Cyberwar in Practice

profileCyberSter
Russian_Cyber_Power_and_StructURALAsymmetry.pdf

Russian Cyber Power and Structural Asymmetry

Juha Kukkola Finnish National Defence University, Helsinki, Finland [email protected] Abstract: Russian Federation aims to be an independent cyber superpower. Russian national cyber power is based on structural changes of Internet governance. This paper argues that by developing so-called ‘digital sovereignty’ Russian Federation is intentionally creating asymmetric advantage in cyberspace. This ‘structural cyber asymmetry’ is both defensive and offensive resource of national cyber power. By shaping and delineating cyberspace on technical, syntactic, and semantic levels with technical, administrative, and political tools to closed national network, i.e. RuNet, Russia achieves disproportionate military advantage on strategic level. Firstly, this paper presents the concept of ‘structural cyber asymmetry’ to challenge traditional notions of asymmetry and cyber power. Secondly, it examines influential Russian military academic writings and most important policy documents to understand how Russians perceive cyber power and the shaping of cyberspace on strategic level. Thirdly, it provides discussion on ‘structural cyber asymmetry’s’ effects on Russia’s national cyber power. This paper shows, that although there are significant terminological and conceptual differences between Western and Russian understandings of cyber issues, ‘structural cyber asymmetry’ provides a beneficial tool for understanding Russian cyber policy. It resonates decidedly better with Russian strategic cultural thinking than traditional Western concepts. This paper also provides fresh theoretical view on Russia’s cyber policies and finds evidence that Russia is intentionally shaping cyberspace to enhance its military cyber power. The overall aim of this paper is to increase understanding of Russian security and military strategy in cyberspace by using novel concepts and original, Russian language sources. Keywords: Russian cyber power, structural asymmetry, digital sovereignty, RuNet, closed national network

1. Introduction The future of Internet as borderless, open, free and secure sphere of human activity is challenged. It is confronted by the will of some nation states to apply principles of territorial sovereignty to Internet. This process has been called the birth of ‘Cyber Westphalia’, and it will affect how we conceptualize and utilize cyber power now and in the future (Demchak & Dombrowski, 2011; Demchak & Dombrowski, 2013). Starting, at the latest, from 2014 Russian Federation has been at the forefront of this process (Sovet Bezopasnosti Rossiiskoi Federatsii 2014). It codified this process to policy by releasing new Information Security Doctrine in 2016 (Doktrina, 2016) which was aimed at controlling the Russian segment of Internet, summarized as ‘digital sovereignty’ (Tsifrovaia ekonomika, 2017; Strategiia, 2017; Yefremov, 2017). Mari Ristolainen has argued that this project ‘RuNet 2020’ is aimed at safe, closed, and fully state controlled Internet and that we should take this project seriously (Ristolainen, 2017). The declaratory aims of ‘RuNet 2020’ are related to national security especially in the information sphere. As has been argued in further studies, building of a closed national network is not only a defensive measure. It might also have an offensive aspect, and have a profound impact on military cyber power balance for the disadvantage of states relying on safe, open and secure Internet principles. This phenomonen has been identified as ’cyber asymmetry’ (cf. Kukkola et al. 2017). Recent studies on Russia’s military and security policies have shown that the Russian approach to deterrence is more comprehensive than Western ones and that a search for asymmetry is part of it (Thomas, 2015; Bruusgaard, 2016; Adamsky, 2017). Built on this view of deterrence, centrally state controlled mobilization of material and human resources is still a valid policy in Russian security politics (Cooper, 2016). If we combine these observations with the perceived blurring of distinction between peace and war (Wirtz, 2017), the study of Russian cyber power on strategic level is highly topical research agenda. In this paper, I further develop the idea of ‘cyber asymmetry’ and define it more rigorously as ‘structural cyber asymmetry.’ I also argue that some states strive to ‘structural cyber asymmetry’ based on their historical, culturally bound strategic thinking. Overall, the aim of this paper is to increase understanding of Russian security and military strategy in cyberspace by using novel concepts and original, Russian language sources. The first part of this paper is introduction. Second part is conceptual analysis of the ‘structural cyber asymmetry.’ It is based on previous studies of cyberspace, cyber power, military strategy, and military asymmetry. Third and fourth parts are qualitative content analysis of leading Russian military journals from the period of 2000-2017. I show how Russians understand military asymmetry, how they discuss about shaping of cyber space, and how asymmetry is understood in these discussions. Fifth part goes on to analyse principal doctrines and strategies of

362

Juha Kukkola

Russian Federation. In it, I show that the documents reflect the ideas presented in the journals and that doctrines and strategies could lead to ‘structural cyber asymmetry.’ In the sixth part, I provide a synthesis and discussion on asymmetry and Russian cyber power.

