8 août 2019 | International, Sécurité

The Air Force sends good guys in to hack its cloud

By: Andrew Eversden

The Air Force invited ethical hackers into its IT networks again this spring, allowing good guys the chance to infiltrate its enterprise-wide Air Force Common Computing Environment in search of vulnerabilities, the white hat hacking company Bugcrowd announced Aug. 6.

The bug bounty program, done in a partnership with Bugcrowd and the Air Force's CCE program office, found 54 vulnerabilities. Bug bounties work under the assumption that the customer, in this case the Air Force, will now close the loopholes the hackers found, making the system more secure.

The CCE cloud uses Amazon Web Services and Microsoft's Azure commercial cloud. The service plans to migrate more than 100 applications to that cloud environment, Bugcrowd executives said.

The largest payout from the bug bounty totaled $20,000. The event ran from March 18 to June 21 at Hanscom Air Force Base in Massachusetts.

Casey Ellis, Bugcrowd founder and CTO, said it was the first time Bugcrowd has worked with the Air Force. The Air Force has completed several other white hat hacking events with the firm HackerOne.

Ellis said that moving to the cloud from on-premise environment represents a “paradigm shift” for many organizations. Penetration testing is an important part of keeping that environment secure, he said. Bugcrowd conducted such tests in six phases: source code analysis, AWS environment testing, Azure environment testing, black box network authentication assessment, social engineering engagement and Air Force portal testing.

Bugcrowd declined to discuss how many vulnerabilities were found throughout each stage of the process.

According to a news release from the Air Force from April, the CCE currently houses 21 Air Force applications and "has room for countess more.”

The computing environment allows the Air Force to have a cloud to host its applications that reside on its Global Combat Support System, which is a centralized, cohesive enterprise resource planning system. The Air Force said in the April release that each migration costs $446,000 and that the service has spent more than $136 million on the program since 2016.

https://www.fifthdomain.com/dod/air-force/2019/08/06/the-air-force-sends-good-guys-in-to-hack-its-cloud/

Sur le même sujet

  • Six considerations from the Defense News Top 100 list

    19 août 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Six considerations from the Defense News Top 100 list

    By: Byron Callan As usual, the annual Defense News Top 100 rankings shed light on changes in the defense sector, while raising additional questions for all interested parties. The rankings among U.S. firms have been relatively stable, with the primary catalyst for several years worth of change being acquisitions or divestitures. The U.S. order will again change in next year's edition, when Raytheon Technologies appears as a single entity for the first time. Defense News added Chinese enterprises in 2019, and so it's good to see this extended in 2020, as China has the second largest defense budget in the world after the U.S. This year's list raises six points worth highlighting, while observing how relative rankings have changed over time. First: These lists are difficult to compile, as they depend in large part on the willingness of contractors to provide sales data. There are some omissions, which hopefully could show up in future rankings — notably, BWX Technologies, SpaceX, General Atomics, Mantech, Parsons and Kratos for the U.S.; more Japanese firms including Kawasaki Heavy Industries; Navantia of Spain and other European naval shipyards; United Aircraft in Russia; ASC Pty in Australia; and PGZ in Poland. There are other Indian firms as well that would likely qualify. Second: It is intriguing to note how long either Lockheed or its successor Lockheed Martin has been the No. 1 U.S. contractor. It's been at the top of the Defense News list since 2003, and data from annual reports show it has been the top U.S. contractor, by sales, since 1980. Size may matter in perpetuating a No. 1 position, so it is notable that the ratio of Lockheed's defense sales to the second-largest contractor has also increased over the years. For this year's list, Lockheed's defense dollars are 165 percent of Boeing's defense sales; in 1988, they were 130 percent higher than the next largest defense contractor, McDonnell Douglas. Third: As much as it's easy to categorize contractors by their home country, it bears repeating that this a global, multinational business with international sales not just from exports. A look at the Australian defense industry highlights the “multi-domestic” nature of contractors in that country. BAE Systems is listed as a U.K. company, but it derives higher annual sales from the U.S. and Saudi Arabia than from London. And in 2019, Israeli firm Elbit had more of its total sales from North America (28 percent of total) than Israel (24 percent of total). Fourth: While the rankings don't capture the changes in the composition of some of the largest contractors, this may have a bearing on competition in the 2020s. CACI and Leidos still are predominantly services contractors, but some of their recent acquisitions, most significantly the Leidos acquisition of Dynetics, are more product-centric. Fifth: Obviously the rankings only capture the top level of the global defense sector, and in assessing supply chains, resiliency, the pace of innovation and technology ingestion, a far wider net has be cast. A July 2020 report by Israel's INSS observed that Israel's defense industry, which has seen consolidation in recent years, is comprised of “about 600 companies” and employs over 45,000 workers. Much as the rankings of the top contractors are of interest, a more critical assessment of the health and agility of contractors may rest on what's happening with smaller firms. Finally: The question of state, private or public ownership is a sixth factor to weigh. State ownership of Chinese firms and partial government stakes in some of the largest European enterprises has entailed different incentives and goals — it's hard to conclude, given the nature of China's rise, that government ownership of contractors has stymied the development and production of competitive weapons systems, though there's little transparency on efficiency. In the 2020s, it remains to be seen how different and competing ownership shapes future rankings. Byron Callan is a policy research expert at Capital Alpha Partners. He specializes in the defense and aerospace industries. https://www.defensenews.com/top-100/2020/08/17/six-considerations-from-the-defense-news-top-100-list/

