Last week I was at the 9th European Conference on Information Warfare and Security (ECIW 2010) in Thessaloniki, Greece. This is an academic conference, so most of the attendants were also speakers. The information about the proceedings is available here. I hosted the Cyber Conflict mini-track, which consisted of five papers, including mine:
Ottis, R. (2010) Proactive Defence Tactics Against On-Line Cyber Militia. In Proceedings of the 9th European Conference on Information Warfare and Security, Thessaloniki, Greece, 01-02 July. Reading: Academic Publishing Limited, p 233-237. [link]
The main idea of my paper was that in order to defeat a loose network of cyber vigilantes (on-line cyber militia), one can potentially adopt a more proactive stance and use various (offensive) information operations. It should be noted that this is only a theoretical exercise, as some of the options considered may be against the laws and regulations of the host country.
If you have any feedback or suggestions for reading material in the similar vein, please let me know.
Showing posts with label paper. Show all posts
Showing posts with label paper. Show all posts
Monday, July 5, 2010
Monday, June 14, 2010
Two papers published at C6
I have updated the publications tab with two papers that were published in the proceedings of the upcoming Conference on Cyber Conflict. As is always the case, by the time they went to print I already had some ideas for changing them. Nevertheless, here they are:
- Lorents, P. and Ottis, R. (2010) Knowledge Based Framework for Cyber Weapons and Conflict. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 129-142.[link]
- Ottis, R. (2010) From Pitch Forks to Laptops: Volunteers in Cyber Conflicts. In Czosseck, C. and Podins, K. (Eds.) Conference on Cyber Conflict. Proceedings 2010. Tallinn: CCD COE Publications, p 97-109. [link]
Wednesday, April 14, 2010
Paper on Cyberspace
I presented a paper [link] at the 5th International Conference on Information Warfare and Security (ICIW) last week. This year the event was hosted by the US Air Force Institute of Technology, at the Wright Patterson AFB, Dayton, Ohio. If you ever get the chance, I recommend to spend a day or two at the Air Force museum in there (yeah, any less will not do).
Our paper (co-authored by Peeter Lorents) presented some of our work on the cyber terminology. Specifically, in the paper we defined cyberspace as "a time-dependent set of interconnected information systems and the human users that interact with these systems".
It was not our intent to come up with a universal definition (which could be useless), but something that provides a background for our future work. So, basically, it is more like a brick destined to become part of a wall, instead of the wall itself.
While we were at it, we came up with a couple of simple implications from our definition, which are explained in more detail in the paper:
P.S. I moved the publications section to a tab at the top. Under that tab is now the full list, with some papers available via Google Docs.
Our paper (co-authored by Peeter Lorents) presented some of our work on the cyber terminology. Specifically, in the paper we defined cyberspace as "a time-dependent set of interconnected information systems and the human users that interact with these systems".
It was not our intent to come up with a universal definition (which could be useless), but something that provides a background for our future work. So, basically, it is more like a brick destined to become part of a wall, instead of the wall itself.
While we were at it, we came up with a couple of simple implications from our definition, which are explained in more detail in the paper:
- both offensive and defensive deployments can take place very rapidly in cyberspace
- it is not feasible to map cyberspace accurately
- both attackers and defenders must constantly reconnoiter or patrol the potential area of conflict in cyberspace.
P.S. I moved the publications section to a tab at the top. Under that tab is now the full list, with some papers available via Google Docs.
Labels:
blogging,
conference,
cyberspace,
definitions,
ICIW,
paper
Wednesday, March 10, 2010
Cyber Conferences
Here are some cyber conferences that might be of interest, in chronological order (disclaimer: I will take part in all of them):
The International Conference on Information Warfare and Security (ICIW), April 8-9 in Dayton, Ohio, US. This is an academic conference with peer reviewed proceedings and covers a wide range of topics from PSYOPS to cyber operations. I will be presenting a paper titled "Cyberspace: Defininition and Implications".
The SMi Conference on Cyber Defence, May 17-18 in Tallinn, Estonia. This is a professional conference that is leaning a bit towards military approaches. I am invited to give a talk there.
The CCD COE Conference on Cyber Conflict (C6), June 16-18 in Tallinn, Estonia. The Conference is a mix of academic and professional presentations and will also publish peer reviewed proceedings of the academic content. There are three tracks: Legal, Strategy and Technical Solutions. I will be managing the Strategy track. I have written about this event before in here and here. Registration is now open.
The European Conference on Information Warfare and Security (ECIW), July 1-2 in Thessaloniki, Greece. This is an academic conference with peer reviewed proceedings and covers a wide range of topics from PSYOPS to cyber operations. I will be chairing the Cyber Conflict mini-track and presenting a paper titled "Proactive Defence Tactics Against On-Line Cyber Militia".
Oh yeah, did I mention that the registration is open for the C6?
The International Conference on Information Warfare and Security (ICIW), April 8-9 in Dayton, Ohio, US. This is an academic conference with peer reviewed proceedings and covers a wide range of topics from PSYOPS to cyber operations. I will be presenting a paper titled "Cyberspace: Defininition and Implications".
The SMi Conference on Cyber Defence, May 17-18 in Tallinn, Estonia. This is a professional conference that is leaning a bit towards military approaches. I am invited to give a talk there.
The CCD COE Conference on Cyber Conflict (C6), June 16-18 in Tallinn, Estonia. The Conference is a mix of academic and professional presentations and will also publish peer reviewed proceedings of the academic content. There are three tracks: Legal, Strategy and Technical Solutions. I will be managing the Strategy track. I have written about this event before in here and here. Registration is now open.
The European Conference on Information Warfare and Security (ECIW), July 1-2 in Thessaloniki, Greece. This is an academic conference with peer reviewed proceedings and covers a wide range of topics from PSYOPS to cyber operations. I will be chairing the Cyber Conflict mini-track and presenting a paper titled "Proactive Defence Tactics Against On-Line Cyber Militia".
Oh yeah, did I mention that the registration is open for the C6?
