Showing posts with label cyberattack. Show all posts
Showing posts with label cyberattack. Show all posts

Monday, December 25, 2023

Predatory Sparrows in Iran

 

In the United States, fears of widespread hacking causing major national disruptions have so far been mostly unfounded.  There have been isolated foreign-based attacks on infrastructure here and there, but no one has so far been able to disrupt an important nationwide system deliberately for political reasons. 

 

Iran hasn't been so fortunate.  A hacker group calling itself Gonjeshke Darande, which translates as "Predatory Sparrow," claims responsibility for knocking out about 70% of Iran's gas stations in the last few days, according to an Associated Press report.  A related CNBC piece connects the Predatory Sparrows with Israel, although the connection is unconfirmed by the group. 

 

This isn't the first time the Sparrows have mounted cyberattacks in Iran.  The CNBC report recounts a fire in an Iranian steel plant in June of 2022 which the group claimed to have started.  The hackers say that they try to avoid inconveniencing civilians, but having 70% of a country's gas stations shut down is more than an inconvenience.  Iran reportedly disconnected most of its government infrastructure from the Internet after the Stuxnet virus damaged uranium-enrichment centrifuges in the late 2000s, but the hackers have evidently found a way around that obstacle.

 

Iran has been sanctioned for its support of terrorism in other countries, and these sanctions prevent hardware and software updates from being installed that might otherwise help the country defend itself against attacks such as these.  Reportedly, software pirating is widespread, but pirated software typically loses manufacturer support for security updates, with the result that such systems are comparatively easy to invade for nefarious purposes.

 

Iran is widely believed to be the power behind Hamas, the group which mounted the October 7 attacks in southern Israel.  Engineering ethics always has to operate before a background of cultural and historical events.  An action which can be construed as ethical in wartime, at least by some people, would be considered highly unethical in peacetime circumstances. 

 

As large-scale hacks go, the Predatory Sparrows' shutdown of most gas stations, which isn't the first time they've done something like this, is not life-threatening, at least to most people.  In tweets, the group claimed to have warned emergency services in advance, and so they at least appear to be trying to avoid serious harm to civilians.  Their idea seems to be that if the people of Iran get fed up enough with issues like not being able to buy gas for a time, they will rise up and throw off the chains of the present regime.  And that might happen, but the ayatollahs in charge have endured much worse challenges up to now, and unless their grip on power gets a lot shakier, they will probably shrug off this cyberattack as easily as they did the others.

 

Cyberattacks are still new enough to count as a novel addition to the warmonger's bag of tricks.  As with other forms of warfare, its success depends on how well-defended the enemy is.  For whatever reason, the United States seems to be doing a better job at defending itself against hacks than Iran has.  I suspect a large factor in this difference has to do with the wide range of systems employed in the U. S. compared to more top-down-governed places like Iran.

 

I have no way of knowing for sure, but it wouldn't surprise me if nearly all the gas stations in Iran use the same kind of hardware and software.  That uniformity makes a system much easier to hack compared to an infrastructure built out of several different brands and designs of technology.  This is why theories of how a national election was allegedly hacked in many U. S. states hold so little water.  A hacker would have to master and invade dozens or hundreds of different systems and would have to gain access to literally thousands of machines through individual county election offices in order to swing millions of votes. 

 

While the rule can be extrapolated beyond its range of usefulness, it is true that in technological systems, diversity lends a kind of strength.  If one brand of system falls to a hacker, the others may not.  Iran would probably like to have a robust market for software, but sanctions and the general economic climate have militated against that.  So in addition to having to limp along with outdated machinery, they suffer from Predatory Sparrows who take advantage of the vulnerabilities of outdated and pirated software.

 

What can the U. S. learn from this situation?  At least two things.

 

First, money spent on cybersecurity is generally worth it.  Regular updates and security patches are simply good practice, and most responsible organizations follow these guidelines. 

