read attachment
Assignement2/~$itten Assignment.docx
Assignement2/10640 (Part 2).pdf
Visit the National Academies Press online, the authoritative source for all books from the National Academy of Sciences, the National Academy of Engineering, the Institute of Medicine, and the National Research Council: • Download hundreds of free books in PDF • Read thousands of books online for free • Explore our innovative research tools – try the “Research Dashboard” now! • Sign up to be notified when new books are published • Purchase printed books and selected PDF files
Thank you for downloading this PDF. If you have comments, questions or just want more information about the books published by the National Academies Press, you may contact our customer service department toll- free at 888-624-8373, visit us online, or send an email to [email protected]. This book plus thousands more are available at http://www.nap.edu. Copyright © National Academy of Sciences. All rights reserved. Unless otherwise indicated, all materials in this PDF File are copyrighted by the National Academy of Sciences. Distribution, posting, or copying is strictly prohibited without written permission of the National Academies Press. Request reprint permission for this book.
ISBN: 0-309-50434-1, 144 pages, 6x9, (2003)
This PDF is available from the National Academies Press at: http://www.nap.edu/catalog/10640.html
http://www.nap.edu/catalog/10640.html
We ship printed books within 1 business day; personal PDFs are available immediately.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities
John L. Hennessy, David A. Patterson, and Herbert S. Lin, Editors, Committee on the Role of Information Technology in Responding to Terrorism, National Research Council
Committee on the Role of Information Technology in Responding to Terrorism
Computer Science and Telecommunications Board
John L. Hennessy, David A. Patterson, and Herbert S. Lin, Editors
THE NATIONAL ACADEMIES PRESS Washington, D.C. www.nap.edu
INFORMATION TECHNOLOGY FOR COUNTERTERRORISM IMMEDIATE ACTIONS AND FUTURE POSSIBILITIES
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
THE NATIONAL ACADEMIES PRESS • 500 Fifth Street, N.W. • Washington, DC 20001
NOTICE: This project was approved by the Governing Board of the National Research Council, whose members are drawn from the councils of the National Academy of Sciences, the National Academy of Engineering, and the Institute of Medicine. The members of the committee responsible for this final report were chosen for their special competences and with regard for appropriate balance.
The study from which this report is largely derived was supported by private funds from the National Academies. The additional work required to produce this report was supported by core funding from the Computer Science and Tele- communications Board (CSTB). Core support for CSTB in this period was pro- vided by the Air Force Office of Scientific Research, Department of Energy, Na- tional Institute of Standards and Technology, National Library of Medicine, National Science Foundation, Office of Naval Research, and the Cisco, Intel, and Microsoft corporations. Sponsors enable but do not influence CSTB’s work. Any opinions, findings, conclusions, or recommendations expressed in this publica- tion are those of the authors and do not necessarily reflect the views of the organi- zations or agencies that provide support for CSTB.
International Standard Book Number 0-309-08736-8 Library of Congress Control Number: 2003101593
Copies of this report are available from the National Academies Press, 500 Fifth Street, N.W., Lockbox 285, Washington, DC 20055; (800) 624-6242 or (202) 334- 3313 in the Washington metropolitan area. Internet, http://www.nap.edu.
Additional copies of this report are available in limited quantity from the Com- puter Science and Telecommunications Board, National Research Council, 500 Fifth Street, N.W., Washington, DC 20001. Call (202) 334-2605 or e-mail the CSTB at [email protected].
Copyright 2003 by the National Academy of Sciences. All rights reserved.
Printed in the United States of America
Suggested citation: Computer Science and Telecommunications Board, Informa- tion Technology for Counterterrorism: Immediate Actions and Future Possibilities, The National Academies Press, Washington, D.C., 2003.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
The National Academy of Sciences is a private, nonprofit, self-perpetuating soci- ety of distinguished scholars engaged in scientific and engineering research, dedi- cated to the furtherance of science and technology and to their use for the general welfare. Upon the authority of the charter granted to it by the Congress in 1863, the Academy has a mandate that requires it to advise the federal government on scientific and technical matters. Dr. Bruce M. Alberts is president of the National Academy of Sciences.
The National Academy of Engineering was established in 1964, under the charter of the National Academy of Sciences, as a parallel organization of outstanding engineers. It is autonomous in its administration and in the selection of its mem- bers, sharing with the National Academy of Sciences the responsibility for advis- ing the federal government. The National Academy of Engineering also sponsors engineering programs aimed at meeting national needs, encourages education and research, and recognizes the superior achievements of engineers. Dr. Wm. A. Wulf is president of the National Academy of Engineering.
The Institute of Medicine was established in 1970 by the National Academy of Sciences to secure the services of eminent members of appropriate professions in the examination of policy matters pertaining to the health of the public. The Institute acts under the responsibility given to the National Academy of Sciences by its congressional charter to be an adviser to the federal government and, upon its own initiative, to identify issues of medical care, research, and educa- tion. Dr. Harvey V. Fineberg is president of the Institute of Medicine.
The National Research Council was organized by the National Academy of Sci- ences in 1916 to associate the broad community of science and technology with the Academy’s purposes of furthering knowledge and advising the federal gov- ernment. Functioning in accordance with general policies determined by the Academy, the Council has become the principal operating agency of both the National Academy of Sciences and the National Academy of Engineering in pro- viding services to the government, the public, and the scientific and engineering communities. The Council is administered jointly by both Academies and the Institute of Medicine. Dr. Bruce M. Alberts and Dr. Wm. A. Wulf are chair and vice chair, respectively, of the National Research Council.
www.national-academies.org
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
iv
COMMITTEE ON THE ROLE OF INFORMATION TECHNOLOGY IN RESPONDING TO TERRORISM
JOHN HENNESSY, Stanford University, Chair DAVID A. PATTERSON, University of California at Berkeley, Vice Chair STEVEN M. BELLOVIN, AT&T Laboratories W. EARL BOEBERT, Sandia National Laboratories DAVID BORTH, Motorola Labs WILLIAM F. BRINKMAN, Lucent Technologies (retired) JOHN M. CIOFFI, Stanford University W. BRUCE CROFT, University of Massachusetts at Amherst WILLIAM P. CROWELL, Cylink Inc. JEFFREY M. JAFFE, Bell Laboratories, Lucent Technologies BUTLER W. LAMPSON, Microsoft Corporation EDWARD D. LAZOWSKA, University of Washington DAVID LIDDLE, U.S. Venture Partners TOM M. MITCHELL, Carnegie Mellon University DONALD NORMAN, Northwestern University JEANNETTE M. WING, Carnegie Mellon University
Staff
HERBERT S. LIN, Senior Scientist and Study Director STEVEN WOO, Program Officer DAVID DRAKE, Senior Project Assistant
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
v
COMPUTER SCIENCE AND TELECOMMUNICATIONS BOARD 2002-2003
DAVID D. CLARK, Massachusetts Institute of Technology, Chair ERIC BENHAMOU, 3Com Corporation DAVID BORTH, Motorola Labs JOHN M. CIOFFI, Stanford University ELAINE COHEN, University of Utah W. BRUCE CROFT, University of Massachusetts at Amherst THOMAS E. DARCIE, AT&T Labs Research JOSEPH FARRELL, University of California at Berkeley JOAN FEIGENBAUM, Yale University HECTOR GARCIA-MOLINA, Stanford University WENDY KELLOGG, IBM Thomas J. Watson Research Center BUTLER W. LAMPSON, Microsoft Corporation DAVID LIDDLE, U.S. Venture Partners TOM M. MITCHELL, Carnegie Mellon University DAVID A. PATTERSON, University of California at Berkeley HENRY (HANK) PERRITT, Chicago-Kent College of Law DANIEL PIKE, Classic Communications ERIC SCHMIDT, Google Inc. FRED SCHNEIDER, Cornell University BURTON SMITH, Cray Inc. LEE SPROULL, New York University WILLIAM STEAD, Vanderbilt University JEANNETTE M. WING, Carnegie Mellon University
Staff
MARJORY S. BLUMENTHAL, Executive Director HERBERT S. LIN, Senior Scientist ALAN S. INOUYE, Senior Program Officer JON EISENBERG, Senior Program Officer LYNETTE I. MILLETT, Program Officer CYNTHIA A. PATTERSON, Program Officer STEVEN WOO, Dissemination Officer JANET BRISCOE, Administrative Officer RENEE HAWKINS, Financial Associate DAVID PADGHAM, Research Associate KRISTEN BATCH, Research Associate PHIL HILLIARD, Research Associate MARGARET HUYNH, Senior Project Assistant
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
vi
DAVID DRAKE, Senior Project Assistant JANICE SABUDA, Senior Project Assistant JENNIFER BISHOP, Senior Project Assistant BRANDYE WILLIAMS, Staff Assistant
For more information on CSTB, see its Web site at <http://www. cstb.org>, write to CSTB, National Research Council, 500 Fifth Street, N.W., Washington, DC 20001, call at (202) 334-2605, or e-mail at [email protected].
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
vii
Preface
Immediately following the events of September 11, 2001, the National Academies (including the National Academy of Sciences, the National Academy of Engineering, the Institute of Medicine, and the National Re- search Council) offered its services to the nation to formulate a scientific and technological response to the challenges posed by emerging terrorist threats that would seek to inflict catastrophic damage on the nation’s people, its infrastructure, or its economy. Specifically, it supported a project that culminated in a report entitled Making the Nation Safer: The Role of Science and Technology in Countering Terrorism (The National Acad- emies Press, Washington, D.C.) that was released on June 25, 2002. That project, chaired by Lewis M. Branscomb and Richard D. Klausner, sought to identify current threats of catastrophic terrorism, understand the most likely vulnerabilities in the face of these threats, and identify highly lever- aged opportunities for contributions from science and technology to coun- terterrorism in both the near term and the long term.
Taking the material on information technology contained in Making the Nation Safer as a point of departure, the Committee on the Role of Information Technology in Responding to Terrorism, identical to the Panel on Information Technology that advised the Branscomb-Klausner committee, drew on sources, resources, and analysis unavailable to that committee during the preparation of its report. In addition, the present report contains material and elaborations that the Branscomb-Klausner committee did not have time to develop fully for the parent report. Both reports are aimed at spurring research in the science and technology com-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
viii PREFACE
munities to counter and respond to terrorist acts such as those experi- enced on September 11.
In addition to presenting material on information technology (IT), Making the Nation Safer includes chapters on nuclear and radiological threats, human and agricultural health systems, toxic chemicals and ex- plosive materials, energy systems, transportation systems, cities and fixed infrastructure, and the response of people to terrorism. The present report focuses on IT—its role as part of the national infrastructure, sug- gested areas of research (information and network security, IT for emer- gency response, and information fusion), and the people and organiza- tional aspects that are critical to the acceptance and use of the proposed solutions. Note that policy is not a primary focus of this report, although policy issues are addressed as needed to provide context for the research programs outlined here.
Information Technology for Counterterrorism draws on many past re- ports and studies of the Computer Science and Telecommunications Board (CSTB). These CSTB reports include Cybersecurity Today and Tomorrow: Pay Now or Pay Later; Computers at Risk: Safe Computing in the Information Age; Embedded, Everywhere: A Research Agenda for Networked Systems of Embedded Computers; Realizing the Potential of C4I: Fundamental Challenges; Information Technology Research for Crisis Management; and Computing and Communications in the Extreme, among others. Furthermore, the report leverages current CSTB studies on geospatial information, authentication technologies, critical infrastructure protection and the law, and privacy.
The Committee on the Role of Information Technology in Respond- ing to Terrorism included current and past CSTB members as well as other external experts. The 16 committee members (see the appendix for committee and staff biographies) are experts in computer, information, Internet, and network security; computer and systems architecture; com- puter systems innovation, including interactive systems; national security and intelligence; telecommunications, including wireline and wireless; data mining and information fusion and management; machine learning and artificial intelligence; automated reasoning tools; information-pro- cessing technologies; information retrieval; networked, distributed, and high-performance systems; software; and human factors. To meet its charge, the committee met several times over a 2-month period and con- ducted extensive e-mail dialogue to discuss the report text.
As was the parent report, this focused report was developed quickly, with the intent of informing key decision makers with respect to the role of information technology in the homeland security effort. The treatment of any of the subjects in this report is far from comprehensive or exhaus- tive—instead, the report highlights those subject aspects that the commit- tee deems critical at this time. Accordingly, the report builds on, and cites
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
ixPREFACE
heavily, prior CSTB reports that more substantially address the relevant issues.
The committee wishes to thank the CSTB staff (Herbert Lin as study director, Steven Woo for research support, and D.C. Drake for adminis- trative support) for developing coherent drafts from scraps of e-mail and brief notes from committee meetings.
John L. Hennessy, Chair David A. Patterson, Vice Chair Committee on the Role of Information Technology
in Responding to Terrorism
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
xi
Acknowledgment of Reviewers
This report has been reviewed in draft form by individuals chosen for their diverse perspectives and technical expertise, in accordance with pro- cedures approved by the National Research Council’s (NRC’s) Report Review Committee. The purpose of this independent review is to pro- vide candid and critical comments that will assist the institution in mak- ing the published report as sound as possible and to ensure that the report meets institutional standards for objectivity, evidence, and responsive- ness to the study charge. The review comments and draft manuscript remain confidential to protect the integrity of the deliberative process. We wish to thank the following individuals for their participation in the review of this report:
Edward Balkovich, The RAND Corporation, Richard Baseil, The MITRE Corporation, Jules A. Bellisio, Telcordia, Tom Berson, Anagram Laboratories, James Gray, Microsoft, Daniel Huttenlocher, Cornell University, Richard Kemmerer, University of California at Santa Barbara, Keith Marill, New York University Bellevue Hospital Center, William Press, Los Alamos National Laboratory, Fred Schneider, Cornell University, and Edward Wenk, University of Washington.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
xii ACKNOWLEDGMENT OF REVIEWERS
Although the reviewers listed above provided many constructive comments and suggestions, they were not asked to endorse the conclu- sions or recommendations, nor did they see the final draft of the report before its release. The review of this report was overseen by R. Stephen Berry of the University of Chicago. Appointed by the NRC’s Report Review Committee, he was responsible for making certain that an inde- pendent examination of this report was carried out in accordance with institutional procedures and that all review comments were carefully con- sidered. Responsibility for the final content of this report rests entirely with the Computer Science and Telecommunications Board and the Na- tional Research Council.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
xiii
Contents
EXECUTIVE SUMMARY 1
1 BACKGROUND AND INTRODUCTION 10 1.1 What Is Terrorism?, 10 1.2 The Role of Information Technology in National Life
and in Counterterrorism, 11 1.3 The Information Technology Infrastructure and
Associated Risks, 12
2 TYPES OF THREATS ASSOCIATED WITH INFORMATION TECHNOLOGY INFRASTRUCTURE 15 2.1 Attack on IT as an Amplifier of a Physical Attack, 15 2.2 Other Possibilities for Attack Involving IT, 16
2.2.1 Attacks on the Internet, 16 2.2.2 Attacks on the Public Switched Network, 18 2.2.3 The Financial System, 20 2.2.4 Embedded/Real-Time Computing, 20 2.2.5 Control Systems in the National Critical
Infrastructure, 21 2.2.6 Dedicated Computing Facilities, 23
2.3 Disproportionate Impacts, 23 2.4 Threats in Perspective: Possibility, Likelihood,
and Impact, 24
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
xiv CONTENTS
3 INVESTING IN INFORMATION TECHNOLOGY RESEARCH 28 3.1 Information and Network Security, 31
3.1.1 Authentication, 33 3.1.2 Detection, 35 3.1.3 Containment, 37 3.1.4 Recovery, 40 3.1.5 Cross-cutting Issues in Information and Network
Security Research, 41 3.2 Systems for Emergency Response, 46
3.2.1 Intra- and Interoperability, 47 3.2.2 Emergency Deployment of Communications
Capacity, 55 3.2.3 Security of Rapidly Deployed Ad Hoc Networks, 57 3.2.4 Information-Management and Decision-Support
Tools, 58 3.2.5 Communications with the Public During an
Emergency, 59 3.2.6 Emergency Sensor Deployment, 60 3.2.7 Precise Location Identification, 61 3.2.8 Mapping the Physical Aspects of the
Telecommunications Infrastructure, 62 3.2.9 Characterizing the Functionality of Regional Networks
for Emergency Responders, 62 3.3 Information Fusion, 63
3.3.1 Data Mining, 68 3.3.2 Data Interoperability, 69 3.3.3 Natural Language Technologies, 69 3.3.4 Image and Video Processing, 70 3.3.5 Evidence Combination, 70 3.3.6 Interaction and Visualization, 71
3.4 Privacy and Confidentiality, 71 3.5 Other Important Technology Areas, 75
3.5.1 Robotics, 75 3.5.2 Sensors, 76 3.5.3 Simulation and Modeling, 78
3.6 People and Organizations, 80 3.6.1 Principles of Human-Centered Design, 81 3.6.2 Organizational Practices in IT-Enabled
Companies and Agencies, 89 3.6.3 Dealing with Organizational Resistance to Interagency
Cooperation, 91
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
xvCONTENTS
3.6.4 Principles into Practice, 93 3.6.5 Implications for Research, 95
4 WHAT CAN BE DONE NOW? 97
5 RATIONALIZING THE FUTURE RESEARCH AGENDA 106
APPENDIX: BIOGRAPHIES OF COMMITTEE AND STAFF MEMBERS 115
WHAT IS CSTB? 127
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
1
Executive Summary
Making the Nation Safer: The Role of Science and Technology in Countering Terrorism, a report released by the National Academies in June 2002,1 articulated the role of science and technology in countering terrorism. That report included material on the specific role of information tech- nology (IT). Building on that report as a point of departure, the panel of experts responsible for the IT material in Making the Nation Safer was reconvened as the Committee on the Role of Information Technology in Responding to Terrorism in order to develop the present report.
DEFINING TERRORISM FOR THE PURPOSES OF THIS REPORT
Terrorism can occur on many different scales and with a wide range of impacts. While a terrorist act can involve a lone suicide bomber or a rental truck loaded with explosives, Americans’ perception of catastrophic terrorist acts will forever be measured against the events of September 11, 2001. In one single day, thousands of lives and tens of billions of dollars were lost to terrorism. This report focuses primarily on the high-impact catastrophic dimensions of terrorism as framed by the events of Septem- ber 11. Thus, in an IT context, the “lone hacker,” or even the cyber- criminal—while bothersome and capable of doing damage—is not the focus of this report. Instead, the report considers the larger threat posed
1National Research Council. 2002. Making the Nation Safer: The Role of Science and Tech- nology in Countering Terrorism. The National Academies Press, Washington, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
2 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
by smart, disciplined adversaries with ample resources. (Of course, measures taken to defend against catastrophic terrorism will likely have application in defending against less sophisticated attackers.)
THE ROLE OF INFORMATION TECHNOLOGY IN SOCIETY AND IN COUNTERTERRORISM
Information technology is essential to virtually all of the nation’s criti- cal infrastructures, from the air-traffic-control system to the aircraft them- selves, from the electric-power grid to the financial and banking systems, and, obviously, from the Internet to communications systems. In sum, this reliance of all of the nation’s critical infrastructures on IT makes any of them vulnerable to a terrorist attack on their computer or telecommu- nications systems.
An attack involving IT can take different forms. The IT itself can be the target. Or, a terrorist can either launch or exacerbate an attack by exploiting the IT infrastructure, or use IT to interfere with attempts to achieve a timely response. Thus, IT is both a target and a weapon. Like- wise, IT also has a major role in counterterrorism—it can prevent, detect, and mitigate terrorist attacks. For example, advances in information fusion and data mining may facilitate the identification of important patterns of behavior that help to uncover terrorists or their plans in time to prevent attacks.
While there are many possible scenarios for an attack on some element(s) of the IT infrastructure (which includes the Internet, the tele- communications infrastructure, embedded/real-time computing such as SCADA [supervisory control and data acquisition] systems, and dedi- cated computing devices such as desktop computers), the committee believes that the most devastating consequences would occur if an attack on or using IT were part of a multipronged attack with other, more physi- cal components. In this context, compromised IT could expand terrorist opportunities to widen the damage of a physical attack, diminish timely responses to the attack, and heighten terror in the population by provid- ing false information about the nature of the threat.
The likelihood of a terrorist attack against or through the use of the IT infrastructure must be understood in the context of terrorists. Like other organizations, terrorist groups are likely to utilize their limited resources in activities that maximize impact and visibility. A decision by terrorists to use IT, or any other means, in an attack depends on factors such as the kinds of expertise and resources available, the publicity they wish to gain, and the symbolic value of an attack. How terrorists weigh such factors is not known in advance. Those wanting to create immediate public fear
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
3EXECUTIVE SUMMARY
and terror are more likely to use a physical attack than an attack that targets IT exclusively.
WHAT CAN BE DONE NOW: SHORT-TERM RECOMMENDATIONS
The committee makes two short-term recommendations with respect to the nation’s communications and information systems.
Short-Term Recommendation 1: The nation should develop a pro- gram that focuses on the communications and computing needs of emer- gency responders. Such a program would have two essential compo- nents:
• Ensuring that authoritative, current-knowledge expertise and sup- port regarding IT are available to emergency-response agencies prior to and during emergencies, including terrorist attacks.
• Upgrading the capabilities of the command, control, communica- tions, and intelligence (C3I) systems of emergency-response agen- cies through the use of existing technologies. Such upgrades might include transitioning from analog to digital systems and deploying a separate emergency-response communications network in the aftermath of a disaster.
Short-Term Recommendation 2: The nation should promote the use of best practices in information and network security in all relevant public agencies and private organizations.
• For IT users on the operational level: Ensure that adequate informa- tion-security tools are available. Conduct frequent, unannounced red-team penetration testing of deployed systems. Promptly fix problems and vulnerabilities that are known. Mandate the use of strong authentication mechanisms. Use defense-in-depth in addi- tion to perimeter defense.
• For IT vendors: Develop tools to monitor systems automatically for consistency with defined secure configurations. Provide well- engineered schemes for user authentication based on hardware tokens. Conduct more rigorous testing of software and systems for security flaws.
• For the federal government: Position critical federal information sys- tems as models for good security practices. Remedy the failure of the market to account adequately for information security so that appropriate market pro-security mechanisms develop.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
4 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
WHAT CAN BE DONE IN THE FUTURE
Because the possible attacks on the nation’s IT infrastructure vary so widely, it is difficult to argue that any one type is more likely than others. This fact suggests the value of a long-term commitment to a strategic research and development program that will increase the overall robust- ness of the computer and telecommunications networks. Such a program could improve the nation’s ability to prevent, detect, respond to, and recover from terrorist attacks. This agenda would also have general appli- cations, such as reducing cybercrime and responding to natural disasters. Three critical areas of research are information and network security, C3I systems for emergency response, and information fusion. Although tech- nology is central to these three areas, it is not the sole element of concern. Research in these areas must be multidisciplinary, involving technolo- gists, social scientists, and domain experts. Since technology deployed for operational purposes is subject to the reality of implementation and use by humans, technology cannot be studied in isolation from how it is deployed and used.
Information and Network Security
Research in information and network security is relevant to the nation’s counterterrorism efforts for several reasons. IT attacks can amplify the impact of physical attacks and lessen the effectiveness of emergency responses. IT attacks on SCADA systems could be devastating. The increasing levels of social and economic damage caused by cybercrime suggest a corresponding increase in the likelihood of severe damage through cyberattacks. The technology discussed here is relevant to fight- ing cybercrime and to conducting efforts in defensive information warfare.
Research in information and network security can be grouped in four areas: authentication, detection, containment, and recovery; a fifth set of topics such as dealing with buggy code is broadly applicable.
• Authentication is relevant to better ways of preventing unautho- rized parties from gaining access to a computer system to cause harm.
• Detection of intruders with harmful intentions is critical for thwart- ing their actions. However, because intruders take great care to hide their entry and/or make their behavior look innocuous, such detection is a very challenging problem (especially when the intruder is an insider gone bad).
• Containment is necessary if the success of an attacker is to be limited in scope. Although the principle of graceful degradation under attack is well accepted, system and network design for graceful degradation is not well understood.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
5EXECUTIVE SUMMARY
• Recovery involves backup and decontamination. In a security con- text, backup methods for use under adversarial conditions and applicable to large systems are needed. Decontamination—the process of distin- guishing the clean system state from the infected portions and eliminat- ing the causes of those differences—is especially challenging when a sys- tem cannot be shut down.
• Other areas. Buggy code (i.e., flawed computer programs) is prob- ably the oldest unsolved problem in computer science, and there is no particular reason to think that research can solve the problem once and for all. One approach to the problem is to provide incentives to install fixes, even though the fixes themselves may carry risks such as exposing other software flaws. Many system vulnerabilities result from improper administration, and better system administration tools for specifying secu- rity policies and checking system configurations are necessary. Research in tools for auditing functionality to ensure that hardware and software have the prescribed—and no additional—functionality would be helpful. Security that is more transparent would have higher adoption rates. Under- standing the failure in the marketplace of previous attempts to build in computer security would help guide future research efforts.
IT and C3I for Emergency Response
C3I systems are critical to emergency responders for coordinating their efforts and increasing the promptness and effectiveness of their response. C3I for emergency response to terrorist attacks poses chal- lenges that differ from natural disasters: the number of responding agen- cies—from local, state, and federal governments—increases the degree of complexity, while the additional security or law-enforcement presence that is required may interfere with rescue and recovery operations.
C3I systems for emergency responders face many challenges:
• Regarding ad hoc interoperability, different emergency responders must be able to communicate with each other and other agencies, and poor interoperability among responding agencies is a well-known prob- lem. Thus, for example, there is a technical need for protocols and tech- nology that can facilitate interconnection and interoperation.
• Emergency situations result in extraordinary demands on commu- nications capacity. Research is needed on using residual capacity more effectively and deploying additional (“surge”) capacity.
• In responding to disasters, emergency-response managers need decision-support tools that can assist them in sorting, evaluating, filtering, and integrating information from a vast array of voice and data traffic.
• During an emergency, providing geographically sensitive public
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
6 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
information that is relevant to where people are (e.g., for evacuation pur- poses) is a challenging technical problem.
• Sensors deployed in an emergency could track the spread of nuclear or biological contaminants, locate survivors (e.g., through heat emanations or sounds), and find pathways through debris.
• Location identification of people and structures is a major problem when there is physical damage to a structure or an area.
Information Fusion
Information fusion promises to play a central role in the prevention, detection, and response to terrorism. For example, the effectiveness of checkpoints such as airline boarding gates could be improved signifi- cantly by creating information-fusion tools to support checkpoint opera- tors in real time (a prevention task). Also, advances in the automatic interpretation of image, video, and other kinds of unstructured data could aid in detection. Finally, early response to biological attacks could be supported by collecting and analyzing real-time data such as admissions to hospital emergency rooms and purchases of nonprescription drugs in grocery stores. The ability to acquire, integrate, and interpret a range and volume of data will support decision makers such as emergency-response units and intelligence organizations.
Data mining is a technology for analyzing historical and current online data to support informed decision making by learning general patterns from a large volume of specific examples. But to be useful for counter- terrorist purposes, such efforts must be possible over data in a variety of different and nonstructured formats, such as text, image, and video in multiple languages. In addition, new research is needed to normalize and combine data collected from multiple sources to improve data inter- operability. And, new techniques for data visualization will be useful in exploiting human capabilities for pattern recognition.
Privacy and Confidentiality
Concerns over privacy and confidentiality are magnified in a counter- terrorism intelligence context. The perspective of intelligence gatherers, “collect everything in case something might be useful,” conflicts with the pro-privacy tenet of “don’t collect anything unless you know you need it.” To resolve this conflict, research is needed to provide policy makers with accurate information about the impact on privacy and confidentiality of different kinds of data disclosure. Furthermore, the development of new privacy-sensitive techniques may make it possible to provide useful information to analysts without compromising individual privacy. A va-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
7EXECUTIVE SUMMARY
riety of policy actions could also help to reduce the consequences of pri- vacy violations.
Other Important Technology Areas
This report also briefly addresses three other technology areas: robotics, sensors, and modeling and simulation:
• Robots, which can be used in environments too dangerous for human beings, combine complex mechanical, perceptual, and computer and tele- communications systems, and pose significant research challenges such as the management of a team of robots and their integration.
• Sensors, used to detect danger in the environment, are most effec- tive when they are linked in a distributed sensor network, a problem that continues to pose interesting research problems.
• Modeling and simulation can play important roles throughout crisis- management activities by making predictions about how events might unfold and by testing alternative operational choices. A key challenge is understanding the utility and limitations of models hastily created in response to an immediate crisis.
People and Organizations
Technology is always used in some social and organizational context, and human culpability is central in understanding how the system might succeed or fail. The technology cannot be examined in isolation from how it is deployed. Technology aimed at assisting people is essential to modern everyday life. At the same time, if improperly deployed, the technology can actually make the problem worse; human error can be extremely costly in time, money, and lives. Good design can dramatically reduce the incidence of error.
Principles of Human-Centered Design
Systems must be designed from a holistic, systems-oriented perspec- tive. Principles that should guide such design include the following:
• Put human beings “in the loop” on a regular basis. Systems that use human beings only when automation is incapable of handling a situation are invariably prone to “human error.”
• Avoid common-mode failures, and recognize that common modes are not always easy to detect.
• Observe the distinction between work as prescribed and work as practiced.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
8 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Procedures that address work as prescribed (e.g., tightening procedures and requiring redundant checking) often interfere with getting work done (i.e., work as practiced).
• Probe security measures independently using tiger teams. Tiger-team efforts, undertaken to test an organization’s operational security posture using teams that simulate what a determined attacker might do, do what is necessary in order to penetrate security.
Organizational Resistance to Interagency Cooperation
An effective response to a serious terrorist incident will inevitably require interagency cooperation. However, because different agencies develop—and could reasonably be expected to develop—different inter- nal cultures for handling the routine situations that they mostly address, interagency cooperation in a large-scale disaster is likely to be difficult under the best of circumstances.
There are no easy answers for bridging the cultural gulfs between agencies that are seldom called upon to interact. Effective interagency cooperation in times of crisis requires strong, sustained leadership that places a high priority on such cooperation and is willing to expend budget and personnel resources in support of it. Exercises and activities that promote interagency cooperation help to identify and solve some social, organizational, and technical problems, and also help to reveal the rival- ries between agencies.
Research Implications Associated with Human and Organizational Factors
To better integrate the insights of social science into operational IT systems, research is relevant in at least four different areas:
• Formulating of system development methods that are more ame- nable to the incorporation of domain knowledge and social science exper- tise;
• Translating social science research findings into guidelines and methods that are readily applied by the technical community;
• Developing reliable security measures that do not interfere with work processes of legitimate employees; and
• Understanding the IT issues related to the disparate organizational cultures of agencies that will be fused under the Department of Home- land Security.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
9EXECUTIVE SUMMARY
RATIONALIZING THE LONG-TERM RESEARCH AGENDA
The committee is silent on which government agency would best support the proposed research agenda. However, the research agenda should be characterized by the following:
• Support of multidisciplinary problem-oriented research that is use- ful both to civilian and to military users;
• A deep understanding and assessment of vulnerabilities; • A substantial effort in research areas with a long time horizon for
payoff, and tolerance of research directions that may not promise imme- diate applicability;
• Oversight by a board or other entity with sufficient stature to at- tract top talent to work in the field and to provide useful feedback; and
• Attention to the human resources needed to sustain the counter- terrorism IT research agenda.
One additional attribute of this R&D infrastructure would be desir- able: the ability of researchers to learn from each other in a relatively free and open intellectual environment. Constraining the openness of that environment such as with classified research would have negative conse- quences for the research itself. Yet the free and open dissemination of information has potential costs, as terrorists may obtain information that they can use against us. The committee believes (or at least hopes) that there are other ways of reconciling the undeniable tension, and calls for some thought to be given to a solution to this dilemma.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
10
1
Background and Introduction
1.1 WHAT IS TERRORISM?
Terrorism is usually defined in terms of non-state-sponsored attacks on civilians, perpetrated with the intent of spreading fear and intimida- tion. Terrorism can occur on many different scales and can cause a wide range of impacts. For many Americans, the events of September 11, 2001, changed dramatically their perceptions of what terrorism could entail. In the space of a few hours, thousands of American lives were lost, and property damage in the tens of billions of dollars occurred—an obviously high-impact event. However, as illustrated by the subsequent anthrax attacks, widespread disruption of key societal functions, loss of public confidence in the ability of governmental institutions to keep society safe, widespread loss of peace of mind, and/or pervasive injury to a society’s way of life also count as manifestations of “high impact.” It is on such high-impact, catastrophic dimensions of terrorism that the Committee on the Role of Information Technology in Responding to Terrorism decided to concentrate in order to keep the analytical focus of this report manage- able.
The committee does not mean to suggest that only events of the mag- nitude of those on September 11 are worth considering. But the commit- tee is primarily addressing events that would result in long-lasting and/ or major financial or life-safety impacts and that would generally require a coordinated response among multiple agencies, or are in many other respects very complicated to manage. Damaging and destructive though individual attacks are, the digital equivalent of a single car bomb with
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
11BACKGROUND AND INTRODUCTION
conventional explosives (e.g., a single hacker breaking into a nominally unsecured system that does not tunnel into other critical systems) is not the primary focus of this report.
In the context considered here, the adversary must be conceptualized as a very patient, smart, and disciplined opponent with many resources (money, personnel, time) at its disposal. Thus, in an information tech- nology context, the “lone hacker” threat—often described in terms of maladjusted teenage males with too much time on their hands—is not the appropriate model. Protection against “ankle biters” and “script kiddies” who have the technical skills and understanding as well as the time needed to discover and exploit vulnerabilities is of course worth some effort, but it is important as well to consider seriously the larger threat that potentially more destructive adversaries pose.
1.2 THE ROLE OF INFORMATION TECHNOLOGY IN NATIONAL LIFE AND IN COUNTERTERRORISM
Information technology (IT) is essential to virtually all of the nation’s critical infrastructures, which makes any of them vulnerable to a terrorist attack on the computer or telecommunications networks of those infra- structures. IT plays a critical role in managing and operating nuclear- power plants, dams, the electric-power grid, the air-traffic-control system, and financial institutions. Large and small companies rely on computers to manage payroll, track inventory and sales, and perform research and development. Every stage in the distribution of food and energy from producer to retail consumer relies on computers and networks. A more recent trend is the embedding of computing capability in all kinds of devices and environments, as well as the networking of embedded sys- tems into larger systems.1 And, most obviously, IT is the technological underpinning of the nation’s communications systems, from the local loop of “plain old telephone service” to the high-speed backbone connec- tions that support data traffic. These realities make the computer and communications systems of the nation a critical infrastructure in and of themselves, as well as major components of other kinds of critical infra- structure, such as energy or transportation systems.
In addition, while IT per se refers to computing and communications technologies, the hardware and software (i.e., the technological artifacts
1Computer Science and Telecommunications Board, National Research Council. 2001. Embedded, Everywhere: A Research Agenda for Networked Systems of Embedded Computers. National Academy Press, Washington, D.C. (Note that most Computer Science and Tele- communications Board reports contain many references to relevant literature and addi- tional citations.)
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
12 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
of computers, routers, operating systems, browsers, fiber-optic lines, and so on) are part of a larger construct that involves people and organiza- tions. The display on a computer system presents information for a person who has his or her own psychological and emotional attributes and who is usually part of an organization with its own culture and standard oper- ating procedures. Thus, to understand how IT might fail or how the use of IT might not achieve the objectives desired, it is always necessary to consider the larger entity in which the IT is embedded.
IT also has a major role in the prevention, detection, and mitigation of terrorist attacks.2 This report focuses on two critical applications. First, emergency response involves the agencies, often state and local, that are called upon to respond to terrorist incidents—firefighters, police, ambu- lance, and other emergency health care workers, and so on. These agen- cies are critically reliant on information technology to communicate, to coordinate, and to share information in a prompt, reliable, and intelligible fashion. Second, information awareness involves promoting a broad knowledge of critical information in the intelligence community to iden- tify important patterns of behavior. Advances in information fusion, which is the aggregation of data from multiple sources for the purpose of discovering some insight, may be able to uncover terrorists or their plans in time to prevent attacks. In addition to prevention and detection, IT may also help rapidly and accurately identify the nature of an attack and aid in responding to it more effectively.
1.3 THE INFORMATION TECHNOLOGY INFRASTRUCTURE AND ASSOCIATED RISKS
The IT infrastructure can be conceptualized as having four major elements: the Internet, the conventional telecommunications infrastruc- ture, embedded/real-time computing (e.g., avionics systems for aircraft control, supervisory control and data acquisition [SCADA] systems con-
2Computer Science and Telecommunications Board, National Research Council, 1996, Computing and Communications in the Extreme: Research for Crisis Management and Other Applications, National Academy Press, Washington, D.C.; Computer Science and Tele- communications Board, National Research Council, 1999, Information Technology Research for Crisis Management, National Academy Press, Washington, D.C. For purposes of the present report, prevention is relevant to the period of time significantly prior to an attack; during that period, a pending attack can be identified and the terrorist planning process for that attack disrupted or preempted. Detection is relevant in the period of time immediately before or during an attack (since an attack must first be detected before a response occurs). Mitigation is relevant during the time immediately after an attack, and it generally involves actions related to damage and loss minimization, recovery, and reconstitution.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
13BACKGROUND AND INTRODUCTION
trolling electrical energy distribution), and dedicated computing devices (e.g., desktop computers).
Each of these elements plays a different role in national life, and each has different specific vulnerabilities. Nevertheless, the ways in which IT can be damaged fall into three categories.3 A system or network can become:
• Unavailable. That is, using the system or network at all becomes very difficult or impossible. The e-mail does not go through, or the com- puter simply freezes, or response time becomes intolerably long.
• Corrupted. That is, the system or network continues to operate, but under some circumstances of operation, it does not provide accurate results or information when one would normally expect. Alteration of data, for example, could have this effect.
• Compromised. That is, someone with bad intentions gains access to some or all of the capabilities of the system or network or the information available through it. The threat is that such a person could use privileged information or system control to further his or her malign purposes.
These types of damage are not independent—for example, an attacker could compromise a system in order to render it unavailable.
Different attackers might have different intentions with respect to IT. In some cases, an element of the IT infrastructure itself might be a target to be destroyed (e.g., the means for people to communicate or to engage in financial transactions). Alternatively, the target of the terrorist might be another kind of critical infrastructure (e.g., the electric-power grid), and the terrorist could either launch or exacerbate the attack by exploiting the IT infrastructure, or use it to interfere with attempts to achieve a timely and effective response.
