Showing posts with label cyber militia. Show all posts
Showing posts with label cyber militia. Show all posts

Wednesday, December 15, 2010

DDoS - a legitimate form of protest?

The cyber attacks against supporters and opponents of Wikileaks have generated a fair bit of debate about whether or not DDoS can be a legitimate form of protest. I tend to side with the "nays" on this one.

Sure, DDoS could be compared to a sit in, but with infinitely lower entry threshold. One does not need to travel anywhere, or actually waste their time "sitting", and very often does not risk dealing with law enforcement - the computer can protest on their behalf all night long. It's more like throwing nails on a freeway and going home.

But my main argument against protest DDoS is that it can then be used for any cause. Attacks against Radio Free Europe? It's cool, they just protestin'! As can be seen from the Wikileaks affair, both sides in there are using cyber attacks to get their message across. Is this truly what we want? I dont like you, so I have the right to DDoS you? I have the right for free speech and the right for making stupid people shut up?

Friday, November 19, 2010

Cyber Security Conference in Georgia

I was in Tbilisi last week and spoke at the Georgian Cyber Security and IT Innovation conference. The first day focused solely on cyber security topics. Agenda and materials are available here. As expected, the 2008 Russia-Georgia war and its cyber component came up in several presentations.

My talk on Volunteers in Cyber Conflict was based on a number of papers I have written on the subject. While I have focused on the offensive (and illegal) hactivism/patriotic hacking so far, I am in the process of switching gears and focusing on the defencive (and official) use of volunteers. For example, the reserve cyber units in US military, the WARP system in UK and the Cyber Defence League in Estonia. I believe there is great merit in harnessing the skills and resources of security specialists and enthusiasts for a constructive purpose.

Friday, October 15, 2010

Hacker Halted in Miami

I have been in Miami this week, attending the Hacker Halted Conference. Among the workshops that closed the conference today was the Cyber Security Forum Initiative (CSFI) event, where I got to speak about my research (Volunteers in Cyber Conflicts) next to some other interesting characters, like Roger Kuhn and Jeff Bardin. The talk went well, which is a good thing as it is based on an early prototype of my upcoming PhD thesis.

Update: Paul de Souza's post on the CSFI workshop

Monday, July 5, 2010

Another paper published at ECIW

Last week I was at the 9th European Conference on Information Warfare and Security (ECIW 2010) in Thessaloniki, Greece. This is an academic conference, so most of the attendants were also speakers. The information about the proceedings is available here. I hosted the Cyber Conflict mini-track, which consisted of five papers, including mine:

Ottis, R. (2010) Proactive Defence Tactics Against On-Line Cyber Militia. In Proceedings of the 9th European Conference on Information Warfare and Security, Thessaloniki, Greece, 01-02 July. Reading: Academic Publishing Limited, p 233-237. [link]

The main idea of my paper was that in order to defeat a loose network of cyber vigilantes (on-line cyber militia), one can potentially adopt a more proactive stance and use various (offensive) information operations. It should be noted that this is only a theoretical exercise, as some of the options considered may be against the laws and regulations of the host country.

If you have any feedback or suggestions for reading material in the similar vein, please let me know.

Monday, June 14, 2010

Two papers published at C6

I have updated the publications tab with two papers that were published in the proceedings of the upcoming Conference on Cyber Conflict. As is always the case, by the time they went to print I already had some ideas for changing them. Nevertheless, here they are:
  • Lorents, P. and Ottis, R. (2010) Knowledge Based Framework for Cyber Weapons and Conflict. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 129-142.[link]
  • Ottis, R. (2010) From Pitch Forks to Laptops: Volunteers in Cyber Conflicts. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 97-109. [link]
Any comments and feedback welcome.

Friday, May 14, 2010

Baltic Cyber Shield 2010

I spent the first two days of this week engaged in a multinational distributed cyber defence exercise - Baltic Cyber Shield. It was a tech-centric exercise organized by CCD COE and various Swedish defence organizations, particularly the Swedish National Defence College and the Swedish Defence Research Agency. The Estonian Cyber Defence League, a volunteer cyber defence organization, also provided invaluable support. All in all, about 100 people from about 10 countries took part in the exercise.

According to the scenario, six blue teams (3 Swedish, a Latvian, a Lithuanian and a NATO team) of up to ten experts were deployed to take over compromised and poorly set up networks targeted by an extremist environmental group's "cyber warfare division" (multi-national red team). The exercise was distributed, so the participants performed the defence and attack missions remotely.

