Posts

Showing posts matching the search for cyberwar

Review of Martin Libicki's Cyberdeterrence and Cyberwar

Image
Amazon.com just posted my three star review of Martin Libicki's Cyberdeterrence and Cyberwar . I've reproduced the review in its entirety here because I believe it is important to spread the word to any policy maker who might read this blog or be directed here. I've emphasized a few points for readability. As background, I am a former Air Force captain who led the intrusion detection operation in the AFCERT before applying those same skills to private industry, the government, and other sectors. I am currently responsible for detection and response at a Fortune 5 company and I train others with hands-on labs as a Black Hat instructor. I also earned a master's degree in public policy from Harvard after graduating from the Air Force Academy. Martin Libicki's Cyberdeterrence and Cyberwar (CAC) is a weighty discussion of the policy considerations of digital defense and attack. He is clearly conversant in non-cyber national security history and policy, and that knowl...

Response to Marcus Ranum HITB Cyberwar Talk

Image
Many readers have been asking me to comment on Marcus Ranum 's keynote titled Cyberwar is Bullshit at Hack In The Box Security Conference 2008 - Malaysia . (What a great conference; I think we are seeing the Asia-Pacific area really grow its digital security community. You can access the conference materials here . I'd like to point out my friend CS Lee spoke about NSM at the event.) The article Don’t waste funds preparing for cyberwars summarized Marcus' talk as follows: The billions of dollars spent on researching cyberwarfare can be put to better use because cyberwar is never going to be as effective as conventional war, said an IT ­security expert. Marcus Ranum, chief security officer of Tenable Network Security said cyberattacks aren’t a good force multiplier in an actual war. Many people, he said, talk about cyberspace as if it can be a new form of battlefield but this is not possible because you can’t occupy and hold cyberspace as you would a piece of enemy te...

China's View Is More Important Than Yours

Image
In my post Review of Dragon Bytes Posted I wrote the following to summarize analysis of Chinese thoughts on cyberwar, as translated from original Chinese publications: The Chinese military sees Western culture, particularly American culture, as an assault on China, saying "the West uses a system of values (democracy, freedom, human rights, etc.) in a long-term attack on socialist countries ... Marxist theory opposes peaceful evolution, which... is the basic Western tactic for subverting socialist countries" (pp 102-3). They believe the US is conducting psychological warfare operations against socialism and consider culture as a "frontier" that has extended beyond American shores into the Chinese mainland. The Chinese therefore consider control of information to be paramount, since they do not trust their population to "correctly" interpret American messaging (hence the "Great Firewall of China"). In this sense, China may consider the US as the...

Cyberwar Is Real

Image
A number of people, inside and outside the security world, think that any discussion of real threats is a manufactured justification for intrusive government action. Their argument is simple. The government wants to control the people, or obtain a resource, or pursue some objective that could not be reasonably achieved if transparently presented to the citizenry. The government "propaganda machine," sometimes in coordination with "the media" and "big business," "manufactures" a "crisis" whose only solution is increased government power. The people acquiesce in order to preserve their safety, and the government achieves its objective. As a result, those who see the world in this manner treat any discussion of real threats as step 2 in this process towards decreased liberty via increased government power. Those who seek to inform the citizenry of real threats are dismissed as sowing "FUD." This is a tragedy, because it means ...

Why Russia and China Think We're Fighting Cyberwar Now

Image
Thanks to the Team Cymru news feed for pointing me to Emerging Cyberthreats and Russian Views on Information Warfare and Information Operations by Roland Heickerö of the Swedish Defence Research Agency . I found this content in pages 23-24, "Differences and similarities between Russian, US and Chinese views on IW," to be really interesting: In order to understand the Russian view in a wider context, a comparison has been made with Russia’s most important competitors – the USA and China – and their approach to information operations... All three countries agree on the important role information has in today’s conflicts. Over time its importance will grow. The USA has influenced the mindsets of the others, especially regarding ideas about information superiority and information dominance, as well as command and control warfare. Information adds a new dimension to warfare and IW weapons could be used offensively and defensively to protect a country’s own information resources ...

