Two connected learning models Explore the linear model at KillChains.com

Preserved research input · KW-RPT-004

The Vulnerability Surface of Kill Web Architectures: Non-Kinetic Disruption and Defense Strategies in Joint All-Domain Command and Control

An analysis of non-kinetic disruption, timing, middleware, electromagnetic, supply-chain, and zero-trust challenges in distributed battle networks.

Digest verified 1bf27ca84e9020b7c2c084fbccced36a674ee8c012297e943a5015eda3d51c22

The Vulnerability Surface of Kill Web Architectures: Non-Kinetic Disruption and Defense Strategies in Joint All-Domain Command and Control

Introduction to the Distributed Algorithmic Battlespace

The paradigm of modern warfare has fundamentally shifted from a platform-centric approach to a data-centric architecture, fundamentally altering the calculus of military power projection and defense. Historically, military operations relied on linear, highly rigid "kill chains," wherein discrete, sequential steps—ranging from target acquisition by a specific sensor to engagement by a designated shooter—were executed through centralized command and control (C2) structures1. Today, driven by the proliferation of advanced sensors, autonomous systems, and artificial intelligence (AI), concepts such as the United States Department of Defense’s (DoD) Joint All-Domain Command and Control (JADC2) and the Defense Advanced Research Projects Agency’s (DARPA) Mosaic Warfare envision a radically different operational framework: the interconnected "kill web"1. Within this architecture, the traditional linear kill chain is replaced by a perpetually changing, omnidirectional network of observation, orientation, decision, and action nodes operating seamlessly across the land, sea, air, space, and cyber domains1. The core objective of the kill web is to ensure that any sensor can cue the most appropriate effector in near-real-time, stripping away the fragility of single-point failures and creating overlapping dilemmas for the adversary2. By utilizing cloud computing, algorithmic warfare, and multi-path communication networks, a kill web allows for force disaggregation, enabling a military to absorb localized kinetic losses while maintaining systemic combat effectiveness4. However, this profound operational elasticity inadvertently vastly expands the digital and electromagnetic attack surface8. Adversarial doctrines have evolved to recognize that attempting to out-scale or out-attrit a high-end kinetic defensive architecture is economically and strategically unviable9. Consequently, near-peer competitors have pivoted toward non-kinetic disruption, aiming to paralyze the opponent's kill web through electronic warfare (EW), cyber intrusions, Global Navigation Satellite System (GNSS) spoofing, and data poisoning11. This exhaustive report investigates the non-kinetic and cybersecurity vulnerabilities inherent in a kill web architecture. By analyzing the intersection of algorithmic manipulation, electromagnetic spectrum operations (EMSO), precision timing protocols, legacy hardware integration, and the complexities of deploying Zero Trust Architecture (ZTA) at the tactical edge, the analysis reveals how adversaries can disrupt, degrade, and deceive a interconnected network without ever resorting to kinetic strikes.

The Point Defense Paradox and Architectural Fragility

The transition from concentrated, high-value military platforms to highly distributed networks introduces a severe structural vulnerability characterized as the "point defense paradox"1. Traditional air and missile defense (AMD) doctrines were predicated on the static protection of a handful of major installations, utilizing layered coverage to defend discrete, high-value assets1. The kill web's distributed operations—such as the U.S. Air Force's Agile Combat Employment (ACE)—exponentially expand these defensive requirements, necessitating the protection of dozens or hundreds of disaggregated nodes, each possessing varying levels of criticality to the overall network1. Because it is logistically and economically impossible to physically defend every dispersed node in a disaggregated web, the architecture relies entirely on its software and its ability to rapidly share data, adapt routing, and compose new engagement solutions on the fly to survive physical attrition15. This agility is predicated on continuous, uncorrupted data flow17. If an adversary can sever the logical and electromagnetic links between these nodes, or poison the data being shared among them, the distributed force is rapidly reduced to isolated units incapable of coordinated action, effectively rendering advanced long-range munitions and distributed sensors useless19. The structural complexity of JADC2 further compounds this cyber vulnerability. Current military systems suffer from proprietary data stores, disparate visualization formats, closed architectures, and incompatible radio protocols established during an era of service-specific acquisition22. The mandate to integrate these heterogeneous systems introduces numerous technological software bridges and translation layers that, while solving interoperability, create novel exploitation vectors20.

Architectural CharacteristicLegacy Kill Chain ConceptEmerging Kill Web Concept (JADC2/Mosaic)Primary Non-Kinetic Vulnerability
Network StructureSerial, linear, rigidMesh, multi-path, dynamically composableCascading failure via algorithmic manipulation or middleware exploitation
Component IntegrationPre-integrated, homogeneous platformsComposed on-the-fly, highly heterogeneousDynamic translation latency and unauthenticated data bus hijacking
Defense ParadigmPoint defense of major hubs/basesDistributed network resilience and redundancyNode isolation via broad-spectrum electronic warfare (EW)
Decision TempoHuman-in-the-loop (hours to minutes)AI-driven "Super-OODA" (seconds to milliseconds)Data poisoning, model extraction, and operator automation bias

