Two connected learning models Explore the linear model at KillChains.com

Preserved research input · KW-RPT-014

Kill Web vs. Kill Chain: From Sequential Targeting Processes to Composable Battle Networks

A comparative report that distinguishes the ordered execution process from the composable network of possible, authorized mission pathways.

Digest verified 16c5fe778d20b35fb3ddcf53fa4e4232a55963bb766c0737120e00b3373fbb57

Kill Web vs. Kill Chain: From Sequential Targeting Processes to Composable Battle Networks

Executive Summary

A kill chain and a kill web are best understood as concepts at different levels of abstraction. A kill chain is an ordered process connecting detection of a target to the delivery and assessment of an effect. In contemporary U.S. Air Force doctrine, the dynamic-targeting version is find, fix, track, target, engage, and assess—F2T2EA. The same term is also used in cybersecurity for Lockheed Martin’s seven-stage intrusion model, although the military-targeting and cyber-intrusion meanings should not be conflated. citeturn17view0turn22search6

A kill web is a networked force and mission architecture containing multiple possible sensor, command-and-control, support, and effector combinations. DARPA describes it as an alternative to limited, monolithic, predefined chains: commanders can select and retask sensors, effectors, and supporting capabilities across air, land, maritime, space, and cyber domains. A recent CNA formulation similarly defines a web as a collection of multiple sequences and nodes that supplies multiple pathways to an effect. citeturn20view0turn16view9

The most important analytical conclusion is that a kill web does not eliminate kill chains. Rather, it provides an architecture from which one or more chains can be composed, recomposed, and rerouted. DARPA program language explicitly describes a disaggregated kill web as executing rapidly composable, joint, all-domain kill chains. The relationship is therefore analogous to that between a transportation network and a particular route through it: the web is the option space; the chain is the selected path for a particular mission. citeturn4view3turn20view0

A kill web can improve resilience, tempo, force utilization, and cross-domain integration because the loss or unavailability of one sensor, communication path, headquarters, or weapon need not terminate the mission. DARPA’s Adapting Cross-Domain Kill-Webs program specifically sought rapid substitution when a capability is lost, while the Department of Defense’s Joint All-Domain Command and Control strategy calls for communications diversity, redundant infrastructure, common data standards, mission command, and elimination of single points of failure. citeturn20view0turn17view2turn17view3

Those benefits are conditional rather than automatic. A physically distributed force can remain logically centralized if every engagement depends on one cloud environment, fusion service, gateway, classification domain, or approval authority. Conversely, a conventional kill chain may contain redundant links and delegated execution. Topology, technical resilience, and command authority are separate variables. A nominal web may therefore be brittle, while a carefully designed chain may be robust.

Kill webs also introduce costs that chains conceal or avoid: interoperability engineering, combinatorial testing, data provenance, cybersecurity exposure, electromagnetic-spectrum dependence, algorithmic opacity, resource contention, coalition releasability, and ambiguity over engagement authority. RAND’s examination of Mosaic Warfare and Naval Integrated Fire Control–Counter Air found that rapid composability and complex multidimensional relationships increase certification and integration challenges; GAO has likewise reported that the Department of Defense still lacks a comprehensive framework for guiding and measuring Combined Joint All-Domain Command and Control investments. citeturn17view6turn20view2turn21view5

Bottom line: kill chains remain indispensable for describing, authorizing, executing, auditing, and assessing particular engagements. Kill webs are most valuable as architectures for generating multiple authorized kill chains under contested and rapidly changing conditions. Defense organizations should therefore procure and test resilient mission pathways, not merely connected platforms—and should avoid treating “any sensor to any shooter” as a literal or universally desirable requirement. The practical objective is the rapid selection of the best authorized, compatible, sufficiently trusted, and operationally available pathway to a desired effect.

Scope, Assumptions, and Definitions

This report assumes that “kill web” primarily refers to the military concept associated with distributed maritime operations, Mosaic Warfare, Joint All-Domain Command and Control, stand-in forces, and cross-domain sensor-to-effector integration. Because “kill chain” has a well-established second meaning in cybersecurity, the cyber model is addressed separately where relevant. The term “kill” should not be read as necessarily implying a lethal effect: current Air Force doctrine applies the F2T2EA construct to lethal and nonlethal capabilities, including operations in cyberspace, space, the information environment, and the electromagnetic spectrum. citeturn17view0

Military kill chain. A military kill chain is an ordered set of functions that connects target detection and characterization with a decision, engagement, and assessment. Air Force Doctrine Publication 3-60 identifies F2T2EA as the condensed process for dynamic targeting and calls it, colloquially, the kill chain. The broader joint targeting process is iterative rather than mechanically linear: targets may be recycled, phases can overlap, and assessment may trigger new collection or engagement. citeturn17view0turn16view0

The word chain can describe at least three related things:

  • a doctrinal process such as F2T2EA;
  • a concrete mission thread connecting particular sensors, decision nodes, communications links, weapons, and assessment systems;
  • an analytical representation used to locate bottlenecks, dependencies, latency, or vulnerabilities.

Those meanings overlap but are not identical. A doctrinal process specifies functions that must be satisfied; a technical mission thread specifies systems and interfaces; an operational chain adds authorities, timing, rules of engagement, and resource allocation.

Kill web. A kill web is a network of heterogeneous nodes and potential connections from which multiple chains can be formed. DARPA’s ACK program describes the selection of sensors, effectors, and support elements across organizational and domain boundaries, with capability substitutions when systems are lost or unavailable. The Marine Corps’ Stand-in Forces concept similarly defines kill webs as enabling the rapid identification, selection, tasking, and retasking of assets from disaggregated or distributed forces. citeturn20view0turn17view4

A useful formal abstraction is:

\[ G=(V,E,C,A) \]

where \(V\) is the set of nodes—sensors, processors, headquarters, weapons, logistics and assessment assets—\(E\) is the set of technically possible links, \(C\) represents operational constraints such as latency, range, track quality, capacity, security classification, and availability, and \(A\) represents legal and command authorities. A kill chain is then an authorized path or subgraph through \(G\) that satisfies the mission’s effect, timing, confidence, and risk requirements. This formulation highlights why connectivity alone does not create a usable web: an edge may exist technically but remain unusable because the data is insufficiently accurate, the weapon is unavailable, the information cannot be released, or the responsible commander lacks authority.

