Appendix 2_Performance Work Statement_Amendment 01.pdf
PDF 209 KB Posted
- Attached to
- DNS Resolver Services Federal contract opportunity
- Solicitation number
- HQ0034-20-R-0264
- Issued by
- DOD Washington Headquarters Service
About this file
This performance work statement outlines requirements for a DNS resolver services contract to provide the Department of Defense with enhanced domain name system security and threat intelligence capabilities. The successful contractor will operate a secure, carrier-grade DNS resolver service leveraging commercial threat feeds and government-provided lists to block domains associated with security risks. The contractor must also establish and maintain a data lake to store DNS query logs from all downstream users for a minimum of six months online and one year in cold storage. Additional requirements include a web portal and application programming interfaces for control and data access, 99.999% service uptime, and training materials for new customers. The base period of performance is one year with two optional one-year extensions. The estimated query volume for the Department of Defense Information Network is 400 million queries per day but this is expected to increase as additional user groups are added to the service.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Appendix 1_Provisions and Clauses_Amendment 01.pdf | ||
| Synopsis_Solicitation_HQ0034-20-R-0264_Amendment 01.pdf | ||
| HQ0034-20-R-0264 QandA_Amendment 01.pdf | ||
| Appendix 2_Performance Work Statement.pdf | ||
| Synopsis_Solicitation_HQ0034-20-R-0264.pdf | ||
| Appendix 1_Provisions and Clauses.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED//FOUO
PERFORMANCE WORK STATEMENT (PWS)
HQ0034-20-R-0264
22 JULY6 AUGUST 2020
1. Project Title: DNS Resolver Service and Data Lake
2. Background
Cyber security threats leverage the Domain Name Service (DNS) during the course of malware campaigns. DNS resolver services providers to detect, mitigate, and evolve with threats and provide users the best, first line of defense. While some private sector companies have moved to commercial providers, the Federal government lags behind and remains vulnerable with an in-house, hand crafted defensive architecture. Seeking a modern approach, the DoD can leverage the threat intelligence curated and maintained by leading cyber security companies and stores logs in a secure, yet accessible data lake for analysis.
The Department’s need for real-time DNS protection based on up-to-the-minute intelligence increased with the Coronavirus (COVID-19) pandemic. According to public sources, malicious actors are exploiting the health crisis by:
● Establishing websites that pose as “official” information sources but in reality host exploit kits and malware;
● Conducting COVID-19 phishing campaigns (which started as early as January 2020);
● Spoofing DNS or hijacking router DNS settings;
“Scams include impersonating government organizations like the World Health Organization to try to solicit donations or trick users into downloading malware;
pretending to have information about government stimulus payments, and phishing attempts aimed at workers who are working remotely… in many cases the malware and phishing threats aren't new but just existing malware campaigns update to exploit fear and confusion around COVID-19.”1
These issues are exacerbated by an increasing reliance on the web and web applications to conduct business as more and more employees work remotely. A commercially provided DNS resolver service will provide a security capability for downstream
1 “Google saw more than 18 million daily malware and phishing emails related to COVID-19 last week”. The
Verge. Lyons, Kim. April 16, 2020. <https://www.theverge.com/2020/4/16/21223800/google-malware-phishing-covid-19-coronavirus-scams> organizations that will protect against threats and exploits first identified outside of the government, but incorporated into the vendor’s proprietary intelligence feeds.
Incorporating an architecture commonly found in the private sector, the Defense Digital Service (DDS) created a prototype, centralized outbound DNS resolution service that combined commercial DNS solutions leveraging their proprietary commercial feeds, combined with threat intelligence from the Intelligence Community (IC) to provide automated response and blocking. This prototype service provided monitoring and security for outbound DNS queries while also continually evolving with adversary threat intelligence.
The prototype demonstrated the efficacy of a cloud-based, commercially-provided DNS resolver service for the Defense Information Network (DoDIN) through the pilot. DDS is seeking to expand this service through a permanent, scalable solution.
3. Objectives
DDS is planning to transition the pilot capability to a commercial contractor, with the following objectives:
a. Provide Outbound DNS Resolver Service: Expand on a modern approach to providing security for the DoDIN and the Defense Industrial Base (DIB). This service will provide DNS layer blocking based on industry identified and validated threats and also facilitate DNS query privacy and integrity via DNS over TLS (DoT) and DNS over HTTPS (DoH). The long term objective is to improve protection against emerging threats through near real time integration of newly identified blocked applications and fewer false positives.
b. Leverage private industry to deploy a service that can be used by other U.S.
