Cyber Policy Scenario

profileCyberSter
CyberResilienceAnEssentialnewParadigmforEnsuringNationalSurvival.pdf

Cyber Resilience: An Essential new Paradigm for Ensuring National Survival

William Arthur Conklin1 and Anne Kohnke2 1College of Technology, Houston, USA 2College of Management, Lawrence Technological University, Southfield, USA [email protected] [email protected] Abstract: Cyberspace is full of adversaries with potential actors ranging from state-sponsored groups to criminal enterprises, to anyone with an Internet connection who wishes to do harm. Due to financial limitations, organizations historically prioritized what systems and information assets to protect and hoped that an attacker would not find under protected systems. The paradigm that is presented argues that a cyberresilient strategy is a more effective and cost-efficient approach to protecting America’s critical infrastructure. The focus on maintaining core functionality, rather than protecting data is at the heart of cyberresliency with the idea to restrict the defense of less critical, or peripheral elements, while ensuring the survival of the system as a whole. This paper presents both the justification and underlying principles for implementing cyber resilience, as well as a standard process for designing and deploying a cyber resilient architecture. Keywords: cyber resilience, cyberresilient strategy, critical infrastructure, core functionality focus

1. Introduction With the continued investment in cybersecurity and the pervasiveness of successful breaches, conventional cybersecurity is not working (Symantec, 2014; Trend-Micro, 2015, PRC, 2016). An entirely new approach discussed in this paper, called cyber resilience, ensures that the organization will continue to survive no matter how destructive the attack. This approach is also resource efficient and focuses on the absolute protection of only those functions that are vital to an organization’s survival. Cyber resilience is important because the increasing presence of advanced cyber threats makes it inevitable that every organization will ultimately be targeted (OAS, 2015). Cyber resilience recognizes that there are too many cutting-edge hacking tools to prevent sophisticated attackers from finding the cracks in even the most robust cyber-security perimeter (Lois, 2015). Thus, there is a need for a new paradigm. Cyberspace is full of adversaries with potential actors ranging from state-sponsored groups to criminal enterprises, to anyone with an Internet connection who wishes to do harm. Cyberattacks on the various elements of the U.S. critical infrastructure occur on a daily basis. For instance, the Industrial Control Systems- Computer Emergency Response Team (ICS-CERT) reports that U.S. industrial control systems were attacked at least 245 times over a 12-month period (OAS, 2015). “While China, the U.S. and Russia lead the world in cyber- attacks, virtually every government engages in such attacks, and nearly every country has its share of computer hackers” (Wagner, 2017). The ability to launch a successful cyber-attack makes every nation- state, into a potential super power (Wagner, 2017). Perhaps the most egregious example comes from the Ukraine. In December 2015, a presumed Russian cyber- attacker successfully seized control of the Prykarpattyaoblenergo Control Center (PCC) in the Ivano-Frankivsk region of Western Ukraine (Wagner, 2017). This attack marked the first time that a concerted cyber-attack was successfully launched against a nation’s power grid (Wagner, 2017). However Stuxnet, in 2010, might be the first instance of a nation enforcing policy through other means (Howard & Parot, 1976). The perpetrators of the Ukrainian attack were observed conducting similar exploits against the U.S. energy sector (Brasso, 2016). Although there was never any actual disruption, many experts believe that those activities were a probe for future moves on the U.S. infrastructure (Brasso, 2016). One key question is, “Could a catastrophic cyberattack in the United States Infrastructure ever occur? The National Security Agency’s former Director, Mike Rodgers, made his own evaluation of the possibility of a successful attack against critical infrastructure when he said; “It’s a matter of, when, not if” (Smith, 2014). Power grids are the most frequently mentioned target (Wagner,2016; Brasso, 2016; Smith, 2014) due to the interconnectedness of power grids which opens them up to “cascading failures”. As nearby grids take up the slack for a failed grid system, they overload and fail themselves, causing a chain reaction. Rogers says that such

