Wednesday, June 12, 2013
Monday, October 8, 2012
CFP for CyCon 2013 is out
Thursday, August 2, 2012
Time to climb a new mountain - Part II
The current plan is to split my time between teaching and researching in Tallinn University of Technology (Estonia) and University of Jyväskylä (Finland), with 25% of my time left for various projects that I can pursue in self-employed mode (ideas welcome). The switch is going to happen in the next few months and should be complete by the end of the year.
I will still focus on cyber conflict and national cyber security research, so that is not going to change. However, I hope to tie my current research with a different field or approach, such as AI or situational awareness, in order to cover interesting new ground. I am not set on a topic yet and will explore cooperation opportunities as they develop.
Wednesday, May 2, 2012
Time to climb a new mountain
I feel I am ready to explore cyber security and cyber conflict from new angles. I love teaching, so an academic approach is definitely a possibility. It would also be interesting to gain experience from private sector perspective. Most likely I will try to combine various options to get the "perfect blend" for the time being. By the look of things I will make my decision later this month.
I can't say for sure what road I will follow, but one thing I definitely want to do is to revive this blog. I have been very busy (personally, academically, professionally) for the past couple of years and, sadly, this blog was one of the easiest things to put on hold while I got things sorted out. Yet, people still seem to find it every once in a while, as the visit counter passed ten thousand last month. This adds to my motivation to get things going again.
Time to re-invent myself...
Thursday, November 10, 2011
CFP for CyCon 2012
Mark your calendars - I hope to see you in Tallinn in June!
Wednesday, December 15, 2010
DDoS - a legitimate form of protest?
Sure, DDoS could be compared to a sit in, but with infinitely lower entry threshold. One does not need to travel anywhere, or actually waste their time "sitting", and very often does not risk dealing with law enforcement - the computer can protest on their behalf all night long. It's more like throwing nails on a freeway and going home.
But my main argument against protest DDoS is that it can then be used for any cause. Attacks against Radio Free Europe? It's cool, they just protestin'! As can be seen from the Wikileaks affair, both sides in there are using cyber attacks to get their message across. Is this truly what we want? I dont like you, so I have the right to DDoS you? I have the right for free speech and the right for making stupid people shut up?
Friday, November 19, 2010
Cyber Security Conference in Georgia
My talk on Volunteers in Cyber Conflict was based on a number of papers I have written on the subject. While I have focused on the offensive (and illegal) hactivism/patriotic hacking so far, I am in the process of switching gears and focusing on the defencive (and official) use of volunteers. For example, the reserve cyber units in US military, the WARP system in UK and the Cyber Defence League in Estonia. I believe there is great merit in harnessing the skills and resources of security specialists and enthusiasts for a constructive purpose.
Monday, October 25, 2010
CFP: International Conference on Cyber Conflict
As for the CFP [pdf]:
In 2011 the conference will focus on the combination of defensive and offensive aspects of Cyber Forces and will combine different views on cyber defense and operations in the current and envisaged threat environments. All this shall not be limited to military perspective.
Legal, strategic and technical submissions are welcome on equal grounds.
Researchers and practicians are encouraged to submit papers covering novel and scientifically significant practical works related to 2011’s topics via our web portal. Accepted papers - after passing the peer-review - will be published in the conference proceedings provided in hard cover and digitally though IEEE Xplore.
Paper submission deadline is 20 JAN 2011.
Wednesday, October 20, 2010
Article in FutureGov Magazine
The article is available in the August-September issue [large pdf!], on pages 70-72.
Monday, September 6, 2010
Interview explosion
Thursday, August 26, 2010
CFP: ECIW 2011
Please feel free to circulate this CFP:
This is a call for papers for 10th European Conference on Information Warfare and Security being held at The Institute of Cybernetics at the Tallinn University of Technology, Tallinn, Estonia on the 7-8 July 2011.
The 10th European Conference on Information Warfare and Security (ECIW) is an opportunity for academics, practitioners and consultants from Europe and elsewhere who are involved in the study, management, development and implementation of systems and concepts to combat information warfare or to improve information systems security to come together and exchange ideas. There are several strong strands of research and interest that are developing in the area including the understanding of threats and risks to information systems, the development of a strong security culture, as well as incident detection and post incident investigation. This conference is continuing to establish itself as a key event for individuals working in the field from around the world.
Please consider submitting to this conference. We are interested in the entire range of concepts from theory to practice, including case studies, works-in-progress, and conceptual explorations. The conference committee welcomes contributions on a wide range of topics using a range of scholarly approaches including theoretical and empirical papers employing qualitative, quantitative and critical methods.
