{"id":61105,"date":"2019-11-14T17:33:01","date_gmt":"2019-11-14T09:33:01","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/satellite-providers-stymied-by-lack-of-cyber-standards\/"},"modified":"2019-11-14T17:33:01","modified_gmt":"2019-11-14T09:33:01","slug":"satellite-providers-stymied-by-lack-of-cyber-standards","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/satellite-providers-stymied-by-lack-of-cyber-standards\/","title":{"rendered":"Satellite Providers Stymied by Lack of Cyber Standards"},"content":{"rendered":"<\/p>\n<p>Satellite companies vying to sell to the government and defense markets know their prospective customers want them to be cyber-secure, but the absence of industry standards and guidance leaves them scratching their heads about exactly how secure they need to be, and how best to attain that level of cybersecurity.<\/p>\n<p>That was the take away from a panel of experts on the government and defense markets at CyberSat last week.<\/p>\n<p>\u201cThe question everyone has been asking here, and they\u2019re asking it at other (space industry) conferences I\u2019ve attended, is: What do we need to do to secure our space assets?\u201d noted Harrison Caudill, founder of the non-profit <strong>Orbital Security Alliance<\/strong>.<\/p>\n<p>The answers tended to be couched in generalities, he said, but \u201cThere are specific things we know can be done\u201d to harden space-based systems against cyberattack.<\/p>\n<p>The Alliance, he said, was in the process of drafting very detailed and specific standards and practices that satellite operators and service providers could use to ensure their enterprises met the highest levels of cybersecurity. He said that the non-profit hoped to publish an initial version early next year, for feedback and input from industry. Eventually, he added, the alliance hoped the use of the standards would be made mandatory by federal legislation and he said the group would lobby Congress to make that happen.<\/p>\n<p>\u201cIt\u2019s not a perfect solution, it\u2019s not a permanent solution,\u201d he said, \u201cBut it\u2019s an important first step.\u201d<\/p>\n<p>Part of the problem satellite companies face is uncertainty about which products work best, acknowledged Ron Bushar, vice president and CTO for government solutions at cybersecurity stalwart <strong>FireEye<\/strong>.<\/p>\n<p>It wasn\u2019t a problem unique to the satellite industry, he added.<\/p>\n<p>\u201cThe state of cybersecurity from a vendor perspective is pretty broken right now,\u201d he said. \u201cThere\u2019s a lot of money that\u2019s going into the sector \u2026&nbsp;and it\u2019s following a traditional Silicon Valley (venture capital) of model of \u2018Let\u2019s bet on a lot of different ideas and see what comes out best.\u201d But, he added, while that\u2019s a great approach for, say, ride-sharing apps \u2014 \u201cwhen one fails, there\u2019s another one right behind it\u201d \u2014 it\u2019s a major problem when dealing with security.<\/p>\n<p>\u201cCybersecurity architectures, first, have to work. They have to protect you effectively. And two, they have to (be able to) reside in place for many years. There\u2019s a significant investment both in money and time. If you pick the wrong technology \u2026 you\u2019ll experience cascading effects for many years.\u201d<\/p>\n<p>CISOs and other executives tasked with defending their company\u2019s IT often complain privately that there\u2019s a bewildering variety of cybersecurity technologies and approaches; and no real objective measurements of how effective they are \u2014 leaving potential buyers at the mercy of marketing buzzwords.<\/p>\n<p>Worse, Bushar acknowledged, when companies try to hedge their bets by buying from more than one vendor, the different products often don\u2019t work with each other. \u201cYou have all these solutions that don\u2019t integrate well, that don\u2019t talk to each other \u2014 it\u2019s a highly competitive landscape.\u201d<\/p>\n<p>At least government and defense officials now recognize the problem, noted Robert Vick, program manager for the Space Protection and Response Program at the <strong>Air Force Research Laboratory<\/strong>. \u201cWe spent the first three or four years trying to convince people in the government that this was a real problem and that you could not just make it all go away with National Security Agency (NSA) encryption. And then about six months, a year ago, there was this pivot on a dime and now everyone is like, \u2018Okay, we get it, we believe you, now what do we need to do?\u201d<\/p>\n<p>Part of that change of heart was connected to the growing use by military and other agencies of commercially provided satellite communications, he said. \u201cWhen I\u2019m using something that wasn\u2019t designed and built for me and may not be operated by me, how do the rules change? How does our mindset have to change?