Showing posts with label CCD COE. Show all posts
Showing posts with label CCD COE. Show all posts

Wednesday, June 12, 2013

CFP: CyCon 2014

Next year's CyCon is going to take place 3-6 June and focus on active defence.

Important Dates Abstract submission 01 October 2013
Full paper 10 January 2014
Notification of Authors 3 March 2014
Final Paper 24 March 2014


The CFP is available here.

Friday, March 1, 2013

Academic life

It has been a long time since my last post and a lot has happened since. The last year has been interesting, as I was searching for my next challenge. I'll try rebooting this blog, as well.

I left the NATO Cooperative Cyber Defence Centre of Excellence at the turn of the year. I had been involved with it since January of 2005, when I first joined the team that was doing the preparation work to get the Centre established. When that happened in May of 2008, I took on the role of a scientist (first at R&D, later at Training and Doctrine). This time was instrumental in my personal and professional growth and I am very grateful to the Centre and the Estonian Defence Forces for the opportunities I was offered during my service. However, after five years at CCD COE, it was time to move on, lest I get too comfortable in my role there.

Therefore, I did some soul searching and job searching last year. My job search revealed that there are many empty slots to fill, so I opted for the approach that allows me to address the qualified manpower shortage in the most direct way. Last September I took on a part-time teaching position in University of Jyväskylä, Finland, in order to get experience and to see a bit more of the academic world. As of last month, I am also an Associate Professor in Tallinn University of Technology, working on cyber security topics (a 50% position). Both of these Universities have ambitious goals for building up a strong cyber security program, so I will have some interesting years ahead.

I have also reserved a fraction of my time for other interesting projects (consulting, etc.) that come up, such as cyber exercises and targeted short term research projects. All in all, this arrangement gives me a lot of flexibility and a wider net to fish for exciting challenges.

So far, I am enjoying myself. Life is very busy, but fun as well. 

Thursday, November 22, 2012

ECIW 2013 in Jyväskylä, Finland

The next European Conference on Information Warfare and Security (ECIW) takes place in University of Jyväskylä, Finland, on 11-12 July 2013. I will run a mini-track on Cyber Professionalism and Military Cyber Operations. The description of the mini-track follows:
In a time of constrained resources, everyone is trying to do more with less. One area that merits serious study is the use of military cyber operations in support of, or instead of, conventional military operations. While by no means a cheap option, cyber operations offer asymmetric benefits if used sparingly and only against targets of strategic importance.
 
While not a part of the standard order of battle yet, many states are making serious efforts in developing their military cyber capability. In general, they all share the same problems: figuring out the composition and TTP’s of cyber units, finding the best possible people to staff them and integrating the cyber capabilities with the existing toolset of the commander.

Topics for this track may include but are not limited to:
  • military cyber operations
  • tactics, techniques and procedures for cyber operations
  • identifying, recruiting, training and retaining cyber operatives
  • cyber force structure – unit composition, specialization, location in the command chain, rank mix, etc.
  • role of active forces, reserve forces, as well as militias and other volunteer groups. 
The CFP is open until 20 December, so it is time to warm up your keyboards.
 
You may have noticed that my affiliation is listed as University of Jyväskylä. This is because for the past three months I have taught in Jyväskylä as a (part-time) post-doctoral researcher. It is part of my transition from my current main position in the NATO CCD COE to academia in the next few months. I am also applying for a part time position in Tallinn University of Technology and will hopefully join the faculty there in February.

Monday, October 8, 2012

CFP for CyCon 2013 is out

The CFP for the NATO CCD COE annual conference CyCon 2013 is now out. Abstract submission deadline is 01 November, so it is time to write down your thoughts.


Monday, September 3, 2012

Tallinn Manual

The Tallinn Manual, or Manual on the International Law Applicable to Cyber Warfare (MILCW), is nearing completion. While the book version is getting its finishing touches at Cambridge University Press (scheduled to publish in early 2013), the soft copy is now available on the NATO CCD COE website. [NB! Be sure to note the disclaimers about the status of the manual!]