Government (USG) agencies and partners: Create a cloud-based platform that can scale across the DoDIN, as well as to other government agencies and non-government entities. The service should be capable of accepting traffic from DOD partners such as supply chain companies, other government agencies and their partners for which they have authority to provide cyber security services.
c. Provide a consolidated, cloud-based storage for identifying and researching threats: Query logs from downstream customers of the DNS resolver service will be stored in a consolidated, secured data lake. The government will identify varying levels of access controls that enable customers to view their own data, while allowing RDT&E and security operation programs to evaluate the broader data set.
4. Technical Requirements/Tasks and Deliverables
The following section specifies the Performance Objectives and Performance Elements for the contract. The government intends to procure the following services:
4.1 Performance Requirements
4.1.1 Secure DNS Resolver Service
The contractor shall provide a secure, carrier-grade DNS resolver service (i.e., providing high-availability and high-uptime). This will be upstream from the current on-premise implementations at desperate customers (e.g., government agency, DIB company facilities, or non-government entities) and will provide domain resolution and blocking services to downstream organizations via secure connections (via DoT and DoH) from downstream organizations.
The contractor shall provide a commercial security feed to its secure DNS resolver service and use this curated offering to prevent spam, Acceptable Use Policy (AUP) infractions, and botnet / malware infections. This commercial feed shall be capable of integrating additional sources identified and provided by the government to the contractor.
The DNS resolver service will only provide protection against domains classified as a security threat (i.e., it will not implement content blocking such as domains associated with adult content). Content blocking may be employed by the organizations that use the DNS resolver service on existing customer services (e.g., the customer organization may block sites resolved by DNS at their Web Content Filter layer). The DNS layer provides protection against security threats shall be deemed the default, global policy for all organizations downstream and requires organizations downstream to implement organization-specific content blocking that might differ between organizations. This allows individual mission enclaves to craft appropriate additional or less restrictive policies as necessary. The contractor shall allow policies to be created in a self-service manner through the service’s web portal or with consultation from a government identified representative at each organizational subcomponent level that points traffic to the DNS resolver service.
The initial scope requires the contractor to supply DNS security service to an expected user base that includes the DoDIN and government partners, such as DIB companies. These Internet-connected companies will have the option to point their corporate resolvers to the DNS service over an encrypted connection (DoT or DoH) or over UDP port 53 and receive the same protection as NIPRNet clients. As non- NIPR connected missions proliferate, this service will also be able to meet their needs and have similar security standards as the rest of the DODIN. Split VPN users may also be incorporated as immediate customers.
The DNS Resolver Service shall have the capability, with no restrictions, to accommodate additional customers as directed by the government, which include, but are not limited to: other non-DoD federal agencies, state and local governments, and organizations for whom the Government has authority for providing cyber security services.
4.2 Performance/Deliverables
4.2.1 Secure DNS Resolver Service
The contractor shall operate the secure DNS resolver services continuously, 24 hours per day, 7 days per week, 365 days per year (366 days in leap years) in accordance with the uptime requirements detailed in 4.2.1.1.
The contractor shall include, as part of providing DNS resolver services, blocking based on curated data feeds from the contractor’s proprietary threat lists. The contractor shall install a sufficient number of DNS resolver service instances, at discrete cloud locations, to assure performance thresholds are sufficiently managed.
The base DNS resolver service shall support, at a minimum, a user-base equivalent to the government’s estimates for NIPRnet users, DIB clients, and off-base users as indicated by the government. The contractor shall be able to scale the service as the government incorporates more users.
Quality Assurancee: Vendor shall provide an automated, real-time dashboard to the government. Failure to meet the threshold shall result in the government’s non-exercise of the next Option Year.
4.2.1.1 Uptime: The DNS resolver service shall maintain high-availability and high-uptime. Specifically, the DNS resolver service, as configured, shall use Anycast addressing. The DNS resolver service shall uniformly operate with multiple redundant locations, providing a single seamless and transparent user appearance, while each instance is discretely addressable by system administrators.
The DNS resolver service shall maintain availability in a fully operational state of no less than 99.999% of the time within any annual period.
Failovers to alternate operating locations shall respond within 60ms. Failover to a redundant resolver shall be resolved by an alternative resolver and provide optimal routing to resources based on the client query.
Quality Assurancee: Vendor shall provide an automated, real-time dashboard to the
4.2.1.2 Receiving Queries: The upstream resolvers shall support at least three methods of receiving queries from downstream clients: requests made over UDP port 53 and requests made via an encrypted connection (via DoT and DoH). DoT shall be the default as it supports privacy of DNS traffic and integrity of query responses from the upstream provider.