A Little More on Cyberwar, from Joint Pub 1

Image
Everyone's been talking about cyberwar this week, thanks in part to the Economist coverage. Many of the comments on my posts and elsewhere discuss the need for definitions. I thought it might be useful to refer to an authoritative source on war for the United States: DoD Joint Publication 1: Doctrine for the Armed Forces of the United States ( .pdf ), known as JP 1. Incidentally, back in 1997 as an Air Force 1Lt straight from intelligence school, I worked on doctrine publications like this for Air Intelligence Agency, specifically the early doctrine on information warfare, like the August 1998 publication of Air Force Doctrine Document 2-5: Information Operations ( .pdf ). What does JP 1 say about war? War is socially sanctioned violence to achieve a political purpose . In its essence, war is a violent clash of wills. War is a complex, human undertaking that does not respond to deterministic rules. Clausewitz described it as “the continuation of politics by other means” [Boo...

Why Neither the US Nor China Admits Cyberwar

Image
Why won't the US or China (or even Russia) admit we're engaged in cyberwar? I have a theory based on historical precedent, involving all three countries: the Korean War. Since my time in the Air Force I knew that US pilots had directly engaged Russian pilots in the skies over Korea in the 1950s. This was an "open secret." Recently I watched the NOVA episode Missing in MiG Alley , which confirmed this fact: NARRATOR: For 40 years, Russia's role in Korea remained a secret. Now, one of the Soviets' top aces, Sergei Kramarenko, can finally talk about his exploits in MiG Alley. SERGEI KRAMARENKO: (Russian dialogue) INTERPRETER: It was a secret mission, neither before nor after the war were we allowed to reveal that we were going to fly for the North Koreans...against the Americans. It was top secret. SERGEI KRAMARENKO: (Russian dialogue) INTERPRETER: We were told that in case we were shot down beyond the front line we had to kill ourselves. Not to surrender wa...

Taking the Fight to the Enemy Revisited

I just read Bruce Schneier's essay Security Matters: Vigilantism Is a Poor Response to Cyber Attack . He's commenting on the news I discussed in Taking the Fight to the Enemy : As reported in Federal Computer Week, Cartwright said: "History teaches us that a purely defensive posture poses significant risks," and that if "we apply the principle of warfare to the cyberdomain, as we do to sea, air and land, we realize the defense of the nation is better served by capabilities enabling us to take the fight to our adversaries, when necessary, to deter actions detrimental to our interests..." Of course, the general is correct. But his reasoning illustrates perfectly why peacetime and wartime are different, and why generals don't make good police chiefs. A cyber-security policy that condones both active deterrence and retaliation -- without any judicial determination of wrongdoing -- is attractive, but it's wrongheaded, not least because it ignores the line...

National Security Strategy is Empty on "Cyberspace"

Image
The new National Security Strategy (.pdf) says the following about "cyberspace": Secure Cyberspace Cybersecurity threats represent one of the most serious national security, public safety, and economic challenges we face as a nation. The very technologies that empower us to lead and create also empower those who would disrupt and destroy. They enable our military superiority, but our unclassified government networks are constantly probed by intruders. Our daily lives and public safety depend on power and electric grids, but potential adversaries could use cyber vulnerabilities to disrupt them on a massive scale. The Internet and e-commerce are keys to our economic competitiveness, but cyber criminals have cost companies and consumers hundreds of millions of dollars and valuable intellectual property. The threats we face range from individual criminal hackers to organized criminal groups, from terrorist networks to advanced nation states. Defending against these threats to ou...

PBS Frontline Program on "Cyberwar"

This story summarizes a speech made by John Arquilla , co-director of the Center on Terrorism & Irregular Warfare at the Naval Postgraduate School in Monterey. Arquilla advocates building a "Corp of Hackers," saying "We have to re-examine that punitive approach to the hacking community, and try, instead, to turn it into something that can be useful, and perhaps even to reform some of these people away from their own illegal actions." I'd never heard of this guy, and was skeptical when the article stated "Arquilla... helped develop the offensive cyber weapons used by the U.S. military in Kosovo, in Afghanistan and in the Gulf War." Google led me to this PBS interview , where we learn Arquilla helped build the Joint Surveillance and Target Acquisition Radar System while working for Central Command during the first Gulf War. JSTARS isn't what I'd call an "offensive cyber weapon," at least as far as computers go. Still, this art...

China Cyberwar, or Not?

