protectionnistes», le Premier ministre malaisien a promis que, si l'UE poursuivait sa mobilisation contre l'huile de palme, son pays renoncerait également aux produits européens, notamment en acquérant plutôt des chasseurs chinois. La Malaisie a annoncé son intention d'acheter des chasseurs à la Chine, si l'Union européenne continuait sa campagne contre le biocarburant à base d'huile de palme, rapporte la version numérique du journal New Straits Times, citant le Premier ministre du pays. «Nous pouvons adopter des mesures réciproques, s'ils ne veulent pas acheter notre huile de palme. Dans ce cas, nous n'avons non plus besoin de leurs produits. Je viens de rentrer du Pakistan où, lors d'un défilé, il y avait des chasseurs fabriqués par la Chine. Si nous avons besoin d'un chasseur, nous examinerons l'acquisition de ceux fabriqués en Chine», a déclaré le chef du gouvernement malaisien, Mahathir Mohamad, lors d'une rencontre à laquelle étaient présents des fabricants d'huile de palme. Pour rappel, il avait été plus tôt annoncé que la Malaisie examinait la possibilité de se procurer des chasseurs polyvalents français Rafale ou des Eurofighter Typhoon, produits par le consortium européen Eurofighter GmbH. Mahathir Mohamad considère que l'UE agit d'une manière «injuste» lorsqu'elle propose de prohiber l'huile de palme, ajoutant qu'il s'agit d'une mesure protectionniste par laquelle ce bloc cherche à plonger «dans la pauvreté» les Malaisiens. «L'huile de palme n'est pas un poison et ils ne doivent pas dire qu'on ne peut pas en mettre dans la nourriture. Ils n'ont pas pitié de 600.000 pauvres ouvriers qui perdront leur emploi et seront privés de revenus, si on ferme les plantations», a-t-il ajouté. https://fr.sputniknews.com/international/201903241040483791-malaisier-chasseurs-europe-chine/

  • Cyberwarriors need a training platform, and fast

    11 juin 2018 | International, C4ISR

    Cyberwarriors need a training platform, and fast

    By: Mark Pomerleau U.S. Cyber Command's cyber teams are now built and transitioning to readiness, and now the force needs a dedicated platform to conduct training. Given the importance of properly preparing cyberwarriors, the Army (acting as Cyber Command's executive agent for all the service's cyber teams) has been using a rapid acquisition approach called other transaction authorities to field a training platform. The Persistent Cyber Training Environment, or PCTE, is not a single entity, but rather a complex system of systems that will require many moving parts for individual and collective training, as well as mission rehearsal. According to Jim Keffer, director of cyber at Lockheed Martin, it will be more than just a cyber range. It'll require event management; scheduling for training exercises; scenario design features; control of the exercises; assessments; red forces; library of capabilities that can be linked to designing adversary network mock-ups (which will require good intelligence); and classrooms to put all this together. The reason such a high-end training environment is being fast-tracked is because cyberwarriors don't currently have anything akin to what traditional war fighters use to prepare for combat. Capstone cyber exercises that only occur once or twice a year are not enough for the force, and in many cases the first-time cyberwarriors will engage with an adversary in the real world and not in simulations. “It's like a fighter pilot going up and the first time he's flown actual combat is against a real adversary,” Keffer told Fifth Domain. “That's not a good way to fight wars. That's not a good way to train your troops. That's not a good way to decrease the risk to your forces.” Incremental approach The overall PCTE is made up of a number of cyber investment challenges, or CICs, that the Army is releasing incrementally and will eventually string together. This will “bring together some of the best technology that's out there” to address immediate needs in various categories as the longer-term vision of what PCTE might look like coalesces, Deon Viergutz, vice president of Cyber Solutions at Lockheed Martin, told Fifth Domain in an interview. The Army will release five CIC's to get multiple industry approaches as it heads up the full PCTE indefinite delivery/indefinite quantity contract, Viergutz said, adding, “I believe that is still under work, the long term for PCTE and the acquisition.” While CIC one has been awarded, CIC two should be awarded in the next few weeks. According to contracting documents, CIC two is focused on enabling user access to the PCTE and training aids through a portal. CIC three, which is forthcoming in mid- to late-June, is focused on red team planning, as well as master exercise control. CIC four, estimated for release in July, will focus on training assessment. There is no information released yet regarding CIC five. One important question remains unclear, however: In the end, who will be the integrator of systems — the government or a contractor? “The seams between all these capabilities tend to be the weak points. Having an integrator to kind of tie all that together — the ranges and all these different capabilities — would be important to make sure that the cyberwarriors get the best capability that they deserve ... as quickly as possible,” Keffer said. “If the government wants to be the integrator, we'll do all we can to help them out. If they want industry to be the integrator, industry has a lot of experience doing that, especially Lockheed Martin; we're big in the training business.” https://www.fifthdomain.com/dod/2018/06/04/cyberwarriors-need-a-training-platform-and-fast/