Labels:
CCD COE,
conference,
paper
Wednesday, February 3, 2010
Why Science? Because it works! Kind of ...
Every once in a while I get into a discussion on whether or not it is difficult to enter the scientific community. My theory is that it rests mostly on motivation and self confidence, as is excellently demonstrated by the example of professors Zola and Charlie Chrobak.
I am not really familiar with their current work [pdf], but I have a feeling that it is related to some previous research on Artificial Intelligence.
Thanks to Dr Risto Vaarandi for pointing me to this wonderful story of the underdogs in science.
I am not really familiar with their current work [pdf], but I have a feeling that it is related to some previous research on Artificial Intelligence.
Thanks to Dr Risto Vaarandi for pointing me to this wonderful story of the underdogs in science.
Thursday, January 14, 2010
The Schmitt analysis
Here is a bit of reading from 2002 that is still relevant today. Michael N. Schmitt wrote an article called "Wired warfare: Computer network attack and jus in bello" [pdf], where he explored what the international humanitarian law has to say about CNA. It should be required reading for all of us cyber conflict researchers, as sooner or later we will have to tackle with showing how our theories work (or not) in the framework of existing laws. And the article shows, that lawyers' concerns are often a bit different from what we might expect.
Since direct injury and death is presumably difficult to reach with cyber, let's discuss the other two. Would financial loss be enough to evoke the damage criteria? If so, how much loss are we talking about? Does destruction only apply to physical objects or is information also on the menu? What if an attacker drops all tables in the national registry of [CLASSIFIED] and manages to mess up the backups as well? The truth is out there...
Schmitt follows a trail of deductions similar with the 'armed conflict' with the concepts of 'targeting' and 'attack' in the law. He also touches the classification of targets to combatants and military objectives, civilians and civilian objects, as well as dual use objects. He discusses targeting economic systems (stock market, banks etc) as military targets and once again returns to the threshold of 'injury, death, damage or destruction'.
The civilian section includes an interesting bit about contractors or civilians who perform cyber attacks. He points out that those civilians (and contractors) with an official tie to the military could still be targeted and could be considered prisoner of war (because they are 'accompanying the armed forces'), if captured. On the other hand, if civilians launch the attack and they do not have an official connection, they would be 'illegal combatants' (who may still be attacked). This is only in case where the cyber attacks are severe enough to pass the threshold mentioned above.
Unfortunately his section on dual use objects is relatively short. I think the dual use category is extremely important in cyber context, as one could argue that most systems could potentially be dual use (Internet, for example, can serve as a backup communication system for the military and it is most likely going to be the main battlefield of cyber conflict). This is definitely one aspect that merits further study.
He shows that the legal framework actually supports cyber attacks over kinetic in some cases, such as shutting down dams and nuclear power stations (which you should not do with kinetics).
He analyzes several aspects of CNA targeting, including discrimination, distinction, proportionality, collateral damage, incidental injury and perfidy. I think the difference between a perfidy and a ruse is what would often get IT guys in trouble.
Overall, he covers a lot of ground and to my knowledge, there is still no better, definite answer on what is and is not allowed in cyber space. As always, read the paper for full info.
As an anecdote, I found it very funny when Richard Nixon's head (President of Earth in Futurama), faced with a legal obstacle, says something along the lines of: "Well, I know a place where the Constitution doesn't mean squat!" and the camera zooms to the Supreme Court. [from memory, so it may be a little inaccurate]For those who are a unsure what jus in bello means, he provides a definition:
"... that body of law concerned with what is permissible, or not, during hostilities, irrespective of the legality of the initial resort to force by the belligerents."With that clear, let's move on. He quickly analyzes whether the international humanitarian law applies to CNA at all and finds that yes it does, if it can be classified as 'armed conflict'. That, in turn, requires that 'armed forces' are engaged in the conflict. However, the link between CNA and armed forces is not very strong, so he analyzes the contradictions in the text of the law and its application to conclude that:
"... humanitarian law principles apply whenever computer network attacks can be ascribed to a State are more than merely sporadic and isolated incidents and are either intended to cause injury, death, damage or destruction (and analogous effects), or such consequences are foreseeable."Obviously, the biggest problem here is the attribution. Cyber is very much a silent service when it comes to taking credit for the really complicated and high profile attacks. Government A could very well pull off a 'cyber war' and remain anonymous. Better yet, make it look like it came from Govt. B.
Since direct injury and death is presumably difficult to reach with cyber, let's discuss the other two. Would financial loss be enough to evoke the damage criteria? If so, how much loss are we talking about? Does destruction only apply to physical objects or is information also on the menu? What if an attacker drops all tables in the national registry of [CLASSIFIED] and manages to mess up the backups as well? The truth is out there...
Schmitt follows a trail of deductions similar with the 'armed conflict' with the concepts of 'targeting' and 'attack' in the law. He also touches the classification of targets to combatants and military objectives, civilians and civilian objects, as well as dual use objects. He discusses targeting economic systems (stock market, banks etc) as military targets and once again returns to the threshold of 'injury, death, damage or destruction'.
The civilian section includes an interesting bit about contractors or civilians who perform cyber attacks. He points out that those civilians (and contractors) with an official tie to the military could still be targeted and could be considered prisoner of war (because they are 'accompanying the armed forces'), if captured. On the other hand, if civilians launch the attack and they do not have an official connection, they would be 'illegal combatants' (who may still be attacked). This is only in case where the cyber attacks are severe enough to pass the threshold mentioned above.
Unfortunately his section on dual use objects is relatively short. I think the dual use category is extremely important in cyber context, as one could argue that most systems could potentially be dual use (Internet, for example, can serve as a backup communication system for the military and it is most likely going to be the main battlefield of cyber conflict). This is definitely one aspect that merits further study.
He shows that the legal framework actually supports cyber attacks over kinetic in some cases, such as shutting down dams and nuclear power stations (which you should not do with kinetics).
