Showing posts with label cyber war. Show all posts
Showing posts with label cyber war. Show all posts

Friday, November 19, 2010

Cyber Security Conference in Georgia

I was in Tbilisi last week and spoke at the Georgian Cyber Security and IT Innovation conference. The first day focused solely on cyber security topics. Agenda and materials are available here. As expected, the 2008 Russia-Georgia war and its cyber component came up in several presentations.

My talk on Volunteers in Cyber Conflict was based on a number of papers I have written on the subject. While I have focused on the offensive (and illegal) hactivism/patriotic hacking so far, I am in the process of switching gears and focusing on the defencive (and official) use of volunteers. For example, the reserve cyber units in US military, the WARP system in UK and the Cyber Defence League in Estonia. I believe there is great merit in harnessing the skills and resources of security specialists and enthusiasts for a constructive purpose.

Monday, May 3, 2010

The Law of Armed Conflict in Cyberspace

Last week I spent three days with a group of law experts, who are trying to figure out how to interpret the current laws of armed conflict (LOAC) for cyberspace. The group is headed by Mike Schmitt, and includes many other heavyweights like Derek Jinks, Ken Watkins, Tom Wingfield and Bill Boothby, just to name a few.

This work is very important, as there are no laws specifically drafted for conflicts in cyberspace or suitable court cases to analyze (to my knowledge). To bridge the gap between the laws written in the (arguably) pre-cyber era and the events that we witness and theorize about today, one needs to make good use of one's imagination. This was my role, I guess - I was one of the "cyber experts" who was tasked to come up with examples and analogies on the spot, while explaining some basic concepts from computer science, informatics, physics, etc. to a crowd who normally deal with the legal issues in the realm of things that kill people and blow stuff up.

I must say it was a wonderful learning experience and I look forward to the next meeting. It also clearly identified some issues that I have not seen discussed (recognized?) by us theoretical/conceptual researchers, who approach the cyber conflict from the de-facto viewpoint (what the technology allows to do and what is actually being done in cyberspace). While we may say that the de-jure viewpoint is outdated and not realistic, we cannot argue that it is, in fact, the law.

Some issues that I personally found interesting (contrasted with the cyber-centric viewpoint) were:
  • the legal concepts of armed attack, use of (armed) force and armed conflict in cyberspace, and
  • the legal status of non-military personnel, who perform cyber attacks during wartime.
While this work is still in its infancy, I hope the resulting manual will settle some of the speculative cyber warfare discussions of today.

Wednesday, March 31, 2010

Georgia 2008 and Cyber Neutrality

I happened across an article [pdf] about neutrality in cyberspace by Korns and Kastenberg. In the article, the authors analyze an aspect of the 2008 Georgia cyber conflict that usually receives little attention: the fact that the Georgian government moved some of its online services to other countries during the war. Specifically, the authors worry about what this means to the neutrality of the host countries.

While they raise an interesting question, I do have some issues.

First, there is the question of whether US lost neutral status in the Russia-Georgia war by hosting some services:
"The fact that American IT companies provided assistance to Georgia, a cyber belligerent, apparently without the knowledge or approval of the US government, illustrates what is likely to become a significant policy issue."
Were Georgian websites under attack? Yes, no doubt. Was this a part of the Russian war campaign? Maybe, but at least officially the Russians deny their involvement. Well, if neither belligerent takes responsibility for the attacks, then we can't really refer to Georgia as a "cyber belligerent" (what does this mean, anyway?). We are left with attacks that do not amount to war, but crime or political hactivism, and I am unaware of any international prohibition on cooperating against criminals or hactivists - even on the business level. Besides, blaming Georgia for this decision is similar to arresting the victim of a street mugger, as the only known party in the criminal act.

Then there is the question of the type of aid that was provided to Georgia (citing a Supreme Court decision):
"If the US government establishes a strict position of neutrality, American industry may provide nonmilitary and humanitarian support to a belligerent, but firms are required to halt all commerce that militarily aids a combatant."
I believe this is undiscovered country. Presumably, the drafters of this document kept in mind the physical goods industry, whereas in cyberspace we are mostly concerned with services. Is hosting a government public relations website "commerce that militarily aids a combatant"? I would argue against that, because otherwise US would have to pull the plug on EVERYTHING every time there is a conflict where US remains neutral (although there is a question whether US was truly neutral in this case, as illustrated in the paper).
"Under a traditional international law rubric, to remain neutral in a cyber conflict a nation cannot originate a cyber attack, and it also has to take action to prevent a cyber attack from transiting its Internet nodes."
Since US is one of the leading nations harboring ISPs with questionable practices, and is also home to a large number of malware infected computers (bots in a botnet), then any time you have a large DDoS attack, US is likely to be on the "attack source" list [to be fair, the authors have also covered this aspect]. I consider it quite likely that at least some US-based computers were used against the Georgian sites during the war. If the Russian Federation was behind the attacks, does this mean that US lost its neutrality and became a belligerent? Again, I would say no. It would be great if US could clean up its part of the Internet, though.

The rest of the paper does a quick analysis of several potentially applicable laws and treaties. Again, while I do not agree with all of their conclusions, they have done a very good job of pulling together thought-provoking concepts. I highly recommend reading it.

These are just some first reactions, but I can see that I need to do some deep thinking on the subject.

Reference:
Korns, S.W., Kastenberg, J.E. (2008) "Georgia’s Cyber Left Hook." Parameters: 38.4 : 60-76. U.S. Army War College. Available at: http://www.carlisle.army.mil/usawc/Parameters/08winter/korns.pdf

Tuesday, March 16, 2010

Cyber Warfare a WMD?