Kill mesh. Terminology is not fully settled. CNA’s 2026 study distinguishes a chain, a web, and a mesh: a chain is one sequence, a web supplies multiple sequences, and a mesh contains many potential pathways whose selection is substantially algorithmic. Under this formulation, a mesh may be more resilient and adaptive than a web, but its behavior is less predictable. Other authors use web, mesh, battle network, distributed kill chain, and system of systems less precisely or nearly interchangeably. citeturn16view9

Cyber kill chain. Lockheed Martin’s original intrusion kill-chain model comprises reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. It is an adversary-behavior and defensive-analysis framework, not a friendly sensor-to-weapon architecture. citeturn22search6

That cyber model is valuable because it encourages defenders to disrupt an intrusion at multiple stages and to connect individual indicators into campaign intelligence. Its limitations are also well documented: real intrusions can skip stages, repeat them, branch, begin inside the perimeter, or move laterally after compromise. MITRE notes that ATT&CK tactics do not imply a fixed chronological flow and that adversaries can move among them repeatedly; the Unified Kill Chain was developed partly to expand the scope of the original model. citeturn22search1turn22search2

“Cyber kill web” is not a comparably standardized cybersecurity framework. In military kill-web discussions, cyber is usually one domain supplying sensors, access, command-and-control support, protection, or effects. It is therefore more precise to speak of cyber capabilities participating in a military kill web than to assume that the phrase denotes a recognized successor to the Cyber Kill Chain.

The origins of both military terms are somewhat contested. Modern military kill-chain formulations emerged from U.S. Air Force efforts in the 1990s to shorten the sensor-to-shooter process and were institutionalized through F2T2EA and dynamic targeting. CNA attributes early articulation of the kill process to General John Jumper, while Air Force historical accounts also associate the evolving sequence with senior Air Force leaders such as General Ronald Fogleman. The cyber adaptation was formally presented by Eric Hutchins, Michael Cloppert, and Rohan Amin in the 2011 Lockheed Martin paper. citeturn16view9turn14search0turn22search6

No single uncontested inventor of “kill web” is evident in the public record. Its intellectual antecedents include system-of-systems engineering, cooperative engagement, network-centric warfare, distributed lethality, and cross-domain fires. The term was visibly employed in U.S. naval discourse by the mid-2010s, including the Navy’s 2016 NIFC-CA/F-35 live-fire demonstration, and was subsequently developed more systematically through DARPA’s Mosaic Warfare and ACK programs and Marine Corps stand-in-force concepts. citeturn21view0turn20view0turn17view4

Doctrinal and Intellectual Foundations

The kill chain has a clearer doctrinal status than the kill web. Air Force Doctrine Publication 3-60 explicitly names F2T2EA as the dynamic-targeting kill chain. It also makes clear that compressed timelines do not erase target-development standards: sufficient intelligence and legal review must still support an engagement. The chain is therefore not merely a technical latency problem; it is a command, intelligence, legal, and operational process. citeturn17view0turn18view0

Current Air Force doctrine also anticipates elements often associated with web architectures. Targeting is described as continuous, iterative, interdisciplinary, and all-domain. Its automation appendix identifies common target-data standards and interoperability as foundations for information sharing among components, reachback organizations, and multinational partners, and it calls for architectures that continue transferring data in contested, degraded, or operationally limited conditions. citeturn16view0turn17view1turn18view1

The Department of Defense’s JADC2 strategy supplies much of the enabling logic for a kill web even when it does not consistently use that term. JADC2 organizes activity around sensing, sense-making, deciding, and disseminating action across domains. Its strategy calls for AI-assisted processing, resilient and redundant communications, flexible data formats, common standards, interoperability with mission partners, and the ability to operate in degraded command-and-control environments. citeturn16view2turn18view2turn18view3

JADC2 is not simply an effort to centralize more information at higher headquarters. The strategy explicitly associates the “act” function with mission command, under which subordinate commanders understand senior intent and retain the ability to act when communications fail or operational urgency precludes seeking further guidance. It also calls for eliminating single points of failure. These provisions are doctrinally important because a web that requires continuous permission from a remote headquarters would not realize the resilience promised by its technical topology. citeturn17view2turn17view3

DARPA provides the most explicit official description of the kill web as an architecture of options. The ACK program sought a decision aid that could identify available sensors, effectors, and support elements across services and domains, account for capacity and quality of service, compare competing options, and respect distinct authorities and mission priorities. Its “capability marketplace” concept was intended to permit decentralized adaptation without requiring each participant to expose sensitive implementation details. citeturn20view0

This framing reveals that a kill web is not merely a communications network. It is simultaneously:

  • a resource-allocation problem, because sensors and effectors may be supporting other missions;
  • an optimization problem, because options differ in probability of success, time, risk, cost, and opportunity cost;
  • an authority problem, because domains and organizations operate under different command and legal arrangements;
  • an information-abstraction problem, because capabilities must be advertised without disclosing sensitive sources and methods;
  • a resilience problem, because substitutions must be found when nodes or links fail. citeturn20view0

The Marine Corps’ Stand-in Forces concept applies the web to forward, distributed forces operating inside contested maritime areas. Stand-in forces are expected to maintain target custody, contribute organic sensors and weapons, integrate with naval, joint, and coalition capabilities, and help “complete” kill webs. The formulation implies that small forward units need not carry every element of a self-contained strike complex; their operational value can come from providing one or more critical nodes to a larger force architecture. citeturn17view4turn18view4

The Navy’s NIFC-CA experience is a principal technical and acquisition antecedent. NAVSEA describes NIFC-CA as a system-of-systems effort that integrates independently acquired radars, weapons, command-and-control systems, and platforms to engage targets beyond the shooter’s organic detection range. Navy mission-engineering literature emphasizes mission architectures, technical reference designs, common interfaces, integrated testing, and governance across program boundaries. citeturn20view4

NATO targeting doctrine reinforces an essential constraint on web-enabled operations: additional technical pathways do not remove political, legal, or coalition controls. NATO’s public AJP-3.9 requires joint-force guidance on priorities, engagement authority, positive identification, rules of engagement, collateral-damage processes, coordination, and acceptable risk. It also notes that national caveats can constrain asset allocation and engagement. citeturn17view8turn17view9turn18view7

A kill web must consequently be modeled as an authorized network, not simply a physical network. A coalition sensor may detect and track a target but be unable to transmit fire-control-quality data at the necessary classification. A national weapon may be technically compatible but unavailable for the target category. A subordinate unit may possess both data and weapon range but lack delegated engagement authority. These are operationally equivalent to absent links.