He analyzes several aspects of CNA targeting, including discrimination, distinction, proportionality, collateral damage, incidental injury and perfidy. I think the difference between a perfidy and a ruse is what would often get IT guys in trouble.
Overall, he covers a lot of ground and to my knowledge, there is still no better, definite answer on what is and is not allowed in cyber space. As always, read the paper for full info.
Monday, December 28, 2009
Milblogging, ad-hoc cyber militia and science
I read an paper by Sean Lawson, about the debate and conflict [pdf] between the US Army and the Milblogging community (servicemembers who blog about their experience in the military, including combat reports).
While the article focuses on the blogging servicemen, we should also make a note that the same tool is available to everyone. This spontaneous "online, volunteer public affairs or information operations corps" would be a perfect rallying tool for an ad-hoc cyber militia. Consider, that there are numerous blogs on controversial issues (including pro and contra sides for each), which typically have a steady readership, even if it is small. All it takes is for the blogger to post a rally cry (and some instructions) and an ad-hoc cyber militia is formed and ready for action.
Members of such a group are pre(self)selected and have strong feelings about the issue. Therefore, they probably need very little persuasion to join up.
If you have the time and the interest, there is also a link to his Doctoral Dissertation on his web site. It gives a good overview of the development of the science of war, explaining the heritage of terms such as OODA loop and netcentric warfare, as well as providing an overview of the relation between US military and the scientific community. Interesting to read. Nearly 400 pages, however, so be warned.
While the article focuses on the blogging servicemen, we should also make a note that the same tool is available to everyone. This spontaneous "online, volunteer public affairs or information operations corps" would be a perfect rallying tool for an ad-hoc cyber militia. Consider, that there are numerous blogs on controversial issues (including pro and contra sides for each), which typically have a steady readership, even if it is small. All it takes is for the blogger to post a rally cry (and some instructions) and an ad-hoc cyber militia is formed and ready for action.
Members of such a group are pre(self)selected and have strong feelings about the issue. Therefore, they probably need very little persuasion to join up.
If you have the time and the interest, there is also a link to his Doctoral Dissertation on his web site. It gives a good overview of the development of the science of war, explaining the heritage of terms such as OODA loop and netcentric warfare, as well as providing an overview of the relation between US military and the scientific community. Interesting to read. Nearly 400 pages, however, so be warned.
Labels:
cyber militia,
paper,
review
Thursday, December 10, 2009
Warp speed, Mr Spock!
I realize that Spock is normally not at the helm, but there is method to my madness (I think). Spock is a science officer and therefore a better addressee in the case of academic publishing. The problem with the publishing process in science is that it is ... well ... light speed at best. And light is just way too slow if you want to explore the universe.
Consider this: if the Sun were to mysteriously explode with no warning, we would remain in blissful ignorance of the fact for roughly 8 minutes. So, something better is needed. In case of the Star Trek universe, the answer is Warp Drive, which allows for faster-than-light travel.
Similarly, the publishing process (write abstract, get it accepted, write full paper, get it reviewed, improve it, publish it) usually takes months, sometimes even years. This means that an idea can potentially die of old age before it is given birth (officially). Also, multiple people can work on the same idea and only discover on the eleventh hour that somebody has already beaten them to it (by 2 minutes and 42 seconds). Additionally, peer review is limited to one or two pairs of eyes, instead of the wider community. So, something better is needed.
I guess the best thing we have going for us is the Internet. Posting raw ideas in a blog like this, getting feedback and comments WHILE you develop a paper, not AFTER it is published could potentially be the warp drive that I'm looking for.
Oh, I am well aware that I am not the first one to gripe about this problem, nor is my solution original in any way. But it is something that I intend to try. So please, feel free to demolish my ideas in the comments section (or contact me directly via e-mail).
Shields up!
Consider this: if the Sun were to mysteriously explode with no warning, we would remain in blissful ignorance of the fact for roughly 8 minutes. So, something better is needed. In case of the Star Trek universe, the answer is Warp Drive, which allows for faster-than-light travel.
Similarly, the publishing process (write abstract, get it accepted, write full paper, get it reviewed, improve it, publish it) usually takes months, sometimes even years. This means that an idea can potentially die of old age before it is given birth (officially). Also, multiple people can work on the same idea and only discover on the eleventh hour that somebody has already beaten them to it (by 2 minutes and 42 seconds). Additionally, peer review is limited to one or two pairs of eyes, instead of the wider community. So, something better is needed.
I guess the best thing we have going for us is the Internet. Posting raw ideas in a blog like this, getting feedback and comments WHILE you develop a paper, not AFTER it is published could potentially be the warp drive that I'm looking for.
Oh, I am well aware that I am not the first one to gripe about this problem, nor is my solution original in any way. But it is something that I intend to try. So please, feel free to demolish my ideas in the comments section (or contact me directly via e-mail).
Shields up!
Monday, December 7, 2009
Review: Jose Nazario on Political DDoS Attacks
Time for another review. This time it is Jose Nazario's CWCON paper called "Politically Motivated Denial of Service Attacks." He is looking at DDoS as one of the more visible and popular cyber attack forms and is limiting his sample to the ones with a political motivation (vs the standard criminal motivation - money).
NOTE: The final published version of this paper was accepted after the conference so it includes some more recent examples.
His research is based on data from three sources: ATLAS project at Arbor Networks (basically, ATLAS collects data from sensors to provide an overview of the more visible cyber campaigns), infiltrated botnet C&C servers and border gateway protocol (BGP) routing data.
He starts out with a little overview of major political DDoS campaigns of the past, covering the following events:
NOTE: The final published version of this paper was accepted after the conference so it includes some more recent examples.
His research is based on data from three sources: ATLAS project at Arbor Networks (basically, ATLAS collects data from sensors to provide an overview of the more visible cyber campaigns), infiltrated botnet C&C servers and border gateway protocol (BGP) routing data.