Adversarial Doctrine: System Destruction Warfare

Understanding the vulnerabilities of the kill web requires analyzing the doctrinal frameworks developed to defeat it. The Chinese People's Liberation Army (PLA), observing the devastating effectiveness of U.S. network-centric warfare during the 1991 Gulf War, developed a strategic doctrine known as "System Destruction Warfare"6. This doctrine operates on the premise that modern conflict is no longer a clash of individual platforms or units, but a confrontation between opposing complex operational systems13. Under System Destruction Warfare, the primary objective is to paralyze or destroy the adversary's system-of-systems at its critical nodes and linkages rather than seeking the total kinetic annihilation of enemy forces13. The tactics focus on blinding intelligence, surveillance, and reconnaissance (ISR) radars, jamming communication links, and disrupting command structures to achieve the rapid degradation of enemy command authority10. By integrating space, cyber, and electronic warfare capabilities—formerly under the Strategic Support Force (SSF)—the PLA aims to execute "Multi-Domain Precision Warfare," unified by artificial intelligence to coordinate simultaneous attacks across all operational domains10. This doctrine is aggressively operationalized through state-sponsored cyber and intelligence apparatuses, such as the Ministry of State Security (MSS) and the United Front Work Department (UFWD)10. Advanced Persistent Threat (APT) groups, such as Volt Typhoon and the Shadow-Earth-053 campaign, actively target critical civilian and military infrastructure across the Indo-Pacific and the United States10. By pre-positioning malware in water, power, and communications grids, these actors seek to disrupt domestic mobilization, logistics, and the foundational networks required to sustain a kill web during the onset of a crisis10. Furthermore, the co-opting of "frontier" companies globally allows for the clandestine insertion of hardware and software backdoors into dual-use technologies, transforming the global supply chain into an active attack vector against the kill web10.

Algorithmic Warfare and the Vulnerability of the Super-OODA Loop

The strategic objective of a kill web is to achieve decision dominance by operating continuously inside an adversary’s Observe-Orient-Decide-Act (OODA) loop13. Originated by U.S. Air Force Colonel John Boyd, the OODA loop emphasizes that operating at a faster and more effective cognitive tempo allows a force to enmesh the adversary in a world of confusion and disorder24. By integrating Artificial Intelligence (AI) and Machine Learning (ML), algorithmic warfare compresses this human-scale cognitive process into a machine-speed automated cycle, fundamentally altering the character of war by creating a "Super-OODA loop"11. Within JADC2, this manifests as a "Sense, Make Sense, Act" paradigm25. Automated Target Recognition (ATR) algorithms utilize computer vision to process terabytes of sensor data (Observe), predictive analytics fuse this data into a Common Operating Picture (Orient), and AI battle managers generate thousands of optimized cross-domain engagement strategies (Decide) in a matter of seconds2. However, delegating critical cognitive functions to AI models introduces acute, systemic vulnerabilities categorized under Adversarial Machine Learning (AML). If the algorithmic foundation of the kill web is compromised, the very speed of the system becomes a lethal liability, rapidly propagating corrupted decisions and false targets across the battlespace29.

Data Poisoning in the Sensor Grid

Data poisoning constitutes a preemptive or active attack on the ML models underpinning the kill web. Because an AI system's efficacy is entirely dependent on its training data, adversaries can inject deceptive inputs to manipulate the algorithm's learned parameters before or during deployment2. In a military context, if an AI is trained on data containing subtle, adversarial manipulations, the deployed model may systematically misclassify threats, ignoring enemy armor or flagging civilian infrastructure as hostile29. A critical weakness of the sensing grid is its susceptibility to inaccurate predictions generated by forced data poisoning via cyber-attacks31. Adversaries can embed false "patterns of life" into intelligence streams, slowly corrupting the AI's baseline of "normal" behavior31. As the AI incorporates this poisoned data through continuous learning, it begins to classify abnormal, hostile movements as benign, corrupting the orientation phase of the OODA loop31. This slow-burn degradation sows confusion and distrust in the AI's recommendations, achieving the adversary’s goal of paralyzing the commander's decision-making process without triggering traditional cyber-intrusion alarms31. Furthermore, reliance on imported commercial datasets, Graphics Processing Units (GPUs), or pre-trained AI models creates immense strategic vulnerabilities11. Recognizing this, defense ministries are actively pursuing technological sovereignty; for instance, India's Evaluating Trustworthy Artificial Intelligence (ETAI) framework and the push for a Sovereign Military Data Cloud aim to establish a secure environment for training algorithms natively, insulating the armed forces from adversarial algorithmic manipulation and supply-chain backdoors11.

Evasion, Model Extraction, and Timing Side-Channels

Beyond poisoning the training data, adversaries target deployed models via evasion and extraction techniques. Model extraction attacks aim to reverse-engineer a neural network's architecture for commercial gain or to identify its vulnerabilities32. Research demonstrates that deep learning architectures are highly susceptible to timing side-channel attacks32. Because the total execution time of a neural network is correlated to its depth (due to the sequential computation of its layers), an adversary with black-box access to the target model can query the system, measure the inference time for a given input, and utilize a regressor model to accurately predict the depth of the target network32. By identifying the depth and structural parameters, the search space for replicating the algorithm is exponentially reduced. The adversary can then construct a highly accurate substitute model using Reinforcement Learning and knowledge distillation, mimicking the predictions of the target model32. Once a surrogate model is created, the adversary can generate highly effective, transferable adversarial examples—such as bespoke camouflage, physical perturbations on vehicles, or digital noise—designed specifically to evade the target ATR system32. In the field, this allows adversaries to deploy inflatable decoys or apply specific physical disruptions that exploit the automated target recognition's mathematical blind spots, generating high false-negative rates and allowing kinetic assets to operate entirely undetected by the kill web's sensor grid28.

