Sea Control - Sea Control 366 - Cybersecurity and Strategic Sealift with Jason Ileto

Episode Date: July 28, 2022

Links: Cyber at Sea: Protecting Strategic Sealift in the Age of Strategic Competition, by Jason Ileto, Modern War Institute, May 10, 2022. ...

Transcript
Discussion (0)
Starting point is 00:00:00 Hey, folks, it's Jared. Today, my guest is Jason Aletto, and we're going to be discussing cybersecurity, cyberattacks, and strategic sea lift. This episode was edited and produced by Dr. Ed Salo. I'd like to pause here to highlight our local chapters. Whether you're in South Korea, Egypt, Singapore, France, New York, India, or the Caribbean, chances are there's a SimSec local chapter near you. You can find a full listing of our chapters and contact information on the website at simsec.org. So if you're interested, please reach out and get involved. Finally, I want to take the opportunity to recommend our partners in the SimSec Podcast Network, The Bilge Pumps. You can find Alex, Jamie, Drack, and a pile of iron brew bottles wherever you download your podcasts.
Starting point is 00:00:37 With that, Kimber's Men. You're listening to Sea Control, hosted by the Center for International Maritime Security. Aloha, shoemates, and welcome back aboard Sea Control. My guest today is Jason Aleto, and we'll be discussing his article for Modern War Institute's Competition in the Cyberspace Project, Cyber at Sea, Protecting Strategic Sealift in the Age of Strategic Competition. So, Jason, welcome. Could you introduce yourself to the listeners, please? Sure. Thanks, Jared, and thanks for having me. I'm Jason Aleto, a student, at least for the next two weeks, at the Naval War College in Newport, Rhode Island, where I'm also involved with the Cyber and Innovation Policy Institute. I was selected to participate in the Vice Admiral Gravely program.
Starting point is 00:01:26 It's an advanced research program. And the article that I wrote that we're going to discuss today is one of the products of my research. I'm a supply officer in the United States Navy with a data analysis and operations research background. And I've served a couple tours related to SEALIFT. Well, thank you for joining us. As a reminder, all opinions are our own and not reflective of any institution with which we might be otherwise associated. So, Jason, what's the importance of military sea lift to the U.S., both in peacetime and wartime? Okay, so first, let's start with peacetime.
Starting point is 00:02:01 So, well, first, what is sea lift, military sea lift? It's the capacity to move military equipment to areas of the world where they're needed. Part of that equation is that we have squadrons of preposition ships or prepo ships, and they're just chock full of military equipment. and they're stationed in strategic locations around the globe that, you know, can be moved into a war theater if necessary. And, you know, you could pretty much guess where those locations are, places where they're a short distance away from the fight that we need to. Another part of the equation is having seal of ships that can be activated and to move military equipment from our domestic bases back home to where they're normally stationed to the war fight. And then
Starting point is 00:02:47 finally, the third part of the leg is we can call upon commercial vessels in the shipping industry that we maintain contracts with, or the U.S. Transcom maintains contracts with, and they can be hired to move military equipment as well. So by retaining that capability in peacetime, the military has a credible deterrence effect in that if a contingency pops up, the military has that means to move effective combat power into the theater. Anyone who could be a competitor to us, you know, if they wanted to pop something off, well, in the back of their mind, they're going to have to think, well, okay, they can come here using, you know, they could bring the combat power to where we are. So with that, talking about wartime, that's exactly what Sealift does. It's
Starting point is 00:03:36 by far the most efficient way to transport military cargo. During wartime, it moves between 90 to 95 percent of cargo certainly moving equipment by air using airlift is a faster way to move some you know you can move a tank into a theater within you know a day or two but you can move like one or two tanks with sea lift you can move a whole you know battalion into theater it's you know it's a lot slower but definitely more efficient and if you have the time you know it's You know, when we when we did Desert Storm, you know, there was the whole run up to that. And, you know, these these ships were activated and they were on their way. Yeah, the timestamp is for listeners recording this on May 28th.