The government will identify and furnish to the contractor the names and contact information for organizations that are approved to point DNS traffic to the upstream resolvers.
Participating organizations agree to abide by these program’s terms and conditions in order to participate in this program’s service. This will include, but not be limited to, express written consent to make their query data available in a consolidated data lake and accessible for analysis by government entities. Data on queries resolved through this service will be accessible to the government at an enterprise wide level and to downstream organizations to view their own data based on access controls.
The vendor may not store query logs outside of the accredited data lake defined in Section 4.2.5.
The resolver must have the ability to apply global policy sets to all customers of the service. In addition, the resolvers must have the ability to apply different rulesets to each individual customer as defined by the government.
The government will identify and notify the contractor when an organization should be removed from the service. The contractor needs to support device attribution to the parent Organization, and limit use of the resolver solely to Organizations that the identified government representative authorizes to use the service.
Quality Assurance: Vendor shall provide an automated, real-time dashboard to the
4.2.1.3 Tier 3 Support: The contractor shall establish and maintain a Tier 3 help desk available continuously, 24 hours per day, 7 days per week, 365 days per year (366 days in leap years) as part of their normal operations with the ability to resolve issues with their DNS resolver service. The contractor shall manage a formal help desk ticketing system.
Organizations pointed to the service will have their own tier 1 support to manage blocked/allowed domains and tier 2 support to resolve issues at boundary layers or blocklists before the DNS resolver. The contractor shall provide organizations on the service with a contact phone number and email so that the Tier 3 support can be reached directly. The contractor shall begin technical response activities within 2 hours of each ticket receipt. The contractor shall provide status reports detailing the ticket status and disposition actions. Other specific tracking criteria shall be negotiated with the Government.
Quality Assurance: Vendor shall provide an automated, real-time dashboard to the
4.2.2 Threat Intelligence
The contractor shall provide internal, commercially-sourced threat intelligence to provide automated, dynamic (regularly updated) responses to domain queries.
This includes leveraging threat intelligence for the purposes of blocking domains associated with security threats, unblocking domains no-longer deemed a threat, and providing responses that redirect downstream clients to “sinkhole” resources (i.e., the ability to respond to a DNS query with the IP address of a service that will proxy the outbound connection).
Method of SurveillanceQaulity Assurance: Vendor shall provide an automated, real-time dashboard to the government. Failure to meet the threshold shall result in the government’s non-exercise of the next Option Year.
4.2.2.1 Sinkholes: The contractor shall provide the ability to establish sinkholes to gather information about previously-unclassified domains and determine whether it should be allowed or blocked. Also, these sinkholes will be used to gather additional intelligence from applications making requests to undesired domains (e.g., cross-domain violations or requests for updates for end-of-life operating systems). The contractor shall create sinkholes to include the ability to allow and block requests to domains as well as to respond with custom IP addresses as well.
The contractor shall provide a capability to create a custom response (e.g., a sinkhole or custom block page) to DNS queries based on the classification of the domain. For every security category, the provider shall allow for a custom IP address to be used in response to the DNS query.
This capability shall support and enable downstream organizations to troubleshoot false positives and immediately and rapidly identify where the classification is occurring across a variety of upstream resolvers.
Method of SurveillanceQuality Assurance: Vendor shall provide an automated,
4.2.2.2 Government Lists: The contractor shall provide the ability for the USG to supplement the existing sources of unclassified commercial threat intelligence used within the contractor’s DNS resolver service. The contractor shall have the ability to support up to 10 USG sources of domains in a variety of methods (rsync, SMTP, and
STIX).
The contractor shall establish a capability to identify and evaluate additions/deletions from the feed before introducing updates into production.
The government may provide supplemental lists of sites for blocking as government furnished information for incorporation. The government furnished information shall be incorporated into the DNS blocking within 24 hours of receipt.
The contractor shall create a capability to preserve threat intelligence provided by the USG as an isolated information and response set of the DNS resolver service strictly for the purposes directed by the USG. This will not be used to enrich the larger threat intelligence platform maintained by the contractor and provided to other customers. The threat feeds provided by the USG for use in the DNS resolution service shall be implemented exclusively for users of this Government-owned service.
Data analytics received from DNS queries sent to this service by the government are exclusively for use by this service and the government only and may not be incorporated into lists or services offered to other customers outside of this contract.
Method of Surveillance: Vendor shall provide an automated, real-time dashboard to the government. Failure to meet the threshold shall result in the government’s non-exercise of the next Option Year.
