EDGE Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/edge/ Breaking news about the market for products, systems and services for the U.S. intelligence community Thu, 09 Apr 2026 13:05:08 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg EDGE Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/edge/ 32 32 59882712 GreyNoise Intelligence introduces C2 detection https://intelligencecommunitynews.com/greynoise-intelligence-introduces-c2-detection/?utm_source=rss&utm_medium=rss&utm_campaign=greynoise-intelligence-introduces-c2-detection Thu, 09 Apr 2026 13:05:08 +0000 https://intelligencecommunitynews.com/?p=44286 On April 7, GreyNoise Intelligence introduced Command and Control (C2) Detection, a new intelligence module that unlocks insights about cyber attack...

The post GreyNoise Intelligence introduces C2 detection appeared first on Intelligence Community News.

]]>
On April 7, GreyNoise Intelligence introduced Command and Control (C2) Detection, a new intelligence module that unlocks insights about cyber attack behavior, based on information contained in outbound network traffic logs. C2 Detection empowers security teams to detect active compromise earlier, prioritize response based on attacker progression, and accelerate investigation by surfacing malware hashes and family classifications tied to confirmed callback infrastructure.

“Edge devices have become the most targeted assets on the internet, and the industry’s visibility into what happens after they’re compromised has been dangerously limited,” said Ash Devata, CEO, GreyNoise Intelligence. “GreyNoise has always been one of the most authoritative sources on inbound network threats. With C2 Detection, our customers can not only identify who’s probing their perimeter, but whether a device is already compromised and who it’s phoning home to.”

Cyber adversaries frequently attack edge devices to exploit known vulnerabilities and gain access. GreyNoise utilizes the world’s most sophisticated deception network of over 5,000 sensors in 80 countries to observe internet traffic and can determine whether activity is malicious in intent based on certain behavioral characteristics and patterns. In cases where an IP is attempting to initiate a download of malware onto a network, valuable insights can be found in the network’s outbound traffic log, since compromised devices often call out to C2 servers to receive additional instructions. This information can provide valuable insights to help security teams determine whether their perimeter has been breached.

Powered by GreyNoise’s callback IP intelligence and malware hash data, C2 Detection provides post-exploitation, outbound-facing threat intelligence by surfacing active compromise through outbound communication with attacker-controlled infrastructure. It provides an end-to-end overview about how attacks actually work, including what payloads were delivered, what binaries were downloaded, which external servers were used for Command and Control, and what commands and behaviors were associated with those sessions.

By matching outbound egress traffic against a continuously updated dataset of confirmed malware-hosting IPs and C2 infrastructure, C2 Detection produces a signal that indicates exactly how serious each match is. Security teams can use this dataset of ‘phone home’ addresses that compromised devices communicate with for potential breach detection via outbound telemetry by matching it against their outbound logs. If an internal device has been communicating with malicious IPs, there is a high degree of likelihood that the device has been compromised.

“With C2 Detection, GreyNoise is effectively closing the visibility gap at the edge of the network,” said Corey Bodzin, chief product officer, GreyNoise Intelligence. “Up until now, security teams have had a structural blind spot on post-exploitation activity, especially on edge devices like firewalls, VPN concentrators, and internet-facing IoT. These are now the most actively exploited assets on the internet, but Endpoint Detection and Response (EDR) can’t be run on them, and their native telemetry is often too sparse to detect callback behavior. Our research shows that millions of edge devices are already infected and silently calling out to malware-hosting servers, C2 nodes, and associated file hashes.  C2 Detection surfaces that activity, and empowers security teams to take action faster.”

Source: GreyNoise

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post GreyNoise Intelligence introduces C2 detection appeared first on Intelligence Community News.

]]>
44286
CISA releases directive on edge device risk mitigation https://intelligencecommunitynews.com/cisa-releases-directive-on-edge-device-risk-mitigation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-releases-directive-on-edge-device-risk-mitigation Thu, 12 Feb 2026 12:44:04 +0000 https://intelligencecommunitynews.com/?p=43839 The United States faces persistent cyber campaigns that threaten both public and private sectors, directly impacting the security and privacy...

The post CISA releases directive on edge device risk mitigation appeared first on Intelligence Community News.

