Intelligence

Making the cloud safe for intel

Shutterstock image: cloud infrastructure.

The intelligence community’s research organization is seeking ideas on how to make virtual computing environments more secure.

The Intelligence Advanced Research Projects Activity is planning a broad agency announcement for September for a project that could enhance data protection in the intelligence community's private cloud and have larger ramifications for unclassified government data stored on public clouds.

The project, dubbed Virtuous User Environment (VirtUE), was inspired by the long-running shift from desktop boxes to virtual computing, IARPA Program Manager Kerry Long said.

Speaking at FCW's Cloud Summit on Aug. 10, Long said one of the flaws of virtualization is that it is almost too exact. It "copied all the problems" found in traditional desktops, he said, and security measures designed to segregate data on a virtual machine are potentially vulnerable.

IARPA is seeking a computing environment that can run on a cloud or other virtualized infrastructure without interfering with internal operations, collect log data on users and act as a sensor for threat detection. A "virtue" could also surround individual applications or computing roles to, for example, segregate email from the wider internet with the goal of making phishing attacks less threatening or to govern the activities of a router or peripheral device.

Additionally, it must run on an Amazon Web Services hypervisor -- as Amazon is the cloud platform of choice for the intelligence community.

Long said he hopes the ideas from researchers and academics will yield a new approach that will reduce the amount of log data generated and collected in the intelligence community. For instance, improved sensor capabilities would mean that a "virtue" could collect log data only in response to certain suspicious activity rather than collecting data on every event. That approach could enhance the use of analytics to process insider threat data.

Officials envision having a three-phase program. A formal announcement for the first phase is expected next month. 

About the Author

Adam Mazmanian is executive editor of FCW.

Before joining the editing team, Mazmanian was an FCW staff writer covering Congress, government-wide technology policy, health IT and the Department of Veterans Affairs. Prior to joining FCW, Mr. Mazmanian was technology correspondent for National Journal and served in a variety of editorial roles at B2B news service SmartBrief. Mazmanian started his career as an arts reporter and critic, and has contributed reviews and articles to the Washington Post, the Washington City Paper, Newsday, Architect magazine, and other publications. He was an editorial assistant and staff writer at the now-defunct New York Press and arts editor at the About.com online network in the 1990s, and was a weekly contributor of music and film reviews to the Washington Times from 2007 to 2014.

Click here for previous articles by Mazmanian. Connect with him on Twitter at @thisismaz.


Rising Stars

Meet 21 early-career leaders who are doing great things in federal IT.

Featured

  • SEC Chairman Jay Clayton

    SEC owns up to 2016 breach

    A key database of financial information was breached in 2016, possibly in support of insider trading, said the Securities and Exchange Commission.

  • Image from Shutterstock.com

    DOD looks to get aggressive about cloud adoption

    Defense leaders and Congress are looking to encourage more aggressive cloud policies and prod reluctant agencies to embrace experimentation and risk-taking.

  • Shutterstock / Pictofigo

    The next big thing in IT procurement

    Steve Kelman talks to the agencies that have embraced tech demos in their acquisition efforts -- and urges others in government to give it a try.

  • broken lock

    DHS bans Kaspersky from federal systems

    The Department of Homeland Security banned the Russian cybersecurity company Kaspersky Lab’s products from federal agencies in a new binding operational directive.

  • man planning layoffs

    USDA looks to cut CIOs as part of reorg

    The Department of Agriculture is looking to cut down on the number of agency CIOs in the name of efficiency and better communication across mission areas.

  • What's next for agency cyber efforts?

    Ninety days after the Trump administration's executive order, FCW sat down with agency cyber leaders to discuss what’s changing.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group