2. Structural cyber asymmetry The concept of ‘structural cyber asymmetry’ is based on the premises that cyber power is contextual and relational phenomenon. It only gains meaning through the situation it is used in (Baldwin, 1989; Guzzini, 1993). In this paper, power is understood to be used in and through cyber space which is understood as “an electronic medium through which information is created, transmitted, received, stored, processed and deleted” (Godwin III, et al., 2014). Cyber space is man-made and malleable environment, and a domain of human activity that has its own characteristics which affect the use power (Libicki, 2007). From these premises, I derive the following definition of cyber power: “an ability that empowers an actor to influence others in or through cyber space and to shape it to its advantage according to its preferences” (Cf. Endresen, 2016). The use of cyber power is intentional, although not always strictly rational, and, as such, tied to the ideas and beliefs actors have concerning power, its use, and the world at large (Gray, 1999). This is reflected in the kind of strategies actors choose to utilize power. It should be emphasized that these cyber strategies, understood as planning, preparation and action, are always implemented against an opponent that has power and will of its own (Luttwak, 2001). In Western military thinking, asymmetry has been connected to ‘asymmetric warfare’ or ‘conflict’ since 1970s (Freedman, 2013). Basically, asymmetric warfare came to be defined as warfare by non-state actors against military superpower or coalition that relied on high-tech conventional capabilities and methods and was restrained by fear of casualties and collateral damage (Evans, 2005). Approach to asymmetry based on means and methods is, however, too narrow. The reason is, firstly, that there is more to asymmetry than non-state actors and unconventional means. Secondly, cyberspace is artificial and can be shaped according to security needs of states. Thirdly, some states are willing to depart from the idea of global commons towards nationally controlled closed networks. And fourthly, closed networks provide both defensive and offensive advantage (Kukkola, et al., 2017, 166). It has even been proposed that asymmetry is part of every conflict and ‘asymmetric warfare’ is a-historical misnomer (Strachan, 2013). Building on previous studies (cf. Kukkola, et al., 2017), I propose ‘Structural cyber asymmetry’ as a different kind of approach. It is based on the notion that shaping of cyberspace by creating a closed nation network creates asymmetry in power. It is a disproportionate, exploitable imbalance between actors (Oehmen & Multari, 2014). Cyberspace can be analyzed as ‘digital territory’ consisting of distance between points (hops), borders between subspaces (Firewalls, filtering, routing, subnetworks and AAA –policies etc.) or environment (electromagnetic radiation, protocols, information processes). The nature of this territory affects actors. ‘Structural cyber asymmetry’ is relational and structural concept. Although structural asymmetry is connected to the resources of a nation, asymmetry is not a direct result of utilizing those resources, but is intermediated by the attributes of cyberspace. Structural asymmetry is not, then, a resource or capacity of actor, but an attribute of cyberspace. Digital territory is not shaped directly. Cyberspace is affected by technology, governance, politics and norms. By studying these, it is possible to see where, when and how asymmetry is deliberately or unintentionally created. Asymmetry provides advantage through differences in the quality of situation awareness, speed of decision-making, and freedom of action. By comparing these three elements between belligerents, it is possible to make observations on disproportioned advantages. The effects of ‘structural cyber asymmetry’ on strategic level relate to ways to use force. It is argued that asymmetry through the closing of national networks provides a belligerent definite advantage in deterrence, in controlling the way conflict evolves, and in threatening opponent from a position of strength. (Kukkola, et al., 2017, 171).

3. Russian asymmetry as a strategic response The concept of asymmetry is most often used in Russian journals in the context of ‘asymmetric response’ (asimmetrichnii otvet). Asymmetric response can be considered as ‘genuine’ Russian concept and it gives context to Russian understanding of asymmetry. ‘Asymmetric response’ was first used during 1980s, when Soviet Union tried to counter United States’ Strategic Defense Initiative and AirLand Battle doctrine. Later, it has become a catch phrase meaning cost-effective solution to military unbalance between great powers (Kokoshin, 2007).

