Cyber Porposal

profileCyberSter
CYBER_DOMAIN_STRATEGIES_POLI.pdf

CYBER DOMAIN: STRATEGIES, POLICIES, DOCTRINES AND

LEGAL PERSPECTIVES

Mihai-Ştefan DINU Senior Researcher, National Defense University “Carol I”,

[email protected]

Abstract: Once it was understood that the term” information society” is something more than a metaphor suggesting the ongoing reality for almost five decades, different more or less complex theories made their way

into the ideas of specialists and the academia that promoted development of most human activities in a virtual

space created by semiconductors and developed over the networking infrastructure of the 7 continents.

Gradually, population of this space by government entities, corporate, military, educational, etc. but also its use

as a medium of socialization through various platforms like Google+, Facebook, and Twitter brought to the

attention of all users the presence of behaviors less desirable. It is about criminal activities whose range can go

from mere unauthorized access to a computer or computer system and continues with identity theft and

launching various attacks on governmental critical infrastructure, inflicting significant damages.

On this background, policymakers, supported by field theorists have promoted and implemented through various

government policies, cyber security strategy in order to protect national infrastructures and ensure continuity of

daily activities. This type of defensive behavior against damaging cyber actions was also adopted by military

organizations having seen the opportunity to conduct certain types of operations in cyberspace. So they were

issued and implemented the cyber operations doctrines, while extending the conceptual field and leading to the

emergence of terms like cyber war, cyber warfare, cyber operations and elements regarding legal framework of

waging this kind of war etc.

In this paper we analyze how some of these concepts were defined and implemented, focusing on the need for

adopting new legal regulations, both national and international adapted to the new realities of the modern

information society.

Keywords: cyberspace, cyber-attack, cyber conflict, cyber security strategy, cyber doctrine, cyber law

Introduction

There is no doubt that modern human life on the XXI century could not be perceived in its entirety without the significant role of technology, especially information and communication technology, which permitted in the last two decades a burst regarding not only at professional level of communication and information of human activities, but at the individual intimate level of every individual. Along with these aspects of human life, research and development activities benefitted of the means provided by the technological development. Thus, should not have been a surprise for anyone that the perspective depicted at the beginning of the 8th decade of XXth century by Yoneji Masuda in his work The Information Society as Post-Industrial Society1, promoted information utility as the main production center of information society. In his perspective the information utility constitute of information networks and data banks, in other words a public infrastructure based on interconnected computers.

In the same period Masuda’s view was promoted another significant event was taking place: The Internet emerged public from the military testing laboratories. Initially perceived as a tool that facilitated communication, Internet rapidly expanded its functions along with geographic area. Today, the Internet is not only a technological tool, in 2011 the United

1 Yoneji Masuda, The Information Society as Post-Industrial Society, World Future Society, Washington D.C., 1981.

139

Nations declared in a report issued by the Special Rapporteur on the promotion and protection of the right to freedom and opinion and expression, Frank LaRue, that by the fact that it facilitates the realization of a range of other human rights2, the access to internet is a fundamental right. This affirmation comes in the context in which, 11 years earlier, Estonia legislates3 Internet access as a basic human right, in the year 2009 France Constitutional Council4 declared it a fundamental right and, similarly, a 2010 decision5 of Costa Rica Constitutional Court.

Obviously, the free access to internet did not attract only positive actions, but also criminal ones, the large virtual cyberspace becoming populated not only with actors offering facilitating social, educational or professional tools but with diverse criminal actors whose actions lead to decisions taken by vast majority of nation states to legally, politically and technically protect their infrastructures.

On the actors and actions taken by the states or organizations we will focus on the subsequent structures of this paper.

Brief Presentation of Actors in Cyberspace – their targets, techniques and effects

Statistics indicates that malevolent actions of actors in cyberspace in the previous year (2016) experienced an increased number comparing with th previous two years as depicted in the following graph.