RAND’s Mosaic Warfare research develops the web logic further. Its identified attributes include fractionation of functions across many platforms, heterogeneity, rapid composability, complex and evolving system architecture, scalability, multiagent collaboration, and significant use of automation or AI. RAND also cautions that rapidly combining subsystems for missions for which they were not originally intended creates difficult testing, certification, safety, and legal problems. citeturn17view6turn18view6

CNA’s more recent research shows that kill-chain, kill-web, and kill-mesh concepts are not confined to U.S. planning. Its review of Chinese military and national-security research found extensive interest in modeling, evaluating, simulating, and generating kill processes, with aspirations for systems that are dynamic, cross-domain, redundant, distributed, self-organizing, and resilient. CNA nevertheless found limited public evidence that the People’s Liberation Army has operationalized the full concept at the level implied by some theoretical work. citeturn16view9

The doctrinal status of “kill web” therefore remains uneven. It appears in official concepts, technology programs, service publications, demonstrations, and acquisition analysis, but public sources do not show a single, standardized joint doctrinal definition equivalent to the Air Force’s explicit F2T2EA formulation. Joint doctrine itself is authoritative guidance rather than an inflexible prescription, and portions of the current Joint Publication library are not publicly accessible without authenticated access. citeturn19search9turn19search0

Structural Comparison

The structural difference can be represented simply.

flowchart LR
    F[Find] --> X[Fix]
    X --> TR[Track]
    TR --> TG[Target and authorize]
    TG --> E[Engage]
    E --> A[Assess]

The diagram depicts the functional logic of a military kill chain, not an assertion that every real engagement is perfectly linear. Collection, target development, authorization, engagement, and assessment can overlap or repeat, but a particular engagement still has identifiable dependencies and decision points. Air Force doctrine describes F2T2EA as the condensed dynamic-targeting process while preserving intelligence and legal standards under compressed timelines. citeturn17view0

flowchart LR
    subgraph Sensors_and_Sources
        S1[Space ISR]
        S2[Airborne sensor]
        S3[Maritime or ground sensor]
        S4[Cyber or EMS source]
    end

    subgraph Processing_and_Command
        P1[Edge fusion]
        P2[Joint or coalition fusion]
        D1[Decision support]
        A1[Engagement authority]
    end

    subgraph Effectors
        E1[Air weapon]
        E2[Ship or submarine weapon]
        E3[Land-based fire]
        E4[Cyber or EMS effect]
    end

    S1 --> P1
    S1 --> P2
    S2 --> P1
    S2 --> P2
    S3 --> P1
    S3 --> P2
    S4 --> P2

    P1 --> D1
    P2 --> D1
    D1 --> A1

    A1 --> E1
    A1 --> E2
    A1 --> E3
    A1 --> E4

    P1 -. alternate path .-> E2
    P2 -. alternate path .-> E3

The dotted connections in the second diagram are potential rather than automatically valid pathways. Each must meet requirements for identity, track quality, timing, security, compatibility, weapon-target pairing, authority, and risk. This qualification is central to the difference between a useful operational web and an aspirational connectivity diagram. DARPA’s ACK program explicitly identified availability, capacity, quality of service, competing missions, and domain authorities as major obstacles to selecting cross-domain pathways. citeturn20view0

AttributeKill chainKill web
Basic natureA process or specific mission thread connecting target discovery to an effect and assessment.An architecture and option space containing multiple possible mission threads. citeturn17view0turn16view9
Unit of designEnd-to-end execution of one engagement or class of engagement.Nodes, interfaces, standards, authorities, and rules by which chains can be composed.
TopologySequential or predominantly sequential, with identifiable dependencies.Many-to-many, with branching, convergence, substitution, and alternative routes.
Sensor-effector pairingOften planned or predefined; the sensor and shooter may be organic to one formation or established mission package.Pairing can be selected or changed dynamically across services and domains. citeturn20view0
RedundancyUsually achieved by duplicating a critical component or providing a backup within the chain.Ideally achieved through path diversity: different sensors, processors, links, headquarters, or effectors can satisfy the same function.
ResilienceVulnerable when an indispensable node, link, or approval point is lost; can still be resilient if deliberately duplicated.Can degrade gracefully when alternatives remain, but may fail catastrophically through common dependencies such as one cloud, gateway, timing source, or data service. citeturn17view3turn20view0
DecentralizationCompatible with either centralized or delegated control.Favors distributed execution and edge decision-making, but technical distribution does not guarantee delegated authority. citeturn17view2
TempoPredictable procedures and known interfaces can reduce coordination time, but serial approvals or fixed pairings can create bottlenecks.Can accelerate retasking and best-effector selection, but option comparison, data validation, and authority resolution can add delay.
Decision-makingRelatively bounded decision space; humans can often understand the complete thread.Larger and more dynamic option space; decision aids, optimization, AI, and automation become more important. citeturn20view0turn17view6
Command and controlClear ownership and accountability are easier to establish for a defined chain.Requires federated command relationships, mission command, conflict resolution, allocation rules, and explicit delegation.
ISRCollection is commonly matched to a known target-development or engagement requirement.Multiple sources can cross-cue, maintain target custody, improve coverage, and replace lost sensors.
Weapons integrationShooter commonly relies on organic or predetermined fire-control inputs.Supports third-party targeting, engage-on-remote, and selection of a nonorganic or cross-domain effector. citeturn21view0turn20view4
Nonkinetic effectsCyber, space, information, or electromagnetic effects can be inserted into the sequence.Nonkinetic capabilities can serve as sensors, enablers, protection, deception, or effectors alongside physical weapons. citeturn17view0turn20view0
Data modelPoint-to-point translation may be sufficient for a small number of known participants.Common standards, metadata, interfaces, identity, provenance, and machine-readable constraints are foundational. citeturn17view1turn18view3
LogisticsDemand is more predictable for a planned package, platform, or unit.Distributed nodes increase survivability and flexibility but complicate fuel, munitions, power, spares, maintenance, software versions, and configuration control.
TestingA bounded mission thread can be tested against known inputs, outputs, and failure conditions.The number of combinations can grow rapidly; testing must sample architectures, degraded states, adversarial inputs, substitutions, and emergent behavior. citeturn17view6turn18view6
Principal failure modeBreaking a critical link or delaying a serial decision.Common-mode failure, false fusion, cyber compromise, resource contention, incompatible data, authority ambiguity, or uncontrolled complexity.
Best suited toStable missions, tightly controlled effects, mature interfaces, and cases where auditability and simplicity dominate.Contested, dynamic, multidomain operations where assets are dispersed and losses, jamming, or rapid retasking are expected.