I must say it was a lot of fun. As expected, there were all kinds of issues, but in the end, everything went quite well. The attackers were able to maintain a steady push, compromising well over a hundred systems over the two days, while the defenders tried different strategies to maintain their services while locking the attackers out of their networks.

As a member of the referee team, I got another good experience, and learned some things that can contribute to my PhD research (the attackers were, after all, supposedly a non-government volunteer group who engaged in politically motivated cyber attacks). Congratulations are in order to the members of Blue 5, a Swedish expert team, who won the exercise.

Next week I will be at the SMi's Cyber Defence Conference in Tallinn.

Thursday, January 28, 2010

Jeffrey Carr Inside Cyber Warfare

Jeffrey Carr's new book, Inside Cyber Warfare came out late last year and is an interesting resource for the cyber researcher. If you are familiar with the Grey Goose Reports I and II and have been reading Jeff's blog at IntelFusion, then a lot of the material will look familiar.

The book covers a lot of ground (pretty much all of it), but this is also its weakness. The principle of universality vs effectiveness states that there can't be both at the same time. Therefore, the book feels at times like a train ride - interesting scenery is rushing by, but you do not catch the full richness of it, just glimpses.

I found the Grey Goose Reports an interesting read, although somewhat rough around the edges. Granted, they were done under serious time constraints and included input from many people, so it was to be expected. I'm glad to see that Jeff has polished away a lot of that.

Jeff goes through a host of examples of recent cyber conflicts, specifically looking at potential state-sponsored events like the Russia-Georgia (cyber) conflict of 2008. He includes a lot of small facts and stories that may not have caught your attention before, so it pays to read the book instead of just scanning over it quickly.

On the other hand, however, I find that the biggest problem with Grey Goose and this book is that in the end, they are just stories with a plausible explanation. To me, there is still no concrete PROOF of state involvement in Georgia 2008, even though there are a thousand circumstantial evidence arrows pointing at it. So we are stuck with the attribution question, again.

This brings me back to my own research - understanding "independent" online cyber militia and looking for ways to deal with the phenomenon. I'll have a post on some potential tactics soon.

As I said above, the book definitely contains a lot of interesting information and may provide you with the interesting fact or angle that was missing, if you are researching cyber conflicts. So, if you get the chance, read it.

Monday, January 11, 2010

First post

...of 2010. This year has actually started with a flurry of activity and I seem to be quite busy for at least the next five weeks or so. I guess this is good, as most of the activity is centered around my research.

This year will be important for my PhD studies. I plan to research and publish some core pieces of my thesis in preparation for the write-up and defense in 2011. Specifically, I want to address the structure, capabilities and weaknesses of volunteer cyber militia. Tackling those issues will not be easy, requiring me to revisit some concepts that I haven't looked at in years.

Monday, December 28, 2009

Milblogging, ad-hoc cyber militia and science

I read an paper by Sean Lawson, about the debate and conflict [pdf] between the US Army and the Milblogging community (servicemembers who blog about their experience in the military, including combat reports).

While the article focuses on the blogging servicemen, we should also make a note that the same tool is available to everyone. This spontaneous "online, volunteer public affairs or information operations corps" would be a perfect rallying tool for an ad-hoc cyber militia. Consider, that there are numerous blogs on controversial issues (including pro and contra sides for each), which typically have a steady readership, even if it is small. All it takes is for the blogger to post a rally cry (and some instructions) and an ad-hoc cyber militia is formed and ready for action.

Members of such a group are pre(self)selected and have strong feelings about the issue. Therefore, they probably need very little persuasion to join up.

If you have the time and the interest, there is also a link to his Doctoral Dissertation on his web site. It gives a good overview of the development of the science of war, explaining the heritage of terms such as OODA loop and netcentric warfare, as well as providing an overview of the relation between US military and the scientific community. Interesting to read. Nearly 400 pages, however, so be warned.

Tuesday, December 22, 2009

Russia and Cyber Attacks

A colleague pointed me to an article in the Baltic Security and Defence Review, an annual publication of the Baltic Defence College (international staff college for military officers at OF3-OF5 ranks). MAJ William Ashmore (US Army) writes an overview of recent cyber conflicts with Russia, titled "Impact of Alleged Russian Cyber Attacks" [pdf].