Starting point is 00:04:21 So there's something sea lift related that needs to be discussed in the context of the Russia-Ukraine war. And we're not discussing it. The reason is because it hasn't happened yet. So if I'm not drawing allusions to that, that's the reason. I will say, I mean, we did just see like a month's long buildup for the Russians to move things all the way across Russia via rail, in most cases, to position themselves to invade Ukraine. So I think I think your your point stands as far as the time horizon is not always as short as you think it is. And sea lift is is a good option to move things there. But I think we spent a lot of time in the Navy talking about the vulnerabilities over the course of transit. so thinking mostly about convoy operations but you opted to focus here on vulnerabilities during
Starting point is 00:05:08 the final leg of transit why was that sure i mean well you know simply said it's it's the part of the journey that i have the most experience with you know i'm not an army guy so i'm you know i'm not too focused on you know the fort to port part i mean so normally the journey of a tank you know into the war zone definitely it's a long journey with many legs and layovers from their home base to a war zone. I mean, the first is the Fort DePorte moving cargo from the origin to a rail station where it's got to get tied up to a rail car, travel across rail across the country, and then until it arrives at a seaport embarkation where you can load it onto a cargo ship
Starting point is 00:05:48 before it makes its trans-oceanic journey. And then finally, after that leg, it gets to its seaport of debarkation, and then it gets unloaded and then staged and integrated with the rest of its unit for its onward movement. So each of these legs of transit, you know, of course there are vulnerabilities and specifically cyber vulnerabilities, but I focused on the sea transit part because I've got several years of working on sea lift issues and I'm more familiar with these issues. Certainly there's a lot of research that have been done regarding vulnerabilities in port facilities. You know, there's a growing list of ports that have been
Starting point is 00:06:23 hit by cyber attacks. I mean, you have Antwerp, Rotterdam, Long Beach, Barcelona, San Diego, Vancouver, Marseille, Cape Town, Houston, and, you know, the list goes on and on and on. You know, I haven't really studied port facilities since I was, you know, my last degree, I was studying critical infrastructure vulnerabilities in Monterey at the Naval Postgraduate School. So I did that for a previous thesis, but that was over a decade ago. And I haven't, you know, focused on that since. But after that, I did a tour at US Transcom at the Joint Distribution Process Analysis Center, where I did analysis on the SEALIF fleet. I've worked with military SEALIF command and the Department of Transportation, the Maritime Administration in DC, and we worked a whole range of issues regarding SEALIF. So I was just more comfortable with the SEALIFT ships, the ships themselves, and the issues there. And I was more comfortable in doing a deep dive into that. That's a good segue. As you mentioned, all those port attacks.
Starting point is 00:07:29 But what sorts of cyber attacks we already observed against maritime targets? What were some of the impacts of those attacks? Well, for the ships, certainly the first one that comes to mind is the shipping company Maersk, one of the world's largest global shipping companies. And they're one of the shipping companies that actually has a contract with the U.S. government to move military equipment during times of conflict or other national emergencies. The military gives them a retainer every year of X amount of money per ship saying, hey, you know, if the balloon goes up, we need you to drop what you're doing or drop off your cargo, race to export, pick up this gear and then bring it to the war zone. And we have these contracts for various reasons. One of them is to maintain a robust mariner base, U.S. citizens that sail on these ships that we can call upon. But so back to Maersk. So back in 2017, their data systems were affected by a malware called NotPetya by a group called Sandworm Team. And they're linked with Russia's General Staff Main Intelligence Directorate, or the GRU. The intent of NotPetya and going into, you know, events of today, the events of NotPetya was to disrupt government, financial and energy sectors.
Starting point is 00:08:52 Basically, this was done in Ukraine, but there were spillover effects and it found its way into Maersk's systems. So its impact was that 3,500 of its servers were destroyed, 49,000 laptops that were owned by Maersk destroyed. Their phone lines wouldn't work. Their cloud services, they were affected. So all in all, all of this made it so that their operations just ground to a halt. They couldn't do anything. And if you're looking at fiscally, they ended up losing or suffering $300 million in losses due to this malware. So that's one type of cyber attack.