Some comments on the BBC story on USCybercom, which I picked up from USCybercom Watch:
"Not everyone is convinced of USCybercom's military value. One US official at the London conference said that if cyber warfare was a WMD it was only a weapon of "mass disruption, not destruction"."
Only, indeed. While I agree that the effect of cyber warfare is more disruptive than destructive, I cannot agree with the implication this quote seems to make. Just because you cannot blow things up with something does not mean that it is not important. ENIGMA, anyone? Actually, the example by Professor Kuehl in the beginning (bomb v cyber op) illustrates the benefit of cyber very well.

Secondly, military value does not equal WMD. Infantry is not considered a WMD, so surely it cannot have military value? Clearly, this is nonsense. However, I am afraid I am doing injustice to the unnamed speaker at the conference, who may have had something entirely different in mind.

Thirdly, let's forget about the whole WMD thing. It overly complicates issues by raising emotions from nothing. Cyber operations can and do happen every day and and we do not see "mass destruction" in the headlines. Yes, in theory, a cyber attack could have global and devastating effects (for example, by creating a cascading failure in the power grid), but this is a fringe case. Most cyber operations would be far more limited in scope, aiming for operational/strategic effects through tactical level cyber operations. And as for battlefield damage, cyber operations are perhaps best viewed as a way to maximise the effects of kinetic/thermic/EM weapons.

Monday, March 8, 2010

On offensive operations in cyberspace

This year started out in full gear for me and it seems that this is the first week where I can take a breath and write down some of my thoughts.

Last week I was invited to give a talk at one of many cyber defence/IA related conferences in Europe. As is often the case, the question of offensive cyber operations came up. It seems that whenever this happens, the automatic (and politically correct) answer is: well, the military can't plan an offensive cyber campaign, because most likely they will not be able to identify the actor behind the incoming cyber attacks (the attribution problem). They are right, counterattacks in cyberspace can be tricky.

However, this misses the point completely. Who says that cyber operations have to be symmetric (targeting only cyber aggressors with cyber ops). There is every reason for the military to plan and prepare offensive cyber operations for various military situations. When a military is deployed to fight someone, then the target should already be identified and is not necessarily limited to cyber operatives.

It makes sense to consider different ways to achieve a military objective: aerial bombardment, naval blockade, precision drone strikes, landing a division of Marines, cutting off C2 with cyber attacks, jamming radio communication with EW, threatening with nukes, etc. In fact, according to the principle of least harm, it is consceivable that the commander should FAVOR cyber attacks over more lethal options, if the end result is the same.

There is no good reason to limit the options of the commanders in the doctrine-writing phase between conflicts. Sure, there are legal issues, attribution issues, collateral damage issues and so on - as is the case with drone strikes, for example. And yet the drones are in the sky today. It just shows that where there is a will, there is also a way.

The only real counterargument for offensive cyber is that we don't want to see it on the battlefield (like nukes, bio and chem). However, clearly this is a Genie that we cannot force back into a bottle. Potential adversaries, both state and non-state are already using cyber attacks on a daily basis. Therefore, it makes sense to include this option in the play book of the commanders of the future.

It should be noted that I am not advocating military use of cyber attacks on a daily basis, but only in conflict situations and against "legal" targets. I am also aware that the whole "legal" issue is far from solved and most likely will not be solved in any reasonable timeframe.

Thursday, January 28, 2010

Jeffrey Carr Inside Cyber Warfare

Jeffrey Carr's new book, Inside Cyber Warfare came out late last year and is an interesting resource for the cyber researcher. If you are familiar with the Grey Goose Reports I and II and have been reading Jeff's blog at IntelFusion, then a lot of the material will look familiar.

The book covers a lot of ground (pretty much all of it), but this is also its weakness. The principle of universality vs effectiveness states that there can't be both at the same time. Therefore, the book feels at times like a train ride - interesting scenery is rushing by, but you do not catch the full richness of it, just glimpses.

I found the Grey Goose Reports an interesting read, although somewhat rough around the edges. Granted, they were done under serious time constraints and included input from many people, so it was to be expected. I'm glad to see that Jeff has polished away a lot of that.

Jeff goes through a host of examples of recent cyber conflicts, specifically looking at potential state-sponsored events like the Russia-Georgia (cyber) conflict of 2008. He includes a lot of small facts and stories that may not have caught your attention before, so it pays to read the book instead of just scanning over it quickly.

On the other hand, however, I find that the biggest problem with Grey Goose and this book is that in the end, they are just stories with a plausible explanation. To me, there is still no concrete PROOF of state involvement in Georgia 2008, even though there are a thousand circumstantial evidence arrows pointing at it. So we are stuck with the attribution question, again.

This brings me back to my own research - understanding "independent" online cyber militia and looking for ways to deal with the phenomenon. I'll have a post on some potential tactics soon.

As I said above, the book definitely contains a lot of interesting information and may provide you with the interesting fact or angle that was missing, if you are researching cyber conflicts. So, if you get the chance, read it.

Thursday, January 21, 2010

The Schmitt analysis, Part II

This is my second post that looks at the legal aspects of cyber conflicts. As Sean pointed out, Schmitt also wrote a piece in 1999 that gives a framework for evaluating whether or not jus ad bellum applies to cyber conflict. The text is available here [pdf]. Note that the last post was about jus in bello and this one is on jus ad bellum, which the author defines as:
"... that body of international law governing the resort to force as an instrument of national policy ..."
... or in other words, when is it ok to go to war. The article limits the scope to CNA between state actors, which is good, because applying the laws of war on non-state actors is always tricky. In the end, however, it needs to be done, because many of the actors in the cyber conflicts of today are definitely not state actors. Schmitt poses two generic scenarios of interest:
"In the first, State A conducts CNA operations against State B with no intention of ever escalating the conflict to the level of armed engagement. The advantages gained through the CNA are ends in themselves. In the second scenario, State A conducts CNA operations in order to prepare the battle space for a conventional attack. The goal is to disorient, disrupt, blind, or mislead State B so as to enhance the likelihood that conventional military operations will prove successful."
He again stumbles on the issue of whether or not CNA constitutes "use of force" if the legal text is interpreted the traditional way. He then brings counterexamples of "lawful" use of force, which require a different analysis approach. Schmitt analyzes the text, looks at the history behind it, and shows how the application of law has evolved over time with court cases. He arrives to the conclusion that in the end, what matter are the consequenses.