I had the pleasure to participate in the development of this very interesting Manual for three years. As one of the 'Technical Experts', my role was to explain various cyber and computing concepts to the lawyers, as well as participate in creating many of the examples found in the book.

I wish to thank the group, for it was fascinating work and I learned a great deal in the process.

Wednesday, May 2, 2012

Time to climb a new mountain

After four years as a Scientist at the NATO CCD COE, which was preceded by another three years of work helping set up and develop the Centre, the time has finally come to move on to face new challenges. Or to be a bit more specific, this time will come sometime in the second half of 2012.

I feel I am ready to explore cyber security and cyber conflict from new angles. I love teaching, so an academic approach is definitely a possibility. It would also be interesting to gain experience from private sector perspective. Most likely I will try to combine various options to get the "perfect blend" for the time being. By the look of things I will make my decision later this month.

I can't say for sure what road I will follow, but one thing I definitely want to do is to revive this blog. I have been very busy (personally, academically, professionally) for the past couple of years and, sadly, this blog was one of the easiest things to put on hold while I got things sorted out. Yet, people still seem to find it every once in a while, as the visit counter passed ten thousand last month. This adds to my motivation to get things going again.

Time to re-invent myself...

Thursday, November 10, 2011

CFP for CyCon 2012

The CFP for the fourth International Conference on Cyber Conflict is out. As has been the tradition so far, the conference title has changed yet again - the short version is now CyCon.

Mark your calendars - I hope to see you in Tallinn in June!

Monday, October 25, 2010

What does CCD COE do?

I get this question a lot.

Well, while there are a lot of things that will not make it into limelight, our people do publish some of the work in public academic conferences and journals.

CFP: International Conference on Cyber Conflict

Finally, the CFP for our own conference is out. The International Conference on Cyber Conflict is the third conference in the series organized by CCD COE. This year, we also have IEEE as a co-sponsor. The conference will take place 07-10 June 2011 in Tallinn, Estonia.

As for the CFP [pdf]:

In 2011 the conference will focus on the combination of defensive and offensive aspects of Cyber Forces and will combine different views on cyber defense and operations in the current and envisaged threat environments. All this shall not be limited to military perspective.

Legal, strategic and technical submissions are welcome on equal grounds.

Researchers and practicians are encouraged to submit papers covering novel and scientifically significant practical works related to 2011’s topics via our web portal. Accepted papers - after passing the peer-review - will be published in the conference proceedings provided in hard cover and digitally though IEEE Xplore.

Paper submission deadline is 20 JAN 2011.

Thursday, August 26, 2010

CFP: ECIW 2011

I am back from my summer hiatus and ready to kick-start another year of cyber conflict studies. Let's start with the CFP to the 10th European Conference on Information Warfare and Security (ECIW). This time it is held in Tallinn, Estonia. It is hosted by the Institute of Cybernetics at Tallinn University of Technology, in collaboration with the CCD COE. I will be serving as the local Program Chair, so I hope to see some of you there.

Please feel free to circulate this CFP:
This is a call for papers for 10th European Conference on Information Warfare and Security being held at The Institute of Cybernetics at the Tallinn University of Technology, Tallinn, Estonia on the 7-8 July 2011.

The 10th European Conference on Information Warfare and Security (ECIW) is an opportunity for academics, practitioners and consultants from Europe and elsewhere who are involved in the study, management, development and implementation of systems and concepts to combat information warfare or to improve information systems security to come together and exchange ideas. There are several strong strands of research and interest that are developing in the area including the understanding of threats and risks to information systems, the development of a strong security culture, as well as incident detection and post incident investigation. This conference is continuing to establish itself as a key event for individuals working in the field from around the world.

Please consider submitting to this conference. We are interested in the entire range of concepts from theory to practice, including case studies, works-in-progress, and conceptual explorations. The conference committee welcomes contributions on a wide range of topics using a range of scholarly approaches including theoretical and empirical papers employing qualitative, quantitative and critical methods.

Case studies and work-in-progress/posters are welcomed approaches. PhD Research, proposals for roundtable discussions, non-academic contributions and product demonstrations based on the main themes are also invited.