]]>
The United States faces persistent cyber campaigns that threaten both public and private sectors, directly impacting the security and privacy of the American people. These campaigns are often enabled by unsupported devices that physically reside on the edge of an organization’s network perimeter. Unsupported devices – referred to in this Directive as “end of support (EOS)” – are those that are no longer maintained by their vendors.

The imminent threat of exploitation to agency information systems running EOS edge devices is substantial and constant, resulting in a significant threat to federal property. CISA is aware of widespread exploitation campaigns by advanced threat actors targeting EOS edge devices. Recent public reports of campaigns targeting certain vendors highlight actors’ attempts to use these devices as a means to pivot into FCEB information system networks. Edge devices are attractive targets due to their extensive reach into an organization’s network and integrations with identity management systems. These devices are especially vulnerable to cyber exploits targeting newly discovered, unpatched vulnerabilities. Additionally, they no longer receive supported updates from the original equipment manufacturer, exposing federal systems to disproportionate and unacceptable risks. However, unlike many attack vectors, this can be remediated by agencies following proven lifecycle management practices as outlined in the required actions of this Directive.

This Binding Operational Directive, developed in coordination with OMB, implements OMB policy on phasing out unsupported information systems and information system components. BOD 26-02 specifically addresses EOS devices deployed on the “edge” or public-facing areas of federal networks, exposed to external environments such as the internet. However, EOS devices should not reside anywhere on federal networks. This Directive aligns with OMB’s Circular A-1301Managing Information as a Strategic Resource, which establishes policy for the management of federal information resources, emphasizing security, privacy, and the efficient use of resources throughout their lifecycle. A-130 requires that “unsupported information systems and system components are phased out as rapidly as possible, and planning and budgeting activities for all IT systems and services incorporate migration planning and resourcing to accomplish this requirement.”2 Agencies should mature their lifecycle management practices to identify hardware and software nearing their EOS dates, plan for timely replacements, procure vendor-supported alternatives, and develop a plan for decommissioning EOS devices while minimizing disruptions to agency operations. Agencies that do not maintain appropriate lifecycle management processes for edge devices have a greater risk of compromise and an increased overall risk associated with EOS technology.

To support agencies in the initial identification of EOS devices, CISA developed an EOS Edge Device List. This preliminary repository provides information on devices that are already EOS or soon-to-be EOS. This Directive requires federal agencies to use this information to identify and remediate vulnerabilities within the first three months of Directive issuance. This Directive also specifies long-term requirements for managing EOS edge devices across all federal networks.

Review the directive from CISA.

Source: CISA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post CISA releases directive on edge device risk mitigation appeared first on Intelligence Community News.

]]>
43839
Cubic DTECH, Instant Connect and Rally Tactical Systems team up https://intelligencecommunitynews.com/cubic-dtech-instant-connect-and-rally-tactical-systems-team-up/?utm_source=rss&utm_medium=rss&utm_campaign=cubic-dtech-instant-connect-and-rally-tactical-systems-team-up Thu, 20 Feb 2025 14:58:33 +0000 https://intelligencecommunitynews.com/?p=41019 Cubic DTECH Vocality, Instant Connect Software and Rally Tactical Systems (RTS) are breaking new ground with the integration of Instant...

The post Cubic DTECH, Instant Connect and Rally Tactical Systems team up appeared first on Intelligence Community News.

]]>
Cubic DTECH Vocality, Instant Connect Software and Rally Tactical Systems (RTS) are breaking new ground with the integration of Instant Connect Enterprise (ICE) as the encrypted end-to-end and transport layer security wrapper for tactical push-to-talk traffic. The Joint Interoperability Test Command (JITC)-certified software platform is included on the DoD Information Network (DoDIN)-approved product list.

The ICE platform is a proven, military-grade tactical communications solution that integrates with RTS’ Engage Engine and Cubic’s Radio Over IP (RoIP) gateways, including the DTECH Vocality RoIP, M3X and M3-SE, enabling special operations teams worldwide to leverage the blended solution capability for multilingual missions.