He provides a list of criteria to be analyzed in order to check whether a cyber attack could be considered "use of force" in terms of international law. Here they are:
"1) Severity: Armed attacks threaten physical injury or destruction of property to a much greater degree than other forms of coercion. Physical well-being usually occupies the apex of the human hierarchy of need.
2) Immediacy: The negative consequences of armed coercion, or threat thereof, usually occur with great immediacy, while those of other forms of coercion develop more slowly. Thus, the opportunity for the target state or the international community to seek peaceful accommodation is hampered in the former case.
3) Directness: The consequences of armed coercion are more directly tied to the actus reus than in other forms of coercion, which often depend on numerous contributory factors to operate. Thus, the prohibition on force precludes negative consequences with greater certainty.
4) Invasiveness: In armed coercion, the act causing the harm usually crosses into the target state, whereas in economic warfare the acts generally occur beyond the target’s borders. As a result, even though armed and economic acts may have roughly similar consequences, the former represents a greater intrusion on the rights of the target state and, therefore, is more likely to disrupt international stability.
5) Measurability: While the consequences of armed coercion are usually easy to ascertain (e.g., a certain level of destruction), the actual negative consequences of other forms of coercion are harder to measure. This fact renders the appropriateness of community condemnation, and the degree of vehemence contained therein, less suspect in the case of armed force.
6) Presumptive Legitimacy: In most cases, whether under domestic or international law, the application of violence is deemed illegitimate absent some specific exception such as self-defense. The cognitive approach is prohibitory. By contrast, most other forms of coercion—again in the domestic and international sphere--are presumptively lawful, absent a prohibition to the contrary. The cognitive approach is permissive. Thus, the consequences of armed coercion are presumptively impermissible, whereas those of other coercive acts are not (as a very generalized rule)."
An example of the use of the Schmitt analysis in a more quantitative form is available here [pdf].

He spends a fair amount of time analysizing what actions could be taken in response to CNA. He comes up with a relatively simple decision procedure:
"1) Is the technique employed in the CNA a use of armed force? It is if the attack is intended to directly cause physical damage to tangible objects or injury to human beings.
2) If it is not armed force, is the CNA nevertheless a use of force as contemplated in the U.N. Charter? It is if the nature of its consequences track those consequence commonalities which characterize armed force.
3) If the CNA is a use of force (armed or otherwise), is that force applied consistent with Chapter VII, the principle of self-defense, or operational code norms permitting its use in the attendant circumstances?
a) If so, the operation is likely to be judged legitimate.
b) If not and the operation constitutes a use of armed force, the CNA will violate Article 2(4), as well as the customary international law prohibition on the use of force.
c) If not and the operation constitutes a use of force, but not armed force, the CNA will violate Article 2(4).
4) If the CNA does not rise to the level of the use of force, is there another prohibition in international law that would preclude its use? The most likely candidate, albeit not the only one, would be the prohibition on intervening in the affairs of other States."
A second decision procedure is available for determining whether or not a response with armed force is applicable:
"1) If the computer network attack amounts to a use of armed force, then the Security Council may characterize it as an act of aggression or breach of peace and authorize a forceful response under Article 42 of the Charter. To constitute an armed attack, the CNA must be intended to directly cause physical damage to tangible objects or injury to human beings.
2) If the CNA does not constitute an armed attack, the Security Council may nevertheless find it to threaten the peace (the absence of inter-state violence) and authorize a use of force to prevent a subsequent breach of peace. The CNA need not amount to a use of force before the Council may determine that it threatens peace.
3) States, acting individually or collectively, may respond to a CNA amounting to armed attack with the use of force pursuant to Article 51 and the inherent right of self-defense.
4) States, acting individually or collectively, may respond to a CNA not amounting to armed attack, but which is an integral part of an operation intended to culminate in armed attack when:
a) The acts in self-defense occur during the last possible window of opportunity available to effectively counter the attack; and
b) The CNA is an irrevocable step in an imminent (near-term) and probably unavoidable attack."
The paper contains a lot of insight (at least to an outsider like me) of how the international law works and what may be the questions asked after the first real cyber war. I highly recommend reading this paper in full to get the picture. I know the author is currently working on updating the analysis, but until then, we must wait.

Thursday, January 14, 2010

The Schmitt analysis

Here is a bit of reading from 2002 that is still relevant today. Michael N. Schmitt wrote an article called "Wired warfare: Computer network attack and jus in bello" [pdf], where he explored what the international humanitarian law has to say about CNA. It should be required reading for all of us cyber conflict researchers, as sooner or later we will have to tackle with showing how our theories work (or not) in the framework of existing laws. And the article shows, that lawyers' concerns are often a bit different from what we might expect.
As an anecdote, I found it very funny when Richard Nixon's head (President of Earth in Futurama), faced with a legal obstacle, says something along the lines of: "Well, I know a place where the Constitution doesn't mean squat!" and the camera zooms to the Supreme Court. [from memory, so it may be a little inaccurate]
For those who are a unsure what jus in bello means, he provides a definition:
"... that body of law concerned with what is permissible, or not, during hostilities, irrespective of the legality of the initial resort to force by the belligerents."
With that clear, let's move on. He quickly analyzes whether the international humanitarian law applies to CNA at all and finds that yes it does, if it can be classified as 'armed conflict'. That, in turn, requires that 'armed forces' are engaged in the conflict. However, the link between CNA and armed forces is not very strong, so he analyzes the contradictions in the text of the law and its application to conclude that:
"... humanitarian law principles apply whenever computer network attacks can be ascribed to a State are more than merely sporadic and isolated incidents and are either intended to cause injury, death, damage or destruction (and analogous effects), or such consequences are foreseeable."
Obviously, the biggest problem here is the attribution. Cyber is very much a silent service when it comes to taking credit for the really complicated and high profile attacks. Government A could very well pull off a 'cyber war' and remain anonymous. Better yet, make it look like it came from Govt. B.

