4 juin 2020 | International, C4ISR, Sécurité

Watchdog says Pentagon needs better planning for IP update 17 years after first attempt

A federal watchdog found that poor planning by the Department of Defense has blurred the department's understanding of the risks and costs associated with upgrading the system that routes internet traffic across the globe, known as Internet Protocol version 6 (IPv6).

According to a June 1 report from the Government Accountability Office, the Pentagon needs to improve its transition planning for the most recent effort, which began in April 2017. The DoD has tried twice previously to implement IPv6 in 2003 and 2010, but stopped those transitions after identifying security risks and lacking adequately trained personnel.

The problem for the DoD is that IPv4, the IP management system the DoD uses, is running out of address space. IPv4 only has room for 4.3 billion addresses. In contrast, IPv6, created in the 1990s, provides about 340,000,000,000,000,000,000,000,000,000,000,000,000 (undecillion) IP addresses. The Defense Department owns approximately 300 million IP addresses with about 59.8 million unused and planned for use by future DoD components. The department estimates it will run out of its unused IP addresses by 2030.

The department's IPv6 implementation plan from early 2019 listed 35 actions needed to switch over from IPv4. Eighteen of those steps were scheduled to be completed by March 2020. The report said six of the 18 tasks were completed on time.

Upgrading to IPv6 would increase connectivity, add security, improve the warfighter's connection and communications on the battlefield, and preserve interoperability with allied systems, the GAO wrote.

The watchdog found that the department was not compliant with several IPv6 transition requirements from the White House's Office of Management and Budget. The DoD hasn't completed a cost estimate, developed a risk analysis or finished an inventory of IP compliant devices, the report said. Pentagon officials told the GAO that they knew their time frame for the transition was “optimistic," adding that they thought the pace was reasonable "until they started performing the work,” the GAO wrote.

“Without an inventory, a cost estimate, or a risk analysis, DOD significantly reduced the probability that it could have developed a realistic transition schedule,” the GAO wrote. “Addressing these basic planning requirements would supply DOD with needed information that would enable the department to develop realistic, detailed, and informed transition plans and time frames.”

The Department did meet OMB's requirement to name an official to lead and coordinate the agency planning. But because the Pentagon failed to complete the other three OMB requirements. the move is at risk.

“Without an inventory, a cost estimate, or a risk analysis, DOD's plans have a high degree of uncertainty about the magnitude of work involved, the level of resources required, and the extent and nature of threats, including cybersecurity risks,” the GAO wrote.

Among the DoD's goals it did complete are several IPv6 training programs, information sharing opportunities and a program management office.

The GAO recommended that Defense Secretary Mark Esper direct the DoD chief information officer to complete an inventory of IP-compliant devices, develop a cost estimate and perform a risk analysis. The DoD agreed that it needed to develop a cost estimate and risk analysis but didn't concur that it needed to inventory devices, citing new guidance from OMB and calling an inventory “impractical” because of the department's size.

“The lack of an inventory is problematic due to the role that it should play in developing transition requirements,” the GAO wrote.

https://www.c4isrnet.com/it-networks/2020/06/02/watchdog-says-pentagon-needs-better-planning-for-ip-update-17-years-after-first-attempt/

