Internet Traffic Analysis and Cybersecurity in Homeland Security
This paper examines the role of internet traffic analysis in U.S. Homeland Security, exploring how the Department of Homeland Security (DHS) and the Department of Defense (DoD) collaborate to protect national cyberspace. It covers the significance of traffic analysis techniques, encrypted mobile communications, the security risks posed by portable devices, and the implications of borderless cyber threats. The paper also discusses the EINSTEIN 3 Accelerated (E3A) intrusion prevention system, Mobile Ad Hoc Networks (MANETs), and policy frameworks such as the Cyberspace Policy Review of 2009. Recommendations include incremental policy reform, expanded academic cybersecurity education, and greater integration of homeland security management training with STEM-oriented cyber programs.
- Introduction: DHS-DoD cybersecurity cooperation agreement and personnel exchange
- Background: The Cybersecurity Landscape: Borderless cyber threats and everyday digital vulnerability
- Importance of Internet Traffic Analysis and Mobile Messaging: Traffic interception techniques, MANETs, and encrypted messaging risks
- Security Risks of Portable Devices: Mobile device vulnerabilities and DHS workforce security gaps
- Resolution: EINSTEIN Systems and Network Security: EINSTEIN 3 Accelerated intrusion prevention and NCPS architecture
- Conclusion and Recommendations: Incremental reform, academic cybersecurity education, and policy gaps
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Grounds policy analysis in concrete institutional detail, citing specific agreements between DHS and DoD and naming particular programs such as EINSTEIN 3 Accelerated (E3A) and the National Cyber-Security Protection System (NCPS).
- Moves logically from background and threat identification through technical mechanisms to practical recommendations, giving the paper a clear problem-solution arc.
- Uses empirical data — attack-type breakdowns and data-breach statistics by industry — to support claims about the scale and variety of cyber threats.
Key academic technique demonstrated
The paper demonstrates policy synthesis: it draws on government reports, academic journal articles, and agency assessments to construct a multi-layered argument. Rather than relying on a single source type, the author triangulates official DHS documentation, scholarly analysis (Harknett & Stever; Kessler & Ramsay), and technical research (Kiran & Anish) to show how technological, institutional, and educational factors interact in national cybersecurity.
Structure breakdown
The paper opens with an introductory overview of DHS-DoD cooperation agreements, then provides background on the borderless nature of cyber threats and their effect on everyday infrastructure. A central section addresses traffic analysis techniques, mobile messaging risks, and MANET security. A separate section examines portable device vulnerabilities. The resolution section explains the EINSTEIN system architecture and managed security services. The conclusion advocates incremental reform and expanded academic programs, tying the practical and policy threads together.
Introduction
One of the biggest challenges currently faced by the Department of Homeland Security is guaranteeing cybersecurity. Each and every day some type of cybercrime occurs, and such crimes have the potential to affect the country's national security. This paper investigates the significance of internet traffic analysis to Homeland Security, including the importance of traffic monitoring, encrypted traffic and its implications for cybersecurity, and the manner in which the United States has handled cybersecurity over the past twenty years. The methods that the government has used during this period are discussed, as are encrypted mobile messaging applications. Recommendations and a conclusion are provided at the end.
In the recent past, the Department of Homeland Security (DHS) and the Department of Defense (DoD) signed an agreement to enhance cooperation between the two agencies with regard to improving United States cybersecurity capabilities. The agreement is aimed specifically at enhancing cybersecurity cooperation on capabilities development, mission activities, and strategic planning. It also outlines the specific individual and joint goals and responsibilities for both departments. The most crucial element of the agreement is a personnel exchange, which the Department of Defense expects will improve the different lines of communication between DHS and DoD.
Under the cooperation agreement, the Department of Homeland Security will appoint an individual to the position of Director of Cybersecurity Collaboration, who will work within the NSA (National Security Agency) and serve as the Department's liaison to the United States Cyber Command. In addition, the agreement specifies that DHS will supply additional staff from its offices to the National Security Agency, including officers from its Office of the General Counsel, Office for Civil Rights and Civil Liberties, and Privacy Office (Bobby, 2010). The DoD was to, in return, send a group of experts from its Cryptologic Services Group to the Department of Homeland Security's NCCIC (National Cybersecurity and Communications Integration Center), with the aim of supporting Homeland Security's cybersecurity efforts and coordinating those efforts with the operations of the DoD.