Since direct injury and death is presumably difficult to reach with cyber, let's discuss the other two. Would financial loss be enough to evoke the damage criteria? If so, how much loss are we talking about? Does destruction only apply to physical objects or is information also on the menu? What if an attacker drops all tables in the national registry of [CLASSIFIED] and manages to mess up the backups as well? The truth is out there...

Schmitt follows a trail of deductions similar with the 'armed conflict' with the concepts of 'targeting' and 'attack' in the law. He also touches the classification of targets to combatants and military objectives, civilians and civilian objects, as well as dual use objects. He discusses targeting economic systems (stock market, banks etc) as military targets and once again returns to the threshold of 'injury, death, damage or destruction'.

The civilian section includes an interesting bit about contractors or civilians who perform cyber attacks. He points out that those civilians (and contractors) with an official tie to the military could still be targeted and could be considered prisoner of war (because they are 'accompanying the armed forces'), if captured. On the other hand, if civilians launch the attack and they do not have an official connection, they would be 'illegal combatants' (who may still be attacked). This is only in case where the cyber attacks are severe enough to pass the threshold mentioned above.

Unfortunately his section on dual use objects is relatively short. I think the dual use category is extremely important in cyber context, as one could argue that most systems could potentially be dual use (Internet, for example, can serve as a backup communication system for the military and it is most likely going to be the main battlefield of cyber conflict). This is definitely one aspect that merits further study.

He shows that the legal framework actually supports cyber attacks over kinetic in some cases, such as shutting down dams and nuclear power stations (which you should not do with kinetics).

He analyzes several aspects of CNA targeting, including discrimination, distinction, proportionality, collateral damage, incidental injury and perfidy. I think the difference between a perfidy and a ruse is what would often get IT guys in trouble.

Overall, he covers a lot of ground and to my knowledge, there is still no better, definite answer on what is and is not allowed in cyber space. As always, read the paper for full info.

Tuesday, December 29, 2009

Cyber communities

I happened on an interesting site (wish I had found it sooner) that also deals with cyber warfare research. Near the top of the blog pile is an interesting series of posts, which looks at the various Cyber Warfare communities that have a stake in the issue:
Although there are a lot of good points in there, let me just reiterate one - there are not many publication opportunities for cyber warfare researchers. Sure, you can hook your topic to information security, information operations, or any number of other topics, but still - very few dedicated venues like the upcoming Conference on Cyber Conflict.

I'll now turn back to the Selil blog, to see what else I can find. See you all next year!

Tuesday, December 22, 2009

Russia and Cyber Attacks

A colleague pointed me to an article in the Baltic Security and Defence Review, an annual publication of the Baltic Defence College (international staff college for military officers at OF3-OF5 ranks). MAJ William Ashmore (US Army) writes an overview of recent cyber conflicts with Russia, titled "Impact of Alleged Russian Cyber Attacks" [pdf].

While the article covers a lot of ground it seems that he is not a subject matter expert in cyber conflicts. The quality of the references is relatively weak (mostly public news media) and there are a few simple errors. On the other hand, he has done a fairly broad background check for the legal/doctrinal work done at OSCE, UN etc.

He provides an overview of events in Estonia 2007 and Georgia 2008 among others, and a summary of NATO's activities in setting up cyber defence. He spends some time on Herman Simm's case (highly placed spy for Russians in Estonian MoD, caught 2008), although to me his arguments there seem a bit weak.

He reviews the national and international responses/comments to the Russian cyber campaigns, including potential attribution. There is also a fairly interesting chapter about future trends in Russian cyber activities (including Dr Panarin's recommendations). I think he may be onto something when he says that in Russia, cyber is mostly seen as an offensive capability.

With the US primarily focused on the Chinese cyber threat, the Russian (and other) cyber studies remain in the background. Therefore, it is a refreshing piece of reading, regardless of some issues with depth or quality. As always, read the article for full info.

Happy holidays!

Friday, December 18, 2009

McAfee's Virtual Criminology Report 2009

I set aside some time this week to read the McAfee Virtual Criminology Report 2009 [pdf]. It has a provocative sub-title "Virtually Here: The Age of Cyber Warfare" that caught my eye. So, what was useful in there for me?

As the foreword (by CEO of McAfee) already points out, politically motivated cyber attacks are on the rise and the term cyber crime is not fit to describe them well. The foreword also makes the important point that this report comes from a private sector perspective, unlike the usual government/military perspectives on cyber warfare. As it turns out later, however, it is more of a broad spectrum overview that doesn't really focus on any special sector or issue.

The report gives a short overview of the events in Estonia 2007, Georgia 2008 and US/South Korea 2009. The Georgian overview is based on the US Cyber Consequences Unit overview [pdf], which is the public high-level summary of a more detailed report.

Of more interest is the method for cyber attack attributes that is presented on pages 8-9. Experts will assign values to a cyber conflict in four categories to determine the severity of the event (no reference):
"Source: Was the attack carried out or supported by a nation-state?
Consequence: Did the attack cause harm?
Motivation: Was the attack politically motivated?
Sophistication: Did the attack require customized methods and/or complex planning?"
They have provided a table for assigning values and have applied the model on the three conflicts mentioned earlier, providing a bar graph. I have done similar work in my Master's studies. In retrospect, it is only of limited use, because the values are highly subjective and in the end - it does not prove anything.

