DISA and the 1996 Mapping of Private Internet Hubs
By Marcus Boone ·
Private internet providers and long-distance telecommunications hubs were mapped by a military combat agency in a report that lists 'vulnerabilities' but offers no plan to fix them.
The privacy of every person using a modem in 1996 was traded for a military map of the web's weakest points. The cost was a permanent invitation for the Pentagon to treat commercial infrastructure as a battlefield.
In December 1996, the Office of the Manager, National Communications Systems issued a report titled the "Internet/PSN Interconnectivity and Vulnerability Report." The record available to us is the archive's curated description of the report rather than the original pages. Marked as "Unclassified," the document establishes a cold, methodical inventory of the early commercial internet, broken down into its constituent parts and scrutinized for weakness. It does not read as a guide for protection; it reads as a guide for penetration.
Tool Implementation
To understand why a combat agency was auditing the web, one must look at the issuer. The report came from the Office of the Manager, National Communications Systems, an office within the Department of Homeland Security that managed national security and emergency communications until its dissolution in 2012. However, the operational muscle behind this office was DISA, the combat support agency that provides the information technology and communications required for the president and the secretary of defense to command the U.S. military.
When a combat support agency conducts a "vulnerability analysis," the objective is rarely the altruistic hardening of civilian systems. The record shows the report was divided into four key sections: a history of the internet, four specific "aspects" of the internet, an analysis of tools, and a list of vulnerabilities. The "aspects" under the microscope were Internet Service Providers, Interexchange Points, Internet Routing Protocols, and Internet Access.
Internet Service Providers are the private commercial entities that control the gateways and management tools required for the public to access the internet. Interexchange Points are the long-distance telecommunications hubs, exemplified by the infrastructure of AT&T Communications, Inc., which managed the flow of telephone traffic across its 23 subsidiaries. By grouping these together, DISA linked the private company providing your dial-up connection to the massive physical hubs where that data converged.
Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu
The Long-Distance Hubs
The record specifies that the report included a section on "Internet Analysis," which detailed "Tool Functionality and Tool Implementation." This is where the document moves from observation to application. The public record establishes that DISA’s primary mission is the support of combatant commands. In the context of 1996, the transition of the internet from a government-funded academic experiment to a commercial utility created a critical gap in military oversight.
If you control the Interexchange Points—the physical junctions where long-distance traffic is handed off—you do not need to hack individual computers. You simply need to sit at the junction. The report's focus on these hubs, combined with its analysis of "Internet Routing Protocols," reveals a strategic interest in the plumbing of the web.
The connection is clear: DISA was not interested in the content of a single email, but in the architecture of the flow. By mapping the Interexchange Points, the military identified the precise locations where the most data could be intercepted with the least effort. The report treated the private infrastructure of companies like AT&T not as a partner in national stability, but as a set of targets for "Tool Implementation."
A Map for the Offensive
There is a glaring void in the record. The report identifies "vulnerabilities," yet there is no mention of a remediation roadmap, no security requirements for the ISPs, and no set of instructions on how to patch the holes DISA found. In any legitimate security audit, the discovery of a vulnerability is followed by a plan to fix it. Here, the vulnerability is the end goal.
Furthermore, the record is silent on how DISA obtained its data. The technical specifics of "Internet Routing Protocols" and the internal layouts of "Interexchange Points" are not public knowledge; they are proprietary corporate secrets. The report does not mention data-sharing agreements, subpoenas, or voluntary cooperation. It simply presents the analysis as a finished product.
This is where the "Unclassified" marking becomes a weapon of deception. The desk's reading is that this document is a sanitized shell. It provides the conceptual framework—the "who" and the "where"—while the "how" was stripped out and placed in a classified annex. The unclassified version tells the world that the military is "analyzing" the internet; the classified version likely contained the specific exploit vectors used to enter those systems.
If the shape of this file is what it appears to be, the "Tool Implementation" section was not about building better firewalls. The pattern suggests this was a blueprint for offensive target acquisition. The military was identifying the choke points of the nascent commercial web to ensure that when the time came to redirect traffic or silence a node, they already had the map.
The Architecture of Access
The grouping of "Internet Routing Protocols" and "Interexchange Points" is the most telling detail of the record. These are the mechanisms that decide where a packet of data goes and the physical places where those decisions are executed. The desk's reading is that this report hides the development of signals intelligence capabilities specifically designed for traffic redirection. If you know the protocol and you own the hub, you can make a message go wherever you want, or make it vanish entirely, before it ever reaches its destination.
Because the report lacks any corresponding section on mitigation, the vulnerabilities were viewed as operational opportunities rather than systemic risks. The military did not want the holes plugged; they wanted the keys to the doors. The silence regarding the legal mechanisms used to coerce private ISPs into providing this architectural data suggests a relationship of dependency and secrecy that predates the formal surveillance expansions of the post-9/11 era. This was the prototype.
The pattern suggests that a full release of the 1996 files would show a systematic effort to weaponize the commercial internet before the public even understood how to use it. The still-withheld pages are protecting the specific tools that turned a civilian communication system into a military sensor array. The result was a precedent where the Department of Defense viewed the private sector's infrastructure as a permissible extension of the battlefield.
Who paid for this? The American public, who believed they were logging into a private network, while the combat support agency at the center of the web was quietly cataloging every exit and every entrance. The 1996 report proves that the surveillance state did not emerge from a sudden crisis of terror; it was built into the very routing protocols of the internet by an agency that saw a vulnerability and decided to keep it open.
Sources
- Office of the Manager, National Communications Systems,Internet/PSN Interconnectivity and Vulnerability Report. Unclassified. — National Security Archive (GWU)
- Document PDF (Office of the Manager, National Communications Systems,Internet/PSN Interconnectivity and Vulnerability Report. Unclassified.)
- Background: National Communications System — Wikipedia