Showing posts with label Cyberwarfare. Show all posts
Showing posts with label Cyberwarfare. Show all posts

Thursday, January 12, 2012

Should There Be a Cyberwar Treaty, Part 2

In my previous article on whether there should be a cyberwar treaty, I argued that Cyberwar wasn’t like other types of conflict, and that it wasn’t likely that a treaty would ever happen.
Being a lawyer, I like to play devil’s advocate, so here’s a different perspective.


Jeffrey Carr, in his new edition of “Inside Cyber Warfare” says that there are currently 28 nation states that have cyber warfare capabilities. Does the rapid spread of Cyber Warfare capabilities mean that there should be a treaty? There are major differences in how Cyber conflicts would take place versus other types of conflicts. For example, unlike physical confrontation, any Nation in the world can attack any other Nation directly or indirectly. In addition, rogue political parties or factions within a nation can take actions that don’t necessarily represent the country’s views as a whole. Do the different dynamics of Cyber Warfare warrant a treaty? Does the amount of damage that can be caused by Cyber Warfare relative to the cost of hacking warrant a treaty?


How do we distinguish between Cyber Crime and Cyber Terrorism or Cyber Warfare? I think this is where progress is most likely to be made with any Cyber Treaties. In order to successfully track the global criminal, there needs to be a global network of cooperation between legal systems on a scale that doesn’t exist today. After 6,000 credit cards were stolen, the Israeli Government declared that this was an act of terrorism. Is that an overreaction? Should the Israeli Defense Forces respond by hacking the hacker?


Shouldn’t we be focusing on prevention? How much is law enforcement willing to engage with businesses and individuals to protect their information? How do we know when an incident of hacking should be escalated from being a law enforcement matter to being a national security matter?


Cyber Criminals can automate crime. They can commit hundreds of crimes per second, and in fact they can perpetrate multiple of types of crimes all at the same time. Law Enforcement can’t automate catching criminals, prosecuting them, or incarcerating them. This is necessarily done one criminal at a time. Law Enforcement will always be slower than Cyber Criminals.


There are other types of warfare that do have treaties. The Geneva Convention covers many aspects of physical confrontation, but there has never been a formal international espionage treaty, which Cyber Warfare is more analogous to. This isn’t to say that this isn’t a great time to start.


One might ask, what other organizations are there that the 28 Cyber Warfare Club members already belong to? Interpol is one example. InterPol, has a staff of about 600 and a budget of 80 million. In contrast, the FBI has a staff of 35,500 and a budget of 8 billion. To me, this means by necessity, cybercriminals will go global to reduce their risk from being caught domestically by the biggest law enforcement agency in the world.


The lowest hanging fruit for a Cyber Security Treaty, then, is probably Cyber Crime, not Cyber Warfare. Countries could coordinate their Cyber Crime efforts, which makes a lot of sense, especially in a global economy.


A Cyber Warfare treaty could address analogs in Cyber Security similar kinds of things that are already addressed in the Geneva Convention. For example:



  • Cyber Attacks should not be targeted at activities that kill non-combatants (like targeting commercial airlines.)

  • Cyber Attacks should not deprive individuals of a fair trial if accused of a war crime.

  • Cyber Attacks should not target Hospitals.

  • Cyber Attacks should not target biological or nuclear weapons storage facilities.

Even these few examples create their own problems, however. What if, for example, a Nation State attacks a biological weapons or nuclear weapons production facility (as was the case with Stuxnet)? Does this actually help enforce the Geneva Convention? What if there is a danger to civilians around where these facilities are located?


At least one Cyber Warfare treaty was created last year. The ANZUS treaty between Australia and America was extended to include Cyber Attacks. If one country is attacked, then it is considered to be an attack on both. It might be likely that other alliances will consider similar extensions this year (NATO, the UN, etc.).

Friday, October 7, 2011

Cyberattack on Predator Drones?

Wired's Danger Room points out that US Predator and Reaper drones have been under attack by a computer virus:

http://www.wired.com/dangerroom/2011/10/virus-hits-drone-fleet

To date, the virus has only apparently been logging the keystrokes of the operators. From the article, I get the impression that it is the operators workstations and not the drones themselves that are the subject of the attack. Wasn't this how computers took over the world in Terminator 3? Or was that Terminator 4? I can never remember.

Monday, August 15, 2011

Should There Be a CyberWar Treaty?, Part 1

The Department of Defense released their Strategy For Operating In Cyberspace in July. In the document, they add Cyber to the traditional 4 domains...Land, Sea, Air, and Space.


This paper raises the question, at least in my mind: Should there be a Cyberwarfare treaty? I think the short answer is a definite “Maybe.”


I think a longer answer is that a arms treaty, like chemical or nuclear, is meant to deter the production of those types of weapons by government entities. Even if such a treaty were to be ratified, it would not stop other entities, whether commercial, criminal, or private from creating the same.