“The ICE platform eliminates language barriers, providing real-time communication across 70+ languages to accelerate and clarify crucial communications,” said Anthony Verna, senior vice president and general manager of DTECH Mission Solutions. “The combined solutions remove delays and other drawbacks associated with human translators in the field, thus creating a new standard in coalition interoperable tactical communications.”

“Our platform is secure and accurate, giving warfighters a decisive advantage in coalition peacekeeping, enforcement and other missions,” said Forrest Claypool, Instant Connect CEO. “Special operations teams know that ICE allows them to extend the language translation capability to remote environments at the tactical edge. It’s about providing teams with the communications flexibility they need when seconds matter.”

Source: Cubic

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post Cubic DTECH, Instant Connect and Rally Tactical Systems team up appeared first on Intelligence Community News.

]]>
41019
NSA and partners advise on edge device mitigation strategies https://intelligencecommunitynews.com/nsa-and-partners-advise-on-edge-device-mitigation-strategies/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-and-partners-advise-on-edge-device-mitigation-strategies Wed, 05 Feb 2025 13:41:35 +0000 https://intelligencecommunitynews.com/?p=40895 On February 4, the National Security Agency (NSA) announced that it has joined the Australian Signals Directorate’s Australian Cyber Security...

The post NSA and partners advise on edge device mitigation strategies appeared first on Intelligence Community News.

]]>
On February 4, the National Security Agency (NSA) announced that it has joined the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the Canadian Centre for Cyber Security (CCCS), and others to release three guides Cybersecurity Information Sheets (CSIs) that highlight critically important mitigation strategies for securing edge device systems, including firewalls, routers, and virtual private network (VPN) gateways.

Collectively, these reports – “Mitigation Strategies for Edge Devices: Executive Guidance,” “Mitigation Strategies for Edge Devices: Practitioners Guidance,” and “Security Considerations for Edge Devices” – provide a high level summary of existing guidance for securing edge devices, with comprehensive recommendations for tactical, operational, and strategic audiences to enhance network security and improve resilience against cyber threats.

“Edge devices act as boundaries between organizations’ internal enterprise networks and the Internet; if left unsecured, even unskilled malicious cyber actors have an easier time finding and exploiting vulnerabilities in their software or configurations,” said Eric Chudow, an NSA cybersecurity vulnerability analysis subject matter expert. “As organizations scale their enterprises, even though securing all devices is important, prioritizing edge device security is vital to defend the many endpoints, critical services, and sensitive data they protect.”

The guide, “Mitigation Strategies for Edge Devices: Executive Guidance” is intended for executives within large organizations and critical infrastructure sectors responsible for the deployment, security, and maintenance of enterprise networks. It outlines seven key mitigation strategies for managing and securing edge devices within traditional network architectures:

  1. Know the edge
  2. Procure secure-by-design devices
  3. Apply hardening guidance, updates, and patches
  4. Implement strong authentication
  5. Disable unneeded features and ports
  6. Secure management interfaces
  7. Centralize monitoring for threat detection

 

The companion guide, “Mitigation Strategies for Edge Devices: Practitioners Guidance,” is written for operational, cybersecurity, and procurement staff and provides an overview of what edge devices are; risks and threats to them; relevant frameworks and controls by some of the authoring nations; and a more in depth discussion on the seven mitigation strategies. Additionally, the report includes a case study of a successful exploitation to show how malicious actors compromise edge devices when they are not secured properly and to highlight further how edge devices are critical to the security of a network.

Expanding on the other reports, the “Security Considerations for Edge Devices” guidance details threats to edge devices from common malicious techniques and ways organizations can reduce the risk of compromise with mitigation recommendations. The publication also outlines factors organizations should consider when evaluating the security of edge devices, along with recommendations for edge device manufacturers to improve the built-in and default security of devices they produce.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post NSA and partners advise on edge device mitigation strategies appeared first on Intelligence Community News.

]]>
40895
SAIC unveils zero trust edge capabilities https://intelligencecommunitynews.com/saic-unveils-zero-trust-edge-capabilities/?utm_source=rss&utm_medium=rss&utm_campaign=saic-unveils-zero-trust-edge-capabilities Mon, 06 Nov 2023 13:44:00 +0000 https://intelligencecommunitynews.com/?p=37057 On November 2, Reston, VA-based Science Applications International Corp. (SAIC) announced new, purpose-built Zero Trust security capabilities, which provide a...

