Showing posts with label cyber defence. Show all posts
Showing posts with label cyber defence. Show all posts

Friday, November 19, 2010

Cyber Security Conference in Georgia

I was in Tbilisi last week and spoke at the Georgian Cyber Security and IT Innovation conference. The first day focused solely on cyber security topics. Agenda and materials are available here. As expected, the 2008 Russia-Georgia war and its cyber component came up in several presentations.

My talk on Volunteers in Cyber Conflict was based on a number of papers I have written on the subject. While I have focused on the offensive (and illegal) hactivism/patriotic hacking so far, I am in the process of switching gears and focusing on the defencive (and official) use of volunteers. For example, the reserve cyber units in US military, the WARP system in UK and the Cyber Defence League in Estonia. I believe there is great merit in harnessing the skills and resources of security specialists and enthusiasts for a constructive purpose.

Wednesday, September 2, 2009

Asymmetry in Cyberspace

The other day I started to ponder about what constitutes a fight in cyberspace. I find that it is fundamentally different from what could be termed conventional fighting (in a military sense) - tank engagements, infantry ambushes etc.

The issue is really about the asymmetry between attackers and defenders. A cyber attacker needs to find just one opening, while the defender needs to cover every conceivable (and inconceivable) weakness. This is a critical mismatch in terms of resources.

Another asymmetric aspect is the fact that in a "cyber battle", attackers rarely present a target themselves, because they are difficult to identify. Even if the attack can be attributed, there is little that can be done with a cyber retaliation. An attacker does not "own" critical technical infrastructure, which could be taken out. They just use the public communication infrastructure as a service provider and a "human shield".

In a potential two-way cyber engagement this works both ways. A practical example would be to use red teams to knock out critical infrastructure targets on the other side, while "ignoring" the attackers from the other side and relying on the quality of one's defence.

Tuesday, August 25, 2009

Blog reset

I am back from my summer hiatus. As promised, I will continue to throw my ideas and thoughts in here.

I have often found it interesting how some people fear the offensive side of cyber. 'Defense only' is the politically correct way of putting things, even though it is pure nonsense. Skills and knowledge to be a good defender is largely dual-use.

Look at it this way. Imagine briefing a general: "Sir, our defensive infantry brigades have dug in around the city, we can now deploy our offensive infantry regiment to attack the enemy." True, some units are better equipped and trained for offensive or defensive missions, but that does not mean that they lack the capability to do both.