featured

WASHIGTON — While US officials have warned of munitions shortfalls from the Iran conflict, the Navy’s top cyber official identified another key observation from recent military operations: the “cyber magazine” can be vulnerable to exhaustion as well.

“Your cyber magazine of these exquisite fires is empty pretty damn quick,” Vice Adm. Heidi Berg, commander of Fleet Cyber Command/10th Fleet, said in response to a question regarding lessons from Russia’s invasion of Ukraine and US operations in Venezuela, the Middle East and elsewhere.

“How are you going to regenerate and continue to develop accesses and effects to be able to deliver over the course of what will almost always be against a peer competitor, a longer-term sustained conflict?” she added, speaking at HammerCon, hosted by the Military Cyber Professionals Association on Thursday.

Berg did not go into details, but officials and experts for years have acknowledged that cyber capabilities and bespoke exploit tools are not limitless, necessarily reusable or easy to come by: once an adversary, or company, patches a flaw in a system, the tactic can become obsolete. They also can’t be replenished like traditional munitions with an infusion of money and production lines, given it requires time and skill to discover exploits and develop the tools to take advantage of them.

While the debate about a shortfall in physical munitions has splashed across headlines, the status of America’s cyber munitions has remained largely out of the public eye, especially in the context of operations in Iran. Cyber has often been thought of as a persistent, daily contest below the threshold of armed conflict, but now the US has found itself in sustained combat operations in cyberspace since the launch of Operation Epic Fury (OEF).

“From an OEF perspective, just to put in perspective, so 28 February, and it hasn’t stopped. Probably for the first time for the cyber force at large, it’s been this constant,” Lt. Gen. Christopher Eubank, commander of Army Cyber Command and the cyber official charged with running cyber operations in the Middle East, said during the same event.

After Epic Fury initially kicked off, experts told Breaking Defense that in one-off operations such as Absolute Resolve that captured Venezuelan leader Nicholas Maduro — which Berg described Thursday as “the largest and most complex cyber operation that had ever been executed” — perpetual access isn’t always as big a concern as sustaining a military campaign over time.

But Jason Kikta, a former cyber operator with CYBERCOM, told Breaking Defense today that access was the “real asset” in cyber operations and agreed that it is “quickly expended and slow to replenish.”

With sustained activity in Epic Fury, there will be many missions that will evolve and change parameters and priorities as the battlefield and cyberspace evolves, while American hackers will be working around the clock to find more accesses. But, there’s still always the question of what to do once accesses are gained: continue to gather intelligence, or to break something, which almost certainly eliminates the ability for cyber to impact that target again while also closing any intelligence value.

As far as the price tag for developing ever-newer cyber capabilities, US Cyber Command, in an unfunded priorities list sent to Congress earlier this year, requested an additional $229 million for scaling cyber operational capacity and the development and deployment of cyber munitions, according to InsideDefense. Those funds would go toward limitations in CYBERCOM’s ability to generate and sustain cyber effects at speed and scale, the publication reported.

Source: www.breakingdefense.com

0

Your email address will not be published. Required fields are marked *

0/30 character