Case studies and work-in-progress/posters are welcomed approaches. PhD Research, proposals for roundtable discussions, non-academic contributions and product demonstrations based on the main themes are also invited.
You can find calls for papers for these tracks at:
http://academic-conferences.org/eciw/eciw2011/eciw11-call-papers.htm
The ECIW conference proceedings are:
· listed in the Thomson Reuters ISI Index to Scientific and Technical Proceedings (ISTP/ISI Proceedings)
· listed in the Thomson Reuters ISI Index to Social Sciences & Humanities Proceedings (ISSHP)
· listed in the Thomson Reuters ISI Index to Social Sciences & Humanities Proceedings (ISSHP/ISI Proceedings).
· indexed by the Institution of Engineering and Technology in the UK.
Conference publications are submitted for accreditation on publication. Please note that depending on the accreditation body, this process can take several months.
Please feel free to circulate this message to any colleagues or contacts you think may be interested.
Monday, July 5, 2010
Another paper published at ECIW
Ottis, R. (2010) Proactive Defence Tactics Against On-Line Cyber Militia. In Proceedings of the 9th European Conference on Information Warfare and Security, Thessaloniki, Greece, 01-02 July. Reading: Academic Publishing Limited, p 233-237. [link]
The main idea of my paper was that in order to defeat a loose network of cyber vigilantes (on-line cyber militia), one can potentially adopt a more proactive stance and use various (offensive) information operations. It should be noted that this is only a theoretical exercise, as some of the options considered may be against the laws and regulations of the host country.
If you have any feedback or suggestions for reading material in the similar vein, please let me know.
Monday, June 14, 2010
Two papers published at C6
- Lorents, P. and Ottis, R. (2010) Knowledge Based Framework for Cyber Weapons and Conflict. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 129-142.[link]
- Ottis, R. (2010) From Pitch Forks to Laptops: Volunteers in Cyber Conflicts. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 97-109. [link]
Wednesday, June 2, 2010
There are those who know...
The issue is about people with access to classified material making authoritative statements, because they "know how things really are". However, since what they know and how they know it is classified, they will not follow through with argumentation. A person who has no access to the classified material has no way of verifying the correctness of the claim, so he has to take it on faith.
My short stance on this is - if it is classified, shut up about it. One, it is not helpful for the open debate. Two, classified is not equivalent to correct. Three, "classified" may refer to something that does not exist.
Friday, May 21, 2010
CFP: IEEE S&P - Cyber Conflict
IEEE SECURITY & PRIVACY CALL FOR PAPERS
Special Issue on Cyber Conflict
(Sept./Oct. 2011 issue)
Deadline for abstract submissions: 15 June 2010
Full papers due: 1 October 2010
Guest editors:
Thomas A. Berson (Anagram Laboratories)
Dorothy E. Denning (Naval Postgraduate School)
In 2007, Estonia was the target of massive denial-of-service attacks over the controversial relocation of a Soviet-era war memorial. Although the attacks leveraged botnets scattered all over the world, they were believed to originate in Russia or with persons of Russian descent. The following year, Georgia was the victim of similar attacks in conjunction with a ground confrontation with Russia. Meanwhile, large-scale cyber espionage operations into US military networks, computers belonging to the Dalai Lama and the government of India, critical infrastructures, major companies including Google, and various other targets have been traced back to China.
These incidents offer a glimpse into a future where cyberspace plays a key role in conflicts involving either or both nation-states and non-state actors. Over a hundred countries are reportedly developing capabilities for cyber espionage and cyber attack – capabilities that many individual hackers, criminals, and spies already possess and freely use.
These developments have raised numerous questions, including: What constitutes an act of war in cyberspace? How does the law of armed conflict apply to cyber attacks? Do we need international treaties governing cyber conflict? Can cyber attacks be deterred or pre-empted? Can we detect and analyze cyber attacks with sufficient speed and certainty as to limit their damages and determine attribution? Should states be responsible for attacks conducted by their citizens or using computers in their territory? What are the security implications of cyber conflict? What are the privacy implications?
IEEE Security & Privacy magazine seeks papers on all aspects of cyber conflict, including technology, policy, legal, ethical, operational, and strategic issues, especially as they relate to security and privacy. Papers can provide a broad overview or more in-depth coverage of a specific topic, country, or case study.
Authors should submit abstracts of 100-500 words as plain text or a .pdf file to dedennin@nps.edu by June 15. Authors whose abstracts fall within the scope of the issue will then be invited to submit full papers to the journal for peer-review. Papers will be due October 1 and should not exceed 6,000 words. The writing should be down-to-earth, practical, and original. Articles that are accepted for publication will be professionally copyedited according to the IEEE Computer Society style guide.