 

Second, in technological diversity there is strength.  Highly centralized national mandates dictating the details of any kind of cyber-infrastructure are liable to produce security vulnerabilities.  The software industry is still one of the most lightly-regulated ones in our economy, and the resulting variety and dynamism is a security advantage as well as providing customers with the latest and greatest, other things being equal.  Any attempt by government to do heavy-handed regulation is likely to lead to a uniformity that would not be in the best interests of customers, and it might make life easier for predatory sparrows and their like.

 

It's too bad that Iranians are having to wait in long lines at the 30% of gas stations that still operate (a fraction apparently chosen deliberately by the hackers), but when your government fights a proxy war, you can expect the enemy to get back at it by both fair means and foul.  With cyberattacks, the line between fair and foul is especially fuzzy, and Iranians should be glad that the hackers are as relatively polite as they are.  Still, it's a pain, and we can long for a day when neither Iran nor Hamas nor Israel has to resort to hacking, because peace has at long last come to earth. 

 

And that's what Christmas is all about.  But that's a story for another time.

 

Sources:  The AP report "A suspected cyberattack paralyzes the majority of gas stations across Iran" appeared prior to Dec. 18, 2023 on the AP website at https://apnews.com/article/iran-gas-stations-cyberattack-a9ae33c352812e40ca3d255a2533fea9.  I also referred to a CNBC report at https://www.cnbc.com/2023/12/18/pro-israel-hackers-claim-cyberattack-disrupting-irans-gas-stations.html.

Monday, June 06, 2022

Cyberattack Forestalled—For a Change

 

This blog focuses on engineering ethics situations that make headlines.  And by the nature of what makes headlines, most of the time it's bad news.  But every so often, some disaster is narrowly averted instead of going ahead and killing people or causing damage, so today I'd like to look at a small but significant success story, as reported in a recent Associated Press item.

 

Back in 2014, a hacker and activist named Martin Gottesfeld got upset about a teenager under treatment at Boston Children's Hospital who was involved in a highly publicized custody battle.  Gottesfeld decided to use his hacking skills to jam up the hospital's computer networks with junk data that took two weeks to unsnarl and cost the hospital an estimated $600,000.  The FBI got involved in tracking him down and convicting him, and he was sentenced to ten years in prison.

 

This incident familiarized the Children's Hospital IT people with the FBI.  When the FBI learned last summer that agents apparently hired by Iran were planning a cyberattack on the hospital, the FBI supplied their IT people with enough defensive help to forestall the attempted attack.  This bit of good news was unveiled recently at a cybersecurity conference at Boston College by FBI Director Christopher Wray.

  

For every really bad engineering-related tragedy that hits the headlines, there are usually several other less harmful or even harmless incidents that go unreported, either because the results were not bad enough to make the news, or because someone fixed the problem before it got really out of hand.  The FBI's success in preventing Boston Children's Hospital from falling victim to Iranian-sponsored cyberterrorists is in this category. 

 

In today's hyperspeed news cycle, the traditional slant toward bad news that has existed ever since print media was invented has only gotten worse.  This means that most of what we learn about institutions of all kinds—government agencies, the legal profession, the medical profession, and even religious organizations—tends to be critical or derogatory in some way.

 

Now to some extent, that is as it should be.  One important function of a free press is to search out wrongdoing and incompetence and expose it to the light of publicity, where one hopes that the democratic process, or embarrassment, or something, will cause an improvement in the situation.  So it's only natural that editors choose stories about something going wrong over happy-clappy items that say how wonderfully some new product is working, or how some federal agency successfully rescued people from a disaster.  But some good news does get out anyway.

 

Specifically with regard to the FBI, its popularity among the public has shifted in recent years.  According to a 2019 Pew research poll, the percentage of Americans with a favorable opinion of the FBI remained remarkably constant among both Democrats and Republicans from 2010 to 2016, within a few percentage points of 70%.  But after that, partisanship began to show, with the percentage of Republicans favoring it dipping to about half, and the percentage of Democrats rising above 70%.  Still, on average, as of three years ago, the FBI was still favorably viewed by a majority of U. S. citizens, according to Pew.

           

We depend so much in complex industrial societies for the proper functioning of institutions that it's hard to imagine what we'd do if they broke down.  But there are a number of ways public institutions fail, and one of them is to lose the public's trust. 

