Showing posts with label military; computers. Show all posts
Showing posts with label military; computers. Show all posts

Thursday, August 14, 2008

Cyberwar!

Cyberwar is real. It’s official, we now have another battlespace besides the sea, the ground, the air and space. The internet is now a battlefield. According to a NY Times report, someone was attacking Georgia’s internet infrastructure with denial of service attacks. (A denial of service attack occurs when a website is overwhelmed with coordinated barrages of requests. The website cannot process all the requests, so it overloads and shuts down. Service denied.) No one knows exactly who was behind the attacks, which happened in late July and lasted only about 24 hours, although there is some speculation that the July attacks were a “dry run” for the more extensive cyberattacks that happened as the violence in Georgia escalated earlier this week.

One internet security expert told the NY Times that his group had been tracking “botnets” (a malicious program that blasts streams of useless data) were staged in preparation for attack over the weekend; probably by a “shadowy” criminal gang out of St. Petersburg known as the Russian Business Network. The botnets were activated shortly before the Russian airstrikes on Georgia began on Sunday. Although everyone cautions against jumping to conclusions, the attackers used the same tools and commands as those known to come from the Russian Business Network and were launched from computers the organization controls.

Since Georgia doesn’t rely heavily on its relatively small internet infrastructure, the cyberattacks didn’t have a huge effect. The attacks did, however, shut down a number of government websites which limited the Georgian government’s ability to communicate with its citizens. The attacks also focused on media, communications, and transportation sites. The National Bank of Georgia had their website defaced. Attacks like those on Georgian sites would have had more severe consequences, if they had been directed at an internet-dependent country (like the US) where transportation, electricity, water, banking, and media outlets are all tied to the internet.

This is the information age. Computers and the internet are here to stay. They make our lives easier; but they also create another “center of gravity” that is subject to attack. Recognize it and deal with it. Cyberwar is here to stay.

Unfortunately, according to a report from the Associated Press, the Pentagon has put the Air Force's planned Cyber Command on hold and may end up doing away with it altogether. The Cyber Command was planned as the entity that would coordinate computer network defense, and possibly computer network attacks, much the same way as the Air Force's Air Combat Command coordinates air defense and attacks from the air for theater commanders. I agree with former-Air Force Secretary Wynne who said that, given the use of cyberattack during the action in Georgia, "this is a very poor time to send a signal that the United States is not interested in focusing on warfighting in the cyber domain."

Information as Propaganda

Kat (who writes at Castle Argghhh, a prominent milblog) has written a wonderful post discussing propaganda. Her main point, that “all information is propaganda. Official information is official propaganda. Thus, it always deserves to be challenged. Paraphrasing Socrates, question everything” is extremely well taken. She also points out that:

In the end, we decide what we make of information, but leaving information unchallenged means that we leave perceptions unchallenged. Milblogs, political blogs and others came to prominence because people were looking for missing information. Because we did not believe we were getting a complete picture or story. Because we believed that without some sort of expertise or background information, the real story was missed for sound bites or two sentences that basically said: bomb today, three soldiers killed. Left to itself and to ourselves, we would have been led to believe, purposefully or not, that the only thing happening in Iraq or Afghanistan was bombs and death.

What is a military blog or milblog? It is a place to get direct information or stories from men and women in the military or retired from the military or with connections to the military. Mostly without any filters. When those blogs proved accurate and the people legitimate, their voices were trusted more than any other media source to be the gage by which to evaluate progress. We linked to those stories to persuade ourselves and others of the facts or views being different than those presented.

We were and are, in fact, conducting a very small part of the information war whether that is our original intent, current purpose or accepted outcome. Information dissemination is information warfare.

All information is meant to inform and persuade. Thus, all information becomes propaganda. All official information is official propaganda. Regardless of who it comes from or how trusted the source. Looking at information to evaluate its persuasive purposes and capability is not paranoid any more than evaluating the purpose of a commercial for its ability to sell a product is paranoia. It does not entail the same potential risk to national or international actions, but it is the same concept.


Right on Kat!

Thursday, May 15, 2008

Carpet Bombing in Cyberspace?

Col Charlie Williamson, an AF judge advocate, wrote an interesting article titled Carpet Bombing in Cyberspace published in the on-line version of the Armed Forces Journal. In it, Col Williamson calls for a military botnet to act, when necessary, as an offensive weapon against computer networks that may be attacking ours. We’re not just talking about your garden-variety hackers here, characterized by the caricature of the pale-faced geek hiding out in his mom’s basement trying to find the backdoor into the Pentagon’s super secret supercomputer just to say “Kilroy was here.” We’re talking about either state-sponsored or terrorist-sponsored cyberthreats, who are extremely sophisticated in their means and methods. It is this type of cyberattack for which Col Williamson proposes his botnet cyberbomber. Personally, I think he’s on to something.

Col Williamson uses a history lesson to show that our current methods of protecting our computer networks have become outdated. He likens our computer networks firewalls, passwords, and gateways to a medieval castle’s walls, moats and drawbridges. Like a castle fortress, a computer’s protections can help keep out intruders, and may serve as a minor deterrent, but those protections, according to Col Williamson, do not “strike the enemy while he is still on the move.”

Col Williamson believes we need to have the offensive capability to do so, as a part of a scheme of defense in depth. That idea is simple; you defend in close by taking the fight to the enemy offensively. For defending our most sensitive computer networks, Col Williamson proposes a botnet. A botnet is a “collection of widely distributed computers controlled from one or more points.” He suggests we use all those old and outdated computers the DoD is constantly replacing. Good idea? I think the concept is good, but as with everything else, the “devil is in the details.” There would have to be a great deal of engineering done by a lot of very smart people. There would have to be a lot of discussion on when, and how, to deploy this potential weapon. Most critically, there would have to be the willingness to accept what would most likely be a high political cost of using a weapon like this.

In some ways, that is the most interesting question: are there some computer systems (and what are they) that are so important that we have to risk the political implications of using an offensive botnet cyberspace weapon to protect them, even at the expense of losing political capitol? I’m certain there are some “red line” computer systems out there that should not be crossed. But if we do field, then use, this type of weapon the political backlash would be huge; particularly if some of the computer systems used by the “adversaries” are located in a putative-allies’ country. Could you imagine the uproar. . . . What would the U.N. say? What would France say?