The report also mentions many well known issues in cyber conflict, including:
  • many nations are preparing for cyber war, but covertly
  • criminals and politically motivated attackers use the same tools and techniques
  • criminal groups may cooperate with governments
  • financial and other critical information infrastructure is at high risk
  • sharing threat information is good
  • there is a need for a public debate about the use of cyber weapons
  • the attribution problem and a nice intro to the cyber deterrence issue
  • the need for updated legal measures
  • cyber espionage
  • etc.
On one hand, this report should bring little new information for the experts and researchers that focus on the issue. It uses little or no quality (written) references, but this issue is balanced out with the number of expert interviews and direct quotes. Therefore, I thought it was nice to read, but I found nothing really provocative in there.

On the other hand, however, I find that it does a very good job as an introduction to the whole cyber conflict issue for non-specialist readers. If you need to convince your boss or your grandmother that cyber conflicts should be studied - have them read this report.

Monday, November 16, 2009

Shane Harris - The Cyberwar Plan

Shane Harris has an interesting article in the National Journal. The main punchline seems to be that in 2007 US performed a cyber operation against insurgents in Iraq (and is planning to fight in cyberspace in the future, as well). Specifically:
"At the request of his national intelligence director, Bush ordered an NSA cyberattack on the cellular phones and computers that insurgents in Iraq were using to plan roadside bombings. The devices allowed the fighters to coordinate their strikes and, later, post videos of the attacks on the Internet to recruit followers. According to a former senior administration official who was present at an Oval Office meeting when the president authorized the attack, the operation helped U.S. forces to commandeer the Iraqi fighters'communications system. With this capability, the Americans could deceive their adversaries with false information, including messages to lead unwitting insurgents into the fire of waiting U.S. soldiers."

As is the tradition with revelations like this, in the end, there are no easily verifiable facts and the story itself is deniable, if necessary. On the other hand, it does say out loud what many others have omitted to so far and brings a clearly understandable example of the potential use of cyber power.

The article gives a very nice overview of many of the problems in cyber, such as finding and retaining personnel for the cyber force, attributing attacks to a state, potential escalation of the conflict to include third parties, collateral damage etc. One of the problems is the interdependency between civilian and military infrastructure, well illustrated by the quote from an USAF official: "... Iraq didn't do a good job of partitioning between the military and civilian networks." We have seen that human shield tactics work relatively well against western military. Consider then that the mixed infrastructure is like an ultimate human (civilian) shield, which could be used as a deterrent against military cyber attacks.

In a way, this article illustrates the media bias in security studies. We (western media) have long heard stories and laments of Chinese, Russian, Iranian and North Korean evildoing in cyberspace - spying on government leaders, attacking opposition web servers at home and abroad, etc. It is rare to hear someone state the obvious truth that western countries are, in fact, often doing the very same thing. With that out of the way, we can get down to business of analyzing conflicts in cyberspace.

The article briefly covers the Estonia 2007 and Georgia 2008 cyber attacks. Unfortunately, he makes the wide-spread comment of "crippling effects" in the Estonian case, which I have tried to correct and explain here. However, he only uses these cases as examples to illustrate the problems of attribution.

He proceeds by illustrating one of the key reasons why cyber operations have failed to make it into mainstream military use. A briefing on the 1999 Kosovo campaign concluded that:
"... the cyber-operation "could have halved the length of the [air] campaign." Although "all the tools were in place ... only a few were used." The briefing concluded that the cyber-cell had "great people," but they were from the "wrong communities" and "too junior" to have much effect on the overall campaign. The cyber-soldiers were young outsiders, fighting a new kind of warfare that, even the briefing acknowledged, was "not yet understood.""
It is true - cyber warfare is not yet understood. Not even by the experts who are trained to fight it. There are very few examples (often anecdotal) of actual use of cyber operations to achieve military success, and even those are usually restricted to a very narrow part of the grand plan. Therefore, it is too early to say if applying the doctrine in large scale conventional military operations will bring cyber to the dominant position, or supportive, or just annoying. It will probably take a conventional, serious (life-or-death for the state), war between two technologically advanced states to really bring out the benefits and drawbacks of cyber war.

The rest of the article is also a good read, so I highly recommend it. I don't agree with parts of it, such as the MAD doctrine as a useful analogy (I've commented on it here), but it does provide a good introduction to the military cyber issues, especially for those who are new to the topic.

Monday, November 9, 2009

Review: Amit Sharma on Cyber Wars

Time for another review of the articles published in the proceedings of the CCD COE Cyber Warfare Conference. Next up is Amit Sharma from India, who wrote an interesting paper titled "Cyber Wars: A Paradigm Shift from means ot Ends".

He starts out by explaining the idea behind the paper. He hopes to provide a
"framework in which cyber warfare will have a strategic effect by acting as primary means to achieve conventional ends, hence will induce a paradigm shift from the conventional notion of cyber warfare as a tactical force multiplier to the notion of strategic cyber warfare acting as primary means of achieving grand strategic objectives in the contemporary world order. The author will accomplish this objective by deriving the elixir of Clausewitz’s Trinitarian warfare and applying the concepts of Rapid dominance and Parallel warfare in cyber space so as to generate the strategic paralytic effect envisaged in effect based warfare. The author will conclude by shattering the conventional dictum of cyber defence, based on the notion of “defence in layers” and legal aspects of Law of Armed Conflict; by providing the only feasible and viable cyber defence strategy relying on the application of Rational Deterrence Theory (RDT) in general and on the idea of Mutually Assured Destruction (MAD) in particular so as to maintain the strategic status quo."
A tall order by any standard. The paper is written in an artistic and forceful language, painting the scene of an apocalyptic cyber strike that ends all and paralyses the entire state from the government to the citizen by simultaneously disrupting the trinity of government, military and people. I think that this strong emphasis on total paralysis (and total war) is a potential weakness of his approach.