The post SAIC unveils zero trust edge capabilities appeared first on Intelligence Community News.

]]>
On November 2, Reston, VA-based Science Applications International Corp. (SAIC) announced new, purpose-built Zero Trust security capabilities, which provide a solution to answer the Zero Trust pillars addressing data, identity, devices, networks, applications and workloads.

The new Zero Trust security capabilities have been tested and validated on an AWS Snowball Edge and AWS Snow Family device with on-board storage and compute power for select Amazon Web Services (AWS) capabilities. AWS Snowball Edge can support local processing and edge-computing workloads in addition to transferring data between a user’s local environment and AWS.

“SAIC has brought together the best-in-class tools to deliver a mission-ready Zero Trust Edge capabilities that provides multi-level secure data processing and analytics and prioritizes data in a DDIL environment to transport back to the cloud,” said Lauren Knausenberger, chief innovation officer at SAIC. “This provides warfighters with a critical capability to extend their enterprise OCONUS, with the ability to run disconnected ops and rapidly adopt technologies and capabilities needed for mission success. This capability has the potential to be a critical enabler for Combined Joint All-Domain Command and Control (JADC2), with the ability to deploy at forward operating bases, on air platforms and at sea.”

Through the combined efforts of AWS; SAIC; Koverse, an SAIC company; Okta; CrowdStrike; Zscaler and Splunk, ready-to-install cybersecurity and Zero Trust technologies combine data and provide multi-level security from the edge through the enterprise. This capability meets the challenges of Wide Area Network (WAN) or no WAN connectivity by enabling offline compute capabilities and replicates mission-critical data after connectivity is restored. These components of software and hardware allow the capabilities to address the five pillars of the Zero Trust Maturity Model and therefore help increase cybersecurity posture at the edge.

SAIC is an industry leader in cloud and cybersecurity, addressing Zero Trust security capabilities, including the latest capabilities which have been validated and tested on an AWS Snowball Edge device.

Source: SAIC

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post SAIC unveils zero trust edge capabilities appeared first on Intelligence Community News.

]]>
37057
Enterprise Edge Security: A Strategy Checklist https://intelligencecommunitynews.com/ic-insiders-enterprise-edge-security-a-strategy-checklist/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-enterprise-edge-security-a-strategy-checklist Mon, 06 Mar 2023 13:57:39 +0000 https://intelligencecommunitynews.com/?p=34895 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies In the past, it...

The post Enterprise Edge Security: A Strategy Checklist appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

In the past, it may have been enough to think about data protection at the core or strategic level. Today, however, defense, intelligence and civilian agencies must extend their data protection strategies all the way to the tactical edge.

The reason for this change in strategy is the way federal agencies’ operating environments are being influenced by digital transformation. An agency’s IT core infrastructure capabilities, previously maintained in headquarters data centers, now are available in cloud and edge environments, effectively making them micro data centers.

Take the Department of Defense, for example. Command posts, mobile command centers – even vehicles, ships and planes – now have core-level IT capabilities. Similarly, at the civilian level, micro data centers exist at the edge, in embassies, hospitals, and branch or field offices.

There are numerous core-level security concerns at these edge environments, ranging from weather conditions to bandwidth issues. Solutions to these edge environment concerns have specific size, weight and power constraints, depending on the environment. Additionally, technology to protect data is necessary for edge environments in case that equipment is compromised.

It’s important, therefore, to create an effective ecosystem that can protect data at the edge. There are several key considerations to ensure a successful strategy. Let’s take a closer look.

Size concerns and protection from hostile access. The physical environment is a serious aspect for edge security. The government maintains specific size, weight and power (SWaP) requirements for equipment in tactical areas, as well as how durable it is in extreme conditions. And because there is also the reality that equipment may fall into the wrong hands, data security strategies for such circumstances is essential. NIST has sanitation policies, emulated in military standards, that address destruction of physical media after overwriting drives multiple times.