 

Even if an institution's actual performance is just as good as it ever was, if somebody convinces a lot of people that the institution is untrustworthy, it's going to be harder for the institution to carry out its job.  On the other hand, prior good experience with an institution tends to carry forward favorably.

 

The Boston Children's Hospital is a case in point.  From the 2014 experience, it had a positive view of the FBI and probably some personal relationships that made it easy for the FBI to convince them of the seriousness of the recent Iranian threat.  Consequently, they took action that successfully prevented the attack. 

 

But they didn't have to take the FBI seriously, and if this had happened to an organization that either had no prior history with the FBI, or a negative one, the protective advice might well have been ignored, to the detriment of everyone involved.

 

Some of the largest technically-intensive institutions these days which have taken big hits in their public perceptions are the social-media firms:  Facebook, Google, Twitter, and company.  Elon Musk represents no one other than himself, presumably, but his recent move to buy Twitter and take it private is being applauded by those who feel that Twitter has been too high-handed in censoring and banning certain views and people from their system.

 

At the same time, social media, along with the way the Internet treats news in general, bear a lot of responsibility for driving a wedge between the public and all kinds of institutions, social media giants included.  Now that real-time feedback has been finely tuned to maximize "engagement," millions (billions, if you count global numbers) are constantly whipped into outrage about something, and that something usually involves some kind of public institution—if you broaden the definition of "institution" to include things like the Kardashians.

 

It looks like Aristotle's advice of finding a happy medium needs to be followed here.  All-good-news-only media are confined to totalitarian countries such as Russia, and that extreme is to be avoided.  But it looks like we may have something closer to the opposite extreme, an institution-corroding situation in which the only things you hear about the government, educators, legislators, media personalities, and churches is bad news. 

 

I think the real answer lies not so much in yet more government regulation, or eccentric billionaires taking media companies private, but in a more mature citizenry who will not let themselves be coerced into a kind of universal cynicism, but instead use the ancient virtues of justice and prudence to find out the truth amid the smog of disinformation and hype.  And achieving that maturity has to happen one person at a time. 

 

Sources:  The AP website carried the item about Boston Children's Hospital at

https://apnews.com/article/russia-ukraine-technology-health-middle-east-e4f8e7145e4b4447a331d4b0cc5a5bd3.  I also referred to the Pew poll report summarized at https://www.pewresearch.org/politics/2019/10/01/public-expresses-favorable-views-of-a-number-of-federal-agencies/. 

Monday, January 17, 2022

Ukraine Gets Cyberattacked Again

 

First, a little geography lesson.  Ukraine sits north of the Black Sea, bordering Poland, Hungary, and Romania on its west and surrounded by Russia to the north and east.  Like Poland, the Ukraine has been subjugated for much of its history by foreign powers—the old USSR for most of the twentieth century, and even by Lithuania back in the 1400's A. D.  But when the USSR collapsed, the Ukraine gained independence again.  It is the poorest country of Europe, but has rich farmlands, which is one reason why foreigners want to take it over.

 

If you've been paying any attention to world news, you know that Vladimir Putin has been saber-rattling about a possible invasion of Ukraine recently, massing 100,000 troops on the border between the two countries and ramping up his warlike rhetoric.  Russia has been chipping away at the country since at least 2014, when the pro-Russian President of Ukraine, Viktor Yanukovych, lost an election, and Putin invaded the Crimea, the peninsula that sticks out into the Black Sea and separates it from the Sea of Azov to its northeast.  Having succeeded in that, Putin has since been backing forces that have taken over portions of eastern Ukraine, and it appears that he would like nothing better than to welcome the entire country back to the domination of Russia.  So far, the government of Ukraine has had different ideas.

 

As part of Putin's campaign, a war that isn't quite a war, most authorities agree that Russian-based hackers mounted a cyberattack called NotPetya back in 2017.  It was aimed primarily at Ukranian institutions, but it also affected thousands of other systems as well.  The White House later estimated that NotPetya caused about $10 billion worth of damage worldwide. 