  • Contract Awards by US Department of Defense - July 2, 2019

    3 juillet 2019 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité, Autre défense

    Contract Awards by US Department of Defense - July 2, 2019

    NAVY Lockheed Martin Corp., Lockheed Martin Aeronautics Co., Fort Worth, Texas, is awarded $348,223,161 for modification P00019 to a previously awarded cost-plus-fixed-fee contract (N00019-17-C-0001). This modification is for production non-recurring, special tooling and special test equipment in support of low-rate initial production Lot 12 F-35 Lightning II aircraft for the Air Force, Navy, Marine Corps, non-U.S. Department of Defense (DoD) partners and foreign military sales (FMS) customers. Work will be performed in Fort Worth, Texas (23.80%); El Segundo, California (23.86%); San Diego, California (17.03%); Samlesbury, United Kingdom (7.65%); Orlando, Florida (6.63%); Cedar Rapids, Iowa (3.44%); Nashua, New Hampshire (2.71%); Clearfield, Utah (2.15%); Marietta, Georgia (1.77%); East Aurora, New York (1.59%); Palmdale, California (1.40%); Cheltenham, United Kingdom (0.96%); Turin, Italy (0.81%); Clearwater, Florida (0.79%); Melbourne, Florida (0.60%); Irvine, California (0.58%); Kongsberg, Norway (0.53%); Arlington, Texas (0.48%); Rolling Meadows, Illinois (0.46%); Tempe, Arizona (0.38%); Inglewood, California (0.33%); Papendrecht, Netherlands (0.28); Garden Grove, California (0.21%); Montmorency, Australia (0.20%); Marion, Virginia (0.17%); Independence, Ohio (0.14%); Amesbury, Massachusetts (0.13%); Rome, New York (0.13%); Los Angeles, California (0.10%); Hot Springs, Arkansas (0.10%); Lystrup, Denmark (0.09%); Grand Rapids, Michigan (0.09%); Owego, New York (0.07%); Sharon, Massachusetts (0.06%); Wichita, Kansas (0.06%); Boulder, Colorado (0.05%); Carlsbad, California (0.04%); Ontario, California (0.04%); Delta, British Columbia, Canada (0.03%); Long Beach, California (0.01%); Lindenhurst, New York (0.01%); Eskisehr, Turkey (0.01%); Saint Peters, Missouri (0.01%); Santa Fe Springs, California (0.01%); and Rancho Cucamonga, California (0.01%). Work is expected to be completed in August 2022. Fiscal 2017 aircraft procurement (Navy and Marine Corps); fiscal 2018 and 2019 aircraft procurement (Air Force, Navy and Marine Corps); non-U.S. DoD partner and FMS funds in the amount of $348,223,161 are being obligated at time of award, $17,899,115 of which will expire at the end of the current fiscal year. This modification combines purchases for the Air Force ($129,642,270; 38%); Navy ($69,738,685; 20%); Marine Corps ($61,001,500; 17%); non-U.S. DoD partners ($60,840,706; 17%) and FMS customers ($27,000,000; 8%). The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. Anchor Innovation Inc.,* Virginia Beach, Virginia (N50054-19-D-1901); Beach Marine Services Inc.,* Portsmouth, Virginia (N50054-19-D-1902); Colonna's Shipyard Inc.,* Norfolk Virginia (N50054-19-D-1903); East Coast Repair & Fabrication LLC,* Norfolk, Virginia (N50054-19-D-1904); Fairlead Boatworks Inc.,* Newport News, Virginia (N50054-19-D-1905); Lyon Shipyard Inc.,* Norfolk, Virginia (N50054-19-D-1906); Q.E.D. Systems, Inc.,* Virginia Beach, Virginia (N50054-19-D-1907); United States Marine Inc.,* Gulfport, Mississippi (N50054-19-D-1908); and Willard Marine Inc.,* Virginia Beach, Virginia (N50054-19-D-1909) for Mid-Atlantic Regional Maintenance Center Marine Boatyard and Industrial Support for Lot I, and Colonna's Shipyard Inc.,* Norfolk, Virginia (N50054-19-D-1910); East Coast Repair and Fabrication LLC,* Norfolk, Virginia (N50054-19-D-1911); Fairlead Boatworks Inc.,* Newport News, Virginia (N50054-19-D-1912); and Lyon Shipyard Inc.,* Norfolk, Virginia (N50054-19-D-1913) for Mid-Atlantic Regional Maintenance Center Marine Boatyard and Industrial Support for Lot II, are each awarded firm-fixed-price, indefinite-delivery/indefinite-quantity, multiple award contracts to furnish the management, material support services, labor, supplies and equipment deemed necessary to provide marine boatyard and industrial support which includes modifications, upgrades, service life extension and repairs to non-commissioned boats, crafts, lighterage and service craft and/or their associated systems and periodic maintenance. These contracts include options which, if exercised, would bring the cumulative ceiling value to $216,979,810. These