126

William Arthur Conklin and Anne Kohnke

attacks are part of “coming trends” in which so-called zero-day vulnerabilities in U.S. cyber systems are exploited (Smith, 2014). The reason why the protection of our national infrastructure is so critically important is that a major exploit, like a successful cyberattack on the electrical grid could leave the U.S. cloaked in darkness, unable to communicate and without any form of twenty-first century transport. It would likely kill many thousands of citizens, perhaps millions either through civil unrest, failure of public systems, or mass starvation (Brasso, 2016; Maynor, 2006). Many experts believe that the cyberwar began in 2003 (Wagner, 2017) when the Northeast (U.S.) blackout occurred. That blackout caused 11 deaths and an estimated $6 billion in economic damages (Wagner, 2017). After the attack, SCADA attacks occurred in the UK, Italy and Malta, among others. According to Dell’s 2015 Annual Security Report, cyber-attacks against infrastructure systems doubled in 2014 to more than 160,000. (Wagner, 2017) Infrastructure systems are diverse and coupled with the criticality of the sensors and controllers that comprise a typical infrastructure system, make them tempting targets for attack. Therefore, there have been long-standing concerns about the overall digital infrastructure being vulnerable to cyberwarfare and cyberterrorism attacks (Eisenhauer, 2006, Nat-Geo, 2017). Notwithstanding the disastrous nature of cyberattacks on digital targets, none of the industries in our current national infrastructure have developed coherent plans, or effective strategies, to protect themselves (Brasso, 2016). This has caused an increasing interest in a coherent model for defending the critical infrastructure against cyberattack (Symantec, 2014; E-Y, 2014). The approach we discuss in this paper is particularly suited to ensuring the continued survivability of infrastructure systems because the focus is on maintaining core functionality, rather than protecting data. The idea is to restrict the defense of less critical, or peripheral elements, while ensuring the survival of the system as a whole. This strict emphasis on survivability versus data protection is the reason why cyber resilience, versus cybersecurity, should be considered as the approach of choice for critical systems.

2. A new paradigm for ensuring our way of life This discussion offers an entirely new and different paradigm, one that is both resource efficient and which ensures that the organization will continue to survive, no matter how destructive the attack. The approach is called “cyber resilience” and is not the same thing as cyber security. Cyber resilience ensures the absolute security and reliability of just those critical functions, which the organization needs in order to continue to survive and carry-out its mission. Carl von Clausewitz sums up the role of strategy this way; “Strategy is the necessary response to the inescapable reality of limited resources” (Clausewitz, 1989). No General ever has the luxury of overwhelming numbers or unlimited resources so an approach that needs to be adopted is one that is likely to succeed given the assets that are available at the time of conflict. In this respect, Clausewitz posits that a successful strategy finds the most advantageous point to concentrate all the resources necessary to achieve the primary goal, which is to win the battle, even if some of the lesser objectives are not achieved (Clausewitz, 1989). Cybersecurity is the inheritor of the old information assurance mission and accordingly, cybersecurity is still based around creating and ensuring a protection perimeter. The perimeter is created by assuring all logical points of access to the protected space that lies within that boundary. Since the protection perimeter of even a small organization can involve numerous points of access, electronic, physical and human, this task normally requires an extensive resource commitment to be even be remotely successful. Whereas, cyber resilience only ensures those organization elements that are deemed critical to system survival. The requirement to maintain the functioning of a few critical components is less resource intensive than the need to ensure the confidentiality, integrity and availability of all assets within secure space. Therefore, cyber resilience is much more resource efficient and the narrowing of scope allows protection measures to be concentrated onto a far smaller attack surface, which notionally ensures more effective protection for the things that simply can’t be allowed to fail.