Despite the significant mutual support that both departments will offer each other, the agreement in no way interferes with the DHS and DoD authorities, oversight mandates, command relationships, or civil and privacy liberties. One of the most important strengths of the agreement is that Homeland Security will have greater access to the Department of Defense — particularly its National Security Agency — and its expertise and resources.
Background: The Cybersecurity Landscape
The borderless nature of cyberspace threats calls for increased collaboration between countries to combat them. International collaboration is a key component of DHS's cyber mandate of safeguarding and securing U.S. cyberspace. The Department, through the NPPD (National Protection and Programs Directorate), has created several functions to boost its international cooperation programs with other nations and organizations. These functions are carried out under the Office of Cybersecurity and Communications in NPPD. Several parties have, however, insisted that for the NPPD to succeed in its international collaborations program, it should streamline its functions and operations so that it can consolidate its resources and better facilitate foreign relations (DHS Can Strengthen Its International Cybersecurity Programs, 2012). The United States Computer Emergency Readiness Team also needs to improve its information-sharing with related agencies so that it can better coordinate incident response.
Cybersecurity encompasses all operations and activities aimed at protecting and securing cyberspace and computer infrastructure, in addition to measures aimed at restoring ICT systems and the information contained within those systems. To best protect a cyberspace, there is a need to form security policies and best practices, collect tools, develop guidelines and approaches, train staff, and deploy appropriate technologies. Additionally, cybersecurity involves the reduction of threats and vulnerabilities, incident response, deterrence of attacks, international cooperation, and recovery measures. Because cyber-attacks are borderless in nature, governments and international organizations must act in concert to develop cybersecurity policies, procedures, and plans with the objective of enhancing cooperation, incident response, and deterrence operations.
In the present-day world, many aspects of daily life have been moved to computers and online systems — for instance, education (online research, report cards, and virtual classrooms), healthcare (computer-based equipment and medical forms), finance (online bank transactions, electronic paychecks, and loans), government (online filing of birth records, death records, tax records, and social security), transportation (aircraft navigation, car engine systems, and traffic control signals), and communications (texting, cell phones, and email). This is where cybersecurity becomes essential: it involves all the protective measures aimed at deterring cyber-attacks and securing computer systems (Cyber Security Awareness, 2012). The growing volume and increasingly sophisticated nature of attacks targeting data theft, phishing scams, and other vulnerabilities require constant vigilance in protecting computers and ICT systems.
The most common types of cyber-attacks observed today include viruses, malware, worms, and trojans (50%); criminal insider threats (33%); theft of data-bearing devices (28%); SQL injection (28%); phishing (22%); web-based attacks (17%); social engineering (17%); and other attack types (11%) (Cyber Crime Statistics and Trends [Infographic], 2013).
The internet has empowered individuals like never before. Even adolescents with the right skills can effectively disable traffic control systems, manipulate stock trading, and steal personal information from online databases. What individuals can accomplish on their own, criminal groups can do on a larger scale. Organized crime groups have been involved in cybercrime for quite some time, and cybersecurity experts, scholars, law enforcement agencies, and governments contend that traditional criminal groups are becoming increasingly involved in electronic crimes. Available data shows, however, that cybercriminals are more likely to be loosely linked to online networks than to be entrenched members of formal criminal organizations. In the past few years, extremist organizations have also been found to use cybercrime to finance their activities. For instance, Imam Samudra, the mastermind of the 2002 Indonesia bombings, reportedly called on his followers to use credit card fraud to finance their militant activities.
Data breaches are also unevenly distributed across industries. Medical and healthcare organizations account for 38.9% of breaches, followed by business (35.1%), educational institutions (10.7%), government and military (9.9%), and banking, credit, and financial entities (5.3%) (Cyber Crime Statistics and Trends [Infographic], 2013).
Importance of Internet Traffic Analysis and Mobile Messaging
Traffic analysis is defined as the process of intercepting and examining online communications with the aim of making inferences from their patterns. Such analysis can be performed even when the online communications or messages cannot be decrypted (Kiran and Anish, 2015). This type of analysis works best with large volumes of messages: the higher the number of messages intercepted, the more that can be deduced from the information. Traffic analysis can be conducted by agencies for counterintelligence or military intelligence purposes. It can also be used by criminal organizations, making it a significant concern for cybersecurity experts. Knowing who is communicating with whom, at what time, and for what duration can give an attacker important clues about information that parties would prefer to keep private.