Image
I've been writing about the Chinese threat for a while. I was glad to see Professor Spafford chime in with Who is Hacking Whom? : It remains to be seen why so many stories are popping up now. It’s possible that there has been a recent surge in activity, or perhaps some recent change has made it more visible to various parties involved. However, that kind of behavior is normally kept under wraps. That several stories are leaking out, with similar elements, suggests that there may be some kind of political positioning also going on — the stories are being released to create leverage in some other situation. Cynically, we can conclude that once some deal is concluded everyone will go back to quietly spying on each other and the stories will disappear for a while, only to surface again at some later time when it serves anoher political purpose. And once again, people will act surprised. If government and industry were really concerned, we’d see a huge surge in spending on defenses and...

Mutually Assured DDoS

Image
Thanks to several of you for asking for my opinion of the article Carpet bombing in cyberspace: Why America needs a military botnet by Col. Charles W. Williamson III. I'd like to cite a few excerpts and comment directly. The world has abandoned a fortress mentality in the real world, and we need to move beyond it in cyberspace. America needs a network that can project power by building an af.mil robot network (botnet) that can direct such massive amounts of traffic to target computers that they can no longer communicate and become no more useful to our adversaries than hunks of metal and plastic. America needs the ability to carpet bomb in cyberspace to create the deterrent we lack... This is interesting. Why do we need to project force in cyberspace to deter our enemies? Cyberwar is usually cited as a means of conducting asymmetric warfare, meaning one side is much weaker than other in conventional means. Cyberwar is expected to be conducted against US assets (critical infras...

The Toughest Question in Digital Security

Image
The toughest question in digital security is "who cares?" The recent Tweet by hogfly (@4n6ir) made me ponder this question. He points to an Aviation Week story by David Fulghum, Bill Sweetman, and Amy Butler titled China's Role In JSF's Spiraling Costs . It says in part: How much of the F-35 Joint Strike Fighter’s spiraling cost in recent years can be traced to China’s cybertheft of technology and the subsequent need to reduce the fifth-generation aircraft’s vulnerability to detection and electronic attack? That is a central question that budget planners are asking, and their queries appear to have validity. Moreover, senior Pentagon and industry officials say other classified weapon programs are suffering from the same problem. Before the intrusions were discovered nearly three years ago, Chinese hackers actually sat in on what were supposed to have been secure, online program-progress conferences, the officials say. The full extent of the connection is stil...

2014-2015 Professional Reading Round-Up

At an earlier point in my career, I used to read a lot of technical security books. From 2006 to 2012 I published a series of Best Book Bejtlich Read posts. Beginning in 2013 I became much more interested in military-derived strategy and history, dating back to my studies at the Air Force Academy in the early 1990s. I stopped reviewing books at Amazon.com and didn't talk about my reading. Last week I read Every Book I Read in 2015 by T. Greer, which inspired me to write my own version of that post. I have records for 2014-2015 thanks to a list I keep at Amazon.com. I'm modifying Greer's approach by not including personal reading, but I am adopting his idea to bold those titles that were my favorites. The following are presented such that the most recently read appears first. 2015 Reading (37 books): Restraint: A New Foundation for U.S. Grand Strategy   by Barry R. Posen  *(I'm joining the "restraint" school. I will say more about this in 2016.) Le...

Reference: TaoSecurity Press

I started appearing in media reports in 2000. I used to provide this information on my Web site, but since I don't keep that page up-to-date anymore, I decided to publish it here. As of 2017 , Mr. Bejtlich generally declines press inquiries on cybersecurity matters, including those on background. 2016 Mr. Bejtlich was cited in the Forture story Meet the US's First Ever Cyber Chief , published 8 September 2016. Mr. Bejtlich was interviewed for the NPR story Cybersecurity: Who's Vulnerable To Attack? , aired 30 July 2016. Mr. Bejtlich was interviewed for the Washington Post story It’s not just the DNC; we all send emails we probably shouldn’t , published 25 July 2016. Mr. Bejtlich was interviewed for the New Scientist story NATO says the internet is now a war zone – what does that mean? , published 22 June 2016. Mr. Bejtlich was interviewed for the Military Times story The Pentagon's controversial plan to hire military leaders off the street , published 19 June...