Ideally, edge security products should come with a cryptographic erase solution to protect encrypted data. Cryptographic erase enables data encryption keys, used to encrypt/decrypt data, to be erased or destroyed without destroying the storage drive. Regardless of who controls the physical equipment, data will remain encrypted and inaccessible.

Because personnel at the edge may lack experience with data security, edge products must be simple to use, with secure, easy to understand default configurations. And because systems at the edge may potentially suffer connectivity issues, they must be able to store and secure data locally. That data can be sent back to the core once the connection is restored. Units must be configurable at both the enterprise and local level. When connecting multiple units, these units must be manageable and configurable at the enterprise level.

Cryptographic key management. Data encryption at the edge can be difficult for an organization’s IT security teams. These teams must manage multiple cryptographic keys for many different encryption solutions with native key management capabilities. Native key management solutions are usually not interoperable, however; this means that system administrators may end up storing cryptographic keys and encrypted data in the same place.

Because of behaviors like this, centralized key management solutions are essential. Centralized key management solutions allow for secure storage and backup of encryption keys. Access control policies also are better defined and encryption tasks can be separated from key management tasks. These key management solutions provide key lifecycle management- from creation, rotation, backup, and destruction. These tasks are vital at the edge where keys are particularly vulnerable.

Ideally, organizations should look for cryptographic key management solutions that offer hardware security modules as removable tokens. Such products are ideal for the edge, because removing a detachable token keeps encrypted data safe, no matter how remote or hazardous the tactical environment may be.

Authentication and access control. New threats and risks can be worse at the edge because of shifting operational requirements. That calls for simple, scalable solutions for authentication.

The most secure way to limit access to data and applications is through multi-factor authentication. At the edge, it’s important to deploy multi-factor authentication across multiple environments. This will secure access no matter which devices are used, or whether data is maintained locally, on-premises, or in the cloud.

Protection for mission-critical data in transit. Cloud data migration, global collaboration, and bandwidth requirements at the edge have all made much greater demands on high-speed wide-area networks. Data moving across the network is under constant threat, so encrypt everywhere, for both data in motion and at rest.

In transit, data is best protected by network encryptors that enable people, organizations and locations to securely share information. Such network encryptors protect data, video, voice, and metadata from eavesdropping, surveillance, and overt and covert interception. At the edge, that level of encryption is critical.

To make it easier on network architecture and IT professionals, it is critically important to look for solutions with vendor-agnostic interoperability. Flexibility is also important, because as we’ve previously noted, security and network requirements are continually changing in edge environments.

Compliance. IT environments become increasingly susceptible to attack as they move out to the edge. Minimizing vulnerability means ensuring compliance with security requirements. To ensure compliance, the same enterprise-level security policies must be used across the architecture. Consequently, look for solutions with certifications from multiple organizations. These certifications include FIPS 140, the Commercial Solutions for Classified program, Committee on National Security Systems Memo #063-2017, and Department of Defense’s Information Network Approved Product List.

Building an IT infrastructure with hardened security that extends to the very edge might seem like an almost insurmountable challenge. But if you take these considerations into account, you’ll find it much easier to develop a system with appropriate access controls – one that protects data at rest and in transit, from the core to the cloud to the edge.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post Enterprise Edge Security: A Strategy Checklist appeared first on Intelligence Community News.

]]>
34895
Tactical Edge Reference Architecture https://intelligencecommunitynews.com/ic-insiders-tactical-edge-reference-architecture/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-tactical-edge-reference-architecture Mon, 17 Oct 2022 13:10:46 +0000 https://intelligencecommunitynews.com/?p=33685 Deploying at the Edge with Kubernetes From IC Insider Rancher Government Solutions By: Andy Clemenko, Field Engineer, Rancher Government Solutions...

The post Tactical Edge Reference Architecture appeared first on Intelligence Community News.

]]>
Deploying at the Edge with Kubernetes

From IC Insider Rancher Government Solutions

By: Andy Clemenko, Field Engineer, Rancher Government Solutions

andy.clemenko@rancherfederal.com

Twitter: @clemenko

 

Rancher Government Solutions (RGS) field engineers get asked all the time about how to deploy at the edge. Search the internet for “edge computing” and you’ll get more than 300 million results that all say something different. This tells us two important things: 1) there is enormous interest in the topic; and 2) there is also enormous confusion about it.