He starts out with a little overview of major political DDoS campaigns of the past, covering the following events:
- 2001 Hainan Island incident
- 2007 Estonia campaign
- 2008 China v CNN campaign
- 2008 Georgia campaign
- 2008 Burma
- 2007 elections in Russia
- 2008 Radio Free Europe campaign
- 2008 anti-NATO campaign in Ukraine
- 2009 MSK forum DDoS in Kazakhstan
- 2008 DDoS-censoring of Russian opposition websites
- 2009 Israel v Gaza/Hamas
- 2009 Kyrgyzstan - a false positive?
- 2008 Kommersant DDoS
- 2009 Kazakhstan opposition sites under DDoS
- 2009 South Korean/US campaign
It is noticeable how most of these events are known by the target only. In history, conflicts are usually named after both/all participants or at least the participants are known. In cyber conflicts, however, it seems to be the norm that the aggressor remains anonymous. Even if all the circumstantial evidence and opinions point against one entity, rarely is there enough proof to attribute the attack in court.
He continues to describe the attacker type that seem to be behind most of the attacks listed. In general, the attackers are "classic right-wing" supporters of the government and targeting internal or external opposition. He also writes about using propaganda to recruit supporters for a cyber campaign and then training them online - a basic ad-hoc cyber militia. What the militia cannot achieve with finesse and expertise, they make up in numbers (DDoS).
He points out that the classical goals for such attacks are to punish the target, or to show dissent, or to censor the target (especially true for attacks against news outlets and opposition parties). He brings examples of partial attribution: Nashi youth group in Russia, the Chinese Honker Union and StopGeorgia.ru. Note that in all these cases the attackers made the claim - nothing has been proven in court (as far as I know).
He reviews some broad responses to the cyber campaigns listed and finishes with recommendations:
He continues to describe the attacker type that seem to be behind most of the attacks listed. In general, the attackers are "classic right-wing" supporters of the government and targeting internal or external opposition. He also writes about using propaganda to recruit supporters for a cyber campaign and then training them online - a basic ad-hoc cyber militia. What the militia cannot achieve with finesse and expertise, they make up in numbers (DDoS).
He points out that the classical goals for such attacks are to punish the target, or to show dissent, or to censor the target (especially true for attacks against news outlets and opposition parties). He brings examples of partial attribution: Nashi youth group in Russia, the Chinese Honker Union and StopGeorgia.ru. Note that in all these cases the attackers made the claim - nothing has been proven in court (as far as I know).
He reviews some broad responses to the cyber campaigns listed and finishes with recommendations:
- harness public support and international cooperation
- deploy available commercial tools
- be open to commercial offers to help
- develop a more efficient decision making process
- delegate authority
- consensus is sometimes not necessary
In conclusion, he also points out that we need to study guerilla and asymmetric warfare in order to succeed on the cyber battlefield.
The paper has numerous examples from recent years and thus gives a good overview of the extent of the problem. However, the examples have different level of detail (often too vague) to be of much help on researching a specific case. I would have expected a more detailed analysis of a limited number of campaigns. As always, read the paper for full value.
The paper has numerous examples from recent years and thus gives a good overview of the extent of the problem. However, the examples have different level of detail (often too vague) to be of much help on researching a specific case. I would have expected a more detailed analysis of a limited number of campaigns. As always, read the paper for full value.
Labels:
botnet,
cyber attack,
cyber conflict,
cyber militia,
DDoS,
paper,
review
Wednesday, December 2, 2009
Review: Billy Rios on Cyber Attacks
It has been a busy time since last post. I gave a short lecture at the NATO School in Germany last week and I'm preparing some paper ideas for next year. However, I decided to take a short breather and review another paper from the Conference on Cyber Warfare - Billy K. Rios wrote a piece titled "Sun-Tzu Was a Hacker: An Examination of the Tactics and Operations from a Real World Cyber Attack." His work is partially based on the Grey Goose Report I.
The paper tries to map some real cyber operations to equivalent concepts in maneuver warfare, particularly drawing on the Georgia case and the US Marine Corps doctrine. He starts out by describing the essence of maneuver warfare and points out that cyber operations cannot "win a war". Instead, they can break up the enemy's cohesion and allow for exploitation by other (conventional) means. Incidentally, the Chinese seem to have adopted the same idea.
Discussing decentralized command and commanders intent, he brings the example of how a target list of Georgian sites was posted in a forum without clear instructions for action. The forum members then contributed with potential attack plans/instructions and discussed the campaign. As a result, a variety of targets and options became available and the attackers could each choose a course of action suitable for their skill, resources and level of motivation. As a side note, similar behavior was observed a year earlier during the cyber campaign against Estonia.
As an example of combined arms, he brings the example of SQL injection queries for fingerprinting and gaining access to database contents (NB! starting a month before the armed conflict), exploiting this information for intelligence, preparing automated attack tools that are then provided through the forum to anyone interested. I think he could have used a better example, because the link to combined arms is not clearly apparent.
Illustrating the concept of initiative he uses the examples of pre-emtive intrusions to Georgian systems and the sustained pressure to keep initiative on the attacker side, while keeping the Georgians to react. As a result, responding to cyber attacks wasted valuable time.
He also explains the importance of identifying and attacking enemy Centres of Gravity, although he does not connect it to the Georgian case. The important point is that these centres need not be physical fortifications or units, but can also encompass things like morale and resolve. Clearly, cyber attacks are a potential way of attacking the enemy centres of gravity, especially C2 networks and information targets.
He then points out that conventional weapons have physical limitations and the skill of the operator can only have relatively little effect in terms of stretching the effective range, damage etc. For example, a skilled marksman with a M4 carbine can hit a target from several hundred meters with standard sights, but not much more. On the other hand, the cyber warrior's capability to do damage is directly correlated with his skills. I especially like this sentence:
Rios summarizes the paper by emphasizing that
The paper tries to map some real cyber operations to equivalent concepts in maneuver warfare, particularly drawing on the Georgia case and the US Marine Corps doctrine. He starts out by describing the essence of maneuver warfare and points out that cyber operations cannot "win a war". Instead, they can break up the enemy's cohesion and allow for exploitation by other (conventional) means. Incidentally, the Chinese seem to have adopted the same idea.