3. Operationalizing cyber resilience - Saltzer and Schroeder’s principles Cyber resilience is founded on classification, prioritization, and comprehensive strategic policy-based deployment of a rigorous set of real-world security controls (Symantec, 2014). Cyber resilience requires the

127

William Arthur Conklin and Anne Kohnke

creation of a set of well-defined processes, which react to penetrations of the organizational perimeter by locking down the asset they are designed to protect (US- CERT, 2016). These protection processes are both electronic and behavioral in focus and they are designed to protect key assets, as well as ensure optimum recovery of the overall system in the event of successful attack (Symantec, 2014). Saltzer and Schroeder arguably laid down the basis for cybersecurity design in their founding principles (Saltzer, 1974). The concept of cyber resilience hinges on four lesser known principles. Most people in cybersecurity know about and practice design concepts such as Least Privilege, Complete Mediation, Separation of Duties and Psychological Acceptability and fewer people think about these four (Saltzer, 1974):

Economy of mechanism: Keep the design as simple and small as possible.

Work factor: The cost must be greater than the potential attacker is willing to commit.

Least common mechanism: Minimize the amount of mechanism common to all users.

Compromise recording: reliably record the actions of a compromise.

The principles underlie the cyber resilience approach. Economy of mechanism advises the construction of simple strongpoints around critical assets, rather than basing the protection on the complexities of comprehensive perimeter access control. In conventional military tactics, a strongpoint is a key position, which is very difficult to overrun or avoid. With respect to illustrating the difference between cyber resilience and cybersecurity, one example would be that a strongpoint is like locking critical assets in a safe, rather than protecting them by assuring access to the building they are in, which is perimeter access control. In military doctrine, strongpoints are arrayed in mutually supporting, defense-in-depth defense in depth mesh arrangements called hedgehogs, rather than formed into a contiguous line of increasingly rigorous perimeter access controls. The hedgehog arrangement implements the principle of least common mechanism in that strongpoint defenses are tailored to just the threats affecting the protection target. This allows for very straightforward simplicity in the design. It also allows the organization to maximize security resources by building up the capabilities of only the protection for the critical features, rather than diffusing the investment by attempting to protect everything. Most importantly, if the strongpoint protecting the critical assets are robust enough, they will be too expensive for the attacker to assault. So, the attacker will be shepherded to more vulnerable targets. That is the work factor principle in operation. Work factor also serves to maximize the defender’s rapid response capability. In effect, organizations will be able to rapidly concentrate their resources at the point of attack knowing that the essential functions are protected. Since the critical system protection, e.g., strongpoint, positions, will be bypassed due to their impossibly high work factor rate, the organization will be able to concentrate its resources on recovery of non-critical functions and information. Finally, the organization will be able to deploy and conduct the most effective recovery possible because information from prior incidents will be available to planners and responders to help optimizing the response. That is the intent of the compromise recording principle. In essence, the effect of an attack on a non-essential resource can be minimized through lessons learned from prior attacks. In addition, the road to recovery can be planned in advance because the execution and outcomes of the attack have been recorded for study.

4. Tactics one and two: Economy of mechanism and work factor Cyber resilience involves the formulation of well-defined strategies and the implementation of rigorous strongpoint countermeasures, which are designed to inflict unsustainable work factor requirements on attacker. Consequently, the most important thing the organization needs to know is, “exactly how many strongpoints will I need to build and exactly how much investment will be required to make each strongpoint infeasible to attack?” It should be possible to identify all those organizational functions that are too critical for the organization to lose and still stay in business. This involves a simple strategic planning process and accordingly, the organization will then concentrate sufficient resources to ensure that those specific protection targets will always demand too great an investment on the attacker’s part. Thus, cyber-resilient architectures are founded on making decisions about what the organization can’t afford to lose and then ensuring that it won’t lose them.

128

William Arthur Conklin and Anne Kohnke

The success of a cyber-resilient defense hinges on defining protections for critical assets that are too costly for the attacker to break. The protections do not have to ensure absolute and unquestionable security, but they DO have to assure enough protection that attackers will find the resource investment unpalatable, and thus, move on to another target. Since there are likely to be a much greater number of soft targets, e.g., non-essential assets, than hard ones, cyber resilience defenses will not require as great an investment as a strategy that is aimed at protecting all the resources, soft and hard, inside a perimeter.

