Showing posts with label article. Show all posts
Showing posts with label article. Show all posts

Wednesday, October 20, 2010

Article in FutureGov Magazine

I recently wrote an article for FutureGov Magazine about the events in Estonia in 2007. Although my intent was to tone down the hype surrounding the incident, the final "independent" editing process managed to come up with a intro paragraph about "cyber war", even though I had specifically avoided this term in the article itself. I guess that is the risk one takes with media.

The article is available in the August-September issue [large pdf!], on pages 70-72.

Monday, September 6, 2010

Interview explosion

I gave an interview to Baltic News Service (BNS) on Friday. Instead of writing it up as one article, they chose to create a bunch of short pieces that are currently flooding some news portals in Estonia. For a casual observer, it looks like I have personally launched a massive frontal assault on cyber awareness issues. Interesting development, although unintentional.

Wednesday, March 31, 2010

Georgia 2008 and Cyber Neutrality

I happened across an article [pdf] about neutrality in cyberspace by Korns and Kastenberg. In the article, the authors analyze an aspect of the 2008 Georgia cyber conflict that usually receives little attention: the fact that the Georgian government moved some of its online services to other countries during the war. Specifically, the authors worry about what this means to the neutrality of the host countries.

While they raise an interesting question, I do have some issues.

First, there is the question of whether US lost neutral status in the Russia-Georgia war by hosting some services:
"The fact that American IT companies provided assistance to Georgia, a cyber belligerent, apparently without the knowledge or approval of the US government, illustrates what is likely to become a significant policy issue."
Were Georgian websites under attack? Yes, no doubt. Was this a part of the Russian war campaign? Maybe, but at least officially the Russians deny their involvement. Well, if neither belligerent takes responsibility for the attacks, then we can't really refer to Georgia as a "cyber belligerent" (what does this mean, anyway?). We are left with attacks that do not amount to war, but crime or political hactivism, and I am unaware of any international prohibition on cooperating against criminals or hactivists - even on the business level. Besides, blaming Georgia for this decision is similar to arresting the victim of a street mugger, as the only known party in the criminal act.

Then there is the question of the type of aid that was provided to Georgia (citing a Supreme Court decision):
"If the US government establishes a strict position of neutrality, American industry may provide nonmilitary and humanitarian support to a belligerent, but firms are required to halt all commerce that militarily aids a combatant."
I believe this is undiscovered country. Presumably, the drafters of this document kept in mind the physical goods industry, whereas in cyberspace we are mostly concerned with services. Is hosting a government public relations website "commerce that militarily aids a combatant"? I would argue against that, because otherwise US would have to pull the plug on EVERYTHING every time there is a conflict where US remains neutral (although there is a question whether US was truly neutral in this case, as illustrated in the paper).
"Under a traditional international law rubric, to remain neutral in a cyber conflict a nation cannot originate a cyber attack, and it also has to take action to prevent a cyber attack from transiting its Internet nodes."
Since US is one of the leading nations harboring ISPs with questionable practices, and is also home to a large number of malware infected computers (bots in a botnet), then any time you have a large DDoS attack, US is likely to be on the "attack source" list [to be fair, the authors have also covered this aspect]. I consider it quite likely that at least some US-based computers were used against the Georgian sites during the war. If the Russian Federation was behind the attacks, does this mean that US lost its neutrality and became a belligerent? Again, I would say no. It would be great if US could clean up its part of the Internet, though.

The rest of the paper does a quick analysis of several potentially applicable laws and treaties. Again, while I do not agree with all of their conclusions, they have done a very good job of pulling together thought-provoking concepts. I highly recommend reading it.

These are just some first reactions, but I can see that I need to do some deep thinking on the subject.