You can find calls for papers for these tracks at:

http://academic-conferences.org/eciw/eciw2011/eciw11-call-papers.htm

The ECIW conference proceedings are:

· listed in the Thomson Reuters ISI Index to Scientific and Technical Proceedings (ISTP/ISI Proceedings)

· listed in the Thomson Reuters ISI Index to Social Sciences & Humanities Proceedings (ISSHP)

· listed in the Thomson Reuters ISI Index to Social Sciences & Humanities Proceedings (ISSHP/ISI Proceedings).

· indexed by the Institution of Engineering and Technology in the UK.

Conference publications are submitted for accreditation on publication. Please note that depending on the accreditation body, this process can take several months.

Please feel free to circulate this message to any colleagues or contacts you think may be interested.

Monday, June 14, 2010

Two papers published at C6

I have updated the publications tab with two papers that were published in the proceedings of the upcoming Conference on Cyber Conflict. As is always the case, by the time they went to print I already had some ideas for changing them. Nevertheless, here they are:
  • Lorents, P. and Ottis, R. (2010) Knowledge Based Framework for Cyber Weapons and Conflict. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 129-142.[link]
  • Ottis, R. (2010) From Pitch Forks to Laptops: Volunteers in Cyber Conflicts. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 97-109. [link]
Any comments and feedback welcome.

Friday, May 14, 2010

Baltic Cyber Shield 2010

I spent the first two days of this week engaged in a multinational distributed cyber defence exercise - Baltic Cyber Shield. It was a tech-centric exercise organized by CCD COE and various Swedish defence organizations, particularly the Swedish National Defence College and the Swedish Defence Research Agency. The Estonian Cyber Defence League, a volunteer cyber defence organization, also provided invaluable support. All in all, about 100 people from about 10 countries took part in the exercise.

According to the scenario, six blue teams (3 Swedish, a Latvian, a Lithuanian and a NATO team) of up to ten experts were deployed to take over compromised and poorly set up networks targeted by an extremist environmental group's "cyber warfare division" (multi-national red team). The exercise was distributed, so the participants performed the defence and attack missions remotely.

I must say it was a lot of fun. As expected, there were all kinds of issues, but in the end, everything went quite well. The attackers were able to maintain a steady push, compromising well over a hundred systems over the two days, while the defenders tried different strategies to maintain their services while locking the attackers out of their networks.

As a member of the referee team, I got another good experience, and learned some things that can contribute to my PhD research (the attackers were, after all, supposedly a non-government volunteer group who engaged in politically motivated cyber attacks). Congratulations are in order to the members of Blue 5, a Swedish expert team, who won the exercise.

Next week I will be at the SMi's Cyber Defence Conference in Tallinn.

Friday, March 26, 2010

C6 preliminary agenda published

The CCD COE Conference on Cyber Conflict preliminary agenda is now published. Please take a look and see if something interesting catches your eye. If so, the registration is also open and I look forward to seeing you in June.

Wednesday, March 10, 2010

Cyber Conferences

Here are some cyber conferences that might be of interest, in chronological order (disclaimer: I will take part in all of them):

The International Conference on Information Warfare and Security (ICIW), April 8-9 in Dayton, Ohio, US. This is an academic conference with peer reviewed proceedings and covers a wide range of topics from PSYOPS to cyber operations. I will be presenting a paper titled "Cyberspace: Defininition and Implications".

The SMi Conference on Cyber Defence, May 17-18 in Tallinn, Estonia. This is a professional conference that is leaning a bit towards military approaches. I am invited to give a talk there.

The CCD COE Conference on Cyber Conflict (C6), June 16-18 in Tallinn, Estonia. The Conference is a mix of academic and professional presentations and will also publish peer reviewed proceedings of the academic content. There are three tracks: Legal, Strategy and Technical Solutions. I will be managing the Strategy track. I have written about this event before in here and here. Registration is now open.