This piece is designed to dispel that confusion and outline exactly how we at RGS deploy at the tactical edge leveraging Kubernetes.

First, let’s define the tactical edge.

What is the Tactical Edge?

In 2012, the Software Engineering Institute and Carnegie Mellon University partnered on a piece on Cloud Computing at the Tactical Edge.

From the abstract: “Handheld mobile technology is reaching first responders, disaster-relief workers, and soldiers in the field to aid in various tasks, such as speech and image recognition, natural-language processing, decision making, and mission planning.”

Fast-forward 10 years to today and it is amazing to see the amount of compute that can fit inside a coffee can. Case in point: ASROCK Industrial has a very powerful 4X4 BOX-5800U computer in a package that is 4 inches by 4 inches by 2 inches. Not only is it tiny, but its power consumption is low enough to run on batteries. Compute has gotten both powerful enough and small enough to run big applications from the palm of your hand.

At Rancher Government, we define the tactical edge as: A small case or kit that contains compute power and that is easily portable. The number and size of the nodes can vary. Being portable is the key characteristic.

Using this definition, we can start to think about real world applications of such a cluster, box, backpack or kit. The idea of “moving computation to where the data lives” can be applied. A lot of our work involves helping organizations process data in the field and then distill it into more meaningful data to be sent back upstream.

Important Considerations for Computing at the Tactical Edge

For all its potential and enabling power, there are two important considerations for computing at the tactical edge. The first one involves power, space, and cooling. And it’s not surprising. These are challenges for even the biggest data centers in the world.

When looking for edge hardware, pay attention to the Thermal Design Power, or TDP for short. This will indicate how much power is required for that device. Remember that the power requirements will increase when the device is under a heavy load. Calculating the combined TDP for an edge kit is important to understanding how long a battery will last, or how much power supply is needed. For reference, the kit below has a combined TDP of roughly 185 watts. Computing at the edge requires sufficient power, and enough space to allow for cooling.

The second major consideration involves manageability, specifically how to manage the operating system and applications far away from “home.” This is where Kubernetes and GitOps can dramatically increase the velocity of deployment and manageability. Ideally, teams will want a lightweight Kubernetes distribution and management layer since not all Kubernetes distributions can operate in a smaller compute envelope. The Container Journal recently highlighted a lot of the advantages of leveraging Kubernetes at the Edge.

Hardware

Once power, space, cooling, and manageability have been assessed, teams can start thinking about a tactical edge architecture.

Boy, do we have many choices of hardware these days! X86 or Arm? Intel or AMD? My favorite approach for picking hardware is to look at the applications that are needed. We call this approach “working backward.” Once the total amount of compute required is calculated, we can start looking at the amount of CPU that will be needed. Adding the application CPU and Memory together with the Kubernetes and management overhead we get the “compute envelope” – meaning, the total amount of CPU cores and memory. Of course, there are other components, like networking, that are worth looking at as well.

For this reference architecture, we have chosen three ASROCK 4X4 BOX-5800U boards. There is a good balance of cores, memory, storage and TDP. Each board has eight cores and supports up to 64gb of ram. For storage, there is NVME (PCIe Gen3x4) support and a SATA3 port. As for power, we were able to use a single 150w power supply for all three boards. Each board has a TDP of 60Watts. Under heavy load there were no issues at all. The boards also have multiple NICs, including a 2.5gb one.

To maximize the portability, we added a Gl.inet Beryl Travel Route. The router is great for extending the connectivity to additional devices like a laptop. The router also has a “repeater” function for Wifi – meaning, all the nodes reach the internet for updating and initial loading of software. And of course, an internal DHCP server. As a side note, some of the Gl.iNet routes also have WireGuard (VPN) capabilities.

One last piece to this architecture is a Netgear GS105 five-port one-gigabit ethernet switch. The switch provides communication between the nodes. The switch could easily be upgraded to 2.5 gigabits if needed. However, if the case only had two nodes, the GL.iNet router would be able to handle all the internal traffic.