Even though all theoretical model are abstractions, I believe his trinity (imagine a triangle) model is somewhat idealistic and naive. His description of the people corner is exclusively oriented to the liberal western countries (which includes the minority of the world's population and, arguably, are not as liberal or democratic as they may portray themselves). What about the rest of the world? The model's military corner is focused on the network-centric digital troops, which again represent the minority (although a powerful one) in the militaries of the world and even that is not always as networked on the battleground as the doctrine would imply. Last, but not least, the government corner, where governments are charged to provide "a secure, secular and democratic environment" for the people. Well, let's try to name some big countries that fit that idealistic description to the letter in practice, as well as in theory. It won't be easy. So, the model applies in a theoretical ideal case and I agree that in such a case the implications can be extremely dangerous.

The danger comes from simultaneously taking down all three components of the trinity with a parallel cyber campaign, which, as we have just reviewed, is entirely dependent on the assumption that the country is wired beyond the point of safe return. He concedes that in most recent cyber conflicts this parallelism has not taken place and we have seen much more limited campaigns.

He then proceeds with a five step plan for a strategic cyber campaign: "Shape, Deter, Seize initiative, Dominate and Exit". This is a nice and clean model for describing a (cyber) conflict, but I disagree with some of his conclusions.

In discussing the deter stage, he touches on the concept of countervailing, or "making known to the potential adversary that the implication of a nuclear strike would be far greater than the potential gains an adversary can achieve by initiating the first strike." He mentions that the recent cyber attacks against Estonia, Georgia, UK, France etc. may be an example of cyber counterveiling. I do not see it that way, as a key point of countervailing relies on letting the enemy know your capability - and no state has taken responsibility for the attacks listed. Furthermore, the cases he cites are not traditional military conflicts (with the possible exception of the Georgia attacks), but merely harassment or espionage, which do not demonstrate the potential destructive capability of a state. They do serve as reminders that networks are vulnerable, however.

He does make a good point that in order to deter an attack you need a "Cyber Triad capability", which consists of
"Regular defence/military assets and networks, [...] isolated conglomerate of air-gapped networks situated across the friendly nations as part of cooperative defence, which can be initiated as credible second strike option; and [...] a loosely connected network of cyber militia involving patriotic hackers, commercial white hats and private contractors which can be initiated after the initial strike or in case of early warning of a potential strike."
He proceeds by demonstrating that the concept of defense in layers and the Law of Armed Conflict (LoAC) do not work in a strategic cyber campaign. I do not understand his point that a system built on the concept of defense in layers (defence-in-depth) is "as strong as its weakest link." To me, defense in layers means exactly the opposite - you can take out any single node and the system remains secure due to the other layers.

His other argument is that LoAC does not cover strategic cyber warfare. Granted, there have been no successful applications of LoAC to strategic cyber warfare yet, but that is because we have not yet seen a strategic cyber warfare campaign in the armed conflict sense. As mentioned above, we have plenty of hactivism, espionage and other examples that fall outside the LoAC framework, but no state-on-state wars where cyber has played a significant role. Therefore, it is premature to throw LoAC out of the window as it is today. However, I agree that it needs updating to meet modern scenarios and the CCD COE is among the experts that work toward this goal (some discussions on this took place at the Cyber Conflict Law and Policy Conference).

He finishes by arguing that Mutually Assured Destruction (MAD) doctrine is the best way to keep states from engaging in strategic cyber warfare. I would argue that MAD simply does not work well in cyberspace, as
  1. attribution of the cyber attack may be impossible,
  2. in case attribution can be achieved, there is a question of false-flag operations,
  3. in case a second strike is launched, there will be ample collateral damage to third states, which can escalate the conflict further,
  4. the cyber triad is never ideal and many (most) countries in the world today are almost invulnerable to strategic cyber warfare, because they have little or no reliance on cyberspace,
  5. in case a strategic cyber campaign succeeds against a modern military power, they can always retaliate with weapons of mass destruction (missile silos should be air-gapped from the rest of cyberspace, at least I would hope so).
Overall, the paper has a lot of provocative thoughts and arguments and I enjoyed reading it (what would be the point of reading things that do not raise a single question or counterargument). I have not covered some of his points that I agree with and, as always, I recommend reading the full paper. We met briefly at the Conference in June and discussed some of the points above, and in the end agreed to disagree on some of them. I wish him luck in his research, as he definitely rocks the boat.

Wednesday, October 28, 2009

Centralized vs de-centralized cyber campaigns

The previous post got me thinking about some of the key tenets of the Chinese approach: the cyber campaign must be centrally controlled, executed by organic forces and have a tightly focused target.

Obviously, this centralized approach provides good command and control opportunities. It also limits collateral damage and I guess, most important of all, eliminates possible interference from volunteer actions (such as someone taking control of one of the key entry points to the enemy network and shutting you out). Historical examples also seem to show that volunteers are more likely to engage visible targets (web sites etc) that have little or no tactical value.

On the other hand, NOT using the volunteers (the de-centralized approach) denies you the use of a potential resource. Odds are that if a country has a developed patriotic hacking community, they will take part in the conflict one way or the other, so you might as well try to guide them to be useful.

The second argument for using volunteers is psychological. It displays public support to your campaign, potentially reinforcing the mindset in other sectors of the society. It also brings in small but visible IW victories, as press covers the "citizen campaign" against the opposing side.

The third argument would be the Fog of War. The patriotic hacking community can provide the smoke screen necessary to execute the important strikes against key nodes. Remember, if the plan is to concentrate your attacks in time and (network) space, they will become immediately visible. However, if you have attacks of various severity levels happening all the time the enemy may not recognize the significance of the critical attack until it is too late.

The fourth argument is that patriotic hackers can "prep the battlefield" before the hostilities commence, provide retaliatory attacks after the hostilities, target third parties and civilian or commercial targets while the state can deny any involvement. This supposes that there is an established patriotic hacker community in place, so the world does not necessarily consider there to be a direct link to the specific conflict.

Finally, political attacks by civilians as part of a larger conflict have no clear regulation and few legal precedents. If the host country is not willing to cooperate with the criminal investigation (not likely in a time of war) the attackers will remain anonymous and protected, while the state still has "formal" deniability.

