Technical Responses - 31 JUL 2020.pdf

PDF 33 KB Posted

Attached to
Enhanced Network Visualization Environment Cyber Operations Infrastructure Federal contract opportunity
Solicitation number
W56KGY-19-R-0003
Issued by
Department of the Army Materiel Command Army Contracting Command Aberdeen Proving Ground

About this file

This document contains a Request for Information from the Department of the Army Materiel Command Army Contracting Command seeking industry feedback on cyber capabilities. Respondents are requested to submit a white paper by 30 days after posting demonstrating their ability to develop and perform cyber capabilities including visualizing networks using packet capture data, parsing known and unknown protocols from bulk historical or live streaming data of 100Gbps or faster through custom programming, conducting deep packet forensics and fingerprinting, producing systems for both passive and active in-line data capture, and extracting products from large data captures of gigabytes or more. Responses must also show the ability to gain and maintain a TS/SCI authority to operate and include a SCIF rated to TS/SCI.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Question 1. Will the Government accept responses that are classified?

Responses will be at the unclassified level.

Question 2. We understand there are multiple definitions for terms such as ‘active’ vs ‘passive’. Would the Government please clarify the terms “active vs. passive in-line capture” with a definition or by providing an example?

A “passive in-line capture” is a capture of network traffic that is done without requiring an agent to be installed on any device in the network and which can be accomplished using an in-line tap (e.g. Gigamon, Ixia Flex Tap) such that there is no active participation (i.e. no network traffic generated) on the network by the capture device.

An “active” capture is one that requires an agent to be running on devices or that actively sends traffic across the network in order to gain information about the nodes on the network. An example of an active capture tool is ACAS.

a) For your question 2 in the RFI solicitation, regarding parsing "unknown protocols", does it mean for the traffic with unknown protocols, our solution is supposed to parse the known parts of traffic and store/detect/label the other parts with "unknown"?

The question is asking if the vendor is capable of custom programming, or using COTS / GOTS solutions, to parse protocols that are not widely published. Examples include certain proprietary network protocols, unpublished protocols introduced by foreign governments, etc.

b) For your question 2 in the RFI solicitation, regarding "bulk historical data or live stream data of 100Gbps or faster", does it mean integrating with a particular hardware to process live stream of 100Gbps or faster?

What processing (e.g., deep packet forensics) is in the scope?

Bulk historical data is data that has been captured at an earlier time in the form of PCAP, network device artifacts, etc. Bulk could mean many terabytes of data.

For live stream of data 100Gbps or faster, can the solution integrate with a network feed of 100Gbps and perform active deep packet inspection to produce an accurate network topology in near real time.

c) For your question 3 in the RFI solicitation, what is in the scope for the fingerprinting capability, e.g., endpoint and network information such as OS, device, hardware, firmware, software (version, patches, etc.), protocols at different layers, etc., if applicable?

Fingerprinting should be as accurate as possible, providing as much detail about the network node or endpoint as can be extracted from the analysis of the capture. Precision is important, such that a fingerprint of “Windows” for the OS of an endpoint is less valuable than a fingerprint of “Windows 7”, which is less valuable than a fingerprint of “Windows 7, SP1”, etc.

d) For your question 4 in the RFI solicitation, regarding “active in-line data capture”, is it in the scope for inline active flow monitoring? What else is in the scope? In my opinion, this might be related to our question b).

Can the vendor provide the means to feed captures from the network, to include passive captures collected from a tap or active captures collected using a COTS / GOTS capability that has direct access to the network and devices on the network, to the processing system to perform analysis and produce an accurate network topology?

e) For your question 6 in the RFI solicitation, does it mean maintaining SCIF at TC/SCI level? Is it a must for this effort?

The vendor must have a SCIF that is rated up to the TS/SCI level for this effort.

File details come from the government source that posted it. Updated .