The Human-Machine Teaming Dilemma and Automation Bias

The intersection of algorithmic vulnerability and human psychology creates the perilous Human-Machine Teaming (HMT) dilemma25. DoD policy, such as Directive 3000.09, mandates appropriate human judgment in the use of force, effectively creating a "Strategic Centaur" where AI handles data processing and speed, while human commanders provide ethical and strategic oversight25. However, when decision windows shrink from hours to mere seconds, human operators inherently lack the cognitive capacity to independently verify the AI’s rationale across thousands of data points9. This inevitably leads to automation bias—the psychological tendency for humans to over-rely on machine recommendations, even when contradictory environmental evidence is present24. Conversely, if the AI outputs are degraded by adversarial inputs, or if the system produces a high volume of false positives due to decoy saturation, operators may completely lose trust in the system, reverting to slow, manual processes31. This cognitive friction is a primary objective of adversarial cognitive electronic warfare25. By forcing the human operator to manually verify anomalies, the adversary successfully decompresses the defender's OODA loop, completely negating the speed advantage of the kill web and restoring operational parity11.

Electromagnetic Spectrum Operations (EMSO) and Communications Denial

The electromagnetic spectrum (EMS) functions as the central nervous system of the kill web. A data-centric force assumes the continuous transmission of high-bandwidth, low-latency information across dispersed spatial, aerial, maritime, and terrestrial nodes3. Recognizing this absolute dependency, peer adversaries have heavily invested in Cyber Electromagnetic Activities (CEMA) and Electronic Warfare (EW) to deny, degrade, and control the EMS, realizing that isolating a node is tactically equivalent to destroying it13.

Node Isolation and Dynamic Link Interdiction

The modern Electromagnetic Operational Environment (EMOE) is characterized as congested, contested, and constrained13. It is congested by the explosive growth of both military and commercial spectrum users, and contested by adversaries who have invested heavily in detection and attack platforms13. Within this environment, adversaries employ cognitive electronic warfare—AI-driven jamming systems that learn and adapt to friendly radar and communication signals in real-time, moving beyond the limitations of pre-programmed responses11. Unlike legacy jamming, which relies on static frequency hopping libraries, cognitive EW can autonomously identify low-probability-of-intercept (LPI) networks and dynamically generate custom waveforms to disrupt them21. The strategic objective is to fragment the kill web into disparate, blind entities. Without the ability to share targeting data across domains, the distributed forces cannot execute the "any sensor, any shooter" mandate2. For example, if Marine Littoral Regiments operating at the tactical edge are severed from the JADC2 data fabric, they cannot cue standoff weapons from naval or aerial assets, rendering the entire distributed architecture inert21.

The Shift to Continuous, Ambiguous Emissions

To counter EMSO threats, traditional military doctrine relied heavily on emission control (EMCON)—maintaining strict radio silence to avoid geolocation and targeting. However, a kill web cannot function without constant data exchange. Consequently, future C2 architectures must render the EMS a plane of maneuver, shifting from a posture of minimal emissions to one of continuous, but ambiguous, emissions17. This strategy relies on hiding genuine C2 traffic within a massive volume of deceptive signals, creating a "fog of war machine" that orchestrates sophisticated deception campaigns to overwhelm the adversary's signals intelligence (SIGINT)35. The goal is force protection through active enemy kill chain disruption rather than passive concealment17. Even so, the sheer volume of transmission required to sustain a kill web provides adversaries with continuous vectors for traffic analysis, targeted denial-of-service (DoS) attacks, and algorithmic hacking19. To mitigate this, DARPA's Mission-Integrated Network Control (MINC) program seeks to develop software-defined networking (SDN) technology that autonomously configures "networks of networks," prioritizing information paths to achieve self-healing kill webs that dynamically route around jammed or destroyed nodes34.

Precision Timing and Navigation (PNT) Vulnerabilities: The IEEE 1588 PTP Threat

A highly overlooked but critically fatal vulnerability within the kill web architecture lies in its foundational reliance on absolute precision timing. To execute multi-domain sensor fusion, dynamic spectrum access, encrypted communications, and coordinated fires, all nodes within the kill web must be synchronized to the sub-microsecond or nanosecond level39. This synchronization is predominantly achieved via Global Navigation Satellite Systems (GNSS) disciplined oscillators distributed over Ethernet or packet-based networks using the IEEE 1588 Precision Time Protocol (PTP)41.

The Mathematics of Timing Degradation

In aerospace and defense deployments, timing integrity directly dictates operational success. At operational velocities, one nanosecond of timing error translates to approximately 0.3 meters of positioning error39. For complex kill web operations—such as multi-static radar processing, time-difference-of-arrival (TDOA) geolocation, or the sensor fusion required to track and intercept hypersonic glide vehicles—loss of timing coherence rapidly degrades intercept probability, destabilizes control loops, and renders latency unpredictable7. The threat to GNSS and PTP is categorized into distinct classes of interference and spoofing:

Threat ClassMechanism of AttackOperational ImpactDetectability
Class I: UnintentionalHarmonics from non-GNSS devices or industrial equipment.Minor degradation of signal quality.High (easily identified and mitigated)36.
Class II: JammingOverpowering GNSS signals by raising the noise floor.Hard fault; immediate loss of external timing reference. Nodes revert to local holdover.High. Receivers instantly flag the loss of lock and trigger alarms36.
Class IV: SpoofingInjecting counterfeit GNSS signals synchronized to satellite geometry.Gradual, stealthy pull of the receiver's time and position solution (PVT).Low. Bypasses standard receiver fault monitoring, feeding false data as truth36.