Sur le même sujet

  • The US Navy is seeking upgrades for the F-35 radar’s sea-search mode

    12 juin 2019 | International, Aérospatial, Naval

    The US Navy is seeking upgrades for the F-35 radar’s sea-search mode

    By: David B. Larter and Valerie Insinna WASHINGTON — The U.S. Navy wants more from the F-35 jet's radar, which in sea-search mode is limited to what is directly in front of the aircraft, according to documents exclusively obtained by Defense News. According to the documents, the radar, Northrop Grumman's AN/APG-81 active electronically scanned array radar, can either hone in on a sector based on a specific point on the ground, or work in what is commonly known as “snowplow mode,” which, as the name suggests, searches everything in front of the aircraft. The Navy wants to be able to scan a wider area when in sea-search mode, something that the radar is currently not set up for, according to officials who spoke to Defense News. Officials also said the problem is on track for a solution, but may not be implemented until as late as 2024 with the Block 4 upgrades, notably adding that a solution will not be in place before a full-rate production decision on the F-35 this year. Ultimately, giving the Navy what it wants will be a matter of boosting computing power and upgrading software, officials explained. The issue is listed as a category 1 deficiency, according to the documents, which further define the limitation as something that means “adequate performance [is] not attainable to accomplish the primary or alternate mission(s).” The issue dates back to 2012, according to the documents. In this scale, category 1 represents the most serious type of deficiency. It's unclear why the issue is listed as a deficiency. The system is working in accordance with design specifications, according to both the documents and a statement from a Lockheed Martin executive. “The F-35's current radar sea search function meets the enterprises' expressed required specification," said Greg Ulmer, Lockheed Martin's general manager of the company's F-35 program. “As we modernize the F-35, we are bringing enhanced search capabilities, which represent an increase from the original requirements, and we stand ready to integrate the upgrade in the future, based on customer priorities and direction.” In an interview with Defense News, the head of the Pentagon's F-35 program office, Vice Adm. Mat Winter, said the issue was being resolved by software and computing upgrades, and there would be no requirement for a new radar. “We're not mechanically scanning, we're electronically scanning,” Winter said. “And being able to accurately scan the maritime environment, it just takes increased computing power, and that's what we're doing. ... It's a software fix, and then an allocation of computing power.” Winter may be referring to a planned bundle of computer upgrades called Tech Refresh 3, where the jet will get more modern computing systems that will increase the jet's processing power and memory. According to one document obtained by Defense News, TR3 is a prerequisite for a future radar fix. Those TR3-equipped jets won't roll off the production line until 2023. Defense News submitted written questions to the Defense Department's F-35 program office concerning these and other deficiencies, but it did not respond by press time, despite multiple follow-ups over a period of months. A retired fighter pilot, who reviewed the documents for Defense News and agreed to speak on condition of anonymity, agreed with Winter's assessment that the fix was likely software-based. Early on in the F/A-18's APG-79 AESA radar, there were glitches in the operation, but software updates smoothed out the system. Fixing the APG-81 should follow a similar track as the aircraft progresses, the pilot explained. “As long as the array itself is technically sound, I suspect over time they'll be able to find ways to continue to build out capability through software updates,” the retired fighter pilot said. https://www.defensenews.com/smr/hidden-troubles-f35/2019/06/12/the-us-navy-is-seeking-upgrades-for-the-f-35-radars-sea-search-mode/

  • DoD ‘Office’ Functions Move To Cloud In Multi-Billion-Dollar Contract

    3 septembre 2019 | International, C4ISR

    DoD ‘Office’ Functions Move To Cloud In Multi-Billion-Dollar Contract

    By BARRY ROSENBERG WASHINGTON: Overshadowed by the dispute with DoD's planned single-award JEDI cloud contract is another multi-billion-dollar single-award cloud contract awarded today that will actually determine the software that military personnel and civil servants use every day. Under the $7.6 billion 10-year Defense Enterprise Office Solutions (DEOS) cloud contract, the Pentagon will use Microsoft productivity tools such as word processing, spreadsheets, email, collaboration, file sharing, and storage — Office 365. Those applications presently reside mostly on legacy desktop computers, and will transition to a cloud-based solution across all military services. The result should be improved cybersecurity, for one thing. “The notion is that if you have it professionally and centrally managed it should be better patched and configured than having hundreds of individually managed servers,” said David Mihelcic, former chief technology officer at the Defense Information Systems Agency (DISA) and now a consultant with DMMI. “This seems reasonable, but I don't think there is any cyber magic in DEOS either.” The joint General Services Administration/Defense Department DEOS blanket purchase agreement was awarded to CSRA (acquired by General Dynamics in April 2018 for $9.7 billion) and its subcontractors Dell Marketing (a wholesale distributor of computers, peripherals, and software) and Minburn Technology (a value added reseller that specializes in Microsoft enterprise software agreements). The award includes a five-year base period with two two-year options and one one-year option. “DOD's cloud strategy includes both general purpose and fit-for-purpose clouds (and) DEOS is a great example of a fit-for-purpose cloud that supports our multi-cloud strategy,” said DOD Chief Information Officer Dana Deasy in a statement. “DEOS will streamline our use of cloud email and collaborative tools while enhancing cybersecurity and information sharing based on standardized needs and market offerings. “The journey to the cloud has been, and will continue to be, an iterative learning process. All lessons learned from pilot programs and the department's early cloud adopters have been rolled into this solution. DEOS takes advantage of technical, security and contractual lessons from these ongoing pilots, while military services are leveraging them to assess the readiness of their infrastructure to support migration to DEOS.” DEOS includes voice, video, and text collaboration capabilities, which the DoD already has with capabilities under enterprise services like: Defense Collaboration Services (DCS), which provides secure web conferencing and instant messaging services on the Non-secure Internet Protocol Router Network (NIPRNet) and Secure Internet Protocol Routing Network (SIPRNet), and Extensible Messaging and Presence Protocol (XMPP) chat. “Will it be an improvement over the current capabilities? I guess we will see,” said Mihalcic. “I can't say I found the collaborative capabilities of O365 better than what we had in DoD.” While DEOS on the surface appears to provide a back-office function, it can also be considered a weapon system given that it will provide common enterprise applications at local base, post, camp, and station levels — including deployed and afloat organizations — over the sensitive but unclassified NIPRNet and the secret SIPRNet, to include operations in Denied, Disconnected, Intermittent, and Limited Bandwidth (D-DIL) environments. “I would say almost certainly (DEOS is a warfighting capability), especially the SIPR instance,” said Mihelcic. “DoD uses email, chat, and DCS collaboration in support of warfighting today and this will now take on those needs. “As for DIL environments, DISA had threshold requirements for deployable instances in the draft RFP. The vendor most likely will satisfy with existing MS Exchange and Sharepoint software on deployable servers. To be honest, I think that most tactical units, including deployed Marines and Navy afloat, will stick with what they have.” https://breakingdefense.com/2019/08/dod-office-functions-move-to-cloud-in-multi-billion-dollar-contract/