Figure no 1. Comparison of monthly cyber-attacks in previous three years6

Regarding categories of actors in cyberspace we briefly mention here:

 State sponsored actors  Individual actors  Hacktivists  Cyber-terrorists

2 ***, A/HRC/17/27/ - Report of the Special Rapporteur on the promotion and protection of the right to freedom and opinion and expression, Frank LaRue, United Nations’ General Ansambly, 16 May 2011, p. 7 3 Stephen Tully, A Human Right to Access the Internet? Problems and Prospects, in Human Rights Law Review, vol. 14, Issue 2, Oxford University Press, pp. 175-195 4 ***, Decision no. 2009-580 of June 10th 2009 at www.conseil-constitutionnel.fr/conseil- constitutionnel/root/bank_mm/anglais/2009_580dc.pdf (14.02.2017) 5 Sala Constitutional, La Sala en la Prensa 2010(2011) p. 118 at www.poder-judicial.go.cr/sala- constitutional/documento/salaenpresa2010.pdf (14.02.2017) 6 Paolo Passeri, 2016 Cyber Attacks Statistics, at www.Hackmageddon.com/2017/01/19/2016-cyber-attacks- statistics/ (16. 02.2017)

140

 Organized crime actors  Organizations  Information security actors  Authorities and Law enforcement  Unknown Identity or no affiliation actors

In most cases, statistics indicates that motivations driving the attacks are as follows:  Cyber crime  Hacktivism  Cyber espionage  Cyber warfare  Unknown

Figure no 2. Comparison of percentages regarding motivations of attacks in 2015 and 20167

The targets affected by these attacks are diverse, percentages of these attacks by target

being graphed in figure no.3.

Figure no 3. Comparison of percentages indicating nature of targets in 2015 and 20168

There is an important characteristic of those attack resulting from the graph, namely the fact that if industrial, governmental and organization entities, keep their top places, in

7 Paolo Passeri, 2016 Cyber Attacks Statistics, at www.Hackmageddon.com/2017/01/19/2016-cyber-attacks- statistics/ (16. 02.2017) 8 Ibidem

141

2016 there was an increase in attacks regarding education entities. According to a report9 issued in 2016, the main vectors of attack used against education entities were:

 Obtained credentials  Phishing  Reconnaissance  Remote access tools  Scanning tool  SQL Injection  Web Shell

In this point we can make the transition from targets to the attacker’s preferred techniques. Also cited statistics realized by Paolo Passeri, indicates that top ten techniques (figure no. 4) used by the attackers are as follows:

 Account hijack  Targeted attack  DDoS attack  SQL Injection  Malware etc.

Figure no 4. 10 most used attack techniques in 2014, 2015 and 201610

Divers actors acting in Cyberspace, the multitude of targets and the complex

techniques of attack, should be an indicator measuring permeability level of cyberspace by malevolent attacks that can range from cybercrime to cyber espionage and cyber warfare.

Strategies and doctrines in the cyber warfare era

Cyber-attacks are a very cheap and accessible way of striking the power of a State. In context of rapid development of the global cyber system, the interdependency level is growing along with the dependence of energy, transportation, communications, financial and military critical infrastructures on the global network.

9 ***, Common Cyber Threats to Universities, Multi-State Information Sharing & Analysis Center, New York, 2016, p. 2. 10 Paolo Passeri, 2016 Cyber Attacks Statistics, at www.Hackmageddon.com/2017/01/19/2016-cyber-attacks- statistics/ (16. 02.2017)

142

Thus, the effects of a major cyber-attack could be disastrous for the entire human activity11, leading to economic crisis, disruptions12 in communications and transportations and health infrastructure, we previously mentioned some of the consequences in the Russian- Georgian war back in 2008. Such cyber tools can be easily transformed in cyber weapons in the hand of terrorist or criminal organizations which can be very active during an ongoing armed conflict.

In order to prevent such situations nation states issued Cybersecurity National Strategies and Cybersecurity Implementation Plans. In this regard international organizations like NATO assumes the mission to enhance the capability, cooperation and information sharing among NATO, NATO nations and partners in the field of cyber defense through education, research and development, lessons learned in order to accumulate, create and disseminate knowledge in the above mentioned field.

