Robust and Resilient Logistics Operations in a Degraded Information Environment

Don Snyder, Elizabeth Bodine-Baron, Mahyar A. Amouzegar, Kristin F. Lynch, Mary Lee, John G. Drew

ResearchPublished Nov 22, 2017

Cover: Robust and Resilient Logistics Operations in a Degraded Information Environment

Logistics operations depend on accurate information. Even relatively small errors in support systems can, in some circumstances, have large effects on operations. But errors are inevitable, so logistics operations should be robust to errors, whether they are a random occurrence or the result of a deliberate, targeted cyber attack. The U.S. Air Force asked RAND Project AIR FORCE to determine where it is most fruitful to focus effort in making changes to tactics, techniques, and procedures to improve an airman's ability to detect, evaluate, and mitigate significant corruption of logistics data. The goal is to respond to errors in data before they have a significant negative effect on combat operations.

Highly automated processes — in which humans do not see the data during normal operations — present a significant challenge for detection. Detection of corrupted data is most critical during wartime, yet anomalies are less evident during wartime than during peacetime because wartime itself is an anomaly. Therefore, mechanisms are needed to adjust detection mechanisms from peacetime to wartime conditions. For workers (airmen, civilians, and contractors) to detect anomalous data, they all must be trained to understand the expected baseline and must be continuously vigilant when examining data. Leadership must also create an environment that encourages workers to report suspected anomalous data.

Recommendations include defining, within logistics policy, what measures the logistics community should take in response to each information operations condition level and creating a new central body (perhaps within an existing organization) — the Global Data Integrity Cell — that would receive all reports of suspected data anomalies to enable enterprise-wide situational awareness.

Key Takeaways

Critical Areas in Which to Enhance the Ability to Detect Corrupted Data

  • The detection must be sufficiently prompt. Promptness results from a combination of individuals detecting and reporting corrupted data quickly and detecting corrupted data early in the chain of custody.
  • Highly automated processes — in which humans do not see the data during normal operations — present a significant challenge for detection. Automation requires special mechanisms to assist in detecting corruption.
  • Detection of corrupted data is most critical during wartime, yet anomalies are less evident during wartime than during peacetime because wartime itself is an anomaly. Mechanisms are needed to adjust detection mechanisms from peacetime to wartime conditions.
  • For workers (airmen, civilians, and contractors) to detect anomalous data, they all need to be trained to understand the expected baseline and need to be continuously vigilant when examining data.
  • Leadership must create an environment that encourages workers to report suspected anomalous data.

Recommendations

  • Define, within logistics policy, what measures the logistics community should take in response to each information operations condition level. This action is the most likely to yield positive, tangible results with the least expenditure of resources.
  • Adopt simple methods to detect data corruption in fully automated processes that are routinely used in fraud detection (such as Benford's Law).
  • Enhance the education and training of all members of the enterprise about the threat to operations from data corruption (and cyber attack more generally).
  • Supplement current reporting mechanisms and assessments.
  • Create a new central body (perhaps within an existing organization) — the Global Data Integrity Cell — that would receive all reports of suspected data anomalies to enable enterprise-wide situational awareness.
  • For optimal response, enact strategies to prioritize proactive mitigations and specific reported incidents. Assign a time frame for assessment of each incident and potential mitigation.

Topics

Document Details

Citation

Chicago Manual of Style

Snyder, Don, Elizabeth Bodine-Baron, Mahyar A. Amouzegar, Kristin F. Lynch, Mary Lee, and John G. Drew, Robust and Resilient Logistics Operations in a Degraded Information Environment. Santa Monica, CA: RAND Corporation, 2017. https://www.rand.org/pubs/research_reports/RR2015.html.
BibTeX RIS

Research conducted by

This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.