5. Tactic three: Least common mechanism In order to implement a proper strongpoint defense, the relationship between the system’s critical assets must be identified, and labeled. This is necessary to establish the precise state of dependencies and interdependence of objects within the system. And more importantly, the interface between the users of those assets must be well understood and characterized for the purpose of implementing control. Next, a broad-spectrum risk assessment should be performed for each of the identified system interdependencies and user accesses. The idea is to obtain full situational awareness both in terms of critical asset interactions, as well as the potential threats arising from them. Using this awareness, a provably effective control response must be deployed for each of the critical assets. Focus resources on assuring only those components that are designated as critical. This is primarily an engineering design exercise, driven by precise knowledge of the components and their inter- relationships. The resources that are left over after all critical asset dependencies are ensured are then allocated to protection and recovery of the rest of the system. Since no single function operates separately from all other critical functions, the resilience must be incorporated into the architecture in such a way that critical functions cannot be accessed by a backdoor. This is a pure design/control deployment exercise. Nevertheless, resilience of the critical asset control design and deployment must be evaluated and confirmed to be correct. This is a classic testing and assurance function that periodically characterizes the effectiveness of critical control performance against stated mission goals.

6. Tactic four compromise Recording and strategic recovery planning Well-defined processes need to be established to ensure that all data obtained from both attacks and compromises is recorded for analysis and planning. The aim is to ensure that all system functions are fully restored within requisite parameters, based on a method, or plan. This requires a suitable array of evidence gathering review and testing processes and metrics sufficient to evaluate any form of compromise for future planning (Bradford, 2017). The aim is to allow the organization to wholly understand it’s digital environment and to build the most effective rapid response team, with the expectation to design well-defined scenarios for how each attack will be managed. The main reason why compromise recording is so effective is that ninety-two percent of cybersecurity incidents fall into nine basic attack patterns (Verizon, 2014):

Cyber Espionage

Insider Misuse

DOS Attacks

Crimeware

Web App Attacks

Payment Card Skimmers

Point of Sale Intrusions,

Miscellaneous Errors

Physical Theft and Loss

All of these basic attack patterns can be studied, documented, and a response crafted to ensure the most effective resolution for a given known situation. The ability to dynamically respond to exploits, based on lessons learned is crucial to keeping costs down. If this is done effectively, the organization will have both security and cost efficiency.

129

William Arthur Conklin and Anne Kohnke

7. Conclusion The increasing presence of advanced cyber threats makes it inevitable that all organizations will ultimately be targeted (OAS, 2015). Data indicates that conventional cyber security approaches will never be able to successfully protect us (Symantec, 2014; Trend-Micro, 215, PRC, 2016). Cyber resilience requires the organization to spend whatever it takes to develop a well-defined, explicit set of controls to ensure survival of just those critical elements that cannot be subject to compromise. The controls must assure provable protection of core functionality and the various interdependencies in the enterprise’s eco-system (EY, 2014). The concept of cyber resilience goes far beyond the classic boundaries of better access controls (EY, 2014). Instead, organizations establish a “cyber resilience strategy and architecture” that gives them the ability to withstand and recover rapidly from disruptive events (EY, 2014). Practically speaking, the best argument for cyber resilience is that it concentrates resources where they will make the most difference. This is particularly germane to national security in that any attack on an infrastructure element threatens a lot more than simple business processes. Thus, cyber resilience is a particularly significant aspect of ensuring survival and easing recovery of the critical systems that underwrite our way-of-life. In general, it is our belief that very little substantive thinking has taken place when it comes to a specific and generally implementable approach protecting the critical infrastructure. This is partly because there is no practical process that explicitly dictates how to unfailingly protect critical infrastructure components, given the inevitability of failure in traditional approaches. The ideas presented here are a start toward eventually overcoming this lack of knowledge and presents a process and a framework for structuring and communicating standard cyber resilience best practice to the educational community at large.