363

Juha Kukkola

‘Asymmetric response’ is defined by other concepts. First is the rather consistently defined concept of military power (Kirillov, 2005). Military potential (potentsial) consists of all material and moral resources that can be mobilized as military power (moshch’) through states’ military policy. Strategy utilizes military power by planning, organizing and conducting use of force through forces and means (sily i sredstva) and forms and methods (formi i sposoby). Perceived change in the character of war in 2000s – 2010s has high-lighted the role of peace time, non-military, indirect, and asymmetric action as part of military strategy (Kartapalov, 2015; Gerasimov, 2017). Second defining concept is that the Russian Federation is a great power (derzhava), so asymmetry for Russia is related to balance of power between great powers (Strategiia, 2015). Third defining concept is ‘counter struggle’ (protivoborstvo). It derives from Russian strategic culture which is based on Soviet past and Cold war. Basically, it presupposes that relations between great powers are constant dialectical struggle for pre-eminence with all means at their disposal (Babich, 2008; Shalamberidze, 2011). Fourth one is strategic deterrence (strategicheskoe sderzhivanie). Strategic deterrence is a complex set of measures to anticipate threats, persuade, threat, and coerce aggressors, and if needed, to restrict escalation and inflict unbearable costs on aggressors. It has a peace time function to protect interest, neutralize threats and a war time function to eliminate them. (Khriapin & Afanas’ev, 2005; Matvichuk & Khriapin, 2010). The above mentioned concepts should be understood as parts of Russian strategic culture which is state-centric and antagonistic to United States and NATO (Strategiia, 2009; Strategiia, 2015). ‘Asymmetric response’ has been a recurring theme in Russian military discussion during 2000-2017 (Mikhailov, 1999; Kolyvanov, 2006; Gorbachev, 2006; Kulakov, 2008; Chekinov & Bogdanov, 2012; Kartapalov, 2015; Gerasimov, 2017). It can be summarized as a military strategic idea that promises cost-effective solution for strategic deterrence against perceived threat. Aspiration to military parity or symmetry with all costs is anathema because it is perceived to have led to the collapse of the Soviet Union. Instead, vaguely defined indirect and asymmetric actions or means should be developed and used. They are based on protecting national critical assets, finding out potential opponent’s weaknesses, developing ways to threaten those weaknesses (creative use of resources at hand or developing innovative technology), forecasting the future, obfuscating opponent about real capabilities, and neutralizing possible threats through military means, diplomacy, politics, economy and information ‘counter struggle’. Advantage should be sought already in peace time. ‘Asymmetric response’ has been used to define actions against United States’ missile defence program and cyber capabilities, Prompt Global Strike program, Network Centric Warfare (NCW) concept, use of ‘colour revolutions’ and lately against ‘controlled chaos’ or United States’ and NATO’s ‘hybrid war’ against Russia. Concepts of ‘structural cyber asymmetry’ and ‘asymmetric response’ resonate quite well with each other. There are same elements in both and creation of a closed national network could be considered as protecting critical assets (information and infrastructure) to gain asymmetric advantage cost-efficiently, and as providing added means of deterrence besides conventional military and nuclear ones.

4. From weakness to strength – Information asymmetry Russian military journals were already discussing ‘information warfare’ (bor’ba) in the beginning of 2000s (Kalinovskii, 2001). Some claimed that in the context of ‘informatization’ (informatizatsiia) information confrontation takes primacy over armed warfare. Its essence was the battle for information supremacy (prevoskhodstvo) which alone could achieve political objectives (Bogdanov 2003). Others contested this view, and sought more restricted, operationally useful definition (Gorbachev, 2006; Orlianskii, 2002 & 2008). The militarization of information space worried Russians already in 1998 when they put forward in United Nations their proposal on international information security. In their view, United States dominated Internet and used it to threaten less developed states with ‘information weapons’. (Dylevskii, et al., 2007). On the operational- tactical levels Russians were trying to solve, how NCW could be applied to their armed forces and how new means of information warfare (with competing definitions) should be integrated into the current doctrine (Vypasniak, 2009; Dul'nev, et al., 2011). On strategic level, Russians developed the concept of Unified military information space. It was based on United States’ Defense Information Systems Network (DISN) (Sherstiuk, 2003; Karpov, et al., 2004). ‘Informatization’ has been presented both as a military threat and as a possibility. It was a threat because Russia was lacking behind its potential opponent in information sphere and that opponent controlled Internet (Molchanov, 2008; Litovkin, 2011). Internet, as defining part of information space, is perceived as a national security interest for Russia. Possibilities, which were thought as asymmetric responses, were: international