Discussing decentralized command and commanders intent, he brings the example of how a target list of Georgian sites was posted in a forum without clear instructions for action. The forum members then contributed with potential attack plans/instructions and discussed the campaign. As a result, a variety of targets and options became available and the attackers could each choose a course of action suitable for their skill, resources and level of motivation. As a side note, similar behavior was observed a year earlier during the cyber campaign against Estonia.
As an example of combined arms, he brings the example of SQL injection queries for fingerprinting and gaining access to database contents (NB! starting a month before the armed conflict), exploiting this information for intelligence, preparing automated attack tools that are then provided through the forum to anyone interested. I think he could have used a better example, because the link to combined arms is not clearly apparent.
Illustrating the concept of initiative he uses the examples of pre-emtive intrusions to Georgian systems and the sustained pressure to keep initiative on the attacker side, while keeping the Georgians to react. As a result, responding to cyber attacks wasted valuable time.
He also explains the importance of identifying and attacking enemy Centres of Gravity, although he does not connect it to the Georgian case. The important point is that these centres need not be physical fortifications or units, but can also encompass things like morale and resolve. Clearly, cyber attacks are a potential way of attacking the enemy centres of gravity, especially C2 networks and information targets.
He then points out that conventional weapons have physical limitations and the skill of the operator can only have relatively little effect in terms of stretching the effective range, damage etc. For example, a skilled marksman with a M4 carbine can hit a target from several hundred meters with standard sights, but not much more. On the other hand, the cyber warrior's capability to do damage is directly correlated with his skills. I especially like this sentence:
"Creating an offensive cyber capability is less about finding the right hardware and more about finding the right people and skillsets."He also highlights that it poses a problem for intelligence analysts, as it is very difficult to estimate or track the development of offensive cyber capability, because the key component is the skillset of operators, not the invested money or acquired hardware.
Rios summarizes the paper by emphasizing that
- cyber capability should be incorporated into the overall plan, as it will not win the war on its own.
- Command and Control should be kept decentralized and decisions delegated to the lowest level. [This is in contrast to the Chinese doctrine, which seems to prefer rigid central control and limited use of the cyber strikes. - RO]
- the individual cyber specialist is the weapon system, not his laptop or his sidearm.
The paper is short and to the point. I like the summary, which brings out some good points (even some that do not seem apparent from the main text).
Labels:
cyber attack,
cyber doctrine,
paper,
review
Monday, November 9, 2009
Review: Amit Sharma on Cyber Wars
Time for another review of the articles published in the proceedings of the CCD COE Cyber Warfare Conference. Next up is Amit Sharma from India, who wrote an interesting paper titled "Cyber Wars: A Paradigm Shift from means ot Ends".
He starts out by explaining the idea behind the paper. He hopes to provide a
Even though all theoretical model are abstractions, I believe his trinity (imagine a triangle) model is somewhat idealistic and naive. His description of the people corner is exclusively oriented to the liberal western countries (which includes the minority of the world's population and, arguably, are not as liberal or democratic as they may portray themselves). What about the rest of the world? The model's military corner is focused on the network-centric digital troops, which again represent the minority (although a powerful one) in the militaries of the world and even that is not always as networked on the battleground as the doctrine would imply. Last, but not least, the government corner, where governments are charged to provide "a secure, secular and democratic environment" for the people. Well, let's try to name some big countries that fit that idealistic description to the letter in practice, as well as in theory. It won't be easy. So, the model applies in a theoretical ideal case and I agree that in such a case the implications can be extremely dangerous.
The danger comes from simultaneously taking down all three components of the trinity with a parallel cyber campaign, which, as we have just reviewed, is entirely dependent on the assumption that the country is wired beyond the point of safe return. He concedes that in most recent cyber conflicts this parallelism has not taken place and we have seen much more limited campaigns.
He then proceeds with a five step plan for a strategic cyber campaign: "Shape, Deter, Seize initiative, Dominate and Exit". This is a nice and clean model for describing a (cyber) conflict, but I disagree with some of his conclusions.
In discussing the deter stage, he touches on the concept of countervailing, or "making known to the potential adversary that the implication of a nuclear strike would be far greater than the potential gains an adversary can achieve by initiating the first strike." He mentions that the recent cyber attacks against Estonia, Georgia, UK, France etc. may be an example of cyber counterveiling. I do not see it that way, as a key point of countervailing relies on letting the enemy know your capability - and no state has taken responsibility for the attacks listed. Furthermore, the cases he cites are not traditional military conflicts (with the possible exception of the Georgia attacks), but merely harassment or espionage, which do not demonstrate the potential destructive capability of a state. They do serve as reminders that networks are vulnerable, however.
He does make a good point that in order to deter an attack you need a "Cyber Triad capability", which consists of
His other argument is that LoAC does not cover strategic cyber warfare. Granted, there have been no successful applications of LoAC to strategic cyber warfare yet, but that is because we have not yet seen a strategic cyber warfare campaign in the armed conflict sense. As mentioned above, we have plenty of hactivism, espionage and other examples that fall outside the LoAC framework, but no state-on-state wars where cyber has played a significant role. Therefore, it is premature to throw LoAC out of the window as it is today. However, I agree that it needs updating to meet modern scenarios and the CCD COE is among the experts that work toward this goal (some discussions on this took place at the Cyber Conflict Law and Policy Conference).