References Brasso, B. (2016) “Cyber Attacks Against Critical Infrastructure Are No Longer Just Theories”, [online], Fire-Eye,

https://www.fireeye.com/blog/executive- perspective/2016/04/cyber_attacks_agains.html. Bradford, Contrel (2017), “Disaster Recovery Metrics: What They Are and How to Use Them,” Recovery Zone,

http://www.storagecraft.com/blog/disaster-recovery-metrics-use/, accessed March 2017 Conklin, William Arthur, Dan Shoemaker and Anne Kohnke (2017), “Cyber Resilience: Rethinking Cybersecurity Strategy to

Build a Cyber Resilient Architecture, International Conference on Cyber War, Dayton, OH Eisenhauer, J., Donnelly, P., Ellis, M., and O’Brien, M (2006)., Roadmap to Secure Control Systems in the Energy Sector, Energetics Incorporated, Sponsored by the U.S. Department of Energy and the U.S. Department of

Homeland Security, January 2006. Ernst and Young (2014), “Achieving Resilience in the Cyber Ecosystem”, [online], Ernst and

Young,http://www.ey.com/Publication/vwLUAssets/cyber_ecosystem/$FILE/EY- Howard, Michael and Peter Paret, Carl von Clausewitz, On War, Princeton University Press, 1976 Lois, J. E. (2015) “It Can Happen to You: Know the Anatomy of a Cyber Intrusion,” Navy Cyber Defense Operations

Command (NCDOC), Story Number: NNS151019-05, Release Date: 10/19/2015. Maynor and R. Graham (2006). "SCADA Security and Terrorism: We're Not Crying Wolf", X-Force, Black Hat,

file:///C:/Users/dansh/AppData/Local/Temp/BH-Fed-06-Maynor-Graham-up-1.pdf, accessed March 2017 National Geographic Channel, "American Blackout". March, 2017accessed 3-14-2017. OAS. (2015) “Report on Cybersecurity and Critical Infrastructure in the Americas, Organization of American States”,

[online] Trend Micro Incorporated, https://www.trendmicro.com/cloud- content/us/pdfs/security- intelligence/reports/critical-infrastructures-west-hemisphere.pdf.

Privacy Rights Clearinghouse. (2016). “A Chronology of Data Breaches,” PRC, San Diego, California. Symantec. (2014) “A Manifesto for Cyber Resilience”, [online], Symantec,

https://www.symantec.com/content/en/us/enterprise/other_resources/b-a-manifesto-for- cyber-resilience.pdf. Trend Micro. (2015) “Report on Cybersecurity and Critical Infrastructure in the Americas, Organization of American States”.

Trend Micro Incorporated. https://www.trendmicro.de/cloud-content/us/pdfs/security-intelligence/reports/critical- infrastructures-west-hemisphere.pdf

US-CERT. (2016) “Cyber Resilience Review (CRR)”, [online], Department of Homeland Security, https://www.us- cert.gov/sites/default/files/c3vp/crr-fact-sheet.pdf.

Verizon, 2014 Data Breach Investigations Report, Verizon Corporation, 2014 Wagner, Daniel and Bailey Schweitzer, “The Growing Threat of Cyber-Attacks on Critical Infrastructure”, THE BLOG,

May,25, 2017, http://www.huffingtonpost.com/daniel-wagner/the- growing-threat-of-cyb_b_10114374.html accessed July, 2017