The table deliberately avoids equating “chain” with “centralized” and “web” with “decentralized.” A chain may be executed autonomously by one platform: Air Force doctrine notes that a platform with the necessary sensors, weapons, and authority can perform the entire dynamic-targeting sequence. Conversely, a web may send every decision through a central headquarters and therefore have a centralized operational bottleneck. citeturn17view0

A further distinction is between component redundancy and path redundancy. Two identical communications terminals connected through the same satellite, gateway, authentication service, and spectrum allocation provide component redundancy but limited path diversity. A resilient web requires alternatives that do not share all important failure causes.

For analytical purposes, web resilience should therefore be measured by the number of independent, authorized, mission-capable pathways, not by the raw number of connected nodes. Ten sensors that all depend on the same vulnerable communications relay may contribute less resilience than two genuinely independent sensor-to-effector paths.

Operational Implications

Planning. Chain-based planning begins with a defined effect and constructs a workable sequence: which asset will find the target, how it will be fixed and tracked, where identification and collateral-damage analysis occur, who authorizes engagement, which weapon is allocated, and how results will be assessed. It is well suited to detailed synchronization and clear assignment of responsibility.

Web-based planning must do more preparatory architecture work. Rather than selecting one complete path in advance, planners define desired effects, performance thresholds, available capabilities, substitution rules, authorities, data standards, acceptable risks, and fallback routes. DARPA’s ACK model shows that this also requires representing capacity and quality of service: an airborne sensor may technically be able to support a mission but lack dwell time; a cyber capability may be reserved for a higher-priority operation; a long-range weapon may be compatible but scarce. citeturn20view0

Web planning therefore shifts some effort from scheduling a mission package to governing an ecosystem of capabilities. The staff must establish in advance which combinations are authorized, what data confidence is required, how competing requests will be prioritized, what happens when communications fail, and when a machine-generated recommendation requires human review.

Targeting and legal review. A web can compress the time between detection and effect, but it cannot legitimately omit target validation, positive identification, proportionality analysis where applicable, rules-of-engagement compliance, collateral-damage estimation, or engagement authority. Air Force doctrine states that dynamic targets remain subject to target-development standards even under compressed timelines. NATO doctrine similarly requires guidance on positive identification, national caveats, engagement authority, deconfliction, and acceptable risk. citeturn17view0turn17view8turn18view7

The practical challenge is to make legal and command constraints machine-readable without reducing them to simplistic automation. A decision service may be able to exclude a weapon whose effects exceed collateral-damage limits or an asset whose nation has entered a caveat. It is much more difficult to encode ambiguous context, strategic sensitivity, intelligence-source protection, escalation risk, or changing commander’s intent.

ISR and target custody. A chain commonly depends on one designated ISR source or a planned handoff. A web can employ multiple sensors to detect, classify, geolocate, cross-cue, and continuously maintain custody of a target. A low-observable aircraft may contribute a track to a ship; space-based ISR may cue an unmanned aircraft; passive electromagnetic sensing may refine a target detected by radar; cyber intelligence may reveal operating patterns that focus physical collection.

The corresponding risk is false confidence through fusion. Multiple reports are not independent confirmation when they originate from the same underlying source. Automated fusion can duplicate tracks, merge distinct objects, propagate stale coordinates, or amplify deception. Web design consequently requires provenance, timestamps, confidence scores, sensor-error characterization, correlation logic, and the ability to reconstruct how a target solution was produced. Air Force doctrine’s emphasis on common target-data standards and interoperability is necessary but not sufficient; data must also be trustworthy and operationally meaningful. citeturn17view1

Weapons integration. The key operational promise is separation of sensing from shooting. A weapon platform no longer has to detect a target with its own organic sensor, provided it receives sufficiently accurate, timely, authenticated, and weapon-compatible information from elsewhere. NIFC-CA is a concrete example of this engage-on-remote logic. citeturn21view0turn20view4

This requires much more than transmitting coordinates. Different weapons need different update rates, track quality, uncertainty bounds, identification standards, reference frames, latency limits, and midcourse guidance. The architecture must also prevent incompatible or unsafe combinations. “Any sensor to any shooter” is therefore a useful slogan for breaking organizational assumptions but a poor literal engineering requirement.

A more defensible formulation is:

Any qualified and authorized sensor should be able to contribute to any technically compatible and operationally appropriate effector through a trusted mission pathway.