However, as I have noted before, there is a price for accepting patriotic hacking in a state. Most pressing are the long term rise in cyber crime and the potential that they act against the state. On the other hand, if the decision has been made or if there is already a well-established community in place, one should consider the possible uses of this force. Because whether you plan for (with) them or not, they will participate in the fight.

Monday, October 26, 2009

Cyber Report on China

I got a tip to a new report on Chinese cyber capabilities [pdf] by Northrop Grumman. The report aims to provide "a comprehensive open source assessment of China’s capability to conduct computer network operations (CNO) both during peacetime and periods of conflict."

They start off with an overview of the strategic developments in China. Even though there is no official CNO strategy, the PLA is in fact preparing to fight the cyber battle. I found it interesting that they consider domination in cyber space a prerequisite for air and naval domination. This is a clear indication of its importance in the Chinese thinking. It also explains why the EW/IW/CW issue is seen as the forcing agent behind the "informationization" of the PLA.

Chinese writings identify enemy C4ISR and logistics systems as the primary targets in a military conflict and also point out that IW will fire the opening "shots" in a war. However, there is also indication that IW and conventional techniques can and should be used together for maximum effect. I think this is very important, because I have often seen the mindset that IW is something separate from "real" warfighting. Then again, the Chinese have thousands of years of experience to draw upon, so it is not surprising that they see the value of combining the two.

They also point out that China is very active in developing counter-space weapons (EW, CW, kinetic, directed energy, EMP etc.) in order to fight a potentially tech-heavy oriented opponent such as the US.

Another interesting aspect is targeting. Instead of trying to blanket the battlefield, the Chinese writings suggest taking out key nodes in order to provide opportunities for other forces to exploit the resulting confusion in a specific point in the battlefield. I believe this refers more towards EW and kinetic than cyber, as tactical use of cyber attacks would probably be difficult to implement.

It seems that the PLA is actively training to fight in conditions where CW/IW is a common part of the battle field, including special training centers and a designated Blue Force (OPFOR) regiment. In addition, several universities seem to engage in offensive CW research and education.

There is an interesting note about using EW/CW pre-emptively to deter an enemy or to limit the size of the conflict without much bloodshed. In fact, they seem to consider CW a deterrent second only to nuclear at the strategic level. I like the comment that CW is the PLAs longest range weapon.

Another key point that I agree with is that CNO is useful for damaging/degrading systems, but also for deploying PSYOPS/deception against enemy personnel, enemy supporters and the public in general. I have met some people who consider PR the one and only element of IW and I just disagree. With so many options available under IW, it would be irresponsible to overly limit yourself to use only one.

There is an excellent section about how the Chinese might use CNO against the US (military) in a conflict scenarion. I agree wholeheartedly that the logistics and C2 systems at the theater or higher level would be sensible targets to buy time for the PLA and to cause confusion among US forces. However, as I have noted before, the discussion here is limited to purely military targets (like in the US discussion), but in a total war the commercial sector may be the more important strategic target.

The following section gives a broad overview of what is publicly known about the Chinese CW structure. Of particular interest for me are the PLA IW militia units, which seem to be drafted from commercial and academic entities to supplement PLAs integral capabilities. The idea of using telcos and universities (for example) to create sub-units for the militia is perhaps not intuitive for the westerners, but it does make sense. You have people with the right skills, established relationships and access to networks and systems - all they need is a mission.

The second interesting bit is that some militia sub-units seem to focus purely on R&D. In order to understand the significance, consider if infantry (militia) battalion is likely to have a dedicated infantry tactics research and development platoon. This highlights the difference between the information warriors and the traditional fighters. The report also mentions discussions about setting a different standard (age limit, physical condition) for the cyber warrior, something that was also debated here.

Moving on to the independent Chinese (patriotic) hacker community, the report claims that around 2002-2004 the state reversed its previously favorable stance towards patriotic hactivism and as a result the movement has died down. This was not the notion I got in Stockholm in May, where Dr Xu Wu from Arizona State University talked about Chinese cyber nationalism. According to him, the patriotic hacker community is alive and well, albeit somewhat underground. He also claimed that the state was having difficulties deciding what to do with this resource, as it is difficult to control - something that I also predicted in my paper about volunteer cyber attackers. Dr Wu compared it to a double-edged sword, which can cut both ways. It is possible, however, that this discrepancy does not exist and the official cyber militias have incorporated a significant part of the patriotic hacker community.

The report then provides a couple of examples of recent attacks probably originating from China. There are also various examples of relations between the state and the hacker community, including state recruitment in the hacker forums. One of the more interesting examples is how a java language user group transformed into a patriotic hacker group over the EP-3 incident. This is an excellent illustration of how "cyber tribes" can very quickly develop into cyber militias.

In the following section, cyber espionage is investigated from the US perspective. The report points out that potential Chinese espionage efforts are a great concern for the US counter-intelligence community, especially in the light of the reactive cyber defense paradigms in place. They claim that there is a strong case for state-sponsored attacks, although it is often difficult to fully attribute the attack to a state.

The report includes a nice explanation of a targeted attack via e-mail to get access to the organization's systems. However, they include an even more interesting case study of a large data heist in a US firm. It provides a simple description of the time line and activities uncovered by the forensic team.

The report concludes with a comprehensive list of China-related cyber events between 1999 and 2009.

Overall, the report is easy to read and low-tech. It covers many interesting aspects of the Chinese cyber issues. However, since this is a public and open-source report, it does not go into too much detail and it may inadvertently include some deception information. All-in-all, I enjoyed it and it provided me with a lot of things to think about. It also confirms some of my own theories and thoughts.

As always, read the report for full detail.