The European Conference on Information Warfare and Security (ECIW), July 1-2 in Thessaloniki, Greece. This is an academic conference with peer reviewed proceedings and covers a wide range of topics from PSYOPS to cyber operations. I will be chairing the Cyber Conflict mini-track and presenting a paper titled "Proactive Defence Tactics Against On-Line Cyber Militia".

Oh yeah, did I mention that the registration is open for the C6?

Wednesday, November 4, 2009

CFP: Conference on Cyber Conflict

The Call for Papers is out for the CCD COE Conference on Cyber Conflict. The event will take place in Tallinn from 16-18 June 2010 and it combines the two conferences that the Centre organized in 2009 (You can read summaries here and here). There will be a separate training day on June 15th.

Bruce Schneier will give the keynote address and judging from the experience of the this year's events we expect many other interesting talks and papers as well.

The conference is split into three tracks: Technical, Concepts and Strategy, and Legal and Policy. Paper submissions are welcome to all tracks. Note that the deadline for abstract submission is a mere four weeks away!

Key dates
Abstract due: 30 November
Paper due: 01 March 2010
Conference: 16-18 June 2010

Monday, October 19, 2009

CWCON '09 proceedings available

Yep, they are finally here. The proceedings of the CCD COE Conference on Cyber Warfare, which took place in June, have now been published with the help of IOS Press. Titled "The Virtual Battlefield: Perspectives on Cyber Warfare" it appears as book three in the Cryptology and Information Security Series, and is edited by Christian Czosseck and Kenneth Geers of the Centre.

It's 300 pages contain 21 peer-reviewed papers presented at the conference. In the coming weeks I hope to follow through on my promise and write reviews for the ones that are of most interest for me.

On the same note, the call for papers for the next year's conference is due out shortly, so start warming up your paper ideas.

Monday, September 14, 2009

Cyber Conflict Law and Policy Conference

As mentioned earlier, I attended the Cyber Conflict Law and Policy Conference in Tallinn last week. The event was organized by the CCD COE and took place in Swissotel from 9-11 September. About 150 attendees from about two dozen countries discussed issues like the applicability of the Law of Armed Conflict, legal frameworks etc. I will try to briefly summarize by sessions.

Setting the Stage

The conference opened with a keynote speech by the President of Estonia, Mr Toomas Hendrik Ilves. He stressed the need to adapt the defense thinking (including legal frameworks) to the changes in technology. He illustrated the point with medieval defensive structures in Tallinn, which were useless in fending off air raids during WWII. He also talked about the need for collective cyber defence. An important idea was that in NATO, as far as cyber defence is concerned, we should focus more on Article 4 (consultation among nations) today, so that if and when Article 5 (collective self-defence) is ever needed, there is already some consensus.

Next speaker was MG Glynne Hines, Director of NATO HQ C3 Staff. He pointed out the need for consistent legal advice and the usefulness of embedding lawyers in a cyber defence organization. He alsp briefly touched upon some changes in NATO that were initiated by the lessons learned from the 2007 cyber attacks against Estonia: adoption of NATO cyber defence policy and concept, accelerated development of NCIRC and the NATO cyber defence exercise.

Ms Eneken Tikk of the CCD COE, the content organizer for the conference, introduced a draft Framework for International Cyber Security (FICS), which was developed in cooperation with George Mason University Center for Infrastructure Protection (GMU CIP). Basically, they are a collection of abstract models/slides that should be helpful in reaching a common understanding about the issue.

Country Reports on Cyber Security Strategy

Ms Heli Tiirmaa-Klaar from Estonian MoD gave a brief overview of the 2007 April-May events, as well as the pervasiveness of e-services in Estonia. She then proceeded to introduce the Estonian Cyber Security Strategy. Some more points from her talk: cyber attacks pose a new asymmetric threat against critical infrastructure and the development of cyber defence capabilities is very uneven across different states.

Dr Per Oscarson from the Swedish Civil Contingencies Agency gave an overview about his organisation and the Swedish approach to national cyber security. It seems the Swedes have at least in theory a model for planning cyber security, consisting of two main parts: the strategy (vision and strategic directions) and the action plan (explicit objectives and measures).