364

Juha Kukkola

control over ‘information weapons’ (Dylevskii, et al., 2007), cheapness of information-technological means (compared to e.g. nuclear weapons) (Kalinovskii, 2001), counter-C2 against NCW by using Electronic Warfare (Dul'nev, et al., 2011), and, most interestingly, creation of unified military command and control system (EASU). The last one is based on an idea developed in Soviet times, and is based on national, inter-governmental, hierarchical, command and control network. (Baraniuk, 2003; Korytko & Sheptura, 2011). It is an example of how strategic culture shapes the thinking about information warfare in Russia. In the beginning of 2010s military journals published articles on conceptual differences of cyber space and information space. They referred to Western, mainly American, academic studies and policies, and to domestic academic studies. One of the main conceptual problems was, how to separate or combine cyber, electronic and information (psychological) warfare (Antonovich, 2011; NVO, 2013). A kind of compromise was information- technological warfare which defined means as technological but objects as ranging from infrastructure to decision-making and will of the opponent (Strel'tsov, 2011; Chekinov & Bogdanov, 2012). Cyber, as a term, almost never appeared in official documents (cf. Doktrina, 2016). Discussions in the journals were probably affected by the official use of the term ‘information’ instead of ‘cyber’, although cyber was still used up to 2017 in some articles (Gerasimov, 2017). Around 2011 the new threat of ‘controlled chaos’ and later ‘hybrid war’ strengthened demands for, on the one hand, controlling national information space, and, on the other hand, ensuring access to global information space in case of a blockade. (Kuznetsova, 2013; Vorob’ev & Kiselev, 2014). ‘Information counter struggle’ was also elevated to the realm of national and military security, and strategic deterrence was given an information component (Gryzlov & Pertsev, 2015; Chekinov, et al., 2015; Romashkina & Koldobskii, 2015). Information (in its technological and psychological dimensions) was now considered to have strategic effect which required militarized, whole-of-government approach (Dylevskii, et al., 2016). Clearly disillusioned by Russia’s unsuccessful bid to create international agreement to ban ‘information weapons’, Russian writers proposed more regional arrangements for information security (Beliantsev, et al., 2015; Dylevskii, et al., 2016). None of the articles studied in this paper directly refers to cyber or information-technological ‘power’ or ‘digital sovereignty.’ Although, it should be noted, that the term ‘information power’ (informatsionnaia moshch’) has been described in other sources as information infrastructure, scientific- technological potential, intellectual potential, means of information counter-struggle etc. (cf. Beprintev, 2011). In the articles, power is implicitly present as aspects of military security and power: as information, technological, and economic potential. Its negation, weakness, is associated to vulnerabilities of critical information infrastructure, deficiencies in automatic command and control systems of military, dependence on foreign technology, and level of education. ‘Digital sovereignty’ is also implicitly present as many authors state that states will fall prey to stronger ones if they do not control their information space and devolop their capabilities (Chekinov & Bogdanov, 2015; Chekinov, et al., 2015). United Sates was presented as a potential opponent in 2000s and later as a clear and present enemy in information sphere. Russians acknowledged that they were weaker than United States technologically and economically, and a response (otvet) was needed. Search for asymmetry is implicitly, and in some texts explicitly, present. Russia must contain United States and NATO with international agreements and with cooperation with willing partners, and it must develop technical means which are based on vulnerabilities of more developed states, and protect itself from use of information-technical use of force. This is partly done by shaping cyberspace.

5. Asymmetric ideas in to action Russian Federation’s National security strategy (Strategiia, 2015) states that information security is part of national security, and that national security is ensured by information (partly technological) means. Information means are part of strategic deterrence and prevention of military threats. Critical information infrastructure is one of the objects of information threats. According to Military doctrine of Russian Federation (Doktrina, 2014) military threats are present in information space (informatsionnoe prostranstvo). These emanate from the use of ‘information or communication technology’ to inter alia against sovereignty and territorial integrity. To reduce these threats all security organizations should be connected to unified network. Also, one of the tasks of armed forces is the construction of information management system and its integration with automatized command

365

Juha Kukkola

and control systems on all levels of military hierarchy. Military policy of Russian Federation includes cooperation on information-technological issues with interested states. Doctrine of information security of Russian Federation (Doktrina, 2016) states that Russia has national interests in information sphere (informatsionnaia sfera). Protection in peace time, under threat, or during war of critical information infrastructure, which may reside outside of Russian borders, and of unified communications network, is one of the national interests of Russia. One other interest is protection of sovereignty in information sphere. These interests are threatened by foreign counties using information-technological means. In the context of military defence, Russia responds to these threats with strategic deterrence and by ensuring protection of its systems with inter alia information forces and means. Russia also enhances stability (ustoichivost’) of its critical information infrastructure and avoids giving control of its infrastructure to foreign actors. Lastly, in the context of strategic stability, Russia ensures information security by “developing national management system of the Russian part of Internet.” This should be done in centralized and vertical fashion. Strategy of the development of the information society in the Russian Federation 2017 – 2030 (Strategiia, 2017) is based on above mentioned documents. Strategy states, that to protect the critical information infrastructure of the state and national telecommunication networks, regulation, centralized monitoring and control of information systems and networks must be ensured. These objectives are achieved, for instance, by independent functioning of Russian segment of Internet which requires state control of said segment. Based on the strategy, Russian government updated its State program ‘Digital economy of the Russian Federation’ (Tsifrovaia ekonomika, 2017) which states that in information security Russia shall achieve ‘digital sovereignty’ in 2020. All the documents addressed here highlight the importance of developing and protecting scientific- technological and economic base of state. The drive to unify and control national cyber space is clearly present. So is the desire to respond to the perceived threats from information space. Main elements of this response are the ability to close out threats, establishment of organizations to deter threats, reduction of threats by regional cooperation, and development of strong digital economy. It should be noted that none of the documents mention asymmetry or aggressive intentions, only prevention and deterrence.