 

Now we come down to this week.  On Jan. 15, dozens of Ukrainian government computer systems were infected with malware disguised as ransomware.  An infected computer displayed a demand for a certain ransom to be paid in Bitcoin, but what really happened is that the malware "renders the computer system inoperable," ransom or no ransom. 

 

Microsoft issued a statement saying that they observed these attacks aimed primarily at Ukrainian government agencies and closely-allied organizations, and that they had issued updates that will address the problems.  But in the meantime, the Ukraine is suffering yet another cyberattack which appears to be instigated by Russia, although no firm evidence of the source has yet been forthcoming.

 

To my knowledge, nobody has actually died as a result of the most recent cyberattack on the Ukraine.  But to the extent that the public relies on computer-mediated government services, the consequences of a massive shutdown of government computers can range from the inconvenient to the life-threatening, in government-run hospitals, for example. 

 

In the logic of war, an enemy's assets are always a target, and now that computer networks and systems form so much of the infrastructure of modern life, they have become a uniquely vulnerable target.  Cyberattacks borrow from the fields of espionage, sabotage, and terrorism to create an insidious threat that knows no boundaries.  And defending against such attacks is a responsibility that is widely distributed among both public and private actors. 

 

All these features make cyberwarfare a different kind of thing from conventional warfare, and it is taking time for both military and civilian thinking to catch up to it. 

 

When this topic has come up in the past, I have taken the position that the U. S. military, in any event, seems to have an overly narrow focus on what cyberwarfare might amount to in the future.  While I am no technical expert in this area, I can see that even cyberattacks on U. S. organizations that have been definitely attributed to government-sponsored hackers in China or Russia do not seem to cause much concern on the part of our government, except to provoke warnings to private interests to do their cybersecurity better. 

 

That may make sense if you're a Boeing or a Kaiser Permanente, with entire staffs of IT security specialists.  But especially in the U. S., we have a great many small businesses whose functioning is nonetheless critical to our economy.  Many of them can't afford a full-time IT person, so IT maintenance is handled on an as-needed basis:  if something breaks, the owner hires somebody to fix it, but otherwise deals with things on his or her own. 

 

A supply-chain cyberattack similar to what was used against Ukraine could target a popular piece of software such as, for example, Quicken—something that almost all small businesses use.  With a few keystrokes, such an attack could cause devastation far beyond what we are presently seeing with the Omicron COVID-19 variant, which has done nothing worse than kill thousands of people and cause massive absenteeism, both involuntary due to sickness and voluntary due to vaccine mandates. 

 

The fact that nothing like that has happened in the U. S., with a few exceptions, may mean that the way we are doing things is just fine and we don't need to worry about a massive cyberattack that would bring the U. S. economy to its knees.  On the other hand, it may mean that whoever is capable of mounting such an attack is simply biding their time, awaiting the proper geopolitical moment when such an attack could be coordinated with more conventional warlike actions for maximum effect.  I hope it's the former, but I suspect it might be the latter.

 

What am I asking for?  Certainly not for every software app to be government-certified as secure.  At the university where I work, we have experienced a small-scale version of that type of thing, and all it has done so far is to create a lot of confusion and delays in purchasing needed software.  If there are government and military forces out there safeguarding not only their own systems, but those belonging to the public at large, I would at least like to know about it, in a general way.  And because my federal taxes are paying for it, I'd like to know what I'm getting for my money.

 

In the meantime, we can hope that the Ukrainian government has figured out how to defend itself and its citizens from what has to be the worst spate of cyberwarfare endured by any nation so far.  And maybe we can learn some lessons from them:  either good examples if they succeed, or bad examples if they lose and get absorbed into Russia. 

 

Sources:  I referred to the article "Microsoft discloses malware attack on Ukraine govt networks" which appeared on the AP News website on Jan. 15 at https://apnews.com/article/technology-business-europe-russia-ukraine-404c5e751709fba66b31fd512f734d80.  I also referred to a Microsoft blog at https://blogs.microsoft.com/on-the-issues/2022/01/15/mstic-malware-cyberattacks-ukraine-government/and Wikipedia articles on NotPetya, Ukraine, and the Crimea.

Monday, June 21, 2021

Foreign Hacking of Utilities: Crimes or Acts of War?