Reference:
Korns, S.W., Kastenberg, J.E. (2008) "Georgia’s Cyber Left Hook." Parameters: 38.4 : 60-76. U.S. Army War College. Available at: http://www.carlisle.army.mil/usawc/Parameters/08winter/korns.pdf

Tuesday, December 22, 2009

Russia and Cyber Attacks

A colleague pointed me to an article in the Baltic Security and Defence Review, an annual publication of the Baltic Defence College (international staff college for military officers at OF3-OF5 ranks). MAJ William Ashmore (US Army) writes an overview of recent cyber conflicts with Russia, titled "Impact of Alleged Russian Cyber Attacks" [pdf].

While the article covers a lot of ground it seems that he is not a subject matter expert in cyber conflicts. The quality of the references is relatively weak (mostly public news media) and there are a few simple errors. On the other hand, he has done a fairly broad background check for the legal/doctrinal work done at OSCE, UN etc.

He provides an overview of events in Estonia 2007 and Georgia 2008 among others, and a summary of NATO's activities in setting up cyber defence. He spends some time on Herman Simm's case (highly placed spy for Russians in Estonian MoD, caught 2008), although to me his arguments there seem a bit weak.

He reviews the national and international responses/comments to the Russian cyber campaigns, including potential attribution. There is also a fairly interesting chapter about future trends in Russian cyber activities (including Dr Panarin's recommendations). I think he may be onto something when he says that in Russia, cyber is mostly seen as an offensive capability.

With the US primarily focused on the Chinese cyber threat, the Russian (and other) cyber studies remain in the background. Therefore, it is a refreshing piece of reading, regardless of some issues with depth or quality. As always, read the article for full info.

Happy holidays!

Tuesday, September 29, 2009

"Where Computer Security Meets National Security"

I read an interesting article by Helen Nissenbaum, on "Where Computer Security Meets National Security" (2005) [pdf, Springer link] .

She starts with a good point that the "traditional" computer security, developed in the technical community and focused on the protection of a computer (system) is difficult to port into national security terms, where damage to life, economy, morale and reputation is the core worry. She argues that the "technical computer security" focuses primarily on ensuring confidentiality, integrity and availability, even though there is a push to extend this to ensuring overall "trustworthiness" of a computer system (including resilience etc.).

She calls the competing national security conception cyber security (a term that has grown more popular since then). According to her, cyber security is most concerned with three problems:
  • using computer networks "as a medium or staging ground for antisocial, disruptive, or dangerous organizations and communications." In other words, propaganda, phishing and a host of other soft threats;
  • using computer networks to attack the critical societal (information) infrastructure, or the hard threats; and
  • using computer networks against computer networks. I may misunderstand her reasoning, but I think computer networks in the larger sense (Internet infrastructure, SCADA systems, public services on the internet) are also part of the critical information infrastructure, and I would combine the last two categories into one.
I found it interesting that she illustrates how computer security can be used in various moral (protect users from harm) and immoral ways (protect the interests of the company, while limiting the usefulness of the product to the end user).

She then reviews the concept of "securitization" by the Copenhagen School. Essentially, it means that unlike "realist" methods, there are more threats than just military aggression and there are more targets as well (state + religion, economy, environment etc.). Furthermore, securitization is a process of making something into a security issue (especially in the eyes of the public). In her words: "In general, to securitize an activity or state-of affairs is to present it as an urgent, imminent, extensive, and existential threat to a significant collective."
[Note: An interesting concept and something to be studied later.]

The next chapter shows some steps how cyber security has been securitized, including a funny interlude about how the music and film industry is trying to securitize the P2P threat against their obsolete business model. She also covers some examples of cyber space shown as a potential battle space and it's asymmetric nature.