The Danger of Gradual Spoofing (Class IV)

While jamming (Class II) completely denies the signal, it triggers immediate system alerts, allowing the kill web to transition to inertial navigation systems (INS) or local atomic clocks (holdover)36. Spoofing (Class IV) is significantly more dangerous because it is inherently deceptive. Because civilian GNSS L1 C/A signals arrive at the Earth's surface at approximately \-130 dBm (20 dB below the thermal noise floor), they are easily overpowered by low-cost terrestrial transmitters36. An advanced spoofing attack proceeds in three phases: alignment, takeover, and navigation36. The adversary matches the counterfeit signal to the authentic parameters, imperceptibly takes over the tracking loops, and then slowly drags the clock time away from Coordinated Universal Time (UTC)36. Recent field measurements from the JammerTest 2024 campaign demonstrated that a slow, common-mode pull of a receiver's clock time can alter the system by over 1.01 milliseconds while the internal accuracy flag reports a deviation of only 51 nanoseconds—a gap of nearly 20,000 times44. Because the PTP grandmaster clock blindly trusts the GNSS input, it acts as a force multiplier for the attack, propagating this falsified time across the entire tactical network44.

Systemic Desynchronization of the Kill Web

If an adversary successfully introduces microsecond-level timing offsets into a subset of the kill web's nodes, the consequences for the data-centric architecture are catastrophic39.

1. Sensor Fusion Failure: Algorithms relying on Kalman filters to weigh and merge data from disparate optical, radar, and inertial sensors will begin discarding valid tracks because the timestamps no longer align48. In autonomous systems, a slight camera or LiDAR delay induced by timing manipulation can reduce target detection accuracy by up to 88.5%50.

2. Data Link Collapse: Frequency-hopping spread spectrum networks and Time-Division Multiple Access (TDMA) architectures, such as Link 16, require extraordinarily precise time slots for transmission16. Timing drift causes signal collisions, packet loss, and the eventual dropping of nodes from the network, isolating critical assets51.

3. Algorithmic Confusion: Because the errors develop gradually, AI-driven battle managers will process the degraded spatial and temporal data as truth. This results in the generation of faulty engagement solutions, misallocation of interceptors, and complete loss of situational awareness36.

Mitigating this requires Assured PNT (a-PNT) architectures, which utilize Controlled Reception Pattern Antennas (CRPA) for null-steering, cryptographic signal authentication (e.g., M-Code, Galileo OSNMA), and cross-verification using localized sensor fusion algorithms47. Furthermore, the deployment of Chip-Scale Atomic Clocks (CSACs), eLoran terrestrial broadcasts, and emerging Low Earth Orbit (LEO) capabilities are necessary to provide resilient timing holdover55.

Middleware Exploitation and Legacy Hardware Integration Risks

The realization of Mosaic Warfare and JADC2 relies heavily on integrating legacy platforms that were never designed to communicate with one another3. Traditional acquisition required forcing a universal communication standard across all service branches, a process that is notoriously slow, expensive, and politically contentious16. To achieve the kill web rapidly, DARPA developed "Mission Integration Tools," most notably the System-of-systems Technology Integration Tool Chain for Heterogeneous Electronic Systems (STITCHES) and the Adapting Cross-domain Kill-webs (ACK) program16.

The Vulnerability of On-the-Fly Middleware (STITCHES)

STITCHES acts as a rapid software integration tool that auto-generates ultra-low latency middleware between systems, translating data across different coding languages without altering the original hardware or Operational Flight Programs (OFP)16. While STITCHES brilliantly circumvents interoperability bottlenecks by composing software patches on demand, it inherently introduces a sprawling, dynamic attack surface15. Because the middleware is auto-generated on the fly to patch disparate systems, standard static security analysis and manual code reviews cannot keep pace61. If an adversary compromises the translation library or the STITCHES toolchain itself, they could inject malicious logic directly into the data streams connecting the kill web's components59. The adversary could alter targeting coordinates, mission parameters, or sensor telemetry in transit, with neither the sending nor the receiving system detecting the manipulation, as the middleware seamlessly authenticates the formatting on both ends56. Furthermore, managing the isolation of critical versus non-critical data across these dynamic bridges requires formally proven hypervisors (e.g., seL4) to prevent container escape and lateral movement59.

Exploitation of the MIL-STD-1553 Serial Data Bus

Compounding the middleware risk is the underlying hardware of the legacy platforms being integrated. JADC2 initiatives aim to connect nearly all major weapons and avionics systems, the vast majority of which rely on the MIL-STD-1553 serial data bus—a 48-year-old technology standard developed in the 1970s8. The MIL-STD-1553 protocol was designed strictly for reliability and weight reduction in point-to-point wiring, with absolutely no security mechanisms, authentication, or encryption built into its architecture8. It operates on implicit trust; any terminal connected to the bus is assumed to be authorized. By linking these highly vulnerable, unauthenticated internal networks to the broader JADC2 data fabric via tools like STITCHES, the kill web inadvertently exposes the internal avionics and flight computers of advanced platforms (including the F-15 and F-35) to remote intrusion8. If an attacker breaches the kill web's external network defenses and pivots onto a platform's 1553 bus, the lack of authentication allows them to eavesdrop on critical telemetry, send bogus altitude or fuel data to the pilot, or worst of all, masquerade as the flight computer8. This capability could cause platform instability, aborted missions, or the hijacking of weapon systems, representing a critical single point of failure in the JADC2 construct8.