130

xiv

conferences. His award-winning research has gained a spotlight as the Best Paper of the 15th International Conference on WWW/Internet in Mannheim Germany. Dr Joey Jansen van Vuuren is the manager of the Cybersecurity Centre of Innovation at the CSIR in South Africa. The Centre focuses on the promotion of cybersecurity research collaboration, education and threat exchange. As Research Leader for Cyber Defence she gave strategic research direction for South African National Defence Force and Government sectors. Her own research focus on cybersecurity governance and policy. Anas Mu’az Kademi is a doctoral candidate under the supervision of Assoc. Prof. Ahmet Koltuksuz in computer engineering at Yasar University. His PhD research explores how cyberspace can be formalized–using cellular automata. He holds M.Sc. from the same university. Interested in information security, cyber-warfare, networking, cellular automata and strategic cybersecurity. Min Kang is a 2d Lt and is currently a student pursuing his Master’s degree in Computer Science with a concentration in Cyber Security at the Air Force Institute of Technology. After graduation, he will attend Undergraduate Cyber Training to become a Cyberspace Operations Officer. Martti J Kari is PhD student of cyber security in Jyväskylä University, Finland. He retired as colonel from Finnish Defense Intelligence in the end of year 2017. His last post was assistant chief of Defense Intelligence. He has MA in Russian language and literature in Jyväskylä University. Kari has worked as a university teacher from the beginning of year 2018 In Jyväskylä University. Omer F. Keskin is a Ph.D. Student in Engineering Management and a Graduate Assistant in Old Dominion University. He holds an MS Degree in engineering management and a BS degree in systems engineering. His research is focused on risk and reliability analysis of critical infrastructure cyber physical systems. Anne Kohnke is an assistant professor of IT at Lawrence Technological University in the United States where she teaches courses in both information technology and organization development/change management disciplines at bachelor through doctorate levels. Her research focus is in the areas of cybersecurity, risk management, IT governance, and extraterritorial surveillance and privacy. Anne earned her PhD from Benedictine University. Captain Juha Kukkola has Master’s degree in Political science (2005) and Military science (2008) and serves as a research officer at Finnish National Defense University (FNDU). He is currently PhD student at FNDU and is writing his doctoral thesis on Russia’s military cyber power and strategy. He has served in Finnish Defense Forces from 2008 as a platoon leader, signals officer, staff officer and lecturer. He is specialized in Air defense, C4 systems and Russian and Cyber studies. He can be contacted by email at [email protected] Hyong Lee is a Senior Policy Analyst with National Defense University’s (NDU) Center for Applied Strategic Learning (CASL) in Washington DC. Mr. Lee started his career in government service in 1992 as a Presidential Management Intern (PMI), now known as Presidential Management Fellows. In 1996, Mr. Lee moved to Hawaii, where he eventually became Chief of the Decision Support Branch (J084) at US Pacific Command. As Chief of J084, he oversaw the development and execution of a number of seminar games and table top exercises. Mr. Lee joined NDU in January 2002 when he started working at the National Strategic Gaming Center (NSGC), the prior incarnation of CASL. He supports exercise efforts for the various components of National Defense University, the Joint Staff, combatant commanders, and CASL outreach audiences. His more recent projects include anti-terrorism / force protection, consequence management, cyber security, and integrating more technology into exercises. Louise Leenen is a Principal Researcher in the Cyber Defence research Group at the Council for Scientific and Industrial Research (CSIR), South Africa. She holds a PhD Computer Science (in Constraint Programming) from the University of Wollongong in Australia. Her research focus is on artificial intelligence applications in the defence environment, cyber defence and ontology development. She is the Chair of the IFIP Working Group 9.10 on ICT in War and Peace. Martti Lehto, PhD (Military Sciences), Col G.S. (ret.) is Professor in Cyber security in the University of Jyväskylä in the Faculty of Information Technology. He has over 30 years’ experience as developer and leader of C4ISR Systems in Finnish Defence Forces. Now he is a Cyber security and Cyber defence researcher and teacher and the pedagogical director of the Cyber Security MSc. program. He is also Adjunct professor in National Defence University in Air and Cyber Warfare. He has

Reproduced with permission of copyright owner. Further reproduction prohibited without permission.