Tempo. Chains can be fast because they are rehearsed, bounded, and predictable. A single aircraft with sensors, weapons, and delegated authority may close its own chain faster than a distributed web that has to discover capabilities, transfer data across networks, reconcile classifications, select an effector, and obtain approval. Air Force doctrine explicitly recognizes that one platform may perform all functions where capability and authority permit. citeturn17view0

Webs improve tempo when fixed pairings or unavailable assets would otherwise create delay. They can replace a lost sensor, redirect a weapon already in position, or distribute a target solution to several potential effectors. Their true speed advantage should therefore be measured not only by minimum sensor-to-effect time under ideal conditions, but by time to reconstitute an effective chain after disruption.

Command and control. Kill-web operations increase the importance of commander’s intent, predelegated authorities, and mission command. When communications are available, higher headquarters may supply broader situational awareness, cross-domain coordination, and resource optimization. When communications are degraded, subordinate commanders need enough local data, rules, and authority to continue. The JADC2 strategy explicitly ties decision advantage to both resilient communications and the ability of subordinates to act when linkages are broken. citeturn17view2turn18view2

The most resilient arrangement is often a hybrid:

  • strategic priorities, sensitive authorities, and scarce-resource allocation remain centralized;
  • tactical execution and substitution within approved bounds are decentralized;
  • edge elements retain degraded-mode capability;
  • headquarters can intervene when operational or escalation risk exceeds delegated thresholds.

A web without authority delegation can produce information-rich paralysis. A web with poorly bounded delegation can produce duplicated engagements, fratricide, escalation, or competition for scarce assets.

Cyber and electromagnetic effects. Cyber capabilities can contribute intelligence, deny adversary sensors, disrupt command networks, manipulate data, protect friendly mission systems, or create direct nonkinetic effects. Electromagnetic warfare can detect emitters, degrade communications, deceive sensors, or protect friendly links. Current Air Force doctrine treats these as potential elements of the kill chain rather than as categorically separate activities. citeturn17view0

Integrating them into a web is difficult because their authorities, planning horizons, confidence levels, and assessment methods differ from those of kinetic weapons. A cyber access may require months to establish and may be lost after use. Its effects may be uncertain, reversible, geographically diffuse, or difficult to attribute. Electromagnetic attack may simultaneously protect one force and interfere with another friendly pathway. Cross-domain synchronization must therefore consider not only whether an effect is available, but also its persistence, observability, collateral consequences, intelligence cost, and impact on future operations.

Cybersecurity is also an internal vulnerability of the web. More interfaces, gateways, software-defined functions, coalition connections, and automated decisions expand the attack surface. An adversary may not need to destroy a weapon if it can corrupt track provenance, delay timing, compromise identity services, poison an optimization algorithm, or manipulate the advertised availability of assets. JADC2 consequently calls for cyber-hardened technologies, layered defense, secure information sharing, and operation in contested electromagnetic conditions. citeturn17view3turn18view3

Assessment. In a conventional chain, the asset conducting battle-damage assessment may be planned as part of the same mission thread. A web can draw on many sources and can redirect available sensors after engagement. This improves opportunities for rapid reattack or transition to a different effect.

Assessment nevertheless becomes harder when several kinetic and nonkinetic actions converge. Planners must distinguish whether the result came from physical destruction, temporary disruption, adversary adaptation, deception, or an unrelated system failure. Without rigorous causal assessment, a web may optimize for apparent activity rather than strategic effect.

Logistics and sustainment. Distributed forces complicate an adversary’s targeting and permit alternative operational routes, but they create a larger sustainment problem. More nodes mean more batteries, generators, fuel points, spare parts, munitions types, software baselines, cryptographic material, antennas, maintainers, and transportation requirements. The Marine Corps’ stand-in-force concept links distributed operations and kill-web participation to survivable sustainment and continued operation in contested areas, while JADC2 includes data-enabled force readiness and logistics among the functions needed for all-domain operations. citeturn11view1turn4view1

A technically interchangeable effector is not operationally interchangeable if its ammunition is exhausted, its software is outdated, its crew lacks the relevant certification, or its network keys cannot be updated. Logistics status must therefore become part of the web’s capability representation. The system should know not merely that an asset exists, but whether it can reach the required position, remain there, receive the data, execute the effect, and recover or be resupplied.

Advantages, Disadvantages, and Failure Modes

The principal advantages of a kill chain are conceptual clarity, accountability, bounded complexity, and testability. Each function and handoff can be assigned to an organization; communications and weapon interfaces can be verified against a known mission thread; legal and command responsibilities are comparatively easy to locate; and planners can calculate resource requirements with reasonable precision.

Chains are particularly suitable when a mission requires tight control, a unique weapon, sensitive intelligence, specialized rules of engagement, or highly predictable sequencing. They are also useful as diagnostic tools: identifying where a chain is slow or fragile often yields a more actionable engineering problem than attempting to optimize an entire enterprise network.

Their principal disadvantage is dependency. If the assigned sensor cannot maintain custody, the designated data link is jammed, the headquarters cannot approve, the planned tanker is unavailable, or the weapon platform cannot reach its release point, the mission may fail even though other friendly capabilities could theoretically perform the function. Fixed chains can also reinforce service and program stovepipes by tying sensors, command systems, and weapons to organic platforms.

The principal advantages of a kill web are adaptability, path diversity, cross-domain synergy, and improved utilization of distributed capabilities. A web can use a sensor that is best positioned rather than one organic to the shooter, allocate an effector based on current range and inventory, and substitute around losses or jamming. DARPA’s ACK program explicitly linked the concept to rapid substitution, better sharing of resources, latent capacity, and load balancing across domains. citeturn20view0

A web can also complicate adversary planning. In a fixed chain, an opponent may identify and attack the indispensable sensor, relay, headquarters, or shooter. In a functioning web, the same effect may be generated by several combinations, forcing the adversary to suppress a larger and more heterogeneous set of systems.

