Showing posts with label cyber attack. Show all posts
Showing posts with label cyber attack. Show all posts

Wednesday, December 15, 2010

DDoS - a legitimate form of protest?

The cyber attacks against supporters and opponents of Wikileaks have generated a fair bit of debate about whether or not DDoS can be a legitimate form of protest. I tend to side with the "nays" on this one.

Sure, DDoS could be compared to a sit in, but with infinitely lower entry threshold. One does not need to travel anywhere, or actually waste their time "sitting", and very often does not risk dealing with law enforcement - the computer can protest on their behalf all night long. It's more like throwing nails on a freeway and going home.

But my main argument against protest DDoS is that it can then be used for any cause. Attacks against Radio Free Europe? It's cool, they just protestin'! As can be seen from the Wikileaks affair, both sides in there are using cyber attacks to get their message across. Is this truly what we want? I dont like you, so I have the right to DDoS you? I have the right for free speech and the right for making stupid people shut up?

Wednesday, October 20, 2010

Article in FutureGov Magazine

I recently wrote an article for FutureGov Magazine about the events in Estonia in 2007. Although my intent was to tone down the hype surrounding the incident, the final "independent" editing process managed to come up with a intro paragraph about "cyber war", even though I had specifically avoided this term in the article itself. I guess that is the risk one takes with media.

The article is available in the August-September issue [large pdf!], on pages 70-72.

Friday, May 14, 2010

Hostage Deterrence

Today I happened to hear yet another discussion about the impossibility of deterrence in cyberspace, when I realized that it may not be entirely true.

While I agree that in the conventional sense, cyberspace does not support the concept of deterrence very well (lack of attribution), I think there is a special case where it might work. Consider a situation, where Nation A develops a credible offensive cyber capability and announces a policy that regardless of attribution, if a critical cyber attack were launched against it, it would automatically launch a critical cyber attack against Nation(s) B(,C,D, ...). In that highly controversial case, Nation A would actually have a deterrent against the other Nation(s) in question.

In other words, Nation B is effectively deterred from launching a critical cyber attack against Nation A.

Obviously, the weak point here is that any Nation X may do a false flag or anonymous attack in order to make Nation A to attack Nation B without cause. That is why it is not normal deterrence, but something you might call "hostage deterrence". Has anyone come across such a thing before, either in theory or in practice?

Friday, May 7, 2010

Cyber Attacks and NATO Article 5

I gave a lecture about malicious uses of cyberspace to an international group in Germany yesterday, and one of the attendees asked me if a cyber attack could ever be a trigger for the collective self defense clause of NATO a.k.a. Article 5.

A very good question.

Allow me to answer via analogy:
1. A cyber attack is either malicious use of commonly available technology (computers, software, network infrastructure, ...) or the use of a cyber weapon (something specifically crafted for causing damage/disruption in cyberspace - such as a DoS tool) in order to create a cyber incident.
2. The ONLY time when Article 5 was actually invoked was in response to the malicious use of commonly available technology (passenger aircraft during 9/11).
3. Therefore, it follows that if the cyber attack causes serious enough harm, it can trigger Article 5 action.

The question that remains, then, is what level and type of harm will cross this threshold. In reality, this will never be set in stone. Likely there will be some cases that will automatically trigger it, however, in the end it will be case by case, as it is with "conventional" attacks.

Monday, March 8, 2010

On offensive operations in cyberspace

This year started out in full gear for me and it seems that this is the first week where I can take a breath and write down some of my thoughts.

Last week I was invited to give a talk at one of many cyber defence/IA related conferences in Europe. As is often the case, the question of offensive cyber operations came up. It seems that whenever this happens, the automatic (and politically correct) answer is: well, the military can't plan an offensive cyber campaign, because most likely they will not be able to identify the actor behind the incoming cyber attacks (the attribution problem). They are right, counterattacks in cyberspace can be tricky.

However, this misses the point completely. Who says that cyber operations have to be symmetric (targeting only cyber aggressors with cyber ops). There is every reason for the military to plan and prepare offensive cyber operations for various military situations. When a military is deployed to fight someone, then the target should already be identified and is not necessarily limited to cyber operatives.