Starting point is 00:09:33 Another type of cyber attack is involving targeting a ship's navigation system. So there's a couple of ways you could do that. You could either misdirect a GPS signal, you know, you can jam it or you can spoof AIS or automatic identification system. It's a system that's on on any large ship or your electronic chart display and information systems. And that's basically like the computer version of like the paper charts that, you know, mariners are familiar with. So we've observed Russia, for instance, demonstrating this capability by jamming GPS during NATO exercises in Norway a couple of years back. For the AIS signals, we've seen AIS signals being spoofed in the Strait of Hormuz. An example of that is a British-flagged oil tanker that was tricked into following its AIS recommendations into Iranian territorial waters. Well, once that happened, the Islamic Revolutionary Guard Corps seized the ship, imprisoned the crew for like two months.
Starting point is 00:10:34 And there's a whole there's a whole backstory about why they you know why they did that. There was reprisal for one of their ships being captured. But but yeah, the way that the ship made its way into Iranian waters was was a scooping AIS. Other AIS anomalies we've seen in the port of Shanghai, which is the world's busiest port. we've seen AIS anomalies that kind of point to that there's an electronic warfare system that was being developed there. And then also back to Ukraine, well, I'll just say, so there were two NATO ships that were docked in Odessa,
Starting point is 00:11:09 and according to their AIS, and AIS is linked, so basically you can communicate your AIS signal to any other ship in the area, in fact, globally. um they were saying that hey we're we're we've left port and we were transiting to uh to you know across the sea and um but they were still in port if you looked at all of the security footage it showed that they were still in port but you know their aes signal said that they were moving so what's the impact of these attacks is you can really cause confusion like if you were in a maritime traffic separation scheme or if you were blindly following your aes that ship could be left
Starting point is 00:11:46 off course and then another type of cyber attack um is we've seen demonstrated that you could do a cyber attack on the ship's uh software and on the operations of the ship you know there's software that calculates the stability of a ship as far as where all the weight is distributed um there effects you can do with that that are in my article uh there are systems that can control the rudders so the ship control and there's software that operates machinery that can be hacked using satellite communications or serial ports, or if you were extra frisky and you could physically get on board the ship with a USB stick, or if you inadvertently handed a USB stick to a crew member and they put it in their computer. So a lot of these ship control systems are connected.
Starting point is 00:12:33 So let's say if you were able to take control of the fuel systems software, you could take control of the air conditioning or, you know, more seriously, like the generators or other auxiliary systems. So that's just a summary of a couple of attacks that we've observed against maritime targets. We've talked on here about the age of the strategic SEALA fleet. I think our friend Dr. Sal Mercogliano has, you see, created an entire second career bemoaning the state of our strategic SEALA fleet and the age of the vessels. How vulnerable is that fleet given its age because i would think that you know conversely to their concerns about material condition uh that age may help it where where you think about cyber vulnerabilities well that's true
Starting point is 00:13:24 and you know i i read sal and um wholly agree with with all of his points about the age of the ships and um you know that that's a sensitive topic for me because you know i i see the material condition of these ships and and the age you know it's it's undeniable that a lot of our seal of ships are very old and in serious need of recap or recapitalization and you know there's only a couple ways that the the government can do that that they could either buy new ships which is prohibitively expensive or you could look and search and buy ships that are by used ships on the market that still have a lot of useful life but maybe not appropriate for the commercial sector because they've gone and made the latest and greatest thing so and and you know if we going
Starting point is 00:14:08 back to what i said earlier about having a credible force you need that that force to move that equipment so that if the balloon goes up you know these ships are ready to go i mean if you look at the seal of ships for most of their operating life the ones owned by the government at least they're kept in a reduced operating status where you have this skeleton crew that performs the maintenance so you don't have a big crew to work on and then you know if we go into a wartime scenario you know the the contract with a lot of these operating companies and what the ships are charged with doing is to get up to full speed get to full operating status full and fully crewed up within five working days and you know ships aren't designed to just sit and pour there's decide to be
Starting point is 00:14:54 run at sea um you know it seems counterintuitive like well don't you preserve it by just keeping it keeping it important but if you have that machinery laying dormant for that for so long that's no good and add to the fact like like we said the age of the ships you know some of these ships have been carrying cargo since the war in iraq and when i say the war in iraq i don't mean oif i mean desert storm so so that enough about the the material condition what you were what you're asking about with given their age and how high tech they are if they're still cyber vulnerable i mean the fact is you got to have at least some systems that are upgraded to to be able to do the the sat coms you know i mean yeah they're not like fly by wire but there are still
Starting point is 00:15:39 a lot of systems that are vulnerable and like i said before once you reach a certain tonnage you have to have the coast guard requires you to have ais on board the ship so they these ships even though they're old they still have systems that can be affected by by cyber attacks what mitigating measures do you recommend i'll address all the types of cyber attacks that that i mentioned before so first regarding the the shipping companies that operates the ships like like like maersk they have been but they should continue to invest in hardening their networks for resiliency you know and use the most up-to-date software for real with robust patching for all of their systems you know these companies should operate under the assumption that eventually at
Starting point is 00:16:24 some point they will have a cyber attack someone will strike their business operations and they need to have you know they need to maintain and test plans for mitigation and recovery um you know that's kind of the general practice right now there's companies that have sprung up that you know like we do cyber security and even the military has contracted some of these these companies to you know look at their ships and you know the military not you know i was talking earlier about mares these commercial companies the military is vulnerable as well i mean And Military Seal of Command operates these ships as well. So they've hired outside organizations to look at them, and they have their own organic IT team.
