AVIONICS CYBER TEST AND EVALUATION

Similar documents
RDT&E BUDGET ITEM JUSTIFICATION SHEET (R-2 Exhibit)

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

UNCLASSIFIED FY 2016 OCO. FY 2016 Base

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE D8Z: Central Test and Evaluation Investment Program (CTEIP) FY 2011 Total Estimate. FY 2011 OCO Estimate

Cybersecurity TEMP Body Example

CYBER SECURITY PROTECTION. Section III of the DOD Cyber Strategy

UNCLASSIFIED R-1 ITEM NOMENCLATURE

Test and Evaluation in Acquisition of Capabilities

New DoD Approaches on the Cyber Survivability of Weapon Systems

Headquarters U. S. Air Force. The Air Force s Perspective

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE D8Z: Central Test and Evaluation Investment Program (CTEIP) FY 2012 OCO

UNCLASSIFIED FY 2016 OCO. FY 2016 Base

FIGHTER DATA LINK (FDL)

17 th ITEA Engineering Workshop: System-of-Systems in a 3rd Offset Environment: Way Forward

AGI Technology for EW and AD Dominance

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

UNCLASSIFIED R-1 ITEM NOMENCLATURE FY 2013 OCO

UNCLASSIFIED R-1 ITEM NOMENCLATURE

UNCLASSIFIED. UNCLASSIFIED Army Page 1 of 7 R-1 Line #9

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

UNCLASSIFIED. UNCLASSIFIED Air Force Page 1 of 8 R-1 Line #86

SPS-TA THALES AIRBORNE SYSTEMS INTEGRATED SELF-PROTECTION SYSTEM FOR TRANSPORT AND WIDE-BODY AIRCRAFT.

UNCLASSIFIED R-1 ITEM NOMENCLATURE

UNCLASSIFIED. UNCLASSIFIED Navy Page 1 of 12 R-1 Line #147

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE BB: Special Operations Aviation Systems Advanced Development

GOOD MORNING I D LIKE TO UNDERSCORE THREE OF ITS KEY POINTS:

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE A: Landmine Warfare and Barrier Advanced Technology FY 2012 OCO

F-16 Fighting Falcon The Most Technologically Advanced 4th Generation Fighter in the World

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE D8Z: Central Test and Evaluation Investment Program (CTEIP) FY 2013 OCO

Exhibit R-2, RDT&E Budget Item Justification

Exhibit R-2, RDT&E Budget Item Justification February 2007

UNCLASSIFIED R-1 ITEM NOMENCLATURE

Cybersecurity FY16 CYBERSECURITY. Cybersecurity 441

ARMY RDT&E BUDGET ITEM JUSTIFICATION (R2 Exhibit)

Air Force intelligence, surveillance, and reconnaissance (ISR)

UNCLASSIFIED. Cost To Complete Total Program Element Continuing Continuing : Physical Security Equipment

UNCLASSIFIED R-1 ITEM NOMENCLATURE

Cybersecurity United States National Security Strategy President Barack Obama

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE F: Requirements Analysis and Maturation. FY 2011 Total Estimate. FY 2011 OCO Estimate

First Announcement/Call For Papers

Department of Defense DIRECTIVE. SUBJECT: Electronic Warfare (EW) and Command and Control Warfare (C2W) Countermeasures

AMRDEC. Core Technical Competencies (CTC)

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE F: Major T&E Investment. FY 2011 Total Estimate. FY 2011 OCO Estimate

Test and Evaluation of Highly Complex Systems

SYSTEM DESCRIPTION & CONTRIBUTION TO JOINT VISION

Exhibit R-2, RDT&E Budget Item Justification

UNCLASSIFIED. FY 2017 Base FY 2017 OCO

UNCLASSIFIED. UNCLASSIFIED Air Force Page 1 of 13 R-1 Line #68

Castles in the Clouds: Do we have the right battlement? (Cyber Situational Awareness)

DISTRIBUTION STATEMENT A

Inside the Beltway ITEA Journal 2008; 29: Copyright 2008 by the International Test and Evaluation Association

UNCLASSIFIED. UNCLASSIFIED R-1 Line Item No. 2 Page 1 of 9

Navy Information Warfare Pavilion 19 February RADM Matthew Kohler, Naval Information Forces

UNCLASSIFIED FY Quantity of RDT&E Articles

AGENCY: Defense Security Cooperation Agency, Department of Defense.