It makes sense to consider different ways to achieve a military objective: aerial bombardment, naval blockade, precision drone strikes, landing a division of Marines, cutting off C2 with cyber attacks, jamming radio communication with EW, threatening with nukes, etc. In fact, according to the principle of least harm, it is consceivable that the commander should FAVOR cyber attacks over more lethal options, if the end result is the same.

There is no good reason to limit the options of the commanders in the doctrine-writing phase between conflicts. Sure, there are legal issues, attribution issues, collateral damage issues and so on - as is the case with drone strikes, for example. And yet the drones are in the sky today. It just shows that where there is a will, there is also a way.

The only real counterargument for offensive cyber is that we don't want to see it on the battlefield (like nukes, bio and chem). However, clearly this is a Genie that we cannot force back into a bottle. Potential adversaries, both state and non-state are already using cyber attacks on a daily basis. Therefore, it makes sense to include this option in the play book of the commanders of the future.

It should be noted that I am not advocating military use of cyber attacks on a daily basis, but only in conflict situations and against "legal" targets. I am also aware that the whole "legal" issue is far from solved and most likely will not be solved in any reasonable timeframe.

Tuesday, December 22, 2009

Russia and Cyber Attacks

A colleague pointed me to an article in the Baltic Security and Defence Review, an annual publication of the Baltic Defence College (international staff college for military officers at OF3-OF5 ranks). MAJ William Ashmore (US Army) writes an overview of recent cyber conflicts with Russia, titled "Impact of Alleged Russian Cyber Attacks" [pdf].

While the article covers a lot of ground it seems that he is not a subject matter expert in cyber conflicts. The quality of the references is relatively weak (mostly public news media) and there are a few simple errors. On the other hand, he has done a fairly broad background check for the legal/doctrinal work done at OSCE, UN etc.

He provides an overview of events in Estonia 2007 and Georgia 2008 among others, and a summary of NATO's activities in setting up cyber defence. He spends some time on Herman Simm's case (highly placed spy for Russians in Estonian MoD, caught 2008), although to me his arguments there seem a bit weak.

He reviews the national and international responses/comments to the Russian cyber campaigns, including potential attribution. There is also a fairly interesting chapter about future trends in Russian cyber activities (including Dr Panarin's recommendations). I think he may be onto something when he says that in Russia, cyber is mostly seen as an offensive capability.

With the US primarily focused on the Chinese cyber threat, the Russian (and other) cyber studies remain in the background. Therefore, it is a refreshing piece of reading, regardless of some issues with depth or quality. As always, read the article for full info.

Happy holidays!

Friday, December 11, 2009

Abstract on capabilities of novice cyber warriors

Below is an abstract paper idea that I am currently developing. The main idea is to look at the potential actions available for low level attackers - people who have no special training or experience with cyber attacks. The working title is "From pitch forks to laptops: volunteers in cyber conflicts". I would be grateful for any useful references on this topic.

Abstract:

The capability for organized violence in the international setting has normally been the domain of nation states. Cyberspace, however, provides an international arena where almost anyone has the power to attack any target at will. While most of these attacks have little effect, there is often little disincentive to using them, as attribution of cyber attacks and prosecution of attackers is still the exception, instead of the norm. Thus, the 21st century farmers with pitch forks or cyber militia become more than a local force and, if organized well enough, can mount an offensive cyber campaign that could damage the economy or social order of a nation state on the other side of the planet.

In order to test this claim, I will first consider the potential threat from the Internet users who are untrained in hacking techniques and who have very limited resources. In general, there are two types of activities that are open for such persons: supporting the cyber campaign by providing resources, cover and training (among other things) and launching cyber attacks as part of the cyber campaign. It is important to note that the support activities may be more significant than fighting in a People’s War type conflict.

I will proceed by considering the potential threat from advanced hackers or hacker organizations. While there have been many well publicized hactivism campaigns, there are few examples of serious cyber strikes that target critical systems. Therefore, most of this analysis is theoretical, drawing on past examples as appropriate.

In the end, national security planners must face this threat and develop a strategy to counter it. I include some proposals for dealing with the cyber militia problem and discuss the potential merits and pitfalls of farmers with laptops engaging in cyber campaigns both on their own as well as in the service of a state.

Monday, December 7, 2009

Review: Jose Nazario on Political DDoS Attacks

Time for another review. This time it is Jose Nazario's CWCON paper called "Politically Motivated Denial of Service Attacks." He is looking at DDoS as one of the more visible and popular cyber attack forms and is limiting his sample to the ones with a political motivation (vs the standard criminal motivation - money).