6. In conclusion Based on the analysis presented in this paper Russians have not been so much interested in elements of cyber power but instead in its implementation. Their discussions in academic journals and policy documents are threat-based, defensive. Still, Russians have a well-defined concept of military power which includes information-technological potential. Also, as they are routinely discussing United States’ cyber capabilities, they are implicitly discussing about their own strengths and weaknesses. They recognize the asymmetry in this relationship and try to find responses to it, asymmetrically. Their answer is, firstly, to protect themselves by applying principles of territorial sovereignty to cyber space. ‘Nationally controlled part of Internet’ enables them to threaten potential aggressors with less fear of surprise attack or retaliation. Secondly, they try to find cost- effective solutions to maintain their strategic deterrence. This is done by finding out technological weaknesses and investing on cost-effective technological innovations. Thirdly, through diplomacy and alliances Russians acquire ways to go around ‘digital blockades’ or ‘sanctions.’ International norm building is part of the strategy. Based on journals and official documents studied in this paper, it is possible to argue, that elements of building ‘structural cyber asymmetry’ are present in Russian military security thinking and policies. Whatever this is intentional policy or not, is an open question. However, shaping of cyber space in the spirit of ‘cyber Westphalia’ is progressing and its implications for global military security should not be taken lightly.

References Adamsky, D., (2017) From Moscow with coercion: Russian deterrence theory and strategic culture. Journal of Strategic

Studies. [Online] Available at: https://doi.org/10.1080/01402390.2017.1347872 [Accessed 5 August 2017] Antonovich, P. I. (2011) O sovremennom ponimanii termina «kibervoina». Vestnik Akademii voennykh nauk, 35(2), pp 89-

96. Babich, V. V. (2008) O novom podkhode k analizu sovremennogo protivoborstva i nekotorykh drugikh problemakh.

Voennaia mysl', 2008(3), pp 33-42. Baldwin, D. A. (1989) Paradoxes of Power. New York: Basil Blackwell. Baraniuk, V. V. (2003) Edinoe informatsionnoe prostranstvo VS RF: problemy sozdaniia. Voennaia mysl', 2003(3), pp 36-38.

366

Juha Kukkola

Beliantsev, A. E., Lymar, A. V. & Kazachenko, A. N. (2015) Informatsionnaia bezopasnost' kak vazhneishii faktor gosudarstvennoi informatsionnoi politiki Rossiiskoi Federatsii. Vestnik Akademii voennykh nauk, 52(3), pp 79-84.

Bogdanov, S. A. (2003) Veroiatnyi oblik vooryzhennoi bor’by budushchevo. Voennaia mysl', 2003(12), pp 2-7. Bruusgaard, K. (2016) Russian strategic deterrence. Survival, 58(4), pp 7-26. Chekinov, S. G. & Bogdanov, S. A. (2012) Strategicheskoe sderzhivanie i natsional'naia bezopasnost' Rossii na sovremennom

etape. Voennaia mysl', 2012(3), pp 11-20. Chekinov, S. G. & Bogdanov, S. A. (2015) Voennoe iskusstvo na nachal'nom etape XXI stoletiia: problemy i suzhdeniia.

Voennaia mysl', 2015(1), pp 32-43. Chekinov, S. G., Bogdanov, S. A. & Popov , O. B. (2015) Problema sovremennoi voennoi bezopasnosti Rossii v usloviakh

globalizatsii. Vestnik Akademii voennykh nauk, 53(4), pp 172-181. Cooper, J. (2016) What If War Comes Tomorrow: Who Russia Prepares for Possible Armed Aggression. Whitehall Report 4-

16, London: RUSI. Demchak, C. & Dombrowski, P. (2011) Rise of a Cybered Westphalian Age. Strategic Studies Quarterly, Spring, 5(1), pp 32 -

61. Demchak, C. & Dombrowski, P. (2013) Cyber Westphalia: Asserting State Prerogatives in Cyberspace. Georgetown Journal

of International Affairs, Internationa Engagement on Cyber III, pp 29-38. Doktrina (2014). Voennaia doktrina Rossiiskoi Federatsii. [Online] http://www.scrf.gov.ru/security/military/document129/

[Accessed 4 October 2017]. Doktrina (2016) Dokrina informatsionnoi bezopasnosti Rossiiskoi Federatsii. [Online]

http://static.kremlin.ru/media/acts/files/0001201612060002.pdf [Accessed 2017 September 22]. Dul'nev, P. A., Kovalev, V. T. & Il'in , L. N. (2011) Asimmetrichnoe protivodeistvie v setetsentricheskoi voine. Voennaia mysl',

2011(10), pp 3-8. Dylevskii, I. N., Komov, S. A., Korotkoe, SV., Rodinov, S. N. & Fedorov, A. V. (2007) Voennaia politika Rossiiskoi Federatsii v

oblasti mezhdunarodnoi informatsionnoi bezopasnosti: regional'nyi aspekt. Voennaia mysl', 2007(2), pp 32-40. Dylevskii, I. N., Zapivakhin, V. O., Komov, S. A., Korotkov, A. A. (2016) O dialektike sderzhivaniia i predotvrashcheniia

voennykh konfliktov v informatsionnuiu eru. Voennaia mysl', 2016(7), pp 3-11. Endresen, R. S. (2016) Hard Power in Cyberspace: CNA as a Political Means. In: Pissanidis, N., Rõigas, H. & Veenendaal, M.