An Enterprise Environment for Information Assurance / Computer Network Defense Testing and Evaluation

Detect, Deny, Disrupt, Degrade and Evade Lethal Threats. Advanced Survivability Suite Solutions for Mission Success

UNCLASSIFIED R-1 ITEM NOMENCLATURE

JOINT SURVEILLANCE TARGET ATTACK RADAR SYSTEM (JSTARS) E-8C AND COMMON GROUND STATION (CGS)

U.S. Air Force. AF Cyber Resiliency Office for Weapon Systems (CROWS) I n t e g r i t y - S e r v i c e - E x c e l l e n c e

UNCLASSIFIED R-1 ITEM NOMENCLATURE FY 2013 OCO

ISR Full Crew Mission Simulator. Intelligence, Surveillance and Reconnaissance Capabilities for Airborne and Maritime Live Mission Training

The Verification for Mission Planning System

Office of the Under Secretary of Defense for Acquisition, Technology, and Logistics

Huntsville Aerospace Marketing Association (HAMA)

AMPS - Airborne Missile Protection System

Exhibit R-2, RDT&E Budget Item Justification

Request for Solutions: Distributed Live Virtual Constructive (dlvc) Prototype

ARMY MULTIFUNCTIONAL INFORMATION DISTRIBUTION SYSTEM-LOW VOLUME TERMINAL 2 (MIDS-LVT 2)

F/A-18 E/F SUPER HORNET

UNCLASSIFIED UNCLASSIFIED

Air Force intelligence, surveillance, and reconnaissance (ISR)

UNCLASSIFIED R-1 ITEM NOMENCLATURE FY 2013 OCO

STATEMENT OF. MICHAEL J. McCABE, REAR ADMIRAL, U.S. NAVY DIRECTOR, AIR WARFARE DIVISION BEFORE THE SEAPOWER SUBCOMMITTEE OF THE

B-1B CONVENTIONAL MISSION UPGRADE PROGRAM (CMUP)

3 rd Annual Electromagnetic Spectrum Operations Summit

The Future of Cyber Experimentation and Testing

Headquarters U.S. Air Force

Public Affairs Guidance

Exhibit R-2, RDT&E Budget Item Justification February 2008

Middle Tier Acquisition and Other Rapid Acquisition Pathways

UNCLASSIFIED. UNCLASSIFIED R-1 Line Item No. 3 Page 1 of 15

Industry Day RDML Mat Winter Commander, Naval Air Warfare Center Weapons Division. 23 May 2012

Interoperability Testing Using the Hardware-in-the-Loop Test Tool

Radar Open Systems Architectures

UNCLASSIFIED. UNCLASSIFIED Air Force Page 1 of 15 R-1 Line #32

UNCLASSIFIED. UNCLASSIFIED Air Force Page 1 of 6 R-1 Line #62

Chapter 13 Air and Missile Defense THE AIR THREAT AND JOINT SYNERGY

UNCLASSIFIED R-1 ITEM NOMENCLATURE

UNCLASSIFIED. R-1 Program Element (Number/Name) PE A / Landmine Warfare and Barrier Advanced Technology. Prior Years FY 2013 FY 2014 FY 2015

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE F: C2ISR Tactical Data Link FY 2012 OCO

Bay Area UASI. Introduction to the Bay Area UASI (Urban Areas Security Initiative) Urban Shield Task Force Meeting

UNCLASSIFIED. FY 2016 Base FY 2016 OCO

GAO ELECTRONIC WARFARE. The Army Can Reduce Its Risks in Developing New Radar Countermeasures System. Report to the Secretary of Defense

EW Modeling and Simulation: Meeting the Challenge

UNCLASSIFIED. FY 2017 Base FY 2017 OCO

NAVAL AIR SYSTEMS COMMAND RESEARCH AND ENGINEERING GROUP & NAVAL AIR WARFARE CENTER AIRCRAFT DIVISION

UNCLASSIFIED R-1 ITEM NOMENCLATURE. FY 2014 FY 2014 OCO ## Total FY 2015 FY 2016 FY 2017 FY 2018

Cyber Resiliency FAQ

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE F: Multi-Platform Electronics