Zero Trust at the Tactical Edge and the Next-Generation Security Triad

To secure the data fabric against lateral movement, credential theft, and middleware exploitation, the DoD has mandated the adoption of Zero Trust Architecture (ZTA) across all information networks, guided by frameworks such as NIST SP 800-2072. ZTA operates on the principle of "never trust, always verify," replacing obsolete perimeter-based defenses with the continuous authentication of every user, device, application, and data flow2. While highly effective in stable enterprise cloud environments, implementing strict ZTA at the tactical edge—characterized by Denied, Degraded, Intermittent, and Low-bandwidth (DDIL) conditions—presents extreme engineering and operational challenges63.

The Overhead of Continuous Authentication in Multi-RAT Environments

Modern kill webs rely on Unmanned Aerial Vehicles (UAVs), ground sensors, and dismounted troops transitioning rapidly across Multi-Radio Access Technologies (multi-RAT)—such as 5G cellular, SATCOM, Wi-Fi, and proprietary tactical mesh networks (e.g., DJI OcuSync, Link 16\)51. Under standard ZTA protocols, every transition between these networks constitutes crossing a trust boundary, instantly invalidating the device's authentication state, attestation, and contextual trust signals65. This introduces a fundamental tension between absolute security and operational physics. Re-establishing cryptographic trust at every network transition incurs massive bandwidth and processing overhead65. In resource-constrained edge devices, naïve ZTA implementation can consume a critical fraction of the device's communication power budget and introduce authentication latency that invalidates time-sensitive kinetic targeting65. If the continuous verification process fails due to a temporary EW jamming event (a DDIL condition), legitimate nodes are automatically locked out of the network by their own security protocols, inadvertently achieving the adversary’s goal of node isolation without the adversary having to sustain the jamming67.

The Next-Generation Security Triad: PQC and ZTA Convergence

The cryptographic burden on the kill web is further exacerbated by the mandated transition to Post-Quantum Cryptography (PQC), driven by the National Security Agency's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)51. Embedded military systems, which prioritize availability and extremely low latency (e.g., smart munitions, fire control systems), are largely incompatible with the larger key sizes, memory footprints, and processing requirements of nascent PQC algorithms like ML-KEM and ML-DSA51. The convergence of ZTA, PQC, and AI Security forms what analysts term the "Next-Generation Security Triad"70. Synchronizing these mandates across the kill web is immensely complex. If a fire control system experiences a 100-millisecond latency spike while performing a post-quantum cryptographic handshake for Zero Trust authentication, it may miss a critical engagement window against a hypersonic threat51. Thus, the architectural constraints of embedded systems create a scenario where enforcing maximum security (confidentiality and integrity) directly degrades operational capability (availability and speed)51.

High-Risk Intersections: NC3 Integration and Escalation Dynamics

The most perilous vulnerability of the JADC2 framework involves its intersection with the nation's nuclear deterrent. The DoD strategy includes Line of Effort (LOE) 4, which mandates the integration of Nuclear Command, Control, and Communications (NC3) with JADC226. NC3 is predicated on the "always/never rule"—ensuring nuclear weapons can always be used exactly as ordered, and never used without authorization7. Integrating legacy, highly isolated NC3 architectures into an AI-driven, multi-domain kill web introduces profound escalation risks. If conventional early-warning sensors and nuclear C2 systems share the same cloud infrastructure or communication pathways, an adversary's attempt to degrade conventional kill webs via data poisoning, cyber intrusions, or PTP spoofing could inadvertently blind or manipulate nuclear early-warning systems7. For instance, if an automated target recognition algorithm is spoofed into classifying a conventional missile launch as a nuclear first strike, it could accidentally accelerate the decision-making cycle based on a false premise, triggering catastrophic, unintended escalation71. Establishing secure, verifiable firewalls between conventional kill webs and NC3 while maintaining the speed advantages of JADC2 remains an unresolved strategic challenge.

Defensive Mitigations and Future-Proofing the Kill Web

Securing the kill web requires a fundamental paradigm shift from assumptions of perfect, unassailable connectivity to architectures built explicitly for graceful degradation and resilience under persistent attack.

  • Disruption Tolerant Networking (DTN): The kill web must universally adopt DTN protocols (e.g., RFC 4838\) derived from interplanetary networking architectures73. DTN utilizes a "store-carry-and-forward" Bundle Protocol located between the application and transport layers, allowing nodes to hold data securely in persistent memory during EMS denial and forward it when connectivity is re-established76. This prevents the total collapse of the data fabric during jamming events and enables communication in highly mobile, disrupted environments75.
  • Byzantine Fault Tolerance (BFT) in AI: AI battle managers and sensor fusion algorithms must be engineered with Byzantine Fault Tolerance7. This architectural approach ensures the system can continue operating accurately and safely even if a subset of the network’s nodes are spoofed, compromised, or transmitting poisoned data, preventing malicious inputs from corrupting the entire COP.
  • Assured PNT and Alternative Timing: The absolute reliance on GNSS for network timing must be severed. Tactical nodes require deeply integrated, localized timing holdovers—such as Chip-Scale Atomic Clocks (CSACs)—and the integration of alternative timing signals like AM/FM broadcasts, cosmic time synchronization, and optical/inertial sensor fusion to maintain sub-microsecond synchronization entirely independent of vulnerable space-based signals39.
  • Risk-Adaptive Zero Trust: ZTA implementations at the tactical edge must abandon rigid, binary authentication in favor of Bayesian risk models. These models dynamically adjust verification rigor based on the current threat environment, environmental consistency, and resource constraints, preventing security protocols from inadvertently causing operational denial-of-service during combat65.
  • Directed Energy Weapons (DEW): To counter the asymmetric cost burden of drone swarms and cheap loitering munitions that exploit the kill web's sensor saturation, defenders must integrate Directed Energy Weapons (high-power lasers and microwaves). DEWs flip the cost curve by offering speed-of-light engagement and an infinite magazine, ensuring the physical survival of critical nodes while the software adapts to electromagnetic threats9.