(eds.) 8th International Conference on Cyber Conflict: Cyber Power. Tallinn: NATO CCD COE, pp 23-36. Evans, M. (2005) Elegant irrelevance revisited: A critique of fourth-generation warfare. Contemporary Security Policy, 26(2),

pp 242-249. Freedman, L. (2013) Strategy: A History. New York: Oxford University Press. Gerasimov, V. V. (2017) Sovremennye voyny i aktual'nye voprosy oborony strany. Vestnik Akademii voennykh nauk , 59(2),

pp 9-13. Godwin III, J. B., Kulpim, A., Rauscher, K. F. & Yaschenko, V. (eds.) (2014) Critical Terminology Foundations 2. Russia-U.S.

Bilateral on Cybersecurity. Policy Report 2/2014. Moscow: EastWest Institute and the Information Security Institute of Moscow State University.

Gorbachev, Iu. E. (2006) V inostrannykh armiiakh. Setetsentricheskaia voina: mif ili real'nost'?. Voennaia mysl', 2006(1), pp 66-76.

Gray, C. S. (1999) Modern Strategy. Oxford: Oxford University Press. Gryzlov, B. M. & Pertsev, A. B. (2015) Informatsionnoe protivoborstvo. Istoriia i sovremennost'. Vestnik Akademii voennykh

nauk, 51(2), pp 124-128. Guzzini, S. (1993) The Limits of Neorealist Power Analysis. International Organization, 47(3), pp 443 - 478. Kalinovskii, O. N. (2001) Diskussionnaia tribuna. "Informatsionnaia voina" - eto voina?. Voennaia Mysl', 2001(1), pp 57-59. Karpov, E. A., Burenin, N. I. & Ziuzin, N. A. (2004) Edinoe voennoe informatsionnoe prostranstvo: problemy sozdaniia.

Voennaia mysl', 2004(8), pp 45-49. Kartapalov, A. V. (2015) Uroki voennykh konfliktov, perspektivy razvitiia sredstv i sposobov ikh vedeniia. Priamye i

nepriamye deistviia v sovremennykh mezhdunarodnykh konfliktakh. Vestnik Akademii voennykh nauk , 51(2), pp 26- 36.

Khriapin, A. L. & Afanas’ev, V. A. (2005) Slovo iubiliaram. Kontseptual'nye osnovy strategicheskogo sderzhivaniia. Voennaia Mysl', 2005(1), pp 8-12.

Kirillov, V. V. (2005) Geopolitika i bezopasnost'. Voennaia moshch' gosudarstva: sushchnost', struktura, problemy. Voennaia mysl', 2005(9), pp 2-12.

Kokoshin , A. (2007) Asimmetrichnyy otvet nomer odin. Nezavisimoe Voennoe Obozrenie, 27 July 2007. [Online] http://nvo.ng.ru/concepts/2007-07-27/4_otvet.html [Accessed 4 January 2018]

Kolyvanov, G., 2006. Neponiatnaia asimmeriia. Genshtab popytalsia skazat' novoe slovo v voennoi nauke. Nezavisimoe Voennoe Obozrenie, 3 February 2006. [Online] https://dlib.eastview.com/browse/doc/8960544 [Accessed 4 January 2018]

Korytko, V. K. & Sheptura, V. N. (2011) Problemy postroeniia edinogo informatsionnogo prostranstva Vooruzhennykh Sil Rossiiskoi Federatsii i vozmozhnye puti ikh resheniia. Voennaia mysl', 2011(10), pp 16-26.

Kukkola, J., Ristolainen, M. & Nikkarila, J-P. (2017) Game Changer. Structural transformation of cyberspace. Finnish Defence Research Agency Publications 10. Tampere: Juvenes Print.

Kulakov, A. (2008) Asimmetrichnii otver ne spaset. Nezavisimoe voennoe obozrenie, 25 July 2008. [Online] https://dlib.eastview.com/browse/doc/18663911 [Accessed 4 January 2018]

367

Juha Kukkola

Kuznetsova, N. N. (2013) Ob aktual'nosti problem, sviazannykh s ugrozoi informatsionnoi bezopasnosti. Vestnik Akademii

voennykh nauk, 44(3), pp 46-47. Libicki, M. C. (2007) Conquest in Cyberspace. National Security and Information Warfare. Cambridge: Cambridge University

Press. Litovkin, V. (2011) Kibervoina s sistemami upravleniia. Nezavisimoe voennoe obozrenie, 4 February 2011. [Online]

https://dlib.eastview.com/browse/doc/23680274 [Accessed 4 January 2018] Luttwak, E. N. (2001) Strategy: The Logic of War and Peace. Cambridge: The Belknap Press of Harvard University Press. Matvichuk, V. V. & Khriapin, A. L. (2010) Sistema strategicheskogo sderzhivaniia v novykh usloviiakh. Voennaia mysl',

2010(1), pp 11-16. Mikhailov, N. V. (1999) Vesomye otvety na voyennye vyzovy. Nezavisimoe Voennoe Obozrenie, 30 April 1999. [Online]

https://dlib.eastview.com/browse/doc/3515343 [Accessed 4 January 2018] Molchanov, N. A. (2008) Informatsionnyi potentsial zarubezhnykh stran kak istochnik ugroz voennoi bezopasnosti RF.