He finishes by arguing that Mutually Assured Destruction (MAD) doctrine is the best way to keep states from engaging in strategic cyber warfare. I would argue that MAD simply does not work well in cyberspace, as
He starts out by explaining the idea behind the paper. He hopes to provide a
"framework in which cyber warfare will have a strategic effect by acting as primary means to achieve conventional ends, hence will induce a paradigm shift from the conventional notion of cyber warfare as a tactical force multiplier to the notion of strategic cyber warfare acting as primary means of achieving grand strategic objectives in the contemporary world order. The author will accomplish this objective by deriving the elixir of Clausewitz’s Trinitarian warfare and applying the concepts of Rapid dominance and Parallel warfare in cyber space so as to generate the strategic paralytic effect envisaged in effect based warfare. The author will conclude by shattering the conventional dictum of cyber defence, based on the notion of “defence in layers” and legal aspects of Law of Armed Conflict; by providing the only feasible and viable cyber defence strategy relying on the application of Rational Deterrence Theory (RDT) in general and on the idea of Mutually Assured Destruction (MAD) in particular so as to maintain the strategic status quo."A tall order by any standard. The paper is written in an artistic and forceful language, painting the scene of an apocalyptic cyber strike that ends all and paralyses the entire state from the government to the citizen by simultaneously disrupting the trinity of government, military and people. I think that this strong emphasis on total paralysis (and total war) is a potential weakness of his approach.
Even though all theoretical model are abstractions, I believe his trinity (imagine a triangle) model is somewhat idealistic and naive. His description of the people corner is exclusively oriented to the liberal western countries (which includes the minority of the world's population and, arguably, are not as liberal or democratic as they may portray themselves). What about the rest of the world? The model's military corner is focused on the network-centric digital troops, which again represent the minority (although a powerful one) in the militaries of the world and even that is not always as networked on the battleground as the doctrine would imply. Last, but not least, the government corner, where governments are charged to provide "a secure, secular and democratic environment" for the people. Well, let's try to name some big countries that fit that idealistic description to the letter in practice, as well as in theory. It won't be easy. So, the model applies in a theoretical ideal case and I agree that in such a case the implications can be extremely dangerous.
The danger comes from simultaneously taking down all three components of the trinity with a parallel cyber campaign, which, as we have just reviewed, is entirely dependent on the assumption that the country is wired beyond the point of safe return. He concedes that in most recent cyber conflicts this parallelism has not taken place and we have seen much more limited campaigns.
He then proceeds with a five step plan for a strategic cyber campaign: "Shape, Deter, Seize initiative, Dominate and Exit". This is a nice and clean model for describing a (cyber) conflict, but I disagree with some of his conclusions.
In discussing the deter stage, he touches on the concept of countervailing, or "making known to the potential adversary that the implication of a nuclear strike would be far greater than the potential gains an adversary can achieve by initiating the first strike." He mentions that the recent cyber attacks against Estonia, Georgia, UK, France etc. may be an example of cyber counterveiling. I do not see it that way, as a key point of countervailing relies on letting the enemy know your capability - and no state has taken responsibility for the attacks listed. Furthermore, the cases he cites are not traditional military conflicts (with the possible exception of the Georgia attacks), but merely harassment or espionage, which do not demonstrate the potential destructive capability of a state. They do serve as reminders that networks are vulnerable, however.
He does make a good point that in order to deter an attack you need a "Cyber Triad capability", which consists of
"Regular defence/military assets and networks, [...] isolated conglomerate of air-gapped networks situated across the friendly nations as part of cooperative defence, which can be initiated as credible second strike option; and [...] a loosely connected network of cyber militia involving patriotic hackers, commercial white hats and private contractors which can be initiated after the initial strike or in case of early warning of a potential strike."He proceeds by demonstrating that the concept of defense in layers and the Law of Armed Conflict (LoAC) do not work in a strategic cyber campaign. I do not understand his point that a system built on the concept of defense in layers (defence-in-depth) is "as strong as its weakest link." To me, defense in layers means exactly the opposite - you can take out any single node and the system remains secure due to the other layers.
His other argument is that LoAC does not cover strategic cyber warfare. Granted, there have been no successful applications of LoAC to strategic cyber warfare yet, but that is because we have not yet seen a strategic cyber warfare campaign in the armed conflict sense. As mentioned above, we have plenty of hactivism, espionage and other examples that fall outside the LoAC framework, but no state-on-state wars where cyber has played a significant role. Therefore, it is premature to throw LoAC out of the window as it is today. However, I agree that it needs updating to meet modern scenarios and the CCD COE is among the experts that work toward this goal (some discussions on this took place at the Cyber Conflict Law and Policy Conference).
He finishes by arguing that Mutually Assured Destruction (MAD) doctrine is the best way to keep states from engaging in strategic cyber warfare. I would argue that MAD simply does not work well in cyberspace, as
- attribution of the cyber attack may be impossible,
- in case attribution can be achieved, there is a question of false-flag operations,
- in case a second strike is launched, there will be ample collateral damage to third states, which can escalate the conflict further,
- the cyber triad is never ideal and many (most) countries in the world today are almost invulnerable to strategic cyber warfare, because they have little or no reliance on cyberspace,
- in case a strategic cyber campaign succeeds against a modern military power, they can always retaliate with weapons of mass destruction (missile silos should be air-gapped from the rest of cyberspace, at least I would hope so).
Labels:
cyber war,
deterrence,
paper,
review,
strategy
Thursday, October 22, 2009
Review: Analogies and Cyber Security
Here is a short review of the paper "What Analogies Can Tell Us About the Future of Cyber Security" by David Sulek and Ned Moran, published in the proceedings of the CCD COE Cyber Warfare Conference.
In the paper they explore the potential dangers that come with using colorful analogies like cyber Pearl Harbor, cyber Katrina, cyber 9/11 etc. In order to deal with these dangers they propose to start with developing a detailed issue history. A well written issue history helps determine which analogies apply. They give a short example in the form of the cyber issue history that, among other things, lists what is known, what is unclear and what is presumed about the topic.
They then provide a framework for exploring cyber analogies. It consists of two dimensions: one axis representing inspiration (hope and possibility) vs desperation (fear and danger) and the other systemic (evolution) vs disruptive (revolution). They give some examples for each: invention of the telegraph was an inspiring event, as it created new possibilities to communicate. On the other hand, the Y2K bug represented a potential danger to the computer systems. World War I was a linear, systemic result of military build-up, whereas 9/11 was a disruptive, revolutionary event. I think the first pair of examples is a good fit, but I am not so sure about the second. One could argue that there is an evolutionary line of developments that lead to both tragedies, we just haven't taken the time to really reflect on the reasons for, the facts of and the aftershocks of the 9/11 attacks. But I digress.