Tuesday, July 14, 2009

On definitions

A big problem in the field of cyber is the lack of commonly agreed definitions. I think cyber war and cyber terrorism are the worst, each having numerous conflicting definitions. So, in order to clarify my own thoughts, here is my attempt to pin down the meaning of some popular phrases in the context of national security:
  • cyber attack - malicious use of information systems in order to influence the information, systems, processes, actions or decisions of the target without their consent,
  • cyber conflict - a confrontation between two or more parties, where at least one party uses cyber attacks against the other(s),
  • cyber war - a cyber conflict between state actors, where the critical information infrastructure is attacked,
  • cyber terrorism - a cyber conflict where one party is using cyber attacks to cause fear, physical damage, and/or death among the civilian population of the other party.
Note that information collection, an activity usually limited to espionage, intelligence gathering and crime, is not included in the cyber attack definition. [TO DO: better explanation of the concept]

I am sure these definitions will change as my understanding of the topic grows.

Thursday, July 2, 2009

A time for a Cyber Service of the Military?

I stumbled on an article by COL Surdu and LTC Conti, which was published earlier this year in the IA Newsletter [Vol 12, No 1, 2009 - pdf]. In the article, they argue that US needs a new military service that would handle the cyber warfare mission.

Currently, each service already has small elements dispersed in the structure, but they are not coordinated, nor are they integrated into the bigger picture. I think they bring out a good point that the US military (in fact, other militaries as well) is not fit to fight a cyber war, as its leadership, processes and culture are fundamentally incapable to understand it.

The main problem is that the military does not place enough emphasis on technical expertise, or as they put it:
"Today’s militaries excel at their respective missions of fighting and winning in ground, sea, and air conflict; however, the core skills each institution values are intrinsically different from those skills required to engage in cyberwarfare.
...
To understand the culture clash evident in today’s existing militaries, it is useful to examine what these services hold dear—skills such as marksmanship, physical strength, and the ability to jump out of airplanes and lead combat units under enemy fire. Accolades are heaped upon those who excel in these areas. Unfortunately, these skills are irrelevant in cyberwarfare.
...
Consider the awards, decorations, badges, patches, tabs, and other accoutrements authorized for wear by each service. Absent is recognition for technical expertise. Echoes of this ethos are also found in disadvantaged assignments, promotions, school selection, and career progression for those who pursue cyberwarfare expertise, positions, and accomplishments."
I wholeheartedly agree with their arguments, having come to a similar conclusion some time ago. Their proposal to deal with this issue is to create a new service that would be on equal status with the kinetic services. However, I am not so convinced that a transition so profound can be made in one step. Perhaps it would be better to use the USAF model and first create cyber commands (historical Army Air Corps) within the services, then integrate them, and then, maybe, raise them into a new service.

They are right, however, that the root of the problem lies with the personnel management in the military. One could say that a techie should stay in the service, become the top dog and change it from within, but that discounts the fact that techies do not get promoted to top dog. In fact, there are precious little positions near the top that have anything to do with technology. Therefore, a techie must either be a multi-talent or forget his tech aspirations and plod up the traditional leadership/management track. Meanwhile, people who have a talent for tech positions will not be promoted and more than likely get rotated to (technologically) meaningless positions... or they get out. Therefore, any step that will accommodate the requirements and skills of the tech oriented service members while not undermining the traditional services, is a step in the right direction.

Friday, June 26, 2009

Evgeny Morozov on Cyber Myths

Evgeny Morozov of the Open Society Institute has an interesting essay in the Boston Review about myths in cyberspace. Specifically, he addresses the scaremongering and vague threat information that is used to get access to funding, fame or power.

He points out many official statements that exaggerate the threat from cyber terrorism and cyber war and asks the question: is there any evidence to back up these claims? No, at least not in the public realm. He also makes a point that the threat from the net information is produced by intelligence/defence organizations and information security companies that benefit from the increased funding. I think he is right in the sense that there are very few facts available, so we are left with hypotheses and conjecture. Honestly, I am partly to blame, as I have presented similar worst case scenarios in numerous conferences, in order to raise awareness of the topic.

He also touches the foggy quagmire that is the international legal definition of cyber warfare and what, if anything can and should be done if one breaks out. I think we will not have a clear answer on this in the near future, but at least the topic is also addressed by professionals.

In terms of how useful cyber attacks are for the military, Morozov refers the opinion that superpowers do not need cyber power, as they have more conventional means to crush the enemy. While that may be true, the question of attribution once again comes up - who will the superpower nuke, if they cannot identify the source of the cyber attack?

On the other hand, his conclusion that we should focus more on the threats from cyber crime and cyber-espionage is correct. However, it is not correct because cyber war is improbable, but because the tools used in cyber war will be very similar to the ones used in crime and espionage. The same piece of malware can be used to steal your personal data, collect intelligence on your organization or to disrupt your networks in preparation for a war. Thus, better defense against crimeware will also mean better defense in war.

A comment on Estonia

Unfortunately, Morozov uses unclear wording that may suggest that Estonia was off-line for nearly a month in 2007. It would be more correct to say that Estonia was under attack for about three weeks in 2007, but only a few critical on-line services (like banks) were affected for clients inside Estonia. One of the options, a white-list based "island Estonia" defence meant that the vast majority of the attacks could be easily blocked while maintaining service to the vast majority of the clients. As a result, clients of the two biggest banks in Estonia saw only a 45-90 minute interruption of service at the start of the attacks and that only affected the web interface of the banks. What is worrying, however, that these were critical "civilian" targets in a political conflict.

Sure, non-critical services (public government websites and news sites, for example) did suffer longer service outages due to cyber attacks (mostly simple DDoS), but in my opinion this was not a big issue for the state as a whole. The biggest effect would be potential information blockade, as local news sites or press sites are off-line, but that can easily be remedied by using other means of communication to push the message out (remember, e-mail works, phones work, faxes work, radio and TV are still on air, and even the postman makes his rounds). I personally had no problems communicating with friends and colleagues abroad throughout the period.