Getting to the meat of the issue, she compares the two approaches:
  • Computer security recognizes a broad range of the degree and type of harm, while the cyber security assumes that the threats are dire or existential.
  • Computer security focuses on protecting the "individual nodes" (people, computers), while cyber security looks at "collective security."
  • Computer security rests on the moral foundation of protecting from harm, while the moral aspects of cyber security can vary depending on the securitization process.
An important question she brings up is when is securitization warranted? When is a threat dire enough to become a national security issue that is handled in secrecy, and potentially in ways not common to a democratic state? She argues that there is lack of reliable data on the size of the threat from the computer security perspective, as research is focused on (potential) vulnerabilities, while reporting of actual incidents is hap-hazard at best. She also touches on the issue that the same attack can be viewed in many different contexts (criminal, national defence, activism etc.).

She concludes that in the end, the "technical computer security" approach might be better, as it provides security at the user level and thus still allows us to use the net for the core purpose of sharing information and ideas. The highly securitized state controlled approach, on the other hand, raises questions about privacy, freedom of speech etc.

To sum up, a very interesting article with much food for thought. I found several interesting insights here and I am sure that more will pop up later. If anything caught your eye, I recommend reading the article in full, as there are many details that I did not cover.

Thursday, September 17, 2009

Article in Akadeemia

One of my articles (Conflicts in the information age - cyber attacks and the citizen society) was published in the Estonian academic journal called Akadeemia (2009, nr 9, Special Edition on War and Peace) a few days ago.

In the article, I revisit the own forces/hired guns/volunteers categories and focus on the latter. I try to explain some interesting aspects of using volunteers, such as the parallel rise in crime and the need to "exercise" the volunteers regularly. I also try to look at why ordinary people from the street may become belligerents in cyber space, specifically addressing radicalization through Internet and formulation of cyber tribes. I end the article with a positive note, that volunteers can be harnessed for good, as well as evil. Consider, for example, defensive volunteer organizations, such as the WARP network in UK. In addition, I touch upon the personal responsibility of today's netizens - we all have a part to play in developing a safer cyber society.

Friday, September 4, 2009

Paper on Cyber Society

I co-authored a paper with Peeter Lorents and Raul Rikk that was published in the 13th International Conference on Human-Computer Interaction, San Diego, in July. You can also find the paper in LNCS 5623, pp. 180-186.

The paper is titled Cyber Society and Cooperative Cyber Defence. In it, we explore the concept of cyber society, which we define as "a society where computerized information transfer and information processing is (near) ubiquitous and where the normal functioning of this society is severely degraded or altogether impossible if the computerized systems no longer function correctly."

We then examine Estonia as an early form of a cyber society and illustrate it's potential vulnerabilities with the events of April-May 2007. We conclude the paper with the foundations behind the establishment of the Cooperative Cyber Defence Centre of Excellence.

This was my first co-authored paper and as such a new experience. One of the problems of having multiple authors is to write a consistent paper - something that could be improved in this case. However, I think it does convey the ideas that we wanted.

Thursday, July 2, 2009

A time for a Cyber Service of the Military?

I stumbled on an article by COL Surdu and LTC Conti, which was published earlier this year in the IA Newsletter [Vol 12, No 1, 2009 - pdf]. In the article, they argue that US needs a new military service that would handle the cyber warfare mission.

Currently, each service already has small elements dispersed in the structure, but they are not coordinated, nor are they integrated into the bigger picture. I think they bring out a good point that the US military (in fact, other militaries as well) is not fit to fight a cyber war, as its leadership, processes and culture are fundamentally incapable to understand it.

The main problem is that the military does not place enough emphasis on technical expertise, or as they put it:
"Today’s militaries excel at their respective missions of fighting and winning in ground, sea, and air conflict; however, the core skills each institution values are intrinsically different from those skills required to engage in cyberwarfare.
...
To understand the culture clash evident in today’s existing militaries, it is useful to examine what these services hold dear—skills such as marksmanship, physical strength, and the ability to jump out of airplanes and lead combat units under enemy fire. Accolades are heaped upon those who excel in these areas. Unfortunately, these skills are irrelevant in cyberwarfare.
...
Consider the awards, decorations, badges, patches, tabs, and other accoutrements authorized for wear by each service. Absent is recognition for technical expertise. Echoes of this ethos are also found in disadvantaged assignments, promotions, school selection, and career progression for those who pursue cyberwarfare expertise, positions, and accomplishments."
I wholeheartedly agree with their arguments, having come to a similar conclusion some time ago. Their proposal to deal with this issue is to create a new service that would be on equal status with the kinetic services. However, I am not so convinced that a transition so profound can be made in one step. Perhaps it would be better to use the USAF model and first create cyber commands (historical Army Air Corps) within the services, then integrate them, and then, maybe, raise them into a new service.