Similarly, all computer software has a shelf life, and this is also true for computer viruses. A hacker creating a computer virus is reliant upon an operating system. When those operating systems are updated, patched, or replaced, the virus ceases to have value. This is not true for other types of arms control. A 50 year old nuclear warhead is still dangerous.


What would such a treaty say? Should it be specific to the types of code that shouldn’t be written? Should it ban countries from producing soldier-hackers? Should it create an outright ban on the types of computer warfare that are not allowed? Should there be a Geneva Convention for the Internet?


All these conventions don’t fit the makeup of the internet. This is the internet where companies and technologies, whole computer languages, have lifecycles measured in months, not years. Assuming that a written treaty could apply is a misunderstanding of how the Internet is governed. Every aspect of the internet is governed by social convention, software licenses, and terms of service. These conventions necessarily change very quickly over time. Not to mention that even if such a treaty could be ratified, it would be obsolete by the time the ink was dry.


It would be great if Governments were willing to commit to one another that they won’t attack each others nuclear reactors with computer viruses. Jails. Air traffic Control systems. This misses the point of the greatest protection we already have…the one that worked throughout the cold war…mutually assured destruction. Because of Globalization, an attack on the US, would have immediate and drastic economic consequences for every other nation state in the world. Even a small scale attack on a major country would have similar consequences…given the amount of damage that the world has felt the problems in Ireland, Greece, and Portugal. And there is no reason to think that an attack would be limited to only one country at one time. If such an attack were to take place, it would be just as easy to attack everyone that is against your particular point of view.


A treaty like this would probably be unnecessary given current Alliances.


The best idea for a treaty like this would be a world wide treaty that includes all major players to share resources, visibility, intelligence, to protect critical infrastructure against non-state actors. This would be very similar to how many organizations as well as state governments have developed inter-organizational Information Security Advisory Councils to share real time threat information. Some large ISPs like AT&T and Verizon are offering this kind of real time threat monitoring from a world-wide perspective, so it would be a huge step in CyberSpace if governments took the same measures.


Click here for part 2 of my series on Cyber Warfare Treaties.

Monday, August 8, 2011

Cyberwar - Cyber Arms Dealers

Business Week has a nice article on the Cyberwarfront arms race:

http://www.businessweek.com/printer/magazine/cyber-weapons-the-new-arms-race-07212011.html

I think the most interesting part about the article is the idea of a Cyber "Arms Dealer". This makes me wonder what other analogs to traditional warfare might be out there... Mercenary Hackers?


Thursday, July 21, 2011

Barack Obama's Audacity of Hack, Chapter One

In May, the White House released a comprehensive proposal for a number of CyberSecurity measures. Unlike most of the other legislation proposed that focuses on Data Breaches or Do-Not Track. The White House proposal has 6 different sections that include changes to Homeland Security CyberSecurity as well as coordination of CyberSecurity between agencies.



  • Data Breach Notifications


  • Homeland Security CyberSecurity Authority and Information Sharing


  • CyberSecurity Regulatory Framework for Covered Critical Infrastructure


  • Coordination of Federal Information Security Policy


  • Personnel Authorities Related to CyberSecurity Positions


  • Preventing Restrictions on Data Center Locations


At 52 pages, the entire proposal is very dense, which makes me think this could be a sequel to Obama’s second book, the Audacity of Hope. The proposal, which I’ve nicknamed the Audacity of Hack, is interesting at points and surprising at others. I still think it is very "hopeful" to think that any of this legislation will passed this year, but hopefully there will be some progress. This will be a multi-part series looking at the proposal.


The first thing that strikes me is how different all the data breach proposals are. The White House may well be the most conservative of all the proposals.


The average max penalty for a data breach for the House of Representatives proposals is $3.8 million. The average max penalty for a data breach for the Senate is nearly double that at $7.2 million. The senate is also much higher for the daily average penalty at $12,333 versus $7,333 for the house.

Tuesday, July 5, 2011

War Powers Resolution and Cyberwar

If you've been following the war in Libya and the Obama's report to Congress in June, you'll know that the administration is claiming that our military actions in Libya are not covered under the War Powers Resolution which would require them to be terminated after 60 days. To get around this window, there must be an authorization for the use of military force by Congress or a declaration of war.

The reasoning in the White House report is basically that since the action in Libya involves drones, no soldiers are being put in danger, so the War Powers Resolution doesn't apply. The reasoning also follows that we are acting in Libya under limited circumstances, only going after specific targets.

What does this have to do with Information Security you ask? Since Clinton ignored the Resolution in 1999, and other presidents have argued that the War Powers Resolution is unconstitutional, the conspiracy theorist in me wonders if the intent in this report wasn't to set a precedent in order for future actions to follow the same model. It seems to me that the same reasoning could be applied to Cyberwarfare. Soldier/Hackers are essentially the same as drone pilots. Cyberwar, if such a thing ever happens, will also most likely be fought in small theaters and in limited circumstances...not an all out world Cyberwar. Cyberwar actions would by definition also only be directed against specific types of infrastructure.