The first major disadvantage is integration complexity. Each new node creates potential interface, security, timing, safety, and certification relationships with other nodes. The number of possible combinations can grow much faster than the number of systems. RAND notes that Mosaic Warfare’s rapidly evolving relationships and use of subsystems for unanticipated missions make testing and legal or safety certification especially challenging. citeturn17view6turn18view6

The second disadvantage is dependence on data and software. A conventional weapon platform may retain useful organic capability after losing wide-area connectivity. A web-centric force that has traded away organic sensors, local processing, or onboard decision capacity may become less resilient if the network is denied. The design goal should therefore be graceful degradation, not permanent dependence on a perfect enterprise network.

The third disadvantage is cyber and electronic attack surface. The web offers more points for intrusion, spoofing, jamming, traffic analysis, identity compromise, and data poisoning. Shared services create economies and interoperability, but they may also become high-value common-mode targets.

The fourth disadvantage is cognitive and organizational overload. A commander presented with dozens of technically feasible options may decide more slowly unless the system filters them according to mission priorities, confidence, cost, risk, and authority. Yet the filtering algorithms themselves may be opaque or based on incomplete assumptions. Human-machine decision design is therefore as important as connectivity.

The fifth disadvantage is competition for resources. A sensor, tanker, satellite channel, electronic-attack aircraft, cyber access, or long-range weapon may be advertised to several missions simultaneously. Local optimization can degrade the wider campaign. ACK’s emphasis on capability value, cost, competing missions, and capacity reflects this problem. citeturn20view0

The sixth disadvantage is coalition friction. A coalition may have many physical nodes but relatively few usable cross-national paths because of classification, releasability, national caveats, incompatible data labels, sovereign approval requirements, or different rules of engagement. NATO doctrine makes clear that national constraints remain relevant even in time-sensitive targeting. citeturn17view8turn17view9

Typical kill-chain failure modes include:

  • loss or degradation of a critical sensor;
  • inability to maintain track custody;
  • a serial approval bottleneck;
  • failure of a designated communications link;
  • the assigned weapon being out of range, unavailable, or unsuitable;
  • assessment arriving too late to support reattack.

Typical kill-web failure modes include:

  • all apparent alternatives sharing one hidden dependency;
  • false or manipulated data propagating across many consumers;
  • incompatible timing, coordinate, identification, or track-quality standards;
  • an optimization service selecting a technically possible but operationally unauthorized path;
  • multiple commands allocating the same scarce capability;
  • coalition nodes receiving incomplete or unreleasable information;
  • emergent interactions that were never tested;
  • a centrally managed web becoming a single operational bottleneck.

A useful distinction is between structural resilience and behavioral resilience. Structural resilience means that alternative nodes and links exist. Behavioral resilience means the force can detect disruption, choose a valid substitute, transfer authority and data, and continue the mission within the required time. A network diagram may show the former while exercises reveal the absence of the latter.

Cases and Illustrative Scenarios

A conventional dynamic-targeting chain. Consider a mobile surface-to-surface missile launcher detected by a remotely piloted aircraft. The aircraft locates and tracks the launcher; intelligence personnel establish identity and confidence; a command center validates the target and conducts legal and collateral-damage review; the air component assigns a strike aircraft; the aircraft engages; and the remotely piloted aircraft returns to assess the result.

This arrangement offers clear responsibility and a comprehensible audit trail. It can also be rapid if the chain is rehearsed and authority is delegated. Its weakness is the set of indispensable dependencies: the remotely piloted aircraft’s control link, access to the relevant headquarters, the availability of the strike aircraft, and the time required for approval. The example corresponds closely to the functional logic of F2T2EA. citeturn17view0

NIFC-CA and the 2016 F-35 test. In September 2016, the Navy demonstrated a cross-platform engagement in which an unmodified Marine Corps F-35B acted as an elevated sensor for an over-the-horizon threat. It transmitted data through its Multifunction Advanced Data Link to a ground station connected to USS Desert Ship, which represented a ship at sea. An Aegis Baseline 9.C1 system and Standard Missile-6 then detected and engaged the target. A Navy program official described the event as closing the fire-control loop among previously unrelated technologies and contributing to a kill web sharing sensors, links, and weapons. citeturn21view0

This demonstration illustrates separation of sensor and shooter, cross-platform data translation, and engage-on-remote operations. It should not be overstated as proof of a universally composable web. It demonstrated one carefully engineered, tested, and authorized cross-platform chain within a broader architecture. RAND’s subsequent analysis noted that NIFC-CA began with a small number of exemplar chains, established a common data format early, and relied on sustained experimentation and integration across legacy programs. citeturn17view7turn18view5

The case is especially important for acquisition. NIFC-CA was not created by procuring one new “kill web system.” It integrated multiple independent programs through systems engineering, common architectures, testing, and governance. NAVSEA describes the effort as requiring synchronization across program offices, technical baselines, mission architectures, and force-level evaluation. citeturn20view4

A hypothetical resilient maritime web. A forward Marine unit detects an adversary surface formation using passive sensing. Its primary beyond-line-of-sight communications path is jammed. The unit sends a lower-bandwidth track report through an alternate relay to a maritime operations center. Space-based sensing confirms the formation; an unmanned aircraft refines classification; a destroyer’s missile inventory is constrained by an air-defense mission; the command-and-control system therefore recommends a land-based antiship weapon. The responsible commander approves the engagement, and a different sensor conducts assessment.

The web advantage is not that every node communicates with every other node. It is that several functions—detection, confirmation, engagement, and assessment—can be satisfied by different combinations after the preferred path becomes unavailable. The stand-in-force concept’s emphasis on forward sensing, target custody, distributed assets, and completion of naval and joint kill webs is consistent with this model. citeturn17view4

The scenario also exposes constraints. The alternate communications path may not support full-motion data; the space track may be insufficient for weapon guidance; the land-based unit may lack engagement authority; coalition observations may be classified differently; and the destroyer may still be the only platform able to engage within the required time. A useful web does not conceal these constraints—it represents them.

A brittle web disguised as a resilient one. Imagine fifty sensors and ten weapon systems connected to a common cloud fusion environment. The architecture appears highly redundant. In practice, every participant depends on one identity-management service, one timing source, one cross-domain gateway, and one remote engagement-approval cell. An adversary disrupts the gateway or corrupts the fusion service. Most of the apparent pathways fail simultaneously.