They are right, however, that the root of the problem lies with the personnel management in the military. One could say that a techie should stay in the service, become the top dog and change it from within, but that discounts the fact that techies do not get promoted to top dog. In fact, there are precious little positions near the top that have anything to do with technology. Therefore, a techie must either be a multi-talent or forget his tech aspirations and plod up the traditional leadership/management track. Meanwhile, people who have a talent for tech positions will not be promoted and more than likely get rotated to (technologically) meaningless positions... or they get out. Therefore, any step that will accommodate the requirements and skills of the tech oriented service members while not undermining the traditional services, is a step in the right direction.

Friday, June 26, 2009

Evgeny Morozov on Cyber Myths

Evgeny Morozov of the Open Society Institute has an interesting essay in the Boston Review about myths in cyberspace. Specifically, he addresses the scaremongering and vague threat information that is used to get access to funding, fame or power.

He points out many official statements that exaggerate the threat from cyber terrorism and cyber war and asks the question: is there any evidence to back up these claims? No, at least not in the public realm. He also makes a point that the threat from the net information is produced by intelligence/defence organizations and information security companies that benefit from the increased funding. I think he is right in the sense that there are very few facts available, so we are left with hypotheses and conjecture. Honestly, I am partly to blame, as I have presented similar worst case scenarios in numerous conferences, in order to raise awareness of the topic.

He also touches the foggy quagmire that is the international legal definition of cyber warfare and what, if anything can and should be done if one breaks out. I think we will not have a clear answer on this in the near future, but at least the topic is also addressed by professionals.

In terms of how useful cyber attacks are for the military, Morozov refers the opinion that superpowers do not need cyber power, as they have more conventional means to crush the enemy. While that may be true, the question of attribution once again comes up - who will the superpower nuke, if they cannot identify the source of the cyber attack?

On the other hand, his conclusion that we should focus more on the threats from cyber crime and cyber-espionage is correct. However, it is not correct because cyber war is improbable, but because the tools used in cyber war will be very similar to the ones used in crime and espionage. The same piece of malware can be used to steal your personal data, collect intelligence on your organization or to disrupt your networks in preparation for a war. Thus, better defense against crimeware will also mean better defense in war.

A comment on Estonia

Unfortunately, Morozov uses unclear wording that may suggest that Estonia was off-line for nearly a month in 2007. It would be more correct to say that Estonia was under attack for about three weeks in 2007, but only a few critical on-line services (like banks) were affected for clients inside Estonia. One of the options, a white-list based "island Estonia" defence meant that the vast majority of the attacks could be easily blocked while maintaining service to the vast majority of the clients. As a result, clients of the two biggest banks in Estonia saw only a 45-90 minute interruption of service at the start of the attacks and that only affected the web interface of the banks. What is worrying, however, that these were critical "civilian" targets in a political conflict.

Sure, non-critical services (public government websites and news sites, for example) did suffer longer service outages due to cyber attacks (mostly simple DDoS), but in my opinion this was not a big issue for the state as a whole. The biggest effect would be potential information blockade, as local news sites or press sites are off-line, but that can easily be remedied by using other means of communication to push the message out (remember, e-mail works, phones work, faxes work, radio and TV are still on air, and even the postman makes his rounds). I personally had no problems communicating with friends and colleagues abroad throughout the period.