Tactical Data Links (TDL) and Computer Science meet usually when it comes to interoperability and implementation. However looking at it from an IT security perspective, some interesting issues occur. These become more relevant the more military hard- and software is built using commercial of the shelf (COTS) systems, that are usually implemented using standard Internet technology and software development patterns. This paper looks at Link 16, Link 11 and VMF security considerations and how compatible they are to current IT security standards. Typical security issues are discussed and concepts to mitigate them presented, which however need to be analysed for their suitability to TDL.
This article is a report of the IFIP AIMS 2016, which was held at Universität der Bundeswehr München, Germany from June 20 to June 23, 2016. AIMS 2016 focused on the theme “Management and Security in the Age of Hyperconnectivity”. The AIMS conference positions itself in the network management community as an educational venue for young researchers and Ph.D. students. The AIMS program included keynotes, technical sessions and Ph.D. Workshop sessions, but also hands-on labs and an educational panel for training young academics. The highlights on each of the parts of the AIMS 2016 program are summarized in this article.
Computing centers of small and mid-sized companies, experimental labs of IT research institutes or IT training centers nowadays all have one thing in common: the complexity of their systems and the need for running these systems securely increases dramatically. Routers, switches, firewalls, intrusion detection systems, monitoring services, various sensors and other IT security components are just a few systems modern computing centers have to run. The operators of these computing centers can hardly be experts in all of these systems and they are challenged by dynamic and fast moving IT services and network infrastructures. Furthermore, the lack of well-trained personnel for administrating these systems exacerbates the problem of securely running such complex systems given the fact of increasing number of security attacks onto them. To overcome this problem we present a concept and an architecture to support operators of computing centers and lab environments in their daily work in a new, machine supported and semi virtualized way in order to achieve a higher level of security, a better situational awareness and faster response time for (security) incidents. But even more demanding is the decision making process itself, as many decisions are not made by technical experts but by the management level. Thus, our architecture also integrates decision makers - non IT-experts or technicians - in this process. Based on high level visualization of operative effects and outcomes to the management, e.g. impact of compromised and attacked systems or system failures on the business, our new architecture for a level-appropriate processing and visualization of complex information and data, assists to bridge the gap between the language of the technician and the decision maker in order to take time critical and constructive decisions.
Military operations heavily rely on tactical data links to exchange command and control data allowing participants to gain an understanding of the operational situation. Since today most operations involve multiple nations cooperating on a mission these tactical data links are standardised e.g. as a NATO STANAG. However these standards are very complex and regularly updated to reflect technological advances. Therefore implementing TDL systems adhering to these standards is a very complex and error prone process. By supporting a NATO group developing an XML implementation of TDL standards and providing a toolset to implement a multi TDL capable system configured using these XML-TDL-specifications, the authors demonstrate how to shorten this process and allow for a completely automated implementation of TDL-STANAGs.
In the area of military simulations, a multitude of different approaches is available. ”Close Combat Tactical Trainer”, ”Joint Tactical Combat Training System”, ”Battle Force Tactical Training” or ”Warfighter’s Simulation 2000” are just some examples within the history of the large DoD Development Program in Modelling and Simulation, representing just a small piece of the variety of diverse solutions. Very often, individual simulators are very unique and so it is often difficult to classify military simulations even for experienced users. This circumstance is further boosted due to the fact that in the field of military simulations - unlike in other areas - no general classification for military simulations exists. To address this shortcoming, this publication is dedicated to the idea of providing a first contribution to the development of a commonly accepted taxonomy in the area of military simulations. To this end, the problem field is structured into three main categories (general functional requirements for simulators, special military requirements for simulators and non-functional requirements for simulators). Based upon that, individual categories are provided with appropriate classes. For a better understanding, the taxonomy is also applied to a concrete example (NetLogo Rebellion).
Throughout the last couple of years network forensics has gained higher importance due to the ever-growing quantity and quality of attacks. In contrast to conventional network forensics which relies on a central approach, both legal as well as technical guidelines nowadays favor a decentralized approach since aspects like privacy, limited data manipulation possibilities and scalability are addressed superiorly there. In this regard, however, present (decentralized) solutions are all in the need of an improvement especially in the area of protection against manipulation, i.e., falsification of relevant forensics data particularly in case of sophisticated attacks. Following the idea of strategic pre-incident preparation, this publication presents a decentralized approach, which, in advance, selectively collects data based on the suspiciousness of the connection to facilitate a (possible) investigation. To this end, we present an agent-based framework including prototype and evaluation that particularly uses Geolocation to fulfill this task.