WCDR Adrian Frost from UK MoD proceeded by giving a quick overview of the British approach. Apparently, UK considers cyber as one of the five domains (air, land, sea, space and cyber), similar to some thoughts I have heard from USAF in recent years. He briefly introduced the UK Cyber Security Strategy (approved 23 June), which aims to secure UK advantage in cyberspace by reducing risk (public), exploiting opportunities (industry) and improving knowledge, capabilities and decision-making (international).

Autopsy of a Cyber Conflict

Professor Daniel Ryan from the US National Defense University gave an interesting talk about the lawyer's look at a cyber incident. Specifically, he addressed the issue that there are regular incidents (handled as per SOP or ignored) and then there are INCIDENTs that really matter. In the latter case, one needs to determine if it is an attack (or accident, technical failure etc.), who is behind the attack (attribution) and who can/should respond to the attack (law enforcement, intelligence, military, lawyers).

Next, Dr Bret Michael from the US Naval Postgraduate School addressed various cyber conflict issues from a more technical viewpoint. Among his points was the claim that cloud computing will change the way we work and will introduce new security challenges. An interesting thought was the martial arts analogy - in cyber defence we should not focus on rigid and forceful response (karate), but rely more on the flexibility and use of the opponent's strength (aikido).

Unfortunately I had to leave early that day and I didn't catch Mr Joe Weiss' (Industry Expert and Control Systems) talk on industrial control systems, but I heard that he gave an insightful presentation on the vulnerabilities associated with the systems that uphold modern society.

Cyber Security Institutionalized - Pieces of an Effective Defence Model

The second day started with Ms Eneken Tikk's talk on international organization's legal and policy approaches to cyber incidents. Sha listed the numerous laws, regulations and directives that various IOs have produced to deal with cyber security matters. To limit the scope, she briefly examined the documents that focus on data protection and concluded that while there are a lot of regulations in place, they tend to be stovepiped and there is not enough practice in using the breadth of tools available. She also discussed the different approaches that have been taken in various EU countries on data protection.

Ms Yurie Ito from ICANN, formerly of JP-CERT gave a presentation about recent developments in ICANN, with regard to security. Unfortunately she did not have enough time to delve deeper into her slides on Conficker, as I am sure her insight would have been valuable.

Ms Maeve Dion from GMU CIP addressed public-private partnerships and national input to international cyber security. She touched various points, including the many areas of law that deal with aspects of cyber, informal vs formal networks in cyber defence, developing strategy and risk analysis methodologies.

The day ended with three working groups that discussed FICS and cyber law/policy issues.

Enhanced FICS

The final day started with Professor Derek Jinks from US Naval War College. His talk was on the Law of Armed Conflict (LoAC) and the military perspective. He pointed out that LoAC is not there to minimize "war" as an official status of affairs, but to minimize organized violence. Another good point was that "armed" does not imply any physical properties or mechanics, but rather organized application of violence. He further explored the concept of armed attack, as it is often used in the definition of armed conflict. He noted that armed attack is subject to various conditions, such as severity (death or substantial destruction of property), status of the attacker (according to UN terms, attacker is state, but in practice it is often a non-state actor that may or may not have state sponsorship), status of the target (again, old rules dictate the state as target, whereas in practice, any entity that the state can claim sovereignty over, incl. citizens), necessity, proportionality, time-proximity etc. He also raised some interesting questions about new concepts like cyber occupation (displacing civil authority by means of cyber attacks). A very good talk indeed, even though he did not have enough time to go into all the details.

Next came Dr Thomas Ramsauer from German Ministry of Interior. His talk focused on the law enforcement perspective, but he also revisited some LoAC questions. He used a nice model of cyber conflicts, where you have the damage to target on one axis and organization of the attackers on the other. Then, as damage and level of organization increase, one progresses from cyber crime to cyber terrorism to cyber war. While I don't think it is that simple, it is a nice and visual way of presenting the idea. He also briefly touched the Schmitt test and the concept of attributing "private attacks" to a state actor. An interesting thought was that in order to limit collateral damage to civilians, commanders in future wars may be obliged to prefer cyber attacks over traditional means of warfare.