While the article covers a lot of ground it seems that he is not a subject matter expert in cyber conflicts. The quality of the references is relatively weak (mostly public news media) and there are a few simple errors. On the other hand, he has done a fairly broad background check for the legal/doctrinal work done at OSCE, UN etc.

He provides an overview of events in Estonia 2007 and Georgia 2008 among others, and a summary of NATO's activities in setting up cyber defence. He spends some time on Herman Simm's case (highly placed spy for Russians in Estonian MoD, caught 2008), although to me his arguments there seem a bit weak.

He reviews the national and international responses/comments to the Russian cyber campaigns, including potential attribution. There is also a fairly interesting chapter about future trends in Russian cyber activities (including Dr Panarin's recommendations). I think he may be onto something when he says that in Russia, cyber is mostly seen as an offensive capability.

With the US primarily focused on the Chinese cyber threat, the Russian (and other) cyber studies remain in the background. Therefore, it is a refreshing piece of reading, regardless of some issues with depth or quality. As always, read the article for full info.

Happy holidays!

Friday, December 11, 2009

Abstract on capabilities of novice cyber warriors

Below is an abstract paper idea that I am currently developing. The main idea is to look at the potential actions available for low level attackers - people who have no special training or experience with cyber attacks. The working title is "From pitch forks to laptops: volunteers in cyber conflicts". I would be grateful for any useful references on this topic.

Abstract:

The capability for organized violence in the international setting has normally been the domain of nation states. Cyberspace, however, provides an international arena where almost anyone has the power to attack any target at will. While most of these attacks have little effect, there is often little disincentive to using them, as attribution of cyber attacks and prosecution of attackers is still the exception, instead of the norm. Thus, the 21st century farmers with pitch forks or cyber militia become more than a local force and, if organized well enough, can mount an offensive cyber campaign that could damage the economy or social order of a nation state on the other side of the planet.

In order to test this claim, I will first consider the potential threat from the Internet users who are untrained in hacking techniques and who have very limited resources. In general, there are two types of activities that are open for such persons: supporting the cyber campaign by providing resources, cover and training (among other things) and launching cyber attacks as part of the cyber campaign. It is important to note that the support activities may be more significant than fighting in a People’s War type conflict.

I will proceed by considering the potential threat from advanced hackers or hacker organizations. While there have been many well publicized hactivism campaigns, there are few examples of serious cyber strikes that target critical systems. Therefore, most of this analysis is theoretical, drawing on past examples as appropriate.

In the end, national security planners must face this threat and develop a strategy to counter it. I include some proposals for dealing with the cyber militia problem and discuss the potential merits and pitfalls of farmers with laptops engaging in cyber campaigns both on their own as well as in the service of a state.

Monday, December 7, 2009

Review: Jose Nazario on Political DDoS Attacks

Time for another review. This time it is Jose Nazario's CWCON paper called "Politically Motivated Denial of Service Attacks." He is looking at DDoS as one of the more visible and popular cyber attack forms and is limiting his sample to the ones with a political motivation (vs the standard criminal motivation - money).

NOTE: The final published version of this paper was accepted after the conference so it includes some more recent examples.

His research is based on data from three sources: ATLAS project at Arbor Networks (basically, ATLAS collects data from sensors to provide an overview of the more visible cyber campaigns), infiltrated botnet C&C servers and border gateway protocol (BGP) routing data.

He starts out with a little overview of major political DDoS campaigns of the past, covering the following events:
  • 2001 Hainan Island incident
  • 2007 Estonia campaign
  • 2008 China v CNN campaign
  • 2008 Georgia campaign
  • 2008 Burma
  • 2007 elections in Russia
  • 2008 Radio Free Europe campaign
  • 2008 anti-NATO campaign in Ukraine
  • 2009 MSK forum DDoS in Kazakhstan
  • 2008 DDoS-censoring of Russian opposition websites
  • 2009 Israel v Gaza/Hamas
  • 2009 Kyrgyzstan - a false positive?
  • 2008 Kommersant DDoS
  • 2009 Kazakhstan opposition sites under DDoS
  • 2009 South Korean/US campaign
It is noticeable how most of these events are known by the target only. In history, conflicts are usually named after both/all participants or at least the participants are known. In cyber conflicts, however, it seems to be the norm that the aggressor remains anonymous. Even if all the circumstantial evidence and opinions point against one entity, rarely is there enough proof to attribute the attack in court.