So here is a first distinction we have to mention, that between cyber security and cyber defense. In terms of definition such distinction is rather difficult because of the specific definitions issued in national strategies or doctrine by every nation state.

When the cyber security is discussed there are proposed definitions like the desired state of an information system in which it can resist events from cyberspace likely to

compromise the availability, integrity or confidentiality of the data stored, processed or

transmitted and of the related services that these systems offer or make accessible.

Cybersecurity makes use of information systems security techniques and is based on fighting

cybercrime and establishing cyber defense13, or the protection of internet connected systems (to include hardware, software and associated infrastructure), the data on them, and the

services they provide, from unauthorized access, harm or misuse. This includes harm caused

intentionally by the operator of the system, or accidentally, as a result of failing to follow

security procedures or being manipulated into doing so14. In Romanian perspective, cyber security means the state of normality resulting from

the application of a set of proactive and reactive measures that ensure the confidentiality,

integrity, availability, authenticity, and non-repudiation of information electronically for

public and private resources and services in cyberspace. Proactive and reactive measures

may include policies, concepts, standards and guidelines for security, risk management,

training and awareness activities, implementing technical solutions to protect cyber

infrastructure, identity management, and consequence management15.

Diversity of perspectives it is kept also in defining cyber defence/defense concept, the common element being the military characteristics of the term. Therefore, the proposed definitions stated that cyber defense means:

 organized capabilities to protect against, mitigate from and rapidly recover from the effects of cyber-attack (US/Russia perspective16);

11 Dănuţ Turcu, Main Information Security Activities Of An Intelligence Service, in Buletin of “CAROL I” National Defense University, No. 1/2014, Bucuresti, 2014, p. 51. 12 Sorin Topor, Aproach About Joint Cyber And Electronic Warfare And Futures Of The Military Operations, in the 10th International Scientific Conference “Strategies XXI”: Strategic Changes In Security And International Relations, vol. 3, “CAROL I“ National Defense University Publishing House, Bucharest, 2014 , pp. 72-76 13 ***, Information systems defence and security: France’s strategy, French Network and Information Security Agency, Paris, 2011, p. 21. 14 ***, National Cyber Security Strategy 2016-2021, issued by HM Government, 2016, p. 75. 15 ***, HG 271/2013, pentru aprobarea Strategiei de securitate cibernetică a României şi a Planului de acţiune la nivel naţional privind implementarea Sistemului naţional de securitate cibernetică, Monitorul Oficial Partea I nr. 296 din 23.05.2013 16 https://ccdcoe.org/cyber-definitions.html

143

 the set of all technical and non-technical measures allowing a State to defend in cyberspace information systems that it considers to be critical (France perspective)17;

 all measures to defend cyber space with military and appropriate means for achieving military-strategic goals. Cyber defense is an integrated system,

comprising the implementation of all measures relating to ICT and information

security, the capabilities of milCERT and CNO (Computer Network

Operations) as well as the support of the physical capabilities of the army

(Austria perspective18). Implementing National Security Strategy, there are some states, namely US that

translates strategy’s imperatives into military doctrine19. The US doctrine integrates cyberspace into joint operations, defines cyberspace operations and their relation to joint functions, along with their planning and coordination, covering authorities, roles and responsibilities, providing a joint doctrine for the planning, preparation, execution, and assessment of joint cyber operations across the range of military operations.

Legal perspectives

As we stated in previous section of our paper, cyber-attacks are a very cheap and accessible way to strike the power of a State. Techniques of cyber-attack can be easily transformed in cyber weapons in the hand of terrorist or criminal organizations which can be very active during an ongoing armed conflict or even on the background of non-violent tensions. What happened if cyber-attacks are conducted as an armed conflict? There are any norms of law of armed conflict applicable to cyber conflicts?