The size of packets being exchanged between two hosts can also be important data for an attacker, even when the attacker is unable to see the traffic contents. Observing a short series of single-byte payload packets with regular pauses between each packet may indicate an interactive session between two hosts, where each packet represents a keystroke (Kiran and Anish, 2015). Large packets maintained over time tend to indicate file transfers between hosts, also revealing which host is sending and which is receiving the file. On its own, this data may not be highly detrimental to network security; however, a creative attacker can combine this data with other information to evade intended security procedures (Northcutt, 2015). A mechanism based on traffic behavior can assist in the identification of P2P users and even differentiate the type of P2P application being used. IP/TCP also lends itself to traffic analysis to the point that "fingerprinting" of systems becomes possible. Passive fingerprinting tools — such as Tenable's Passive Vulnerability Scanner, Source Fire's RNA, and the free tool P0f — enable analysts to identify operating systems without actively sending probing packets.
High-ranking U.S. officials and lawmakers have intensified concerns regarding the growing threat of jihad-driven terror attacks against the United States. Social media activity by attackers has been found to connect individuals to radical groups, and FBI Director James Comey has noted that such incidents highlight the difficulties faced by law enforcement. The Islamic State has been increasingly guiding followers toward encrypted communications platforms, making it more difficult for law enforcement officers to access relevant data. This use of encrypted mobile messaging applications represents a direct challenge to traditional traffic analysis methods ('Terrorism has gone viral,' 2015).
Mobile devices present unique challenges for network security. Device intents or identities cannot be verified in advance; therefore, nodes must cooperate for the integrity of network operation. Nodes may, however, decline to cooperate by not forwarding packets for others in order to conserve their resources (Northcutt, 2015). Additional factors that make secure communication in informal wireless networks challenging include promiscuous operation modes, node mobility, restricted processing power, and restricted availability of resources such as bandwidth, memory, and battery power.
Conclusion and Recommendations
The Obama administration released its Cyberspace Policy Review in May 2009 — Guaranteeing a Trusted and Resilient Information and Communications Infrastructure — which it anticipated would lay the foundation for a new national cybersecurity approach. The most significant legislative proposal of that period, the Cybersecurity Act of 2009, suggested major alterations to existing federal government approaches. The common starting point of each of these reform attempts is that present federal organization and national cybersecurity policy is insufficient for the task of protecting cyberspace (Harknett and Stever, 2015). Whereas much of the current cybersecurity debate leans toward radical reform, this paper recommends an incremental strategy for reorganization — one that builds on the hard work of the previous decade and is accompanied by a re-conceptualization of the solution set. The path to cybersecurity is designed to be long, challenging, and complex. No significant federal policy reform can be achieved without taking into consideration the intergovernmental policy dimensions and the threat perceptions fueling those reforms. Success will remain elusive if the general public stays inactive in contributing to national cybersecurity (Harknett and Stever, 2015).
Increased education is another key recommendation. Since the 1990s, academic programs in information security have been available. The DHS and NSA co-sponsor the Center of Academic Excellence in Information Assurance Education (CAEIAE) program, which recognizes academic curricula and institutional dedication to information security education at two-year, four-year, graduate, and research institutions. However, at present there is no recognized academic certification agency or body for homeland security or cybersecurity programs specifically.
Academia should apply new thinking, new understanding, and new approaches to the country's response to cyber-attacks (Kessler, 2012). Just as cybersecurity is as much about policy and procedure as it is about technology, responses to today's cyber-related security challenges must encompass not only technical solutions but also numerous related subjects — including national defense, political science, history, diplomacy, and other social sciences. According to the Homeland Security Act of 2002, academia should take an active role in homeland security education (Kessler, 2012). Thus far, the DHS Science and Technology (S&T) Directorate has been the major point of contact between DHS and the academic community. Currently, the S&T Directorate supports twelve Centers of Excellence (COEs) through its Office of University Programs. These centers represent a broad network of universities that advance basic and applied research in science, technology, engineering, and mathematics (STEM) programs.
STEM-oriented cybersecurity programs are largely grounded in the physical sciences and focus on programming, tool development, and the application of security methods, rather than on managerial, evaluative, or policy dimensions of applied cybersecurity. By contrast, most homeland security programs tend to be broadly applied social programs that develop the critical and analytical assessment skills of middle managers. Incorporating cybersecurity policy and management elements into homeland security courses would directly address the academic needs of DHS and other homeland security agencies for the future.
Create your account
Always verify citation format against your institution’s current style guide requirements.