They spend the rest of the paper analyzing four cases from each quadrant of the model as a potential fit for cyber security. The four cases are the Strategic Defence Initiative (inspiration, evolution), the Cold War (desperation, evolution), the [US] National Highway System (inspiration, revolution) and finally, Pearl Harbor (desperation, revolution). Each case reveals interesting overlaps with cyber. However, each also has its discrepancies, so no clear match emerges.
They sum up their analysis in four points:
In the paper they explore the potential dangers that come with using colorful analogies like cyber Pearl Harbor, cyber Katrina, cyber 9/11 etc. In order to deal with these dangers they propose to start with developing a detailed issue history. A well written issue history helps determine which analogies apply. They give a short example in the form of the cyber issue history that, among other things, lists what is known, what is unclear and what is presumed about the topic.
They then provide a framework for exploring cyber analogies. It consists of two dimensions: one axis representing inspiration (hope and possibility) vs desperation (fear and danger) and the other systemic (evolution) vs disruptive (revolution). They give some examples for each: invention of the telegraph was an inspiring event, as it created new possibilities to communicate. On the other hand, the Y2K bug represented a potential danger to the computer systems. World War I was a linear, systemic result of military build-up, whereas 9/11 was a disruptive, revolutionary event. I think the first pair of examples is a good fit, but I am not so sure about the second. One could argue that there is an evolutionary line of developments that lead to both tragedies, we just haven't taken the time to really reflect on the reasons for, the facts of and the aftershocks of the 9/11 attacks. But I digress.
They spend the rest of the paper analyzing four cases from each quadrant of the model as a potential fit for cyber security. The four cases are the Strategic Defence Initiative (inspiration, evolution), the Cold War (desperation, evolution), the [US] National Highway System (inspiration, revolution) and finally, Pearl Harbor (desperation, revolution). Each case reveals interesting overlaps with cyber. However, each also has its discrepancies, so no clear match emerges.
They sum up their analysis in four points:
- There is no single analogy that works for cyber.
- Cases that balance inspiration and desperation leave the strongest impression on history.
- Many analogies used today are at the extreme ends of the model.
- It is important to build a good timeline for an issue, in order to understand the reasons for events.
Overall, it is a nice read and an interesting analysis of the four cases. I may not agree with the interpretation of historical events, but then again, the model is meant to be an abstract tool to describe analogies. As such, there will always be opportunities to interpret events in different ways.
The main point for me is to review the cyber analogies that I have used in the past. The analysis of the four cases has given me some food for thought and hopefully, next time I blurt out with something, I remember to also offer caveats.
As always, the paper itself is much more detailed and I recommend reading it in full.
The main point for me is to review the cyber analogies that I have used in the past. The analysis of the four cases has given me some food for thought and hopefully, next time I blurt out with something, I remember to also offer caveats.
As always, the paper itself is much more detailed and I recommend reading it in full.
Labels:
cyber security,
paper,
review
Monday, October 19, 2009
CWCON '09 proceedings available
Yep, they are finally here. The proceedings of the CCD COE Conference on Cyber Warfare, which took place in June, have now been published with the help of IOS Press. Titled "The Virtual Battlefield: Perspectives on Cyber Warfare" it appears as book three in the Cryptology and Information Security Series, and is edited by Christian Czosseck and Kenneth Geers of the Centre.
It's 300 pages contain 21 peer-reviewed papers presented at the conference. In the coming weeks I hope to follow through on my promise and write reviews for the ones that are of most interest for me.
On the same note, the call for papers for the next year's conference is due out shortly, so start warming up your paper ideas.
It's 300 pages contain 21 peer-reviewed papers presented at the conference. In the coming weeks I hope to follow through on my promise and write reviews for the ones that are of most interest for me.
On the same note, the call for papers for the next year's conference is due out shortly, so start warming up your paper ideas.
Labels:
CCD COE,
conference,
paper,
proceedings
Friday, September 4, 2009
Paper on Cyber Society
I co-authored a paper with Peeter Lorents and Raul Rikk that was published in the 13th International Conference on Human-Computer Interaction, San Diego, in July. You can also find the paper in LNCS 5623, pp. 180-186.
The paper is titled Cyber Society and Cooperative Cyber Defence. In it, we explore the concept of cyber society, which we define as "a society where computerized information transfer and information processing is (near) ubiquitous and where the normal functioning of this society is severely degraded or altogether impossible if the computerized systems no longer function correctly."
We then examine Estonia as an early form of a cyber society and illustrate it's potential vulnerabilities with the events of April-May 2007. We conclude the paper with the foundations behind the establishment of the Cooperative Cyber Defence Centre of Excellence.
This was my first co-authored paper and as such a new experience. One of the problems of having multiple authors is to write a consistent paper - something that could be improved in this case. However, I think it does convey the ideas that we wanted.
The paper is titled Cyber Society and Cooperative Cyber Defence. In it, we explore the concept of cyber society, which we define as "a society where computerized information transfer and information processing is (near) ubiquitous and where the normal functioning of this society is severely degraded or altogether impossible if the computerized systems no longer function correctly."
We then examine Estonia as an early form of a cyber society and illustrate it's potential vulnerabilities with the events of April-May 2007. We conclude the paper with the foundations behind the establishment of the Cooperative Cyber Defence Centre of Excellence.
This was my first co-authored paper and as such a new experience. One of the problems of having multiple authors is to write a consistent paper - something that could be improved in this case. However, I think it does convey the ideas that we wanted.
Labels:
article,
CCD COE,
conference,
cyber society,
Estonia,
paper
Thursday, July 9, 2009
ECIW 09 in Lisbon
I just got back from Lisbon and the 8th European Conference on Information Warfare and Security. This annual conference brings together 60-100 academics from across the world to present and discuss their research during the two-day event.