 

The hacking and week-long shutdown of the Colonial Pipeline last month that spread gasoline shortages throughout the East Coast is only the most visible incident in a series of worrisome cases that may presage something even worse.  A recent Bloomberg News report highlights the fact that U. S. utility systems such as oil and gas pipelines, water systems, and electric grids are extremely vulnerable to the same kind of ransomware attack that shut down Colonial's system.

 

A friend of mine once summarized engineering ethics with a two-word phrase: "No headlines."  Properly engineered systems that have adequate safety precautions and other mitigations against potential disaster weather all kinds of threats, from internal failures to external hacking attempts, and just keep going.  But as insiders know, beneath the publicly-visible smooth surface there may be many small incidents that engineers manage to catch before they become major problems. 

 

The Bloomberg report cites one:  earlier this year, the cybersecurity firm Dragos discovered that a hacker had managed to access hundreds of computers involved in operating water systems across the U. S.  Presumably this breach was repaired before any actual damage was done, but gaining access through popular software used by many of the same kinds of enterprises is often the first step in a carefully-planned cyberattack that can take months or years to set up. 

 

What is even more surprising than the attacks themselves is the wall of indifference that many private firms and cybersecurity companies encounter when they try to gain the attention of government agencies such as the FBI or the Department of Homeland Security.  The pipeline firm ONE Gas of Tulsa, Oklahoma found last January that a foreign hacker was trying to gain access to the computer system that controls natural-gas traffic across the south central U. S.  After fending off the attack, a cybersecurity firm involved in the defense tried to get a response from the FBI, the Department of Defense, and the Department of Homeland Security.  Representatives of these agencies listened to the story in a conference call, but that was the end of their involvement.

 

From the agencies' point of view, their apparent indifference may be justified.  Because ONE Gas successfully defended itself against the attack, their story was analogous to a homeowner whose attack dogs scared off a burglar trying to break into the garage.  Police might listen politely to such a tale, but because no actual crime was committed, there is not much else they can do.  And thereby hangs a dilemma that needs to be resolved if we hope to avoid successful hacking attempts on utilities in the future: whether to keep regarding ransomware attacks as crimes or acts of war.

 

The dilemma goes back to some fundamental legal definitions. 

 

What has been mostly neglected up to this point is the fact that many cybercrime organizations are hosted by, encouraged by, and possibly operated by foreign governments—China, Russia, and North Korea among them.  Readers of this blog are familiar with my position that cyberattacks committed by foreign individuals or entities constitute matters that should be dealt with by the U. S. military.  But centuries of traditional thinking about what war amounts to stand in the way.

 

The U. S. legal code says that an act of war is "an action by one country against another with an intention to provoke a war or an action that occurs during a declared war or armed conflict between military forces of any origin."  Right there, we run into problems if we try to consider a ransomware attack by, say, agents of the Russian government, as an act of war.

 

To be an act of war, and thus a concern of the U. S. military, one would have to show that Russia in that case was either intending to provoke a war, or was doing it during a declared war, or was doing it during an "armed conflict" between military forces, no matter where they came from.

 

The first condition requires that we somehow divine the fact that Russia, in this hypothetical case, intended to provoke a war.  Proving intent in law is notoriously difficult, so let's skip that one.

 

The second condition requires that a declared war is going on between Russia and the U. S.  To say the least, that would lead to other problems, so let's skip that one too.

 

The third condition requires only that the action happens during an "armed conflict between military forces of any origin."  There are two big roadblocks in this phrase.  The first is the word "armed" and the second is "between military forces."  I'm no lawyer, but it seems that if the armed forces of Russia attacked not our military, but only civilian U. S. targets, it wouldn't be an act of war, at least not by this definition.  And the other problem is even worse.

 

"Armed conflict" means fighting with arms:  guns, bombs, and similar armaments, all of which are designed explicitly to kill people.  The notion that some guy sitting in his basement in Minsk could hit a few keys and shut off power or water to millions of people in a country on the other side of the world was clearly not anticipated by whoever wrote this definition. 