\u201d he asked.<\/p>\n<p>A big part of his challenge, Vick added, was having to \u201ctranslate cyber-speak for the space community,\u201d as there was little common ground on vocabulary.<\/p>\n<p>And the translation problem exists in both directions, he explained, because traditionally space assets were built with very different architectures than conventional IT, which often meant that commodity cybersecurity solutions didn\u2019t work. \u201cImplementation-wise, space is special,\u201d he said.<\/p>\n<p>Historically, noted Bushar, there\u2019s been \u201ca natural barrier to traditional cyberattacks (against space systems) because you\u2019re dealing with legacy (IT) architectures that are very esoteric and now well understood\u201d outside of a very small community of specialists.<\/p>\n<p>That same \u201csecurity by obscurity\u201d model was long touted by the users of industrial control systems, or ICS \u2014 the highly specialized software that runs machinery for factories, refineries, chemical plants and power generation facilities.<\/p>\n<p>As in control system environments, Bushar said, \u201cThe risk point tends to come at the seams, where those specialized architectures are integrated with conventional IT systems\u201d which are vulnerable to hackers.<\/p>\n<p>But a new generation of small satellites \u2014 mass produced much more cheaply than traditional birds \u2014 was changing that paradigm, said Vick. \u201cWe\u2019re at an inflection point in the industry,\u201d he pointed out.<\/p>\n<p>That commoditization represented a tremendous opportunity for the industry, argued Caudill. \u201cRight now everyone has to do everything\u201d on their own. Each company in the market has \u201cto figure out how to do their own communications, their own encryption, their own key management, (their own) system operations (and their own) licensing, everything.<\/p>\n<p>\u201cThis is enormously expensive, time consuming and injects enormous business risk,\u201d he said.<\/p>\n<p>But in fact, most operators only needed an ability to communicate with their satellite and a way to get their data back from it and could be agnostic about that is achieved. \u201cFor the most part, you don\u2019t care how that happens,\u201d Caudill said, \u201cIt could be smoke signals\u201d as long as it enables your mission.<\/p>\n<p>With more common architectures between different satellite operators, and with this agnosticism about how to communicate, \u201cWe can concentrate our cybersecurity controls into a few managed service providers\u201d that then provide secure communication and control to the market.<\/p>\n<p>\u201cThat will lock down 80 percent of our attack surface,\u201d and will end up being less expensive for the operators. \u201cWe can save the market money and make them more secure,\u201d he said.<\/p>\n<p>The scale of the challenge was huge, he added, and went way beyond the government and defense sectors. Nation state adversaries could target small providers, too cash strapped to pay out for cybersecurity. And the fact that they might be too small or cyber-insecure to win government or military work didn\u2019t diminish their value to U.S. adversaries.<\/p>\n<p>\u201cEven our smallest startup is leveraging billions of dollars of R&amp;D spending that they have not had to do,\u201d he said. \u201cNorth Korea can\u2019t launch satellites, but they can hack.\u201d And that could get them access to overhead surveillance capabilities that would be completely beyond their reach otherwise.<\/p>\n<p>\u201cThis is in no uncertain terms a national security disaster,\u201d he concluded.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Satellite companies vying to sell to the government and defense markets know their prospective customers want them to be cyber-secure, but the absence of industry standards and guidance leaves them scratching their heads about exactly how secure they need to be, and how best to attain that level of cybersecurity. That was the take away [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61109,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-61105","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/61105"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=61105"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/61105\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/61109"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=61105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=61105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=61105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}