In short, IT is both a target and a weapon that can be deployed against other targets. Counterterrorist activities thus seek to reduce the likeli- hood that IT functionality will be diminished as a result of an attack or as a result of the damage that might come from the use of IT as a weapon against valued targets.
A terrorist attack that involves the IT infrastructure can operate in one of several modes. First, an attack can come in “through the wires” as a hostile program (e.g., a virus or a Trojan horse program) or as a denial-
3Computer Science and Telecommunications Board, National Research Council. 2002. Cybersecurity Today and Tomorrow: Pay Now or Pay Later. National Academy Press, Washing- ton, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
14 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
of-service attack.4 Second, some IT element may be physically destroyed (e.g., a critical data center or communications link blown up) or compro- mised (e.g., IT hardware surreptitiously modified in the distribution chain). Third, a trusted insider may be compromised (such a person, for instance, may provide passwords that permit outsiders to gain entry);5 such insiders may also be conduits for hostile software or hardware modi- fications. All of these modes are possible and, because of the highly public and accessible nature of our IT infrastructure and of our society in general, it is impossible to fully secure this infrastructure against them. Nor are they mutually exclusive, and in practice they can be combined to produce even more destructive effects.
4A “through-the-wires” attack is conducted entirely at a distance and requires no physical proximity to the target.
5Computer Science and Telecommunications Board, National Research Council. 1999. Trust in Cyberspace. National Academy Press, Washington, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
15
2 Types of Threats
Associated with Information Technology Infrastructure
Most of the nation’s civil communications and data network infra- structure is not hardened against attack, but this infrastructure tends to be localized either in geography or in mode of communication. Thus, if no physical damage is done to them, the computing and communications capabilities disrupted in an attack are likely to be recoverable in a rela- tively short time. Although their scope or scale is limited, they are none- theless potentially attractive targets for what might be called “incremen- tal” terrorism. That is, terrorists could use IT as the weapon in a series of relatively local attacks that are repeated against different targets—such as banks, hospitals, or local government services—so often that public confi- dence is shaken and significant economic disruption results.
However, this report focuses primarily on catastrophic terrorism, and the committee’s analysis is aimed at identifying threats of that magnitude in particular and at proposing science and technology (S&T) strategies for combating them. Of course, serious efforts are needed to develop and deploy security technologies to harden all elements of the IT infrastruc- ture to reduce the potential for damage from repeated attacks.
2.1 ATTACK ON IT AS AN AMPLIFIER OF A PHYSICAL ATTACK
Given IT’s critical role in many other elements of the national infra- structure and in responding to crises, the committee believes that the targeting of IT as part of a multipronged attack scenario could have the most catastrophic consequences. Compromised IT can have several disas- trous effects: expansion of terrorists’ opportunities to widen the damage
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
16 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
of a physical attack (e.g., by providing false information that drives people toward, rather than away from, the point of attack); diminution of timely responses to an attack (e.g., by interfering with communications systems of first responders); and heightened terror in the population through mis- information (e.g., by providing false information about the nature of a threat). The techniques to compromise key IT systems—for example, launching distributed denial-of-service (DDOS) attacks against Web sites and servers of key government agencies at the federal, state, and local levels; using DDOS attacks to disrupt agencies’ telephone services and the emergency-response 911 system; or sending e-mails containing false information with forged return addresses so that they appear to be from trusted sources—are fairly straightforward and widely known.
2.2 OTHER POSSIBILITIES FOR ATTACK INVOLVING IT
When an element of the IT infrastructure is directly targeted, the goal is to destroy a sufficient amount of IT-based capability to have a signifi- cant impact, and the longer that impact persists, the more successful it is from the terrorist’s point of view. For example, one might imagine at- tacks on the computers and data storage devices associated with impor- tant facilities. Irrecoverable loss of critical operating data and essential records on a large scale would likely result in catastrophic and irrevers- ible damage to the U.S. economy. However, most major businesses al- ready have disaster-recovery plans in place that include the backup of their data in a variety of distributed and well-protected locations (and in many cases, they augment backups of data with backup computing and communications facilities).1 While no law of physics prevents the simul- taneous destruction of all data backups and backup facilities in all loca- tions, such an attack would be highly complex and difficult to execute and is thus highly unlikely.
2.2.1 Attacks on the Internet
The infrastructure of the Internet is another possible terrorist target, and given the Internet’s public prominence, it may appeal to terrorists as an attractive target. The Internet could be seriously degraded for a rela- tively short period of time by a denial-of-service attack,2 but such impact
1On the other hand, backup sites are often shared—one site may protect the data of multiple firms.
2A denial-of-service attack floods a target with a huge number of requests for service, thus keeping it busy servicing these (bogus) requests and unable to service legitimate ones.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
17TYPES OF THREATS ASSOCIATED WITH IT INFRASTRUCTURE
is unlikely to be long lasting. The Internet itself is a densely connected network of networks that automatically routes around links that become unavailable,3 which means that a large number of important nodes would have to be destroyed simultaneously to bring it down for an extended period of time. Destruction of some key Internet nodes could result in reduced network capacity and slow traffic across the Internet, but the ease with which Internet communications can be rerouted would mini- mize the long-term damage.4 (In this regard, the fact that substantial data-networking services survived the September 11 disaster despite the destruction of large amounts of equipment—concentrated in the World Trade Center complex—reflected redundancies in the infrastructure and a measure of good fortune as well.)
The terrorist might obtain higher leverage with a “through-the-wires” attack that would require the physical replacement of components in Internet relay points on a large scale,5 though such attacks would be much harder to plan and execute. Another attack that would provide higher leverage is on the Internet’s Domain Name System (DNS), which translates domain names (e.g., example.com) to specific Internet Protocol (IP) addresses (e.g., 192.0.34.72) denoting specific Internet nodes. A rela- tively small number of “root name servers” underpins the DNS. Al- though the DNS is designed to provide redundancy in case of accidental failure, it has some vulnerability to an intentional physical attack that might target all name servers simultaneously. Although Internet opera- tions would not halt instantly, an increasing number of sites would, over a period of time measured in hours to days, become inaccessible without root name servers to provide authoritative translation information. How- ever, recovery from such an attack would be unlikely to take more than several days—damaged servers can be replaced, since they are general- purpose computers that are in common use.
In addition, most companies today do not rely on the Internet to carry out their core business functions. Even if a long-term disruption to the Internet were a major disruption to an e-commerce company such as Amazon.com or Dell, most other companies could resort to using phones
3Computer Science and Telecommunications Board, National Research Council. 2001. The Internet’s Coming of Age. National Academy Press, Washington, D.C. Note, however, that the amount of redundancy is primarily limited by economic factors.
4This comment largely applies to U.S. use of the Internet. It is entirely possible that other nations—whose traffic is often physically routed through one or two locations in the United States—would fare much worse in this scenario.
5For example, many modern computers allow certain hardware components to be repro- grammed under software control. Improper use of this capability can damage hardware permanently.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
18 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
and faxes again to replace the Internet for many important functions. (For example, the Department of the Interior has been largely off the Internet since December 5, 2001,6 but it has continued to operate more or less as usual.)
Because the Internet is not yet central to most of American society, the impact of even severe damage to the Internet is less than what might be possible through other modes of terrorist attack. However, current trends suggest that the reliance on the Internet for key functions is likely to grow in the future, despite the existence of real security threats, and so this assessment about lower levels of impact from attacks on the Internet may become less valid in the future.
Box 2.1 provides some historical examples of attacks on the Internet.
2.2.2 Attacks on the Public Switched Network
The telecommunications infrastructure of the public switched net- work is likely to be less robust than the Internet. Although the long-haul telecommunications infrastructure is capable of dealing with single-point failures (and perhaps even double-point failures) in major switching cen- ters, the physical redundancy in that infrastructure is finite, and damag- ing a relatively small number of major switching centers for long-distance telecommunications could result in a fracturing of the United States into disconnected regions.7 Particular localities may be disrupted for a con- siderable length of time—in the aftermath of the September 11 attacks in New York City, telephone service in the downtown area took months to restore fully. Note also that many supposedly independent circuits are trenched together in the physical trenches along certain highway and rail rights-of-way, and thus these conduits constitute not just “choke points” but rather “choke routes” that are hundreds of miles long and that could be attacked anywhere.
An additional vulnerability in the telecommunications infrastructure is the local loop connecting central switching offices to end users; full recovery from the destruction of a central office entails the tedious rewir- ing of tens or hundreds of thousands of individual connections. Destruc- tion of central offices on a large scale is difficult, simply because even an individual city has many of them, but destruction of a few central offices
6For additional information, see <http://www.computerworld.com/storyba/ 0,4125,NAV47_STO66665,00.html>.
7An exacerbating factor is that many organizations rely on leased lines to provide high(er)-assurance connectivity. However, these lines are typically leased from providers of telecommunications infrastructure and hence suffer from many of the same kinds of vulnerabilities as those that affect ordinary lines.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
19TYPES OF THREATS ASSOCIATED WITH IT INFRASTRUCTURE
BOX 2.1 Historical Examples of Attacks on the Internet
• In March 1999, the Melissa virus infected e-mail systems worldwide. Accord- ing to estimates from federal officials, the virus caused $80 million in disruption, lost commerce, and computer downtime, and infected 1.2 million computers. The virus launched when a user opened an infected Microsoft Word 8 or Word 9 document contained in either Office 97 or Office 2000.1 The virus, programmed as a macro in the Word document, prompted the Outlook e-mail program to send the infected document to the first 50 addresses in the victim’s Outlook address book. When a recipient opened the attachment in the e-mail, which appeared to be from a friend, co-worker, boss or family member, the virus spread to the first 50 e-mail addresses in that person’s address book, and thus continued to propagate. Six months after the first appearance of Melissa, variant strains continued to make their way into users’ inboxes despite warnings and widespread publicity about opening attachments while the macro function is enabled.
• Over a four-day period beginning February 7, 2000, distributed denial-of- service attacks temporarily shut down Yahoo, Amazon, E*Trade, eBay, CNN.com, and other Web sites. Yahoo shut down its site for several hours during peak viewing hours at an estimated cost of $116,000.2 While the companies behind the targeted Web sites said that the attacks themselves would have minor financial impact, the attacks were of such importance that the White House convened a group of comput- er-security experts and technology executives to discuss the Internet’s vulnerabilities. Federal officials spent millions in investigations of the DDOS attacks that garnered significant public attention.
• On July 19, 2001, the Code Red program “worm” infected more than 359,000 computers in less than 14 hours and 2,000 new infections per minute occurred dur- ing the height of its attack. Nimda, a similar hostile program first appearing on September 18, 2001, was potentially more damaging because it combined success- ful features of previous viruses such as Melissa and ILOVEYOU. During the first 24 hours, Nimda spread through e-mail, corporate networks, and Web browsers, infect- ing as many as 150,000 Web server and personal computers (PCs) in the United States. The virus—“admin” spelled backwards—was designed to affect PCs and servers running the Windows operating system and to resend itself every 10 days unless it was deleted. Nimda reproduced itself both via e-mail and over the Web— a user could be victimized by merely browsing a Web site that was infected. Further- more, the infected machines sent out a steady stream of probes looking for new systems to attack. The additional traffic could effectively shut down company net- works and Web sites; Nimda-generated traffic did not slow down the Internet over- all, but infected companies reported serious internal slowdowns.3 Code Red and Nimda are examples of these new blended threats. Both are estimated to have caused $3 billion worldwide in lost productivity and for testing, cleaning, and de- ploying patches to computer systems.4
1Ann Harrison. 1999. “FAQ: The Melissa Virus,” COMPUTERWORLD, March 31. Avail- able online at <http://www.computerworld.com/news/1999/story/0,11280,27617,00.html>.
2Ross Kerber. 2000. “Vandal Arrests Would Only Be the Beginning Penalties, Damages Seen Hard to Determine,” The Boston Globe, February 11.
3Henry Norr. 2001. “New Worm Plagues Systems Worldwide,” The San Francisco Chron- icle, September 19.
4Gregory Hulme. 2002. “One Step Ahead—Security Managers Are Trying to Be Prepared for the Next Blended Threat Attack,” InformationWeek, May 20.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
20 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
associated with key facilities or agencies (e.g., those of emergency-re- sponse agencies or of the financial district) would certainly have a signifi- cant immediate though localized impact. However, the widespread avail- ability of cellular communications, and mobile base-stations deployable in emergency conditions, may mitigate the effect of central office losses.
2.2.3 The Financial System
The IT systems and networks supporting the nation’s financial sys- tem are undeniably critical. The financial system is based on the Federal Reserve banking system, a system for handling large-value financial trans- actions (including Fedwire operated by the Federal Reserve, CHIPS, and SWIFT), and a second system for handling small-value retail transactions (including the Automated Clearing House, the credit-card system, and paper checks).8 By its nature, the system for retail transactions is highly decentralized, while the system for large-value transactions is more cen- tralized. Both the Federal Reserve system and the system for large-value transactions operate on networks that are logically distinct from the pub- lic telecommunications system or the Internet, and successful information attacks on these systems likely necessitate significant insider access.9
2.2.4 Embedded/Real-Time Computing
Embedded/real-time computing in specific systems could be at- tacked. For example, many embedded computing systems could be cor- rupted over time.10 Of particular concern could be avionics in airplanes,
8For an extended (though dated) discussion of the infrastructure underlying the financial system, see John C. Knight et al., 1997, Summaries of Three Critical Infrastructure Applications, Computer Science Report No. CS-97-27, Department of Computer Science, University of Virginia, Charlottesville, November 14.
9The fact that these networks are logically separate from those of the Internet and the public switched telecommunications network reduces the risk of penetration considerably. In addition, security consciousness is much higher in financial networks than it is on the Internet. On the other hand, the fact that these networks are much smaller than the Internet suggests that there is less redundancy in them and that the computing platforms are likely to be less diverse compared with those on the Internet, a factor that tends to reduce security characteristics as compared with those of the Internet. Also, the physical infrastructure over which these financial networks communicate is largely shared, which means that they are vulnerable to large-scale physical disruptions or attacks on the telecommunications infrastructure.
10An inadvertent demonstration of this possibility was illustrated with the Y2K problem that was overlooked in many embedded/real-time systems designed in the 1980s and ear- lier.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
21TYPES OF THREATS ASSOCIATED WITH IT INFRASTRUCTURE
collision-avoidance systems in automobiles, and other transportation sys- tems. Such attacks would require a significant insider presence in techni- cally responsible positions in key sectors of the economy over long peri- ods of time. Another example is that sensors, which can be important elements of counterterrorism precautions, could be the target of an attack or, more likely, precursor targets of a terrorist attack.
2.2.5 Control Systems in the National Critical Infrastructure
Another possible attack on embedded/real-time computing would be an attack on the systems controlling elements of the nation’s critical infrastructure, for example, the electric-power grid, the air-traffic-control system, the financial network, and water purification and delivery. An attack on these systems could trigger an event, and conceivably stimulate an inappropriate response that would drive large parts of the the overall system into a catastrophic state. Still another possibility is the compro- mise or destruction of systems and networks that control and manage elements of the nation’s transportation infrastructure; such an attack could introduce chaos and disruption on a large scale that could drastically reduce the capability of transporting people and/or freight (including food and fuel).
To illustrate, consider the electric-power grid, which is one of the few, if not the only, truly national infrastructures in which it is theoretically possible that a failure in a region could cascade to catastrophic propor- tions before it could be dealt with. The electric-power grid is controlled by a variety of IT-based SCADA systems. (Box 2.2 describes some of the security issues associated with these systems.) Attacks on SCADA sys- tems could obviously result in disruption of the network (“soft” damage), but because SCADA is used to control physical elements, such attacks could also result in irreversible physical damage. In cases in which back- ups for damaged components were not readily available (and might have to be remanufactured from scratch), such damage could have long-lasting impact. (Similar considerations apply to other parts of the nation’s infra- structure.)
An electronic attack on a portion of the electric-power grid could result in significant damage, easily comparable to that associated with a local blackout. However, if terrorists took advantage of the chaos caused by a local blackout, they could likely inflict greater physical damage than would be possible in the absence of a blackout.
Another plausible disaster scenario that could rise to the level of cata- strophic damage would be an attack on a local or regional power system that cascaded to shut down electrical power over a much wider area and possibly caused physical damage that could take weeks to repair.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
22 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 2.2 Security Vulnerabilities and Problems of SCADA Systems
Today’s supervisory control and data acquisition (SCADA) systems have been designed with little or no attention to security. For example, data in SCADA systems are often sent “in the clear.” Protocols for accepting commands are open, with no authentication required. Control channels are often wireless or leased lines that pass through commercial telecommunications facilities. Unencrypted radio-frequency command pathways to SCADA systems are common and, for economic reasons, the Internet itself is increasingly used as a primary command pathway. In general, there is minimal protection against the forgery of control messages or of data and status messages. Such control paths present obvious vulnerabilities.
In addition, today’s SCADA systems are built from commercial off-the-shelf com- ponents and are based on operating systems that are known to be insecure. Dereg- ulation has meant placing a premium on the efficient use of existing capacity, and hence interconnections to shift supply from one location to another have increased. Problems of such distributed real-time dynamic control, in combination with the complex, highly interactive nature of the system being controlled, have become major issues in operating the power grid reliably.
A final problem arises because of the real-time nature of SCADA systems, in which timing may be critical to performance and optimal efficiency (timing is impor- tant because interrupts and other operations can demand millisecond accuracy): security add-ons in such an environment can complicate timing estimates and cause severe degradation to SCADA performance.
Compounding the difficulty of securing SCADA systems is the fact that informa- tion about their vulnerability is so readily available. Such information was first brought into general view in 1998-1999, when numerous details on potential Y2K problems were put up on the World Wide Web. Additional information of greater detail—dealing with potential attacks that were directly or indirectly connected to the President’s Commission on Critical Infrastructure Protection—was subsequently posted on Web pages as well. Product data and educational videotapes from engi- neering associations can be used to familiarize potential attackers with the basics of the grid and with specific elements. Information obtained through semiautomated reconnaissance to probe and scan the networks of a variety of power suppliers could provide terrorists with detailed information about the internal workings of the SCADA network, down to the level of specific makes and models of equipment used and version releases of corresponding software. And more inside information could be obtained from sympathetic engineers and operators.
By comparison with the possibility of an attack on only a portion of the power grid, the actual feasibility of an attack that would result in a cascading failure with a high degree of confidence is not clear; a detailed study both of SCADA systems and the electric-power system would prob- ably be required in order to assess this possibility. However, because of the inordinate complexity of the nation’s electric-power grid, it would be difficult for either grid operators or terrorists to predict with any confi-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
23TYPES OF THREATS ASSOCIATED WITH IT INFRASTRUCTURE
dence the effects on the overall grid from a major disruptive event in one part of the system. Thus, any nonlocalized impact on the power grid would be as much a matter of chance as a foreseeable consequence.
2.2.6 Dedicated Computing Facilities
In many of the same ways that embedded computing could be at- tacked, dedicated computers such as desktop computers could also be corrupted in ways that are hard to detect. One possible channel comes from the extensive use of untrustworthy IT talent among software ven- dors.11 Once working on the inside, perhaps after a period of years in which they act to gain responsibility and trust, it could happen that these individuals would be able to introduce additional but unauthorized func- tionality into systems that are widely used. Under such circumstances, the target might not be the general-purpose computer used in the major- ity of offices around the country, but rather the installation of hidden rogue code in particular sensitive offices. Another possible channel for attacking dedicated computing facilities results from the connection of computers through the Internet; such connections provide a potential route through which terrorists might attack computer systems that do provide important functionality for many sectors of the economy. Ex- amples of widely used Internet-based vectors that, if compromised would have a large-scale effect in a short time, include the operating systems upgrades and certain shareware programs, such as those for sharing mu- sic files. (It is likely that Internet-connected computer systems that pro- vide critical functionality to companies and organizations are better pro- tected through firewalls and other security measures than is the average system on the Internet, but as press reports in recent years make clear, such measures do not guarantee that outsiders cannot penetrate them.)
2.3 DISPROPORTIONATE IMPACTS
Some disaster scenarios could result in significant loss or damage that is out of proportion to the actual functionality or capability destroyed. In
11Untrustworthy talent may be foreign or domestic in origin. Because foreign IT work- ers—whether working in the United States (e.g., under an H1-B visa or a green card) or offshore on outsourced work—are generally not subject to thorough background investiga- tions, an obvious route is available through which foreign terrorist organizations can gain insider access. On the other hand, reports of American citizens having been successfully recruited by foreign terrorist organizations add a degree of believability to the scenario of domestic IT talent’s being used to compromise systems for terrorist purposes.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
24 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
particular, localized damage that resulted in a massive loss of confidence in some critical part of the infrastructure could have such a dispropor- tionate impact. For example, if terrorists were able to make a credible claim that the control software of a popular “fly-by-wire” airliner was corrupted and could be induced to cause crashes on demand, perhaps demonstrating it once, public confidence in the airline industry might well be undermined. A more extreme scenario might be that the airlines themselves would ground airplanes until they could be inspected and the software validated.
To the extent that critical industries or sectors rely upon any element of the IT infrastructure, such disproportionate-impact disaster scenarios are a possibility. For this reason, certain types of attack that do not cause extensive actual damage must be considered to have some catastrophic potential. Accordingly, response plans must take into account how to communicate with the public for purposes of reassurance. (This point is beyond the scope of this report but is addressed in Making the Nation Safer.12 )
2.4 THREATS IN PERSPECTIVE: POSSIBILITY, LIKELIHOOD, AND IMPACT
While the scenarios described above are necessarily speculative, it is possible to make some judgments that relate to their likelihood:
• For a variety of reasons, state support of terrorism poses threats of a different and higher order of magnitude than does cybercrime or terror- ism without state sponsorship. These reasons include access to large amounts of financial backing and the ability to maintain an actively adversarial stance at a high level for extended periods of time. For ex- ample, terrorists with the support of a state might be able to use the state’s intelligence services to gain access to bribable or politically sympathetic individuals in key decision-making places or to systematically corrupt production or distribution of hardware or software.
• The most plausible threats are simple attacks launched against complex targets. The successful execution of complex attacks requires that many things go right, so simplicity in attack planning is an important consideration. Complex rather than simple targets are desirable because of the likelihood that the failure modes of a complex target are usually not
12National Research Council. 2002. Making the Nation Safer: The Role of Science and Tech- nology in Countering Terrorism. National Academies Press, Washington, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
25TYPES OF THREATS ASSOCIATED WITH IT INFRASTRUCTURE
well understood by its designers, and thus there are many more ways in which failure can occur in such systems.
• Attacks that require insider access are more difficult to carry out and thus less likely to occur than attacks that do not. Insiders must be placed or recruited and are not necessarily entirely trustworthy even from the standpoint of the attacker. Individuals with specialized expertise chosen to be placed as infiltrators may not survive the screening process, and because there is a limited number of such individuals, it can be diffi- cult to insert an infiltrator into a target organization. In addition, com- pared to approaches not relying on insiders, insiders may leave behind more tracks that can call attention to their activities. This judgment de- pends, of course, on the presumed diligence of employers in ensuring that their key personnel are trustworthy, and it is worth remembering that the most devastating espionage episodes in recent U.S. history have involved insiders (i.e., Aldrich Ames and Robert Hanssen).
• Attacks that require execution over long periods of time are harder and thus less likely to mount than attacks that do not. Planning often takes place over a long period of time, but the actual execution of a plan can be long as well as short. When a plan requires extended activity that, if detected, would be regarded as abnormal, it is more likely to be discov- ered and/or thwarted.
• Terrorist attacks can be sustained over time as well as occurring in individual instances. If the effects of an attack sustained over time (per- haps over months or years) are cumulative, and if the attack goes unde- tected, the cumulative effects could reach very dangerous proportions. Because such an attack proceeds a little bit at a time, the resources needed to carry it out may well be less than those needed in more concentrated attacks, thus making it more feasible.
• Plans that call for repeated attacks are less likely to succeed than those calling for a single attack. For example, it is true that repeated attacks against the Internet could have effects that would defeat efforts to repair or secure it after one initial attack. Such an onslaught would be difficult to sustain, however, because it is highly likely to be detected, and efforts would be made to counter it. Instead, an adversary with the where- withal to conduct such repeated attacks would more likely make the ini- tial strike and then use the recovery period not to stage and launch an- other strike against the Internet but to attack the physical infrastructure; this strategy could leverage the inoperative Internet to cause additional damage and chaos. (Of course, the fact that physical attacks may be more difficult to conduct must also be taken into account.)
• The IT infrastructure (or some element of it) can be a weapon used in an attack on something else as well as being the target of an attack. An attack using the IT infrastructure as a weapon has advantages and disad-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
26 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
vantages from the point of view of a terrorist planner. It can be conducted at a distance in relative physical safety, in a relatively anonymous fashion, and in potentially undetectable ways. However, the impact of such an attack (by assumption, on some other critical national asset) would be indirect, harder to predict, and less certain.
• Some of the scenarios described above are potentially relevant to information warfare attacks against the United States—that is, attacks launched or abetted by hostile nation-states and/or directed against U.S. military forces or assets. A hostile nation conducting an information attack on the United States is likely to conceal its identity to minimize the likelihood of retaliation, and thus it may resort to sponsoring terrorists who can attack without leaving clear national signatures.
The committee wishes to underscore a very important point regard- ing terrorist threats to the IT infrastructure—they are serious enough to warrant considerable national attention, but they are, in the end, only one of a number of ways through which terrorists could act against the United States. Thus, the likelihood of some kind of terrorist attack against or using the IT infrastructure must be understood in the context of a terrorist organization that may have many other types of attack at its disposal, including (possibly) chemical, biological, nuclear, radiological, suicide, and explosive attacks. This point is important because terrorists, like other parties, have limited resources. Thus, they are likely to concentrate their efforts where the impact is largest for the smallest expenditure of resources.
Many factors would play into a terrorist decision to use one kind of attack or another. The particular kinds of expertise and level of resources available, the effect that the terrorists wished to produce, the publicity they wished to gain, the complexity of any attack contemplated, the sym- bolic value of an attack, the risk of being caught, the likelihood of sur- vival, the defenses that would be faced if a given attack was mounted, and the international reaction to such an attack are all relevant to such a decision. How any given terrorist will weigh such factors cannot be known in advance.
For example, terrorists who want to create immediate public fear and terror are more likely to use a physical attack (perhaps in conjunction with an attack using IT to amplify the resulting damage) than an attack that targets IT exclusively. The reason is that the latter is not likely to be as cinematic as other attacks. What would television broadcast? There would be no dead or injured people, no buildings on fire, no panic in the streets, and no emergency-response crews coming to the rescue. (This is not to say that an attack targeting IT exclusively could not shake public
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
27TYPES OF THREATS ASSOCIATED WITH IT INFRASTRUCTURE
confidence—but it would not have the same impact as images of death and destruction in the streets.)
Note also that “likelihood” is not a static quantity. While it is true, all else being equal, that it is appropriate to devote resources preferentially to defending against highly likely attacks, the deployment of a defense that addresses the threat of a highly likely Attack A may well lead to a subsequent increase in the likelihood of a previously less likely Attack B. In short, terrorists may not behave in accordance with expectations that are based on static probability distributions. It is therefore very difficult to prioritize a research program for countering terrorism in the same way that one might, for example, prioritize a program for dealing with natural disasters.
How likely are terrorist attacks on the IT infrastructure or attacks using the IT infrastructure compared to terrorist attacks spreading small- pox or smuggling a stolen nuclear weapon into the United States? For obvious reasons, the committee is not in a position to make such judg- ments. But while the considerations discussed in this section make cer- tain types of attack more or less likely, none of the scenarios described in Section 2.2 can be categorically excluded.
This fact argues in favor of a long-term commitment to a strategic R&D program that will contribute to the overall robustness of the tele- communications and data networks and of the platforms associated with them. Such a program would involve both fundamental research into the scientific underpinnings of information and network security as well as the development of deployable technology that would contribute to in- formation and network security. Ultimately, the strengthening of the nation’s IT infrastructure can improve our ability to prevent, detect, re- spond to, and recover from terrorist attacks on the nation.13
13Computer Science and Telecommunications Board, National Research Council, 1996, Computing and Communications in the Extreme: Research for Crisis Management and Other Applications, National Academy Press, Washington, D.C; Computer Science and Telecom- munications Board, National Research Council, 1999, Information Technology Research for Crisis Management, National Academy Press, Washington, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
28
3
Investing in Information Technology Research
This chapter describes the shape of a strategic research and develop- ment (R&D) program with respect to information technology for counter- terrorism. However, it should be noted that this program has broad applicability not only for efforts against terrorism and information war- fare but also for reducing cybercrime and responding to natural disasters. While the scope and complexity of issues with respect to each of these areas may well vary (e.g., a program focused on cybercrime may place more emphasis on forensics useful in prosecution), the committee be- lieves that there is enough overlap in the research problems and ap- proaches to make it unwise to articulate a separate R&D program for each area.
Although many areas of information technology research could be potentially valuable for counterterrorist purposes, the three areas de- scribed below are particularly important for helping reduce the likeli- hood or impact of a terrorist attack:
1. Information and network security. Research in information and net- work security is critically relevant to the nation’s counterterrorism efforts for several reasons.1 First, IT attacks can amplify the impact of physical
1Computer Science and Telecommunications Board (CSTB), National Research Council (NRC), 1991, Computers at Risk: Safe Computing in the Information Age, National Academy Press, Washington, D.C. (hereafter cited as CSTB, NRC, 1991, Computers at Risk); Computer Science and Telecommunications Board, National Research Council, 1999, Trust in Cyberspace, National Academy Press, Washington, D.C. (hereafter cited as CSTB, NRC, 1999,
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
29INVESTING IN INFORMATION TECHNOLOGY RESEARCH
attacks and lessen the effectiveness of emergency responses; reducing such vulnerabilities will require major advances in information and net- work security. IT attacks on supervisory control and data acquisition (SCADA) systems in the control infrastructure could also be highly dam- aging, and research to improve the security of such systems will be needed. Second, the increasing levels of social and economic damage caused by cybercrime and the tendency to rely on the Internet as the primary networking and communications channel both suggest that the likelihood of severe damage through a cyberattack is increasing. Finally, the evolution of the Internet and the systems connected to it demonstrates increasing homogeneity in hardware and software (Box 3.1), which makes the Internet more vulnerable at the same time that it becomes more criti- cal. To address these problems, more researchers and trained profession- als who are focused on information and network security will be needed.
2. Systems for emergency response. “C3I” (command, control, commu- nications, and intelligence) systems are critical to emergency responders for coordinating efforts and increasing the promptness and effectiveness of response (e.g., saving lives, treating the injured, and protecting prop- erty). While terrorist attacks and natural disasters have many similarities with respect to the consequences of such events, the issues raised by C3I for emergency response for terrorist disasters differ from those for natural disasters for several reasons. First, the number of responding agencies, including those from the local, regional, state, and federal levels—with possibly conflicting and overlapping areas of responsibility—increases the level of complexity. (For example, in a terrorist attack scenario, the Department of Defense [DOD] might be much more involved than it would be in a natural disaster.) Second, ongoing security and law-en- forcement concerns are much stronger in the wake of a terrorist attack. While looting is often a threat to the community affected by a natural disaster (and may result in the deployment of a police presence in the midst of the recovery effort), the threat from a follow-on terrorist attack may well be much greater or more technologically sophisticated than that posed by looters. And, to the extent that an additional security or law- enforcement presence is required, the sometimes-conflicting needs of se- curity and law-enforcement agencies with the needs of others—for ex-
Trust in Cyberspace); Computer Science and Telecommunications Board, National Research Council, 2001, Embedded, Everywhere: A Research Agenda for Networked Systems of Embedded Computers, National Academy Press, Washington, D.C. (hereafter cited as CSTB, NRC, 2001, Embedded, Everywhere).
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
30 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 3.1 Monoculture and System Homogenity
The existence of “monoculture” on the Internet has both advantages and disad- vantages. Its primary advantage is that increased standardization of systems general- ly allows for greater efficiencies (e.g., easier interoperability). On the other hand, monocultural environments are generally more vulnerable to a single well-designed attack—a fact greatly exacerbated by the extensive interconnections that the Internet provides.
For example, a constant barrage of computer viruses has been designed to at- tack the weaknesses of the Windows operating system and its associated browser and office productivity programs. However, these viruses have had a negligible direct effect on computers running other operating systems. Furthermore, while these attacks can be propagated through computer servers running other operating sys- tems, they are not propagated on these systems.
A monoculture is highly vulnerable to attacks because once a successful attack on the underlying system is developed, it can be multiplied at extremely low cost. Thus, for all practical purposes, a successful attack on one system means that all similar (and similarly configured) systems connected to it can be attacked as well.
As a general rule, inhomogeneity of systems would make broad-based attacks more difficult. This should be considered carefully when designing primary or re- dundant critical network systems.
(Natural “living systems” provide an interesting analogy to the importance of diversity. Heterogeneity plays an important role in preventing minor changes in the climate, environment, or parasites from destroying the entire system. Different spe- cies demonstrate varying levels of vulnerability to the variety of challenges encoun- tered, and this lends resilience to the system as a whole. The diversity of species also lessens the possibility of infectious disease spreading across the entire system.)
ample, the fire and medical personnel on-site—mean that security and law enforcement may interfere with rescue and recovery operations.
3. Information-fusion systems for the prevention, detection, attribution, and remediation of attacks. “Information fusion” promises to play a central role in countering future terrorist efforts. Information fusion is an essential tool for the intelligence analysis needed if preemptive disruption of ter- rorist attacks is to be successful. Knowing that a biological attack is in progress (an issue of detection) or determining the perpetrators of an attack (an issue of attribution) may depend on the fusion of large amounts of information And, in many cases, early warning of an attack increases the effectiveness of any counterresponse to it. In every case, information from many sources will have to be acquired, integrated, and appropri- ately interpreted to support decision makers (ranging from emergency- response units to intelligence organizations). Given the range of formats, the permanence and growing volume of information from each source, and the difficulty of accurately analyzing information from single let alone multiple sources, information fusion offers researchers a challenge.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
31INVESTING IN INFORMATION TECHNOLOGY RESEARCH
It must also be noted that although technology is central to all of the areas listed above, it is not the sole element of concern. Research in these areas must be multidisciplinary, involving technologists, social scientists, and domain experts (e.g., the people from the multiple agencies that need to work together during crisis solutions). All technology deployed for operational purposes is subject to the reality of implementation and op- eration by humans. Thus, systems issues, including human, social, and organizational behavior, must be part of the research to develop the needed technology and the system design to implement it. Technology cannot be studied in isolation of the ways in which it is deployed, and failure to attend to the human, political, social, and organizational aspects of solutions will doom technology to failure. For this reason, Section 3.6 addresses social and organizational dimensions that must be incorpo- rated into study in these areas.
To assist decision makers in the formulation of a research program, Table 3.1 presents the committee’s rough assessment of the criticality of the various research areas identified, the difficulty of the research prob- lems, and the likely time scale on which progress could be made. The criticality of a research area reflects an assessment of the vulnerabilities that might be reduced if significant advances in that area were accom- plished and deployed; areas are ranked “High,” “Medium,” or “Low.” How hard it will be to make significant progress is rated “Very Difficult,” “Difficult,” or “Easy.” The time frame for progress is ranked as “1-4 years,” “5-9 years,” or “10+ years.” Of course, the deployment of research results also presents obstacles, which may reduce effectiveness or lengthen the time until a research result can become a reality. It must also be noted that these assessments are both subjective and subject to some debate, as they were intended to provide readers with a quick calibration of these issues rather than a definitive conclusion.
Finally, while R&D is an essential element of the nation’s response to counterterrorism, it is not alone sufficient. Indeed, the history of infor- mation security itself demonstrates that the availability of knowledge or technology about how to prevent certain problems does not necessarily translate into the application of that knowledge or the use of that technol- ogy. It is beyond the scope of this report to address such issues in detail, but policy makers should be cautioned that R&D is only the first step on a long road to widespread deployment and a genuinely stronger and more robust IT infrastructure.
3.1 INFORMATION AND NETWORK SECURITY
A broad overview of some of the history of and major issues in infor- mation and network security is contained in the CSTB report Cybersecurity
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
32 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
TABLE 3.1 A Taxonomy of Priorities
Time Scale for R&D for Significant
Research Progress and Category Criticality Difficulty Deployment
Improved Information and Network Security High Difficult 5-9 years
Detection and identification High Difficult 5-9 years Architecture and design for
containment High Difficult 5-9 years Large system backup and
decontamination High Difficult 5-9 years Less buggy code High Very difficult 5-9 years Automated tools for system
configuration High Difficult 1-4 years Auditing functionality Low Difficult 10+ years Trade-offs between usability
and security Medium Difficult 5-9 years Security metrics Medium Difficult 1-4 years Field studies of security High Easy 1-4 years
C3I for Emergency Response High Difficult 1-4 years Ad hoc interoperability High Easy 1-4 years Emergency deployment of
communications capacity High Easy 1-4 years Security of rapidly deployed
ad hoc networks Medium Difficult 5-9 years Information management
and decision-support tools Medium Difficult 5-9 years Communications with the
public during emergency High Difficult 1-4 years Emergency sensor deployment High Easy 1-4 years Precise location identification Medium Difficult 5-9 years Mapping the physical
telecommunications infrastructure High Easy 1-4 years
Characterizing the functionality of regional networks for emergency responders High Difficult 1-4 years
Information Fusion High Difficult 1-4 years Data mining High Difficult 1-4 years Data integration High Difficult 1-4 years Language technologies High Difficult 1-4 years Image and video processing High Difficult 5-9 years Evidence combination Medium Difficult 1-4 years Interaction and visualization Medium Difficult 1-4 years
Privacy and Confidentiality High Difficult 1-4 years
Planning for the Future Medium Difficult 10+ years
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
33INVESTING IN INFORMATION TECHNOLOGY RESEARCH
Today and Tomorrow: Pay Now or Pay Later.2 That report builds on a variety of earlier, more detailed CSTB studies related to information and network security.
Despite diligent efforts to create effective perimeter defenses, the pen- etration of defended computer and telecommunications systems by a de- termined adversary is highly likely. Software flaws, lax procedures for creating and guarding passwords, compromised insiders, and insecure entry points all lead to the conclusion that watertight perimeters cannot be assumed. Nevertheless, strengthening defensive perimeters is helpful, and this section deals with the methodologies of today and tomorrow that can detect or confine an intruder and, if necessary, aid in recovery from attack by taking corrective action. (Box 3.2 describes some of the funda- mental principles of defensive strategy.)