 

If computers are used to kill or injure people, however indirectly, does that make them "arms"?  In our Big Freeze here in Texas last February, power failures led more or less directly to the deaths of over a hundred people.  I can imagine that fatalities would also result from a focused effective attack on power or water utilities, and so a lot more than just inconvenience could result.

 

While I appreciate the reservations that the U. S. military feels about getting involved in what looks to them like simply criminal activity, the day may come when we are faced with a situation that goes beyond anything we have seen so far:  a crippling blow to widespread and vital infrastructure, accompanied by a not-so-subtle message from a foreign government that if we will just do thus-and-such, we'll get our water and power back.  Legalese aside, that would be an act of war as far as I'm concerned.  And the best way to prepare for such an attack is to put resources, including military resources, into making sure that it can't happen here. 

 

Sources:  The Tribune News Service article carried by Bloomberg News was picked up in some form by numerous news outlets, including the Arkansas Online website at https://www.arkansasonline.com/news/2021/jun/13/power-water-seen-as-targets/.  I also referred to Cornell University's law school website for the U. S. code's definition of an act of war at https://www.law.cornell.edu/definitions/uscode.php?width=840&height=800&iframe=true&def_id=18-USC-1479682157-1415921654&term_occur=999&term_src=title:18:part:I:chapter:113B:section:2331.  My column on the Colonial Pipeline hack appeared on May 17, 2021.

Monday, January 04, 2021

The SolarWinds Data Breach: Should We Care?

 

The year 2020 will go down in history for a number of reasons, but the cherry on the disaster cake hit the news in mid-December.  Cybersecurity investigators discovered that some software provided by the Austin, Texas network-monitoring software firm SolarWinds was "trojaned" some time in early 2020.  Hackers, later identified as Russian, managed to insert malware into an update of Solar Winds's popular network-monitoring software, and this allowed the hackers to access customers' emails and other supposedly secure data from around March of 2020 until one of SolarWind's customers noticed that someone had stolen some of their cybersecurity tools, and notified the company.  In similar attacks, Microsoft software was similarly compromised.

 

This was a complicated and well-organized exploit, as the hackers focused their attention on high-value targets such as government agencies.  Wikipedia's article on the breach reads like a list of a spy's dream targets:  the Department of Defense, the National Nuclear Security Administration, the National Institutes of Health (in the midst of the COVID-19 pandemic, yet), the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, the Department of State, and the Department of the Treasury.  As in any spying operation, most of what they got won't be that useful to them, but some of it very well may be. 

 

Fortunately, the hackers did not use their access to lock files or cause other disruptions that might have drawn premature attention to what they were doing.  They were spying, not sabotaging.  But of course, what they learned may help them commit sabotage in the future.  We simply don't know.

 

How did this happen?  In the case of SolarWinds, the hackers gained access to the firm's "software-publishing infrastructure" way back in October of 2019.  Clearly, the company's own security measures were insufficient to prevent this initial breach, which if caught could have stopped the whole attack in its tracks.  But something as simple as carelessness with passwords can allow hackers into a system.  Hacking is like burglary, in that ordinary defenses stop the average burglar, but if a huge sophisticated gang decides to focus on your house, there's not a lot you can do to stop them.

 

And SolarWinds was the focus of the Russian hacking group known as "Cozy Bear" because of their critical place in the software supply chain.  Thousands of firms use their network-monitoring software, which meant that "trojanizing" a SolarWinds software update gave the hackers potential access to any of SolarWinds's customer's systems.  And that is exactly what happened.

 

Once the breach was discovered last month, SolarWinds went public and warned its customers of the problem.  But as one expert interviewed on the breach put it, fixing the leaks that the hackers established is like getting rid of bed bugs:  sometimes they are so spread out that finding each individual bug is an impossible task, and you have to burn the mattress.  The reason is that once the attackers got into a system, they could wander around and establish more access points.  And stopping the original breach does nothing about those access points, which can be hard to find.  So even though we know how the hackers got in, it's not going to be an easy matter making sure that they can't keep spying on their victims without throwing out a whole lot of software and starting over from scratch.