Visit www.computer.org/portal/pages/security /author.xml for information about the magazine, including article guidelines.
Friday, May 14, 2010
Hostage Deterrence
While I agree that in the conventional sense, cyberspace does not support the concept of deterrence very well (lack of attribution), I think there is a special case where it might work. Consider a situation, where Nation A develops a credible offensive cyber capability and announces a policy that regardless of attribution, if a critical cyber attack were launched against it, it would automatically launch a critical cyber attack against Nation(s) B(,C,D, ...). In that highly controversial case, Nation A would actually have a deterrent against the other Nation(s) in question.
In other words, Nation B is effectively deterred from launching a critical cyber attack against Nation A.
Obviously, the weak point here is that any Nation X may do a false flag or anonymous attack in order to make Nation A to attack Nation B without cause. That is why it is not normal deterrence, but something you might call "hostage deterrence". Has anyone come across such a thing before, either in theory or in practice?
Baltic Cyber Shield 2010
According to the scenario, six blue teams (3 Swedish, a Latvian, a Lithuanian and a NATO team) of up to ten experts were deployed to take over compromised and poorly set up networks targeted by an extremist environmental group's "cyber warfare division" (multi-national red team). The exercise was distributed, so the participants performed the defence and attack missions remotely.
I must say it was a lot of fun. As expected, there were all kinds of issues, but in the end, everything went quite well. The attackers were able to maintain a steady push, compromising well over a hundred systems over the two days, while the defenders tried different strategies to maintain their services while locking the attackers out of their networks.
As a member of the referee team, I got another good experience, and learned some things that can contribute to my PhD research (the attackers were, after all, supposedly a non-government volunteer group who engaged in politically motivated cyber attacks). Congratulations are in order to the members of Blue 5, a Swedish expert team, who won the exercise.
Next week I will be at the SMi's Cyber Defence Conference in Tallinn.
Monday, May 3, 2010
The Law of Armed Conflict in Cyberspace
This work is very important, as there are no laws specifically drafted for conflicts in cyberspace or suitable court cases to analyze (to my knowledge). To bridge the gap between the laws written in the (arguably) pre-cyber era and the events that we witness and theorize about today, one needs to make good use of one's imagination. This was my role, I guess - I was one of the "cyber experts" who was tasked to come up with examples and analogies on the spot, while explaining some basic concepts from computer science, informatics, physics, etc. to a crowd who normally deal with the legal issues in the realm of things that kill people and blow stuff up.
I must say it was a wonderful learning experience and I look forward to the next meeting. It also clearly identified some issues that I have not seen discussed (recognized?) by us theoretical/conceptual researchers, who approach the cyber conflict from the de-facto viewpoint (what the technology allows to do and what is actually being done in cyberspace). While we may say that the de-jure viewpoint is outdated and not realistic, we cannot argue that it is, in fact, the law.
Some issues that I personally found interesting (contrasted with the cyber-centric viewpoint) were:
- the legal concepts of armed attack, use of (armed) force and armed conflict in cyberspace, and
- the legal status of non-military personnel, who perform cyber attacks during wartime.
Friday, March 26, 2010
C6 preliminary agenda published
Thursday, January 28, 2010
Jeffrey Carr Inside Cyber Warfare
The book covers a lot of ground (pretty much all of it), but this is also its weakness. The principle of universality vs effectiveness states that there can't be both at the same time. Therefore, the book feels at times like a train ride - interesting scenery is rushing by, but you do not catch the full richness of it, just glimpses.
I found the Grey Goose Reports an interesting read, although somewhat rough around the edges. Granted, they were done under serious time constraints and included input from many people, so it was to be expected. I'm glad to see that Jeff has polished away a lot of that.
Jeff goes through a host of examples of recent cyber conflicts, specifically looking at potential state-sponsored events like the Russia-Georgia (cyber) conflict of 2008. He includes a lot of small facts and stories that may not have caught your attention before, so it pays to read the book instead of just scanning over it quickly.
On the other hand, however, I find that the biggest problem with Grey Goose and this book is that in the end, they are just stories with a plausible explanation. To me, there is still no concrete PROOF of state involvement in Georgia 2008, even though there are a thousand circumstantial evidence arrows pointing at it. So we are stuck with the attribution question, again.
This brings me back to my own research - understanding "independent" online cyber militia and looking for ways to deal with the phenomenon. I'll have a post on some potential tactics soon.
As I said above, the book definitely contains a lot of interesting information and may provide you with the interesting fact or angle that was missing, if you are researching cyber conflicts. So, if you get the chance, read it.