This scenario illustrates why node count is a poor proxy for resilience. JADC2’s calls for communications diversity and elimination of single points of failure should be interpreted at the mission-thread level, including shared software and authority dependencies, not only at the radio or platform level. citeturn17view3

Ukraine as a partial analogue. Public analysis of the Russia-Ukraine war describes rapidly evolving combinations of commercial and military communications, unmanned aircraft, distributed artillery, electronic warfare, software-enabled targeting, and decentralized adaptation. NATO-associated lessons emphasize rapid information dissemination, electromagnetic and cyber resilience, and delegated authority; recent European analysis also highlights modularity, open architecture, plug-and-play sensors, software, communications, fires, and logistics. These features resemble kill-web principles, particularly dynamic sensor-to-effector pathways under heavy electronic attack. citeturn12view2turn10search0

It would nevertheless be misleading to label the entire Ukrainian system a single formal kill web. The force comprises multiple overlapping governmental, military, commercial, volunteer, domestic, and foreign systems with uneven security, reliability, standardization, and authority. The more defensible conclusion is that the war provides evidence for the operational value of distributed sensing, rapid software adaptation, alternative communications, and short sensor-to-effector loops, while also showing how quickly technical advantages are countered.

Cybersecurity example. A defender using the Lockheed Martin Cyber Kill Chain can place controls at each intrusion stage: monitor reconnaissance, detect malicious delivery, prevent exploitation, identify installation, disrupt command and control, and block actions on objectives. The model encourages defense in depth because stopping the adversary at any required stage can prevent the final objective. citeturn22search6

A modern intrusion may not follow that clean sequence. An attacker using stolen credentials may begin with valid access, perform internal reconnaissance, establish persistence, move laterally, return to command-and-control channels, and execute several objectives over time. MITRE ATT&CK’s nonsequential structure and the Unified Kill Chain’s expanded phases respond to this complexity. This is conceptually analogous to moving from one cyber chain to a graph of possible attack paths, but it should not be confused with the military kill web’s purpose of composing friendly sensors, authorities, and effectors. citeturn22search1turn22search2

Procurement, Doctrine, and Force-Design Implications

Procurement for a chain tends to optimize a defined mission thread or platform. Procurement for a web must optimize the architecture, interfaces, and portfolio that allow many mission threads to be formed. This changes what should be treated as a deliverable.

The first implication is a shift from platform performance to mission outcomes. Range, payload, radar sensitivity, and magazine size remain important, but a program should also be evaluated by how it contributes to joint mission threads: what data it can publish, what data it can consume, how quickly it can be integrated, whether it can operate when disconnected, and which other systems can substitute for its functions.

GAO reports that past Department of Defense acquisition frequently optimized individual systems rather than connectivity, interoperability, and compatibility. It describes CJADC2 as a concept guiding modernization and new investment rather than a single acquisition program, but it also finds that the department lacks a comprehensive framework for guiding investments and tracking progress. citeturn21view5

The second implication is that integration must be funded as a continuing capability, not treated as a final-stage activity after platforms are delivered. Necessary investments include government-controlled interface standards, reference architectures, gateways, common data models, metadata, automated testing, mission engineering, digital twins, modeling and simulation, ranges, coalition test environments, and software sustainment.

NIFC-CA offers a useful precedent. RAND found that the Navy funded a relatively small integration and test effort across larger component programs, began with three exemplar chains, defined a common data structure early, leveraged existing test infrastructure, and treated test failures as learning opportunities. Its long development period nevertheless reflected the difficulty of integrating legacy systems that had not been designed as one force architecture. citeturn18view5turn17view7

The third implication is a strong requirement for modular open systems approaches. Open architectures do not mean unrestricted access or elimination of security boundaries. They mean government-understood interfaces, separable components, controlled abstractions, reusable services, and the ability to change one part without redesigning the entire force. NAVSEA identifies modularity, open architecture, abstraction, and information hiding as important to the extensibility of integrated naval systems. citeturn20view4

The fourth implication is to procure degraded-mode capability. Requirements should specify what a unit or platform can do when it loses enterprise data, position-navigation-timing services, reachback, satellite communications, or a central fusion service. A web should augment organic capability rather than automatically replacing it. Useful design patterns include local track stores, edge processing, low-bandwidth message formats, multiple communications paths, predelegated engagement criteria, and the ability to revert to simpler chains.

The fifth implication is that testing must become mission-thread and architecture based. Platform-level testing cannot establish whether a web works. Testing should evaluate:

  • end-to-end mission closure across service and coalition boundaries;
  • performance after loss, compromise, or degradation of nodes and links;
  • substitution time and the validity of alternative paths;
  • data provenance, correlation, latency, and confidence;
  • cyberattack, spoofing, jamming, and deceptive inputs;
  • competing demands for scarce sensors and effectors;
  • safety and legal behavior under unanticipated combinations;
  • operation across classification and releasability boundaries.

RAND’s analysis stresses that rapid composition creates a certification problem because subsystems may be used for missions for which they were not initially designed. NAVSEA likewise argues for mission-based testing and technical reference designs across program boundaries. citeturn17view6turn20view4

The sixth implication is to replace simplistic connectivity metrics with operational measures of effectiveness. Relevant metrics include:

MetricOperational meaning
Probability of chain closureLikelihood that an authorized path can find, identify, decide, engage, and assess within mission time.
Independent-path countNumber of usable paths that do not share the same critical failure causes.
Recomposition timeTime required to identify and activate a substitute after disruption.
Sensor-to-decision latencyTime from observation to a decision-quality target state.
Decision-to-effect latencyTime consumed by authority, tasking, weapon preparation, and delivery.
Track and identity confidenceAccuracy, continuity, provenance, and positive-identification quality.
Common-mode exposureDegree to which nominal alternatives rely on the same cloud, gateway, spectrum, timing, software, or authority.
Coalition usabilityPercentage of pathways usable under classification, releasability, caveat, and interoperability constraints.
Graceful-degradation scoreMission performance retained after specified node, link, or service losses.
Cost per achieved effectTotal sensor, C2, weapon, protection, and logistics cost required to produce the desired outcome.
Logistics enduranceDuration for which the selected web can operate given munitions, fuel, power, maintenance, and network-support demands.
Decision quality under loadAbility of humans and automation to select suitable options amid large target and asset volumes.