As noted above, the technology discussed here is relevant for efforts in defensive information warfare and for fighting cybercrime. In addi- tion, many advances in information and network security can improve the reliability and availability of computer systems, which are issues of importance to users even under ordinary, nonthreatening conditions. The fact that such advances have dual purposes could help to generate broader interest and support in R&D in this area, as well as to motivate its incor- poration into industry products.
Research and development in this area should be construed broadly to include R&D on defensive technology (including both underlying tech- nologies and architectural issues), organizational and sociological dimen- sions of such security, forensic and recovery tools, and best policies and practices. Research in information and network security can be grouped in four generic areas: authentication, detection, containment, and recov- ery. A fifth set of topics (e.g., reducing buggy code, dealing with miscon- figured systems, auditing functionality) is broadly applicable to more than one of these areas.
3.1.1 Authentication
A terrorist may seek to gain access to a computer system that he or she is not authorized to use. Once access is gained, many opportunities for causing harm are available, including the installation of hostile pro-
2Computer Science and Telecommunications Board (CSTB), National Research Council (NRC). 2002. Cybersecurity Today and Tomorrow: Pay Now or Pay Later. National Academy Press, Washington, D.C. (hereafter cited as CSTB, NRC, 2002, Cybersecurity Today and To- morrow).
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
34 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 3.2 Principles of Defensive Strategy
Computing and communications systems that contain sensitive information or whose functioning is critical to an enterprise’s mission must be protected at higher levels of security than are adequate for other systems. Several policies should be mandatory for such critical systems:
• The use of encryption for communication between system elements and the use of cryptographic protocols. These practices help to ensure data confidentiality against eavesdroppers and data integrity between major processing elements (e.g., host to host, site to site, element to element); prevent intrusion into the network between nodes (e.g., making “man-in-the-middle” attacks much more difficult); and provide strong authentication (e.g., through the use of public-key-based authentica- tion systems that use encryption and random challenge to strengthen the authentica- tion process or to bind other elements of the authentication, such as biometrics, to the identity of a user).
• Minimal exposure to the Internet, which is inherently insecure. Firewalls provide a minimal level of protection, but they are often bypassed for convenience. (Balancing ease of use and security is an important research area discussed in the main text of this report.) Truly vital systems may require an “air gap” that separates them from public networks. Likewise, communication links that must remain secure and available should use a private network. (From a security perspective, an alterna- tive to a private network may be the use of a connection on a public network that is appropriately secured through encryption. However, depending on the precise char- acteristics of the private network in question, a private network may—or may not— provide higher availability.)
• Strong authentication technology for authenticating users. Security tokens based on encryption (such as smart cards) are available for this purpose, and all entrances from a public data network (such as a network access provider or insecure dial-in) should use them. Furthermore, for highly critical systems, physical security must also be assured.
• Robust configuration control. Such control is needed to ensure that only approved software can run on a system and that all of the security-relevant knobs and switches are correctly set.
Such measures are likely to affect ease of use and convenience, as well as cost. These are prices that must be paid, however, because hardening critical systems will greatly reduce vulnerability to a cyberattack.
grams and the destruction or compromise of important data. In other instances, a terrorist might orchestrate the actions of multiple computers to undertake harmful acts, for example through denial-of-service attacks.3
3Computer Science and Telecommunications Board (CSTB), National Research Council (NRC), 1999, Realizing the Potential of C4I: Fundamental Challenges, National Academy Press, Washington D.C., pp. 144-152 (hereafter cited as CSTB, NRC, 1999, Realizing the Potential of C4I); CSTB, NRC, 1999, Trust in Cyberspace.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
35INVESTING IN INFORMATION TECHNOLOGY RESEARCH
To prevent a terrorist from gaining unauthorized access to a com- puter, it is necessary to prevent that person from successfully posing as an authorized user.4 In other words, an authorized user must pass success- fully through an authentication process that confirms his or her asserted identity as an authorized user. The same is true of computer-to-computer interactions—for some transactions, it is necessary for Computer A to determine if Computer B is one of the computers authorized to interact with it. Here too, a computer-to-computer authentication process is nec- essary so that only individual authorized devices connecting to a network can receive services.
Today, the prevailing method of user authentication is the password. Passwords are easily compromised by the use of weak password-choos- ing techniques, the recording of passwords in open places, the communi- cation channel used for the password entry or administration, and by password-cracking techniques. Requiring several log-in procedures (and usually with different passwords for each) for mapping to permission or authorization techniques makes system administration even more com- plex for the user and the system administrator. Other devices, such as hardware tokens, are usually more secure than are passwords, but a user must have them available when needed.
The ideal authentication system would be a simple, easy-to-use sys- tem that verified identity, could be managed in a distributed manner, had the trustworthiness of cryptographically based systems without today’s complexity, could be scaled to hundreds of thousands (or even millions), and had a cost of ownership that was competitive with passwords. In practice, these desirable attributes often entail trade-offs with one an- other; one way to focus a research effort in authentication would be to address the reduction of these trade-offs.5
3.1.2 Detection
Even with apparently secure authentication processes and technolo- gies, it might still be possible for an intruder to gain unauthorized access to a system, though with more effort if the system were more secure. This possibility suggests a need for detecting and identifying intruders. How-
4The case of a terrorist as an insider who has already been granted access is not within the scope of this particular problem. Insider attacks are addressed in other parts of this report.
5An ongoing CSTB project examines in detail the technologies underlying authentica- tion. See the Web site <http://www.cstb.org> for more information on this subject.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
36 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
ever, intruders are often indistinguishable from valid users and frequently take great care to hide their entry and make their behavior look innocu- ous.
Intrusion-detection systems are designed to monitor users and traffic to detect either anomalous users or unusual traffic patterns that might indicate an active attack. Of course, such monitoring requires good char- acterizations of what “normal” behavior is and knowledge of what vari- ous kinds of behavior mean in the context of specific applications. Today, the major deficiency in this approach is the occurrence of too many false positives. That is, the behavior of legitimate users is sufficiently diverse that some types of legitimate behavior are mischaracterized as anomalous (and hence hostile). Thus, research is needed on reducing the rate of false positives in intrusion-detection systems.
Another approach to intrusion is based on deceiving the cyber- attacker. For example, traps (sometimes referred to as honeypots)—such as apparently interesting files—can be crafted to attract the attention of an intruder so that he or she might spend extra time examining it. That extra time can then be used to provide warning of hostile intent, and it might help in forensic investigation while the hostile party is connected to the system. Alternatively, tools might be created that disguise the actual details of a network when it is probed. Tools of this nature, as well as the development of forensic tools for use in attacker-deceiving environments, may be fruitful areas of research.
A related challenge is the development of intruder-detection methods that scale to function efficiently in large systems. Current approaches to intrusion detection generate enormous amounts of data; higher priority must be given to systems that can analyze rather than merely collect such data, while still retaining collections of essential forensic data. Moreover, the collection and analysis of such large amounts of data may degrade performance to unacceptable levels.
Intrusion-detection systems are also one element of technology that can be used to cope with the threat of insider attack. Because the trusted insider has legitimate access to system resources and information, his or her activities are subject to far less suspicion, which usually allows the insider to act with much greater freedom than would be permitted an outsider who had penetrated the system. Thus, new technologies specifi- cally focused on the possibility of insider attack may be a particularly fruitful avenue of research (Box 3.3). In addition, research focused on understanding common patterns of insider attack (e.g., through the use of application-level audits to examine usage patterns) could be integrated with other kinds of audits to provide a more robust picture of system usage.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
37INVESTING IN INFORMATION TECHNOLOGY RESEARCH
3.1.3 Containment
Today’s systems and networks often fail catastrophically. That is, a successful attack on one part of a system can result in an entire system or network’s being compromised. (For example, the failure of a perimeter defense, such as a firewall, surrounding otherwise unprotected systems can result in an intruder’s gaining full and complete access to all of those systems.) A system that degrades gracefully is more desirable—in this case, a successful attack on one part of a system results only in that part’s
BOX 3.3 Illustrative Technologies for Dealing with the Insider Attack
Authentication, access control, and audit trails are three well-understood tech- nologies that can be used in combating the insider threat. Using these mechanisms to enforce strict accountability can improve protection against the insider threat, but in practice they are often not as successful as they might be. For example, many current tools for access control and audits are difficult to use, or they generate large volumes of data that are, for practical purposes, unreviewable.
Other technology research areas that may be relevant to dealing with insider attack include:
• Attack-specification languages. Programming languages designed for ease of modeling attacks and/or expressing attack behaviors and modalities.
• Modeling and simulation of insider attacks. Better understanding of such attacks to help those seeking to validate technologies to counter the insider threat. Today, simulations of such attacks are difficult to perform and are personnel-inten- sive.
• Authentication of roles, rights, privileges. Approaches to using finer-grained authentication strategies based not on authenticating an individual as an individual but as the holder of certain rights and privileges or embodying a certain role.
• Semantics of authorized access. Development of the semantics of opera- tions and authorization that enable more fine-grained authorization decisions or the flagging of potentially suspect audit trails.
• Automated, dynamic revocation of privileges. Development of effective strategies for the automatic revocation of privileges based on policy-specified factors such as the timing of certain types of access or other user behavior.
• Fingerprinting of documents. Strategies for embedding identifying informa- tion into a document so that its subsequent disposition can be more effectively traced. Such information would be analogous to a copyright notice in a document that can help to determine its origin, except that it would not be easily removable from the document itself.
• Continuous authentication. Technologies for authenticating a user after the initial authentication challenge (to deal with the fact that people walk away from their computers without logging out).
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
38 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
being compromised, and the remainder of the system continues to func- tion almost normally.6
The principle of graceful degradation under attack is well accepted, but system and network design for graceful degradation is not well un- derstood. Nor are tools available to help design systems and networks in such a manner. Even more difficult is the challenge of modifying existing legacy systems to fail gracefully.
In addition, the building blocks of today’s systems are generally com- mercial off-the-shelf components.7 Despite the security limitations of such components, the economics of system development and the speed with which the IT environment changes inevitably require them to be built this way. However, it is not known today how to integrate compo- nents safely, how to contain faults in them, and how to disaggregate them when necessary. While this lack of understanding applies to systems ranging from accounting and payroll systems to telephone switching sys- tems, SCADA systems are a particularly important case.
Architectural containment as a system-design principle calls for the ability to maintain critical functionality (such as engine control on a ship) despite failures in other parts of a system.8 A sophisticated control sys- tem used during “normal operations” must be able to provide basic func- tionality even when parts of it have been damaged.9 Such an approach could be one of the most effective long-term methods for hardening IT targets that oversee critical operations.
For the most part, current approaches to system design involve either the independence of system components (which in modern large-scale systems leads to inefficiencies of operation) or the integration of system components (with the inherent vulnerabilities that this approach entails). Containment essentially navigates between the two extremes; its essential element is the ability to “lock down” a system under attack—perhaps to suspend normal operation temporarily while preserving some basic func- tionality as the system finds and disables potential intruders and to re- sume normal system operation afterward—with less disruption than might be caused by shutting down and rebooting.
Research is thus necessary in several areas: in understanding how to
6CSTB, NRC, 1999, Realizing the Potential of C4I, pp. 144-152. 7CSTB, NRC, 1999, Trust in Cyberspace. 8It should be noted that an essential aspect of designing for containment is the ability to
define and prioritize which functions count as essential. For systems used by multiple constituencies, this ability cannot be taken for granted.
9As an example, a shipboard networking failure on the USS Yorktown left the ship with- out the ability to run its engines. (Gregory Slabodkin. 1998. “Software Glitches Leave Navy Smart Ship Dead in the Water.” Government Computing News, July 13.)
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
39INVESTING IN INFORMATION TECHNOLOGY RESEARCH
fuse a simple, highly secure, basic control system used primarily for op- erations under attack with a sophisticated, highly effective, and optimized control system used for normal operations; in the “decontamination” of a system while it is being used (see Section 3.1.4); and in the resumption of operations without the need for going offline. One “grand challenge” might be the development of a system that could be made more secure at the touch of a button; the cost would be the loss of some nonessential functionality while the system simultaneously decontaminated itself or shut out attackers. A second challenge involves existing systems that need to be examined and restructured. Methods and tools for analyzing systems to identify essential functionality and to restructure those sys- tems to tolerate the loss of nonessential functions could be productively applied to existing designs well before a body of design principles and theories become clear.
A serious problem for which few general solutions are known is the denial-of-service (DOS) attack. For example, consider a DOS attack that is launched against the major Internet news services to coincide with a physical bomb attack on some other target such as a crowded sports stadium. It would be nearly impossible to distinguish legitimate users, who would simply be looking for information, from attackers inundating the news service Web sites to try to prevent access to that information, possibly increasing panic and spreading misinformation. A distributed denial-of-service (DDOS) attack uses many computers to launch attacks against a given target, rendering ineffective the obvious approach of sim- ply cutting off an attacking computer.
One approach to countering a DOS attack calls for authentication so that intruders and bogus traffic can more easily be distinguished. Devel- oping such methods that are both fast and scalable (i.e., effective and fast even when they involve the authentication of large numbers of parties) remains the major challenge in this area, however. (A technique that may be worth further development, at least in the context of authenticating traffic to and from heavily used Web sites, is easy-to-use subscription models.10 ) In any event, research on countering DOS attacks is impor- tant.
Another approach within this general area of containment is the de-
10A subscription model calls for a user to register for service in some authenticated way, so that a site can distinguish that user from a random bad user. Because denial-of-service attacks depend on a flood of bogus requests for service, the availability of a database of registered users makes it easy to discard service requests from requests that are not regis- tered—and those are likely to account for the vast majority of bogus requests. (Of course, there is nothing in this scheme to prevent a registered user from conducting a hostile action, but the number of hostile registered users is likely to be small, allowing counteractions to be taken on an individual basis.)
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
40 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
velopment of broad architectural principles of robust infrastructure for different kinds of applications (e.g., SCADA systems). For example, prin- ciples are needed to guide decisions about the relative robustness of dis- tributed power generation versus centralized power generation in the face of attack.
3.1.4 Recovery
Once an intruder has been detected, confined, and neutralized, the goal becomes recovery—the restoration of a system’s full functional oper- ating capability as soon as possible. As with containment, recovery is highly relevant for reliability, although the presence of a determined ad- versary makes the problem considerably harder. Recovery includes preparations not only to help ensure that a system is recoverable but also to be able to actively reconstitute a good system state.
Backup is an essential prerequisite for reconstitution. Although the basic concepts of system backup are well understood, there are major challenges to performing and maintaining backups in real time so that as little system state as possible is lost. However, normal backup methods have been developed under the assumption of benign and uncorrelated failure, rather than that of a determined attacker who is trying to destroy information. Further, backups of large systems take a long time, and if they are in use during the backup, the system state can change apprecia- bly during that time. Thus, research is needed on ways to preserve infor- mation about system state during backup.
Reconstituting a computer system after an intrusion relies on the use of backup. Unlike a restore operation used to re-create a clean system after a failure, reconstitution requires an additional step: decontamina- tion, which is the process of distinguishing between clean system state (unaffected by an intruder) and the portions of infected system state, and eliminating the causes of those differences. Because system users would prefer that as little good data as possible be discarded, this problem is quite difficult. Decontamination must also remove all active infections, as well as any dormant ones. Once decontamination is performed, attention can be turned to forensics in an attempt to identify the attacker11 and acquire evidence suitable for prosecution or retaliation. In the end, this ability is critical to long-term deterrence.
Given that penetration of computer and telecommunications net- works is likely to continue despite our best efforts to build better perim- eter security, more resilient and robust systems are necessary, with backup and recovery as essential elements.
11CSTB, NRC, 1999, Realizing the Potential of C4I, pp. 144-152.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
41INVESTING IN INFORMATION TECHNOLOGY RESEARCH
12CSTB, NRC, 1991, Computers at Risk; CSTB, NRC, 1999, Trust in Cyberspace. 13Catherine Meadows, 1996, “The NRL Protocol Analyzer: An Overview,” Journal of
Logic Programming, Vol. 26 (2); Dawn Song et al., 2001, “Athena, a Novel Approach to Efficient Automatic Security Protocol Analysis,” Journal of Computer Security, Vol. 9 (1, 2).
New approaches to decontamination are also needed, especially when a system cannot be shut down for decontamination purposes. At present, much of the activity associated with a properly running system interferes with decontamination efforts (particularly with respect to identifying a source of contamination and eliminating it).
3.1.5 Cross-cutting Issues in Information and Network Security Research
A number of issues cut across the basic taxonomy of detection, con- tainment, and recovery described above.
Reducing Buggy Code
Progress in making systems more reliable will almost certainly make them more resistant to deliberate attack as well. But buggy code under- lies many problems related both to reliability and to security, and no attempt to secure systems and networks can succeed if it does not take this basic fact into account.12
Buggy software is largely a result of the fact that, despite many years of serious and productive research in software engineering, the creation of software is still more craft than science-based engineering. Further- more, the progress that has been made is only minimally relevant to the legacy software systems that remain in all infrastructures.
The fact that essentially all software systems contain bugs is not new. Bugs can result from a variety of causes, ranging from low-level errors (e.g., a mathematical expression uses a plus sign when it should use a minus sign) to fundamental design flaws (e.g., the system functions as it was designed to function, but these functions are inappropriate in the circumstances of operation).
Dealing with buggy code is arguably the oldest unsolved problem in computer science, and there is no particular reason to think that it can be solved once and for all by any sort of crash project. Nevertheless, two areas of research seem to be particularly important in a security context:
• Security-oriented tools for system development. More tools that sup- port security-oriented development would be useful.13 For example,
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
42 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
model-checking tools, which have been used successfully for hardware verification, can be used for analyzing designs of security protocols in- cluding authentication protocols14 and electronic commerce protocols;15 static analyzers that have been used successfully for compiler optimiza- tion may be usable to analyze code for information flow properties;16 dynamic analyzers for online monitoring (detection) and reconfiguring (response and recovery) may be used for intrusion detection and foren- sics;17 and theorem-proving tools18 that have been used for proof-carry- ing code19 can be extended to handle more expressive security-specific logics.
• Trustworthy system upgrades and bug fixes. It often happens that a system bug is identified and a fix to repair it is developed. Obviously, repairing the bug may reduce system vulnerability, and so system admin- istrators and users—in principle—have some incentive to install the patch. However, with current technology, the installation of a fix or a system upgrade carries many risks, such as a nontrivial chance of causing other problems, a disruption of existing functionality, or possibly the creation of other security holes, even when the fix is putatively confined to a module that can be reinstalled.20 The essential reason for this problem is
14Gavin Lowe, 1996, “Breaking and Fixing the Needham-Schroeder Public-Key Protocol Using FDR,” in Tools and Algorithms for the Construction and Analysis of Systems, Tiziana Margaria and Bernard Steffen (eds.), Vol. 1055 of Lecture Notes in Computer Science, Springer Verlag; Will Marrero et al., 1997, Model Checking for Security Protocols, Technical Report 97- 139, Department of Computer Science, Carnegie Mellon University, Pittsburgh, Pa., May; J.C. Mitchell et al., 1997, “Automated Analysis of Cryptographic Protocols Using Murphi,” IEEE Symposium on Security and Privacy, Oakland, available online at <http://theory. stanford.edu/people/jcm/papers/murphi-protocols.ps>.
15Nevin Heintze et al., 1996, “Model Checking Electronic Commerce Protocols” (extended abstract), USENIX Workshop on Electronic Commerce; Darrell Kindred and Jeannette M. Wing, 1996, “Fast, Automatic Checking of Security Protocols,” in Proceedings of the USENIX 1996 Workshop on Electronic Commerce, November.
16Andrew C. Myers and Barbara Liskov. 1997. “A Decentralized Model for Information Flow Control,” in Proceedings of the ACM Symposium on Operating System Principles (SOSP ’97). Saint Malo, France, October.
17Giovanni Vigna and Richard A. Kemmerer. 1999. “NetSTAT. A Network-based Intru- sion Detection System.” Journal of Computer Security, Vol. 7 (1).
18Lawrence C. Paulson. 1999. “Proving Security Protocols Correct,” pp. 370-381 in IEEE Symposium on Logic in Computer Science. Trento, Italy. Available online at <http:// www.cl.cam.ac.uk/users/lcp/papers/Auth/lics.pdf>.
19George C. Necula and Peter Lee. 1997. “Proof-Carrying Code,” pp. 106-119 in Proceed- ings of the 24th Annual ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages (POPL). ACM Press, New York, January.
20Frederick P. Brooks. 1975. The Mythical Man-Month. Addison-Wesley, Boston, Mass.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
43INVESTING IN INFORMATION TECHNOLOGY RESEARCH
that although fixes are tested, the number of operational configurations is much larger than the number of test configurations that are possible. Research is thus needed to find ways of testing bug fixes reliably and to develop programming interfaces to modularize programs that cannot be bypassed. An additional dimension of trustworthy upgrades and bug fixes is their installation. If such upgrades and fixes can be developed, their automatic online installation becomes a reasonable desire. Today, some operating systems and programs allow automatic download of such modifications, but it is often the case that they cannot be installed while the system is running. Moreover, in light of the security concerns men- tioned in Section 2.2.6, automatic downloads of bug fixes must be made very highly secure. Research will be needed to solve this problem.21
Misconfigured Systems (Configuration Management)
Because existing permission and policy mechanisms are hard to un- derstand, use, and verify, many system vulnerabilities result from their improper administration.22 There is also a trade-off between fine-grained access control and usability, and both needs are growing. For example, an entire group of people may be given access privileges when only one person in that group should have them. Or, a local system administrator may install a modem on the system he or she administers with the intent of obtaining access from home, but this also provides intruders with an unauthorized access point.
The ability to formulate security policies at the appropriate level, to ensure that policies are consistent across all levels and to state these poli- cies crisply and clearly (e.g., what language is used to express the policy, what mechanisms are used to enforce it, and what is to be done if it is violated) would be helpful. In addition, it will be necessary to develop methods of generating formal descriptions of actual, existing security policies in place and to compare them with desired security policies. Thus, better tools for formulating and specifying security policies and for check- ing system configurations quickly against prespecified configurations should be developed. Better tools for system and network operators to detect added and unauthorized functionality (e.g., the addition of a Tro- jan horse) are also necessary.
21Advances in this area would also have substantial benefit in reducing the workload of system administrators, who today must spend considerable time keeping up with the sheer volume of security patches and assessing the costs and benefits of installing them.
22CSTB, NRC, 1991, Computers at Risk; CSTB, NRC, 1999, Trust in Cyberspace.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
44 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Auditing Functionality
Validation sets are used to ensure that a piece of hardware (e.g., a chip) has the functionality that its design calls for. However, these sets typically test for planned functionality—that is, can the hardware prop- erly perform some specified function? They do not test for unauthorized functionality that might have been improperly inserted, perhaps by some- one seeking to corrupt a production or distribution chain. Similar prob- lems are found in the development of software, especially software sys- tems with many components that are developed by multiple parties. Research is needed for developing tools to ensure that all of the called-for functionality is present and that no additional functionality is present. Research is needed to develop tools that can detect added unauthorized functionality.
Managing Trade-offs Between Functionality and Security
As a general rule, more secure systems are harder to use and have fewer features.23 Conversely, features—such as executable content and remote administration—can introduce unintended vulnerabilities even as they bring operational benefits. (For example, newer word processors allow the embedding of macros into word processing files, a fact that results in a new class of vulnerabilities for users of those programs as well as added convenience.)
One good example of the trade-off between security and usability is the difficulty of establishing an encrypted communications channel using a popular encryption program. One study found that a majority of test- population individuals experienced in the use of e-mail were unable to sign and encrypt a message using PGP 5.0. In a security context, these usability issues go beyond the user-interface design techniques appropri- ate to most other types of software.24
A second example is the buffer overflow problem.25 Over half of the
23CSTB, NRC, 1991, Computers at Risk, pp. 159-160. 24For example, from the user’s perspective, security is secondary to the primary goal of
using the software for some practical purpose. Traditional user-interface design techniques presume that users are motivated to use software for their primary purposes. More discus- sion of this and other relevant issues can be found in Alma Whitten and J.D. Tygar. 1999. “Why Johnny Can’t Encrypt: A Usability Evaluation of PGP 5.0,” Proceedings of the 9th USENIX Security Symposium, August.
25In a buffer overflow, memory is overwritten by an application and control is trans- ferred to rogue code. Type-safe languages allow memory accesses only to specifically authorized locations. For example, programs written in type-safe languages cannot read or write to memory locations that are associated with other programs.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
45INVESTING IN INFORMATION TECHNOLOGY RESEARCH
system and network security vulnerabilities documented by the Com- puter Emergency Response Team (CERT) of the Software Engineering Institute at Carnegie Mellon University throughout CERT’s existence in- volve buffer overflows. These can exploited by an adversary to gain control over a target system. Some ways of preventing buffer overflows are known, but they involve degradations in performance. For example, it is possible for processors to support a programmer-usable capability to designate certain areas of memory as “code” (that cannot be overwritten) versus “data” (that can be overwritten). If this designation is made, buffer overflows cannot result in the transfer of control to rogue code. On the other hand, the extra hardware needed to implement this capability has the effect of slowing down memory access by nontrivial amounts. Java and similar type-safe languages are also more resistant to buffer over- flows than are other languages, but there is overhead in undertaking the check of parameter ranges needed to prevent overflows.
More research is required for performing essential trade-offs between a rich feature set or performance and resistance to attack. Transparent security would be more acceptable to users and hence would be em- ployed more frequently. New authentication mechanisms (or implemen- tations) that combine higher security with lower inconvenience are also needed.
Security Metrics
Many quantitative aspects of security are not well understood. For example, even if a given security measure is installed—and installed prop- erly (something that cannot be assumed in general)—there is no way of knowing the degree to which system security has increased. Threat mod- els are often characterized by actuarial data and probability distributions in which the adverse effects of vulnerabilities are prioritized on the basis of how likely they are to occur; but such models are of little use in coun- tering deliberate terrorist attacks that seek to exploit nominally low-prob- ability vulnerabilities. Notions such as calculating the return on a secu- rity investment—common in other areas in which security is an issue—are not well understood either, thus making quantitative risk management a very difficult enterprise indeed.26 Research is needed for developing meaningful security metrics.
26Information on the economic impact of computer security is available online at <http://www.nist.gov/director/prog-ofc/report02-1.pdf>.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
46 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Intelligence Gathering
Given the rate at which information technology changes, it is likely that new vulnerabilities and new types of attack will emerge rapidly. Because insight into the nature of possible attacks is likely to result in additional options for defense, it is highly desirable to keep abreast of new vulnerabilities and to understand the potential consequences if such vulnerabilities were to be exploited.
Field Studies of Security
Traditional criteria for secure systems, as specified in the “Orange Book,”27 have not been successes. They do not capture current needs or models of computation.28 Worse yet, they have largely failed in the mar- ketplace; very few customers actually bought Orange Book-rated sys- tems, even when they were available.29 Understanding why previous attempts to build secure systems and networks have failed in the market- place, or in defending against outside attack, would help to guide future research efforts. (Further, human and organizational factors are key ele- ments of such analysis, as previously described, and the understanding from such study is likely to be based at least as much on economics, sociology, and anthropology as on technology.30 )
3.2 SYSTEMS FOR EMERGENCY RESPONSE
Technologies for command, control, communications, and intelligence (C3I) have major importance in the response phase of a disaster. In gen- eral, the IT infrastructure for emergency responders must be robust in the
27The “Orange Book” is the nickname for Trusted Computer System Evaluation Criteria— criteria that were intended to guide commercial system production generally and thereby improve the security of systems in use. See U.S. Department of Defense. 1985. Trusted Computer System Evaluation Criteria. Department of Defense 5200.28-STD, “Orange Book.” National Computer Security Center, Fort Meade, Md., December.
28CSTB, NRC, 1999, Realizing the Potential of C4I, pp. 144-152; CSTB, NRC, 1991, Comput- ers at Risk; CSTB, NRC, 1999, Trust in Cyberspace.
29For example, commercial needs for computer security focused largely on data integ- rity, while military needs for security focused on confidentiality, as noted in David Clark and David Wilson, 1987, “A Comparison of Commercial and Military Computer Security Policies,” in Proceedings of the 1987 IEEE Symposium on Security and Privacy, IEEE, Oakland, Calif. Another key failing of the Orange Book approach to security included its omission of networking concerns. For more discussion, see CSTB, NRC, 1999, Trust in Cyberspace.
30See, for example, Donald Mackenzie. 2001. Mechanizing Proof: Computing, Risk, and Trust. MIT Press, Cambridge, Mass.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
47INVESTING IN INFORMATION TECHNOLOGY RESEARCH
face of damage and even potential terrorist attack.31 Although the inci- dent management process has been well studied,32 the IT requirements for such management do not appear to have been thoroughly conceived, even though in a disaster it is essential that IT systems provide for the capability to deliver information, interagency communication and coordi- nation, and communication with those affected both within and beyond the immediate disaster area. In a disaster, equipment must be deployed immediately to provide for appropriate communication to those respond- ing to the situation, and it must be deployed to the multiple agencies in the private and public sectors that are affected, and to and between those directly affected by the incident.33
The committee believes that research in a number of areas, described below, can advance the state of the art for C3I systems for emergency response (and provide collateral benefits for the responses to more com- mon natural disasters as well).
3.2.1 Intra- and Interoperability
The C3I systems of emergency-response agencies must support both intra-agency and interagency communications. But many disasters (whether natural or attack-related) reveal technological shortcomings in a given agency’s C3I systems as vital communications are lost or never heard. And, although the public rhetoric of every emergency-response agency acknowledges the need for cooperation with other agencies, al- most every actual disaster reveals shortcomings in the extent and nature of interagency cooperation.
Perhaps the most basic requirement for an agency’s C3I systems is that they reliably support communications among the personnel of that agency. The C3I systems of most emergency responders today are based on analog radio technology. Although digital and analog communica-
31Computer Science and Telecommunications Board (CSTB), National Research Council (NRC). 1999. Information Technology Research for Crisis Management. National Academy Press, Washington, D.C., p. 39 (hereafter cited as CSTB, NRC, 1999, Information Technology Research for Crisis Management).
32Hank Christen, Paul Maniscalco, Alan Vickery, and Frances Winslow. 2001. “An Over- view of Incident Management.” Perspectives on Preparedness, No. 4, September. Available online at <http://ksgnotes1.harvard.edu/BCSIA/Library.nsf/pubs/POP4>. Accessed No- vember 14, 2002.
33Computer Science and Telecommunications Board (CSTB), National Research Council (NRC). 1996. Computing and Communications in the Extreme: Research for Crisis Management and Other Applications. National Academy Press, Washington, D.C., p. 14 (hereafter cited as CSTB, NRC, 1996, Computing and Communications in the Extreme).
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
48 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
tions systems have advantages and disadvantages (Box 3.4), the disad- vantages of analog communications for emergency responders are con- siderable in the context of large-scale disasters or incidents.
For most routine work, the mostly-analog systems deployed today function adequately to keep personnel in contact with one another. And, because routine work is mostly what response agencies do, the motiva- tion for acquiring new systems is low. Even when new procurements are considered, the needs highest on an agency’s list of priorities are most likely to be those that focus on enhancing its ability to do its everyday work more effectively.
Nevertheless, disasters increase the demand for communications among emergency responders dramatically, and the capacity limitations of analog systems become more apparent. In addition, large-scale disas- ters may affect telecommunications facilities. For example, antennas sup- porting the communications systems of the Fire Department of New York, the New York Police Department, and the Emergency Medical System (EMS) were based on the roof of Building 1 of the World Trade Center, which collapsed soon after the strike.34
Inadequacies in the deployed base of C3I systems for emergency re- sponders cannot be fixed merely by adding more channels. Though emer- gency planning often results in the allocation of additional channels, these channels ease the problem only temporarily. In addition, extra channels require more bandwidth, and hence a broader radio spectrum dedicated to public service communication, even though radio spectrum is a limited resource. More efficient use of spectrum can be obtained by using digital communications systems, which offer additional advantages as well (Box 3.4), such as greater noise immunity and higher security against eaves- dropping (especially with encryption). However, one major impediment to the acquisition of such systems is inadequate funding. Funding needs are further exacerbated by the difficulty of acquiring new digital systems that preserve backwards compatibility with existing legacy analog sys- tems. (In New York City, the Fire Department relied on radios that were at least 8 years old and in some cases 15 years old, and a senior Fire Department official reported that “there [are] problems with the radios at virtually every high-rise fire.”35 )
34Ronald Simon and Sheldon Teperman. 2001. “Lessons for Disaster Management.” Criti- cal Care, Vol. 5:318-320. Available online at <http://www.disasterrelief.org/Disasters/ 011115wtclessons/>.
35Jim Dwyer, Kevin Flynn, and Ford Fessenden. 2002. “9/11 Exposed Deadly Flaws in Rescue Plan.” New York Times, July 7. Available online at <http://www.nytimes.com/
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
49INVESTING IN INFORMATION TECHNOLOGY RESEARCH
BOX 3.4 A Comparison of Digital and Analog Wireless Communications Technologies
Advantages of Digital Communications1
• Digital communications provide higher fidelity and lower susceptibility to interference and static compared with analog communications.
• Digital communications are more inherently secure than analog communi- cations are, and more easily encrypted as well.
• Channels (frequencies) can be shared between users, thus increasing the number of supportable users per channel.
• Because channels can be shared, multiple users can speak simultaneously on a single frequency, thus increasing the amount of information that can be ex- changed.
Advantages of Analog Communications
• Analog communications devices are easier to make interoperable because it is only necessary to match the frequencies of communicating wireless sets, whereas digital systems require the additional step of matching their communications proto- cols.
• Problems in analog communications devices are often easier to diagnose, and communications problems in analog systems are often easier to work around than are those in digital systems.
• The number of technicians and users trained in the use of analog systems is larger.
• Analog communications offer better graceful degradation than that offered by digital systems in the presence of noise as signal-to-noise ratios drop, and they offer better warning to users (through the tone of the communications carried) when they are near the margins of usability.
• Low-frequency transmissions, which are better suited for analog communi- cations than for digital communications, are less subject to line-of-sight restrictions and thus have a higher likelihood of penetrating most walls and bypassing debris.
1Viktor Mayer-Schönberger. 2002. Emergency Communications: The Quest for Interoper- ability in the United States and Europe. BCSIA Discussion Paper 2002-7. John F. Kennedy School of Government, Harvard University, Cambridge, Mass., March.
2002/07/07/nyregion/07EMER.html?pagewanted=1>. Also according to this article, the New York Fire Department had replaced at least some of its analog radios in early 2001 with digital technology better able to transmit into buildings; but after a few months, these new radios were pulled from service because several firefighters said they had been unable to communicate in emergencies. It is not clear whether or not a full “head-to-head” sys- tematic comparison between the analog and digital systems was ever undertaken.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
50 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Interoperability is a broad and complex subject rather than a binary attribute of systems, and it is important to distinguish between inter- operability at the operational and technical levels.36 Operational inter- operability refers to the ability of different operating agencies (e.g., police, fire, rescue, utilities) to provide information services to and accept infor- mation services from other agencies and to use these services in support of their operational goals. Thus, the dimensions of operational inter- operability go beyond IT systems to include people and procedures, inter- acting on an end-to-end basis. By contrast, technical interoperability re- fers to the ability of IT systems to exchange information or services directly and satisfactorily between them and/or their users. Technical interoper- ability involves the ability to exchange relevant bitstreams of information and to interpret the exchanged bits according to consistent definitions— merely providing information in digital form does not necessarily mean that it can be readily shared between IT systems.
Furthermore, numerous computational and database facilities must be established to provide complete and real-time information37 to diverse constituencies whose information and communication requirements, se- curity needs, and authorizations all differ. These facilities must be estab- lished quickly in disaster situations, as minutes and even seconds matter in the urgent, early stages of an incident.38 Furthermore, tight security is essential, especially if the incident is the result of a terrorist attack, be- cause an active adversary might try to subvert the communications or destroy data integrity.39 In addition, an atmosphere of crisis and emer- gency provides opportunities for hostile elements to overcome security measures that are normally operative under nonemergency circum- stances. Thus, another research area is how to build systems that permit security exceptions to be declared without introducing new vulnerabili- ties on a large scale.40
36An extended discussion of interoperability, though in a military context, is provided in CSTB, NRC, 1999, Realizing the Potential of C4I.
37CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 29. 38CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 83; CSTB,
NRC, 1996, Computing and Communications in the Extreme, p. 12. 39CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 24. 40For example, in a crisis, emergency responders may need to identify all of the individu-
als working at a specific company location, and tax records might well be one source of data to construct such a list. However, while names and home addresses may be relevant, income is almost certainly not relevant. Technology that enables controlled release under exceptional circumstances and a means to discern when an “exception state” exists would be helpful for such scenarios, although implementations that simply weaken access control policies in an emergency are highly vulnerable to improper compromise through social
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
51INVESTING IN INFORMATION TECHNOLOGY RESEARCH
Efforts to coordinate communications are complicated by the fact that emergency response to a large-scale incident has many dimensions, in- cluding direct “on-the-ground” action and response, management of the incident response team, operations, logistics, planning, and even admin- istration and finance. Moreover, response teams are likely to include personnel from local, county, state, and federal levels.41
Poor interoperability among responding agencies is a well-known problem (see, for example, Box 3.5)—and one that is as much social and organizational as it is technical.42 The fundamental technical issue is that different agencies have different systems, different frequencies and wave- forms, different protocols, different databases, and different equipment.43 (Box 3.6 addresses some of the impediments to interoperability.) More- over, existing interoperability solutions are ad hoc and do not scale well.44 The nature of agencies’ missions and the political climates in which they traditionally operate make it even harder for them to change their com- munication methods. Thus, it is unlikely that agencies will ever be strongly motivated to deploy interoperable IT systems. Efforts to solve problems of interagency cooperation by fiat are likely to fail to achieve their goal unless they address interagency rivalries and political infight- ing about control and autonomy. Efforts to achieve interoperability some- how must work within this reality of organizational resistance (as dis- cussed further in Section 3.6.3).45
For practical purposes, these comments suggest that when large, multiagency responses are called for, the individual “come-as-you-are” communications systems will eventually have to be transitioned to an interoperable structure that supports all agencies involved—and transitioned with minimal disruption of function during that transfer.46 This complex problem has technological and social dimensions—the tech-
engineering (see Section 3.6.1). By contrast, there are fewer risks of abuse (but also less flexibility) in implementations that are based on a formal declaration of emergency or a particular threat condition rather than on a conversation persuading an operator that such a situation exists. For more discussion, see Computer Science and Telecommunications Board (CSTB), National Research Council (NRC), 2002, Information Technology Research, Innovation, and E-Government, National Academy Press, Washington, D.C. (hereafter cited as CSTB, NRC, 2002, Information Technology Research, Innovation, and E-Government).
41CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 7. 42See for example, Viktor Mayer-Schönberger, 2002, Emergency Communications: The Quest
for Interoperability in the United States and Europe, BCSIA Discussion Paper 2002-7, John F. Kennedy School of Government, Harvard University, Cambridge, Mass., March.
43CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 26. 44CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 119. 45CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 27. 46CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 26.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
52 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 3.5 Examples of Interoperability Difficulties Among Emergency Responders
Columbine High School
In April 1999, two 16-year-old students entered Columbine High School in Littleton, Colorado, and started a shooting spree that left 15 people dead and dozens of others wounded.1 Within minutes of the first shootings, local police, paramedics, and firefighters arrived at the scene. Over the next several hours, they were joined by almost 1,000 law-enforcement personnel and emergency responders. These re- sponders included police forces from 6 sheriff’s offices and 20 area police depart- ments, 46 ambulances and 2 helicopters from 12 fire and emergency medical service agencies, as well as personnel from a number of state and federal agencies. Howev- er, there was no communication system that would permit the different agencies to communicate with one another, and thus coordination became a serious problem. Agencies used their own radio systems, which were incompatible with other sys- tems. With more and more agencies arriving on the scene, even the few pragmatic ways of communication that had been established, such as sharing radios, deteriorat- ed rapidly. Cellular phones offered no alternative, as hundreds of journalists rushed to their phones and overloaded the phone network. Within the first hour of the oper- ation, the Jefferson County dispatch center lost access to the local command post because of jammed radio links. Steve Davis, public information officer of the Jeffer- son County Sheriff’s Office, later commented that “[r]adios and cell[ular] phones and everything else were absolutely useless, as they were so overwhelmed with the amount of traffic in the air.”2
nologies of different responders must not interfere with one another’s operation, and the systems into which these technologies are integrated must be designed so that they complement the users rather than distract them from their missions.47
One important area of research is in defining low-level communica- tion protocols and developing generic technology that can facilitate inter- connection and interoperation of diverse information resources.48 For example, software-programmable waveforms can (in principle) allow a single radio to interoperate with a variety of wireless communications protocols; research in this area has gone forward, but further research is needed.49 A second example is an architecture for communications, per-
47CSTB, NRC, 1999, Information Technology Research for Crisis Management, pp. 50, 84; Computing and Communications in the Extreme, p. 33.
48CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 85. 49Computer Science and Telecommunications Board, National Research Council. 1997.
The Evolution of Untethered Communications. National Academy Press, Washington, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
53INVESTING IN INFORMATION TECHNOLOGY RESEARCH
haps for selected mission areas, that translates agency-specific informa- tion into formats and semantics compatible with a global system.50 More generally, “translation” technology can be developed to facilitate inter- operable communications among emergency responders (e.g., technol- ogy that facilitates interoperability between disparate communications or database systems).
Note also that new technical approaches are not the only option for helping to facilitate interoperable crisis communications. For example, it is likely that some portion of the public networks would survive any disaster; emergency-response agencies could use that portion to facilitate
World Trade Center
On the morning of September 11, 2001, a few minutes after the South Tower of the World Trade Center had collapsed, police helicopters inspecting the North Tow- er reported that “about 15 floors down from the top, it looks like it’s glowing red” and that collapse was “inevitable.” A few seconds later, another pilot reported, “I don’t think this has too much longer to go. I would evacuate all people within the area of that second building.” Transmitted 21 minutes before the North Tower fell, these messages were relayed to police officers, most of whom managed to escape. How- ever, most firefighters in the North Tower never heard those warnings, nor did they hear earlier orders to get out, and the New York Times estimated that at least 121 firefighters were in the tower when it collapsed. The Fire Department radio system had proven unreliable that morning, and it was not linked to the police radio system. Moreover, the police and fire commanders on the scene had only minimal interac- tions to coordinate strategy or to share information about building conditions.
SOURCE (Columbine): Adapted from Viktor Mayer-Schönberger. 2002. Emergency Com- munications: The Quest for Interoperability in the United States and Europe. BCSIA Discussion Paper 2002-7. John F. Kennedy School of Government, Harvard University, Cambridge, Mass., March. (World Trade Center): Adapted from Jim Dwyer, Kevin Flynn, and Ford Fessenden. 2002. “9/11 Exposed Deadly Flaws in Rescue Plan.” New York Times, July 7. Available online at <http://www.nytimes.com/2002/07/07/nyregion/07EMER.html?pagewanted=1>.
1The description and analysis of the Columbine High School incident is based on two John F. Kennedy School of Government cases: “The Shootings at Columbine High School: Responding to a New Kind of Terrorism,” Case No. C16-01-1612.0, and “The Shootings at Columbine High School: Responding to a New Kind of Terrorism Sequel,” Case No. C16-01-1612.1.
2Id, at 16.
50CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 17; CSTB, NRC, 1999, Information Technology Research for Crisis Management. An additional discussion of mission slices and working the semantic interoperability problem appears in CSTB, NRC, 1999, Realizing the Potential of C4I.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
54 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 3.6 Why Interoperability Is Difficult
Interoperability is difficult in an emergency-responder context for many rea- sons. Among them are the following:
• A lack of common operating frequencies. For historical reasons, various public service agencies, from law enforcement to firefighters to emergency medical services have traditionally used different frequency bands for their radio communi- cations.1 Thus, different agencies using different radio systems have generally resort- ed to sharing or carrying radios from other agencies to facilitate interoperability—an obviously clumsy solution.
• Inadequacies of analog radio technology used for emergency commmunica- tions. Today’s emergency communications are largely based on analog technology. Though analog technologies have some advantages for emergency responders, such as greater robustness in the presence of clutter and freedom from line-of-sight restric- tions (see Box 3.4), they are generally unable to handle the enormous traffic volume that characterizes severe incidents.
• Independence of the procuring agencies. As a general rule, response agen- cies acquire IT systems independently, with little coordination of objectives or requirements, whereas optimizing overall system performance requires a full under- standing of the trade-offs entailed by different choices. Individual agencies, espe- cially those that seldom interact with other units, are strongly motivated to solve their own pressing problems, even if doing so makes it harder for them to interact with other units.
• Inability to anticipate all relevant scenarios for use. It is difficult to anticipate in detail how information systems will be used—a difficulty that is multiplied in an uncertain environment. For example, the responders to a large-scale terrorist attack are likely to include agencies that have not worked together in the past. Achieving flexibility in such a situation depends heavily on building in a sufficient degree of interoperability, and yet if a given scenario has not been anticipated, the would-be responders may have no particular idea about who they will need to work with.
• Inclusion of legacy systems. Legacy systems are in-place systems that are relatively old and were not designed to be easily integrated with current and future information systems, but which remain absolutely essential to the functioning of an organization. Furthermore, they often represent significant investment, so replacing them with new, more interoperable systems is not a near-term option. Today, these legacy systems include the vast installed base of conventional analog radio equip- ment used by most emergency-response agencies.
SOURCES: For the first bullet item above, Viktor Mayer-Schönberger, 2002, Emergency Communications: The Quest for Interoperability in the United States and Europe, BCSIA Discus- sion Paper 2002-7, John F. Kennedy School of Government, Harvard University, Cambridge, Mass., March; for second item, Box 3.4 in this report; for third through fifth items, Computer Science and Telecommunications Board, National Research Council, 1999, Realizing the Poten- tial of C4I, National Academy Press, Washington D.C.
1The Federal Communications Commission allocates 13 discrete portions of spectrum for public safety operations but does not specify the types of public safety agencies that are required to use each portion; see Public Safety Wireless Network,1999, Spectrum Issues and Analysis Report.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
55INVESTING IN INFORMATION TECHNOLOGY RESEARCH
interoperability if there were mechanisms for giving them first priority for such use. A second option would be to allocate dedicated spectrum bands for emergency responders and to require by law that they use those frequencies. (This option is likely to be undesirable under most circum- stances, because for routine work a high degree of interoperability is not required, and sharing frequencies might well interfere with such work.) A third option would be to mandate frequency and waveform standards for emergency responders so that they are interoperable. These policy options are not mutually exclusive, and all might benefit from technolo- gies described above.
3.2.2 Emergency Deployment of Communications Capacity
In an emergency, extraordinary demands on communications capac- ity emerge. A disaster (or an attack on the communications of emergency responders in conjunction with a physical attack) is likely to destroy some but not all of the communications infrastructure in a given area, leaving some residual capability. Meanwhile, the disaster provokes greater de- mands for communication from the general public. The result is often a denial-of-service condition for all, including emergency communications services. The absence of telephone dial tone in a disaster area is common because of increased demands.51 Even under high-traffic but nonemer- gency situations, cell-phone networks are sometimes unable to handle the volume of users in a given cell because of statistical fluctuations in call volume, leaving some users without the ability to connect to the network. Nor is the Internet immune to such problems—congestion of shared Internet links, including both last-mile and aggregated feeder links, can cause greatly slowed traffic to occur on facilities that are still operational in a disaster area. Note also that today, the Internet provides modes of communication—e-mail and Web-based information services—that are different from that provided by voice communications.
Given the vastly increased demands for wireless communications that accompany any disaster, efficient spectrum management is essential. One important issue here is the fact that emergency bands need to be kept clear of nonemergency transmissions. However, certain types of nonstandardized but sometimes-deployed higher-speed DSL (digital sub- scriber line) telecommunications equipment are known to radiate in these bands at unacceptable levels of power, and such equipment can interfere
51CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 17.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
56 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
with all emergency transmissions and receptions within 50 yards of the offending telephone lines.52
In addition, it may be possible to improve the use of available spec- trum in a disaster area through the use of processing and portable hard- ware (network equipment or antennas carried by truck into area) that would nominally exceed cost constraints for general deployment. Such equipment ranges from truck-portable cellular stations to antennas us- able for receiving and rebroadcasting degraded emergency-band commu- nications. Vector signal processing of signals from multiple antennas deployed rapidly and ubiquitously can increase available spectrum by an order of magnitude or more. Fast reconnection to high-performance equipment can also greatly increase the amount of information flow to and from affected areas.
Research is needed on using residual (and likely saturated) capacity more effectively, deploying additional (“surge”) capacity,53 and perform- ing the trade-offs among different alternatives. One problem in this area is the management of traffic congestion and the development of priority overrides for emergency usage (and prevention of the abuse of such au- thority).54 For example, the capacity of DSL links could be significantly increased through coordination across neighboring telephone lines (band- width increases of an order of magnitude are sometimes possible). Under normal circumstances, signals transmitted by other users result in cross-
52The specific type of equipment is known as “single-carrier VDSL (very high data rate digital subscriber line).” It is sold by several vendors, despite some local exchange carriers reporting that it interferes with the reception of any amateur radio receiver (which is the same type used in emergencies) within at least 30 meters of an aerial telephone line. At least one local exchange carrier is known to have deployed it in a VDSL trial in Phoenix, Arizona, despite its violation of the radio interference requirements. (John Cioffi, Stanford University, personal communication, July 9, 2002.)
53CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 83. 54CSTB, NRC, 1999, Information Technology Research for Crisis Management, pp. 39, 52;
CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 20. In addition, the White House’s National Communications System (NCS) office has moved to implement a wireless priority service that facilitates emergency-recovery operations for the government and local emergency-service providers. This service will be implemented in phases, with an immediate solution available in early 2002 in selected metropolitan areas and a nation- wide solution (yet to be developed) scheduled for late 2003. Further work after 2003 will concentrate on the development and implementation of “third-generation” technologies that enable high-speed wireless data services. See Convergence Working Group. 2002. Report on the Impact of Network Convergence on NS/EP Telecommunications: Findings and Rec- ommendations. February.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
57INVESTING IN INFORMATION TECHNOLOGY RESEARCH
talk that limits available bandwidth, but in an emergency those interests could be reprioritized.55
A second problem is that optimization algorithms for communica- tions traffic that are appropriate in normal times may have to be altered during emergencies. For example, the destruction of physical facilities such as repeaters and the massive presence of debris could result in an impaired environment for radio transmissions. The rapid deployment of processors optimized to find weak signals in a suddenly noisier environ- ment could do much to facilitate emergency communications.
Research is also needed to develop self-adaptive networks that can reconfigure themselves in response to damages and changes in demand, and that can degrade gracefully.56 For example, in a congested environ- ment, programmed fallback to less data-intensive applications (e.g., voice rather than video, text messaging rather than voice) may provide a mini- mal communications facility. Even today, many cellular networks allow the passing of text messages. Also, both public and private elements of communications infrastructure could be tapped to provide connectivity in a crisis, as happened in New York City on September 11.57
3.2.3 Security of Rapidly Deployed Ad Hoc Networks
The management of communications networks poses unique prob- lems in the crowded emergency disaster zone. Security must be estab- lished rapidly from the outset, as terrorists might try to infiltrate as emer- gency agencies responded.58 It is also necessary to determine a means for temporarily suspending people’s access to facilities, communications, and data without impeding the ability of those with legitimate need to use them. But this suspension process has to be done rapidly, given that minutes and seconds matter in severe emergencies. Note also that large deployments may well pose security problems that are more severe than those posed by smaller deployments.
55Actions that disadvantage commercial consumers in times of emergency have some precedent. Of particular relevance is the Civil Reserve Air Fleet program of the DOD, under which priority use of commercial airliners is given to the Defense Department in times of national emergency. (Because ordinary airliners lack the strong floors needed to support heavy military equipment, the floors are strengthened at government expense, and the government pays the incremental fuel costs of carrying that excess weight.)
56CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 39. 57CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 39. 58CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 24. Embedded, Every-
where (CSTB, NRC, 2001) also discusses security issues associated with ad hoc networks, though in the context of sensor networks rather than communications networks for human beings.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
58 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Research is therefore needed on the special security needs of wireless networks that are deployed rapidly and in an ad hoc manner. (For ex- ample, ad hoc networks are not likely to have a single system administra- tor who can take responsibility for allocating user IDs.)
3.2.4 Information Management and Decision-Support Tools
Emergency responders have multiple information needs that technol- ogy can support.59 For example, a multimedia terminal for a firefighter could have many uses: 60 accessing maps and planning routes to a fire, examining building blueprints for tactical planning, accessing databases locating local fire hydrants and nearby fire hazards such as chemical plants, communicating with and displaying the locations of other fire and rescue teams, and providing a location signal to a central headquarters so that a firefighting team can be tracked for broader operational planning. Note that only some of this data can be pre-stored on the terminal, espe- cially because some data may have to be updated during an operation, so real-time access to appropriate data sources is necessary. Moreover, these different applications require different data rates and entail different trade-offs between latency and freedom from transmission errors. Voice communications, for example, must have low latency (i.e., be real time) but can tolerate noisy signals, whereas waiting a few seconds to receive a map or blueprint will generally be tolerable, though errors may make it unusable. Some applications, such as voice conversation, require sym- metrical bandwidth; others, such as data access and location signaling, are primarily one-way (the former toward the mobile device, the latter away from it).
Another issue arises because disasters create huge volumes of infor- mation to be handled. A large volume of voice and data traffic will be transmitted and received on handheld radios, phones, digital devices, and portable computers. Large amounts of additional information will be available from various sources including the World Wide Web, building blueprints, and interviews with eyewitnesses. However, sorting out reli- able and useful information from this vast array of sources is inevitably difficult, and many crisis responders have adopted a rule of thumb about such information: one-third of the information is accurate, one-third is
59This discussion is taken from CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 59.
60Randy H. Katz. 1995. “Adaptation and Mobility in Wireless Information Systems.” Unpublished paper, available online at <http://daedalus.cs.berkeley.edu>. August 18.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
59INVESTING IN INFORMATION TECHNOLOGY RESEARCH
wrong, and one-third might be either right or wrong.61 Such inaccuracies further compound the difficulties of integrating such data.
Thus, emergency-response managers need tools that can draw on information from diverse and unanticipated sources to assist them in evaluating, filtering, and integrating information and in making decisions based on incomplete knowledge of conditions, capabilities, and needs.62 Such tools would interpret information about the quality and reliability of varied inputs and assist the user in taking these variations into account. These tools would differ from, but could build upon, traditional decision- support tools such as knowledge-based systems, which operate using rules associated with previously examined problems. Because many of the problems raised by crisis management are not known ahead of time, more general techniques are needed. These might include the develop- ment of new representations of the quality of inputs (such as metadata about those inputs regarding qualities such as reliability and uncertainty in the data), data fusion, models of information representation and inte- gration (e.g., integrating pre-existing disaster response plans with deci- sion-support tools), rapidly reconfigurable knowledge-based systems, and new techniques for filtering and presenting information to users and for quickly prioritizing tasks. Section 3.3 addresses some of these issues in a broader context.
3.2.5 Communications with the Public During an Emergency
In a crisis, channels to provide information to the public are clearly needed. Radio, television, and often the Web provide crisis information today, but such information is usually generic and not necessarily helpful to people in specific areas or with specific needs. Information tailored to specific individuals or locations through location-based services (and per- haps simple response systems to ascertain the location of the injured and to identify critical time-urgent needs) could be put to more effective use.
Research is needed to identify appropriate mechanisms—new tech- nologies such as “call by location” and zoned alert broadcasts—for tailor- ing information to specific locations or individuals.63 To enable effective interaction with individual users, ubiquitous and low-cost access is re-
61CSTB, NRC, 1999, Information Technology Research for Crisis Management, Appendix B. 62CSTB, NRC, 1996, Computing and Communications in the Extreme, National Academy
Press, Washington, D.C., p. 104; CSTB, NRC, 1999, Information Technology Research for Crisis Management, pp. 32-33.
63CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 35.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
60 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
quired.64 In addition, such systems should be highly robust against spoof- ing (entry by an intruder masquerading as a trusted party) so that only authorized parties can use the systems to send out information.
For example, the current cell-phone system does not directly support these functions, but it might be possible to modify and exploit it to pro- vide “reverse 911” service,65 that is, a one-way channel to people affected by the crisis that provides a flow of relevant information and guidance. Such mechanisms would probably have to be locally sufficient. That is, the disaster might spare the local cell site—or a temporary cell site could be deployed along with wireless alternatives66—but access to central ser- vices might not be possible.
Finally, providing information to those located outside the immedi- ate emergency area provides important psychological comfort and helps to mitigate a disaster’s consequences. (For example, in the immediate aftermath of the September 11 attacks, “I’m alive” Internet bulletin boards sprang up spontaneously.) Research is needed for establishing more ef- fective means of achieving this objective—especially in updating the sta- tus of affected people—while compromising the local communications infrastructure to a minimal degree.
3.2.6 Emergency Sensor Deployment
During an emergency, responders need information about physical on-the-ground conditions that is sufficiently fine-grained and accurate to be useful. However, existing sensor networks may be disrupted or de- stroyed to some extent—and it is important to be able to recognize an attack on a sensor network and to monitor the state of the network’s health so that emergency responders have an idea of the extent to which they can continue relying on the information provided by the network. When the surviving sensor capability cannot provide adequate informa- tion, the deployment of additional sensors is likely to be necessary. De- pending on the nature of the emergency, sensor capacity would be needed to identify and track the spread of nuclear, chemical, or biological con- taminants, characterize and track vehicular traffic, locate survivors (e.g., through heat emanations, sounds, or smells), and find pathways through debris and rubble. Developing robust sensors for these capabilities is one major challenge; developing architectural concepts for how to deploy them and integrate the resulting information is another.67
64CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 40. 65CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 35. 66CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 18. 67CSTB, NRC, 2001, Embedded, Everywhere.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
61INVESTING IN INFORMATION TECHNOLOGY RESEARCH
3.2.7 Precise Location Identification
When extensive physical damage to a structure or an area occurs, determining the location of physical structures and of people is a major problem. One reason is that many reference points for observers on the ground or in the structure may become unavailable: debris, airborne con- taminants such as smoke and dust, and perhaps simply the lack of illumi- nation can reduce visibility, and street signs may disappear. Also, the physical environment changes to some extent as a result of physical dam- age: fires destroy rooms in buildings, one floor collapses into another, a crater exists where there used to be three buildings.
Thus, technology must be available to help establish reference points when existing ones are destroyed or inadequate. In an open physical environment, location finders based on the Global Positioning System (GPS) serve a useful role, but airborne contaminants, equipment damage, and line-of-sight restrictions could adversely affect the reliability of GPS, and research is needed on ways to determine location in a disaster envi- ronment. Embedded location sensors and sensor networks, either al- ready in place or deployed in response to an incident, are likely to be valuable information sources.68
Responders and victims also require rapid access to accurate loca- tional databases. One such source is pre-existing building blueprints and diagrams.69 Where these do not exist, or where the structures themselves have suffered significant physical damage, on-the-spot mapping will in- evitably be needed. Thus, research is needed to develop digital floor plans and maps of other physical infrastructure.70 The resulting data could be stored in geospatial information systems (GIS), which would allow responders to focus on the high-probability locations of missing people (such as lunchrooms), and avoid dangerous searches of low-prob- ability locations (such as storage areas).71 Research is needed in wearable computers for search-and-rescue operations72 so that responders could update the GIS in real time as they discover victims and encounter infra-
68CSTB, NRC, 1996, Computing and Communications in the Extreme, pp. 24, 25; CSTB, NRC, 2001, Embedded, Everywhere.
69J. Hightower and G. Boriello. 2001. “Location Systems for Ubiquitous Computing.” IEEE Computer, Vol. 33 (8).
70As one example, consider that a firm that installs fiber-optic cables in a city’s sewers is capable of mapping those sewers as well using a sewer-crawling robot that lays cable and tracks its position.
71CSTB, NRC, 1996, Computing and Communications in the Extreme, p. 14. 72CSTB, NRC, 1999, Information Technology Research for Crisis Management, p. 38.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
62 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
structural damage. Another research area is in “map ants”73 —distrib- uted, self-organizing robots deployed in a disaster area to sense move- ment or body heat, for instance. It may also be possible to develop tech- nology to generate the data for accurate maps of a debris-strewn disaster location.
Finally, keeping track of emergency responders’ positions within a disaster area is an essential element of managing emergency response. Technology (similar to E-911 for cell phones) to monitor the progress of these individuals automatically is not yet available on a broad scale.
3.2.8 Mapping the Physical Aspects of the Telecommunications Infrastructure
As noted in Section 2.2.2, the telecommunications infrastructure is for the most part densely connected; hence physical attack is unlikely to dis- rupt it extensively for long periods of time. However, the physical infra- structure of telecommunications (and the Internet) does not appear to be well understood (that is, immediate knowledge of where various circuits are located is in many cases available only in a disaggregated form dis- tributed throughout a myriad of company databases), and there may well exist critical nodes whose destruction would have disproportionate im- pact. (On the other hand, knowing where these critical nodes are is diffi- cult for both network operators and terrorists.) Thus, an important prior- ity is to develop tools to facilitate the physical mapping of network topology, and to begin that mapping with the tools that are available today. This is particularly important for the many converged networks over which both voice and data are carried.
3.2.9 Characterizing the Functionality of Regional Networks for Emergency Responders
In order to develop mechanisms for coordinating emergency-response activities, it is necessary to understand what the various communications and computer networks of emergency responders in a given region are supposed to do. For example, managers from different agencies often speak different “languages” in describing their needs, capabilities, and operational priorities; a common conceptual framework for these pur- poses would be enormously helpful for the coordination of planning ac-
73A study in progress by the Computer Science and Telecommunications Board on the intersections between geospatial information and information technology discusses these self-organizing robots. See <http://www.cstb.org> for more information on this study.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
63INVESTING IN INFORMATION TECHNOLOGY RESEARCH
tivities, yet one is not available.74 Sharing of information among the vari- ous providers of critical infrastructure and emergency-response agencies, even about common tasks and processes, has been a rather uncommon activity in the past.
An additional and challenging problem is that severe emergencies often change what different agencies are expected to do and what priori- ties their duties have. For example, existing plans are often overridden by circumstances (e.g., in the aftermath of the September 11 attacks, phone services to the financial district in Wall Street were given priority; this eventuality had not been anticipated in prior emergency planning). More- over, even if existing plans do not require alteration, emergency agencies must know and be able to execute on what those plans contain. (For example, the notebook containing personnel assignments in a certain type of emergency must be available and easily found.) For this reason, drills and exercises are necessary, and they must involve enough personnel that in a real emergency, some people with drill experience will be participat- ing in actual response operations.
3.3 INFORMATION FUSION
As discussed below, information fusion promises to play a central role in the future prevention, detection, attribution, and remediation of terrorist acts. Information fusion is defined as the acquisition of data from many sources, the integration of these data into usable and acces- sible forms, and their interpretation. Such integrated data can be particu- larly valuable for decision makers in law enforcement, the intelligence community, emergency-response units, and other organizations combat- ing terrorism. Information fusion gains power and relevance for the counterterrorist mission because computer technology enables large vol- umes of information to be processed in short times. (Box 3.7 provides elaborated scenarios for ways in which information-fusion techniques could be useful.)
• Prevention. Security checkpoints have become more important, and more tedious, than ever at airports, public buildings, sporting venues, and national borders. The efficiency and effectiveness of checkpoints could be significantly improved by creating information-fusion tools to
74Hank Christen, Paul Maniscalco, Alan Vickery, and Frances Winslow. 2001. “An Over- view of Incident Management.” Perspectives on Preparedness, No. 4, September. Available online at <http://ksgnotes1.harvard.edu/BCSIA/Library.nsf/pubs/POP4>.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
64 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 3.7 Scenarios for Automated Evidence Combination
Intelligence Analysis
A video monitoring program detects an unknown person speaking at a meeting with a known terrorist in an Arabic television broadcast. This information is brought to the attention of the intelligence analyst who set up the program to scan TV for videoclips that mention individuals known to associate with a particular terrorist group. The analyst decides to find out as much as possible about this new unknown person. First, a check is run on video archives using face detection/recognition software to see if this person’s face had appeared before but was missed. Second, the recording of the person’s speech from the videoclip is used to match against stored archives of conversations. Third, the person’s name, mentioned by someone in the videoclip, is used to search information resources that are both internal (across intel- ligence agencies) and external (such as the Web and multilingual news archives). The search is focused on text that mentions this name in the context of terrorism or in connection with any of the activities of the known terrorist. The material that is found is summarized in a variety of ways to aid analysis, such as in a time line with geographic locations.
The result of this search indicates that the unknown person works for an aid organization that operates in a number of countries, and that the person has recently visited the United States. A request for appropriate legal authority results in a target- ed search of the hotel, air travel, car rental, and telephone transactions associated with this trip. This search reveals connections to other people that the FBI has had under surveillance in the Washington, D.C., area, including through court-approved wiretaps. The automatic analysis of phone calls between the unknown person and those already under surveillance also indicates an unusual pattern of language in- cluding phrases like “wedding party” and “special delivery” in Arabic. These phras- es are subsequently linked to overseas intelligence intercepts. On the basis of this information, the analyst concludes that there may be something being planned for a specific time period and thus initiates a number of additional automatic monitoring and alerting tools focused on these people and these language patterns.
Airport Security Screening
At airport security checkpoints, every carry-on bag is x-rayed, and some per- centage (say, 15 percent) of these bags receives a manual examination searching for items that could be used as weapons. Though this is similar to search procedures in operation today, this scenario also entails checkpoint operators supported by a net- work of computers in this airport that captures image, sound, x-ray, and other sensor information; analyzes these data using computer perception software; shares the data across a national computer network that links every airport in the United States; assists human security agents; can be instructed to monitor for certain people or events as needed; and learns from experience what is normal and abnormal within each of the nation’s airports.
First, the x-ray machines that capture images of each bag are connected to a computer network. As each bag goes through the machine, a computer vision sys- tem analyzes it to attempt to detect suspicious items, such as sharp objects and guns, and alerts the operator if anything is detected, highlighting it on the x-ray screen.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
65INVESTING IN INFORMATION TECHNOLOGY RESEARCH
This computer vision system is not infallible, but then neither is the human baggage screener, and the two working together notice different things, so that together they are more effective than either alone (if they make the same number of errors, but independently, their combined error rate is halved).
Second, as the manual checks are performed on 15 percent of the bags, the computer is informed about which bags are checked and whether anything was found. This information provides training data to the computer, which is tied back to the x-ray image of the bag, enabling the vision system over time to improve its ability to detect suspicious items from the x-rays. Standard machine-learning algorithms are used for this purpose, not unlike those used in face recognition. Of course, the human operator will learn on the job in this way as well, but there is one major difference: the human operator may inspect hundreds or a few thousand bags in a week, whereas the computer network is capturing data from every security station in every airport around the world. Thus, the computer has thousands of times more training experience to learn from in a single day than any human operator could accumulate in a lifetime, leading it to much more refined capabilities.
Because of these extensive training experiences, the computer network is able to learn things that a single operator never could. For example, it will learn which new models of suitcases, briefcases, and purses have become common, and it will therefore be able to spot bags that may be custom-built by a terrorist who has de- signed luggage for a special purpose. It will learn what are typical false alarms raised by each model as it goes through security (e.g., the metal clasp on a particular purse might often be mistaken as a blade by those unfamiliar with that luggage model). The computer system advises the security operator about which 15 percent of the bags should be inspected, decreasing the chance that the operator misses an item or a person who should not go unnoticed. Note that the human operator is still in charge but is greatly aided by the vast experience base gained by the self-improving network of computer sensors and image analyzers.
Third, the computer network can detect patterns involving multiple people en- tering through multiple security stations, or at multiple times. If there are several people taking the same flight, each of whom has “accidentally” brought a pocket knife, this would be detected by the system, even though the individual operators at the different security posts would likely be unaware of this global pattern. Global patterns could also be detected instantly across multiple airports (e.g., single passen- gers boarding with similar “accidental” pocketknives in Boston, San Francisco, Washington, D.C., and New York City).
Fourth, the security checkpoint operator will be informed by the system of events that occurred more globally throughout the airport and in airports with con- necting flights, as captured by security cameras and other sensors throughout the airport. For example, if two people arrived at the airport together (as indicated by the cameras elsewhere in the airport) but get in different lines going through security, the operator might be informed of this somewhat unusual behavior. While no single clue such as this is clear-cut evidence of a dangerous situation, the security station operators are more effective because the network of computer sensors and analysis provides them a more global and more informed picture of what is going on in the airport, enabling them to focus their attention on the most significant risks.
Finally, the information garnered, learned, and transmitted across this network of airport monitoring systems is used to help train individual security operators and to analyze how past security breaches were successful.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
66 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
support the checkpoint operator in real time. For example, future airport- security stations could integrate data received from multiple airports to provide a more comprehensive view of each passenger’s luggage and activities on connecting flights. The stations could use data-mining meth- ods to learn which luggage items most warrant hand-inspection, and they could capture data from a variety of biometric sensors to help verify the identities of individuals and to search for known suspects.
• Detection and attribution. Intelligence agencies are routinely in- volved in information fusion as they attempt to track suspected terrorists and their activities. One of their primary problems is that of managing a flood of data. There are well-known examples in which planned terrorist activity went undetected despite the fact that evidence was available to spot it, because the evidence was just one needle in a huge haystack. Future intelligence and law-enforcement activities could therefore benefit enormously from advances in the automated interpretation of text, im- age, video, sensor, and other kinds of unstructured data. Automated interpretation would enable the computer to sort efficiently through mas- sive quantities of data to bring the relevant evidence (likely combined from various sources) to the attention of an analyst.
• Remediation (response). Early response to biological attacks could be supported by collecting and analyzing real-time data, such as ambu- lance calls, admissions to hospital emergency rooms and veterinary of- fices, or purchases of nonprescription drugs in grocery stores to identify spreading disease. Prototype systems are already under development (Box 3.8). If anomalous patterns emerge that may signify an outbreak of some new pathogen, system administrators can quickly alert health offi- cials.
Many other opportunities exist for such computer-aided evidence- based decision making. For example, the monitoring of activity on com- puter networks might flag potential attempts to break through a firewall; or, sensor networks attached to public buildings might flag patterns of activity within the building that suggest suspicious behavior. In such cases, an unaided decision maker might have difficulty detecting subtle patterns, because the data are voluminous and derive from a variety of sources.
As a general proposition, the development of tools that provide hu- man analysts with assistance in doing their jobs has a higher payoff (at least in the short to medium term) than do tools that perform most or all of the analyst’s job. The former approach places a greater emphasis on using technology to quickly sift large volumes of data in order to flag potentially interesting items for human attention, whereas the latter ap-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
67INVESTING IN INFORMATION TECHNOLOGY RESEARCH
BOX 3.8 Examples of Information Fusion for Detection of Bioterrorism Attacks
• The Biomedical Security Institute’s Real-time Outbreak and Disease Surveil- lance System monitors about 1,200 patient visits per day in 17 western Pennsylvania hospitals and recognizes patterns of infectious disease.1 The system looks for sud- den and frequent outbreaks of cases involving flu-like symptoms, respiratory illness- es, diarrhea, and paralysis that might indicate a bioterror attack. A sudden peak in a certain type of symptom may be the result of a biological agent. Emergency rooms and hospitals provide patient information such as symptoms, age, gender, address, and test results directly to the system.2 Public health doctors are automatically noti- fied if a pattern develops, and they in turn notify the proper authorities.
• The Centers for Disease Control and Prevention supports a number of en- hanced surveillance projects (ESPs) that monitor certain hospital emergency depart- ments to establish baseline rates of various clinical syndromes.3 Anomaly detection models identify significant departures from these baseline rates that are called to the attention of state and local health departments for confirmation and appropriate fol- low-up. ESP has been tested at the 1999 World Trade Organization Ministerial in Seattle, the 2000 Republican and Democratic National Conventions held in Phila- delphia and Los Angeles, respectively, and the Super Bowl/Gasparilla Festival in Tampa, Florida. A similar effort is the Lightweight Epidemiology Advanced Detec- tion and Emergency Response System (LEADERS), which provides a set of tools orig- inally developed for the military to provide real-time analysis of medical data entered at health care delivery points (e.g., hospitals). These data are examined for spatial correlations so that areas of potential disease outbreak can be rapidly identified.
• A system in Washington, D.C., called ESSENCE II (ESSENCE stands for Elec- tronic Surveillance System for Early Notification of Community-based Epidemics) is an operational prototype for the National Capital Region that integrates information on nonmedical information such as employee absenteeism and over-the-counter drug sales with information available from doctors’ visits, diagnostic laboratories, hospital emergency rooms, 911 and poison control calls, and so on. These data are acquired on a near-real-time basis, and are examined to search for temporal and/or spatial anomalies that might indicate an early warning of a bioterrorist attack. Non- medical information is valuable in this context because it is likely to reflect changes in public health status before affected individuals seek medical care on a scale large enough to register a possible attack.4
1Bruce Gerson. 2002. “President Bush Praises Carnegie Mellon, Pitt Collaboration to Fight Bioterrorism.” Carnegie Mellon News. February 13. Available online at <http://www.cmu. edu/cmnews/extra/020213_gbush.html>.
2James O’Toole et al. 2002. “Bush Here Today to Highlight Spending on Terrorism.” Pittsburgh Post-Gazette, February 5. Available online at <http://www.post-gazette.com/region- state/20020205visit0205p2.asp>.
3See <http://ndms.umbc.edu/conference2001/2001con20/Treadwe.htm>. 4For more information on ESSENCE II, see the Web site at <http://www.nyam.org/events/
syndromicconference/agenda.shtml>.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
68 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
proach relies on computers themselves to make high-level inferences in the absence of human involvement and judgment.
A final dimension of information fusion is nontechnical. That is, disparate institutional missions may well impede the sharing of informa- tion. Underlying successful information-fusion efforts is a desire to share information—and it is impossible to fuse information belonging to two agencies if those two agencies do not communicate with each other. Es- tablishing the desire to communicate among all levels at which relevant information could be shared might have a larger impact than the fusion that may occur due to advances in technology. For example, hospitals generally see little benefit and many risks in sharing patient information with other hospitals, even if it may facilitate the care of some patients that use both facilities or improve epidemiologic monitoring. (Note also that achieving a desire for different facilities or agencies to communicate with each other may take more than moral persuasion. This point is addressed in greater detail in Sections 3.6.3 and 3.6.4.)
3.3.1 Data Mining
Data mining is a technology for analyzing historical and current online data to support informed decision making. It has grown quickly in importance in the commercial world over the past decade, because of the increasing volume of online data, advances in statistical machine-learn- ing algorithms for automatically analyzing these data, and improved net- working that makes it feasible to integrate data from disparate sources.
The technical core of data mining is the ability to automatically learn general patterns from a large volume of specific examples. For example, given a set of known fraudulent and nonfraudulent credit-card transac- tions or insurance claims, the computer system may learn general pat- terns that can be used to flag future cases of possible fraud. Other appli- cations are in assessing mortality risk for medical patients (by learning from historical patient data) and in predicting which individuals are most likely to make certain purchases (by analyzing other individuals’ past purchasing data). Decision-tree learning, neural-network learning, Baye- sian-network learning, and logistic-regression-and-support vector ma- chines are among the most widely used statistical machine-learning algo- rithms. Dozens of companies now offer commercial implementations, which are integrated into database and data-warehousing facilities.
The majority of these commercial data-mining applications involve well-structured data. However, current commercially available technol- ogy does not work well with data that are a combination of text, image, video, and sensor information (that is, data in “nonstructured” formats).
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
69INVESTING IN INFORMATION TECHNOLOGY RESEARCH
Moreover, it is largely unable to incorporate the knowledge of human experts into the data-mining process. Despite the significant value of current machine-learning algorithms, there is also a need to develop more accurate learning algorithms for many classes of problems.
New research is needed to develop data-mining algorithms capable of learning from data in both structured and nonstructured formats. And, whereas current commercial systems are very data-intensive, research is needed on methods for learning when data are scarce (e.g., when there are only a few known examples of some kinds of terrorist activity) by incorporating the knowledge of human experts alongside the statistical analysis of the data. Another research area is that of better mixed-initia- tive methods that allow the user to visualize the data and direct the data analysis.
3.3.2 Data Interoperability
An inherent problem of information fusion is that of data interoper- ability—the difficulty of merging data from multiple databases, multiple sources, and multiple media. Often such sources will be distributed over different jurisdictions or organizations, each with different data defini- tions. New research is needed for normalizing and combining data col- lected from multiple sources, such as the combination of different sets of time-series data (e.g., with different sampling rates, clocks, and time zones), or collected with different data schemas (e.g., one personnel data- base may use the variable “JobTitle,” while another uses “Employee Type”). Note that data interoperability is also an essential element of organizational and operational interoperability.