Article 2 Common to the four 1949 Geneva Conventions sets forth the traditional formula: all cases of declared war or to any other armed conflict which may arise between two or more of the High Contracting parties20. In this sense, we could consider that if a cyber- attack that can be attributed to a State result in material damages or loses of human life and therefore an international armed conflict is occurring.

In this regard there are various perspective on the existence of a legal framework applicable to cyber warfare. Thus, in this section of our paper we will analyze different perspectives on this matter, focusing on the views of United Nations (UN), EU and NATO.

At the level of UN, which theoretically benefits from the contributions of almost all countries, there were few initiatives looking to set an international legal framework regarding the regulation of cyber-attacks. Among these initiatives we should mention the 2004 resolution on creation of a global culture of cybersecurity and the protection of critical informational infrastructures, which had a week feedback from the member nations. Beside these initiatives we must note the proposal that Security Council to be empowered with the attribute to decide when a cyber-attack constitutes a threat and violates the international treaties and peace on the basis of article 42: Should the Security Council consider that measures provided for in Article 41 would be inadequate or have proved to be inadequate, it

may take such action by air, sea, or land forces as may be necessary to maintain or restore

international peace and security. Such action may include demonstrations, blockade, and

other operations by air, sea, or land forces of Members of the United Nations21.

17 Ibidem 18 ***, Austrian Cyber Security Strategy, Federal Chancellery of the Republic of Austria, Vienna, 2013, p. 21 19 ***, Joint Publication 3-12 (R), Cyberspace Operations, 2013 20 ***, Geneva Convention I, art. 2; Geneva Convention II, art. 2; Geneva Convention III, art. 2; Geneva Convention IV, art. 2 21***, Charter of the United Nations, at http://www.un.org/en/sections/un-charter/chapter-vii/

144

At European Union level strong efforts were conducted in the direction to norm the behavior of cyberspace actors. We can indicate at least four major legal milestones in this regard:

 2001 Convention on Cybercrime issued by the Council of Europe which could constitute a limitation framework for cyber warfare operations;

 2004 Establishment of European Union Agency for Network and Information Security (ENISA) as a center of expertise for cyber security in Europe.

 2011 Communication on Critical Information Infrastructure protection (CIIP) adopted by European Commission focusing on the protection of Europe from cyber disruptions by enhancing security and resilience22.

 European Parliament resolution of 12 June 2012 on critical information infrastructure protection – achievements and next steps: towards global cyber- security23.

Regarding politic and military level covered by NATO, the initiatives to regulate attacks in cyberspace were taken under the institutional umbrella of NATO Cooperative Cyber Defense Centre of Excellence located in Tallinn (Estonia). Strongest initiative in the analyzed domain is The Tallinn Manual, which was published earlier this month, in its second edition, an updated version that constitute the most comprehensive analysis of how existing international law applies to cyberspace. According to authors Tallinn Manual 2.0 analysis rests on the understanding that the pre-cyber era international law applies to cyber

operations, both conducted by and directed against states. This means that cyber events do

not occur in a legal vacuum and thus states have both rights and bear obligations under

international law24. The same source states that the manual covers a full spectrum of international law as applicable to cyber operations, ranging from peacetime legal regimes to the law of armed conflict. The analysis of a wide array of international law principles and regimes that regulate events in cyber space includes principles of general international law, such as the sovereignty and the various bases for the exercise of jurisdiction. The law of state responsibility, which includes the legal standards for attribution, is examined at length. Additionally, numerous specialized regimes of international law, including human rights law, air and space law, the law of the sea, and diplomatic and consular law are examined within the context of cyber operations.

Conclusions

Following this brief analysis, it is necessary to draw some conclusions. First of all is referring the fact that cyberspace is a relatively new space of human activities and despite its “youth” there are a lot of controversial issues raised at international level regarding behaviors manifesting within it.

