Slashdot Mirror


US Cybersecurity Plan Includes Offense

z4ns4stu writes "Shane Harris of the National Journal describes how the US government plans to use, and has successfully used, cyber-warfare to disrupt the communications of insurgents in Iraq. 'In a 2008 article in Armed Forces Journal, Col. Charles Williamson III, a legal adviser for the Air Force Intelligence, Surveillance, and Reconnaissance Agency, proposed building a military "botnet," an army of centrally controlled computers to launch coordinated attacks on other machines. Williamson echoed a widely held concern among military officials that other nations are building up their cyber-forces more quickly. "America has no credible deterrent, and our adversaries prove it every day by attacking everywhere," he wrote. ... Responding to critics who say that by building up its own offensive power, the United States risks starting a new arms race, Williamson said, "We are in one, and we are losing."'"

13 of 101 comments (clear)

  1. Wait what? by Dyinobal · · Score: 5, Informative

    "America has no credible deterrent, and our adversaries prove it every day by attacking everywhere,"

    Well that's just it you can't build a razor wire wall and laugh as people cut themselves trying to get through it. It seems to me the first mistake to be made is to treat a digital front as if it was a front in an actual war. All you're doing it guarding secrets most often, or sometimes vital services. Best way to protect them is physical separation from civilian networks. I know my friend who does communication translation for the military works on a network where they mirror a hand full of sites (wiki among them) every week and host them in house simply because having the network connected to the internet at large is just to risky.

    1. Re:Wait what? by HiThere · · Score: 3, Interesting

      FWIW:
      I remember reading, I think it was a decade or two ago, about a Nuclear plant that had in internal network for just that reason. And total separation.

      Then they hired a consultant to test or fix something, and that consultant brought in his computer and hooked it up to their network, but he needed some info that was kept on his company's site, so he also hooked it up to the main internet.

      Well, the virus wasn't all THAT damaging, THAT time.

      Separating the nets is VERY desirable. But if you really want to be safe, you need to also use different communication protocols. Different strings for local URIs, etc. Even a simple change would probably be enough, but even a simple change would be a tremendous hassle to implement.

      Say you adopt the httq protocol instead of the http. Now you need to modify all the programs that expect http...because you don't want a rogue http link that sneaks in to be able to be processed. Quite a simple change... You'd want a series of changes at about that level of simplicity, and at all 7 levels of the protocol stack. Each one trivial.

      Now try to run your MSWind software.... Whoops! All you can run is software that either doesn't depend on the net, or is specially crafted. This means OSS, and practically FOSS software.

      (I suppose there might be simpler solutions, but every one I thought of I soon saw holes in.)

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  2. Reminiscent of the Cold War by meustrus · · Score: 4, Insightful

    To me, this is reminiscent of our arms race with the Soviet Union. Military officials were convinced that the Soviets were always one step ahead of them the entire time, even though the only time they got to a technology before us was the launch of Sputnik, which wasn't really a military achievement anyway (we were all decades behind spy satellites or something like SDI). If they didn't think the Soviets were building something better than what we had (which would have been supported by their intelligence gathering) they never stopped using that argument to support large standing armies and rapid technological arms buildup.

    And when the USSR collapsed, we learned that the entire time they had been at least two steps behind us.

    My opinion is that our infrastructure is in such disrepair that if hostile powers had the capability of cyperterrorism, they would have to practice extreme restraint not to use it to put the entire nation in a blackout for a month. If that means they're waiting for a combined-arms assault, then offense is not going to help us when our "military botnet" doesn't have any electricity to run on.

    The recent scare about cyberterrorism causing blackouts in Brazil, only to find that those blackouts were more likely due to natural causes in a poorly maintained electrical grid, supports my point.

    --
    I sometimes ask revealing, often ignorant-seeming questions. Maybe they're harder to answer than you think.
    1. Re:Reminiscent of the Cold War by Chabil+Ha' · · Score: 3, Insightful

      And when the USSR collapsed, we learned that the entire time they had been at least two steps behind us.