Voennaia mysl', 2008(10), pp 2-9. NVO (2013) Voina v kiberprostranstve: uroki i vyvody dlia Rossii. Nezavisimoe voennoe obozrenie, 13 December 2013.

[Online] https://dlib.eastview.com/browse/doc/37852459 [Accessed 4 January 2018] Oehmen, C. & Multari, N. (2014) AiR: Asymmetry in Resilience: Report on the First Meeting on Asymmetry in Resilience for

Complex Cyber Systems. [Online] https://cybersecurity.pnnl.gov/documents/AiR_1.0_Final_Report.pdf [Accessed 19 August 2017]

Orlianskii, V. I. (2008) Informatsionnoe oruzhie i informatsionnaia bor'ba: real'nost i domysly. Voennaia mysl', 2008(1), pp 62-70.

Orlianskii, V. I. (2002) Vooruzhennaia i informatsionnaia bor'ba: sushchnost' i vzaimosviaz' poniatii i iavlenii. Voennaia mysl', 2002(6), pp. 42-47.

Ristolainen, M. (2017) Should ‘RuNet 2020’ Be Taken Seriously? Contradictory Views about Cyber Security Between Russia and the West. Journal of Information Warfare, 16(4), pp 113-131.

Romashkina, N. P. & Koldobskii, A. B. (2015) Novye metody protivoborstva XXI veka. Vestnik Akademii voennykh nauk, 50(1), pp 134-139.

Shalamberidze , E. G. (2011) Teoreticheskie voprosy razvitiia politiki natsional'noi oborony Rossii v usloviiakh mirnogo vremeni s ispol'zovaniem sistemy mer nevoennogo i voennogo kharaktera. Vestnik Akademii voennykh nauk, 37(4), pp 35-43.

Sherstiuk, V. P (2003) Aktual'nye problemy obespecheniia informatsionnoi bezopasnosti Rossiyskoi Federatsii. Voennaia mysl', 2003(6), pp 28-32.

Sovet Bezopasnosti Rossiiskoi Federatsii (2014) Zasedanie Soveta Bezopasnosti Rossiiskoi Federatsii po voprosu ”O protivodeistvii ugrozam natsional’noi bezopasnosti Rossiiskoi Federatsii v informatsionnoq sfere, 1 oktriabia 2014 goda. October 1, 2014. [Online] http://www.scrf.gov.ru/news/allnews/831/ [Accessed 19 December 2017]

Strachan, H. (2013) The Direction of War: Contemporary Strategy in Historical Perspective. New York: Cambridge University Press.

Strategiia (2009) O Strategii natsional'noi bezopasnosti Rossiiskoi Federatsii do 2020 goda. [Online] http://pravo.gov.ru/proxy/ips/?docbody=&nd=102129631 [Accessed 27 September 2017].

Strategiia (2015) O Strategii natsional'noi bezopasnosti Rossiiskoi Federatsii. [Online] http://pravo.gov.ru/proxy/ips/?docbody=&nd=102385609 [Accessed 27 September 2017].

Strategiia (2017) O strategii razvitiia informatsionnogo obshchestva v Rossiiskoi Federatsii na 2017-2030 gody [Online] http://static.kremlin.ru/media/acts/files/0001201705100002.pdf [Accessed 22 September 2017].

Strel'tsov, A. A. (2011) Osnovnye zadachi gosudarstvennoi politiki v oblasti informatsionnogo protivoborstva. Voennaia mysl', 2011(5), pp 18-25.

Thomas, T. (2015) Russia Military Strategy: Impacting 21st Century Reform and Geopolitics. Fort Leavenworth: Foreign Military Studies Office.

Tsifrovaia ekonomika (2017) Programma:"Tsifrovaia ekonomika Rossiiskoi Federatsii". [Online] http://static.government.ru/media/files/9gFM4FHj4PsB79I5v7yLVuPgu4bvR7M0.pdf [Accessed 22 September 2017]

Beprintev, V. B., Manoilo, A. V., Petrenko, A. I. & Frolov, D. B. (2011) Operatsii informatsionno-psikhologicheckoi voiny: kratkii entsiklopedicheckii slovar’-spravochnik. Moscow: Goriachaia liniia – Telekom.

Wirtz, J. J. (2017) Life in the “Gray Zone”: observations for contemporary strategists. Defense & Security Analysis, 33(2), pp 106 - 114.