Transcription:

AVIONICS CYBER TEST AND EVALUATION Joseph Nichols, PhD Technical Advisor for Flight Test and Evaluation Air Force Test Center Edwards AFB CA joseph.nichols.13@us.af.mil 1

Defining avionics cyber testing Cyber T&E process Infrastructure requirements Manpower requirements Summary OUTLINE 2

Traditional IT Industrial Control Systems Platforms CYBERSPACE CATEGORIES 3

Traditional IT Industrial Control Systems Platforms Aircraft avionics and weapons CYBERSPACE CATEGORIES 4

= AVIONICS SYSTEMS ARE DIFFERENT FROM STANDARD PCS AND NETWORKS 5

DOD CYBERSECURITY TEST AND EVALUATION GUIDEBOOK 6

DOD direction to conduct a cybersecurity evaluation of all major US weapon systems Testing must be completed by Dec 2019 Combined vulnerability identification phase Planning combined DT/OT testing NDAA SECTION 1647 7

Vulnerability Identification Phase (Phases 1-2) Cooperative DT/OT (Phases 3-5) Adversarial Assessment (Phase 6) CURRENT PROCESS 8

Specific Requirements Identified in program documentation, e.g., ICDs/CDDs, CONOPS, Product Specifications Implied Requirements Can the system perform its mission in a cyber contested environment? REQUIREMENTS 9

DEFINING THE ATTACK SURFACE 10

Avionics Wheel of Access RF VULNERABILITY IDENTIFICATION 11

Severity of Effect Adversary Accessibility/Capability EVALUATING SUSCEPTIBILITY TO CYBER ATTACK 12

Severity of Effect Most severe threats to be further evaluated in combined DT/OT Adversary Accessibility/Capability EVALUATING SUSCEPTIBILITY TO CYBER ATTACK 13

Evaluation of the system s cybersecurity in a mission context, using realistic threat exploitation techniques, while in a representative operating environment Characterize operational cybersecurity status and determine residual risk COOPERATIVE DT/OT TEST AND EVALUATION 14

To assess the system s defensive cyberspace performance in the operational environment to withstand threat representative cyber-attacks, detect and react to those attacks, and return to normal operations in the event of a successful cyber-attack ADVERSARIAL ASSESSMENT 15

16

DoD test facility capable of conducting cyber testing compatible with the unique features of aircraft avionics and airborne munitions Center of Excellence for avionics cyber T&E and developer of cyber test techniques and test tools Connected with the NCR and other aircraft and weapons cyber test facilities AVIONICS CYBER TEST INFRASTRUCTURE 17

1. Ability to stimulate avionics components to put them in flight modes 2. Ability to provide standard interfaces for avionics busses, radars, data links, radios, mission planning, software loaders, maintenance systems, weapons, sensors, etc. 3. Ability to work with actual aircraft/weapons, real subsystems, emulations, or re-hosted software (requires flight line access) 4. Ability to stimulate sensors through direct injection, or through system apertures (requires anechoic chamber) 5. Test tools capable of penetrating avionics components and returning them to pre-test conditions 6. Realistic threat emulation 7. Multi-level security environment 8. Mobile test tools/procedures for testing in other HITLs AVIONICS CYBER RANGE REQUIREMENTS 18

Cyber T&E expertise for aircraft and weapons requires a merge of traditional avionics test expertise and computer network penetration expertise Sending avionics test engineers to cyber training Developing DOD cyber training courses Standing up new test organization dedicated to all aspects of cyber test and evaluation networks, aircraft, weapons MANPOWER REQUIREMENTS 19

Systems becoming increasingly difficult to defend against emerging cyber threats Cybersecurity T&E should not be treated as a separate process. It should be integrated into the normal system development just as we test functionality and performance New class of test facilities and test tools must be developed to test aircraft avionics and airborne weapon systems New T&E discipline of avionics-cyber tester under development SUMMARY 20

QUESTIONS 21