nine small businesses will have the opportunity to provide offers for individual delivery orders. Work will be performed in the Hampton Roads, Virginia, area and is expected to be complete by July 2020, and work is expected to be completed by July 2024, if all options are exercised. Fiscal 2019 operations and maintenance (Navy) funding in the amount of $32,500 ($2,500 minimum guarantee per contract) was obligated under each contract's initial delivery order and expires at the end of the current fiscal year. These contracts were competitively procured via the Federal Business Opportunities website with nine offers received. The Navy's Mid-Atlantic Regional Maintenance Center, Norfolk, Virginia, is the contracting activity. Leidos Inc., Reston, Virginia, is awarded a maximum $99,000,000 cost-plus-fixed-fee, indefinite-delivery/indefinite-quantity, single award task order contract for aerospace medical and environmental health research support services at the Naval Medical Research Unit-Dayton. Work will be performed in Dayton, Ohio, and is expected to be completed by July 7, 2024. Fiscal 2019 research, development, testing and evaluation (Navy) funding in the amount of $1,000,000 will be obligated upon award under an initial incrementally funded task order and the funds will not expire at the end of the current fiscal year. This contract was competitively procured via the Federal Business Opportunities website, with six offers received. The Naval Medical Logistics Command, Fort Detrick, Maryland, is the contracting activity (N62645-19-D-5005). RWG (Repair & Overhauls) USA Inc., Houston, Texas (N64498-19-D-4019); and the Canadian Commercial Corp. representing Standard Aero Energy Co. (SAE) Winnipeg, Manitoba (N64498-19-D-4020) are each awarded an indefinite-delivery/indefinite-quantity, firm-fixed-price contract for depot level overhaul of Navy 501-K34 marine gas turbine engines for a program cumulative value of $70,000,000. The 501-K34 marine gas turbine engines are used on the Navy ship class DDG-51. Orders will be competed between both offerors. Work under N64498-19-D-4019 will be performed in Houston, Texas, and work under N64498-19-D-4020 will be performed in Winnipeg, Manitoba, and is expected to be completed by March 2024. No funding will be obligated at time of award. Funds will be obligated as individual orders are issued. These contracts were not competitively procured, in accordance with 10 U.S. Code 2304(c)(1), Limited Number of Responsible Sources. The Naval Surface Warfare Center, Philadelphia Division, Philadelphia, Pennsylvania, is the contracting activity. Sikorsky Aircraft Corp., a Lockheed Martin Co., Stratford, Connecticut, is awarded a $21,689,142 cost-plus-fixed-fee delivery order (N00019-19-F-2972) against a previously issued basic ordering agreement (N00019-19-G-0029). This order procures the CH-53K Data Transfer Unit and Defensive Electronic Countermeasure System Replacement program and includes necessary Non Recurring Engineering (NRE) to replace existing subsystems within the CH-53K production aircraft. NRE tasks include investigation, systems engineering support, risk analysis, integration development, weight impact and publication updates. Work will be performed in Stratford, Connecticut (44.02%); Cedar Rapids, Iowa (41.74%); Fort Worth, Texas (7.41%); Vergennes, Vermont (2.81%); City of Industry, California (1.9%); Costa Mesa, California (1.18%); and various locations within the continental U.S. (.94%), and is expected to be completed in January 2021. Fiscal 2017 aircraft procurement (Navy) funds in the amount of $21,689,142 will be obligated at time of award, all of which will expire at the end of the current fiscal year. The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. Epsilon Systems Solutions Inc.,* Portsmouth, Virginia, is awarded a $14,589,487 firm-fixed-price, indefinite-delivery/indefinite-quantity contract for the repair, restoration, overhaul, assembly and test services of the Naval Submarine Universal Modular Mast (UMM). The UMM systems will be completely overhauled off-hull at the vendor's facility to a ready-for-issue status to support the fleet during maintenance availabilities. Required services will be determined on an individual task order level. Work will be performed in Portsmouth, Virginia, and is expected to be completed by July 2024. Fiscal 2019 