Sony Attack - Is it Cyberwar?

profileMIDZ_23
module5_textbook_reading.pdf

Module 5 Textbook Reading

The textbook reading assignment for Module 5 is pages 120-144.

“Cyberwar, Ugh, What Are Zeros and Ones Good For?”: Defining Cyberwar

This short but very important section has two key points you should not miss.

First is that the textbook repeats a common definition of war – that war has a political goal and involves violence. The authors neglect to point out that this definition isn't always accepted as a definition of cyberwar, in particular, the requirement of violence. As an example, a cyberattack that wipes out financial data at stock exchanges, banks, the federal reserve, etc. could cause the US economy to collapse without any physical violence. Many people would consider that to be an act of war. This will be relevant to one of our discussion topics.

The second key point is that there is no clear line between “war” and “peace”. There's a nice quote in the textbook from Joel Brenner. Here's another related quote from the same author:

“We suffer from a Western misconception in our law, religion and policy that 'peace' and 'war' are opposites that cannot occur at the same time … In the minds of many for whom World War II is the paradigmatic conflict, 'war' is not real unless it involves complete mobilization. Many Americans cling to this view, even though war has not been declared on the planet since 1945, while there have been hundreds of organized, violent, and militarized struggles in the interim.”

This comes from his book “Glass Houses”, pages 68-69. We'll read more from that book later in the module.

As is often the case, this quote applies just as easily to “cyberwar” as it does to conventional war.

A War by Any Other Name? The Legal Side of Cyber Conflict

This section is at least as important as the previous. Even though there is no clear line between war and peace, domestic and international laws often are based upon some threshold of war. Deciding whether that threshold has been reached is partly a legal and partly a political decision. And once again, this is just as true in conventional war as it is in cyberwar, the only difference is that we have more experience with conventional war.

What Might a “Cyberwar” Actually Look Like? Computer Network Operations

Though there are some fantastic (fictional) stories out there about wars fought entirely in cyberspace, it is much more likely that cyber attacks will simply be one additional part of traditional kinetic warfare. In fact, they already have been, as examples in this section describe.

The other significant theme of this section is that modern militaries, and none more than the

IT 238 Introduction to Cyberterrorism Central Washington University – ITAM

Module 5 Textbook Reading 2

United States' military, are heavily dependent upon cyberspace. This dependency is across the board, in highly technical areas such as precision targeting of weapons to much more mundane tasks like resupply. But this dependency also makes our military very vulnerable to cyber attacks that could disrupt any of the cyberspace dependent systems.

Focus: What is the US Military Approach to Cyberwar?

This sections discusses the US Cyber Command (CYBERCOM), its organization and the relationship between it and the National Security Agency (NSA).

A large portion of this section discusses using offensive cyber capabilities, or even conventional capabilities, as a way to deter potential cyber attackers. This is a good introduction to the broader topic of deterrence which we will get into much more in a couple of weeks.

Focus: What is the Chinese Approach to Cyberwar?

You've already seen that China is mentioned far more often than any other country as a cyber adversary to the United States. This section describes more about the Chinese governments history and capabilities in cyberspace.

It is actually very unfair to focus so heavily on China. When people who know the most, such as leaders of the NSA speak, they will always say that Russia poses at least as much of a threat as China, if not more.

So why so much emphasis on China? It seems that they get caught much more often than the Russians do. But it may just be that they aren't as good at hiding their attacks, or perhaps they don't even bother to try to hide as much.

Another distinction is that China is definitely responsible for more theft of intellectual property than Russia. This may not reflect any lack of interest by Russia as much as it reflects the difference in the economic power of the two countries. Russia simply doesn't have the manufacturing infrastructure to take advantage of US intellectual property like China can.

In any case, much more is known publicly about China's activities, so that's where this book focuses.

IT 238 Introduction to Cyberterrorism Central Washington University – ITAM