Starting point is 00:17:05 But, you know, we have such a striking example with Maersk, and when we have such observable effects of what a cyber attack can do with NotPetya. As an aside, speaking of the mitigation and network recovery, I mean, it was just random luck that Maersk was able to recover it all. so one of their servers in Ghana was offline during the time of the cyber attack because of a power outage and you know unreliable power supply in that part of Africa once once Marisk was realizing they were getting hit you know they said well is there any any any server that wasn't effective they found this one in Ghana so they had to get a guy to you know hand carry that hard drive from Ghana to London just to begin the recovery. So pretty lucky there. Better to be more prepared than lucky, but they caught a break there. So regarding disruptions to
Starting point is 00:18:01 GPS and AIS, I think that mariners just need to be cognizant that these cyber attacks are out there and just not rely on GPS as a single data point of where you are in the world. And I know that there's a lot of automated systems and when you're when you're driving in the or sailing in the open ocean it's just kind of let me drive this straight straight line but you know you there there are other sources i mean i remember when i was on the bridge as officer of the deck and i was piloting into or out of port you always rely on multiple fixes i mean you have you know your visual cues you have your radar range and distance um that you set to to landmarks so as you're traveling on your voyage track, you always have that backup. I trust that more than GPS because, you know,
Starting point is 00:18:48 with a signal. So, but, you know, when you're out in the open ocean, I mean, there's always celestial navigation. I think every mariner should be able to sail by the stars. And, you know, that's one way to, that's a mitigating measure for cyber attacks against GPS or AIS. So regarding those cyber attacks that penetrate the networks on board ships i think mariners just should also enforce good cyber security practices because i mean they're the first line of defense against malware one example i didn't mention earlier was a cyber attack involving a phishing email with a voicemail themed attachment that targeted a u.s tug operator and you you know you you see these emails in your inbox and it's like you know click here and you're like okay that's obviously
Starting point is 00:19:35 spam or a phishing email but this this poor guy or gal clicked on the link um and it affected the tug and what i was saying earlier about about port ops uh tugs are critical you need a tug to get a big ship in and out of port and you know if you think about like a big shipping port like say san diego and you have all these ships just waiting to get in and i understand like you know And the supply chain issue that we had with San Diego over the last couple of months, a lot of that is there's a lot of backup with containers getting into the port. But still, the ships themselves, you got to get them into port and out of port off of the pier. And you need tugs to do that. So there's many, many links in the chain of, you know, for ship operations.