NOTE: The final published version of this paper was accepted after the conference so it includes some more recent examples.

His research is based on data from three sources: ATLAS project at Arbor Networks (basically, ATLAS collects data from sensors to provide an overview of the more visible cyber campaigns), infiltrated botnet C&C servers and border gateway protocol (BGP) routing data.

He starts out with a little overview of major political DDoS campaigns of the past, covering the following events:
  • 2001 Hainan Island incident
  • 2007 Estonia campaign
  • 2008 China v CNN campaign
  • 2008 Georgia campaign
  • 2008 Burma
  • 2007 elections in Russia
  • 2008 Radio Free Europe campaign
  • 2008 anti-NATO campaign in Ukraine
  • 2009 MSK forum DDoS in Kazakhstan
  • 2008 DDoS-censoring of Russian opposition websites
  • 2009 Israel v Gaza/Hamas
  • 2009 Kyrgyzstan - a false positive?
  • 2008 Kommersant DDoS
  • 2009 Kazakhstan opposition sites under DDoS
  • 2009 South Korean/US campaign
It is noticeable how most of these events are known by the target only. In history, conflicts are usually named after both/all participants or at least the participants are known. In cyber conflicts, however, it seems to be the norm that the aggressor remains anonymous. Even if all the circumstantial evidence and opinions point against one entity, rarely is there enough proof to attribute the attack in court.

He continues to describe the attacker type that seem to be behind most of the attacks listed. In general, the attackers are "classic right-wing" supporters of the government and targeting internal or external opposition. He also writes about using propaganda to recruit supporters for a cyber campaign and then training them online - a basic ad-hoc cyber militia. What the militia cannot achieve with finesse and expertise, they make up in numbers (DDoS).

He points out that the classical goals for such attacks are to punish the target, or to show dissent, or to censor the target (especially true for attacks against news outlets and opposition parties). He brings examples of partial attribution: Nashi youth group in Russia, the Chinese Honker Union and StopGeorgia.ru. Note that in all these cases the attackers made the claim - nothing has been proven in court (as far as I know).

He reviews some broad responses to the cyber campaigns listed and finishes with recommendations:
  • harness public support and international cooperation
  • deploy available commercial tools
  • be open to commercial offers to help
  • develop a more efficient decision making process
  • delegate authority
  • consensus is sometimes not necessary
In conclusion, he also points out that we need to study guerilla and asymmetric warfare in order to succeed on the cyber battlefield.

The paper has numerous examples from recent years and thus gives a good overview of the extent of the problem. However, the examples have different level of detail (often too vague) to be of much help on researching a specific case. I would have expected a more detailed analysis of a limited number of campaigns. As always, read the paper for full value.

Wednesday, December 2, 2009

Review: Billy Rios on Cyber Attacks

It has been a busy time since last post. I gave a short lecture at the NATO School in Germany last week and I'm preparing some paper ideas for next year. However, I decided to take a short breather and review another paper from the Conference on Cyber Warfare - Billy K. Rios wrote a piece titled "Sun-Tzu Was a Hacker: An Examination of the Tactics and Operations from a Real World Cyber Attack." His work is partially based on the Grey Goose Report I.

The paper tries to map some real cyber operations to equivalent concepts in maneuver warfare, particularly drawing on the Georgia case and the US Marine Corps doctrine. He starts out by describing the essence of maneuver warfare and points out that cyber operations cannot "win a war". Instead, they can break up the enemy's cohesion and allow for exploitation by other (conventional) means. Incidentally, the Chinese seem to have adopted the same idea.

Discussing decentralized command and commanders intent, he brings the example of how a target list of Georgian sites was posted in a forum without clear instructions for action. The forum members then contributed with potential attack plans/instructions and discussed the campaign. As a result, a variety of targets and options became available and the attackers could each choose a course of action suitable for their skill, resources and level of motivation. As a side note, similar behavior was observed a year earlier during the cyber campaign against Estonia.

As an example of combined arms, he brings the example of SQL injection queries for fingerprinting and gaining access to database contents (NB! starting a month before the armed conflict), exploiting this information for intelligence, preparing automated attack tools that are then provided through the forum to anyone interested. I think he could have used a better example, because the link to combined arms is not clearly apparent.