4.2.3 Downstream Blocking
The contractor shall provide the ability for the service to integrate with existing downstream protections.
This includes the capability to perform content filtering (or acceptable-use policy filtering) upstream, in addition to security based domain filtering. Downstream clients may perform their own content filtering based on the needs of the organization. Where there are potentially overlaps of common content blocks (e.g., domains associated with adult sites) those blocks may move upstream in future deployments. The initial deployment shall minimally perform security-based blocks only.
Method of SurveillanceQuality Assurance: Vendor shall provide an automated,
4.2.4 Control Interface
The contractor shall provide a web-based portal for downstream organizations to visually interface for the purposes of generating reports and queries, and for making modifications to response policies (e.g., blocked/allowed). This web-based portal shall default to provide viewing of only traffic from that organization.
The contractor will provide as a web application usage statistics and dashboards, providing alerts about blocking instances and the updating of filtering lists.
The government will identify and supply the contractor with the information of who should be given access to the web-based portal and at what permission levels.
All user level access to the control and data environments should enforce the use of multi-factor authentication.
Method of SurveillanceQuality Assurance: Vendor shall provide an automated,
4.2.5 Data Lake
The contractor shall provide a secure, performant, and dynamically scaling data lake service shall be built with industry best practices located within a cloud provider.
The service shall store all log and query information from the DNS resolver service in a searchable centralized data store for analytics.
Method of SurveillanceQuality Assurance: Vendor shall provide an automated,
4.2.5.1 Data Lake Infrastructure: The contractor shall store all query log information to include, at a minimum, each field of the DNS query packet. Additional information regarding the domain and context of the query shall be included based on best practice by the contractor and industry at large, to include date/time stamp, increasing consecutive integer count of log, and result of query. The data shall be stored in a cost-effective, highly-performant format (e.g., Parquet). This data lake shall be scalable and available for querying in near-real-time for a period of six months.
The contractor shall create a data lake that is able to maintain all queries from the DNS resolver service for that six month period. The contractor will maintain all queries for the specified time period regardless of size. The contractor should estimate the size requiring storage based on the expected queries per user provided in the contract structure.
The contractor shall migrate all information that has aged “six months”, barring any active processing conditions, to retained in long-term cloud storage (i.e., “cold storage”) for a period of one year. The long-term cloud storage shall have the capability to retrieve the information of the Government’s choosing. No information shall be discarded or removed from the long-term cloud storage without explicit written consent and agreement from the government.
The contractor shall provide a capability to enable downstream clients to be stored in the same location in the data lake; meaning, the method of transport for the query will be transparent to queries made to the data lake. The same query shall not need to be performed multiple times because of differing transport methods to receive the query from the downstream client.
The data lake shall be constructed in a modular fashion around the data itself.
Specifically, the system used to query the log data shall have the ability to be decoupled from the data itself, affording the ability to leverage differing query mechanisms or, if required, differing cloud providers.
Government shall retain all rights to the data and may transfer it to other storage locations at its discretion. The data shall be maintained in a consistent format that enables transfer. The data shall be maintained in a consistent format to enable consistent transfer methodologies, mechanisms and tools. The format or storage location of the data shall not dictate the technology used to gain insights into the data lake. All data (current and historical) must be available for download by the government or government appointed representative via commercial standard Application Program Interface (API).
Method of SurveillanceQuality Assurance: Vendor shall provide an automated,
4.2.5.2 Data Lake Management: The contractor shall ensure direct, programmatic access to the data lake. The contractor shall provide a web-based portal for generating basic queries. The contractor shall also provide access and infrastructure for clients of the data lake. This access shall use automated tools and exposure methods with open-standards protocols (e.g., psql) and connectors (e.g., ODBC/JDBC). Cloud-provider direct access is acceptable as well. The contractor will allow approved organizations that leverage the DNS resolver service to query their own DNS query history, including accompanying filtering adjudications.
Method of SurveillanceQuality Assurance: Vendor shall provide an automated, the government’s exercise of the next Option Year.
4.2.5.3 Data Lake Uptime:
The data lake service shall maintain availability in a fully operational state of no less than 99.99% of the time within any annual period. The DNS resolvers must be capable of maintaining all logs and analytics data in an event where the data lake is not available.
Method of SurveillanceQaulity Assurance: Vendor shall provide an automated,
4.3. Training and Documentation
The contractor will provide written documentation and standard training materials (such as video tutorials, handbooks, how-to sites, etc.) on how to operate and maintain all components of the service. When the government approves a new customer organization for on-boarding to the service, the government will supply the vendor with a point of contact and specification on access levels.