      Would you have had it any other way? If we had not maintained our paranoia of the Russians one-upping us, would we have maintained our edge? I'll let history stand as the best outcome of the cold war without trying to second guess what would have happened if we had not taken the position we did. The illusion of a perpetual stalemate is certainly preferable to the alternatives.

      --
      We're all hypocrites. We all have hidden parts, it's the contrast between them that make us more a hypocrite than others
    2. Re:Reminiscent of the Cold War by Adambomb · · Score: 3, Funny

      But But But, I want my Kuang Mark 11 to slot into my deck!

      --
      Ice Cream has no bones.
  3. This Sounds Like by boudie2 · · Score: 3, Funny

    A job for Bill Gates, smartest man in the world. Only he can catch Osama Bin Laden and keep the world safe for democracy. Isn't this all sounding like the story line to a bad movie?

  4. Re:what about anonymous? by earlymon · · Score: 3, Insightful

    Because you can't budget for internet hooligans.

    In the 90s the military establishment began to realize and fear that the methods we had in place were dedicated to force on force conflicts but that terrorists - especially postulated nuclear ones - had no solution. Within a decade, that proved prophetic (although thankfully, not the nuke part).

    From TFS:

    Williamson echoed a widely held concern among military officials that other nations are building up their cyber-forces more quickly.

    Looks like déjà vu all over again.

    No one is ever ready for the upcoming threat - they're too busy safeguarding against the last surprise.

    --
    Pathological kinda promises Path + Logical - but instead, you get stuck with pathetic.
  5. Re:Just give it time by earlymon · · Score: 3, Insightful

    In ten or twenty years USA won't be a country worthy of attacking

    You must be too young to remember - that was a popular 70s meme, with the US being the new Roman Empire on its way to an accelerated collapse.

    Don't count the US out until you can count 10. Maybe the reason for its endurance is that the US is really never just one nation of one people.

    ;-)

    :-P

    --
    Pathological kinda promises Path + Logical - but instead, you get stuck with pathetic.
  6. Strangelove by Hemogoblin · · Score: 3, Funny

    Mr President, we must not allow a script-kiddie gap!

  7. Re:Just give it time by TheLink · · Score: 3, Interesting

    No country would start a war with the USA. Not now or in twenty years. Just look at the USA's "defense" budget compared to the rest of the world _total_.

    They're like "that survivalist guy with a whole basement full of guns, ammo, grenades and a rocket launcher or two". It'll be suicide to go up to his house with a BB gun and shoot at it.

    If anyone wants to hurt the USA they'd have to do it more sneakily - so there's no obvious target for their nukes, cruise missiles, bombers etc.

    Same goes for this "cyberwarfare" thing. A massive concerted attack from your country against the USA will just get you bombed.

    The US media likes to make noise about China/<bogeyman of the day> launching cyberattacks on US servers. The fact is, if the Chinese Gov was really involved, the US Gov will just call the Chinese ambassador in, and say: "Hey stop that now". But really which government is going to do that? If my government wanted to start a war with the USA - cyber or otherwise, a real act of patriotism would be to shoot the idiot leader(s) who came up with that idea.

    The attacks are mainly from a bunch of script kiddies or criminals. If the US Gov is really serious about reducing the attacks they should just go follow the money/control channels, and jail the people responsible if they're in the USA (won't surprise me if many are actually from the USA- after all Sanford Wallace is in the USA, and the BlueHippo thing was in the USA ).

    --
  8. Re:what about anonymous? by NotBornYesterday · · Score: 4, Insightful

    Ask the british, french or the romans, most of the countries they conquered don't hate them... and the US was just liberating countries. Something to do with trade, peace, talks, cultural exchange, improving the country and oh... not killing them in droves followed by massively dropping the standard of living.