Illustrating the concept of initiative he uses the examples of pre-emtive intrusions to Georgian systems and the sustained pressure to keep initiative on the attacker side, while keeping the Georgians to react. As a result, responding to cyber attacks wasted valuable time.

He also explains the importance of identifying and attacking enemy Centres of Gravity, although he does not connect it to the Georgian case. The important point is that these centres need not be physical fortifications or units, but can also encompass things like morale and resolve. Clearly, cyber attacks are a potential way of attacking the enemy centres of gravity, especially C2 networks and information targets.

He then points out that conventional weapons have physical limitations and the skill of the operator can only have relatively little effect in terms of stretching the effective range, damage etc. For example, a skilled marksman with a M4 carbine can hit a target from several hundred meters with standard sights, but not much more. On the other hand, the cyber warrior's capability to do damage is directly correlated with his skills. I especially like this sentence:
"Creating an offensive cyber capability is less about finding the right hardware and more about finding the right people and skillsets."
He also highlights that it poses a problem for intelligence analysts, as it is very difficult to estimate or track the development of offensive cyber capability, because the key component is the skillset of operators, not the invested money or acquired hardware.

Rios summarizes the paper by emphasizing that
  • cyber capability should be incorporated into the overall plan, as it will not win the war on its own.
  • Command and Control should be kept decentralized and decisions delegated to the lowest level. [This is in contrast to the Chinese doctrine, which seems to prefer rigid central control and limited use of the cyber strikes. - RO]
  • the individual cyber specialist is the weapon system, not his laptop or his sidearm.
The paper is short and to the point. I like the summary, which brings out some good points (even some that do not seem apparent from the main text).

Wednesday, September 2, 2009

Asymmetry in Cyberspace

The other day I started to ponder about what constitutes a fight in cyberspace. I find that it is fundamentally different from what could be termed conventional fighting (in a military sense) - tank engagements, infantry ambushes etc.

The issue is really about the asymmetry between attackers and defenders. A cyber attacker needs to find just one opening, while the defender needs to cover every conceivable (and inconceivable) weakness. This is a critical mismatch in terms of resources.

Another asymmetric aspect is the fact that in a "cyber battle", attackers rarely present a target themselves, because they are difficult to identify. Even if the attack can be attributed, there is little that can be done with a cyber retaliation. An attacker does not "own" critical technical infrastructure, which could be taken out. They just use the public communication infrastructure as a service provider and a "human shield".

In a potential two-way cyber engagement this works both ways. A practical example would be to use red teams to knock out critical infrastructure targets on the other side, while "ignoring" the attackers from the other side and relying on the quality of one's defence.

Tuesday, August 25, 2009

Blog reset

I am back from my summer hiatus. As promised, I will continue to throw my ideas and thoughts in here.

I have often found it interesting how some people fear the offensive side of cyber. 'Defense only' is the politically correct way of putting things, even though it is pure nonsense. Skills and knowledge to be a good defender is largely dual-use.

Look at it this way. Imagine briefing a general: "Sir, our defensive infantry brigades have dug in around the city, we can now deploy our offensive infantry regiment to attack the enemy." True, some units are better equipped and trained for offensive or defensive missions, but that does not mean that they lack the capability to do both.

Tuesday, July 14, 2009

On definitions

A big problem in the field of cyber is the lack of commonly agreed definitions. I think cyber war and cyber terrorism are the worst, each having numerous conflicting definitions. So, in order to clarify my own thoughts, here is my attempt to pin down the meaning of some popular phrases in the context of national security:
  • cyber attack - malicious use of information systems in order to influence the information, systems, processes, actions or decisions of the target without their consent,
  • cyber conflict - a confrontation between two or more parties, where at least one party uses cyber attacks against the other(s),
  • cyber war - a cyber conflict between state actors, where the critical information infrastructure is attacked,
  • cyber terrorism - a cyber conflict where one party is using cyber attacks to cause fear, physical damage, and/or death among the civilian population of the other party.
Note that information collection, an activity usually limited to espionage, intelligence gathering and crime, is not included in the cyber attack definition. [TO DO: better explanation of the concept]

I am sure these definitions will change as my understanding of the topic grows.