The contractor will support the customer organization in pointing its queries to the DNS resolver service and provide training through the documentation and materials to support their use of all elements of the service to include (setting up an account, pointing traffic to the resolver, accessing the control interface, blocking/allowing domains, accessing the data lake, downloading data, and using built-in analysis tools).
Method of SurveillanceQuality Assurance: Failure to meet the threshold shall result in the government’s non-exercise of the next Option Year.
4.4 Information Protection Requirements
The underlying cloud services for the DNS resolver (to include control interface) and All data lake services (to include limited analytic capability) must be eligible for accreditation to a government identified standard equivalent to FedRamp High or Impact Level 4 (IL4) within 30 days of award. Flexibility will be given to respondents who can show they are FedRamp Ready at the time of award.
This provides DDS and authorized users the ability to manage and access Controlled Unclassified Information (CUI) contained in the data lake.
The Defense Digital Service will work with the vendor to obtain service level Authority To Operate (ATO) if required for the solution. The solution will be required to comply with all applicable Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and DISA Cloud Computing Security Requirements Guide (SRGs).
Method of SurveillanceQuality Assurance: Failure to meet the threshold shall result in the government’s non-exercise of the next Option Year.
5. Query Load Estimate
The contractor shall provide DNS resolver services for DoDIN based on daily query load. Based on historical traffic data, the Government estimates DoDIN’s query load to be an average of 400 million per day.
The contractor is advised of potential changes arising out of new requirements to support additional user bases beyond DoDIN. The Government may modify the contract to add service for additional user bases, which will increase the estimated number of queries per day. Changes in the type of support required will not deviate from the scope of the services covered by this performance work statement.
6. Government Facilities
Basic facilities such as workspace and its associated operating requirements (i.e., phones, desks, utilities, information technology, and consumable and general-purpose office supplies) shall be available to contractors while working in Government facilities.
Contractors may need to access the Pentagon or other Government facilities for meetings. The government shall support providing access to visitors or acquisition of a Common Access Card (CAC).
7. Period of Performance
The contract includes a base period of 12-months, two option periods of 12-months each, and may include additional query support services within scope. The government will award a firm-fixed contract not to exceed 36 months.
Base Year (12months) Option Period 1 (12 months) Option Year 2 (12 months)
When executing an option year, the service level in that option period will reset at the base tier of 400 million queries per day. The government may decide to execute additional in-scope query support (See Section 5), dependent of availability of funds at any point during that option year as the need exists.
8. Contracting Officer Representative COR): The COR will be identified upon award of the contract. The COR monitors all technical aspects of the contract and assists in the contract administration. The COR is authorized to perform the following functions: assure the Contractor performs the technical requirements of the contract:
perform inspections necessary in connections with the contract performance:
maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements, including Government drawings, designs, specifications: monitor Contractor’s performance and notifies both the Contracting Officer and Contractor of any deficiencies; coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.
9. Management/Key Personnel
The contractor shall identify a Program Manager who shall be the primary point of contact for this effort. The Contractor will make technical recommendations for feature development on prototype deliverables to the government program manager who makes the acceptance of all deliverables and subsequent procurement decisions. The contractor will inform the government program manager of known issues in design and development of this prototype and make disclosure of known risks associated with any of the other activities to be conducted under this award.
Deliverables and recommendations shall be provided for government review and approval.
10. Contractor Travel
Travel may be required to various CONUS and OCONUS non-hazardous locations.
The Contractor shall travel as initiated by written tasking and approved by COR prior to travel. The contractor can choose to work in their normal place of business/duty in the National Capital Region. The contractor shall ensure that travel expenses are incurred in accordance with the limitations set forth in FAR 31.205-46.
11. 508 Compliance
Compliance with Section 508 of the Rehabilitation Act of 1973. All electronic and information technology (EIT) procured through this contract must comply with Section 508 of the Rehabilitation Act (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998, unless an agency exception to this requirement exists. See http://www.section508.gov. The Contractor shall indicate for each line item in the schedule whether each product or service is compliant or non-compliant with these accessibility standards. Further, the proposal must indicate where full details of compliance can be found (e.g., vendor’s website or other specific location).
12. Release of Information The Contractor shall not disclose or release to other than Government authorized persons or activities, the content of any Government software, procedures, materials or products generated under this contract, or information provided to the Contractor.
13. Security/Classification
All personnel performing on this contract shall be U.S. citizens.
14. Facility Security Clearance The work to be performed under this contract is up to the FOUO/Unclassified level.
http://www.section508.gov/
File details come from the government source that posted it. Updated .