Ultimately, the victor in algorithmic and system-destruction warfare will not be the force with the most exquisite kinetic platforms, but the force capable of sustaining data coherence, adapting its software architectures in real-time, and operating seamlessly through the inevitable degradation of its digital and electromagnetic linkages18.

Works cited

1. The Point Defense Paradox: Sustaining Airpower in Contested Distributed Operations \> Air University (AU) \> Wild Blue Yonder, https://www.airuniversity.af.edu/Wild-Blue-Yonder/Articles/Article-Display/Article/4316568/the-point-defense-paradox-sustaining-airpower-in-contested-distributed-operatio/

2. A PARADIGM SHIFT FOR THE UK STRATEGIC DEFENCE REVIEW \- CHACR, https://chacr.org.uk/wp-content/uploads/2024/12/The-Battleweb.pdf

3. Mission (Command) Complete: Implications of JADC2 \- NDU Press, https://ndupress.ndu.edu/Media/News/News-Article-View/Article/3841502/mission-command-complete-implications-of-jadc2/

4. Evolution or Revolution | Future Forge \- Defence, https://theforge.defence.gov.au/war-college-papers-2022/evolution-or-revolution

5. Realising a data-centric all-domain kill-web through network-driven system design, https://theforge.defence.gov.au/war-college-papers-2022/realising-data-centric-all-domain-kill-web-through-network-driven-system-design

6. Aligning Emerging Concepts and Capabilities With Mosaic Warfare, https://ciasp.scholasticahq.com/article/127303-aligning-emerging-concepts-and-capabilities-with-mosaic-warfare

7. On the Precipice \- Artificial Intelligence and the Climb to Modernize Nuclear Command, Control, and Communications \- Federation of American Scientists, https://fas.org/wp-content/uploads/2026/01/2026\_on-the-precipice.pdf

8. This vulnerability puts the future of U.S. warfighting at risk \- README, https://readme.synack.com/this-vulnerability-puts-the-future-of-u.s.-warfighting-at-risk

9. Unfair Fights | \- pwkinternational.com, https://pwkinternational.com/2025/11/22/unfair-fights/

10. China Military Strategic Assessment Enhanced Complete | PDF | People's Liberation Army, https://www.scribd.com/document/1056680071/China-Military-Strategic-Assessment-Enhanced-Complete-3

11. AI-Driven Warfare: Preparing India for Future Combat Readiness \- Drishti IAS, https://www.drishtiias.com/daily-updates/daily-news-analysis/ai-driven-warfare-preparing-india-for-future-combat-readiness

12. China Military Strategic Assessment Enhanced Complete | PDF \- Scribd, https://www.scribd.com/document/1056680069/China-Military-Strategic-Assessment-Enhanced-Complete-6

13. (PDF) Offensive Cyber and Information Warfare Strategies Targeting People's Republic of China Military Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR) Systems: A Qualitative Analysis \- ResearchGate, https://www.researchgate.net/publication/403161305\_Offensive\_Cyber\_and\_Information\_Warfare\_Strategies\_Targeting\_People's\_Republic\_of\_China\_Military\_Command\_Control\_Communications\_Computers\_Intelligence\_Surveillance\_and\_Reconnaissance\_C4ISR\_Systems\_A\_Q

14. Artificial Intelligence and Agile Combat Employment \- Army University Press, https://www.armyupress.army.mil/Journals/Military-Review/English-Edition-Archives/May-June-2024/MJ-24-Hagardt/

15. NOT FOR PUBLICATION UNTIL RELEASED BY THE SUBCOMMITTEE Statement by Dr. Peter Highnam, https://www.armed-services.senate.gov/imo/media/doc/Highnam%20Testimony%2004.21.21.pdf

16. Creating Cross-Domain Kill Webs in Real Time \- DARPA, https://www.darpa.mil/news/2020/cross-domain-kill-webs

17. Supporting Command and Control for Land Forces on a Data-Rich Battlefield | RUSI, https://static.rusi.org/Supporting-command-and-control-for-land-forces-on-a-data-rich-battlefield.pdf

18. The Quick and the Dead: How Adaptation in Contact Drives Military Advantage \- Amazon S3, https://s3.us-east-1.amazonaws.com/media.hudson.org/The+Quick+and+the+Dead+-+How+Adaptation+in+Contact+Drives+Military+Advantage+-+Bryan+Clark+-+Ian+Crone+-+Dan+Patt.pdf

19. EMSO Is Everyone's Problem. Let's Do Something About It., https://empyreandefense.com/insights/emso-is-everyones-problem-lets-do-something-about-it/

20. Journal of the Centre for Joint Warfare Studies \- CENJOWS, https://cenjows.in/wp-content/uploads/2026/01/Synergy-\_October\_2022\_-Online.pdf

21. JADO Essential Information Requirements, Data Fabrics, and Joint/Coalition Interoperability \> Air University (AU) \> Article Display, https://www.airuniversity.af.edu/Office-of-Sponsored-Programs/Research/Article-Display/Article/2675860/jado-essential-information-requirements-data-fabrics-and-jointcoalition-interop/

22. TRANSFORM COMMAND AND CONTROL FOR MULTIDOMAIN OPERATIONS \- Government Executive, https://events.govexec.com/the-future-of-army-fires-and-multi-domain-environments-how-data-convergence-is-galvanizing-future-weapon-systems/download/file-20230407175507-transform-command-and-control-for-multidomain-operations.pdf