3.3.3 Natural Language Technologies
In the past decade, the area of language technologies has developed a wide variety of tools to deal with very large volumes of text and speech. The most obvious commercial examples are the Web search engines and speech recognition systems that incorporate technology developed with funding from the Defense Advanced Research Projects Agency (DARPA) and the National Science Foundation (NSF). Other important technolo- gies include information extraction (e.g., extracting the names of people, places, or organizations mentioned within a document), cross-lingual re- trieval (e.g., does an e-mail message written in Arabic involve discussion of a chemical weapon?), machine translation, summarization, categoriza- tion, filtering (monitoring streams of data), and link detection (finding connections). Most of these approaches are based on statistical models of language and machine-learning algorithms.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
70 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
A great deal of online information, in the form of text such as e-mail, news articles, memos, and the Web, is of potential importance for intelli- gence applications. Research is needed on methods for accurately ex- tracting from text certain structured information, such as descriptions of events (e.g., the date, type of event, actors, and roles.) Research is needed to handle multiple languages, including automatic translation, cross-lin- gual information retrieval, and rapid acquisition of new languages. Other important areas of future research are link detection (related to the nor- malization problem mentioned above) and advanced question answer- ing.
3.3.4 Image and Video Processing
The technologies for image and video processing tend to be domain- specific and often combine information from multiple modes. For ex- ample, several companies are beginning to offer image-recognition soft- ware for face recognition and automatic classification of medical and other types of images. Commercially available video indexing-and-retrieval software improves effectiveness by combining techniques of segmenta- tion, face detection, face recognition, key frame extraction, speech recog- nition, text-caption extraction, and closed-caption indexing. This is a good example of information fusion in which multiple representations of content are combined to reduce the effect of errors coming from any given source.
The major limitation of present language and image technologies is in accuracy and performance: despite significant progress, these need to be considerably improved. This is particularly important for counterterrorist systems where the data may be very noisy (i.e., surrounded by irrelevant information) and sparse.
Work is needed on improved algorithms for image interpretation and speech recognition. Many of these research issues are specific to prob- lems arising in a particular medium—for example, recent progress on face recognition has come primarily from understanding how to extract relevant image features before applying machine-learning methods, though this approach may not be applicable to machine learning in other contexts. However, new research is also needed on perception based on mixed media, such as speech recognition based on sound combined with lip motion.
3.3.5 Evidence Combination
Many of the techniques used to combine information from multiple sources, as in video indexing or metasearch engines, are ad hoc. Current
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
71INVESTING IN INFORMATION TECHNOLOGY RESEARCH
research on more principled methods for reasoning under uncertainty needs to be extended and tested extensively in more demanding applica- tions. This is a key technical problem, with widespread implications for many of the applications mentioned above—for example, how to com- bine evidence from hospital admissions and from nonprescription drug purchases to detect a possible bioterrorist attack, how to combine evi- dence from face recognition and voice print to estimate the likely identity of a person, how to combine evidence from multiple sensors in a building to detect anomalous activity, and how to undertake more effective per- sonnel screening.
3.3.6 Interaction and Visualization
All technologies developed for information access and analysis rely on human involvement to specify information problems and to make sense of the retrieved data. Research on human-computer interaction in the areas of query formulation and visualization has the potential for significantly improving the quality and efficiency of intelligence applica- tions. In the area of query formulation, some topics of interest include support for natural-language queries, query triage (deciding which infor- mation resource is needed based on the form of the query), and person- alization based on the context of previous searches and the current task. A variety of visualization techniques have been developed for large-scale scientific applications, but more research is need on techniques that are effective for visualizing huge amounts of dynamic information derived from unstructured data about people, places and events. Such research is potentially valuable because it takes advantage of the human ability to recognize patterns more easily than automated techniques can.
3.4 PRIVACY AND CONFIDENTIALITY
The essential rationale underlying a science-based approach to coun- tering terrorism is that, absent measures to reduce the intrusiveness and burdens of a counterterrorism regime on individuals, these burdens will become so high that they will be intolerable to the American people over the long run. As pressure mounts for the government to collect and process more information, it becomes increasingly important to address the question of how to minimize the negative impacts on privacy and data confidentiality that may arise with applications of information fu- sion.
It is axiomatic that information that is not collected can never be abused. For example, consider the possible collection of an individual’s HIV status. If the individual has concerns that his or her privacy interests
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
72 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
might be compromised by the improper disclosure of HIV status to an employer, then the most effective way to protect such information is not to collect information on HIV status (e.g., by not recording it in medical records or not requiring an HIV test). However, it is also true that infor- mation that is not collected can never be used. Thus, if no one ever collects information about the individual’s HIV status, that person’s medi- cal treatment may be adversely affected.
This dilemma is magnified in a counterterrorism intelligence context. Because terrorists are not clearly identified with any entity (such as a nation-state) whose behavior can be easily studied or analyzed, their indi- vidual profiles of behavior and communication are necessarily the focus of an intelligence investigation. Most importantly, it is often not known in advance what specific information must be sought in order to recog- nize a suspicious pattern, especially as circumstances change. From the perspective of intelligence analysis, the collection rule must be “collect everything in case something might be useful.” Such a stance generates obvious conflicts with the strongest pro-privacy rule “Don’t collect any- thing unless you know you need it.”
Data mining and information fusion have major privacy implications, and increased efforts by commercial and government entities to correlate data with a specific person negatively impact privacy and data confiden- tiality. There is no clear and easy way of resolving this tension. Never- theless, research can help to ameliorate this tension in several ways:
• At a minimum, policy makers need accurate information about the trade-offs between privacy and confidentiality on the one hand and ana- lytical power for counterterrorist purposes on the other under different circumstances of data disclosure. For example, under what circumstances and at what state in an analytical effort are specific identities necessary? What is the impact of increasing less-personalized information? Research is needed to answer such questions.
• Research is needed to mitigate negative aspects of data mining, including research on data-mining algorithms that discover general trends in the data without requiring full disclosure of individual data records. For example, some algorithms work by posing statistical queries to each of a set of databases rather than by gathering every data record into a centralized repository. Others collect aggregate data without requiring full disclosure of individual data records.75
75As a simple example, say that a public health agency is interested in the overall inci- dence of a particular kind of disease being treated at hospitals in a certain area. One method of obtaining this information is for the agency to ask each hospital for the number
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
73INVESTING IN INFORMATION TECHNOLOGY RESEARCH
• Research is needed to develop architectures for data storage that protect privacy without compromising analysis. For example, arrange- ments could be made to use totally separate and distributed data reposi- tories. Using such an approach to information access, an intelligence agency could send a request to other government agencies and “content- providers” asking them if there were any connections between certain individuals. Without revealing the details of the connections, the pres- ence of connections could be made known and then specific legal action could be taken to acquire the data.
Note that institutional concerns about confidentiality can be as strong as individual concerns about privacy. For example, asking hospitals to pass along personally identified patient information to parties not tradi- tionally entitled to such information may well engender institutional re- sistance that may well not be surmountable by fiat (see the discussion in Section 3.6.3).
For many applications such as badges and access tokens, detailed personal information is not necessary; the only requirements are that the token is recognizable as valid and that it has been issued to the person presenting it. It does not even have to have an individual’s name on it. On the other hand, a sufficient aggregation of non-personally-identified in- formation can often be used to identify a person uniquely. Identifying someone as a man of Chinese extraction who has a doctorate in physics, enjoys swing dancing, has an adopted 7-year-old daughter, and lives in upper Northwest Washington, D.C., is probably sufficient to specify a unique individual, even though no particular name is associated with any of these pieces of information. Thus, the mere fact that information is disconnected from personal identifiers is no assurance that an individual cannot be identified if data were aggregated.76
of cases of that disease and to total them. However, if for some reason a hospital has an incentive to keep that number secret, such a request for data raises privacy concerns. An alternative approach is to ask each hospital to report the sum of the number of cases plus some random number. The agency totals the sums and then asks each hospital to report the random number it used. To obtain the true incidence, it then subtracts out from the total all of the random numbers submitted. In reporting this way, no hospital compromises the true number of cases at that hospital.
76It is sometimes surprising how little non-named information is necessary to aggregate in order to re-create an individual’s identity. For example, a large number of people can be identified simply by aggregating their date of birth and zip code. See Computer Science and Telecommunications Board, National Research Council. 2000. IT Research for Federal Statistics. National Academy Press, Washington D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
74 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Another conflict between privacy and intelligence analysis arises be- cause data can be linked. Assuming that various pieces of data have been collected somewhere, intelligence analysis relies on the ability to link data in order to reveal interesting and perhaps significant patterns. Indeed, the very definition of a “pattern of behavior” is one in which data associ- ated with a given individual are grouped so that a trip to Location A can be seen in the context of Transaction B and a phone call with Person C. It is exactly such linkage that gives rise to privacy concerns. Thus, actions taken to increase the interoperability of databases so that meaningful linkages can be created will inevitably raise privacy concerns.
What technical or procedural protections can be developed to guard against inappropriate privacy-compromising linkages but do not also cripple the legitimate search for terrorists? Research in this area is vital. One approach calls for linkages to be uncovered in the relevant comput- ers but not to be revealed except under special circumstances (e.g., when some reasonable cause for suspicion exists77 ). For example, the most recent version of ESSENCE (Box 3.8) uses data that can be rendered anony- mous on a sliding scale of anonymity.78 During normal operation (i.e., when nothing has been detected), sufficiently anonymous data are pro- vided. Once evidence of an attack is encountered, data that are less anony- mous and more identifiable, but also more useful for further analysis, are automatically transmitted. Thus, routine compromises of privacy are not entailed, but when a potential threat is uncovered, less privacy is pro- vided in order to support an appropriate public health response. Another area of research is on decentralized surveillance tools and systems that can provide analysts with information about data trends and clustering, rather than the data values themselves. Such systems promise access to far more data with fewer privacy concerns.
A second approach for protecting privacy calls for audits of accesses to information and generators of linkages to deter those who might do so
77The question of what set of facts and circumstances constitutes reasonable cause be- longs to the realm of policy and law rather than to technology or social science. An analo- gous situation exists with the privacy of medical records. While it is possible for unautho- rized parties to hack their way past security systems that guard medical records, the largest and most significant disclosures of medical records to third parties occur because policy and law exist to allow such disclosures in a perfectly legal manner. See Computer Science and Telecommunications Board, National Research Council. 1997. For the Record: Protecting Electronic Heath Information. National Academy Press, Washington, D.C.
78Computer Science and Telecommunications Board, National Research Council. 2000. Summary of a Workshop on Information Technology Research for Federal Statistics. National Acad- emy Press, Washington, D.C., p. 36.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
75INVESTING IN INFORMATION TECHNOLOGY RESEARCH
inappropriately and to punish those who actually do. In this scenario, an individual uses authorized access to a computer system to obtain sensi- tive information or develops a sensitive linkage and then uses it for some inappropriate purpose. Research is needed to investigate the feasibility of technologies that can mitigate the damage done when “insiders” use technological means to obtain such information inappropriately and also increase the likelihood that the individual abusing his or her access will be caught. Effective organizational policies, practices, and processes to counter such abuses are also an important area of research.
A third approach—entirely based in policy—is to take steps that re- duce the harm suffered by individuals whose privacy is compromised inappropriately. That is, many (though by no means not all) concerns about privacy arise from the fear that improperly disclosed information might be used to an individual’s economic or legal detriment. Thus, a concern about privacy with respect to records of HIV status may be partly rooted in a fear that improper disclosure might result in the loss of health insurance or the denial of a job opportunity in the future; a concern about the privacy of one’s financial records may be rooted in a fear that one could become a “mark” for criminals or the subject of unwarranted tax audits. Laws and regulations prohibiting the use of information obtained through inappropriate disclosures and providing victims with reasonable recourse should such disclosures occur could serve to ease public con- cerns about privacy. (Such laws and regulations are likely to be relevant also to individuals with inaccurate data associated with them, e.g., an inaccurate report of HIV status on a medical record.)
3.5 OTHER IMPORTANT TECHNOLOGY AREAS
A number of other areas of IT are important for counterterrorism purposes. While the committee believes that the research areas described in Sections 3.1 through 3.4 should have the highest priority in any com- prehensive IT research program for counterterrorist purposes, the mate- rial below is intended to indicate why these areas are important and to sketch out how the research might be done.
3.5.1 Robotics
Robots are useful in the areas of military operations, hostile environ- ments, and toxic-waste management. They can serve in high-tech arenas such as space exploration or in home environments— as personal assis- tants for the elderly. Autonomous vehicles in particular include robotic cars, tanks, aircraft, helicopters, land rovers, and “snakes” that crawl up and down rough surfaces. The area of robotics has made substantial
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
76 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
advances in recent years, especially when combined with technologies such as mobile wireless, virtual reality, and intelligent or behavior-based software.
As an extension of small devices and sensors, robots serve two pur- poses. First, robots currently exist to assist or replace emergency workers or military personnel in dangerous situations. For example, bomb squads use robots to inspect, open, and destroy or detonate suspicious packages; tethered or wireless robots, with receivers and transmitters, could re- spond to commands to disarm bombs.
A second purpose for robots could be as sensing devices to detect motion and airborne chemicals. But unlike stationary sensors, robots have the ability to move. For example, a “search-and-rescue” robot could crawl into crevices that are inaccessible or dangerous for humans (e.g., gas-filled pockets), provide surveillance via a mounted camera or micro- phone, and communicate a situational assessment with a wireless trans- mitter. The use of such robots presents challenges such as their being fit into an existing organizational and information hierarchy and being used by workers who might not be familiar with technology.
Though the field of robotics has existed in some form for many years, practically useful robots are only beginning to emerge. For example, the robots used today for search and rescue are little more than remote-con- trolled vehicles. Much more research has to be done on making them function more autonomously, with more robust control and behavior cir- cuits. In addition, the management of teams of robots poses important research problems with respect to multiagent learning, planning, and ex- ecution in the face of uncertainty and potential opponents.
Robots combine complex mechanical, perceptual, computer, and tele- communications systems. More work on all of these areas—and on the problems of integration—needs to be done. Robot arms and manipula- tors are still a major source of weakness. Robotics is a canonical example of a research area that cuts across disciplines. With research problems in pattern recognition, planning, object manipulation (especially at a fine level), machine emotions, mechanical compliance, control theory, and methods for human-robot interaction, robotics draws on expertise from and poses challenges in computer science, mechanical engineering, and electrical engineering, as well as the social sciences.
3.5.2 Sensors
Sensors are relevant in preventing certain kinds of attack (e.g., threat- warning sensors that detect smuggled nuclear materials), detecting certain kinds of attack (e.g., incident-response sensors that indicate the presence
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
77INVESTING IN INFORMATION TECHNOLOGY RESEARCH
of deadly but odorless chemical agents), and mitigating the consequences of an attack (e.g., sensors that indicate whether an individual has been exposed to a biological agent). (For more discussion of particular sensor- specific challenges related to counterterrorism, see the parent report, Making the Nation Safer.79 The networking of sensors will also be neces- sary for broad coverage to be achieved; this area also presents research challenges.80 )
Sensors can be deployed in various environments to gather data: on rooftops to detect airborne chemicals, in hallways to detect movement, and within physical infrastructure such as buildings and bridges to detect metal fatigue and points of failure. These devices could be integrated into objects or systems that are likely to last for long periods of time and must function under constraints such as limited power source, need for ad- equate heat dissipation, and limitations on bandwidth and memory. Moreover, because they protect a civilian rather than a military popula- tion (civilian populations are much less tolerant of false positives and much more vulnerable to false negatives), sensors for counterterrorist purposes must place a very high premium on overall accuracy (i.e., low false positive and low false negative rates).81 Characteristics such as operation against the widest possible number of agents and wide area coverage are also important.
In addition to the challenges related to emergency sensor deployment described in Section 3.2.6, these areas pose difficult research challenges. Sensors are most effective when individual sensors are linked and coordi- nated in a distributed sensor network. Such a network allows informa- tion to be collected, shared, and processed via a “digital nervous system” for situational assessment and personnel monitoring. Perhaps the most important research problem for sensor networks is their self-configur- ability—sensor networks must be able to configure themselves (i.e., inter- connect available elements into an ensemble that will perform the re- quired functions at the desired performance level) and adapt to their environments automatically (respond to changes in the environment or in system resources). This is not to deny the problems faced in particular sensor modalities (e.g., the automatic recognition of dangerous objects in an x-ray of carry-on luggage), but it nevertheless remains a key challenge
79National Research Council. 2002. Making the Nation Safer: The Role of Science and Technol- ogy in Countering Terrorism. National Academies Press, Washington, D.C., pp. 320-324.
80CSTB, NRC, 2001, Embedded, Everywhere. 81In general, for any given test, as the criteria for a positive result are increased, the rate
of false positives decreases while the rate of false negatives increases. The only way to decrease both simultaneously is to devise a better test.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
78 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
to undertake sensor networking and to integrate into a single threat pic- ture sensor readings from a large number of sensors (this is important because of the need for monitoring large areas) each of which are of low accuracy.
3.5.3 Simulation and Modeling
Models are mathematical representations of a system, entity, phe- nomenon, or process, while simulation is a method for implementing a model over time.82 Modeling and simulation can play important roles throughout crisis-management activities. Specifically, emergency re- sponders in a crisis must take actions to mitigate imminent loss of life and/or property. Thus, the ability to make predictions about how events might unfold (e.g., how a plume of chemical or biological agents might disperse in the next few hours, how a fire might spread to adjoining areas, how long a building might remain standing) is important to emergency responders. Simulations can also be useful for testing alternative opera- tional choices.
While traditional simulation models have been applied to severe storms, earthquakes, and atmospheric dispersion of toxic substances, their primary focus has been scientific research rather than real-time crisis re- sponse. One difference between scientific simulations and crisis simula- tions is that the presentation of results for scientific purposes is not al- ways compatible with the needs of emergency responders. For example, plume models of a chemical spill or release of radioactive material typi- cally produce maps showing dispersion in parts per million as a function of time, whereas an emergency responder needs an automatic translation of the concentration of materials into easily interpretable categories such as “Safe,” “Hazardous but not life threatening,” or “Life threatening” so that appropriate action can be taken quickly.
Research in simulation and modeling is needed in several areas if these are to become useful tools for emergency responders:
• Developing ad hoc models. In many situations, a particular terrorist scenario will not have been anticipated. Thus, it would be helpful to have tools to facilitate the creation of ad hoc situation-specific models rapidly (i.e., on a time scale of hours or days). This would include both the data-
82The discussion in this section is adapted largely from CSTB, NRC, 1996, Computing and Communications in the Extreme, and CSTB, NRC, 1999, Information Technology Research for Crisis Management.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
79INVESTING IN INFORMATION TECHNOLOGY RESEARCH
gathering needed for input to the model and the construction of the model itself. Such tools would likely incorporate significant amounts of subject- matter expertise. The performance of such models could not be expected to match that of models developed under leisurely conditions, but they might provide rough guidance that could be very useful to emergency responders. (As with other issues relating to the use of technology, how people actually use such tools matters a great deal. Thus, understanding the actual utility of hastily constructed models as a function of the prac- tice and experience of the users involved is also an essential component of this research.)
• Increasing the timeliness of modeling results. Because of the time pres- sures facing emergency responders, timely results are critical. One ele- ment is fast processing capabilities. Another element, easy to overlook, is the timeliness of data that can be inserted into a model. To be useful for emergency responders, data must be entered on a near-real-time basis (e.g., a model could be linked to weather sensor data), a task that becomes impossible if large efforts at data preprocessing or formatting are neces- sary before a simulation can be run.
• Obtaining adequate computational power. Because many simulations require large amounts of computing power, techniques are needed that enable the rapid requisitioning of computers engaged in scientific re- search and other activities to serve simulation needs in a crisis. Such techniques will require both new administrative arrangements and fur- ther advances in the flexibility, affordability, and ease of use of these resources.
• Rapid rescaling of models. Different emergency responders may need predictions at different time and distance scales. For example, the mayor of a city might require information on whether to order an evacu- ation in response to a successful attack on a nuclear plant and thus would need information on what might happen at the plant on a time scale of 24 hours. On the other hand, a firefighter at the plant may need to know what might happen in the next hour. The ability to run simulations at varying scales of resolution is important for both the mayor and the firefighter, and the needs of each drive the trade-offs between the accu- racy of a prediction and the speed of the response. Thus, research is needed to develop the capability for rescaling models rapidly in response to requests from crisis managers.
• Making initial damage estimates. Rapid assessment of the extent and distribution of damage in the wake of any large incident is difficult be- cause acquiring and synthesizing damage reports take considerable time. However, initial damage estimates are essential for directing response efforts. For example, the destruction of a dam could release a tidal wave
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
80 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
of water that would destroy some houses and spare others. A model that provided initial damage estimates would have to account for building stock (structure type, age, and so on), critical facilities, and lifelines, as well as geological information and demographics, in order to predict the number of casualties and the need for shelter and hospitals. Note also that such models would have direct relevance to the insurance industry and might help guide the development of criteria and pricing for terror- ism insurance policies.
• Improving model interoperability. As a rule, models are developed and used in isolation. Integrating models into information systems for emergency responders would enable more accurate and timely predic- tions to be made. For example, emergency responders at the Murrah Building in Oklahoma City in 1995 used computer-aided design (CAD) software to map the areas to be searched and to correlate estimated loca- tions of victims (based on where their offices had been located before the blast) with the actual scene. More useful would have been the coupling of the CAD data into a structural model that could perform finite-element analysis to predict the loads on various parts of the damaged building, thus indicating where shoring was necessary to prop up damaged struc- tures and reduce the danger to survivors and rescuers from further col- lapses.
3.6 PEOPLE AND ORGANIZATIONS
The craft of espionage distinguishes between the initial penetration of an organization and an ongoing exploitation that continues to yield use- ful information or access. Technology (e.g., a worm, rogue code, a bug, a planted microchip) is often essential to the ongoing exploitation, but it is almost always social methods (e.g., bribing a low-level worker) that allow the initial penetration which facilitates the introduction of that technol- ogy. For example, a bug planted in a room will reveal conversations there for a long time, but it is a failure of people and organizations that allows an enemy agent to plant the bug in the first place. In the immediate aftermath of World War II, Soviet spies in the United States used a one- time pad encryption system, an encryption approach that is provably unbreakable. Nevertheless, U.S. cryptanalysts broke the Soviet code— because the Soviets began to reuse some of the key pads.83
83Key pads are simply lists of random numbers, so there was no particular reason why the Soviets were forced to reuse them. Their reuse was a human error that violated the essential premise underlying the security of one-time pad encryption systems. (See NSA
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
81INVESTING IN INFORMATION TECHNOLOGY RESEARCH
This lesson generalizes to any study that involves the weaknesses and vulnerabilities of any system. That is, technology is always used in some social and organizational context, and human error and human culpabil- ity are central in understanding how the system might fail. Thus, design and deployment are system issues, and since human, social, and organi- zational behavior are part of the system, they must be part of the research and design efforts. The technology cannot be examined in isolation of the ways in which it is deployed.
Technology is aimed at helping people, organizations, and society to accomplish their goals. Technology is essential to modern everyday life, and technology is essential to thwarting would-be terrorists and crimi- nals. At the same time, if deployed poorly, the technology can actually make problems worse. If it is poorly designed, it will lead to numerous errors, usually blamed on the unwitting users of the system, but almost invariably traceable to poor design from a human or organizational point of view. Whatever the reason, human error can be extremely costly in time, money, and lives. Research findings from the behavioral and social sciences can aid in the design of solutions that are effective while being minimally obtrusive. Good design can dramatically reduce the incidence of error—as the experience in commercial aviation shows.
3.6.1 Principles of Human-Centered Design
Both technology and the people around it make errors. It is simply not possible to have zero false positives and zero false negatives simulta- neously, especially in a world filled with uncertainty, ambiguity, and noise. Most importantly, deliberate adversaries seek to cause and exploit false alarms. As a result, the design of a system involving both technol- ogy and people must assume some percentage of false positives and false negatives. The design of a system must provide multiple levels of de- fense, accommodate continual feedback, and allow systematic attempts to improve. In most cases, most errors should be taken as useful feedback and used to improve system performance rather than as signs of failure that require punishment and blame.
The best systems will look for incipient failures—problems that are detected before they do damage—as important measures of operation.
Venona papers online at <http://www.nsa.gov/docs/venona/monographs/monograph- 2.html>.) More generally, the use of one-time pad systems is cumbersome and difficult and does not scale easily to large numbers of users, so they are disfavored for many applica- tions. These disadvantages are all human factors and illustrate well the trade-off between security and ease of use.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
82 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
The time to take corrective action is when incipient errors reach an unde- sirable state but before they turn into serious issues. It is only natural to ignore these early warnings because, of course, no damage has yet been done. But it was exactly this ignoring of early-warning trouble signs that led directly to the disaster with the O-rings on the Space Shuttle Chal- lenger.84
In general, systems must be designed from a holistic, systems-ori- ented point of view rather than by focusing on the technology. Indeed, understanding the human and organizational interactions is important well before technical requirements are established. Then, as the system is being designed, the experts on technology and human behavior jointly devise possible systems and develop rapid prototypes that allow quick and efficient testing of the ideas. Attention to the human requirements early in the design stage coupled with iterative design techniques saves time in the end by minimizing the end testing requirements and reducing the likelihood of major revisions late in the development process.
Consider the phenomenon of “human error.” Experience demon- strates that often what is blamed on “human error” is in fact design error. A focus on the technology in isolation of the manner in which it is de- ployed invariably leads to problems. It is common in the development of automated systems to automate whatever can be done, leaving the rest to the human operators. This often means that the human is “out of the loop,” with little responsibility, until matters reach the point at which the automatic systems can no longer cope. Then the human is suddenly and unexpectedly faced with an emergency, and because at this point every- thing is under human control, any failure is labeled “human error.”
By contrast, when systems are designed with a full understanding of the powers—and weaknesses—of human operators, the incidence of hu- man error is greatly diminished. People must be given meaningful tasks. They must always be engaged (i.e., “in the loop”), and their talents should be employed for high-level guidance, not for entering detailed sequences that require high accuracy. Machines are good at accurate, repetitive actions. People are not.
Human-centered design is a well-explored field with several societ- ies, professional journals, and much academic research as well as applica- tions, especially in aviation safety and computer systems.85 The follow- ing subsections address some basic principles of human-centered design.
84See R.P. Feynman. 1986. “Personal Observations on Reliability of Shuttle,” in App. F, Report of the Presidential Commission on the Space Shuttle Challenger Accident. Available online at <http://science.ksc.nasa.gov/shuttle/missions/51-l/docs/rogers-commission/Appen- dix-F.txt>. Accessed November 18, 2002.
85See, for example, Jef Raskin, 2000, The Human Interface, Addison-Wesley, Boston.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
83INVESTING IN INFORMATION TECHNOLOGY RESEARCH
Defend in Depth and Try to Avoid Common-Mode Failures
Many of today’s systems have a single point of defense. If problems arise there, if there is some error, there is no second line to fall back on.86 A notable exception is aviation safety, which builds multiple systems so that failure at one point does not break the system.
A key difficulty in such a design philosophy is the existence of com- mon-mode failures. The accident literature is filled with examples of common-mode failure, in which redundant safety systems all failed at the same time. For example, in the September 11 attack on the World Trade Center, the medical response was hindered by the fact that the city’s Office of Emergency Management (OEM), responsible for coordinating all aspects of a disaster response, was housed in Building 7 of the World Trade Center, one of the buildings that collapsed several hours after the airplane strikes.
This is not to say that common-mode failures are usually ignored in design. But they can often be difficult to detect and eliminate. The “re- dundant” communications lines cited in Section 2.2.2 are a potential com- mon-mode failure, and yet as the discussion of Section 3.2.8 emphasizes, redundant links that are in fact not redundant are often not easy to iden- tify. A more complex example of a hidden common-mode failure oc- curred in a commercial airliner that lost oil pressure in all three engines simultaneously. The two engines on the wing were quite different from the engine in the tail, and they had been serviced by different technicians. However, it turned out that each engine required an O-ring seal, and due to a complex chain of events, the O-ring was left off the part that was serviced on all three engines. Thus, in this case, the O-ring was the com- mon-mode failure, though on the surface the simultaneous failure did not appear to be a common-mode failure.87
Account for the Difference Between Work as Practiced and Work as Prescribed
In the study of work practices, it is commonplace to observe the dis- tinction between work as practiced and work as prescribed. When people describe their work, they can provide clear and coherent statements about
86P.A. Hancock and S.G. Hart. 2002. “Defeating Terrorism: What Can Human Factors/ Ergonomics Offer?” Ergonomics in Design, Vol. 10 (1): 6-16.
87National Transportation Safety Board (NTSB). 1984. Aircraft Accident Report—Eastern Air Lines, Inc., Lockheed L-1011, N334EA, Miami International Airport, Miami, Florida, May 5, 1983. Report No. NTSB/AAR-84/04. National Transportation Safety Board, Washington, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
84 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
the procedures they follow. But observation of these same people doing actual work shows that they are inconsistent with the descriptions they provided. Why? Because “that was a special case.” In fact, it turns out that special cases are the norm, and the descriptions are of the prototypi- cal case that seldom actually happens. Additionally, these descriptions of procedure are for nonemergency circumstances. During emergencies, established procedures will prove even more inadequate than they are under putatively normal circumstances.
A common approach to improving safety and security is to tighten procedures and to require redundant checking. But tighter procedures to improve security address work “as prescribed.” In practice, the technol- ogy and procedures that are added to make operations safer and more secure quite often get in the way of getting the work done. Security technology and procedures can introduce so many problems into getting the job done that people learn to circumvent them. Because people are inherently helpful and well motivated to do their work, they develop workarounds to bypass security, not because they are not well trained or motivated, but precisely because they are well trained and motivated. In many cases, they could not accomplish their tasks without violating pro- cedures. This is especially true in crises, where normal routines break down and workarounds are essential.
Consider, for example, advice that is often given about passwords. People are advised to use passwords that are long and obscure and to change them frequently so that if one is compromised, it does not remain compromised for long. The result is that people write down their pass- words on yellow Post-it notes and paste them on their terminals, where they are easy for unauthorized users to see.
Biometrics provides another example. Widely accepted as a stronger authentication mechanism than passwords, even biometrics cannot be the entire solution. Biometric mechanisms must sometimes be bypassed for entirely legitimate reasons. “I burned my hand and it’s all bandaged up, so I can’t use the fingerprint machine. Can you let me in just this once?” “I just had a cataract operation and I have to wear an eye patch, so how do I do an iris scan?” Any opening for legitimately bypassing normal proce- dures opens the door for illegitimate bypasses. Even if technology cannot be fooled (and it almost always can be), the people behind the technology can be fooled.
Sometimes problems occur because the pressures on individuals dif- fer from the stated goals of the organization. When people are asked to follow arduous security requirements while at the same time maintaining efficient and productive work schedules, there can be conflicts. Workers must choose which is of greatest importance. Quite often it is the work schedule that is given priority, and although this is not unreasonable, it
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
85INVESTING IN INFORMATION TECHNOLOGY RESEARCH
occurs at the cost of security. The proper goal is to design systems and procedures in which these are not in conflict.
In short, there is a terrible trade-off: the very things that make secu- rity more secure are often those that make our lives more difficult, or in some cases, impossible. When human and organizational factors are not taken into account in system design and development, the measures in- tended to increase security may reduce it because dedicated, concerned workers will thwart such measures in order to get their jobs done. Realis- tic security is cognizant of human and organizational behavior.
Plan for People Who Want to Be Helpful
Crooks, thieves, criminals, and terrorists are experts at exploiting the willingness of people to be helpful—a process usually known as “social engineering.” These adversaries use people to help them understand how to use the onerous technology, and they use people by taking advan- tage of situations that cause breakdowns in normal procedures. In short, they help human error to occur.
For example, badges are often required for entry into a secure facility. However, entry can usually be obtained in the following manner: Walk up to the door carrying an armload of computers, parts, and dangling cords. Ask someone to hold the door open, and thank them. Carry the junk over to an empty cubicle, look for the password and log-in name that will be on a Post-it note somewhere, and log in. If you cannot log in, ask someone for help. As one guide for hackers puts it, “Just shout, ‘Does anyone remember the password for this terminal?’ . . . you would be surprised how many people will tell you.”88
A firefighter who needed to know the security code to get in a secure building through the back door might call the management office of the building and say:
Hey, this is Lt. John Hennessy from Firehouse 17. This is a Code 73 emergency. There are people screaming behind the doors, the building is going to collapse—what’s the security code? Hurry, I’m losing my signal. Hello? Hello? Better hurry. [Sounds of screaming and other loud noises in background.]
A terrorist who needed to know the security code to enter a secure building through the back door would call and say:
88“The Complete Social Engineering FAQ.” Available online at <http://morehouse.org/ hin/blckcrwl/hack/soceng.txt>.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
86 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Hey, this is Lt. John Hennessy from Firehouse 17. This is a Code 73 emergency. There are people screaming behind the doors, the building is going to collapse—what’s the security code? Hurry, I’m losing my signal. Hello? Hello? Better hurry. [Sounds of screaming and other loud noises in background.]
Times of stress and emergency, when security is perhaps of most importance, are exactly the times when the strains are the greatest and the need for normally nonauthorized people (such as firefighters, police, res- cue and health personnel) to gain access is acute. And this is when it is easiest for a terrorist to get in, using the same mechanisms.
Countering social engineering by an adversary is an important counterterrorist technique. But whatever the counter, the solution must not be based on extinguishing the tendencies of people to be helpful. The reason is that helpful people often play a key role in getting any work done at all—and thus the research challenge is to develop effective tech- niques for countering social engineering that do not require wholesale attacks on tendencies to be helpful.
Understand Bystander Apathy
As more people are involved in checking a task, it is possible for safety to decrease. This is called the “bystander apathy” problem, named after studies of a New York City crime in which numerous people wit- nessed an incident but no one helped and no one reported it. Laboratory studies showed that the greater the number of people watching, the lower the likelihood that anyone would help—the major reason being that each individual assumes that if an incident is serious, someone else out of all those watching will be doing something, so the fact that nobody is doing anything means that it must not be a real issue. After all, in New York, anything might be happening: it might be a movie shoot. Similarly, if I am asked to check the meter readings of a technician, and I know that the immediate supervisor has already checked them and that someone else will check my report, I don’t take the check all that seriously: after all, how could a mistake get through with so many people involved? I don’t have to worry. But what if everyone feels that way?
The commercial aviation community has done an excellent job of fighting this tendency with its program of crew resource management (CRM). In CRM, the pilot not flying is required to be an active critic of the actions taken by the pilot who is flying. And the pilot flying is supposed to thank the other for the criticism, even when it is incorrect. Obviously, getting this process in place was difficult, for it involved major changes in the culture, especially when one pilot was junior, the other very senior. But the result has been increased safety in the cockpit.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
87INVESTING IN INFORMATION TECHNOLOGY RESEARCH
Account for Cognitive and Perceptual Biases
The research literature in cognitive and social psychology clearly dem- onstrates that most people are particularly bad at understanding low- probability events. This might be the “one-in-a-million” problem. An airplane pilot might well decide that the situation of three different oil pressure indicators all reading zero oil pressure is likely fallacious, be- cause it is a “one-in-a-million” chance that all three engines would fail at the same time. However, since there are roughly 10 million commercial flights a year in the United States, one-in-a-million means that 10 flights a year will suffer from this problem.
On the other hand, salient events are overestimated in frequency. Thus, aviation is considered more dangerous than automobile driving by many people, despite the data that show just the opposite. What about terrorist acts? These are truly unlikely, deadly though each may be, but if airline passengers overreact, they are apt to attack and possibly seriously injure an innocent passenger who meets some of their preconceptions of a terrorist. Indeed, each successful encounter between passengers and po- tential harrowers increases the likelihood of a future false encounter.
The “boy who cried wolf” is a third perceptual bias—potential threats are often ignored because of a history of false alarms. An effective crimi- nal or terrorist approach is to trigger an alarm system repeatedly so that the security personnel, in frustration over the repeated false alarms, either disable or ignore it—which is when the terrorist sneaks in.
Probe and Test the System Independently
The terms “red team” and “tiger team” refer to efforts undertaken by an organization to test its security from an operational perspective using teams that simulate what a determined attacker might do. Tiger teams develop expertise relevant to their intended targets, conduct reconnais- sance to search for security weaknesses, and then launch attacks that exploit those weaknesses. Under most circumstances, the attack is not intended to be disruptive but rather to indicate what damage could have been done. Properly conducted tiger-team testing has the following char- acteristics:
• It is conducted on an unscheduled basis without the knowledge of the installation being probed, so that a realistic security posture can be tested.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
88 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
• It does not function under unrealistic constraints about what it can or cannot do, so its attack can realistically simulate what a real attacker might do.
• It reports its results to individuals who are not directly responsible for an installation’s security posture so that negative results cannot be suppressed.
• It probes and tests the fundamental assumptions on which security planning is based and seeks to violate them in order to create unexpected attacks.
Why are tiger teams a “people and organization” issue? The essential reason is that an attacker has the opportunity to attack any vulnerable point in a system’s defenses, whether that point of vulnerability is the result of an unknown software bug, a misconfigured access control list, a password taped to a terminal, lax guards at the entrance to a building, or a system operator trying to be helpful.
Over the years, tiger teams have been an essential aspect of any secu- rity program, and tiger-team tests are essential for several reasons:
• Recognized vulnerabilities are not always corrected, and known fixes are frequently found not to have been applied as a result of poor configuration management.
• Security features are often turned off in an effort to improve opera- tional efficiency. Such actions may improve operational efficiency, but at the potentially high cost of compromising security, sometimes with the primary damage occurring in some distant part of the system.
• Some security measures rely on procedural measures and thus depend on proper training and ongoing vigilance on the part of com- manders and system managers.
• Security flaws that are not apparent to the defender undergoing an inspection may be uncovered by a committed attacker (as they would be uncovered in an actual attack).89
In order to maximize the impact of these tests, reports should be disseminated widely. The release of such information may cause embar- rassment of certain parties or identify paths through which adversaries may attack, but especially in the case of vulnerabilities uncovered for which fixes are available, the benefits of releasing such information— allowing others to learn from it and motivating fixes to be installed— generally outweigh these costs. Furthermore, actions can be taken to mini-
89CSTB, NRC, 1999, Realizing the Potential of C4I, p. 147.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
89INVESTING IN INFORMATION TECHNOLOGY RESEARCH
mize the possibility that adversaries might be able to obtain or use such information. For example, passing the information to the tested installa- tion using nonelectronic means would eliminate the possibility that an adversary monitoring electronic channels could obtain it. Delaying the public release of such information for a period of time could allow the vulnerable party to fix the problems identified.
