‘Cyber magazine’ can run out ‘pretty damn quick’ in modern conflict: Admiral在现代冲突中,“网络弹药”可能“很快就会耗尽”:海军上将
In the wake of public debates about the health of physical US munitions, a senior Navy official said the "cyber magazine" isn't infinite either.

U.S. Cyber Command members work in the Joint Operations Center at Fort Meade, Md., April. 2, 2021.
WASHIGTON — While US officials have warned of munitions shortfalls from the Iran conflict, the Navy’s top cyber official identified another key observation from recent military operations: the “cyber magazine” can be vulnerable to exhaustion as well.
“Your cyber magazine of these exquisite fires is empty pretty damn quick,” Vice Adm. Heidi Berg, commander of Fleet Cyber Command/10th Fleet, said in response to a question regarding lessons from Russia’s invasion of Ukraine and US operations in Venezuela, the Middle East and elsewhere.
“How are you going to regenerate and continue to develop accesses and effects to be able to deliver over the course of what will almost always be against a peer competitor, a longer-term sustained conflict?” she added, speaking at HammerCon, hosted by the Military Cyber Professionals Association on Thursday.
Berg did not go into details, but officials and experts for years have acknowledged that cyber capabilities and bespoke exploit tools are not limitless, necessarily reusable or easy to come by: once an adversary, or company, patches a flaw in a system, the tactic can become obsolete. They also can’t be replenished like traditional munitions with an infusion of money and production lines, given it requires time and skill to discover exploits and develop the tools to take advantage of them.
While the debate about a shortfall in physical munitions has splashed across headlines , the status of America’s cyber munitions has remained largely out of the public eye, especially in the context of operations in Iran. Cyber has often been thought of as a persistent, daily contest below the threshold of armed conflict, but now the US has found itself in sustained combat operations in cyberspace since the launch of Operation Epic Fury (OEF).
“From an OEF perspective, just to put in perspective, so 28 February, and it hasn’t stopped. Probably for the first time for the cyber force at large, it’s been this constant,” Lt. Gen. Christopher Eubank, commander of Army Cyber Command and the cyber official charged with running cyber operations in the Middle East , said during the same event.
After Epic Fury initially kicked off, experts told Breaking Defense that in one-off operations such as Absolute Resolve that captured Venezuelan leader Nicholas Maduro — which Berg described Thursday as “the largest and most complex cyber operation that had ever been executed” — perpetual access isn’t always as big a concern as sustaining a military campaign over time.
But Jason Kikta, a former cyber operator with CYBERCOM, told Breaking Defense today that access was the “real asset” in cyber operations and agreed that it is “quickly expended and slow to replenish.”
With sustained activity in Epic Fury, there will be many missions that will evolve and change parameters and priorities as the battlefield and cyberspace evolves, while American hackers will be working around the clock to find more accesses. But, there’s still always the question of what to do once accesses are gained: continue to gather intelligence, or to break something, which almost certainly eliminates the ability for cyber to impact that target again while also closing any intelligence value.
As far as the price tag for developing ever-newer cyber capabilities, US Cyber Command, in an unfunded priorities list sent to Congress earlier this year, requested an additional $229 million for scaling cyber operational capacity and the development and deployment of cyber munitions, according to InsideDefense . Those funds would go toward limitations in CYBERCOM’s ability to generate and sustain cyber effects at speed and scale, the publication reported.
2021年4月2日,美国网络司令部成员在马里兰州米德堡联合行动中心工作。
华盛顿——尽管美国官员警告称伊朗冲突会导致弹药短缺,但海军最高网络官员从最近的军事行动中发现了另一个关键现象:“网络弹药库”也可能面临弹药耗尽的风险。
“你们这些精彩绝伦的网络武器库很快就会被消耗殆尽,”海军中将、第十舰队网络司令部司令海蒂·伯格在回答有关俄罗斯入侵乌克兰以及美国在委内瑞拉、中东和其他地区的行动所带来的教训的问题时说道。
“你们将如何重建并继续发展各种手段和手段,以便在几乎总是与势均力敌的对手进行的长期持续冲突中能够有所作为?”她在周四由军事网络专业人员协会主办的 HammerCon 大会上补充道。
伯格没有详细说明,但多年来,官员和专家都承认,网络能力和定制的漏洞利用工具并非无穷无尽,也未必可以重复使用或轻易获得:一旦对手或公司修复了系统中的漏洞,这种策略就会失效。而且,它们也不能像传统军火那样通过注入资金和生产线来补充,因为发现漏洞并开发利用这些漏洞的工具需要时间和技能。
尽管关于实物弹药短缺的争论占据了各大媒体的头条,但美国网络弹药的状况却一直鲜为人知,尤其是在伊朗行动的背景下。网络空间通常被认为是一种持续不断的日常对抗,其程度低于武装冲突的门槛,但自“持久自由行动”(OEF)启动以来,美国发现自己已在网络空间陷入了持续的作战行动。
“从持久自由行动的角度来看,为了让大家更好地理解,从2月28日开始,行动就一直没有停止。对于整个网络部队来说,这可能是第一次出现如此持续不断的行动,”陆军网络司令部司令、负责中东地区网络行动的网络官员克里斯托弗·尤班克中将在同一场合说道。
在“史诗狂怒”行动最初启动后,专家告诉《防务新闻》,在像“绝对决心”行动这样的一次性行动中(该行动抓获了委内瑞拉领导人尼古拉斯·马杜罗,伯格周四将其描述为“有史以来规模最大、最复杂的网络行动”),持续访问并不总是像长期维持军事行动那样令人担忧。
但美国网络司令部前网络操作员杰森·基克塔今天告诉《防务新闻》,访问权限是网络行动中的“真正资产”,并同意访问权限“消耗很快,补充很慢”。
随着“史诗狂怒”行动的持续进行,许多任务将随着战场和网络空间的演变而不断演进,其参数和优先级也会随之改变。与此同时,美国黑客将夜以继日地寻找更多入侵途径。但是,一旦获得入侵途径,下一步该做什么始终是个问题:是继续收集情报,还是破坏系统?破坏系统几乎肯定会使网络攻击无法再次影响目标,同时也彻底抹杀了情报的价值。
据《InsideDefense》报道,美国网络司令部在今年早些时候提交给国会的一份未获拨款的优先事项清单中,要求额外拨款2.29亿美元,用于扩大网络作战能力以及研发和部署网络弹药。该媒体还报道称,这些资金将用于弥补网络司令部在快速、大规模地产生和维持网络效应方面的能力不足。