Mr Lauri Almann from Aare Raig Attorneys-at-Law (former undersecretary of defence of Estonia) gave a talk on national defence law from the government perspective. He focused on factors of decision making, which consisted of four one-dimensional axis': secret-public, fast-slow, international-national and professional-emotional. He proposed that in cyber conflicts, the first of all these pairs is the relevant (used) property. I am not sure I agree. Secrecy in international environments seems to exlude the fast property and often the professional property as well. He closed by noting that there is not much need to exercise the technical community (as they perform the cyber defence mission daily), but educate and train the legal and political community, who only get involved when things get hot [and potentially profitable - author's note].

Professor Lilian Edwards from University of Sheffield provided a brief glimpse into the information society law and the user perspective. She noted that laws should always set a balance between security and privacy. The problems appear when the balance varies from law to law and over different jurisdictions.

The conference ended by comments of the observers as well as summaries of the working group results. A couple of points that stuck were the slide on the spectrum of state-sponsorship by Jason Healey (US Cyber Conflict Studies Association) and the idea that some sort of International Cyber Tribunal may be needed [not sure how much success other international tribunals have had].

Finally, Mr John Bumgarner from the US Cyber Consequences Unit gave a short overview of their recent report on the lessons learned from the Georgia cyber attacks in 2008. Unfortunately, the report is not public, so his notes were fairly general and added little new insight to the events in Georgia. It's a shame, as he possesses a wealth of knowledge on the subject. I understand his position, but it is yet another example of classification issues diminishing the value of research.

Disclaimer: I hope I did not do injustice to anyone by misunderstanding or missing key issues in their talk.

Overall, the conference was a success and I am looking forward to the next one. I had the chance to talk to many interesting people on the sidelines and I also met some old friends. The cyber scene is very small indeed.

Tuesday, September 8, 2009

Upcoming Conference

This week I will participate in the Cyber Conflict Legal and Policy Conference, in Tallinn. Organized by CCD COE, it aims to build some common ground in understanding the legal issues of cyber defence. More on the conference next week.

Friday, September 4, 2009

Paper on Cyber Society

I co-authored a paper with Peeter Lorents and Raul Rikk that was published in the 13th International Conference on Human-Computer Interaction, San Diego, in July. You can also find the paper in LNCS 5623, pp. 180-186.

The paper is titled Cyber Society and Cooperative Cyber Defence. In it, we explore the concept of cyber society, which we define as "a society where computerized information transfer and information processing is (near) ubiquitous and where the normal functioning of this society is severely degraded or altogether impossible if the computerized systems no longer function correctly."

We then examine Estonia as an early form of a cyber society and illustrate it's potential vulnerabilities with the events of April-May 2007. We conclude the paper with the foundations behind the establishment of the Cooperative Cyber Defence Centre of Excellence.

This was my first co-authored paper and as such a new experience. One of the problems of having multiple authors is to write a consistent paper - something that could be improved in this case. However, I think it does convey the ideas that we wanted.

Sunday, June 21, 2009

CWCON 2009 in Tallinn

This week I attended the first Cyber Warfare Conference in Tallinn, organized by the CCD COE. In fact, I was the moderator for the Strategy track, which included many interesting talks on the emerging field of cyber conflicts. CWCON provides an academic publication opportunity for the scientists, but it also includes presentations by the professional community.

Mikko Hypponen from F-Secure gave a nice overview of the evolution of malware in his keynote speech, while Nart Villeneuve from the Information Warfare Monitor talked about their findings about GhostNet.

Other interesting presentations included Amit Sharma on Strategic Cyber Warfare, Ned Moran on analogies and cyberspace, Cyrus Farivar on the media coverage of cyber events, and Maj Julian Charvat on terrorist use of cyberspace.

I plan on providing a more detailed overview of some of the papers within the next few weeks.

EDIT: The proceedings took longer than expected to print, but I have finally received a copy and have started with the reviews (first ones here and here).