23. China Military Strategic Assessment Enhanced Complete | PDF | People's Liberation Army, https://www.scribd.com/document/1056680072/China-Military-Strategic-Assessment-Enhanced-Complete-4

24. Exploring Decision Advantages \- Improving Speed, Precision and Efficiency in Military Targeting by Applying Artificial Intelligence \- DiVA Portal, https://www.diva-portal.org/smash/get/diva2:1952579/FULLTEXT01.pdf

25. Decision Dominance: AI and the Transformation of the OODA Loop in Combat, https://blog.roninsgrips.com/decision-dominance-ai-and-the-transformation-of-the-ooda-loop-in-combat/

26. Summary of the Joint All-Domain Command and Control Strategy \- Department of War, https://media.defense.gov/2022/Mar/17/2002958406/-1/-1/1/SUMMARY-OF-THE-JOINT-ALL-DOMAIN-COMMAND-AND-CONTROL-STRATEGY.pdf

27. DEFENCE INNOVATIONS AND INTERNATIONAL PARTNERSHIPS: SHAPING THE FUTURE OF SECURITY, https://eta.edu.ge/uploads/2025/Kvleviti%20Centri/13comra.pdf

28. The preparation gap: IHL, human–machine teaming and assurance in military AI systems | International Review of the Red Cross \- Cambridge University Press & Assessment, https://www.cambridge.org/core/journals/international-review-of-the-red-cross/article/preparation-gap-ihl-humanmachine-teaming-and-assurance-in-military-ai-systems/76097D37F7E18C6D792B4A0DA63D11E9

29. POLICY ROUNDTABLE: Artificial Intelligence and International Security, https://tnsr.org/wp-content/uploads/2020/06/TNSR-AI-Roundtable-PDF.pdf

30. Can AI behave ethically during military crises? Preserving human moral agency, https://www.researchgate.net/publication/398143065\_Can\_AI\_behave\_ethically\_during\_military\_crises\_Preserving\_human\_moral\_agency

31. Exploiting the Integrated ISR Systems of the Future | Defense.info, https://defense.info/williams-foundation/2020/07/exploiting-the-integrated-isr-systems-of-the-future/

32. Stealing Neural Networks via Timing Side Channels \- arXiv, https://arxiv.org/pdf/1812.11720

33. (PDF) Stealing Neural Networks via Timing Side Channels \- ResearchGate, https://www.researchgate.net/publication/330035812\_Stealing\_Neural\_Networks\_via\_Timing\_Side\_Channels

34. DARPA Seeks “Always On” Interconnected Networks for Multidomain Missions, https://www.darpa.mil/news/2021/networks-multidomain-missions

35. How Artificial Intelligence Could Reshape Four Essential Competitions in Future Warfare \- RAND, https://www.rand.org/content/dam/rand/pubs/research\_reports/RRA4300/RRA4316-1/RAND\_RRA4316-1.pdf

36. GPS Signal Interference and Spoofing: Risks and Countermeasures \- Navigation Systems, https://navigationsystemsauthority.com/gps-signal-interference-spoofing/

37. Department of War Fiscal Year (FY) 2027 Budget Estimates \- Justification Book, https://comptroller.war.gov/Portals/45/Documents/defbudget/FY2027/budget\_justification/pdfs/03\_RDT\_and\_E/RDTE\_Vol1\_DARPA\_MasterJustificationBook\_PB\_2027.pdf

38. DARPA Programs Overview and Goals | PDF | Artificial Intelligence \- Scribd, https://www.scribd.com/document/640986654/Untitled

39. Assured PNT Depends on Precision Timing \- SiTime, https://www.sitime.com/company/newsroom/blog/precision-timing-foundation-assured-pnt

40. Responder Vehicle Rugged Time Servers Market Research Report 2034 \- Dataintelo, https://dataintelo.com/report/responder-vehicle-rugged-time-servers-market

41. Military Positioning, Navigation and Timing (PNT) Systems \- Defense Advancement, https://www.defenseadvancement.com/suppliers/position-navigation-and-timing-pnt/

42. European Test and Telemetry Conference – ETTC 2024 \- Jimdo, https://storage.e.jimdo.com/file/1a982558-f74e-4ae7-a441-70ce9bdab6eb/e-Booklet-ETTC-2024.pdf

43. Multi-Sensor Time Synchronization Hardware Market Research Report 2033 \- Dataintelo, https://dataintelo.com/report/multi-sensor-time-synchronization-hardware-market

44. On the requirements for successful GPS spoofing attacks | Request PDF \- ResearchGate, https://www.researchgate.net/publication/221609869\_On\_the\_requirements\_for\_successful\_GPS\_spoofing\_attacks

45. SUPPORTING THE UK PUBLIC SECTOR IN PNT AWARENESS, RESEARCH AND KNOWLEDGE (SPARK) \- NLA International, https://nlai.blue/wp-content/uploads/2026/01/spark-pnt-services-overview-uk-2025.pdf

46. Can GPS be Trusted? Part 3 | Mercury Systems, https://www.mrcy.com/company/blogs/can-gps-be-trusted-part-3

47. GNSS User Technology Report, https://prod5.assets-cdn.io/event/6041/assets/8361034923-231960e68d.pdf

48. Modelling and Simulation in the Space Domain Using Sub-Nanosecond Timing and Enhanced Distributed Computing \- NATO, https://publications.sto.nato.int/publications/STO%20Meeting%20Proceedings/STO-MP-MSG-229/MP-MSG-229-08.pdf