He continues to describe the attacker type that seem to be behind most of the attacks listed. In general, the attackers are "classic right-wing" supporters of the government and targeting internal or external opposition. He also writes about using propaganda to recruit supporters for a cyber campaign and then training them online - a basic ad-hoc cyber militia. What the militia cannot achieve with finesse and expertise, they make up in numbers (DDoS).

He points out that the classical goals for such attacks are to punish the target, or to show dissent, or to censor the target (especially true for attacks against news outlets and opposition parties). He brings examples of partial attribution: Nashi youth group in Russia, the Chinese Honker Union and StopGeorgia.ru. Note that in all these cases the attackers made the claim - nothing has been proven in court (as far as I know).

He reviews some broad responses to the cyber campaigns listed and finishes with recommendations:
  • harness public support and international cooperation
  • deploy available commercial tools
  • be open to commercial offers to help
  • develop a more efficient decision making process
  • delegate authority
  • consensus is sometimes not necessary
In conclusion, he also points out that we need to study guerilla and asymmetric warfare in order to succeed on the cyber battlefield.

The paper has numerous examples from recent years and thus gives a good overview of the extent of the problem. However, the examples have different level of detail (often too vague) to be of much help on researching a specific case. I would have expected a more detailed analysis of a limited number of campaigns. As always, read the paper for full value.

Wednesday, October 28, 2009

Centralized vs de-centralized cyber campaigns

The previous post got me thinking about some of the key tenets of the Chinese approach: the cyber campaign must be centrally controlled, executed by organic forces and have a tightly focused target.

Obviously, this centralized approach provides good command and control opportunities. It also limits collateral damage and I guess, most important of all, eliminates possible interference from volunteer actions (such as someone taking control of one of the key entry points to the enemy network and shutting you out). Historical examples also seem to show that volunteers are more likely to engage visible targets (web sites etc) that have little or no tactical value.

On the other hand, NOT using the volunteers (the de-centralized approach) denies you the use of a potential resource. Odds are that if a country has a developed patriotic hacking community, they will take part in the conflict one way or the other, so you might as well try to guide them to be useful.

The second argument for using volunteers is psychological. It displays public support to your campaign, potentially reinforcing the mindset in other sectors of the society. It also brings in small but visible IW victories, as press covers the "citizen campaign" against the opposing side.

The third argument would be the Fog of War. The patriotic hacking community can provide the smoke screen necessary to execute the important strikes against key nodes. Remember, if the plan is to concentrate your attacks in time and (network) space, they will become immediately visible. However, if you have attacks of various severity levels happening all the time the enemy may not recognize the significance of the critical attack until it is too late.

The fourth argument is that patriotic hackers can "prep the battlefield" before the hostilities commence, provide retaliatory attacks after the hostilities, target third parties and civilian or commercial targets while the state can deny any involvement. This supposes that there is an established patriotic hacker community in place, so the world does not necessarily consider there to be a direct link to the specific conflict.

Finally, political attacks by civilians as part of a larger conflict have no clear regulation and few legal precedents. If the host country is not willing to cooperate with the criminal investigation (not likely in a time of war) the attackers will remain anonymous and protected, while the state still has "formal" deniability.

However, as I have noted before, there is a price for accepting patriotic hacking in a state. Most pressing are the long term rise in cyber crime and the potential that they act against the state. On the other hand, if the decision has been made or if there is already a well-established community in place, one should consider the possible uses of this force. Because whether you plan for (with) them or not, they will participate in the fight.

Thursday, September 17, 2009

Article in Akadeemia

One of my articles (Conflicts in the information age - cyber attacks and the citizen society) was published in the Estonian academic journal called Akadeemia (2009, nr 9, Special Edition on War and Peace) a few days ago.

In the article, I revisit the own forces/hired guns/volunteers categories and focus on the latter. I try to explain some interesting aspects of using volunteers, such as the parallel rise in crime and the need to "exercise" the volunteers regularly. I also try to look at why ordinary people from the street may become belligerents in cyber space, specifically addressing radicalization through Internet and formulation of cyber tribes. I end the article with a positive note, that volunteers can be harnessed for good, as well as evil. Consider, for example, defensive volunteer organizations, such as the WARP network in UK. In addition, I touch upon the personal responsibility of today's netizens - we all have a part to play in developing a safer cyber society.

Thursday, July 9, 2009

ECIW 09 in Lisbon

I just got back from Lisbon and the 8th European Conference on Information Warfare and Security. This annual conference brings together 60-100 academics from across the world to present and discuss their research during the two-day event.

