Digital Conflict

By Kevin Coleman

Blog archive

12 courses for a cyber warfare curriculum

Innovation and creativity require out-of-box thinking. That is what catches cyber defenders off guard and often makes the difference between a successful attack and failure. Given that observation, I was recently asked to think about what it would take for the Defense Department to fully integrate that characteristic into its cyber warriors.

First of all, out-of-box thinking runs counter to the traditional military mind-set that is created through current educational programs. Changing that mind-set will take time, and the only thing that can increase the rate of change is demonstrated success through the use of those characteristics.

Second, most cyber warfare training is highly focused on the technical aspects of cyberattacks, and that is a huge shortcoming. A broad background of understanding is needed that includes common operational user methods.

Third, we tend to view a cyberattack as an event. It is not. It is a multithreaded process that has internal recursive loops that incorporate operational feedback.

Using the three constructs above as a foundation, here are 12 programs that should be included in the core curriculum for advanced cyber warfare training.

1. Developing cyberattack strategy.
2. Identifying traditional and nontraditional points of attack.
3. Understanding the 43 current cyberattack vectors.
4. Working the cyberattack process.
5. Understanding tools and techniques supporting the attack process.
6. Using creativity and innovation in cyberattack design.
7. Understanding modular design of cyber weapons.
8. Knowing sources of cyberattack code for reuse and cloaking.
9. Target profiling and vulnerability announcement monitoring.
10. Social profiling of targets in support of social engineering.
11. Designing disinformation and misdirection in cyberattack code.
12. Designing counter cyber forensics in cyberattack code.

Those 12 courses would build the skills necessary for success in the offensive, defensive and intelligence collection areas in the military and intelligence communities and in many sectors of the defense industry.

However, education doesn’t stop there. The dynamics of the extended computer industry — including alternative devices — coupled with the rate of change we are seeing in cyberattack methods and techniques combine to make continuous education a necessity.

Posted by Kevin Coleman on Feb 08, 2011 at 12:12 PM


Featured

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

  • Comment
    Pilot Class. The author and Barbie Flowers are first row third and second from right, respectively.

    How VA is disrupting tech delivery

    A former Digital Service specialist at the Department of Veterans Affairs explains efforts to transition government from a legacy "project" approach to a more user-centered "product" method.

  • Cloud
    cloud migration

    DHS cloud push comes with complications

    A pressing data center closure schedule and an ensuing scramble to move applications means that some Homeland Security components might need more than one hop to get to the cloud.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.