operation and maintenance (Navy) funding in the amount of $566,676 will be obligated at time of award via the first task order and will expire at the end of the current fiscal year. This contract was competitively procured via the Federal Business Opportunities website, with two offers received. The Naval Surface Warfare Center, Philadelphia Division, Philadelphia, Pennsylvania, is the contracting activity (N64498-19-D-4027). Frequentis Defense Inc., Columbia, Maryland, is awarded an $8,454,481 firm-fixed-price contract for non-recurring engineering and logistics for the design, development, test, manufacture and repair of the MD-5A Unmanned Carrier Aviation Mission Control System, which will support the MQ-25 Stingray unmanned air vehicle. The integrated computer system will transport voice communications from carrier-based air vehicle operators to local audio switches, local radio terminals and remote radio terminals. Work will be performed in Columbia, Maryland, and is expected to be completed in March 2021. Fiscal 2019 research, development, test and evaluation (Navy) funds in the amount of $8,454,481 will be obligated at time of award, none of which will expire at the end of the current fiscal year. This contract was not competitively procured pursuant to Federal Acquisition Regulation 6.302-1. The Naval Air Warfare Center Aircraft Division, Lakehurst, New Jersey, is the contracting activity (N68335-19-C-0276). Tompco Inc.,* Seabeck, Washington, is awarded $8,221,449 for firm-fixed-price task order N44255-19-F-4283 under a previously awarded multiple award construction contract (N44255-17-D-4014) for the RM #19-0166 asbestos abatement and replacement of steam condensate and high pressure drain systems, Naval Base Kitsap, Puget Sound, Naval Shipyard and Intermediate Maintenance Facility, Bremerton, Washington. Scope of work includes the abatement of asbestos and replacement of systems throughout the steam distribution system to improve worker safety. This project consists of High Efficiency Particulate Air (HEPA) vacuuming all surfaces, wet wiping, scraping, shoveling, scrubbing and/or mopping where HEPA vacuuming is inadequate to containment and removal of any mud, sand, soil and dust/debris from surfaces including floors, abandoned piping removal and replacement of piping and insulation. The project area is DD5 service gallery and all connected laterals, trenches, utilidors, etc. The work will be performed in Bremerton, Washington, and is expected to be completed by Feb. 3, 2020. Fiscal 2019 working capital contract funds in the amount of $8,221,449 are obligated on this award and will not expire at the end of the current fiscal year. Five solicitation emails were sent and four proposals were received for this task order. The Naval Facilities Engineering Command (NAVFAC), Northwest, Silverdale, Washington, is the contracting activity for the basic contract and the NAVFAC Bremerton Field Engineering, Acquisition Department is the contracting activity for the task order. Sikorsky Aircraft Corp., a Lockheed Martin Co., Stratford, Connecticut, is awarded $7,103,403 for cost-plus-fixed-fee order N00019-19-F-2555 against a previously issued basic ordering agreement N00019-19-G-0029. This order procures non-recurring engineering, development, tooling, manufacturing, qualification, reporting and delivery of the nose, main, intermediate and tail gearbox gears in support of the low rate initial production of the CH-53K aircraft. Work will be performed in Stratford, Connecticut, and is expected to be completed in October 2020. Fiscal 2018 aircraft procurement (Navy) funds in the amount of $7,103,403 will be obligated at time of award, none of which will expire at the end of the current fiscal year. The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. ARMY Yulista Support Services,* Huntsville, Alabama, was awarded a $226,911,155 cost-plus-fixed-fee contract for maintenance and modifications of C5ISR flight activity platforms. Bids were solicited via the internet with zero received. Work locations and funding will be determined with each order, with an estimated completion date of June 19, 2024. U.S. Army Contracting Command, Aberdeen Proving Ground, Maryland, is the contracting activity (W56KGU-19-D-0002). Cornforth Consultants Inc.,* Portland, Oregon (W91237-19-D-0016); K S Ware & Associates