Finally, tiger-team testing launched without the knowledge of the attacked systems also allows estimates to be made of the frequency of attacks. Specifically, the fraction of tiger-team attacks that are detected is a reasonable estimate of the fraction of adversary attacks that are made. Thus, the frequency of adversary attacks can be estimated from the num- ber of adversary attacks that are detected.
3.6.2 Organizational Practices in IT-Enabled Companies and Agencies
An organization’s practices play an important role in countering ex- ternal threats. The discussion below is not meant in any way to be ex- haustive but rather to motivate examination of yet another nontechno- logical dimension of security.
Outsourcing of Product Development and Support
For entirely understandable reasons, many companies outsource IT work to parties whose interests may not be fully aligned with their own. Companies outsource for many reasons, ranging from the availability of skilled human resources that are not indigenous to them to the often- lower cost of doing so (especially when the parties doing the outsourced work have access to cheaper sources of labor).
The practice of outsourcing has security implications. On the one hand, outsourced work represents a potential vulnerability to the com- pany that uses such work, unless that company has the expertise to audit and inspect the work for security flaws. By assumption, a company that outsources work has less control over how the work is done, and the possibility of deliberately introduced security vulnerabilities in out- sourced work must be taken seriously. On the other hand, one reason for outsourcing work is that those doing the work may have greater expertise than the company hiring them—and if security is a special expertise of the former, its capabilities for maintaining security may be greater than that of the latter.
Outsourcing is not in and of itself a practice that leads to insecure IT systems and networks. Nevertheless, prudence dictates that a company understand the potential risks and benefits of outsourcing from a security
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
90 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
perspective. If it does outsource work, a company should undertake careful and informed inspection of the work on system components that provide critical functionality.
Personnel Screening
Behavioral and psychological profiles of typical outside “hackers” have been available for a long time, providing insight into their motiva- tions and techniques. However, similar information about persons likely to present an insider threat is not available today. One challenge to as- sembling such information is the fact that insider adversaries can be char- acterized in many different ways. For example, the behavior of the in- sider will likely vary depending on a wide variety of factors, including whether the person is unwitting, incompetent, coerced, vengeful, and so on. Such factors imply that simply relying on externally observable traits and behaviors in order to identify potential insiders may not prove use- ful, and so integration with background information on individual em- ployees may be necessary to identify potential risks from insiders. Note also that all screening techniques run the risk of incorrectly labeling prob- lematic behavior acceptable or of determining benign behavioral patterns to be indicative of inappropriate behavior or intent.
Managing Personnel in a Security-Oriented Environment
Managing employees in a security-oriented environment is complex. The practices that characterize the handling of classified information of- ten impede the sharing of information among people. Long-term compli- ance with security procedures is often difficult to obtain, as employees develop ways to circumvent these procedures in order to achieve greater efficiency or effectiveness. Personnel matters that are routine in nonsecure environments become difficult. For example, from a security perspective, termination of the access privileges of employees found to be improperly hired or retained must happen without warning them of such termina- tion. On the other hand, due process may prevent rapid action from being taken. The temptations are strong to relax the requirements of due process for security, but not observing due process often has detrimental effects on organizational morale and esprit de corps,90 not to mention the possibility that almost any pretext will suffice for some individual super- visors to eliminate workers they do not personally like.
90Illustrations of the conflict between applying due process and managing the require- ments of security can be found in the cases of Wen Ho Lee and Felix Bloch. In investigating the alleged passing of nuclear weapons design information to the People’s Republic of
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
91INVESTING IN INFORMATION TECHNOLOGY RESEARCH
Many issues arise when an employee is merely under suspicion for wrongdoing or malicious intent—before action is taken to rescind access privileges, the company may run a significant risk of suffering significant damage. This suggests that under these circumstances, the work of the employee must be monitored and controlled, but at the same time the requirements of due process must be observed.
3.6.3 Dealing with Organizational Resistance to Interagency Cooperation
An effective response to a serious terrorist incident will inevitably require the multiple emergency-response agencies to cooperate. Section 3.2.1 describes technical barriers to effective cooperation, but technologi- cal limitations by no means explain why agencies might fail to cooperate effectively.
Specifically, it is necessary to note that the character and traditions of agencies have a profound impact on their ability and willingness to coop- erate. Different agencies exhibit many differences in internal cultures (e.g., in philosophies of staff reward and punishment, in traditions among disciplines in research and implementation, in ethical criteria of staff in terms of private versus public interest, in performance criteria between public and profit-making enterprises, and in degree of participatory deci- sion making). Turf battles and jurisdictional warfare between agencies with overlapping responsibilities are also common, with each agency hav- ing its own beliefs about what is best for the citizenry.
For the public record, the rhetoric of every emergency-response agency acknowledges the need for cooperation with other agencies. But the reality in practice is often quite different from the rhetoric, and in practice almost every disaster (whether natural or attack-related) reveals shortcomings in the extent and nature of interagency cooperation.
China, Lee was charged on multiple counts of mishandling material containing restricted data with the intent to injure the United States and with the intent to secure an advantage to a foreign nation. After being charged, Lee was held in custody under conditions described by the cognizant federal judge as draconian, because it was believed that his pretrial release would pose a grave threat to the nation’s security. The case ended with the dismissal of all but one charge of mishandling classified information and with the judge’s apology for the conduct of the government in the prosecution of this case. Felix Bloch was a Foreign Service officer in the State Department, investigated in 1989 by the FBI for spying for the Soviet Union. Bloch was eventually fired and stripped of his pension in 1990 on grounds that he lied to FBI investigators, but he was never charged. It is alleged that Robert Hanssen gave information to the Soviets revealing that Bloch was under suspicion, which might account for the fact that sufficient grounds for charging Bloch were never found.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
92 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
For example, the emergency response to the September 11, 2001, at- tacks on the World Trade Center revealed a number of cultural barriers to cooperation in the New York City Police and Fire Departments:91
• Police helicopters, with the ability to provide firefighters close-up information on the progress of the fire in the upper parts of the buildings as well as some aerial rescue capability of those gathered on the roofs, were never used for those purposes. An on-site Fire Department chief tried to request police helicopters for such roles but was unable to reach the police dispatcher for the helicopters either by phone or radio. Fur- thermore, the Fire Department had established its command post in the building lobbies, while the police had established their command post three blocks away, and the police did not report to the Fire Department commanders on-site. Said one senior Fire Department official, “They [the police] report to nobody and they go and do whatever they want.”
• The Police and Fire Departments have a formal agreement (in place since 1993) to share police helicopters during high-rise fires and to prac- tice together. However, neither agency has any records of joint drills, although some less formal “familiarization flights” may have been con- ducted for the Fire Department a year or so before September 11.
• While most states and the federal government have forged agree- ments among emergency-response agencies that specify in advance who will be in overall charge of a crisis response, New York City has no such agreement, which left its Police and Fire Departments with no guidance about how to proceed with overall command arrangements on September 11.
• Police fault firefighters and firefighters fault police for unwilling- ness to cooperate. Some police believe that sharing command with the Fire Department is difficult because firefighters lack paramilitary disci- pline characteristic of the police force, while some firefighters thought that the police felt they could and should do everything.
• In the aftermath, senior Fire Department and Police Department officials disagreed over the extent to which the departments were able to coordinate. A senior Fire Department official said that “there is no ques- tion there were communications problems [between the Fire Department and the Police Department] at this catastrophic incident,” while a senior Police Department official said, “I was not made aware that day that we were having any difficulty coordinating.”
91See Jim Dwyer, Kevin Flynn, and Ford Fessenden. 2002. “9/11 Exposed Deadly Flaws in Rescue Plan.” New York Times, July 7. Available online at <http://www.nytimes.com/ 2002/07/07/nyregion/07EMER.html?pagewanted=1>.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
93INVESTING IN INFORMATION TECHNOLOGY RESEARCH
Cultural barriers separating the CIA and the FBI have also been re- vealed in the postmortems that have been conducted since September 11. In particular, the essential mission of the CIA is one of intelligence collec- tion and analysis, while the essential mission of the FBI has been directed toward law enforcement. As a broad generalization, these missions differ in that intelligence is more focused on anticipating and predicting bad events, while law enforcement is more focused on prosecutions and hold- ing perpetrators of dangerous events accountable to a criminal justice system. To illustrate, intelligence analysts place a high value on protect- ing sources and methods for gathering intelligence so that they will be able to continue obtaining information from those channels, while law- enforcement officials place a high value on the ability to use information in open court to gain convictions. (The fact that the FBI and CIA also operate under very different legal regimes governing their domestic ac- tivities is also quite relevant, but beyond the scope of this report. Suffice it to say that these different legal regimes impose explicit behavioral con- straints and serve to shape the environment in which the cultural atti- tudes within each agency develop.)
Desires of agencies to preserve their autonomy also contribute to an active (if subterranean) resistance to interoperability. Personnel of one agency without the capability of communicating with another agency are not easily directed by that other agency. Furthermore, an agency may have a fear (often justified) that communications overheard by another agency will lead to criticism and second-guessing about actions that it took in the heat of an emergency.
There are no easy answers for bridging cultural gulfs between agen- cies that do not interact very much during normal operations. Different agencies with different histories, different missions, and different day-to- day work would be expected to develop different policies, procedures, and philosophies about what is or is not appropriate under a given set of circumstances.
For the most part and under most circumstances, an agency’s culture serves it well. But in crisis, interagency differences impede interagency cooperation, and they cannot be overcome by fiat at the scene of the crisis. For example, a policy directive requiring that agencies adopt and use common communications protocols does not necessarily require emer- gency responders from different agencies to actually interact with one another while an emergency response is occurring.
3.6.4 Principles into Practice
Putting these principles into practice requires that the human require- ments be considered equally with technical and security requirements.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
94 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
The most secure and reliable systems will be those developed with behav- ioral scientists from the user interface community who use an iterative design-test-design implementation strategy.
The major point is to recognize that security and reliability are sys- tems problems: the needs and standard working practices of the people involved are as important as the technical requirements. The very virtues of people are often turned against them when intruders seek to broach security: the willingness to help others in distress is perhaps the weakest link of all in any defensive system, but it would be preferable to design security systems that detract minimally from this valuable human at- tribute. Many failures are due to security requirements that are unreason- able from the point of view of human cognition (e.g., asking for frequent memorization of long, complex passwords) or that severely impact the ability to get the required work done because they conflict with the orga- nizational structures and requirements. It is therefore essential that the needs of the individuals, the workgroups, and the organization all be taken into account. Conscientious workers will do whatever is necessary to get the work done, often at the cost of compromising security. But through proper design, it should be possible to design systems that are both more efficient and more secure.
To achieve effective interagency cooperation in crisis, many things must happen prior to the occurrence of crisis, taking into account the realities of organizational resistance to interoperability. Such cooperation is likely to require:
• Strong, sustained leadership. When a strong leader places a high priority on interagency cooperation, is willing to expend resources and political capital in support of such cooperation, and can sustain that ex- penditure over a time long enough so that the agencies in question cannot “outwait” his or her efforts, organizational change that moves in the di- rection of that priority is more likely.
• Activities that promote interagency understanding and cooperation. One example of such activities is the temporary detailing of personnel from one agency to another (e.g., firefighters and police officers or FBI and CIA analysts on temporary duty at each other’s agencies). Prior exposure to one another’s operational culture generally helps to reduce frictions that are caused by lack of familiarity during a crisis. Of course, to be genuniely helpful, this practice must be carried out on a sufficiently large scale that the personnel so exposed are likely to be those participating in a response to a crisis. Another useful activity is joint exercises that simulate crisis response. As a rule, exercises that involve most or all of the agencies likely to be responding in a disaster—and that use the IT infrastructure that they are expected to use—are an essential preparation for effective
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
95INVESTING IN INFORMATION TECHNOLOGY RESEARCH
interagency cooperation.92 Exercises help to identify and solve some social, organizational, and technical problems, and they help to reveal the rivalries and infighting between agencies whose resolution is important to real progress in this area. To the extent that the agencies and personnel involved in an exercise are the same as those involved in the response to a real incident, exercises can help the response to be less ad hoc and more systematic. Other, less formal activities can also be conducted to improve interagency understanding. For example, personnel from one agency can be detailed to work in another agency in emergency-response situations. As a part of pre-service and in-service training, personnel from one agency can be posted to other agencies for short periods to develop contacts and to understand the operating procedures of those other agencies.
• Budgets that support interagency cooperation. For many agencies, battles of the budget are as important as their day-to-day operational responsibilities. This is not inappropriate, as adequate budget resources are a prerequisite for an agency’s success. Thus, it is simply unrealistic to demand cooperation from agencies without providing budget resources that are dedicated to that end. Note that budget resources support opera- tions (e.g., personnel and training matters) and the procurement of sys- tems, and both are relevant to interagency cooperation.
3.6.5 Implications for Research
The discussion in the previous sections has two purposes. One is to describe the operational milieu into which technology is deployed—a warning that human beings are an essential part of any operational sys- tem and that system design must incorporate sophisticated knowledge of human and organizational issues as well as technical knowledge. A sec- ond purpose is to develop a rationale for research into human and organi- zational issues relating to technology in a counterterrorism context.
Research in this area will be more applied than basic. The social sciences (used broadly to include psychology, anthropology, sociology, organizational behavior, human factors, and so on) have developed a significant base of knowledge that is relevant to the deployment of IT- based systems. But in practice, social scientists with the relevant domain expertise often lack applied skills and the requisite technical IT knowl-
92Despite the creation of New York City’s Office of Emergency Management in 1996 and expenditures of nearly $25 million to coordinate emergency response, the city had not conducted an emergency exercise between 1996 and September 11, 2001, at the World Trade Center—which had been bombed in 1993—that included the Fire Department, the police, and the Port Authority’s emergency staff.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
96 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
edge. Similarly, information technologists often lack the appropriate do- main knowledge and often use a system development process that makes it difficult to incorporate human and organizational considerations.
This point suggests that research is relevant in at least four different areas.
1. The formulation of system development methods that are more amenable to the incorporation of domain knowledge and social science expertise. The “spiral development” methodology for software development is an ex- ample of how user inputs and concerns can be used to drive the develop- ment process, but the method is hard to generalize to incorporate knowl- edge about the organizational context of use.
2. The translation of social science research findings into guidelines and methods that are readily applied by the technical community. The results of this research effort might very well be software toolboxes as well as a “Hand- book of Applied Social Science” or a “Cognitive Engineering Handbook” containing useful principles for system development and design derived from the social science research base.
3. The development of reliable security measures that do not interfere with what legitimate workers must do. These methods must minimize loads on human memory and attention and task interference while providing the appropriate levels of security in the face of adversaries who use sophisti- cated technologies as well as social engineering techniques to penetrate the security.
4. Understanding of the IT issues related to the disparate organizational cultures of agencies that will be fused under the Department of Homeland Secu- rity. This is a complex task, with difficult technical issues interspersed with complex procedural, permissions, and organizational issues requir- ing a mix of technical and social skills to manage. Operationally, the question is how to allow for the sharing of communication and data among different organizations that have different needs to know, differ- ing requirements, and different cultural and organizational structures, in a way that enhances the desired goals while maintaining the required security.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
97
4
What Can Be Done Now?
Developing a significantly less vulnerable information infrastructure is an important long-term goal for the United States. This long-term goal must focus on the creation of new technologies and paradigms for en- hancing security and reducing the impact of security breaches. In the short term, the committee believes that the vulnerabilities in the commu- nications and computing infrastructure of the first-responder network should receive focused attention. Efforts should concentrate on harden- ing first responders’ communications capability as well as those portions of their computing systems devoted to coordination and control of an emergency response. The committee believes that existing technology can be used to achieve many of the needed improvements in both the telecommunications and computing infrastructures of first responders. Unfortunately, the expertise to achieve a more secure system often does not reside within the host organizations—this may be the case, for ex- ample, in local and state government. These facts lead to two short-term recommendations.
Short-Term Recommendation 1: The nation should develop a pro- gram that focuses on the communications and computing needs of emer- gency responders. Such a program would have two essential func- tions:
• Ensuring that authoritative current-knowledge expertise and support re- garding information technology are available to emergency-response agencies prior to and during emergencies, including terrorist attacks. One implementa-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
98 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
tion option is to situate the mechanism administratively in existing gov- ernment or private organizations—for example, the National Institute of Standards and Technology, the Department of Homeland Security, the Department of Defense, the Computer Emergency Response Team of the Software Engineering Institute at Carnegie Mellon University. A second option is to create a national body to coordinate the private sector and local, state, and federal authorities.1 In the short term, a practical option for providing emergency operational support would be to exploit IT ex- pertise in the private sector, much as the armed services draw on the private sector (National Guard and reserve forces) to augment active- duty forces during emergencies. Such a strategy, however, must provide adequate security vetting for private-sector individuals serving in this emergency role and must also be a complement to a more enduring mechanism for providing ongoing IT expertise and assistance to emer- gency-response agencies.
• Upgrading the capabilities of the command, control, communications, and intelligence (C3I) systems of emergency-response agencies through the use of existing technologies and perhaps minor enhancements to them. One key ele- ment of such upgrading should be a transition from legacy analog C3I systems to digital systems. Of course, in the short term, this transition can only be started, but it is clear that it will be necessary over the long term to achieve effective communications capabilities. In addition, maintaining effective communications capability in the wake of a terrorist attack is a high priority, and some possible options for implementing this recom- mendation include a separate emergency-response communications net- work that is deployed in the immediate aftermath of a disaster and the use of the public network to support virtual private networks, with prior- ity given to traffic from emergency responders. (Table 4.1 describes some illustrative advantages and disadvantages of each approach.) Given the fact that emergency-response agencies are largely state and local, there is no federal agency that has the responsibility and authority over state and local responding agencies needed to carry out this recommendation. Thus, it is likely that a program of this nature would have to rely on incentives (probably financial) to persuade state and local responders to participate and to acquire new interoperable C3I systems.
1CSTB has a pending full-scale project on information and network security R&D that will address federal funding and structure in much greater detail than is possible in this report. See the Web site <http://www.cstb.org> for more information on this subject.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
99WHAT CAN BE DONE NOW?
TABLE 4.1 A Comparison of Separate Emergency Networks with Reliance on Surviving Residual Capacity
Emergency Illustrative Illustrative Network Advantage Disadvantage
Separate network deployed Provides high-confidence Would not be the system after an emergency assurance of known regularly used by personnel;
bandwidth availability. without continuous updates and training, they may not be able to use it properly in emergency settings.
Deployment of network may take too long.
Residual public-network Assures immediate Not possible to assure the capacity plus priority for availability of some availability of adequate emergency responders bandwidth because some bandwidth for emergency
part of the public network responders because is likely to survive any availability depends on the disaster. amount of surviving public
network.
Short-Term Recommendation 2: The nation should promote the use of best practices in information and network security in all relevant public agencies and private organizations. Nearly all organizations, whether in government or the private sector, could do much better with respect to information and network security than they do today, simply by exploiting what is already known about that subject today, as dis- cussed at length in Cybersecurity Today and Tomorrow: Pay Now or Pay Later.2 Users of IT, vendors in the IT sector, and makers of public policy can all take security-enhancing actions.
Users of IT in individual organizations are where the “rubber meets the road”—they are the people who must actually make the needed changes work. Only changes in operational practice and deployed tech- nology in individual organizations can have an impact on security, and
2Computer Science and Telecommunications Board (CSTB), National Research Council (NRC). 2002. Cybersecurity Today and Tomorrow: Pay Now or Pay Later. National Academy Press, Washington, D.C. (hereafter cited as CSTB, NRC, 2002, Cybersecurity Today and To- morrow). The discussion in that volume is based on extensive elaboration and analysis contained in various CSTB reports. including Computers at Risk (1991), Trust in Cyberspace (1999), and Realizing the Potential for C4I (1999), among others.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
100 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
the parties responsible for taking action range from chief technical (or even executive) officers to system administrators. Individual organiza- tions can and should:
• Establish and provide adequate resources to an internal entity with responsibility for providing direct defensive operational support to sys- tem administrators throughout the organization . . . . To serve as the focal point for operational change, such an entity must have the author- ity—as well as a person in charge—to force corrective action. • Ensure that adequate information-security tools are available, that everyone is properly trained in their use, and that enough time is avail- able to use them properly. Then hold all personnel accountable for their information system security practices . . . . • Conduct frequent, unannounced red-team [tiger-team] penetration testing of deployed systems and report the results to responsible man- agement . . . . • Promptly fix problems and vulnerabilities that are known or that are discovered to exist . . . . • Mandate the organization-wide use of currently available network/ configuration management tools, and demand better tools from vendors . . . . • Mandate the use of strong authentication mechanisms to protect sen- sitive or critical information and systems . . . . • Use defense in depth. In particular, design systems under the as- sumption that they will be connected to a compromised network or a network that is under attack, and practice operating these systems un- der this assumption. • Define a fallback plan for more secure operation when under attack and rehearse it regularly. Complement that plan with a disaster-recov- ery program.3
Vendors of IT systems and services have key roles to play in improv- ing the security functionality of their products. Such vendors should:
• Drastically improve the user interface to security, which is [virtually] incomprehensible in nearly all of today’s systems . . . . Users and ad- ministrators must be able to easily see the current security state of their systems; this means that the state must be expressible in simple terms. • Develop tools to monitor systems automatically for consistency with defined secure configurations, and enforce these configurations. . . . Ex- tensive automation is essential to reduce the amount of human labor
3CSTB, NRC, 2002, Cybersecurity Today and Tomorrow, p. 13.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
101WHAT CAN BE DONE NOW?
that goes into security. The tools must promptly and automatically re- spond to changes that result from new attacks. • Provide well-engineered schemes for user authentication based on hardware tokens . . . . These systems should be both more secure and more convenient for users than are current password systems. • Develop a few simple and clear blueprints for secure operation that users can follow, since most organizations lack the expertise to do this properly on their own. For example, systems should be shipped with security features turned on, so that a conscious effort is needed to dis- able them, and with default identifications and passwords turned off, so that a conscious effort is needed to select them . . . . • . . . [c]onduct more rigorous testing of software and systems for secu- rity flaws, doing so before releasing products rather than use customers as implicit beta testers to . . . [uncover] security flaws . . . .4 Changing this mind-set is one necessary element of an improved . . . posture [for information and network security].5
In addition, vendors should provide individual consumers with easy- to-use, default-on security tools and features to secure home computers and networks. Because home computers can play a significant role in attacks against cyber infrastructure, actions securing this diffuse infra- structure could help to reduce the potential threat it poses.
Makers of public policy have an important role in securing critical government IT systems and networks. The Office of Management and Budget (OMB) has sought to promote government information and net- work security in the past, but despite its actions, the state of information and network security in government agencies remains highly inadequate. In this regard, the administration and Congress can position the federal government as a leader in technology use and practice by requiring agen- cies to adhere to the practices recommended above and to report on their progress in implementing those measures.6 Such a step would also help to grow the market for security technology, training, and other services.
4“Note that security-specific testing of software goes beyond looking at flaws that emerge in the course of ordinary usage in an Internet-connected production environment. For example, security-specific testing may involve very sophisticated attacks that are not widely known in the broader Internet hacker community.”
5CSTB, NRC, 2002, Cybersecurity Today and Tomorrow, pp. 13-14. 6This concept has been implicit in a series of laws, beginning with the Computer Security
Act of 1987, and administrative guidance (e.g., from OMB and more recently from the Federal Chief Information Officers Council). Although it has been an elusive goal, move- ments toward e-government have provided practical, legal, and administrative impetus. For more discussion, see Computer Science and Telecommunications Board, National Re- search Council. 2002. Information Technology Research, Innovation, and E-Government. Na- tional Academy Press, Washington, D.C.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
102 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 4.1 A Comparison of Fire Safety with Information and Network Security
Today’s fire codes seek to provide a certain level of safety against fire in build- ings, and there is broad acceptance of the idea that compliance with fire codes results in buildings that are safer against fire than those that are not compliant. Fire codes are also developed and enforced by government regulation. A reasonable question is, Why can’t the same kind of regulation be used to improve information and network security?
Fire safety and information and network security are very different in certain key dimensions:
• Intentionality. Most fires are accidental, and hence the fire code is not primarily concerned with the deliberate bypassing of fire safety measures. Arson presents a very different problem (fortunately rare compared to the accidents that account for the majority of fires), and if arson were the primary problem in fire safety, fire codes would look very different indeed—and would likely be much less effective at making buildings safer than they are in today’s environment. However, in the area of information and network security, most system penetrations are deliberate, and so information and network security is much more like protecting against arson than protecting against accidental fires.
• Monoculture versus diversity. A building code seeks to standardize the con- struction of buildings in ways that improve fire resistance. But standardization re- garding safety measures in buildings is useful only when the threats to buildings (in this case, the threat of fires in each of the buildings in question) are independent and uncorrelated. That is, the ways in which fires can start are highly varied, and so measures that are ineffective against one type of fire may well be useful against another type. In the case of information and network security for a largely homoge- neous environment, the threat is highly correlated—an attacker who develops tech- niques for penetrating the security measures of one system knows how to penetrate the security measures of many.
• The rate of change in the underlying technologies. Buildings have existed for many years, and fire has been known to be a threat for a long time. Buildings take
As for the private sector, there is today no clear locus of responsibility within government to undertake the “promotion” of security across the private sector, because neither information and network security in the private sector nor IT products and services are subject today to direct government regulation.7 This will not necessarily always be true, but for
7In this context, “direct regulation” is taken to mean government-issued mandates about what the private sector must do with respect to cybersecurity.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
103WHAT CAN BE DONE NOW?
a long time to design and construct, and the techniques for designing and construct- ing them are relatively stable. By contrast, information technology changes rapidly. Thus, the computer and network systems being protected change quickly, their vul- nerabilities change quickly, and the threat changes quickly.
• Visibility of damage. As a rule, fires create visible damage. But the damage to a computer system or a network may be entirely invisible; indeed, a system that fails to operate normally is only one possible result of an attack on it. A successful attack may lay the foundation for later attacks (e.g., by installing Trojan horse pro- grams that can be subsequently activated), or it may be set to cause damage well after the initial penetration, or enable the clandestine and unauthorized transmission of sensitive information stored on the attacked system (e.g., password files).
• The underlying science. The science underlying fire safety is much better understood and developed than that underlying information and network security. For example, it is understood how to build a fire-resistant structure from first princi- ples. One might specify the use of steel beams that lose structural integrity at a certain temperature. Finite-element analysis based on a sound underlying mathe- matics enables reliable predictions to be made about structural loading. But no such science underlies information and network security and the development of secure systems and networks.
• The availability of metrics. In fire codes, it is meaningful to specify that a building must resist burning for a certain period of time. But there is no comparable metric to specify how long a computer system or network must be able to resist an intruder. More generally, there is no quantitative basis for understanding how much security is made available by the addition of any particular feature in computer or network design.
These important differences should not be taken to mean that nothing is known about information and network security—and as discussed in the main text, there are common sense measures that can be taken that do improve such security. But direct regulation is always more difficult to impose when the benefits are uncertain and/or difficult to articulate, and for this reason, those who wish to impose direct regulation to improve information and network security face many difficulties that warrant thought and deliberation.
a number of reasons (described in Box 4.1), the realities of information and network security make it less amenable to government regulation than other fields such as fire or automobile or flight safety.
In addition, the committee notes that the IT sector is one over which the federal government has little leverage. IT sales to the government are a small fraction of the IT sector’s overall revenue, and because IT purchas- ers are generally unwilling to acquire security features at the expense of performance or ease of use, IT vendors have little incentive to include security features at the behest of government alone. Indeed, it is likely
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
104 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
8Another potentially important aspect of the government’s nonregulatory role, a topic outside the scope of this report, is the leadership role that government itself could play with respect to information and network security. For more discussion, see CSTB, NRC, 2002, Cybersecurity Today and Tomorrow.
9 CSTB, NRC, 2002, Cybersecurity Today and Tomorrow. 10CSTB, NRC, 2002, Cybersecurity Today and Tomorrow.
that attempts at such regulation will be fought vigorously, or may fail, because of the likely inability of a regulatory process to keep pace with rapid changes in technology.
Thus, appropriate market mechanisms could be more successful than direct regulation in improving the security of the nation’s IT infrastruc- ture, even though the market has largely failed to provide sufficient in- centives for the private sector to take adequate action with respect to information and network security. The challenge for public policy is to ensure that those appropriate market mechanisms develop. How to deal constructively with prevailing market dynamics has been an enduring challenge for the government, which has attempted a variety of programs aimed at stimulating supply and demand but which has yet to arrive at an approach with significant impact.
Nevertheless, the committee believes that public policy can have an important influence on the environment in which nongovernment orga- nizations live up to their responsibilities for security. One critical dimen- sion of influencing security-related change is the federal government’s nonregulatory role, particularly in its undertaking of research and devel- opment of the types described above.8 Such R&D might improve secu- rity and interoperability, for example, and reduce the costs of implement- ing such features—thereby making it less painful for vendors to adopt them.
Other policy responses to the failure of existing incentives to cause the market to respond adequately to the security challenge are more con- troversial. If the market were succeeding, there would be a significant private sector demand for more security in IT products, and various IT vendors would emphasize their security functionality as a competitive advantage and product differentiator, much as additional functionality and faster performance are featured today. But this is not the case. Pos- sible options to alter market dynamics in this area include:
• Increasing the exposure of software and system vendors and sys- tem operators to liability for system breaches;9
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
105WHAT CAN BE DONE NOW?
• Mandatory reporting of security breaches that could threaten criti- cal societal functions;10
• Changing accounting procedures to require sanitized summaries of information-security problems and vulnerabilities to be made public in shareholder reports; and
• Encouraging insurance companies to grant preferential rates to companies whose IT operations are regarded as meeting certain security standards of practice.
Note, however, that there are disadvantages as well as advantages to any of these specific options, and a net assessment of their ultimate desir- ability remains to be undertaken.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
106
5
Rationalizing the Future Research Agenda
As noted in Chapter 3, the committee believes that the IT research areas of highest priority for counterterrorism are in three major areas: information and network security,1 information technologies for emer- gency response, and technologies for information fusion. Within each of these areas, a reasonably broad agenda is appropriate, as none of them can be characterized by the presence of a single stumbling block or im- pediment whose removal would allow everything else to fall into place.
Attention to human and organizational issues in a counterterrorism context is also critical. Insight, knowledge, and tools that result from such attention are likely to be much more relevant to systems integration than to technology efforts devoted to proofs-of-principle or other technology development issues. However, that fact does not mean that there is no role for research, especially since system development methodologies that incorporate such tools are scarce or nonexistent. Thus, the engagement of social scientists (e.g., psychologists, anthropologists, sociologists, organi- zational behavior analysts) will be important in any research program in IT for counterterrorist purposes.
Based on the discussion in Chapter 3, Box 5.1 summarizes some of the
1Further discussion of a broader research agenda on information and network security can be found in CSTB’s Computers at Risk (1991) and Trust in Cyberspace (1999). Though these reports were issued several years ago, their comments on a relevant research agenda remain pertinent today, reflecting the reality that the information-security field has not advanced much in the intervening years.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
107RATIONALIZING THE FUTURE RESEARCH AGENDA
topics within these areas that the committee believes would be fruitful to research. It is useful to note that progress in these areas would have commercial applications as well in many cases. The fruits of information and network security research would benefit all users of information tech- nology, though their particular relevance to providers of critical infra- structure is obvious. Emergency responders will be the primary benefi- ciaries of research that focuses on their particular needs. Progress in information fusion has relevance across the spectrum of counterterrorism efforts, from prevention to detection to response, and indeed to informa- tion mining for other public and private purposes. (A point of particular interest is the fact that information-fusion efforts for countering bioter- rorism have significant applicability to public health, especially with re- spect to the early identification of “natural” disease outbreaks.) Advances in developing tools to incorporate knowledge about human and organi- zational factors in systems integration would be relevant to the deploy- ment of most large IT-based systems.
The fact that research in these areas may have commercial relevance raises for some questions about the necessity of government involvement. As noted in Chapter 4, the commercial market has largely failed in pro- moting information and network security. In other cases, the research program required (e.g., research addressing the needs of emergency re- sponders) is of an applied nature—and focused on counterterror applica- tions. As for information fusion, it is highly likely that its applications will have commercial applications once new technologies are developed, but whether those new technologies would develop in the absence of government-supported research and become broadly available is another question entirely.
Most of these technology research areas are not new. Efforts have long been under way in information and network security and informa- tion fusion, though additional research is needed because the resulting technologies are not sufficiently robust or effective, they degrade perfor- mance or functionality too severely, or they are too hard to use or too expensive to deploy. Moreover, given the failure of the market to ad- equately address security challenges, adequate government support for R&D in information systems and network security is especially impor- tant. Information technologies for emergency response have not received a great deal of attention, though efforts in other contexts (e.g., military operations) are intimately related to progress in this area.2
2Military communications and civilian emergency-response communications have simi- larities and differences. Military forces and civilian agencies share the need to deploy emergency capacity rapidly, to interoperate, and to operate in a chaotic environment. But while military communications must typically work in a jamming environment or one in
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
108 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 5.1 Illustrative Topic Areas for Long-Term Research
Authentication, Detection, Identification
• Develop fast and scalable methods for high-confidence authentication. • Explore approaches that could self-monitor traffic and users to detect either
anomalous users or unusual traffic patterns. • Develop intruder-detection methods that scale to function efficiently in large
systems.
Containment
• Develop the tools and design methodologies for systems and networks that support graceful degradation in response to an attack.
• Develop mechanisms to contain attackers and limit damage rather than completely shutting down the system once an intrusion is detected.
• Explore how to fuse a simple, basic control system used during “crisis mode” with a sophisticated control system used during normal operations.
Recovery
• Develop schemes for backing up large systems, in real time and under “hos- tile” conditions, that can capture the most up-to-date, but correct, snapshot of the system state.
• Create new decontamination approaches for discarding as little good data as possible and for removing active and potential infections on a system that cannot be shut down for decontamination.
Cross-cutting Issues in Information and Network Security
• Develop tools that support security-oriented systems development. • Find new ways to test bug fixes reliably. • Develop better system-administration tools for specifying security policies
and checking against prespecified system configurations. • Create new tools to detect added and unauthorized functionality. • Develop authentication mechanisms that provide greater security and are
easier to use. • Create and employ metrics to determine the improvement to system security
resulting from the installation of a security measure. • Monitor and track emerging types of attack and explore potential conse-
quences of such attacks. • Understand why previous attempts to build secure systems have failed and
recommend how new efforts should be structured to be more successful.
C3I Systems for Emergency Response
• Understand how to transition gracefully and with minimal disruption from a unit-specific communication system to a systemwide structure.
• Define new communication protocols and develop generic technology to facilitate interconnection and interoperation of diverse information sources.
• Develop approaches for communication systems to handle surge capacity and function in a saturated state.
• Develop methods to provide more capacity for emergency communication and coordination.
• Create self-adaptive networks that can reconfigure themselves as a function of damage and changes in demand and that can degrade gracefully.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
109RATIONALIZING THE FUTURE RESEARCH AGENDA
• Understand the special security needs of rapidly deployed wireless net- works.
• Develop decision-support tools to assist the crisis manager in making deci- sions based on incomplete information.
• Explore mechanisms to provide information tailored to specific individuals or locations through location-based services.
• Establish more effective means of communicating the status of affected peo- ple to those outside the disaster area.
• Develop robust sensors and underlying architectural concepts to track and locate survivors as well as to identify and track the spread of contaminants.
• Create digital floor plans and maps of other physical infrastructure, and use wearable computers and “map ants” to generate maps that can be updated.
• Develop tools to map network topology, especially of converged networks that handle voice and data traffic.
• Begin to characterize the functionality of regional networks for emergency responders.
Information Fusion for Counterterrorism
• Develop more effective machine-learning algorithms for data mining, in- cluding learning for different data types (text, image, audio, video).
• Develop methods for systems to learn when data are scarce. • Create better mixed-initiative methods that allow the user to visualize the
data and direct the data analysis. • Explore new methods to normalize and combine data from multiple sources. • Create methods to extract structured information from text. • Build approaches to handle multiple languages. • Improve algorithms for image interpretation, speech recognition, and inter-
pretation of other sensors (including perception based on mixed media). • Extend, and test extensively in more demanding applications, the principle-
based methods for reasoning under uncertainty. • Develop techniques for machine-aided query formulation. • Develop visualization techniques that are well-adapted for unstructured
data.
Privacy and Confidentiality
• Understand the impact on confidentiality of different kinds of data disclosure. • Develop data-mining algorithms that can be used without requiring full dis-
closure of individual data records.
Human and Organizational Factors
• Create system development methods that more easily accommodate inputs relevant to human and organizational factors.
• Develop software toolboxes and handbooks that codify and encapsulate principles derived from the social sciences that are relevant to system devel- opment and design.
• Develop reliable security measures that do not interfere with legitimate workers.
• Understand the IT issues related to the disparate organizational cultures of agencies that will be fused under the Department of Homeland Security.
NOTE: A future CSTB report on cybersecurity research will explicate research areas in greater detail.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
110 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
As for the funding of the research program described in this report, computer crime losses are estimated at $10 billion per year (and grow- ing).3 Although statistics on the amount lost to cybercrime are of dubious reliability, there is no doubt that aggregate losses are considerable. The committee believes that because this research program has considerable overlap with that needed to fight cybercrime, progress in this research program has the potential to reduce cybercrime as well. Without rigorous argument, the committee believes that the potential reduction in cybercrime would likely offset a considerable portion (if not all) of the research program described in this report (though of course the primary beneficiaries will be society at large rather than any individual company that today may suffer loss). Nevertheless, the committee has not had access to information that would allow it to determine an appropriate level of funding for the research program described in this report.
The time scale on which the fruits of efforts in these research areas will become available ranges from short to long. That is, each of these areas has technologies that can be beneficially deployed on a relatively short time scale (e.g., in a few years). Each area also has other prospects for research and deployment on a much longer time scale (e.g., a decade or more) that will require the development of entirely new technologies and capabilities.
The committee is silent on the specific government agency or agen- cies that would be best suited to support the program described above,4 though it notes that the recently created Department of Homeland Secu- rity may expand the options available for government action. Rather, the more important policy issue is how to organize a federal infrastructure to support this research. In particular, the committee believes that this infra- structure should have the following attributes. It would:
• Engage and support multidisciplinary, problem-oriented research that is useful both to civilian and military users. (Note that this approach contrasts strongly with the disciplinary orientation that characterizes most academic departments and universities.)
• Develop a research program driven by a deep understanding and
which there is a need for a low probability of intercept, these conditions do not obtain for civilian emergency-response communications. Also, military forces often must communi- cate in territory without a pre-existing friendly infrastructure, while civilian agencies can potentially take advantage of such an infrastructure.
