Skip to Content.
Sympa Menu

netsec-sig - RE: [Security-WG] Strange request from Air Force

Subject: Internet2 Network Security SIG

List archive

RE: [Security-WG] Strange request from Air Force


Chronological Thread 
  • From: "Beadles, Mark A." <>
  • To: "" <>
  • Subject: RE: [Security-WG] Strange request from Air Force
  • Date: Fri, 9 Feb 2018 16:01:53 +0000
  • Accept-language: en-US
  • Authentication-results: spf=pass (sender IP is 128.146.138.10) smtp.mailfrom=oar.net; internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=bestguesspass action=none header.from=oar.net;
  • Ironport-phdr: 9a23:qu90lhxqLd+VL6rXCy+O+j09IxM/srCxBDY+r6Qd2ukVIJqq85mqBkHD//Il1AaPAd2Craocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze+/94HObwlSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDwULs6Wymt771zRRHolikJKiI5/m/UhMx+jq1boQ6uqBNkzoHOfI2YMOBzcr/Bcd4YQ2dKQ8ZfVzZGAoO5d4YDAfcMMvhCoIbgo1sBswC+CRGxD+3o0DBInHz21rAm3ug7Hw3NwQstH9cVv3vKttr6KaMSXv6uzKTTyjXMdelW1S376IfWbhAsuPeBVq9+f8rWzEkgDQLFjlOIpIziJTyVzP4Bs26F4Op8Te6vjG4npxhtojex2sgsipPFhoUPylDL8yhy3YU7JcWgRUJmfdKpH4Fcui6YOodsTc4uXntktDskxrEboZK3YSYHxIk9yxLCaPGKcZKE7g/+WOuROzt0mX1odb2nixa870etyfHwW8yx3VlXsiZJjNnBu3UD1xHc6MWIVP5w8Vu61jmR0w3e7/xILEMvmqfdNpUv2KQ/loAJvkTGBiL2mFv5jKuRdkg84ual9+Ppbqnoq5OFOYF6jQ/zPr0pmsOkH+s0KA8OX3WH+eun073j4Ev5T6hQgv0uiKnZt4zaKtoHqa6lAg9V1YAj5wy4Dze7zNQYmX4HLFVGeB6dk4fpPFTOLOj5Dfe5nVusjC9my+3aMrDuGJnAIXrOnK3ucLpg8UJQ1RQ/wc1H65JREL4BIfbzWkHrtNzfCx80Kwm0zP35B9pny4weXXyAArSCPaPVq1CI/PgjI++Sa48JoDr9MeQq5+byjX8lnl8QZbKp0oULZ3ClBPRmIlmZYHr1jtYPHmcHpQ4+TO3xiF2eSj5feWy+X6M65jEnFo2mF4HDSZ6xgLCfxiu0AIBZZn0VQmyLRD3zeo6ZQfYQeWeNLedglCAJT76sV9Vn2B2z/keu0LdsM/DV5jxdqp3L1d5p6vfVmA1oszF4EpLO/XuKSjQ+tG4BSzs7x+Q3hEVnyR+ql+Iw1/lSGNVf4/5SegAzL9jawvAsWIO6YR7IYtrcEAXued6hGzxkFt8=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Looks like my signature cert was invalid – sorry about that. I assure you that it was me though, you can trust me. Right?

 

Mark Beadles

Chief Information Security Officer

OARnet, an Ohio Technology Consortium Member

A division of the Ohio Department of Higher Education

 

www.oar.net www.oh-tech.org

 

direct 614.292.8217

mobile 614.327.8046

 

From: [mailto:] On Behalf Of Beadles, Mark A.
Sent: Friday, February 09, 2018 10:58 AM
To:
Subject: RE: [Security-WG] Strange request from Air Force

 

We have not been approached by the AF itself on this – but we did receive a request exactly like the one WVNET received a couple years ago from another TLA. We did *not* want to put it on the Higher Ed/Research network for numerous reasons and were quite firm on that. The eventual outcome of that was that the State government agreed to implement the boxes on their side of the network, so that the State’s traffic is monitored by the boxes but the Higher Ed/Research traffic is not.

 

The AF angle is interesting and I will keep an eye on that, since we serve a lot of AF-related things in the Dayton area.

 

Mark Beadles

Chief Information Security Officer

OARnet, an Ohio Technology Consortium Member

A division of the Ohio Department of Higher Education

 

www.oar.net www.oh-tech.org

 

direct 614.292.8217

mobile 614.327.8046

 

From: [] On Behalf Of Rick Haugerud
Sent: Friday, February 09, 2018 10:53 AM
To:
Subject: RE: [Security-WG] Strange request from Air Force

 

We have experienced a situation like this a couple of years ago.  We were contacted by a member of US Air Force Incident Command.  They had identified a series of servers and accounts in one of our colleges that had been compromised, and were being used as a jumping point to go elsewhere.  They asked us to install a “black box” that would allow them to monitor the activity.

 

They actually flew to Lincoln (3 of them) and met with us and described some of the activity.  We allowed them to install the “black box” on our network for about 18 months.  Information sharing was minimal, and ultimately we disconnected the box and shipped it back.

 

Rick

 

Rick Haugerud

Office of Cybersecurity & Identity|ITS|

211 Nebraska Hall, 68588-0522

University of Nebraska |nebraska.edu

Kearney|Lincoln|Omaha

402-472-2135 (o)

 

Information Technology Services
Connecting people, ideas and technology for a better University, a better you.

 

From: [] On Behalf Of John Dundas, III
Sent: Friday, February 9, 2018 9:33 AM
To:
Subject: Re: [Security-WG] Strange request from Air Force

 

On 2/8/18 1:09 PM, Karl Newell wrote:

Hi all,

 

One of our members experienced the following, I’m wondering if anyone has heard of something similar or what your thoughts are.

 

The Air Force contacted the member’s DNS registrar saying they had information to share about the member’s network.  This request made it to the CISO who called back.  The Air Force wanted to install a device on the member’s network to monitor traffic.  It was assumed there would be information sharing but the member did not agree to work with the Air Force.

 

Thanks,

Karl


Karl,

Thanks for posting this.  To my knowledge, CENIC has not been approached by any agency with such a request.

Also thank you for declining the "offer."  Numerous red flags are at full-mast.

John




Archive powered by MHonArc 2.6.19.

Top of Page