Attachment_L-4_Notional_CPFF_TO.docx
DOCX document 25 KB Posted
- Attached to
- Air Force Cyber Operational Testing, Engineering and Range Support (AFCOTERS) Federal contract opportunity
- Solicitation number
- FA255015R8005
About this file
Attachment L-4
View the file
Other files for this federal contract opportunity
Show all 42
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA2550-15-R-8005 Attachment L-4 Notional Cost-Plus-Fixed-Fee Task Order based upon the following Scenario.
This scenario is based upon an actual system, but has been fictionalized. Most often, the 346th Test Squadron must conduct tests on systems with little background information, except a concept of operations and some performance parameters. The task is to develop test measurements and a general description of how the test would be conducted with the elements that would be required for test completion.
Scenario: A system is to be tested. It is not part of the traditional acquisition process and consequently, has no Test and Evaluation Strategy, no Capabilities Design or Production Documents or Test and Evaluation Master Plan. As such, there is no information on the system except what is given in this scenario. The test sponsor has asked for an Operational Utility Evaluation on the system.
System Under Test: Network Intelligence Preparation of the Battlespace Exploitation System
Purpose: The Network Intelligence Preparation of Battlespace (IPB) System provides needed intelligence information of enemy networks. Types of information provided includes: location of mailservers, webservers, backdoors, and vulnerabilities. System can also map target networks and identify known vulnerabilities. The System will be used to gather network IPB.
System must perform the following specific capabilities:
Locate Mail Servers Locate Web Servers Discover existing backdoors Map path to specific IP addresses Locate vulnerabilities based on known vulnerability list. System must operate in garrison operation. Software must run on single laptop or workstation. System must be autonomously operated by 5 level IO specialist.
Test Requirements:
To scan for any mail servers on target network given an IP address range.
Discovery/Connection Scan for ports 25 and 691.
Scan for Operating systems, versions, service pack levels using above ports.
Scanning can be conducted at default speeds (usually fast and not worried about detection. Mail servers generally have high amounts of traffic hitting these ports so being "stealthy'' is not an issue for this run). After finding any targets with these ports, conduct scan to determine operating system.
To scan for any Web Servers Web Servers generally have high volumes of traffic as well so being "stealthy" is not an issue for this scan as well.
Discovery/Connection Scan for ports 80, 8080, 443, 4343.
Scan for Operating systems, versions, service pack levels using the above ports.
To look for a "backdoor" port into target network.
Scan for Operating System listening on above port. Report any other ports open on this box.
This scan should be done in "stealth" mode as the scenario could be looking for our own backdoor and will not want to be detected.
Using Stealthy Scan search for port 12345 Scan for Operating System listening on above port. Report any other ports open on this box.
To Find/Network map target network infrastructure.
Scan should be conducted in Stealth mode as to avoid detection from targets.
Slow Stealth Scan should be done in verbose to gather information targeting infrastructure devices (i.e. routers, switches, firewalls, etc).
Should also look for ports 161and 162 on these devices as a possible vulnerability.
Find any open ports on the Firewall.
Scan given IP range for potential targets Scan will be conducted over a given IP range in order to locate and identify potential targets Scan should be conducted either in stealth mode or in between stealth and normal. The idea is to conduct a scan but not to set off too many alarms to your presence.
Should be conducted in a sense to find host/client boxes and identify various operating systems.
Should note and collect data on any open ports for potential vulnerabilities.
System Criteria:
Key Performance Parameters
| Number |
| Threshold |
| Objective |
| Parameter |
| KPP1 |
| 15 min |
| 12 min |
| Time to complete mission - single function |
| KPP2 |
| 3 min |
| 3 min |
| Recovery time from failure |
| KPP3 |
| 50% |
| 100% |
| System accuracy in identifying targets |
| KPP4 |
| 1% |
| 1% |
| False positives |
System must include the following:
Training program to train level 5 IO specialists how to independently operate the system.
All documentation needed to support operation of the system.
Operators must be trained to operate all hardware and software needed to perform missions.
Perform mission planning to translate operational tasking into necessary input to perform scan.
Operate the scanning tool with the aid of support documentation.
Understand the results of the scans.
Summarization:
Develop a set of test measures to complete an operational test according to the information provided. Describe the procedures required after the development of the test measures to complete a test; the requirements in terms of what needs to be developed and what needs to be accomplished for successful test execution; and the appropriate labor/skill mix required to successfully accomplish the tasks. Answer succinctly. Provide total cost to perform these efforts if issued as a Cost-Plus-Fixed-Fee Task Order. Submit detailed cost breakdown information in the offeror’s own format; to include labor hours, base labor rates, indirect rates and fee.
File details come from the government source that posted it. Updated .