LLC,* Nashville, Tennessee (W91237-19-D-0017); and Aterra-Schnabel JV,* Ambler, Pennsylvania (W91237-19-D-0015), will compete for each order of the $15,000,000 firm-fixed-price contract for national dam safety engineering and design services. Bids were solicited via the internet with 10 received. Work locations and funding will be determined with each order, with an estimated completion date of July 1, 2024. U.S. Army Corps of Engineers, Huntington, West Virginia, is the contracting activity. AIR FORCE Leidos Inc., Reston, Virginia, has been awarded a $66,752,500 cost-plus-fixed-fee contract for rapid technology development and demonstrations. This contract provides for the development of new/novel concepts for sensor and systems of sensor systems across the multiple domains and spectrums that aid in command, control, communications, computers, intelligence, surveillance and reconnaissance and battlespace awareness. Work will performed in Reston, Virginia, with base support at Wright-Patterson Air Force Base, Ohio, and is expected to be completed by June 12, 2024. This award is a result of a competitive acquisition and two offers were received. Fiscal 2019 research, development, test and evaluation funds in the amount of $546,050 are being obligated at the time of award. Contracting activity is the U.S. Air Force, Air Force Materiel Command, Air Force Research Laboratory, Wright-Patterson AFB, Ohio (FA8650-19-C-1941). Engility Corp., Andover, Massachusetts, has been awarded a $40,000,000 firm-fixed-price/cost reimbursement/cost-plus-fixed-fee, indefinite-delivery/indefinite-quantity contract for services supporting the Space and Missile Systems Center, Advanced Systems and Development Directorate, Ground Systems and Space Operations Division at Kirtland Air Force Base, New Mexico. This contract provides engineering, development, integration and sustainment services supporting the current ground system enterprise throughout its evolution, including the transition to and buildout of enterprise ground services. Work will be performed at Kirtland AFB, New Mexico; Schriever AFB, Colorado; Buckley AFB, Colorado; Colorado Springs, Colorado; Space Based Infrared Radar Payload On-Orbit Test Station facility, Azusa, California; the Space Management Battle Lab, Colorado Springs, Colorado; Vandenberg AFB, California, as well as future sites at Naval Research Laboratory, Blossom Point, Maryland, and is expected to be completed by Sept. 20, 2019. This award is the result of a sole source acquisition. Space and Missile Systems Center, Advanced Systems & Development Directorate, Kirtland AFB, New Mexico, is the contracting activity (FA8818-19-D-0004). General Dynamics Information Technology Inc., doing business as General Dynamics Mission Systems, Fairfax, Virginia, have been awarded a $35,683,952, cost-plus-incentive-fee modification (P00015) to previously awarded FA8307-17-F-0004 for next generation GEO overhead persistent infrared (NGG-OPIR). The contract modification provides for additional Medium/LargeSat Common Solutions (MLCS) variants for the NGG-OPIR program, additional MLCS engineering development modules, increased tempest testing and to fund an overrun. Work will be performed at General Dynamics Mission System, Scottsdale, Arizona, and is expected to be completed by March 31, 2022. Fiscal 2019 research and development funds in the amount of $12,726,494.04 are being obligated at the time of award. The Air Force Life Cycle Management Center, Cryptologic Systems Division, Contracting Division, Joint Base San Antonio, Texas, is the contracting activity. DEFENSE LOGISTICS AGENCY Valley Apparel, LLC,* Knoxville, Tennessee, has been awarded a maximum $10,794,000 firm-fixed-price, indefinite-delivery/indefinite-quantity contract for Navy working uniform parkas. This was a competitive acquisition with two responses received. This is a one-year base contract with two one-year option periods. Location of performance is Tennessee, with a July 1, 2020 performance completion date. Using military service is Navy. Type of appropriation is fiscal 2019 through 2020 defense working capital funds. The contracting activity is the Defense Logistics Agency, Troop Support, Philadelphia, Pennsylvania (SPE1C1-19-D-1172). *Small business https://dod.defense.gov/News/Contracts/Contract-View/Article/1895053/source/GovDelivery/

Toutes les nouvelles