  • Raytheon Rheinmetall Land Systems submits bid for US Army combat vehicle competition

    2 octobre 2019 | International, Terrestre

    Raytheon Rheinmetall Land Systems submits bid for US Army combat vehicle competition

    DETROIT, October 1, 2019 /PRNewswire/ - Raytheon Rheinmetall Land Systems, a joint venture formed by Raytheon Company (NYSE: RTN) and Rheinmetall Defence, has submitted its bid for the U.S. Army's new Optionally Manned Fighting Vehicle, or OMFV, program. The team will offer the next-generation Lynx Infantry Fighting Vehicle. Lynx is a next-generation, tracked armored fighting vehicle designed to address the critical challenges of the future battlefield. The vehicle provides ample growth capacity to support new technologies over its lifetime, and features lower life-cycle costs. "U.S. Army soldiers deserve the best possible fighting vehicle when they go into battle and that's exactly what this team is offering," said Sam Deneke, Raytheon Land Warfare Systems vice president. "Lynx provides unparalleled troop protection and features advanced technology that will keep our men and women in uniform ahead of the threat." Scheduled for fielding in 2026, the OMFV is expected to replace the Bradley fighting vehicle. "Our team has spent the last year assembling a U.S. supply chain to ensure that Lynx will be built in America by American workers," said Ben Hudson, global head of Rheinmetall's Vehicle Systems division. "This next-generation combat vehicle will help save lives on the battlefield and further bolster the U.S. industrial base - now that's a win-win." Raytheon technology earmarked for the Lynx includes the company's advanced weapons, Active Protection System, third-generation thermal sights, Coyote® unmanned aircraft system and cyber protection. About Rheinmetall Headquartered in Düsseldorf, the publicly traded Rheinmetall AG is a high-tech enterprise dedicated to the twin modern imperatives of mobility and security. Founded in 1889, the group today consists of two operational components: Rheinmetall Defence and Rheinmetall Automotive. One of the world's leading suppliers of military systems and equipment, Rheinmetall's Defence arm comprises three divisions: Vehicle Systems, Electronic Solutions and Weapon and Ammunition. The group's 23,000-strong global workforce generated sales last year of $6.9 billion. Follow us on Twitter. About Raytheon Raytheon Company, with 2018 sales of $27 billion and 67,000 employees, is a technology and innovation leader specializing in defense, civil government and cybersecurity solutions. With a history of innovation spanning 97 years, Raytheon provides state-of-the-art electronics, mission systems integration, C5I(®) products and services, sensing, effects and mission support for customers in more than 80 countries. Raytheon is headquartered in Waltham, Massachusetts. Follow us on Twitter. Media Contacts Raytheon John B. Patterson +1.520. 440.2194 rmspr@raytheon.com Rheinmetall Oliver Hoffmann Head of Public Relations, Rheinmetall AG +49-(0)211-473 4748 oliver.hoffmann@rheinmetall.com http://www.prnewswire.com/news-releases/raytheon-rheinmetall-land-systems-submits-bid-for-us-army-combat-vehicle-competition-300929126.html

  • Artillery goes trucking to survive drones swarming the battlefield

    13 juin 2024 | International, Terrestre

    Artillery goes trucking to survive drones swarming the battlefield

    The war in Ukraine has put long-range fires front and center at the Eurosatory defense show that kicks off in Paris on June 17.

Toutes les nouvelles