A paper that I wrote for the conference in the winter got published in the proceedings (see publications). The main idea of the paper is that there are three general ways to create an offensive capability in cyberspace:
  • establish a unit/agency for that mission ("conventional" own forces approach)
  • outsource the problem by hiring digital mercenaries, cyber criminals and the like
  • develop or hijack a volunteer force, or a cyber militia, to attack convenient targets with little or no attribution for the state.
In reality, a combination of two or three is potentially more powerful than any single approach.

While thinking about the last two approaches, I came to some interesting conclusions. First, if a government uses volunteers or mercenaries to conduct an "illegal", or at least unethical, campaign against its political enemies, then there will be a rise in (cyber) crime in the state. This happens because the government cannot alienate the "friendly" attackers by arresting them for non-political crimes (such as sending spam, stealing credit card information or DDoSing commercial sites for blackmail). This also explains why cyber criminals seem to flourish in some states that also seem to have an aggressive stance in cyberspace.

The second idea was that in case of volunteer forces, the government would have to "exercise" these forces once or twice a year, in order to keep them "on mission". A volunteer offensive cyber militia will likely disband for more interesting pursuits, if they are not called to arms for several years. This means that the state would have to provide a steady stream of external or internal "enemies" to keep the militia occupied.

Thursday, June 25, 2009

Cyber attacks in Estonia, 2007

My first academic paper was published last year in the Proceedings of the 7th European Conference on Information Warfare and Security, Plymouth. An annual event, this conference brings together people with very different perspectives on information warfare, from psychological to cyber.

My paper was titled Analysis of the 2007 Cyber Attacks Against Estonia from the Information Warfare Perspective (see Publications for more information). In the paper, I analyze the Estonian case by posing three hypotheses and then arguing for and against each of them to find if any of them are plausible.

The first hypothesis is that the event was a Russian information operation, the second is that the event was a false flag operation to discredit Russia, and the last one is that it was a spontaneous grass roots response to Estonian government policy.

The false flag hypothesis is not plausible, considering the amount of circumstantial evidence against Russia (and only Russia) while the Russian government made no effort to stop the attacks or expose the attackers.

A true grass roots movement is also not plausible, as at the very least, passive government support (Russian authorities refusing legal cooperation) seems evident.
NOTE: Interestingly enough, a member of the Russian parliament later claimed that one of his aides was actively involved in the cyber campaign. This fact (?) emerged after publishing, so it is not included in the analysis.

That leaves us with the state information operation scenario. Specifically, it matches a Chinese concept of People's War, where people fight with their own resources and organization, for the interests of the state. That explains hostile rhetoric by politicians, the relatively high number of people involved, as well as lack of interest by the state to identify the attackers.

Unfortunately, the analysis can not attribute the attacks to any specific person, organization, or state. Instead, I find that of the three hypotheses considered, only the information operation scenario was plausible.

In hindsight, I do not consider it a very good paper, as it provides no definitive answer and devotes more detailed analysis to one of the hypotheses. In addition, I had just started my research on the topic, so my understanding of concepts like cyber militias and People's War was still very tentative. On the other hand, even though I notice many things I would write differently today, the conclusion would still remain the same.

Origins of my research interests

In the spring of 2007 I was just finishing my Master's in TUT when the cyber attacks against Estonia started. Since then I have tried to understand these attacks in particular and political large scale cyber attacks in general as part of my PhD studies.

I have found that the Internet, while being the great information equalizer for the common man, is also a convenient information weapon for the common man. In case of recent conflicts we hear with increasing frequency about their prelude, reflection, and aftermath in cyberspace. More likely than not, these attacks are not committed by state run organizations, but people who share or oppose the view of at least one side of the conflict.

While state sponsored attacks undoubtedly exist, I believe they currently keep a much lower profile and are usually in the role of intelligence/counter intelligence operations. There is little or no credible information on state sponsored attacks to harm or disrupt the opponent's systems, even though many nations are actively building such capabilities. It should follow that the next time that two technologically advanced states fight a full conventional war (not a border skirmish), cyber attacks will be used. Until then, however, we can merely speculate and simulate.

Therefore, even though I am also interested in state level cyber conflicts, I mainly focus my research on sub-state actors, as they are more visible and relevant in today's conflicts. I am interested in how they recruit, organize, and fight, as well as what potential effect they can have on their targets.