 

What difference does all this make to the average Joe or Jane?  If you don't work for one of the affected companies or agencies, should you even bother to put this on your already-lengthy worry list? 

 

In itself, the breach's consequences are unpredictable.  Governments keep some things secret for good reasons, mostly, and when those secrets are revealed, bad things can happen.  We are not currently in direct hand-to-hand conflicts with Russia, but there are low-level military operations going on all over the world, many of which the U. S. is involved in without the knowledge of the general public.  As in any military operation, intelligence about plans or proposed actions can be used against you if it leaks, so for one thing, our military forces have been put in a potentially bad situation.  But again, it's hard to tell yet.

 

During World War II, the Germans were largely unaware that the Allies had breached their most-secure code system with the Turing-inspired "bombes" of Bletchley Park, because any military advantage that the Allies' decoding operations gave them was carefully disguised to look like luck.  So we can expect Russia to disguise any advantages it's attained from the Cozy Bear attacks similarly, although we now know roughly what they've been up to. 

 

Institutions change slowly, and the old saying that generals in a new war start out by fighting with the previous war's weapons is still true.  There will always be a need for troops on the ground in some situations, but as more and more commerce and activity of national importance takes place in cyberspace, future battles will also be staged more and more in the digital realm. 

 

As we know from bitter experience in other areas of engineering ethics, it usually takes a spectacular tragedy to inspire major institutional change that could have prevented the tragedy in the first place.  We have been relatively fortunate that bad consequences from cyberattacks on U. S. targets have not approached the magnitude of a 9/11, for example.  Probably the worst ones have been ransomware attacks mounted by apparently private criminal groups that shake down organizations for money, usually in the form of bitcoin.  While serious for the organizations targeted, these sorts of attacks have not up to now appeared to be part of a coordinated terrorist-like systematic assault on the nation's infrastructure.

 

Such an attack could come at any time, however.  And the fact that Cozy Bear hackers were reading the Pentagon's mail for the last nine months does not inspire confidence in the ability of our nation's cyber-warfare personnel to prevent such attacks.  Until we take cyberwarfare fully as seriously, if not more seriously, than attacks with conventional weapons, we are effectively inviting hackers to see what they can do to disrupt life in the United States.  Let's hope they don't try any time soon.

 

Sources:  I referred to an article by Kara Carlson of the USA Today Network which appeared on the Austin  American-Statesman's website on Dec. 30 at https://www.statesman.com/story/business/2020/12/30/solarwinds-breach-could-shape-cybersecurity-future/3999961001/.  I also referred to a chronology of the attacks on the channele2e website at https://www.channele2e.com/technology/security/solarwinds-orion-breach-hacking-incident-timeline-and-updated-details/, and the Wikipedia article "2020 United States federal government data breach."

Monday, January 02, 2017

What Are the Rules of Cyberwarfare?


We are now well into the era of cyberwarfare—the use of computers and computer networks in military, terrorist, and diplomatic conflicts.  But to judge by the recent tiff between President Obama and Russian President Vladimir Putin, neither the U. S. nor Russia has figured out exactly how to use these new weapons, or how to defend against them effectively.

Last July, Wikileaks unleashed a flood of embarrassing emails hacked from the Democratic National Committee, leading to the resignation of that organization's chairwoman Debbie Wassermann Schultz and undoubtedly influencing the Presidential selection process, though to what degree it is impossible to say.  In December, the CIA announced that they were confident that Russian hackers were responsible for stealing the emails and giving them to Wikileaks.  And on Dec. 23, President Obama announced that he was retaliating for the hacks by sending home 35 Russian diplomats and taking other actions against the Russian diplomatic corps in the U. S.  After initial talk by Russian officials of retaliation against the retaliation, Russian President Vladimir Putin surprised many by saying he would suspend any actions against U. S. diplomats in Russia, at least until the Trump administration takes office. 

Retaliation against diplomats has been around ever since there have been diplomats.  Over the decades, countries have developed traditional ways of treating official representatives from foreign lands with policies such as diplomatic immunity from routine prosecution, the suspension of normal customs inspection for diplomatic materials, special diplomatic zones around embassies, and other perks.  But one reason for all these special privileges is that they can be revoked at any time. 

