![]() |
| The first multi-expert blog dedicated solely to counterterrorism issues, serving as a gateway to the community for policymakers and serious researchers. Designed to provide realtime information about terrorism cases and policy developments. |
Cyberwar RealitiesBy Aaron Mannes
This morning, The Washington Times ran an op-ed on cyberwar I co-wrote with my friend (and former boss) Jim Hendler. Much has been written about cyber-war, but very little of it is grounded in reality. Many over-hype the issue while others discount it completely. Much of the misinformation about cyberwar revolves around denial of services attacks, which are serious criminal activity but not much of a national security concern - we've written on this topic in the wake of Russian conflicts with Estonia and Georgia. Here we try to inject a bit of sober and informed reason into the discussion.
Aaron Mannes and James Hendler The denial-of-service (DoS) attacks that started on July 4 garnered typical headlines about cyberwar, but in fact, from a technical standpoint, those "attacks" may be the opposite of real cyberwar. A much less noticed report in Israel's leading daily, Ha'aretz, on Israel's operations against Iran's nuclear program may give greater insight into how cyberwar actually will work. It is no secret that several countries, including the United States, China, Russia and Israel, have examined cyberwar capabilities. What those capabilities might be or how a cyberwar might look are shrouded in mystery. The denial-of-service attacks that made headlines are not it. Those attacks are nothing more than the sending of enormous numbers of requests to servers, preventing Web sites from responding to legitimate traffic and interfering with e-mail. Competent information-technology professionals usually can mitigate these attacks, and even when successful, their impact -- from a national security standpoint -- is marginal. The DoS attacks are carried out by botnets, thousands of compromised computers that can be commanded to simultaneously send e-mails or visit a Web site. The botnets are built using malware that attacks individual computers, often simply taking advantage of software that has not downloaded current security patches. Computers linked to government agencies have been compromised and have become part of botnets -- but this does not necessarily have tremendous security implications. Real cyberwar may require the opposite of the skills required for the DoS attacks that make headlines. According to the article in Ha'aretz, Israeli intelligence has sought to systematically insert malware that can damage information systems within the Iranian nuclear program. It is believed those systems are not connected to the broader Internet and that the malware is inserted into equipment sold to the Iranian government. This is the probable future cyberwar. Modern societies are complex networks of people, information systems and equipment. Enormous advantages will be obtained by powers that can quickly identify and neutralize critical nodes within the systems. Read the complete article here.
|