Operating System

Similar to the array of choices there are in the hardware realm, there are a number of choices when it comes to operating systems. Ubuntu is a great choice for many scenarios. It is built on Debian which has been around for decades. Rocky Linux is another great choice. Rocky is the new Centos. Rocky is built from RHEL with all the enterprise security and stability built in. We have a few guides that talk about using Rocky as a secure foundation for RKE2. For this guide, Rocky for the win! And yes, please leave SElinux enforcing. Use installation method of your choice. If you have PXE infrastructure in place, use it. For cluster in the pictures, we used a usb-c thumb drive.

Software

Since we leverage Kubernetes in our deployments, we use some of the tools in the Rancher portfolio, namely RKE2 for the Kubernetes layer. Next, we use Longhorn for stateful storage across the nodes. And last but not least, we use the Rancher Multi Cluster Manager to orchestrate everything. (More on RKE2, Longhorn and Rancher MCM in a moment). For all the installs we follow the airgap instructions, and for good reason. The downside of the tactical edge is that you must assume there is no network communication with the outside world.

RKE2

What is RKE2 you ask? It is a fully conformant Kubernetes distribution that focuses on security and compliance within the U.S. Federal Government sector. Meaning it has FIPS, SELlinux, STIGs, compliance, and security support at its foundation. Another great reason to choose RKE2 for your Kubernetes layers is that air-gapping the software is not an afterthought. In fact, all of Rancher’s products have airgap install instructions. For the sake of this guide, we will skip providing the code. Please review the airgap install docs for RKE2. The basic procedure for installing air-gapped is to get the tarball that contains all the bits. It is also worth mentioning we have another article on applying the STIG and security best practices for RKE2 and Rancher on Intelligence Community News.

Longhorn

As mentioned above, Longhorn is Rancher’s storage product. Longhorn creates a highly available, encrypted at rest if enabled, storage layer using the aggregate storage already on the nodes. It’s a fantastic way to create storage for stateful applications without having to add additional hardware.

Similar to RKE2, Longhorn has very good documentation for installing across the airgap. Longhorn and Rancher MCM (more below) use a similar model of moving container images and Helm charts. For this reason, it often makes sense to stand up a registry inside the kit.

Rancher

Now let’s look at our flagship product the Rancher Multi Cluster Manager. The Rancher MCM enables you to create a single pane of glass to manage all the applications in your kit. Rancher manages the application life cycles through a variety of methods, including GitOps. Adding version control within the kit will help facilitate GitOps. Rancher’s primary method for installing is Helm. In order to install, air gapped charts will also need to be moved across with the images. Just like in the other products, the Rancher Air-Gapped install docs are very detailed.

At this point in our guide, we have walked through an edge kit that is fairly complete. However, there are a few applications that we can add to improve the functionality. They include:

·       Harvester: Harvester is Rancher’s hyperconverged solution. Harvester can serve Virtual Machines (VMs) out from one of the nodes. Being hyperconverged means Harvester can support VMs and Kubernetes applications from the same node. In fact, the cluster in the pictures above is running Harvester on the third node. Harvester gives the added ability to serve Windows VMs to the kit. Another great use of Harvester is to serve more infrastructure related applications to the kit, like DNS or version control. One fun fact about Harvester is that it uses Longhorn under the hood for storage. In certain applications, it makes sense to run Harvester on all three nodes and then use the VMs to carve out small compute envelopes. This is a good practice for different security domains.

·       Gitea: Gitea is a great solution for in kit version control. In practice, Gitea becomes the source of truth for how the applications are deployed – aka GitOps. One pro-tip is to use a Longhorn volume for Gitea for highly available, stateful, storage.

·       KeyCloak: KeyCloak is an authentication application that can provide Two Factor Authentication alongside SAML2 and OIDC. Basically, KeyCloak will give the kit a greater level of user management to not only Rancher but also to the applications that will be deployed into the kit.

·       Registry: Similar to Gitea as the source of truth for files. A registry is a good idea as a source of truth for images. Harbor is a really good choice for a registry. While the docs to not clearly call out an air-gapped install they do have a section to download the Harbor Install. Another alternative to Harbor is the original Docker Registry.