This writer is old enough to recall some of the many times that the old Soviet Union (USSR) engaged in these kinds of games with the U. S. on any pretext or sometimes no pretext at all.  It was all part of the Cold War chess game, and watched closely for indications that the Soviets might be wanting to warm up the war a little.  Everyone agrees that sending a diplomat packing is a lot better than throwing bombs, so while tensions are raised by such incidents, it's usually a sign that serious conflicts are not in the immediate offing.

Still, there are a couple of notable and disturbing aspects of the DNC hacks and their consequences.  One concerns the identity of the hackers, and the other concerns what constitutes a truly effective response to such attacks.

It took nearly six months for the CIA to be confident enough to announce publicly that Russians were in fact responsible.  In that aspect, hacking and other hard-to-trace cyberattacks resemble terrorism, in that the identity of the terrorists responsible for a given attack is usually not immediately known, and may not ever be discovered.  Although good detective and investigative work often uncovers the perpetrators eventually, the delay between the attack and the discovery of who did it allows for uncertainty to dominate the situation, leading to general confusion, controversy, and other problems that are usually exactly what the attacker wants to achieve in the enemy camp.  It's possible that the CIA made its announcement when it did not because it took all that long to figure out who did it, but for other diplomatic or political reasons.  Still, it's hard to fight back against an enemy if you don't know who he is.

Identifying the source of a cyberattack is only the first step in an effective response.  As in conventional warfare, one doesn't want to overreact, but on the other hand, just letting an enemy get away with anything isn't good either.  An important factor in these not-yet-open-warfare conflicts is how the public perceives them.  Both the U. S. and the Russian presidents do everything with an eye to their constituents, so things done in secret which have secret effects are not that useful.  Instead of using the hacked emails for their own purposes, whoever hacked them (probably the Russians) gave them maximum publicity, and to the extent that the DNC was hampered in its operations, the attack was a success. 

What's new and disturbing about this particular incident is that it represents a significant intrusion into the domestic electoral process by a foreign power which overtly favored a particular candidate—one who will take office on Jan. 20, barring unforeseen circumstances.  What makes the situation worse is that the President-elect does not seem to be all that troubled about it.  Four years in office is a long time, though, and it's likely that Trump and Putin will at some point fail to agree on something, after which it's anyone's guess what will happen.

Part of what makes it so hard to defend against cyberattacks is the global nature of the Internet environment—Moscow or Paris or Adelaide is just as close to my Internet connection as the neighbor down the street.  Traditional military defenses were geographically fixed and you could draw contours of safety within them—here, you have to be concerned about ground attacks, there you are subject to air bombings, and way back behind the front lines, there was almost nothing to worry about.  But cyberattacks can go anywhere there's an Internet connection, and the targets are often only as well-defended as the private organizations and their IT people can make them.  As we know, these defenses range from the almost impregnable to the nearly nonexistent, and so many attractive cyber-targets are almost defenseless against a concerted attack by well-resourced agents of a foreign power.

It's not clear that the best defense is a good offense either, especially when it's not immediately clear who is doing the attacking.  And when many thefts of data are not discovered until months or years after the damage is done, it's even harder to mount an effective response.

It looks like international cyberwarfare will muddle along in this confused state unless and until such a major attack occurs that we get serious about some sort of national defense policy against foreign cyberwarfare.  There are serious concerns being voiced these days about the hacking of power grids and other vital infrastructure systems such as air-traffic control and the domestic Internet itself.  Our best defense for these systems right now is that nobody has a strong reason to attack them, but that could change at any time.  And if it does, I just hope we're ready for what comes afterwards.

Sources:  I referred to a report on President Obama's retaliatory actions against Russia carried by CNN on Dec. 29 at http://www.cnn.com/2016/12/29/politics/russia-sanctions-announced-by-white-house/, and also a report on Putin's non-response at https://www.washingtonpost.com/world/russia-plans-retaliation-and-serious-discomfortoverus-hacking-sanctions/2016/12/30/4efd3650-ce12-11e6-85cd-e66532e35a44_story.html.