A paper that I wrote for the conference in the winter got published in the proceedings (see publications). The main idea of the paper is that there are three general ways to create an offensive capability in cyberspace:
While thinking about the last two approaches, I came to some interesting conclusions. First, if a government uses volunteers or mercenaries to conduct an "illegal", or at least unethical, campaign against its political enemies, then there will be a rise in (cyber) crime in the state. This happens because the government cannot alienate the "friendly" attackers by arresting them for non-political crimes (such as sending spam, stealing credit card information or DDoSing commercial sites for blackmail). This also explains why cyber criminals seem to flourish in some states that also seem to have an aggressive stance in cyberspace.
The second idea was that in case of volunteer forces, the government would have to "exercise" these forces once or twice a year, in order to keep them "on mission". A volunteer offensive cyber militia will likely disband for more interesting pursuits, if they are not called to arms for several years. This means that the state would have to provide a steady stream of external or internal "enemies" to keep the militia occupied.
A paper that I wrote for the conference in the winter got published in the proceedings (see publications). The main idea of the paper is that there are three general ways to create an offensive capability in cyberspace:
- establish a unit/agency for that mission ("conventional" own forces approach)
- outsource the problem by hiring digital mercenaries, cyber criminals and the like
- develop or hijack a volunteer force, or a cyber militia, to attack convenient targets with little or no attribution for the state.
While thinking about the last two approaches, I came to some interesting conclusions. First, if a government uses volunteers or mercenaries to conduct an "illegal", or at least unethical, campaign against its political enemies, then there will be a rise in (cyber) crime in the state. This happens because the government cannot alienate the "friendly" attackers by arresting them for non-political crimes (such as sending spam, stealing credit card information or DDoSing commercial sites for blackmail). This also explains why cyber criminals seem to flourish in some states that also seem to have an aggressive stance in cyberspace.
The second idea was that in case of volunteer forces, the government would have to "exercise" these forces once or twice a year, in order to keep them "on mission". A volunteer offensive cyber militia will likely disband for more interesting pursuits, if they are not called to arms for several years. This means that the state would have to provide a steady stream of external or internal "enemies" to keep the militia occupied.
Labels:
conference,
cyber forces,
cyber militia,
ECIW,
paper
Thursday, June 25, 2009
Cyber attacks in Estonia, 2007
My first academic paper was published last year in the Proceedings of the 7th European Conference on Information Warfare and Security, Plymouth. An annual event, this conference brings together people with very different perspectives on information warfare, from psychological to cyber.
My paper was titled Analysis of the 2007 Cyber Attacks Against Estonia from the Information Warfare Perspective (see Publications for more information). In the paper, I analyze the Estonian case by posing three hypotheses and then arguing for and against each of them to find if any of them are plausible.
The first hypothesis is that the event was a Russian information operation, the second is that the event was a false flag operation to discredit Russia, and the last one is that it was a spontaneous grass roots response to Estonian government policy.
The false flag hypothesis is not plausible, considering the amount of circumstantial evidence against Russia (and only Russia) while the Russian government made no effort to stop the attacks or expose the attackers.
A true grass roots movement is also not plausible, as at the very least, passive government support (Russian authorities refusing legal cooperation) seems evident.
NOTE: Interestingly enough, a member of the Russian parliament later claimed that one of his aides was actively involved in the cyber campaign. This fact (?) emerged after publishing, so it is not included in the analysis.
That leaves us with the state information operation scenario. Specifically, it matches a Chinese concept of People's War, where people fight with their own resources and organization, for the interests of the state. That explains hostile rhetoric by politicians, the relatively high number of people involved, as well as lack of interest by the state to identify the attackers.
Unfortunately, the analysis can not attribute the attacks to any specific person, organization, or state. Instead, I find that of the three hypotheses considered, only the information operation scenario was plausible.
In hindsight, I do not consider it a very good paper, as it provides no definitive answer and devotes more detailed analysis to one of the hypotheses. In addition, I had just started my research on the topic, so my understanding of concepts like cyber militias and People's War was still very tentative. On the other hand, even though I notice many things I would write differently today, the conclusion would still remain the same.
My paper was titled Analysis of the 2007 Cyber Attacks Against Estonia from the Information Warfare Perspective (see Publications for more information). In the paper, I analyze the Estonian case by posing three hypotheses and then arguing for and against each of them to find if any of them are plausible.
The first hypothesis is that the event was a Russian information operation, the second is that the event was a false flag operation to discredit Russia, and the last one is that it was a spontaneous grass roots response to Estonian government policy.
The false flag hypothesis is not plausible, considering the amount of circumstantial evidence against Russia (and only Russia) while the Russian government made no effort to stop the attacks or expose the attackers.
A true grass roots movement is also not plausible, as at the very least, passive government support (Russian authorities refusing legal cooperation) seems evident.
NOTE: Interestingly enough, a member of the Russian parliament later claimed that one of his aides was actively involved in the cyber campaign. This fact (?) emerged after publishing, so it is not included in the analysis.
That leaves us with the state information operation scenario. Specifically, it matches a Chinese concept of People's War, where people fight with their own resources and organization, for the interests of the state. That explains hostile rhetoric by politicians, the relatively high number of people involved, as well as lack of interest by the state to identify the attackers.
Unfortunately, the analysis can not attribute the attacks to any specific person, organization, or state. Instead, I find that of the three hypotheses considered, only the information operation scenario was plausible.
In hindsight, I do not consider it a very good paper, as it provides no definitive answer and devotes more detailed analysis to one of the hypotheses. In addition, I had just started my research on the topic, so my understanding of concepts like cyber militias and People's War was still very tentative. On the other hand, even though I notice many things I would write differently today, the conclusion would still remain the same.
Labels:
cyber conflict,
cyber militia,
ECIW,
paper
Subscribe to:
Posts (Atom)