The seventh implication concerns software and data rights. A force cannot recompose capabilities rapidly if each interface modification requires vendor-specific permission, proprietary data, or a multiyear contract action. Procurement should obtain sufficient interface documentation, test rights, data rights, cybersecurity visibility, and software-delivery mechanisms to permit continuing government-led integration.

The eighth implication is that acquisition security must encompass data integrity and algorithm assurance, not just platform cybersecurity. A kill-web decision aid may influence which target is engaged and which weapon is selected. Its training data, optimization criteria, software supply chain, identity services, and capability advertisements become mission-critical. Systems should preserve auditability: commanders and investigators must be able to determine what data was used, which constraints were applied, why a path was recommended, and who authorized execution.

The ninth implication is organizational. A web cuts across program executive offices, services, intelligence organizations, combatant commands, classification authorities, and coalition partners. Without mission-level governance, each program can satisfy its own requirements while the aggregate force remains incompatible. GAO’s finding that service and defense organizations have pursued independent data-integration efforts illustrates this risk. citeturn20view2turn21view5

Doctrine should address at least six issues.

First, terminology. It should distinguish the kill chain as a functional process or selected mission thread from the kill web as an architecture containing multiple potential chains. This would reduce the tendency to present the concepts as mutually exclusive.

Second, authority. Doctrine should specify how engagement authority, target validation, legal review, cyber authorities, coalition caveats, and scarce-resource allocation are represented and delegated. Technical reach must never be mistaken for command authority.

Third, human-machine roles. Doctrine should distinguish machine functions—data correlation, option generation, constraint checking, resource matching—from inherently command functions such as interpreting intent, accepting operational risk, and authorizing sensitive effects. The appropriate division will differ by mission and weapon.

Fourth, degraded operations. Units should train to continue with partial data, broken links, stale tracks, unavailable headquarters, and compromised nodes. Mission command should be exercised as an operational capability rather than cited only as a principle. JADC2 explicitly links it to acting when communications are broken. citeturn17view2

Fifth, cross-domain deconfliction. Doctrine should cover the interactions among kinetic fires, cyber operations, space support, electromagnetic warfare, deception, intelligence gain or loss, and information effects. One component’s action may disable a sensor or access required by another chain.

Sixth, coalition employment. Combined operations require data-labeling standards, releasable mission applications, national caveat handling, federated identity, and procedures for using partner sensors without assuming partner engagement authority. NATO targeting requirements show that political and national controls remain integral to time-sensitive operations. citeturn17view8turn18view7

Finally, doctrine and procurement should preserve the option to use a simple chain when simplicity is operationally superior. Not every mission benefits from dynamic composition. A highly rehearsed, self-contained chain may be faster, more secure, easier to certify, and easier to control than a broad web. The correct force-design objective is not maximal connectivity. It is sufficiently diverse, trusted, and governable pathways to achieve commander-directed effects under expected disruption.

Key References

  • U.S. Department of the Air Force, Air Force Doctrine Publication 3-60, Targeting, May 2026. Provides the current public Air Force description of dynamic targeting and F2T2EA and addresses targeting automation, common data standards, and contested environments. citeturn16view0turn17view0turn17view1
  • U.S. Department of Defense, Summary of the Joint All-Domain Command and Control Strategy. Establishes the sense–make sense–act framework, mission-command principles, interoperability requirements, resilient communications, and elimination of single points of failure. citeturn16view2turn17view2turn17view3
  • Defense Advanced Research Projects Agency, Adapting Cross-Domain Kill-Webs. Defines the ACK approach to selecting and retasking sensors, effectors, and support capabilities across organizational and domain boundaries. citeturn20view0
  • U.S. Marine Corps, A Concept for Stand-in Forces, 2021. Applies kill-web concepts to forward, distributed maritime forces and cross-domain sensor and weapon integration. citeturn17view4turn18view4
  • Naval Sea Systems Command, “Navy Conducts First Live Fire NIFC-CA Test with F-35,” 2016. Documents a cross-platform, over-the-horizon sensor-to-weapon engagement and official use of the kill-web terminology. citeturn21view0
  • Naval Surface Warfare Center Dahlgren, mission-engineering and integration analysis of NIFC-CA. Describes systems-of-systems governance, mission architectures, technical baselines, open architecture, and cross-program testing. citeturn20view4
  • Timothy Marler et al., RAND, Distributed Kill Chains: Drawing Insights for Mosaic Warfare from the Immune System and from the Navy, 2021. Analyzes fractionation, heterogeneity, composability, autonomy, certification, and NIFC-CA acquisition lessons. citeturn16view6turn17view6turn17view7
  • CNA, Exploring PRC Research on Kill Chains and Kill Webs: How Might It Help the PLA?, 2026. Supplies explicit comparative definitions of chains, webs, and meshes and evaluates Chinese research on kill processes. citeturn16view9
  • NATO, Allied Joint Publication 3.9, Doctrine for Joint Targeting. Provides public guidance on engagement authority, positive identification, rules of engagement, national caveats, deconfliction, and time-sensitive targeting. citeturn16view4turn17view8turn17view9
  • U.S. Government Accountability Office, Defense Command and Control: Further Progress Hinges on Establishing a Comprehensive Framework, 2025. Evaluates CJADC2 investment governance, data sharing, interoperability, and measurement challenges. citeturn20view2turn21view5
  • Eric M. Hutchins, Michael J. Cloppert, and Rohan M. Amin, Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains, 2011. Original Cyber Kill Chain paper. citeturn19search1turn22search6
  • Paul Pols, The Unified Kill Chain. Extends cyber-attack lifecycle analysis beyond the original perimeter- and malware-oriented chain and incorporates a broader range of adversary behavior. citeturn22search2