How Does NSA Defend Critical Defense Networks?

33.6K views
July 18, 2018
by
RSAC Cybersecurity
YouTube video player
How Does NSA Defend Critical Defense Networks?

TL;DR

Effective cyber defense requires continuous operations, rapid response, interagency coordination, and preparation for compromised communication channels. NSA applies foreign intelligence insights to network protection, monitors threats around the clock, rejects suspicious email, counters scanning and exploitation, and coordinates remediation across military services. Defenders should expect disruptive attacks and newly disclosed vulnerabilities to be exploited quickly.

Transcript

So let's go ahead and start. Welcome, everyone. My name is Dave Hogue. I'm NSA's, uh, uh, represent NSA's Cybersecurity Threat Operations Center. And today you're gonna hear NSA's, one of our first public talks about our cybersecurity operations missions. My goal is whether you're a security practitioner or an executive, that we can provide some in... Read More

Key Insights

  • NSA cybersecurity operations combine foreign signals intelligence with information assurance, using knowledge of adversaries’ capabilities and intentions to defend the systems and networks entrusted to the agency and its partners.
  • Continuous cyber defense is necessary because serious incidents occur outside normal business hours. NSA replaced its limited nighttime watch model with fully staffed threat experts and defensive engineers operating twenty-four hours a day, seven days a week.
  • Cybersecurity is a team effort at NSA, with representatives from the Department of Energy, FBI, and DHS positioned on the operations floor so affected organizations can collaborate immediately instead of searching for contacts during an incident.
  • The Cybersecurity Operations Center covers tactical and strategic functions, including rule-based alerting, capability management, intelligence production, incident triage, and support for government responses to activity judged to violate international norms.
  • The Department of Defense unclassified network is mission-critical infrastructure serving three million users across office buildings and battlefields. It supports combat deployments, logistics, and delivery of intelligence, making its defense a no-fail responsibility.
  • Email is the leading intrusion vector described, accounting for a share comparable to the cited estimate that ninety percent of intrusion attempts begin with email. NSA receives thirty-six million emails daily and rejects roughly eighty-five percent.
  • New vulnerabilities can become operational threats within twenty-four hours. After the Apache web server vulnerability associated with the Equifax incident was released, a nation-state actor began scanning Department of Defense networks for unpatched servers within that period.
  • Russian operators can persist aggressively after discovery by restoring command-and-control infrastructure, reinstalling malware, and targeting administrators’ personal email accounts for remediation plans. Defenders confronting such activity need an out-of-band incident response plan.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How does NSA combine intelligence and cybersecurity defense?

NSA brings together its signals intelligence and information assurance missions through cybersecurity operations. Signals intelligence provides insight into foreign adversaries’ capabilities and intentions, while information assurance focuses on designing, building, and securing systems that may remain deployed for years. The operations center applies what NSA knows about adversaries to select and implement defenses for the networks it is responsible for protecting.

Q: Why does cyber defense require twenty-four-hour operations?

Cyber incidents do not follow normal business hours, and NSA found that its on-call experts were repeatedly summoned during nights and weekends. The agency therefore transformed a daytime-heavy operation with an overnight watch function into a continuously staffed center. Threat experts and defensive engineers now work around the clock so they can address nation-state activity, emerging technologies, and urgent defensive needs whenever they appear.

Q: How does interagency coordination improve cyber incident response?

Interagency coordination reduces the time needed to identify the correct contacts and begin joint action. Representatives from organizations including the Department of Energy, FBI, and DHS work directly on the NSA operations floor. If an event affects one of their networks or responsibilities, teams can immediately discuss the problem, combine their expertise, and coordinate a response without relying on an outdated contact list or delayed outreach.

Q: What happens when a cyber event reaches NSA’s operations center?

The Cybersecurity Operations Center initially triages an event and works it during the first twenty-four to seventy-two hours. Its responsibilities span tactical alerting and broader strategic support, including monitoring defensive capabilities, producing intelligence products, and recognizing activity relevant to government declarations. Products can range from classified assessments of nation-state actors to unclassified signatures that partners can deploy on their own networks.

Q: What are the main intrusion vectors affecting Defense Department networks?

The two leading intrusion vectors identified are email and scanning. NSA handles thirty-six million emails each day and rejects about eighty-five percent based on known signatures or suspected new threat activity. Attackers also scan for vulnerable internet-facing systems, often acting rapidly after a vulnerability becomes public. These patterns make email filtering, threat detection, vulnerability management, and prompt patching central defensive priorities.

Q: How quickly can attackers exploit newly disclosed vulnerabilities?

Attackers can weaponize and use a newly released exploit or vulnerability within twenty-four hours, according to the operational pattern described. When the Apache web server vulnerability later associated with the Equifax incident was released in March, a nation-state actor began scanning for unpatched Department of Defense servers within twenty-four hours. Defenders therefore cannot assume that public disclosure provides a long preparation window.

Q: How do NSA and US Cyber Command respond to detected intrusions?

NSA and US Cyber Command operate a tier-one intrusion detection and response system for unclassified Department of Defense networks. They can monitor traffic passively and take active measures such as blocking connections, redirecting activity, or sending suspicious material to a sandbox for analysis. Cyber Command then coordinates downstream action with the Marines, Army, Navy, and Air Force, including removing affected computers and servers.

Q: How should defenders prepare for persistent Russian cyber operations?

Defenders facing a known Russian actor should prepare an out-of-band incident response plan because the attacker may compromise ordinary communication channels and resist removal. In the Department of State intrusion described, operators replaced disabled command-and-control addresses, reinstalled malware after removal, and targeted administrators’ personal email accounts to obtain remediation plans. Response coordination must therefore remain secure even when primary networks and accounts cannot be trusted.

Summary & Key Takeaways

  • NSA’s Cybersecurity Threat Operations Center combines signals intelligence with information assurance to defend critical networks. Its teams use knowledge of foreign adversaries’ capabilities and intentions to guide protective measures, produce actionable intelligence at the lowest practical classification, manage defensive capabilities, and initially handle major incidents for twenty-four to seventy-two hours.

  • The center shifted from a daytime-focused operation with an overnight watch function to a fully staffed twenty-four-hour presence. Threat specialists and defensive engineers now address nation-state activity and emerging technologies continuously, while representatives from agencies including the Department of Energy, FBI, and DHS collaborate directly on incidents affecting their missions.

  • Email and scanning are the leading intrusion vectors discussed. NSA processes thirty-six million emails daily and rejects about eighty-five percent using known signatures or indicators of suspected new threats. Newly disclosed vulnerabilities can be weaponized within twenty-four hours, making rapid patching, active countermeasures, coordinated remediation, and resilient incident communications essential.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