  • Défense : Merkel et Macron trouvent un accord pour renforcer leur coopération

    17 octobre 2019 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Défense : Merkel et Macron trouvent un accord pour renforcer leur coopération

    Les questions de défense ont dominé le conseil des ministres franco-allemand organisé à Toulouse. Un accord pour harmoniser les exportations d'armes a été annoncé. Face à l'accroissement des tensions dans le commerce international, les deux dirigeants ont aussi envoyé un message fort à Airbus. Par Grégoire Poussielgue Publié le 16 oct. 2019 à 19h15 Priorité à la défense. Le climat, les droits d'auteur et l'innovation ont, entre autres, été au menu du conseil des ministres franco-allemand qui s'est tenu mercredi à Toulouse, mais les questions de défense ont occupé une place prépondérante. Dans l'enceinte de la préfecture de Haute-Garonne, Emmanuel Macron et Angela Merkel ont pu lever les points de friction et aller plus loin dans leur politique commune de programmes d'armement. Les « blocages importants ont été levés » sur les programmes de développement du char et de l'avion de combat du futur, ont annoncé les deux dirigeants. La date de janvier 2020 a été retenue pour notifier les crédits tant attendus par les industriels de l'aéronautique qui visent la réalisation de prototypes à l'horizon 2025. La question sensible des exportations d'armes a aussi trouvé une issue. La France et l'Allemagne ont annoncé un accord « juridiquement contraignant sur les règles de contrôle d'exportations d'armement pour les programmes développés en commun ». Cet accord était indispensable pour mener à bien les programmes communs en matière d'armement. Un « résultat concret qui permettra davantage de sécurité », s'est félicitée la chancelière allemande. Un accord obtenu non sans mal car, depuis un an, les tensions sont fortes. Après l'assassinat, il y a tout juste un an, du journaliste saoudien Jamal Khashoggi, l'Allemagne a suspendu ses ventes d'armes vers l'Arabie Saoudite, ce que la France n'a pas fait. Avec l'invasion du Kurdistan syrien, les pays européens ont suspendu leurs exportations d'armes vers la Turquie. Symbole fort sur l'économie Entre Emmanuel Macron et Angela Merkel, il fallait aussi un geste symbolique fort pour marquer la solidité d'un couple franco-allemand « souvent mis à l'épreuve », comme le dit l'Elysée, et ce avant le Conseil européen de la fin de la semaine. Entre le dossier brûlant du Brexit et le rejet de la candidate française, Sylvie Goulard, à la Commission européenne , sans oublier les tensions commerciales croissantes avec les Etats-Unis, l'environnement européen traverse une zone de fortes turbulences. La relation franco-allemande n'y échappe pas. « J'entends parfois dire que la relation franco-allemande est difficile, c'est la situation du monde qui est difficile. S'il n'y avait que nous, les choses seraient plus simples et avanceraient plus vite », a dit le président français après le conseil. Pour le premier conseil des ministres franco-allemand depuis la signature, en janvier dernier, du traité d'Aix-la-Chapelle , qui renforce leur coopération, la chancelière allemande et le président français ont aussi manié le symbole. Avant les rencontres bilatérales et le conseil des ministres à la préfecture de Toulouse, les deux dirigeants ont longuement visité la chaîne de montage de l'A350 sur le site Airbus de Toulouse. Un symbole de « l'excellence européenne » selon le président français et un fer de lance de la coopération franco-allemande depuis un demi-siècle. Rassurer les salariés Après l'augmentation des droits de douane décidée par les Etats-Unis, il s'agissait aussi de rassurer les salariés français et allemands travaillant sur le site de Toulouse. « Nous tenions à venir aux côtés d'Airbus pour dire notre confiance dans l'entreprise et tout ce qui est devant elle. Vous allez construire le futur de cette entreprise. Il y a parfois des moments de doute et d'inquiétude mais c'est une entreprise formidablement solide », a déclaré Emmanuel Macron à l'occasion d'une rencontre avec les salariés. Angela Merkel y est aussi allée de son couplet. « Nous ferons tout pour garantir le succès de cette entreprise dans les années à venir », a-t-elle dit. https://www.lesechos.fr/monde/europe/defense-merkel-et-macron-trouvent-un-accord-pour-renforcer-leur-cooperation-1140681

Toutes les nouvelles