ArticleslgStudy

computer science

Tailored Access Operations

Tailored Access Operations is a computer science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Tailored Access Operations rather than just read about it. In short: The Office of Tailored Access Operations (TAO), structured as S32, is a cyberwarfare intelligence-gathering unit of the National Security Agency (NSA). It has been active since at least 1998, possibly 1997, but was not named or structured as TAO until "the last days of 2000," according to General Michael Hayden.

Tailored Access Operations — main illustration
Tailored Access Operations — illustration

Key takeaways

  • Tailored Access Operations belongs to computer science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Tailored Access Operations to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Tailored Access Operations from memory before moving on to harder problems.

Reference excerpt

The Office of Tailored Access Operations (TAO), structured as S32, is a cyberwarfare intelligence-gathering unit of the National Security Agency (NSA). It has been active since at least 1998, possibly 1997, but was not named or structured as TAO until "the last days of 2000," according to General Michael Hayden. TAO identifies, monitors, infiltrates, and gathers intelligence on computer systems being used by entities foreign to the United States.

History

TAO is reportedly "the largest and arguably the most important component of the NSA's huge Signals Intelligence Directorate (SID), consisting of more than 1,000 military and civilian computer hackers, intelligence analysts, targeting specialists, computer hardware and software designers, and electrical engineers. The office is currently known as Office of Computer Network Operations (OCNO)."

Snowden leak A document leaked by former NSA contractor Edward Snowden describing the unit's work says TAO has software templates allowing it to break into commonly used hardware, including "routers, switches, and firewalls from multiple product vendor lines". TAO engineers prefer to tap networks rather than isolated computers, because there are typically many devices on a single network.

Organization TAO's headquarters are termed the Remote Operations Center (ROC) and are based at the NSA headquarters at Fort Meade, Maryland. TAO has expanded to NSA Hawaii (Wahiawa, Oahu), NSA Georgia (Fort Gordon, Georgia), NSA Texas (Joint Base San Antonio, Texas), and NSA Colorado (Buckley Space Force Base, Denver).

S321 – Remote Operations Center (ROC): six hundred employees gather information from around the world. S323 – Data Network Technologies Branch (DNT): develops automated spyware S3231 – Access Division (ACD) S3232 – Cyber Networks Technology Division (CNT) S3233 – S3234 – Computer Technology Division (CTD) S3235 – Network Technology Division (NTD) Telecommunications Network Technologies Branch (TNT): improve network and computer-hacking methods Mission Infrastructure Technologies Branch: operates the software provided above S328 – Access Technologies Operations Branch (ATO): Reportedly includes personnel seconded by the CIA and the FBI, who perform what are described as "off-net operations", which means they arrange for CIA agents to surreptitiously plant eavesdropping devices on computers and telecommunications systems overseas so that TAO's hackers may remotely access them from Fort Meade. Specially equipped submarines, currently the USS Jimmy Carter, are used to wiretap fibre optic cables around the globe. S3283 – Expeditionary Access Operations (EAO) S3285 – Persistence Division

Virtual locations Details on a program titled QUANTUMSQUIRREL indicate NSA ability to masquerade as any routable IPv4 or IPv6 host. This enables an NSA computer to generate false geographical location and personal identification credentials when accessing the Internet utilizing QUANTUMSQUIRREL.

Leadership From 2013 to 2017, the head of TAO was Rob Joyce, a longtime employee who had previously worked in the NSA's Information Assurance Directorate (IAD). In January 2016, Joyce made a rare public appearance, giving a presentation at the Usenix’s Enigma conference.

NSA ANT catalog

The NSA ANT catalog is a fifty-page classified document listing technology available to the United States National Security Agency (NSA) Tailored Access Operations (TAO) by the Advanced Network Technology (ANT) Division to aid in cyber surveillance. Most devices are described as already operational and available to US nationals and members of the Five Eyes alliance. According to Der Spiegel, which released the catalog to the public on December 30, 2013, "The list reads like a mail-order catalog, one from which other NSA employees can order technologies from the ANT division for tapping their targets' data." The document was created in 2008. Security researcher Jacob Appelbaum gave a speech at the Chaos Communications Congress in Hamburg, Germany, in which he detailed techniques that the simultaneously published Der Spiegel article he coauthored disclosed from the catalog.

QUANTUM attacks

The TAO has developed an attack suite they call QUANTUM. It relies on a compromised router that duplicates internet traffic, typically HTTP requests, so that they go both to the intended target and to an NSA site (indirectly). The NSA site runs FOXACID software, which sends back exploits that load in the background in the target web browser before the intended destination has had a chance to respond, although it is unclear whether the compromised router facilitates this race on the return trip. Prior to the development of this technology, FOXACID software made spear-phishing attacks the NSA referred to as spam. If the browser is exploitable, further permanent "implants" (rootkits, etc.) are deployed in the target computer; e.g., OLYMPUSFIRE for Windows, which gives complete remote access to the infected machine. This type of attack is part of the man-in-the-middle attack family, though more specifically it is called man-on-the-side attack. It is difficult to execute without controlling some of the Internet backbone. There are numerous services that FOXACID can exploit this way. The names of some FOXACID modules are given below:

… excerpt ends here. Continue reading the full article.

Illustrations

Tailored Access Operations illustration
Tailored Access Operations illustration
Tailored Access Operations illustration
Tailored Access Operations: A reference to Tailored Access Operations in an XKeyscore slide
A reference to Tailored Access Operations in an XKeyscore slide
Tailored Access Operations: Lolcat image from an NSA presentation explaining in part the naming of the QUANTUM program
Lolcat image from an NSA presentation explaining in part the naming of the QUANTUM program

Worked examples

Example 1 — a first encounter with Tailored Access Operations

Start with the simplest possible case. Write down what Tailored Access Operations claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In computer science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Tailored Access Operations before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Tailored Access Operations ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Tailored Access Operations

In research
Tailored Access Operations appears in computer science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Tailored Access Operations in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Tailored Access Operations is common in secondary-school and first-year university syllabi. It links to neighbouring topics Computer surveillance, Cyberwarfare in the United States, Hacker groups, so understanding it makes those chapters shorter.
In everyday life
Look for Tailored Access Operations outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “Tailored Access Operations” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Tailored Access Operations in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Tailored Access Operations means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Tailored Access Operations out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Tailored Access Operations in simple terms?

The Office of Tailored Access Operations (TAO), structured as S32, is a cyberwarfare intelligence-gathering unit of the National Security Agency (NSA). It has been active since at least 1998, possibly 1997, but was not named or structured as TAO until "the last days of 2000," according to General M…

Why does Tailored Access Operations matter?

Because it connects several computer science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Tailored Access Operations?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Tailored Access Operations.

Tags

  • Computer surveillance
  • Cyberwarfare in the United States
  • Hacker groups
  • National Security Agency

Keep exploring