Is the U.S. engaged in a “cyber war?” Until recently the identity of the perpetrators of cyber-attacks against U.S. networks, infrastructure and the military were clouded in suspicion and not spoken of out loud. There has been much speculation about cyber war or a cyber-Pearl Harbor, but no official declaration of what constitutes cyber war or naming of names, until now.
In March, General Keith Alexander, speaking before Congress, and in May, Secretary of Defense Leon Panetta, during an interview with ABC News, outwardly named China as the main perpetrator and identified criteria for defining cyber war.
General Alexander, the Director of NSA and CYBERCOM commander, stated, “China is stealing a ‘great deal’ of military-related intellectual property from the United States and was responsible for last year's attacks against cyber-security company RSA . . . .”
Secretary of Defense Panetta said, “Well, there’s no question that if a cyber-attack, you know, crippled our power grid in this country, took down our financial systems, took down our government systems, that that would constitute an act of war.”
Over the last year the Department of Homeland Security (DHS) has voiced their concern over the vulnerability of our critical infrastructure, oil and gas refineries, electric grids and nuclear reactors, to potential cyber-attacks.
If you are not fully convinced of the threat, consider the “Shady RAT (remote access tool)” report by McAfee wherein the firm identify companies and governments which recently discovered that hackers have been in their networks for the last five or six years -- undetected. One might conclude that a clear picture is emerging, but is it?
During the Cold War, when government secrets were stolen, it was treated as espionage or spying. Remember all of the spies tried for espionage: Aldrich Ames, Robert Hansen, the shoot down of Gary Powers and the U2 spy plane over the USSR. What if a nation placed “sleeper cells” in its adversary’s country ready to attack critical infrastructure if a war broke out? Would this be considered spying and part of the “cat and mouse” game or grounds for a retaliatory strike?
Does the fact that these activities can now be accomplished electronically from the safety and comfort of your own nation change the playing field?
At the time, we probably considered the flights of the U2 relatively safe since it flew above the threat zone of anti-aircraft guns.
Does stealing terabytes of military secrets or planting logic bombs in critical infrastructure (to be launched in a moments’ notice to disable the infrastructure) cross the line from espionage to war or is it merely an “act of aggression”?
This and many similar scenarios are now the new normal and must be defined as nations and the international community grapple with technology and current and future capabilities. Where should the line be drawn?
Do we just accept, that an adversary, via computers, can now access and potentially steal, manipulate, or destroy information and functionality, or should nations aggressively draw the line now and openly retaliate in protest?
Obviously, as Secretary of Defense Panetta stated, if someone or some nation disrupt critical infrastructure, deny critical communications, or blind a military defense system, the line has likely been crossed.
Certainly, defacing a website does not even come close to being an act of war or aggression.
But what about stealing terabytes of military secrets to later be used to disable your adversary’s defenses? Quite possibly!
For now, the line will be defined by the reactions of various nations faced with cyber-attacks. If a nation does nothing or retaliates with a similar attack, e.g. theft for theft, then a line has been drawn and a precedent set.
A similar problem is the issue regarding Iran and nuclear weapons. Is Iran’s pursuit of nuclear weapons and statements attributed to them about annihilating Israel and the West enough provocation to take aggressive action to prevent them from obtaining a bomb?
Clearly no one wants to escalate the situation but most agree something must be done before it is too late.
Similarly, in the cyber arena, all interested parties are reacting very cautiously in their response to cyber-attacks, likely to avoid escalation and the setting of precedence.
In the Estonian and the Georgian conflicts the reaction was to block, clean up, and speculate about who may have launched the attacks and only the media claimed that a cyber war might be taking place. Not until recently has one nation, e.g. the US, been so vocal about who is using cyber espionage and attacks to invade and plague their networks.
David Willson is an attorney and cyber security expert for CISSP, Security +, Titan Info Security Group. For more visit www.titaninfosecuritygroup.com .