    The British , French, and Romans killed lots of natives building their empires, they had no compunctions about doing it, and they certainly didn't feel bad about it after. So did the Spanish, for that matter. They also imposed their own laws on other cultures, and taxed their new "subjects", drawing more wealth out of the colonies than they put in, thereby driving down the local economy. The primary reason for being a colonial power has always been to exploit someone else's wealth.

    The US has built (or rebuilt) a lot of infrastructure in the wake of its various invasions. The standard of living in these places would be a lot higher if said infrastructure wasn't still being blown up, this time by people other than the US.

    Not justifying invasions or civilian deaths, just saying I don't agree with your comparison.

    --
    I prefer rogues to imbeciles because they sometimes take a rest.
  9. Re:what about anonymous? by TheCarp · · Score: 3, Insightful

    > In the 90s the military establishment began to realize and fear that the methods we had in place were dedicated to force on force conflicts but
    > that terrorists - especially postulated nuclear ones - had no solution. Within a decade, that proved prophetic (although thankfully, not the nuke
    > part).

    Actually, I tend to think Lawrence Lessig's essay "Insanely Destructive Devices" addressed the issue quite nicely. Technology that can be used for good can always be turned for evil. As technology expands what a person may easily do, or what a small group of people may do, it MUST ALSO expand the amount of harm a person can do.

    Its hard to argue that explosives and guns have not increased the damage of an individual with access to them going psychotic and deciding to kill. I am afraid that this threat is unavoidable. So too the threat of determined individuals with a rational or semi-rational goal of destruction are even more amplified. Terrorism *IS* rational from a soldier at war's viewpoint.

    So, in the end, the ONLY viable solution, besides attempting to raise the bar just enough to mitigate as much as possible the "crazy lone wolf" threats, is decreasing the rationality of terrorism. ONLY by stopping such groups from forming in the first place and growing will they be stopped.

    This is why I actually believe that things like torture programs get more people killed. The hypocrisy of championing due process, the rule of law, and civil rights and then instituting secret programs of detention, rendition, and torture are not lost on the enemy. They join up BECAUSE they know we are hypocrites, it is why they joined.

    Hearts and minds are the only battlefields that matter in the end. The rest is just those victories and defeats playing out.

    -Steve

    --
    "I opened my eyes, and everything went dark again"
  10. Re:Well by NotBornYesterday · · Score: 3, Insightful

    First: American news outlets generally avoid graphic scenes. Other news organizations may report more explicit content, but I think you're confused.

    Second: Any rational, independent-thinking person knows there is a considerable difference between filming action between armed combatants on a battlefield, and the producing a video of the execution of an innocent, helpless, non-combatant hostage. Furthermore, in the first situation the video is a by-product of the main action. If anything, knowledge that the battle is documented may inhibit excessive violence. In the second situation, the video is the primary aim of the action, and because the nature of the video is to cause terror, it encourages greater inhumanity in its actors. But then again, you already knew that.

    The hypocrisy and filthy double standard here is in those who would equate the actions of nameless, faceless terrorists with those of the US military. While they are far from perfect, all branches of the US military bring court martials against those in their command believed to have committed atrocities. There are those who would argue that little has resulted from them, (and they would mostly be right) but that misses the point: No terrorist organization holds (or attempts to hold) itself to nearly the same standards that the US does. No member of al Quaida has ever faced a disciplinary hearing for bombing a mosque, market or school. No insurgent has ever been indicted by his own organization for intentionally targeting innocent civilians. Far from being despised, they are called heros. But then again, you already knew that.

    There are times the US should listen more closely to other voices in the world. Just not to yours. Quite frankly, I wonder why you think the US should give a damn about your opinion, or the opinion of people like you. Not because you think differently, or because we're evil, or we don't listen to our neighbors, but because you obviously care more about your anti-American agenda than you do about dialog. But then again, you already knew that.

    --
    I prefer rogues to imbeciles because they sometimes take a rest.