49. Maintaining Timing and Navigation Accuracy with Assured PNT Hardware, https://edgeaiaus.com.au/maintaining-timing-and-navigation-accuracy-with-assured-pnt-hardware/

50. Attack-Resilient Time Synchronization for Wireless Sensor Networks | Request PDF, https://www.researchgate.net/publication/222397708\_Attack-Resilient\_Time\_Synchronization\_for\_Wireless\_Sensor\_Networks

51. Cryptographic Asset Discovery and Inventory for Embedded Systems: A Framework for Post-Quantum Cryptography Migration in Defense Applications \- Preprints.org, https://www.preprints.org/manuscript/202601.1422

52. Battle Networks and the Future Force \- CSIS, https://www.csis.org/analysis/battle-networks-and-future-force-0

53. Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (P, https://tsapps.nist.gov/publication/get\_pdf.cfm?pub\_id=936011

54. Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (P, https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8323r2.ipd.pdf

55. australia's navigation and timing challenges on hazards, operations, and resilience (anchor) \- FrontierSI, https://frontiersi.com.au/wp-content/uploads/2026/02/FrontierSI\_ANCHOR\_Report\_Feb\_2026.pdf

56. Iran's Mosaic Defence: A New Doctrine in Evolving Warfare \- ResearchGate, https://www.researchgate.net/publication/402975270\_Iran's\_Mosaic\_Defence\_A\_New\_Doctrine\_in\_Evolving\_Warfare

57. ACK, STITCHES And The Air Force's Networking Hopes \- Breaking Defense, https://breakingdefense.com/2021/07/ack-stitches-and-the-air-force-networking-hopes/

58. Accelerating the Air Force's Ability to Adapt and Win, https://www.airandspaceforces.com/article/accelerating-the-air-forces-ability-to-adapt-and-win/

59. dornerworks, llc \- | SBIR, https://www.sbir.gov/portfolio/382063

60. department of defense appropriations for fiscal year 2022 hearings \- GovInfo.gov, https://www.govinfo.gov/content/pkg/CHRG-117shrg44165/pdf/CHRG-117shrg44165.pdf

61. Kevin Hamlen: Research \- The University of Texas at Dallas, https://www.utdallas.edu/\~hamlen/research.html

62. Link-16 User Guide for Newcomers | PDF \- Scribd, https://www.scribd.com/document/696217957/Understanding-Link-16-1

63. 2026 AFCEA TechNet Augusta: Conference Schedule, https://events.afcea.org/Augusta26/Public/sessions.aspx?ID=121007\&View=Sessions\&sortMenu=102001

64. Software Engineering for Continuous Delivery of Warfighter Capability, https://www.cto.mil/wp-content/uploads/2025/08/SWE-Guide-July2025-secured-1.pdf

65. Zero Trust for Multi-RAT IoT: Trust Boundary Management in Heterogeneous Wireless Network Environments \- arXiv, https://arxiv.org/html/2602.08989v1

66. Zero Trust Security for Government | AppGate Federal Division, https://www.appgate.com/federal-division

67. IDCommand | Lastwall, https://www.lastwall.com/technology/identity-platform

68. Zero Trust access at the tactical edge needs warfighter fabric, https://nhimg.org/articles/zero-trust-access-at-the-tactical-edge-needs-warfighter-fabric/

69. Zero Trust for Multi-RAT IoT: Trust Boundary Management in Heterogeneous Wireless Network Environments \- arXiv, https://arxiv.org/pdf/2602.08989

70. The Next-Generation Security Triad: Unifying PQC, ZTA, and AI Security through a Shared Modernization Substrate \- Preprints.org, https://www.preprints.org/manuscript/202512.0653

71. Artificial intelligence and the future of warfare: The USA, China, and strategic stability 9781526145062 \- DOKUMEN.PUB, https://dokumen.pub/artificial-intelligence-and-the-future-of-warfare-the-usa-china-and-strategic-stability-9781526145062.html

72. The Impact of Artificial Intelligence on Strategic Stability and Nuclear Risk \- SIPRI, https://www.sipri.org/sites/default/files/2019-05/sipri1905-ai-strategic-stability-nuclear-risk.pdf

73. delay-tolerant network dtn: Topics by Science.gov, https://www.science.gov/topicpages/d/delay-tolerant+network+dtn

74. Development and Deployment of Delay Tolerant Networks: An Arctic Village Case \- DiVA Portal, https://www.diva-portal.org/smash/get/diva2:989908/FULLTEXT01.pdf

75. Design and implementation of a DTN Convergence Layer Adapter based on the QUIC protocol \- AMS Laurea, https://amslaurea.unibo.it/id/eprint/34752/1/moffa\_mattia\_tesi.pdf

76. Towards Software-Defined Delay Tolerant Networks \- MDPI, https://www.mdpi.com/2673-8732/3/1/2

77. (PDF) Delay-Tolerant-Networks \-Architecture-Routing-Congestion-and-Security-Issues, https://www.researchgate.net/publication/332241035\_Delay-Tolerant-Networks\_-Architecture-Routing-Congestion-and-Security-Issues

78. Software Defined Disruption Tolerant Networks \- Indian Institute of Space Science and Technology, https://iist.cygnusdvlp.in/sites/default/files/2025-05/SC14D004%20FT.pdf

79. GNSS Time and Frequency Transfer | Request PDF \- ResearchGate, https://www.researchgate.net/publication/318175677\_GNSS\_Time\_and\_Frequency\_Transfer