Networks & Digital Warfare

Why patching networks against cyberattacks is ‘very scary’ in the age of AI

The long-standing mantra that certain operational systems must be continuously available and can’t be brought down for a patch is becoming harder to defend as cyber threats accelerate, US officials warn.

US airmen work on network scripting codes and patching vulnerabilities at Shaw Air Force Base, S.C., Aug.18, 2023. (US Air Force photo by Airman 1st Class Mariana Tafur)

TAMPA — The lowly software patch has become a big headache and growing operational problem for Pentagon and defense industry networks due to the explosion of cyberattacks driven by artificial intelligence, a topic that dominated the Defense Intelligence Agency’s DODIIS show this week. 

Multiple speakers here noted that vulnerabilities are being discovered and exploited faster, vendors are issuing fixes at an unprecedented rate and government networks cannot simply be taken offline every time software needs to be updated.

Roger Greenwell, CIO of the Defense Information Systems Agency, described a cycle that is putting a heavy burden on those responsible for patching.

“What keeps me up at night is recognizing that our adversaries are using these capabilities to look for inherent vulnerabilities within our software, within industry software, within common software,” he said. “The speed at which we need to be able to patch [is] working our people very hard these days.

“All of these vendors are out there looking in depth at their code, discovering vulnerabilities, coming out with patches at a rate that we’ve never seen before,” Greenwell said. “How do you make sure that you actually are getting those patches applied to everything? How are you taking care of your workforce who is working rapidly to do this trying to stay ahead of the game.”

The problem is that installing patches often means interrupting systems supporting intelligence, communications, command and control, and other missions that cannot easily tolerate being off-line. 

“We can’t afford the downtime,” Greenwell said, adding that the answer increasingly depends on resilient architectures and industry products with the “ability to dynamically patch literally at a moment’s notice.”

Colin Hankey, the State Department CIO with responsibility for its Intelligence Community element, said the accelerating tempo is also changing cybersecurity risk calculations. 

“We now have an intensity of patching, intensity of security alerts that requires us to accept a little more risk than we used to have been willing to accept because the time just isn’t there,” Hankey said. “We don’t have the ability to sit down and figure out exactly what the impact is going to be. That’s very scary, and there isn’t an easy answer.”

The choice is increasingly between rapidly applying a fix without fully understanding its operational consequences or leaving a known vulnerability exposed. Or, as Hankey put it: “What risk do you accept by not patching?”

There is another complication: a patch itself may not solve the problem.

Defense Intelligence Agency (DIA) CIO Edacheril “EP” Matthew pointed to one case in which a DIA cybersecurity tool identified a zero-day vulnerability in industry and alerted an unmanned vendor. The company issued a patch several weeks later, but according to Matthew, another scan showed “that patch was not valid, not efficient,” forcing officials to return to the vendor before the vulnerability was ultimately corrected.

US Strategic Command Deputy CIO Elizabeth Durham-Ruiz framed patching as a basic readiness requirement. In the beginning of the Russia-Ukraine conflict, she said, officials “struggled” with whether systems could safely be interrupted for updates. 

“The original thought was we’re going to just stop patching,” Durham-Ruiz said. That was untenable, she added, and eventually they settled on setting up an entire team that was charged with reviewing every authorized service interruption. 

Her analogy was physical weapons maintenance: “If you didn’t do maintenance on your weapon system, if you didn’t do maintenance on your aircraft or your submarine, you wouldn’t be able to have trust in that system moving forward.”

For US Transportation Command’s James Grimsley, deputy CIO and executive director for command, control, communications, and cyber systems, the underlying cultural problem is the long-standing mantra that certain operational systems must remain continuously available and can’t be brought down for a patch. That tradeoff is becoming harder to defend as cyber threats accelerate.