3“Cyber Crime.” BusinessWeek Online, February 21, 2000. Available online at <http:// www.businessweek.com/2000/00_08/b3669001.htm>.
4See CSTB, NRC, 2002, Cybersecurity Today and Tomorrow, pp. 13-14.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
111RATIONALIZING THE FUTURE RESEARCH AGENDA
assessment of IT vulnerabilities. This will likely require access to classi- fied information, even though most of the research should be unclassi- fied.
• Support a substantial effort in research areas with a long time hori- zon for payoff. Historically, such investigations have been housed most often in academia, which can conduct research with fewer pressures for immediate delivery on a bottom line. (This is not to say that private industry has no role. Indeed, because the involvement of industry is critical for deployment, and is likely to be essential for developing proto- types and mounting field demonstrations, it is highly appropriate to sup- port both academia and industry perhaps even jointly in efforts oriented toward development.)
• Provide support extending for time scales that are long enough to make meaningful progress on hard problems (perhaps 5-year project du- rations) and in sufficient amounts that reasonably realistic operating en- vironments for the technology could be constructed (perhaps $2 million to $5 million per year per site for system-oriented research programs).
• Invest some small fraction of its budget on thinking “outside the box” in consideration (and possible creation) of alternative futures (Box 5.2).
• Be more tolerant of research directions that do not appear to prom- ise immediate applicability. Research programs, especially in IT, are of- ten—even generally—more “messy” than research managers would like. The desire to terminate unproductive lines of inquiry is understandable, and sometimes entirely necessary, in a constrained budget environment. On the other hand, it is frequently very hard to distinguish between (A) a line of inquiry that will never be productive and (B) one that may take some time and determined effort to be productive. While an intellectu- ally robust research program must be expected to go down some blind alleys occasionally, the current political environment typically punishes such blind alleys as being of Type A, with little apparent regard for the possibility that they might be Type B.
• Be overseen by a board or other entity with sufficient stature to attract top talent to work in the field, to provide useful feedback, and to be an effective sounding board for that talent.
• Pay attention to the human resources needed to sustain the counterterrorism IT research program. This need is especially apparent in the fields of information and network security and emergency commu- nications. Only a very small fraction of the nation’s graduating doctoral students in IT specialize in either of these fields, only a very few profes- sors conduct research in these areas, only a very few universities support research programs in these fields, and, in the judgment of the committee,
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
112 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
BOX 5.2 Planning for the Future
Planning for the future is a critical dimension of any research agenda, though the resources devoted to it need not be large. System architectures and technologies such as switched optical networks, mobile code, and open-source or multinational code development will have different vulnerabilities from the technologies that char- acterize most of the existing infrastructure and hence require different defense strat- egies. Similarly, device types such as digital appliances, wireless headphones, and network-capable cell phones may pose new challenges. Even today, it is hard to interconnect systems with different security models or security semantics; unless this problem is successfully managed, it will become increasingly difficult in the future.
Furthermore, the characteristics of deployed technology that protect the nation against catastrophic IT-only attacks today (e.g., redundancy, system heterogeneity, and a reliance on networks other than the Internet for critical business functions) may not continue to protect it in the future. For example, trends toward deregulation are pushing the nation’s critical infrastructure providers to reduce excess capacity, even though this is what provides much of the redundancy so important to reduced vul- nerability. In the limit, the market dominance of a smaller number of products leads to system monocultures that, like their ecological and agricultural counterparts, are highly vulnerable to certain types of attack.
For these reasons, researchers and practitioners must be vigilant to changes in network technology, usage and reliance on IT, and decreasing diversity. In addition, research focused on the future is likely to have a slant that differs from the orientation of the other research efforts described in this chapter. While the latter efforts might be characterized as building on existing bodies of knowledge (and are in that sense incremental), future-oriented research would have a more radical orientation: it would, for example, try to develop alternative paradigms for secure and reliable operation that would not necessarily be straightforward evolutions from the Internet and information technology of today. One such pursuit might be the design of ap- propriate network infrastructure for deployment in 2020 that would be much more secure than the Internet of today. Another might be an IT infrastructure whose secu- rity relied on engineered system diversity—in which deployed systems were suffi- ciently similar to be interoperable, yet sufficiently diverse to essentially be resistant to large-scale attacks.
only a very small fraction of the universities that do support such pro- grams can be regarded as first-rate universities.
One additional attribute of this R&D infrastructure would be desir- able, though the committee has few good ideas on how to achieve it. The success of the nation’s R&D enterprise in IT (as well as in other fields) rests in no small part on the ability of researchers to learn from each other in a relatively free and open intellectual environment. Constraining the openness of that environment (e.g., by requiring that research be classi- fied or by forbidding certain research from being undertaken) would
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
113RATIONALIZING THE FUTURE RESEARCH AGENDA
have obvious negative consequences for researchers and the creation of new knowledge. On the other hand, keeping counterterrorist missions in mind, the free and open dissemination of information has potential costs as well, because terrorists may obtain information that they can use against us. Historically, these competing interests have been “balanced”— with more of one in exchange for less of the other. But the committee believes (or at least hopes) that there are other ways of reconciling the undeniable tension, and calls for some thought to be given to a solution to this dilemma that does not demand such a trade-off. If such a solution can be found, it should be a design characteristic of the R&D infrastruc- ture.
A comment on the counterterrorist research program is that success- fully addressing the privacy and confidentiality issues that arise in counterterrorism efforts will be critical for the deployment of many infor- mation technologies. This area is so important that research in the area itself is necessary and should be a fundamental component of the work in virtually all of the other areas described in this report.
Finally, it is the belief of the committee that an R&D infrastructure with the characteristics presented above has the best chance of delivering successfully on the complex research problems described in this report. The committee is not arguing for unlimited latitude to undertake research that is driven primarily by intellectual curiosity, but rather for a program focused on the specific national needs described in this report that can look beyond immediate deliverables. More detailed research agendas should be forthcoming from the agencies responsible for implementing the broad research program described in this report.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
115
Appendix
Biographies of Committee and Staff Members
COMMITTEE ON THE ROLE OF INFORMATION TECHNOLOGY IN RESPONDING TO TERRORISM
John L. Hennessy, Chair, is president of Stanford University, where he joined the faculty in 1977, was the chair of the Department of Com- puter Science in 1994, and became dean of the School of Engineering in 1996. He is an expert in computer architecture and is recognized for innovation in software techniques as the codeveloper of reduced instruc- tion set computing (RISC). In 2001 Dr. Hennessy received the Eckert- Mauchly Award from the Association for Computing Machinery and In- stitute of Electrical and Electronics Engineers Computer Society and honorary doctoral degrees from the State University of New York at Stony Brook and Villanova University, his two alma maters. He is currently chairman of the board at Atheros, and was a board member at Alentec Corporation and an advisory board member at Microsoft Corporation and Tensilica. Over the past decade, he has served on numerous commit- tees at the National Academies, most recently as the chair of the Com- puter Science and Engineering Committee and the Committee on Mem- bership during 1999-2000. He has served on the Computer Science and Telecommunications Board committees that produced Global Trends in Computer Technology and Their Impact on Export Control, Academic Careers for Experimental Computer Scientists and Engineers, and Evolving the High Performance Computing and Communications Initiative to Support the Nation’s Information Infrastructure. He has also provided his computer expertise and leadership skills on committees and commissions of the National
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
116 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Science Foundation and the Defense Advanced Research Projects Agency (DARPA). He is an alumnus of CSTB and a member of Tau Beta Pi, Eta Kappa Nu, Pi Mu Epsilon, and the National Academy of Engineering.
David A. Patterson, Vice Chair, is the E.H. and M.E. Pardee Chair of Computer Science at the University of California at Berkeley. He has taught computer architecture since joining the faculty in 1977 and has been chair of the Computer Science Division of the Electrical Engineering and Computer Science Department at Berkeley. He is well known for leading the design and implementation of RISC I, the first Very Large- Scale Integration (VLSI) Reduced Instruction Set Computer, which be- came the foundation for the architecture currently used by Fujitsu, Sun Microsystems, and Xerox. He was also a leader of the Redundant Arrays of Inexpensive Disks (RAID) project, which led to high-performance stor- age systems from many companies, and the Network of Workstation (NOW) project, which led to cluster technology used by Internet compa- nies such as Inktomi. He is a fellow of the Institute of Electrical and Electronics Engineers and the Association for Computing Machinery. He served as chair of the Computing Research Association. His current re- search interests are in building novel microprocessors using Intelligent Dynamic Random Access Memory (IRAM) for use in portable multime- dia devices and using Recovery Oriented Computing to design available, maintainable, and evolvable servers for Internet services. He has con- sulted for many companies, including Digital Equipment Corporation, Hewlett Packard, Intel, and Sun Microsystems, and he is the coauthor of five books. Dr. Patterson served on the CSTB committees that produced Computing the Future: A Broader Agenda for Computer Science and Engineer- ing and Making IT Better: Expanding Information Technology Research to Meet Society’s Needs. He is a member of the National Academy of Engi- neering and a current member of CSTB.
Steven M. Bellovin, fellow at AT&T Research, is a renowned author- ity on security—in particular, Internet security. Dr. Bellovin received a B.A. degree from Columbia University and an M.S. and Ph.D. in com- puter science from the University of North Carolina at Chapel Hill. While a graduate student, he helped create Netnews; for this, he and the other collaborators were awarded the 1995 USENIX Lifetime Achievement Award. At AT&T Laboratories, Dr. Bellovin does research in networks and security, and why the two do not get along. He has embraced a number of public interest causes and weighed in (e.g., through his writ- ings) on initiatives (e.g., in the areas of cryptography and law enforce- ment) that appear to compromise privacy. He is currently focusing on cryptographic protocols and network management. Dr. Bellovin is the coauthor of the recent book Firewalls and Internet Security: Repelling the Wily Hacker, and he is a member of the Internet Architecture Board. He
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
117APPENDIX
has recently been elected to the National Academy of Engineering. He served on the CSTB committee that produced Trust in Cyberspace and is a member of the committee to study authentication technologies and their implications for privacy. That committee is addressing a range of security (and privacy) issues, including those relating to data collection (e.g., bio- metrics) and analysis (e.g., tracking systems), as well as a range of sys- tems issues.
W. Earl Boebert is an expert on information security, with experience in national security and intelligence as well as commercial applications and needs. He is a senior scientist at Sandia National Laboratories. He has 30 years experience in communications and computer security, is the holder or co-holder of 13 patents, and has participated in National Re- search Council studies on security matters. Prior to joining Sandia, he was the technical founder and chief scientist of Secure Computing Corpo- ration, where he developed the Sidewinder security server, a system that currently protects several thousand sites. Before that he worked 22 years at Honeywell, rising to the position of senior research fellow. At Honeywell he worked on secure systems, cryptographic devices, flight software, and a variety of real-time simulation and control systems, and won Honeywell’s highest award for technical achievement for his part in developing a very large scale radar landmass simulator. He also devel- oped and presented a course on systems engineering and project manage- ment that was eventually given to more than 3,000 students in 13 coun- tries. He served on the CSTB committees that produced Computers at Risk: Safe Computing in the Information Age and Trust in Cyberspace, and partici- pated in Project Initiation Fund workshops on “Cyber-Attack” and “In- sider Threat.”
David Borth is an expert on wireless communications, with insight into national security as well as commercial needs. He is corporate vice president and director of the Communication Systems and Technologies Laboratory of Motorola Incorporated, a part of the company’s research arm, Motorola Laboratory. Dr. Borth joined Motorola in 1980 as a mem- ber of the Systems Research Laboratory in corporate research and devel- opment in Schaumburg, Illinois. As a member of that organization, he has conducted research on digital modulation techniques, adaptive digi- tal signal processing methods applied to communication systems, and personal communication systems including both cellular and Personal Communications Service systems. He has contributed to Motorola’s implementations of the GSM, TDMA (IS-54/IS-136), and CDMA (IS-95) digital cellular systems. In his current role, he manages a multinational (United States, Australia, France, Japan) organization focusing on all as- pects of communication systems, ranging from theoretical systems stud- ies to system and subsystem analysis and implementation to integrated
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
118 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
circuit designs. Dr. Borth received his B.S., M.S., and Ph.D. degrees in electrical engineering from the University of Illinois at Urbana- Champaign. Previously, he was a member of the technical staff of the systems division of Watkins-Johnson Company and an assistant profes- sor in the School of Electrical Engineering, Georgia Institute of Technol- ogy. Dr. Borth is a member of Motorola’s Science Advisory Board Associ- ates and has been elected a Dan Noble Fellow, Motorola’s highest honorary technical award. He has been issued 31 patents and has authored or coauthored chapters of 5 books in addition to 25 publications. He received the Distinguished Alumnus Award from the University of Illinois Electrical and Computer Engineering Alumni Association and was elected a fellow of the Institute of Electrical and Electronics Engineers for his contributions to the design and development of wireless telecommu- nication systems. He is a registered professional engineer in the State of Illinois and a current member of CSTB.
William J. Brinkman has been vice president of Physical Sciences Research at Bell Labs of Lucent Technologies since 1993. He is an expert in the area of condensed matter physics as it pertains to telecommunica- tions and information-processing technologies. He received his Ph.D. in physics from the University of Missouri in 1965. Dr. Brinkman joined Bell Laboratories in 1966 after spending one year as a National Science Foun- dation postdoctoral fellow at Oxford University. He moved to Sandia National Laboratories in 1984, but returned to Bell Laboratories in 1987 to become executive director of the Physics Research Division. His respon- sibilities include the direction of research in physical sciences, optoelec- tronic and electronic devices, fiber optics, and related areas. He has worked on theories of condensed matter, and his early work also in- volved the theory of spin fluctuations in metals and other highly corre- lated Fermi liquids. Subsequent theoretical work on liquid crystals and incommensurate systems are additional important contributions that he has made to the theoretical understanding of condensed matter. As man- ager of an industrial research organization with a budget of $200 million. Dr. Brinkman is strongly interested in improving technology conversion and improving the connection between research and products. He was the recipient of the 1994 George E. Pake Prize. Over the past 20 years, he has served on numerous committees of the National Academies, cur- rently the National Academy of Sciences 2002 Nominating Committee and most recently the Committee on Science, Engineering, and Public Policy. He is a member of the National Academy of Sciences.
John M. Cioffi is an expert on communications technologies, with an emphasis on wireline contexts. He received his BS in electrical engineer- ing from the University of Illinois in 1978 and his Ph.D. in electrical engi- neering from Stanford University in 1984. He worked for Bell Laborato-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
119APPENDIX
ries from 1978 to 1984, IBM Research from 1984 to 1986, and has been an electrical engineering professor at Stanford University since 1986. Dr. Cioffi founded Amati Communications Corporation in 1991 (purchased by Texas Instruments in 1997) and was an officer/director from 1991 to 1997. Currently he is on the boards or advisory boards of BigBand Net- works, Coppercom, GoDigital, Ikanos, Ionospan, Ishoni, IteX, Marvell, Kestrel, Charter Ventures, and Portview Ventures. Dr. Cioffi’s specific interests are in the area of high-performance digital transmission. He has received various awards: member, National Academy of Engineering (2001), IEEE Kobayashi Medal (2001), IEEE Millennium Medal (2000), IEEE Fellow (1996), IEE JJ Tomson Medal (2000), 1999 University of Illi- nois Outstanding Alumnus, 1991 IEEE Communications Magazine best pa- per, 1995 American National Standards Institute T1 Outstanding Achieve- ment Award, National Science Foundation Presidential Investigator (1987-1992). Dr. Cioffi has published more than 200 papers and holds over 40 patents, most of which are widely licensed, including basic pat- ents on DMT, VDSL, and vectored transmission. He served on the CSTB committee that produced Broadband: Bringing Home the Bits and is a cur- rent member of CSTB.
W. Bruce Croft is chair of the computer science department, as well as distinguished university professor, at the University of Massachusetts, Amherst, which he joined in 1979. In 1992, he became the director of the National Science Foundation State/Industry/University Collaborative Research Center for Intelligent Information Retrieval (CIIR), which com- bines basic research with technology transfer to a variety of government and industry partners. Dr. Croft received his B.Sc. (Honors) degree in 1973 and an M.Sc. in computer science in 1974 from Monash University in Melbourne, Australia. He earned his Ph.D. in computer science from the University of Cambridge, England, in 1979. His research interests are in several areas of information retrieval, including retrieval models, Web search engines, cross-lingual retrieval, distributed search, question an- swering, text summarization, and text data mining. He has published more than 120 articles on these subjects. Dr. Croft has consulted for many companies and government agencies. He co-founded a search engine startup in 1996, and his research is being used in a number of operational systems. He was chair of the ACM Special Interest Group on Information Retrieval from 1987 to 1991. He is currently editor-in-chief of the ACM’s Transactions on Information Systems and an associate editor for Information Processing and Management. He has served on numerous program com- mittees and has been involved in the organization of many workshops and conferences. He was elected a fellow of ACM in 1997 and received the Research Award from the American Society for Information Science and Technology in 2000. He is a member of CSTB’s Digital Government
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
120 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
committee, which has provided insight into government application con- texts. He has a history of research interactions with the intelligence com- munity, and his emphases relate to data collection and analysis. He is a current member of CSTB.
William P. Crowell is a former deputy director and chief operating officer of the National Security Agency. Prior to the NSA, he was vice president of Atlantic Aerospace Electronics Corporation. In 1998 he joined Cylink and is currently president and CEO. The company helped pioneer the use of computer security systems within major financial and govern- ment institutions. He holds a bachelor’s degree in political science from Louisiana State University.
Jeffrey M. Jaffe has broad knowledge of systems, with emphases on networked/distributed systems and the associated security challenges. He is vice president of research and advanced technologies for Lucent Technologies Bell Laboratories. The Advanced Technologies Group works with Lucent’s business units in the commercial development and deployment of new technologies, with an emphasis in networks plan- ning, software and systems engineering. Prior to joining Lucent, Dr. Jaffe held a variety of research and management positions with International Business Machines (IBM). He joined IBM’s Thomas J. Watson Research Center in 1979, conducting research on networking protocols. He led re- search teams in developing networking and security software and user interfaces. He was later promoted to a number of executive positions, including vice president of systems and software. In this role, he coordi- nated the efforts of global research teams in supporting IBM’s current product lines and developing new software and hardware systems. Dr. Jaffe next served as corporate vice president of technology and helped to convert research into commercial products. He played key roles in as- sessing new technologies and policy enactment. In his most recent posi- tion with IBM, Dr. Jaffe managed all facets of IBM’s network software and security product business. Dr. Jaffe is a fellow of the IEEE and the ACM. The U.S. government has consulted with him on numerous policy initia- tives with a focus on the Internet. In 1997, President Clinton appointed Dr. Jaffe to the advisory committee for the President’s Commission for Critical Infrastructure Protection. Dr. Jaffe has chaired the Chief Technol- ogy Officer Group of the Computer Systems Policy Project (CSPP), which consists of a dozen of the top computer and telecommunications compa- nies. Dr. Jaffe earned a B.S. degree in mathematics, as well as M.S. and Ph.D. degrees in computer science, from the Massachusetts Institute of Technology. He is a current member of CSTB.
Butler W. Lampson is known for his expertise in systems and sys- tems architecture. At present, he is a distinguished engineer at Microsoft Corporation, where he works on problems of broad concern, such as
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
121APPENDIX
security and information management. Before joining Microsoft, Dr. Lampson was a senior corporate consulting engineer at Digital Equip- ment Corporation and a senior research fellow at the Xerox Palo Alto Research Center. He has worked on computer architecture, local area networks, raster printers, page description languages, operating systems, remote procedure call, programming languages and their semantics, pro- gramming in the large, fault-tolerant computing, computer security, and WYSIWYG editors. He was one of the designers of the SDS 940 time- sharing system, the Alto personal distributed computing system, the Xerox 9700 laser printer, two-phase commit protocols, the Autonet LAN, and several programming languages. He received a Ph.D. in electrical engineering and computer science from the University of California at Berkeley and honorary Sc.D. degrees from the Eidgenoessische Technische Hochschule, Zurich, and the University of Bologna. He holds a number of patents on networks, security, raster printing, and transac- tion processing. Dr. Lampson is a member of the National Academy of Engineering. He received the Association for Computing Machinery’s Software Systems Award in 1984 for his work on the Alto, and the Turing Award in 1992. He served on the CSTB committees that produced Com- puters at Risk: Safe Computing in the Information Age, Evolving the High Performance Computing and Communications Initiative to Support the Nation’s Information Infrastructure, and Realizing the Potential of C4I: Fundamental Challenges. He is a current member of CSTB.
Edward D. Lazowska has broad knowledge of software and distrib- uted and high-performance systems. He holds the Bill and Melinda Gates Chair in Computer Science in the Department of Computer Science and Engineering at the University of Washington. Dr. Lazowska received his A.B. from Brown University in 1972 and his Ph.D. from the University of Toronto in 1977. He has been at the University of Washington since that time. His research concerns the design and analysis of distributed and parallel computer systems. Dr. Lazowska is a member of the DARPA Information Science and Technology Group, past chair of the Computing Research Association, past chair of the National Science Foundation Com- puter and Information Science and Engineering advisory committee, and a member of the Technical Advisory Board for Microsoft Research. He served on the CSTB committees that produced Evolving the High Perfor- mance Computing and Communications Initiative to Support the Nation’s In- formation Infrastructure and Looking Over the Fence at Networks: A Neighbor’s View of Networking Research. Currently, he serves on the National Re- search Council committee Improving Learning with Information Technology. He is a fellow of the ACM and of the IEEE and is a member of the Na- tional Academy of Engineering and a current member of CSTB.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
122 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
David E. Liddle has a history of conducting and managing computer systems innovation, with an emphasis on interactive systems. At present, after leaving a series of research-management positions, he is a general partner in the firm U.S. Venture Partners (USVP), a leading Silicon Valley venture capital firm that specializes in building companies from an early stage in digital communications/networking, e-commerce, semiconduc- tors, technical software, and e-health. He retired in December 1999 after 8 years as CEO of Interval Research Corporation. During and after his education (he received B.S. and E.E. degrees from the University of Michi- gan and a Ph.D. in computer science from the University of Toledo, Ohio), Dr. Liddle has spent his professional career developing technologies for interaction and communication between people and computers in activi- ties spanning research, development, management, and entrepreneurship. He spent 10 years at the Xerox Palo Alto Research Center and the Xerox Information Products Group, where he was responsible for the first com- mercial implementation of the graphical user interface and local area net- working. He then founded Metaphor Computer Systems, whose technol- ogy was adopted by IBM and the company ultimately acquired by IBM in 1991. In 1992, Dr. Liddle cofounded Interval Research Corporation with Paul Allen. Since 1996, the company formed six new companies and several joint ventures based on the research conducted at Interval. Dr. Liddle is a consulting professor of computer science at Stanford Univer- sity. He has served as a director at Sybase, Broderbund Software, Metricom, Starwave, and Ticketmaster; he is currently a director with The New York Times. He was honored as a distinguished alumnus from the University of Michigan and is a member of the national advisory commit- tee at the College of Engineering of that university. He is also a member of the advisory committee of the school of engineering at Stanford Uni- versity. He has been elected a senior fellow of the Royal College of Art for his contributions to human-computer interaction. Dr. Liddle has had a number of interactions with national security entities on an advisory ba- sis, providing insights into military mind sets and needs. He is a current member of CSTB.
Tom M. Mitchell has just returned to Carnegie Mellon University (CMU) after a 2-year leave of absence as vice president and chief scientist for WhizBang! Labs. At CMU, he is the Fredkin Professor of Learning and Artificial Intelligence in the School of Computer Science and founding director of CMU’s Center for Automated Learning and Discovery. Dr. Mitchell is known for his work in machine learning, data mining, and artificial intelligence. His research ranges from developing software agents that learn to customize to their users, to Web crawlers that learn to extract factual information from Web sites, to computers that mine medi- cal records to learn which future patients are at high mortality risk. He is
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
123APPENDIX
the author of the widely used textbook Machine Learning. Dr. Mitchell is a fellow and president of the American Association for Artificial Intelli- gence. Prior to joining the faculty of Carnegie Mellon University in 1986, he taught at Rutgers University. He received his B.S. from the Massachu- setts Institute of Technology and his M.S.and Ph.D. degrees in electrical engineering from Stanford University. He has had research funded by the Central Intelligence Agency and has consulted with the agency recently about the application of WhizBang! technology to intelligence needs. He is a current member of CSTB.
Donald A. Norman is a user advocate. Business Week calls him a cantankerous visionary—cantankerous in his quest for excellence. Dr. Norman is cofounder of the Nielsen Norman Group, an executive con- sulting firm that helps companies produce human-centered products and services. In this role, he serves on the advisory boards of numerous companies. Dr. Norman is a professor of computer science at Northwest- ern University and professor emeritus of cognitive science and psychol- ogy at the University of California, San Diego. He is a former vice presi- dent of the advanced technology group of Apple Computer and was an executive at Hewlett Packard. Dr. Norman is the author of The Psychology of Everyday Things, Things That Make Us Smart, and, most recently, The Invisible Computer, a book that Business Week has called the bible of post- PC thinking. He is a current member of CSTB.
Jeannette M. Wing is a professor of computer science at Carnegie Mellon University. Her current focus is on applying automated reason- ing tools to specify and verify autonomous and embedded systems for their fault-tolerant, security, and survivability properties. She is the asso- ciate dean for academic affairs for the School of Computer Science and the associate department head for the computer science Ph.D. program. She received her S.B. and S.M. degrees in electrical engineering and computer science in 1979 and her Ph.D. in computer science in 1983, all from the Massachusetts Institute of Technology. Dr. Wing’s general research inter- ests are in the areas of formal methods, concurrent and distributed sys- tems, and programming languages. She was on the computer science faculty at the University of Southern California (USC) and has worked at Bell Laboratories, USC/Information Sciences Institute, and Xerox Palo Alto Research Center. She has also consulted for Digital Equipment Cor- poration, the Mellon Institute (Carnegie Mellon Research Institute), Sys- tem Development Corporation, and the Jet Propulsion Laboratory. She was on the National Science Foundation Scientific Advisory Board and the Defense Advance Research Projects Agency (DARPA) Information Science and Technology (ISAT) Group. She is or has been on the editorial board of seven journals. She is a member of the ACM (fellow), the IEEE (senior member), Sigma Xi, Phi Beta Kappa, Tau Beta Pi, and Eta Kappa
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
124 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
Nu. Professor Wing was elected an ACM fellow in 1998 and is a current member of CSTB.
STAFF
Herbert S. Lin is senior scientist and senior staff officer at the Com- puter Science and Telecommunications Board, National Research Council (NRC) of the National Academies, where he has been the study director of major projects on public policy and information technology. These studies include a 1996 study on national cryptography policy (Cryptography’s Role in Securing the Information Society), a 1991 study on the future of computer science (Computing the Future: A Broader Agenda for Computer Science and Engineering), a 1999 study of Defense Department systems for command, control, communications, computing, and intelli- gence (Realizing the Potential of C4I: Fundamental Challenges), and a 2000 study on workforce issues in high technology (Building a Workforce for the Information Economy). Prior to his NRC service, he was a professional staff member and staff scientist for the House Armed Services Committee (1986-1990), where his portfolio included defense policy and arms control issues. He also has significant expertise in mathematics and science edu- cation. He received his doctorate in physics from the Massachusetts Insti- tute of Technology. Avocationally, he is a long-time folk and swing dancer and a poor magician. Apart from his CSTB work, a list of publica- tions in cognitive science, science education, biophysics, arms control, and defense policy is available on request.
Steven Woo is the dissemination and program officer with the Com- puter Science and Telecommunications Board of the National Research Council. In this capacity, he formulates the dissemination and marketing plan for the study projects and workshops of CSTB. This includes distri- bution of CSTB reports in government, policy, academia, and private sectors; outreach to promote CSTB to current and potential sponsors; and raising awareness of CSTB’s resources and expertise among government and private industry. In addition, he handles the Program Office activities for some of the projects of CSTB. Prior to joining CSTB, Mr. Woo was an Internet and marketing consultant for clients ranging from Fortune 500s to nonprofits. His background includes marketing services for the Los Angeles Dodgers and several years of experience in systems engineering and analysis. Mr. Woo holds a B.S. in engineering from the University of California at Los Angeles and an M.B.A. from Georgetown University.
D.C. Drake has been a senior project assistant with CSTB since Sep- tember 1999. He is currently working on a project on critical information infrastructure protection and the law and also helped with the project that produced The Internet Under Crisis Conditions: Learning from September 11.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
125APPENDIX
He came to Washington in January 1999 after finishing a master’s degree in international politics and communications at the University of Ken- tucky. He earned a B.A. in international relations and German from Rhodes College in 1996. He has worked for the Hanns-Seidl Foundation in Munich, Germany, and in Washington, D.C., for the National Confer- ence of State Legislatures’ International Programs Office and for the Ma- jority Staff of the Senate Foreign Relations Committee.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
127
What Is CSTB?
As a part of the National Research Council, the Computer Science and Telecommunications Board (CSTB) was established in 1986 to provide independent advice to the federal government on technical and public policy issues relating to computing and communications. Composed of leaders from industry and academia, CSTB conducts studies of critical national issues and makes recommendations to government, industry, and academic researchers. CSTB also provides a neutral meeting ground for consideration of complex issues where resolution and action may be premature. It convenes invitational discussions that bring together prin- cipals from the public and private sectors, ensuring consideration of all perspectives. The majority of CSTB’s work is requested by federal agen- cies and Congress, consistent with its National Academies context.
A pioneer in framing and analyzing Internet policy issues, CSTB is unique in its comprehensive scope and effective, interdisciplinary ap- praisal of technical, economic, social, and policy issues. Beginning with early work in computer and communications security, cyber-assurance and information systems trustworthiness have been a cross-cutting theme in CSTB’s work. CSTB has produced several reports regarded as classics in the field, and it continues to address these topics as they grow in importance.
To do its work, CSTB draws on some of the best minds in the country, inviting experts to participate in its projects as a public service. Studies are conducted by balanced committees without direct financial interests in the topics they are addressing. Those committees meet, confer elec-
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
128 INFORMATION TECHNOLOGY FOR COUNTERTERRORISM
tronically, and build analyses through their deliberations. Additional expertise from around the country is tapped in a rigorous process of review and critique, further enhancing the quality of CSTB reports. By engaging groups of principals, CSTB obtains the facts and insights critical to assessing key issues.
The mission of CSTB is to:
• Respond to requests from the government, nonprofit organizations, and private industry for advice on computer and telecommunications issues and from the government for advice on computer and telecommu- nications systems planning, utilization, and modernization;
• Monitor and promote the health of the fields of computer science and telecommunications, with attention to issues of human resources, information infrastructure, and societal impacts;
• Initiate and conduct studies involving computer science, computer technology, and telecommunications as critical resources; and
• Foster interaction among the disciplines underlying computing and telecommunications technologies and other fields, at large and within the National Academies.
As of November 2002, current CSTB activities with a cybersecurity component address privacy in the information age, critical information infrastructure protection, authentication technologies and their privacy implications, geospatial information systems, cybersecurity research, and building certifiable dependable systems. Additional studies examine the fundamentals of computer science, information technology and creativ- ity, computing and biology, Internet navigation and the Domain Name System, telecommunications research and development, wireless com- munications and spectrum management, and digital archiving and pres- ervation. Explorations are under way in the areas of the insider threat, dependable and safe software systems, wireless communications and spectrum management, digital archiving and preservation, open source software, digital democracy, the “digital divide,” manageable systems, information technology and journalism, and women in computer science.
More information about CSTB can be obtained online at <http:// www.cstb.org>.
Copyright © National Academy of Sciences. All rights reserved.
Information Technology for Counterterrorism: Immediate Actions and Future Possibilities http://www.nap.edu/catalog/10640.html
Assignement2/becerraferi1745 (Part2).pdf
Disasters such as Hurricane Katrina and the 9/11 ter- rorist attacks have made crisis and emergency manage- ment a top priority for policy making and management at all levels. While each crisis or emergency situation is unique in some aspects that are difficult to determine before it actually occurs, all such situations, whether natural or manmade, are unpredictable and threaten high-value priorities such as life, financial well-being, and physical infrastructures.
Emergency management tasks are inherently complex and dynamic, requiring quick knowledge sharing for effective decision making and coordination among mul- tiple individuals and organizations across different lev- els and locations. Unfortunately, there is a general lack of understanding about how to describe and assess the complex nature of emergency management tasks and how knowledge-sharing strategies can improve emer- gency management task performance. This article dis- cusses the role of emergency operations centers (EOCs) and how emergency managers can improve their task performance by understanding and managing the dynamic interplays between task characteristics and knowledge-sharing strategies.
Our observations are drawn from a multiyear, multi- method collaborative research project between Florida International University and the Miami-Dade EOC in Florida. Since 2006, our team has studied EOC tasks and organizational structure, knowledge-sharing strategies for emergency management, and subsequent performance through interviews, review of EOC docu- ments, focus groups, and surveys. We also participated in EOC activations and in several-day-long simulation “drills” — exercises designed by the EOC in which all participating organizations and agencies simulate emer- gency events. These simulation drills are based on prior emergencies and are used to practice coordination and response activities required to accomplish the emer- gency management tasks.
Our observations indicated that, while emergency man- agement tasks are highly complex, the Miami-Dade EOC is successful in effectively and efficiently responding to
emergency situations. The EOC’s success can be largely attributed to its personnel’s utilization of appropriate knowledge-sharing strategies according to the nature of the complexity of those emergency management tasks. The emergency managers with whom we have interacted in the last few years all agree that attempts to better understand the characteristics that determine task complexity can aid the effective management of emergency events. Furthermore, they recognize that the successful completion of these tasks requires appro- priate coordination and knowledge-sharing strategies among multiple actors and organizations across differ- ent levels and locations.
EOC CHARACTERISTICS
The state of Florida is currently considered one of the most effective states in the US with regard to emer- gency management. The State Emergency Response Team (SERT) has identified 18 types of hazards that pose an emergency threat to Florida, including wild- fires, thunderstorms, tornadoes, lightning, flood, terror- ism, drought, heat waves, hurricanes, cold, animals, nuclear accidents, hazardous materials, cyber attacks, information warfare, aircraft, and bombs. The Miami- Dade County Office of Emergency Management (OEM) is the lead agency in an emergency event, and the EOC is the site where all relevant government agencies and other organizations come together to carry out the emergency management operations. The EOC thus rep- resents a temporary organization that is triggered by an emergency event and is composed of various personnel with specialized expertise and skills from different organizations.
Figure 1 depicts the floor plan and the facility setup of the EOC. The large array of organizations is organized into branches such as the Public Safety Functional Group, the Human Services Functional Group, and the Infrastructure Functional Group; neighboring counties’ emergency management liaisons, municipality EOCs, the Air Force Reserve Base, and the Federal Emergency Management Agency (FEMA) participate as well. Many
©2011 Cutter Information LLCCUTTER IT JOURNAL January 201120
Emergency Management Task Complexity and Knowledge-Sharing Strategies by Weidong Xia, Irma Becerra-Fernandez, Arvind Gudi, and Jose Rocha-Mier
PUTTING HEADS TOGETHER
21Get The Cutter Edge free: www.cutter.com Vol. 24, No. 1 CUTTER IT JOURNAL
other agencies are likewise called upon following an emergency event.
COMPLEXITY CHARACTERISTICS OF EMERGENCY MANAGEMENT TASKS
Two complexity characteristics can be used to describe emergency management tasks:
1. Structural complexity
2. Dynamic complexity
Structural complexity refers to the inherent complexity of the task, and it captures the type and number of the various task components (such as time and location of the incident and the personnel, equipment, and organi- zations involved), as well as the interdependencies among the components. It is composed of two dimen- sions: component complexity and interactive complexity. Component complexity represents the multiplicity of the task components (e.g., number of people assigned, variety of organizations represented, computer systems accessed and used, machines required, variety of resources required to complete the task). Interactive complexity represents the degree of interactions and interdependencies among the task components (e.g., the interconnectedness of the people and different organizations participating in a given task).
Dynamic complexity refers to the aspect of the task that involves the decision maker, and it captures the ad hoc
and unpredictable nature of the task. It is composed of three dimensions: task non-routineness, task difficulty, and task significance (see Figure 2). Task non-routineness represents the unexpected and novel events and excep- tional circumstances associated with the task. Task diffi- culty represents the degree to which the information required to perform the task is missing or equivocal, thus leading to conflicting interpretations. Task signifi- cance captures the immediate priority and potential impact of the task.
KNOWLEDGE-SHARING STRATEGIES
Because of the significant amount of information and knowledge needed for quick assessment and decision making, emergency management requires intense knowledge identification and sharing across the diverse organizations involved. As shown in Figure 3, knowl- edge-sharing strategies in the emergency management context can be viewed from two perspectives:
1. Knowledge-sharing purpose — exploration versus exploitation
2. Knowledge-sharing mechanism — personal inter- actions versus written documents
Knowledge sharing can serve one of two purposes. Knowledge exploration refers to situations where discovery of new knowledge is required because there is no existing knowledge for performing the task at
Figure 1 — Miami-Dade EOC activation floor plan.
©2011 Cutter Information LLCCUTTER IT JOURNAL January 201122
hand. Exploration activities often include search, varia- tion, risk taking, experimentation, play, flexibility, dis- covery, and/or innovation. Knowledge exploitation refers to a directed search and utilization of existing knowledge. Exploitation activities often entail refine- ment, choice, production, efficiency, selection, imple- mentation, and/or execution.
Two knowledge-sharing mechanisms can be used in emergency management: personal interactions and written documents. Knowledge sharing through personal inter- action is appropriate for knowledge that is difficult to codify and hard to formally articulate in writing. Such tacit knowledge often resides in individuals based on their experiences and social context. Knowledge sharing through written documents is appropriate for explicit knowledge that has been formally codified and written down in the form of planning guidelines, standard operating procedures, best practices, lessons learned, and/or after-action reports.
FINDINGS AND LESSONS LEARNED
1. EOC tasks are highly complex and at risk of failing because of the inherent dilemmas of dealing with the conflicting dimensions of task complexity.
In order to effectively assess and distinguish the com- plexity dimensions and levels of different EOC tasks, we developed a set of frameworks and assessment tools. In general, the tasks undertaken at the EOC are complex
based on both their structural complexity and their dynamic complexity. A typical EOC activation during the hurricane season calls upon more than 300 person- nel from more 50 organizations. The personnel from each organization possess specialized expertise in a par- ticular aspect of the emergency management process. Differences in the personnel’s background and expertise make information exchange not only necessary, but also difficult. Because of the large number of personnel and organizations involved and the ways they are all inter- connected, structural complexity represents one of the most critical complexity dimensions of emergency management tasks.