Hopefully, you now have a clear definition of the tactical edge and good understanding of how to deploy and leverage Kubernetes at the Edge. This guide is meant as a framework for implementing a similar kit that fits the applications compute envelope. At Rancher Government Solutions, we like to say that our software meets you at the mission – and this is one example of how.

To learn more about how Rancher deploys at the edge and supports mission critical work for customers, visit www.rancherfederal.com

About RGS

Rancher Government Solutions is specifically designed to address the unique security and operational needs of the US Government and military as it relates to application modernization, containers and Kubernetes.

Rancher is a complete open source software stack for teams adopting containers. It addresses the operational and security challenges of managing multiple Kubernetes clusters at scale, while providing DevOps teams with integrated tools for running containerized workloads.

RGS supports all Rancher products with US based American citizens with the highest security clearances who are currently supporting programs across the Department of Defense, Intelligence Community and civilian agencies.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Tactical Edge Reference Architecture appeared first on Intelligence Community News.

]]>
33685
DARPA launches EDGE program https://intelligencecommunitynews.com/darpa-launches-edge-program/?utm_source=rss&utm_medium=rss&utm_campaign=darpa-launches-edge-program Tue, 25 May 2021 13:16:20 +0000 https://intelligencecommunitynews.com/?p=29491 On May 21, DARPA announced its Enhancing Design for Graceful Extensibility (EDGE) program, which aims to create a suite of...

The post DARPA launches EDGE program appeared first on Intelligence Community News.

]]>
On May 21, DARPA announced its Enhancing Design for Graceful Extensibility (EDGE) program, which aims to create a suite of human-machine interface (HMI) design tools to be integrated into systems design processes. By prioritizing and orienting these tools towards quantifying, supporting, and testing situational awareness – rather than on cognitive load at the expense of situational awareness – EDGE will help create HMI systems that allow operators to not just monitor autonomous systems but also adapt their use to meet the needs of unanticipated situations.

“As highly-automated machines and AI-enabled systems have become more and more complicated, the trend in HMI development has been to reduce cognitive workload on humans as much as possible. Unfortunately, the easiest way to do this is by limiting information transfer,” said Bart Russell, EDGE program manager in DARPA’s Defense Sciences Office. “Reducing workload is important, because an overloaded person cannot make good decisions. But limiting information erodes situational awareness, making it difficult for human operators to know how to adapt when the AI doesn’t function as designed. Current AI systems tend to be brittle – they don’t handle unexpected situations well – and warfare is defined by the unexpected.”

The EDGE design tools will focus on supporting the ability of operators of autonomous systems, who are not necessarily data scientists or AI experts, to understand enough about the abstract functioning of a system that they can adapt with it when they encounter off-nominal situations. Designers will be able to leverage EDGE design tools to create HMIs that help operators understand an AI system’s processes, or how it works; the system’s status against its performance envelope (i.e., if it’s in its “comfort zone,” or near the edges of its speed, range, etc.); and the environmental context, which is often where the most unanticipated elements come in.

“We need HMIs that do a better job of exchanging information between the system and the human,” Russell said. “There’s a lot of work right now focused on designing machines to understand human intentions, called AI Theory of Mind. I’m interested in helping humans better understand the complex systems they’re teamed with. EDGE is specifically focused on the Observe, Orient, Decide and less on the Act in the OODA loop. It’s not about how fast you press a button, or the ergonomics of your cockpit, it’s about how well you perceive the information that’s coming to you and does that help you develop sufficient understanding of systems processes, status against the machine’s performance envelope, and the context in which it’s operating to still complete a mission despite off-nominal conditions.”

The suite of EDGE HMI design tools will include models that quantify situational awareness demands to enable detailed co-design between software engineers and HMI designers; composable design methods to speed and mature design implementation; and an HMI breadboard for realistic test and verification early in the design process.

A webinar Proposers Day for interested proposers is scheduled for June 1, 2021. More information and details about registration are available here: https://go.usa.gov/xHSKg. A Broad Agency Announcement (BAA) solicitation is expected be available on beta.SAM.gov in the coming weeks.

Source: DARPA

The post DARPA launches EDGE program appeared first on Intelligence Community News.

]]>
29491