Vorob’ev, I. N. & Kiselev, V. A. (2014) Kiberprostranstvo kak sfera nepriamogo vooruzhennogo protivoborstva. Voennaia mysl', 2014(12), pp 21-28.

Vypasniak, V. I. (2009) O realizatsii setetsentricheskikh printsipov upravleniia silami i sredstvami vooruzhennoi bor'by v operatsiiakh (boevykh deistviiakh). Voennaia mysl', 2009(12), pp 23-30.

Yefremov, A. (2017) Formirovanie kontseptsii informatsionnogo suvereniteta gosudarstva. Pravo. Zhurnal Vysshei shkoly ekonomiki, 2017(1), pp. 201-205. [Online] https://law-journal.hse.ru/2017--1/204343305.html [Accessed 4 January 2018]

368

xiv

conferences. His award-winning research has gained a spotlight as the Best Paper of the 15th International Conference on WWW/Internet in Mannheim Germany. Dr Joey Jansen van Vuuren is the manager of the Cybersecurity Centre of Innovation at the CSIR in South Africa. The Centre focuses on the promotion of cybersecurity research collaboration, education and threat exchange. As Research Leader for Cyber Defence she gave strategic research direction for South African National Defence Force and Government sectors. Her own research focus on cybersecurity governance and policy. Anas Mu’az Kademi is a doctoral candidate under the supervision of Assoc. Prof. Ahmet Koltuksuz in computer engineering at Yasar University. His PhD research explores how cyberspace can be formalized–using cellular automata. He holds M.Sc. from the same university. Interested in information security, cyber-warfare, networking, cellular automata and strategic cybersecurity. Min Kang is a 2d Lt and is currently a student pursuing his Master’s degree in Computer Science with a concentration in Cyber Security at the Air Force Institute of Technology. After graduation, he will attend Undergraduate Cyber Training to become a Cyberspace Operations Officer. Martti J Kari is PhD student of cyber security in Jyväskylä University, Finland. He retired as colonel from Finnish Defense Intelligence in the end of year 2017. His last post was assistant chief of Defense Intelligence. He has MA in Russian language and literature in Jyväskylä University. Kari has worked as a university teacher from the beginning of year 2018 In Jyväskylä University. Omer F. Keskin is a Ph.D. Student in Engineering Management and a Graduate Assistant in Old Dominion University. He holds an MS Degree in engineering management and a BS degree in systems engineering. His research is focused on risk and reliability analysis of critical infrastructure cyber physical systems. Anne Kohnke is an assistant professor of IT at Lawrence Technological University in the United States where she teaches courses in both information technology and organization development/change management disciplines at bachelor through doctorate levels. Her research focus is in the areas of cybersecurity, risk management, IT governance, and extraterritorial surveillance and privacy. Anne earned her PhD from Benedictine University. Captain Juha Kukkola has Master’s degree in Political science (2005) and Military science (2008) and serves as a research officer at Finnish National Defense University (FNDU). He is currently PhD student at FNDU and is writing his doctoral thesis on Russia’s military cyber power and strategy. He has served in Finnish Defense Forces from 2008 as a platoon leader, signals officer, staff officer and lecturer. He is specialized in Air defense, C4 systems and Russian and Cyber studies. He can be contacted by email at [email protected] Hyong Lee is a Senior Policy Analyst with National Defense University’s (NDU) Center for Applied Strategic Learning (CASL) in Washington DC. Mr. Lee started his career in government service in 1992 as a Presidential Management Intern (PMI), now known as Presidential Management Fellows. In 1996, Mr. Lee moved to Hawaii, where he eventually became Chief of the Decision Support Branch (J084) at US Pacific Command. As Chief of J084, he oversaw the development and execution of a number of seminar games and table top exercises. Mr. Lee joined NDU in January 2002 when he started working at the National Strategic Gaming Center (NSGC), the prior incarnation of CASL. He supports exercise efforts for the various components of National Defense University, the Joint Staff, combatant commanders, and CASL outreach audiences. His more recent projects include anti-terrorism / force protection, consequence management, cyber security, and integrating more technology into exercises. Louise Leenen is a Principal Researcher in the Cyber Defence research Group at the Council for Scientific and Industrial Research (CSIR), South Africa. She holds a PhD Computer Science (in Constraint Programming) from the University of Wollongong in Australia. Her research focus is on artificial intelligence applications in the defence environment, cyber defence and ontology development. She is the Chair of the IFIP Working Group 9.10 on ICT in War and Peace. Martti Lehto, PhD (Military Sciences), Col G.S. (ret.) is Professor in Cyber security in the University of Jyväskylä in the Faculty of Information Technology. He has over 30 years’ experience as developer and leader of C4ISR Systems in Finnish Defence Forces. Now he is a Cyber security and Cyber defence researcher and teacher and the pedagogical director of the Cyber Security MSc. program. He is also Adjunct professor in National Defence University in Air and Cyber Warfare. He has

Reproduced with permission of copyright owner. Further reproduction prohibited without permission.