In order to correct such behaviors and to limit disastrous effects that could be brought by the use of dangerous cyber tools/weapons, most of nations took the initiative to issue at domestic and organizational levels national, European, cyber security strategies or similar. All these strategies and military doctrine are resting on the norms of International Law existing before the emergence of cyber space. That is why acting in time of conflict in the cyber space bring to surface diverse legal issues on which the international community must focus a lot from now on, considering the fact that along with the unprecedented development of cyber domain there are similar fields (robotics, artificial intelligence etc.) awaiting to know their

22 http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2009:0149:FIN:EN:PDF 23 http://www.europarl.europa.eu/sides/getDoc.do?pubRef=-//EP//NONSGML+TA+P7-TA-2012- 0237+0+DOC+PDF+V0//EN 24 https://ccdcoe.org/sites/default/files/documents/CCDCOE_Tallinn_Manual_Onepager_web.pdf

145

behavior in the framework of International Law and also the ethical norms that will shape this behavior.

BIBLIOGRAPHY

1. ***, A/HRC/17/27/ - Report of the Special Rapporteur on the promotion and protection of the right to freedom and opinion and expression, Frank LaRue, United Nations’ General Assembly, 16 May 2011

2. ***, Austrian Cyber Security Strategy, Federal Chancellery of the Republic of Austria, Vienna, 2013

3. ***, Charter of the United Nations, at http://www.un.org/en/sections/un- charter/chapter-vii/

4. ***, Common Cyber Threats to Universities, Multi-State Information Sharing & Analysis Center, New York, 2016

5. ***, Decision no. 2009-580 of June 10th 2009 at www.conseil- constitutionnel.fr/conseil-constitutionnel/root/bank_mm/anglais/2009_580dc.pdf (14.02.2017)

6. ***, Geneva Convention I, art. 2; Geneva Convention II, art. 2; Geneva Convention III, art. 2; Geneva Convention IV, art. 2

7. ***, HG 271/2013, pentru aprobarea Strategiei de securitate cibernetică a României şi a Planului de acţiune la nivel naţional privind implementarea Sistemului naţional de securitate cibernetică, Monitorul Oficial Partea I nr. 296 din 23.05.2013

8. ***, Information systems defence and security: France’s strategy, French Network and Information Security Agency, Paris, 2011

9. ***, Joint Publication 3-12 (R), Cyberspace Operations, 2013 10. ***, National Cyber Security Strategy 2016-2021, issued by HM Government,

2016 11. ***, Sala Constitutional, La Sala en la Prensa 2010(2011) p. 118 at www.poder-

judicial.go.cr/sala-constitutional/documento/salaenpresa2010.pdf (14.02.2017) 12. Dănuţ Turcu, Main Information Security Activities Of An Intelligence Service, in

Buletin of “CAROL I” National Defense University, No. 1/2014, Bucuresti, 2014 13. http://eur-

lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2009:0149:FIN:EN:PDF 14. http://www.europarl.europa.eu/sides/getDoc.do?pubRef=-

//EP//NONSGML+TA+P7-TA-2012-0237+0+DOC+PDF+V0//EN 15. https://ccdcoe.org/cyber-definitions.html 16. https://ccdcoe.org/sites/default/files/documents/CCDCOE_Tallinn_Manual_Onep

ager_web.pdf 17. Paolo Passeri, 2016 Cyber Attacks Statistics, at

www.Hackmageddon.com/2017/01/19/2016-cyber-attacks-statistics/ (16. 02.2017)

18. Sorin Topor, Aproach About Joint Cyber And Electronic Warfare And Futures Of The Military Operations, in the 10th International Scientific Conference “Strategies XXI”: Strategic Changes In Security And International Relations, vol. 3, “CAROL I“ National Defense University Publishing House, Bucharest, 2014

19. Stephen Tully, A Human Right to Access the Internet? Problems and Prospects, in Human Rights Law Review, vol. 14, Issue 2, Oxford University Press

20. Yoneji Masuda, The Information Society as Post-Industrial Society, World Future Society, Washington D.C., 1981

146

Reproduced with permission of the copyright owner. Further reproduction prohibited without permission.