Starting point is 00:20:26 And if you just target one of those links, you know, it can break. So I think that the Department of Transportation should mandate that these operating companies or the unions that organize the Mariners require in-person classroom training on cybersecurity. And I say in-person, I say live in-classroom because, I mean, if anyone who's done computer-based training knows that it's often rushed, it's like, oh, shoot, I got to get this done before I leave today. so let me just click click click click click click through and uh you know you don't really retain that knowledge i i do this training yearly and you know i think i've got it down but at the same time you know some of these some of the mariners may be like you know okay let me just get that done click click on the click on click that box but or check that box but uh if you're in a classroom and you have the you know someone talking to you you can't really escape that
Starting point is 00:21:21 Finally, I think that the Department of Defense should be sending cyber red and blue teams to seal of ships and other naval vessels to inspect for these vulnerabilities. And, you know, if they see something, they could patch any outdated systems and just have a flyaway team to go out there, conduct training with the crew, raise the general level of cybersecurity. Now, final question. Are there any particular lessons learned based on the Russia-Ukraine war? And I'll timestamp again here. It's May 28th. So anything that's happened to date? yeah um so okay uh end of may um and i want to first start by highlighting that earlier this month that the state department along with several other european nations have or several european nations have um attributed malicious cyber activity on ukraine by from russia um and they've had disruptive cyber operations that include you know website defacements distributed denial of surface attacks and cyber attacks to delete data from computers belonging to
Starting point is 00:22:30 the government or private entities they don't call out the gru by name but i mean it's the gru and this is their playbook yeah right before the war started before the invasion started uh there was a cyber attack that took down satellite communications um so lesson one expect a cyber cyber attacks in a war in a run-up to a war i mean sometimes it's not really publicized but you know because the effects are hard to see sometimes but um yeah taking down all of your communications right before you get invaded that's that's something uh that you can expect as the war was progressing a lot of people were saying uh hey i thought that russia was super good on cyber And and where are all the cyber attacks? And, you know, well, one, you know, there could be a robust, robust defense or it's just maybe things that we aren't seeing.
Starting point is 00:23:24 But I mean, it's not for the lack of trying on their part. I think a lesson to the effect of mobilization and logistics. I mean, that's really one of the backbones to combat effectiveness. I mean, like, as we said at the beginning, the Russians had a lot of time to mobilize their forces and sending, they were transporting stuff from all the way in, from Siberia via rail car. And I mean, they started the war at the time of their choosing, you know, just, you know, let's wait till after the Olympics. I mean, this is all conjecture, but, you know, they really could have started anytime they waited, you know, waiting for the right weather conditions. you know i think um i mean i personally think and you know everything here is attributed to me that not not reflecting my institution but i i think that you know he probably cut a side deal with with she and said you know we'll we'll wait till after your the olympics and all the pr you get
Starting point is 00:24:20 from that despite all the advances that they've had you know once the war started they the residents made a whole bunch of gains um but we started witnessing the cracks in their logistical network and then the subsequent advances by your ukrainian forces and you know okay it's the end of may at this point um they've they've regained a lot of their territory other than you know in in the donbass area but they're taking back their country and there's been a lot of russian mishaps uh low morale definitely the the mobilization and logistics that that was kind of a weakness um a couple weeks ago um sink the spectacular sinking of the Moskva uh one of the the Russian flagship one of their flagships and but before the the Moskva was sunk there was another
Starting point is 00:25:08 uh ship that was sunk it was a an amphib ship or amphibious ship called the Saratov and uh what was it doing it was on a mission of offloading tanks to replenish the ones that were lost in the south it was sunk off the cost of burden yanks that that's i guess that's the other lesson learned like you here's you have a war between two land powers and you still have a sea lift as an enabling factor uh you know trying to rolling stock or tanks so uh it's sea lift can be an enabling factor but it's also a capability that you still need to protect you know as evidenced by the Saratov. Well, unfortunately, that's all we have time for. I'd like to thank my guest, Jason Aleto. Jason, where can we find you online and what are you working on next?
Starting point is 00:25:56 Well, online, my Twitter handle is at Jason Aleto. That's I-L-E-T-O. I don't really post too much on naval analysis. Mainly it's running commentary on the latest sumo tournament. But, you know, I'm working to get more professional. But as for what I'm working on next, taking orders to the Navy Yard in Washington, D.C., where I'll be working at the Office of the Navy Inspector General. So that's what I'll be doing in the near term. Excellent. Well, thank you again for coming on. To listeners, thanks for tuning in. We'll see you next time.
Starting point is 00:26:46 Thank you. Help me, help me, oh, I'm put in the alley. Put it out in Shemona.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.