In addition to the high structural complexity, EOC tasks are generally high in dynamic complexity as measured by task non-routineness, difficulty, and significance. Because each emergency event could manifest itself with a new set of characteristics (e.g., hurricanes could have different levels of wind speed or precipitation), each event could essentially be unique and introduce a new set of challenges. Decision makers could thus face new tasks that require actions and procedures that are not routinely performed and yet demand immediate response because of the high level of task significance. For example, during Hurricane Katrina, emergency responders in Miami had the task of dealing with the sudden collapse of the SR836 overpass bridge in con- struction between 87th and 107th Avenues. This emer- gency task was non-routine, as emergency crews had never dealt with an overpass collapse before. Because
Task Complexity
Structural Complexity Dynamic Complexity
Component Complexity
Interactive Complexity
Task Non- Routineness
Task Difficulty
Task Significance
Figure 2 — A framework of emergency management task complexity characteristics.
Knowledge Sharing Strategy
Knowledge Sharing Purpose Knowledge Sharing Mechanism
Exploitation Exploration Written Documents
Personal Interactions
Figure 3 — A framework of emergency management knowledge-sharing strategy.
23Get The Cutter Edge free: www.cutter.com Vol. 24, No. 1 CUTTER IT JOURNAL
the task was essentially new, the non-routine informa- tion that was required for decision making may have been unavailable or may have conflicted with other pieces of information.
The different complexity dimensions can be organized into a progressive complexity hierarchy based on their relationships and relative priorities. One of the most sig- nificant challenges emergency managers face is manag- ing the conflicting demands imposed by the different dimensions of task complexity. Tasks that are high in both non-routineness and difficulty require EOC man- agers to take the time to understand the task circum- stances as thoroughly as possible before committing to a particular approach or course of action, yet because of the urgency and high impact of the emergency event, EOC personnel are pressured to respond to the disaster event as quickly as possible.
2. Despite the high levels of complexity, EOC tasks are completed successfully because of effective knowledge sharing.
Effective knowledge management depends on appropri- ately managing the interplays among task complexity characteristics, knowledge-sharing purposes, and knowledge-sharing mechanisms. Managers often share knowledge for exploitation purposes through written documents and systems when they are dealing with component complexity, which tends to be limited to a particular knowledge area. In contrast, when dealing with interactive complexity (which tends to be more unstructured and more likely to cross organizational boundaries), managers often share knowledge for exploitation purposes through personal interactions in order to utilize knowledge that managers in other organizations already possess.
Dealing with dynamic complexity — with its high levels of task non-routineness, difficulty, and significance — is another story. Because of the lack of existing knowledge and the urgency in responding to a novel situation, managers share knowledge primarily for exploration purposes and depend mainly on personal interactions rather than searching written documents and systems.
One of our most interesting findings is that, while per- sonnel more often engage in knowledge exploitation (seeking and reusing existing knowledge) than explo- ration (creating new knowledge), they are more apt to do so through personal interactions than by searching written documents and/or systems. Indeed, the greater the difficulty of the task at hand, the more likely they are to shift to sharing knowledge through personal interactions rather than using prescribed mechanisms such as operating procedures and documents. We have
found that explicit knowledge stored in written docu- ments and systems is more suitable for dealing with lower-order complexity such as component complexity within a particular specialty area, while tacit and/or integrated knowledge sharing through personal inter- actions is more suitable for dealing with high-order emergency task complexity.
3. The EOC organizational structure and facility configuration provide an enabling physical setting for effective knowledge sharing.
Given the high interactive complexity and task signifi- cance of emergency management tasks, the successful completion of these tasks depends less on individual managers possessing the specialized knowledge required to deal with component-level complexity and more on managers from different organizations coordinating effectively to share the knowledge needed to handle the higher order of task complexity. This is no small feat, as emergency managers must search as much information as possible, identify available alternatives, and then coordinate the large number of diverse and interdependent organizations to make immediate deci- sions. The temporary nature of the various organiza- tions’ involvement in the EOC and the high turnover of personnel in the different organizations further exacer- bate the difficulty of managing the high interactivity and significance of EOC tasks. Effective knowledge sharing would not happen without the well-ordered organizational structure of the EOC and the physical proximity of the actors in the facility.
The EOC is the site for all emergency management operations and functional responsibilities. Many assumptions usually made in the organizational con- text with regard to issues such as resource planning, communications, chain of command, and so forth may not hold true in the EOC setting. During an emergency, the participation of representatives from different orga- nizations is transitory. Communication mechanisms could be instituted formally, but the stressful conditions during an emergency might cause the participants to revert to informal means of communication. For similar reasons, the chain of command at the EOC might be construed to be fluid and evolving.
The EOC is organized under the guidelines of the Incident Command System (ICS) within the National Incident Management System (NIMS),1 the first stan- dardized management approach that attempts to unify US federal, state, and local lines of government in times of emergency response activities. One of the manage- ment characteristics of the ICS is an organizational structure that develops in a top-down, modular fashion
©2011 Cutter Information LLCCUTTER IT JOURNAL January 201124
based on the size and complexity of the incident, enabling the assembly of the diverse organizations needed to manage complex emergency events into a temporary but highly fluid and effective organization like the EOC. When situational complexity increases, the organization is able to expand from the top down, adding functional responsibilities as required. For example, one of the procedures adopted at the Miami- Dade EOC is to ramp up (or down) the activation level depending on the severity of the disaster event, thereby increasing (or decreasing) the personnel and resources available for the emergency response operation.
Effective and efficient knowledge sharing among multiple managers from diverse organizations also requires colocation in one facility, with an appropriate communications and information exchange network setup. The EOC central command room is designed and furnished in special ways (see Figure 1). Three large, elongated tables are arranged in the center of the room; each table is equipped with 14-16 workstations and cor- responding chairs, with two stations at the head of each table. A nameplate for each of the various organizations and agencies is neatly displayed at each workstation, which is also equipped with a computer, two tele- phones (one conventional, and another customized), and several manuals and instruction sets. One end of the room has seating arrangements for 8-10 people in each of two rows; the other end has a raised platform for four section managers and a podium with a micro- phone lending an aura of authority and orderliness. There are four ceiling-mounted monitors, and each of the adjoining walls is fitted with four television screens.
Flash back to 29 August 2006. We were in the EOC central command room observing the whole activation procedure for Hurricane Ernesto. The workstations were then manned by the representatives of the various orga- nizations and government agencies and by regional EOC representatives. The heads of three tables were occupied by the Miami-Dade EOC functional branch managers (Public Safety, Human Services, and Infrastructure Functional, respectively), who also periodically updated the status boards on the overhead monitors. The televi- sion sets were muted but linked us to the outside world through different broadcast channels. “Task complex- ity,” “knowledge sharing,” and “emergency task perfor- mance” were no longer empty words or academic terms. They had sprung to life in this activation room, and as we became aware of the gradual deterioration of the weather conditions outside, we realized there was seri- ous work to be done. The faint buzz of telephone discus- sions, the chatter of computer keyboards, and the furtive glances at the television screens conveyed an ambiance
of anxiety and apprehension, yet we could sense the urgency and intensity of purposive knowledge sharing through written documents and systems at each station and the ad hoc gatherings of people exchanging ideas and making decisions. The EOC central command room setup manifested the ICS-guided modular organizational structure and afforded the physical networks for effec- tive knowledge sharing.
4. The EOC’s information and communication technol- ogy tools provide a necessary facilitation environment for knowledge sharing.
The EOC depends on the following state-of-the-art tools to manage emergencies:
Written and system documents for standard oper- ations procedures (SOPs), local response protocols, situation reports, and incident action plans (IAPs) based on past emergency management experiences.
Hurrevac, a software tool developed jointly by the National Hurricane Center, US Army Corps of Engineers, and Federal Emergency Management Agency (FEMA) to track tropical cyclones and pro- vide a continuous flow of information to emergency managers.
SLOSH II, a computer model developed jointly by the National Hurricane Center Storm Surge Group, US Army Corps of Engineers, US Geological Survey (USGS), and FEMA with input from the state of Florida and several local emergency managers, including those from Miami-Dade County. It calcu- lates probable storm surge based on size, direction, and forward speed of a storm.
SALT (Storm Action Lead Time), a software applica- tion developed by the Miami-Dade County OEM and Enterprise Technology Service Department (ETSD) to provide a checklist of pre- and post-storm activities.
Snapshot, a software tool developed by Miami-Dade OEM to provide virtually instant information on damages caused by a storm or flood event.
E-Team, collaborative software for crisis management developed by software vendor NC4.
5. EOC personnel training must go beyond procedural training based on written documents and systems.
The events that trigger emergency management oper- ations are rare and diverse, and there is no single com- prehensive plan that can be devised ahead of time to cope with the next incident. Many of the personnel at the EOC for a particular incident may be first-time partici- pants, because emergency events do not have a regular
25Get The Cutter Edge free: www.cutter.com Vol. 24, No. 1 CUTTER IT JOURNAL
pattern or schedule. They will doubtless have extensive knowledge and expertise in their particular area of spe- cialty (water management, electric utility, phone services, etc.), but they may not have much experience in dealing with the higher levels of complexity presented by a real emergency event. In addition, this might be the first time they are meeting and working with the other EOC members. This is a challenge because the situation will demand a high degree of interaction, under severe time constraints, between representatives of the different organizations.
While training based on traditional written documents and system procedures will help the “new” participants obtain explicit knowledge about what worked in the past, it does not provide the on-the-spot knowledge- sharing skills that are critical for addressing component and interactive task complexity, task non-routineness, task difficulty, and task significance. The Miami-Dade EOC has adopted regular full-scale emergency simula- tion drills to train and update emergency management personnel. These have proven to be a pivotal organiza- tional mechanism not only for giving the participants a live experience of dealing with an emergency event, but, more importantly, for enhancing their knowledge- sharing skills.
CONCLUSION
In this article, we have discussed frameworks for describ- ing the complexity of emergency management tasks and knowledge-sharing strategies that enhance performance. The complexity dimensions — component complexity, interactive complexity, task non-routineness, task diffi- culty, and task significance — represent a progressive hierarchy in terms of the order of magnitude and the pri- ority of actions needed. As we’ve discussed, the nature and level of the different complexity dimensions of an emergency management task dictate the most effective purpose and mechanisms for knowledge sharing.
In addition to dealing with each complexity dimension, emergency managers must grapple with the conflicting demands of the different complexity dimensions. High levels of interactive complexity and non-routineness require emergency personnel to take time to coordinate and search for new solutions, yet high levels of task significance (urgency and impact) demand immediate actions. As a result, many emergency management actions are “rushed irrational” — improvising in nature — rather than “well planned rational” — following the book. There are no one-size-fits-all solutions or proce- dures that emergency management organizations can develop a priori. Therefore, such organizations must be
set up with an appropriate organizational structure, which includes physical configurations and informa- tion and communications technologies that facilitate appropriate knowledge sharing in accordance with the complexity circumstances of the specific emergency situations.
ENDNOTE 1National Incident Management System. US Department of Homeland Security, March 2004 (www.dhs.gov/xlibrary/ assets/NIMS-90-web.pdf).
Weidong Xia is an Associate Professor of Decision Sciences and Information Systems at Florida International University. Dr. Xia received his PhD in IS from the University of Pittsburgh. His research relates to organizational information and knowledge management strategy, project complexity and flexibility, innovation adoption, and management of outsourcing. He has served on the faculty of the Carlson School of Management at the University of Minnesota, and his work has been published in such journals as MIS Quarterly, Decision Sciences, Communications of the ACM, Journal of Management Information Systems, and European Journal of Information Systems. Dr. Xia can be reached at [email protected].
Irma Becerra-Fernandez is Director and Fellow of the Pino Global Entrepreneurship Center and Professor of Management Information Systems at Florida International University College of Business Administration. Her research focuses on knowledge management and systems, business intelligence, enterprise systems, disaster manage- ment, and IT entrepreneurship. Dr. Becerra-Fernandez has studied and advised organizations, in particular NASA, and has served as principal investigator in studies for which she obtained over US $4 million in funding from numerous federal and state agencies, as well as private foundations and organizations. She has published exten- sively in leading journals and is the author of four books. Dr. Becerra- Fernandez has delivered invited presentations and keynote speeches, with both an academic and a practitioner focus, at many research centers, universities, and conferences worldwide. She can be reached at [email protected].
Arvind Gudi is an Assistant Clinical Professor of Management in the LeBow College of Business at Drexel University. Dr. Gudi holds a PhD in business administration, an MS in MIS, and a bachelor’s degree in electronics and telecommunications engineering. Prior to teaching, he had an extensive industry background in systems devel- opment and project management. He has held several professional and management positions with nationally and internationally focused consulting and private companies. His research is focused on the chal- lenges of knowledge management and knowledge integration in the field of emergency (disaster) management. Dr. Gudi can be reached at [email protected].
Jose Rocha-Mier is a PhD candidate in the College of Business Administration at Florida International University. He holds an MBA from the University of Miami. He has extensive industry background and consulting experience. His research relates to knowledge manage- ment and emergency management. Mr. Rocha-Mier can be reached at [email protected].
Assignement2/PUB1067.pdf
Tarek Saadawi Louis Jordan, Jr. Editors
CYBER INFRASTRUCTURE
PROTECTION
CYBER INFRASTRUCTURE
PROTECTION
C y b
e r In
fra stru
ctu re
P ro
te ctio
n E d
ite d
b y
Ta re
k Sa
a d
a w
i Lo
u is Jo
rd a n
Visit our website for other free publication downloads
http://www.StrategicStudiesInstitute.army.mil/
To rate this publication click here.
CYBER INFRASTRUCTURE PROTECTION
Tarek Saadawi Louis Jordan
Editors
May 2011
The views expressed in this report are those of the authors and do not necessarily reflect the official policy or position of the Department of the Army, the Department of Defense, or the U.S. Government. Authors of Strategic Studies Institute (SSI) publica- tions enjoy full academic freedom, provided they do not disclose classified information, jeopardize operations security, or mis- represent official U.S. policy. Such academic freedom empow- ers them to offer new and sometimes controversial perspectives in the interest of furthering debate on key issues. This report is cleared for public release; distribution is unlimited.
*****
This publication is subject to Title 17, United States Code, Sec- tions 101 and 105. It is in the public domain and may not be copy- righted.
ii
*****
Comments pertaining to this report are invited and should be forwarded to: Director, Strategic Studies Institute, U.S. Army War College, 632 Wright Ave, Carlisle, PA 17013-5046.
*****
All Strategic Studies Institute (SSI) publications are avail- able free of charge on the SSI website for electronic dissemi- nation. Hard copies of this report may also be ordered free of charge from the SSI website. The SSI website address is: www.StrategicStudiesInstitute.army.mil.
*****
The Strategic Studies Institute publishes a monthly e-mail newsletter to update the national security community on the re- search of our analysts, recent and forthcoming publications, and upcoming conferences sponsored by the Institute. Each newslet- ter also provides a strategic commentary by one of our research analysts. If you are interested in receiving this newsletter, please subscribe on our homepage at www.StrategicStudiesInstitute. army.mil/newsletter/.
ISBN 1-58487-468-6
iii
CONTENTS
Preface .......................................................................... v
Chapter 1. Introduction ............. ................................. 1 Tarek Saadawi and Louis Jordan
PART I: STRATEGY AND POLICY ASPECTS .......................... .......................................... 13
Chapter 2. Developing a Theory of Cyberpower ............................................................... 15 Stuart H. Starr
Chapter 3. Survivability of the Internet .................. 29 Michael J. Chumer
Chapter 4. Are L arge Scale Data Breaches Inevitable? ........................................................ 51 Douglas E. Salane
Chapter 5. The Role of Cyberpower in Humanitarian Assistance/Disaster Relief (HA/DR) and Stability and Reconstruction Operations ............................81 Larry Wentz PART II: SOCIAL AND LEGAL ASPECTS .......... 127
Chapter 6. The Information Polity: Social and Legal Frameworks for Critical Cyber
Infrastructure Protection .............................. 129 Michael M. Losavio, J. Eagle Shutt, and Deborah Wilson Keeling
Chapter 7. The Attack Dynamics of Political and Religiously Motivated Hackers ........... 159 Thomas J. Holt
PART III: TECHNICAL ASPECTS ........................ 181
Chapter 8. Resilience of Data Centers ................... 183 Yehia H. Khalil and Adel S. Elmaghraby
Chapter 9. Developing High Fidelity Sensors for Intrusion Activity on Enterprise Networks ....................................................... 207 Edward Wagner and Anup K. Ghosh
Chapter 10. Voice over IP: Risks, Threats, and Vulnerabilities .............................................. 223 Angelos D. Keromytis
Chapter 11. Toward Foolproof IP Network Configuration Assessments ....................... .263 Rajesh Talpade
Chapter 12. On the New Breed of Denial of Service (DoS) Attacks in the Internet .......................................................... 279 Nirwan Ansari and Amey Shevtekar
About the Contributors ........................................... 307
iv
v
PREFACE
The Internet, as well as other telecommunication
networks and information systems, have become an integrated part of our daily lives, and our dependency upon their underlying infrastructure is ever-increas- ing. Unfortunately, as our dependency has grown, so have hostile attacks on the cyber infrastructure by network predators. The lack of security as a core el- ement in the initial design of these information sys- tems has made common desktop software, infrastruc- ture services, and information networks increasingly vulnerable to continuous and innovative breakers of security. Worms, viruses, and spam are examples of attacks that cost the global economy billions of dollars in lost productivity. Sophisticated distributed denial of service (DDoS) attacks that use thousands of web robots (bots) on the Internet and telecommunications networks are on the rise. The ramifications of these at- tacks are clear: the potential for a devastating large- scale network failure, service interruption, or the total unavailability of service.
Yet many security programs are based solely on reactive measures, such as the patching of software or the detection of attacks that have already occurred, instead of proactive measures that prevent attacks in the first place. Most of the network security configu- rations are performed manually and require experts to monitor, tune security devices, and recover from attacks. On the other hand, attacks are getting more sophisticated and highly automated, which gives the attackers an advantage in this technology race.
A key contribution of this book is that it provides an integrated view and a comprehensive framework
vi
of the various issues relating to cyber infrastructure protection. It covers not only strategy and policy is- sues, but it also covers social, legal, and technical as- pects of cyber security as well.
We strongly recommend this book for policymak- ers and researchers so that they may stay abreast of the latest research and develop a greater understand- ing of cyber security issues.
1
CHAPTER 1
INTRODUCTION
Tarek Saadawi Louis Jordan
This book is intended to address important issues in the security and protection of information systems and network infrastructure. This includes the strategic implications of the potential failure of our critical net- work and information systems infrastructure; iden- tifying critical infrastructure networks and services; analysis and risk assessment of current network and information systems infrastructure; classification of network infrastructure attacks; automating the man- agement of infrastructure security; and building de- fense systems to proactively detect network attacks as soon as possible once they have been initiated.
The chapters in this book are the result of invited presentations in a 2-day conference on cyber infra- structure protection held at the City University of New York, City College, on June 4-5, 2009.1
The book is divided into three main parts. Part I deals with strategy and policy issues related to cyber security and provides discussions covering the theory of cyberpower, Internet survivability, large scale data breaches, and the role of cyberpower in humanitarian assistance. Part 2 covers social and legal aspects of cy- ber infrastructure protection and discusses the attack dynamics of political and religiously motivated hack- ers. Part 3 discusses the technical aspects of cyber in- frastructure protection including the resilience of data centers, intrusion detection, and a strong emphasis on Internet protocol (IP) networks.
2
STRATEGY AND POLICY ASPECTS
The four chapters in Part I provide a good frame- work for the various issues dealing with strategy and policy of cyber security. In Chapter 2, Stuart H. Starr presents a preliminary theory of cyberpower. The chapter, attempts to achieve five objectives. First, it will establish a framework that will categorize the various elements of the cyber domain. Second, it will define the key terms of interest. Third, it will begin to make clear the various benchmarks and principles that explain the various cyber categories. Fourth, it will characterize the degree to which the various cat- egories of the cyber domain are connected. Finally, it will anticipate key changes in the cyber domain and provide a basis for analyzing them.
However, it must be emphasized that this evolv- ing theory is in its preliminary stages. Thus, it is to be anticipated that it will not be complete. In addition, given the long gestation period for theories of “hard science” (e.g., physics, chemistry, and biology), it is likely that some of the elements are likely to be wrong.
In Chapter 3, Mike Chumer addresses the surviv- ability of the Internet. The use of the “commodity” Internet, referred to simply as the Internet, is the cor- nerstone of private and public sector communication, application use, information sharing, and a host of taken-for-granted usages. During a recent planning symposium in 2007, hosted by SunGard and the New Jersey Business Force, the key discussion question was, “Will the Internet Be There When You Really Need It?” The planning symposium focused on how the internet will be effected if a pandemic based upon H5N1 (the bird flu) was to break out in the United
3
States. In this chapter, Mr. Chumer addresses the fol- lowing issues that resulted from this symposium:
• Foreseeable short- and long-term impacts if the Internet either “crashes,” “goes down,” or “stops working”;
• Whether existing protocols for providing col- laboration and coordination between U.S. service providers (cable, telephone, and “last mile” providers) are sufficient enough to pre- serve Internet access and limit overload;
• Points of Internet failure that planners must consider when modifying or developing busi- ness practices;
• The effects on computer applications and/ or protocols if the Internet slows down rather than halting during a pandemic, as well as miti- gation strategies;
• In the face of heavy demand on the Internet, which features or services should contingency planners expect to shut down or redirect to conserve or preserve bandwidth;
• Whether contingency planners should expect attacks from hackers during a state when the Internet is weakened;
• Whether we as a nation are becoming too de- pendent on the Internet and underestimating its risks for the sake of cost, convenience, and efficiency;
• Will the Internet be resilient enough to hold up under the onslaught of school, business, home enterprise, emergency management, and recre- ational users during a pandemic?
Mr. Chumer concludes the chapter with a set of recommendations drawing upon those presented dur- ing the symposium.
4
Chapter 4 by, Douglas Salane, posits that despite heightened awareness, large scale data breaches con- tinue to occur and pose significant risks to both in- dividuals and organizations. The recent Heartland Payment Systems data breach compromised financial information in over 100 million transactions and in- volved financial records held by over 200 institutions. An examination of recent data breaches shows that fraudsters are increasingly targeting institutions that hold large collections of credit card and social secu- rity numbers. Particularly at risk are bank and credit card payment processors, as well as large retailers who do not properly secure their systems. Frequently, breached data winds up in the hands of overseas orga- nized crime rings that make financial data available to the underground Internet economy, which provides a ready market for the purchase and sale of large volumes of personal financial data. Credit industry studies based on link analysis techniques confirm that breached identities often are used to perpetrate credit fraud soon after a breach occurs. These stud- ies also show that breached identities may be used intermittently for several years. We conclude that strong data breach notification legislation is essential for consumer protection, and that the direct and in- direct costs of breach notification provide significant economic incentives to protect data. Our analysis also concludes that deployment of privacy enhancing tech- nologies, enterprise level methods for quickly patch- ing and updating information systems, and enhanced privacy standards are needed to mitigate the risks of data breaches.
Chapter 5, “The Role of Cyberpower in Humanitar- ian Assistance/Disaster Relief (HA/DR) and Stability and Reconstruction Operations,” by Larry Wentz, ex-
5
plores the role and challenges of cyberpower (infor- mation and communication technologies [ICT]) in humanitarian assistance/disaster relief (HA/DR) and stability and reconstruction operations. It examines whether a strategic use of cyber assets in U.S. Gov- ernment (USG) engagement and intervention activi- ties such as HA/DR and stability and reconstruction operations could lead to more successful results. Cer- tainly, the information revolution has been a dynamic and positive factor in business, government, and so- cial arenas in the Western world. The combination of technology, information content, and people schooled in the use of each has reshaped enterprises and activi- ties of all types.
Complicating the challenges of HA/DR and sta- bility and reconstruction operations related to failed- state interventions are the exacerbating difficulties that typically consist of: spoilers interfering with the intervening forces; refugees and internally displaced persons requiring humanitarian assistance; buildings requiring reconstruction; roads, power, water, tele- communications, healthcare, and education systems that are disrupted or dysfunctional; absence of a func- tioning government and laws, lack of regulations, and enforcement mechanisms; widespread unemploy- ment and poverty; and a shortage of leaders, manag- ers, administrators, and technical personnel with 21st century technical and management skills. Addition- ally, the operations lack a U.S. whole of government approach; a lack of trust among stakeholders; a lack of policy, procedures, business practices, and people; and organizational culture differences. It is not a tech- nology challenge per se, generally, technology is an enabler if properly employed.
6
The chapter concludes that civil-military collabora- tion and information sharing activities and the smart use of information and ICT can have decisive impacts if they are treated as a core part of the nation’s over- all strategy and not just as “nice to have” adjuncts to HA/DR initiatives, or to the kinetic phases of warfare and stability and reconstruction operations. It is fur- ther suggested that utilizing the elements of the infor- mation revolution and the whole of government in a strategic approach to HA/DR and stability and recon- struction operations can have positive results and sets forth the strategic and operational parameters of such an effort. Finally, enhancing the influence of USG re- sponses to HA/DR and interventions in stability and reconstruction operations will require a multifaceted strategy that differentiates the circumstances of the messages, key places of delivery, and sophistication with which messages are created and delivered, with particular focus on channels and messengers.
LEGAL AND SOCIAL ASPECTS
Cybercrime and attack dynamics are explored in Part II of this book. The first chapter is presented by Michael M. Losavio, J. Eagle Shutt, and Deborah Wil- son Keeling. The chapter examines how public policy may evolve to adequately address cybercrime. His- torically, legal protections against criminal activity have been developed in a world wherein any crimi- nal violation was coupled with physical proximity. Global information networks have created criminal opportunities in which criminal violation and physi- cal proximity are decoupled.
In Chapter 6, the authors argue that cyberspace public policy has not adequately incentivized and sup-
7
ported protective behaviors in the cyber community. They examine the roles that user-level/consumer- level conduct, social engagement, and administrative policy play in protecting information infrastructure. They suggest proactive work with laws and admin- istrative/citizen-level engagement to reform the cy- berspace community. To that end, they examine ap- plicable legal and transnational regimes that impact such a strategy and the options for expanding admin- istrative and citizen engagement in the cyber security enterprise.
Chapter 7, by Thomas J. Holt, is titled, “The At- tack Dynamics of Political and Religiously Motivated Hackers.” There is a significant body of research fo- cused on mitigating attacks through technical solu- tions. Though these studies are critical for decreasing the impact of various vulnerabilities and hacks, re- searchers still pay generally little attention to the af- fect that motivations play in the frequency, type, and severity of hacker activity. Economic gain and social status have been identified as critical drivers of com- puter hacker behavior in the past, but few have con- sidered how nationalism and religious beliefs influ- ence the activities of some hacker communities. Such attacks are, however, gaining prominence and pose a risk to critical infrastructure and web-based resources. For example, a number of Turkish hackers engaged in high profile web defacements against Danish websites that featured a cartoon of the prophet Muhammad in 2007. To expand our understanding of religious and nationalist cyber attack, this chapter explores the ac- tive and emerging hacker community in the Muslim- majority nation of Turkey. Using multiple qualitative data sets, including interviews with active hackers and posts from multiple web forums, the findings ex-
8
plore the nature of attacks, target selection, the role of peers in facilitating attacks, and justifications through the lens of religious and national pride. The results can benefit information security professionals, law enforcement, and the intelligence community by pro- viding unique insights on the social dynamics driving hacker activity.
TECHNICAL ASPECTS
The five chapters in Part III characterize the techni- cal and architectural issues of cyber security.
Chapter 8, by Yehia Khalil and Adel Elmaghraby, deals with the topic of the resilience of data centers. Data centers are the core of all legacy information in a cyber society. With the incredible growth of criti- cal data volumes in financial institutions, government organizations, and global companies, data centers are becoming larger and more distributed, posing more challenges for operational continuity in the presence of experienced cyber attackers and the occasional natural disasters. The need for resilience assessment emerged due to the gap in existing reliability, avail- ability, and serviceability (RAS) measures. Resilience as an evaluation metric leads to better system design and management; this chapter illustrates why resil- ience evaluation is needed and it surveys the continu- ing research.
Chapter 9, by Edward Wagner and Anup K. Ghosh, covers the development of high fidelity sen- sors for intrusion activity on enterprise networks. Future success in cyber will require flexible security, which can respond to the dynamic nature of current and future threats. Much of our current defenses are based upon fixed defenses that attempt to protect in-
9
ternal assets against external threats. Appliances like firewalls and proxies positioned at network segment perimeters similar to the Maginot Line attempt to shield us from outsiders attempting to break in. There are other mechanisms such as public key infrastruc- ture and antivirus software within the network pe- rimeter. This added layer is referred to as “Defense in Depth” methodology. However, in each component of security architecture, vulnerabilities are revealed over time. These defenses lack any agility; their defenses must become agile and responsive. They propose high fidelity sensors in the form of virtualized applications on each user’s machine to complement network-based sensors. In addition, they equip each user such that even as they are reporting intrusions, their machine and data are protected from the intrusions they are reporting. Their approach is able to protect users from broad classes of malicious code attacks, while being able to detect and report both known and unknown attack code.
IP networks are no longer optional throughout the business and government sectors. This fact, along with the emergence of international regulations on se- curity, reliability, and quality of service (QoS), means that IP network assessment is also no longer an op- tion. With IP networks representing the core of our cyber infrastructure, the lack of deep understanding of such networking infrastructure may lead to dras- tic strategic implications and may limit our ability to provide a solid cyber infrastructure. The remaining chapters in Part III focus exclusively on IP networks.
In Chapter 10, Angelos Keromytis, indicates that voice over IP (VoIP) and similar technologies are in- creasingly accepted and used by enterprises, consum- ers, and governments. They are attractive to all these
10
entities due to their increased flexibility, lower costs, and new capabilities. However, these benefits come at the cost of increased complexity, reliance on untested software, and a heightened risk of fraud. In this chap- ter, the author provides an overview of VoIP technol- ogies, outlines the risks and threats against them, and highlights some vulnerabilities that have been discov- ered to date. The chapter closes with a discussion of possible directions for addressing some of these is- sues, including the work in the ANR VAMPIRE proj- ect, which seeks to understand the parameters of the problem space and the extent of VoIP-related mali- cious activity.
Chapter 11, by Rajesh Talpade, discusses foolproof IP network configuration assessment. IP networks have come of age. They are increasingly replacing leased-line data infrastructure and traditional phone service, and are expected to offer Public Switched Telephone Network (PSTN)-quality service at a much lower cost. As a result, there is an urgent need for as- suring IP network security, reliability, and QoS. In fact, regulators are now requiring compliance with IP- related mandates. This chapter discusses the complex nature of IP networks, and how that complexity makes them particularly vulnerable to faults and intrusions. It describes regulatory efforts to mandate IP network assessment, explains why many current approaches to assessment fall short, and describes the requirements for an effective solution to satisfy business, govern- ment, and regulatory requirements.
In Chapter 12, Nirwan Ansari and Amey Shevtekar provide an overview on the new breed of denial of service (DoS) attacks on the Internet. Denial of service attacks impose serious threats to the Internet. Many at- tackers are professionals who are motivated by finan-
11
cial gain. They bring a higher level of sophistication along with inventive attack techniques that can evade detection. For example a shrew attack is a new type of threat to the Internet; it was first reported in 2003, and several of these types of attacks have emerged since. These attacks are lethal because of the inability of traditional detection systems to detect them. They possess several traits, such as low average rate and the use of transmission control protocol (TCP) as attack traffic, that empower them to evade detection. Little progress has been made in mitigating these attacks. This chapter presents an overview of this new breed of DoS attacks along with proposed detection systems for mitigating them. The chapter will lead to a better understanding of these attacks, and will stimulate further development of effective algorithms to detect these attacks and to identify new vulnerabilities which have yet to be discovered.
ENDNOTES – CHAPTER 1
1 . Available from www.ccny.cuny.edu/cip09.
PART I
STRATEGY AND POLICY ASPECTS
13
15
CHAPTER 2
DEVELOPING A THEORY OF CYBERPOWER*
Stuart H. Starr
INTRODUCTION
The goal of this chapter is to develop a preliminary theory of cyberpower. A theory of cyberpower will try to achieve five objectives.1 First, it will establish a framework that will categorize the various elements of the cyber domain. Second, it will define the key terms of interest. Third, it will begin to make clear the various benchmarks and principles that explain the various cyber categories. Fourth, it will characterize the degree to which the various categories of the cyber domain are connected. Finally, it will anticipate key changes in the cyber domain and provide a basis for analyzing them.
However, it must be emphasized that this evolv- ing theory is in its preliminary stages. Thus, it is to be anticipated that it will not be complete. In addition, given the long gestation period for theories of “hard science” (e.g., physics, chemistry, and biology), it is likely that some of the elements are likely to be wrong.
* The views expressed in this article are those of the author and do not reflect the official policy or position of the National Defense University, the Department of Defense or the U.S. Government. All information and sources for this chapter were drawn from un- classified materials.
16
ELEMENTS OF A THEORY
Categorize.
In analyzing the cyber domain, four key areas emerge (see Figure 2.1). These include the cyber- infrastructure (“cyberspace”), the levers of national power (i.e., diplomacy, information, military, eco- nomic [DIME], or “cyberpower”), the degree to which key entities are empowered by changes in cyberspace (“cyberstrategy”), and the institutional factors that affect the cyber domain (e.g., legal, governance, and organization). For the purposes of this chapter, this framework will be employed to decompose the prob- lem.
Figure 2.1. A Framework for Categorizing the Cyber Problem.
Levers of Power/ Cyberpower
Cyber-Infrastructure/ Cyberspace
Empowerment/ Cyberstrategy
17
Define.
Although the definitions of many of these terms are still contentious, this chapter will use the follo w - ing definitions of key terms. First is the formal definition of cyberspace that the Deputy Secretary of Defense formulated: “. . . the interdependent network of in- formation technology infrastructures, and includes the Internet, telecommunications networks, computer systems, and embedded processors and controllers in critical industries.”2 This definition does not explicitly deal with the information and cognitive dimensions of the problem. To deal with those aspects explicitly, we have introduced two complementary terms, “cy- berpower” and “cyberstrategy,” which were defined by Professor Dan Kuehl, National Defense University (NDU).
The term cyberpower means “the ability to use cy- berspace to create advantages and influence events in the other operational environments and across the in- struments of power.”3 In this context, the instruments of power include the elements of the DIME paradigm. For the purposes of this evolving theory, primary em- phasis will be placed on the military and information- al levers of power.
Similarly, the term cyberstrategy is defined as “the development and employment of capabilities to op- erate in cyberspace, integrated and coordinated with the other operational domains, to achieve or support the achievement of objectives across the elements of national power.”4 Thus, one of the key issues associ- ated with cyberstrategy deals with the challenge of devising “tailored deterrence” to affect the behavior of the key entities empowered by developments in cyberspace.
18
Explain.
Cyberspace. Over the last 15 years, a set of rules of thumb have emerged to characterize cyberspace. Some of the more notable of these rules of thumb in- clude the following:
• Moore’s Law (i.e., the number of transistors on a chip approximately doubles every 18 months);5
• Gilder’s Law (“total bandwidth of communica- tion systems triples every 12 months”);6
• Proliferation of IP addresses in transitioning from IPv4 to IPv6 (e.g., IPv6 will provide 2128 addresses; this would provide 5x1028 addresses for each of the 6.5 billion people alive today).
In addition, recent analyses have suggested the fol- lowing straw man principles for cyberspace. First, the offensive has the advantage. This is due to the chal- lenges of attribution of an attack and the fact that an adversary faces a “target rich” environment. Conse- quently, if cyberspace is to be more resistant to attack, it may require a new architecture that has “designed in” security.
Cyberpower. Robert Metcalfe formulated one of the oft-quoted laws of cyberpower.7 He characterized the value of a network as “N2,” where N describes the number of people who are part of the network. How- ever, more recently, it has been demonstrated that the value of a network tends to vary as N*log (N). Note that this equation suggests that the “value” of a net- work is substantially less than “Metcalfe’s Law.”8
In addition, there have been many studies about the contribution that net-centricity can have to mission effectiveness. For example, studies of air-to-
19
air combat suggest that the value of a digital link (e.g., Link 16) can enhance air-to-air loss exchange ratios by approximately 2.5.9 This is due to the enhanced situa- tion awareness, improved engagement geometry and the efficiency of the engagement. However, the com- plexity of modern conflict is such that it is difficult to assess the affect of net-centricity on complex missions. Thus, for example, studies of air-land operations are much more complex and very scenario-dependent. In addition, preliminary studies of humanitarian assis- tance/disaster relief and stability operations are cur- rently underway. Chapter 5 in this book will provide preliminary results for those operations.
Cyberstrategy. Recent studies have suggested that the “low end” users (e.g., individuals, “hacktivists,” terrorists, and transnational criminals) have consider- ably enhanced their power through recent cyberspace trends.10 This is due, in part, to the low cost of entry into cyberspace (e.g., the low cost for a sophisticated computer or cell phone; the extensive investment that the commercial world has made in cyberspace (e.g., applications such as Google Earth); and the major in- vestments in cyberspace that have been made by gov- ernments (e.g., the Global Positioning System).
Similarly, potential near-peer adversaries are ag- gressively exploring options to exploit attributes of cyberspace (e.g., exfiltration of data; distributed de- nial of service attacks, and implementation of inno- vative cyber stratagems). These activities have been well-documented in recent news accounts.11
From a U.S. perspective, new concepts and initia- tives are emerging from the Comprehensive National Cyber Initiative (CNCI). At a minimum, it has been recommended that the United States must incorporate a creative and aggressive cyber “opposing force” to stress the system in future experiments and exercises.
20
Institutional Factors. Over the last several years, a number of studies have been conducted to address the issues of cyberspace governance, the legal dimension of cyberspace and cyberpower, the tension between civil liberties and national security, and the sharing of information between the public and private sectors. In the area of cyberspace governance, there is a growing appreciation that one should seek influence over cy- berspace vice governance. In the near term, there are a number of policy governance issues that remain to be addressed (e.g., the extension of the contract of the In- ternet Corporation for Assigned Names and Numbers [ICANN]; and the role of the International Telecom- munications Union [ITU] in cyber governance).
The legal dimension of cyberspace has barely ad- dressed the key issues that must be resolved during the next decade. For example, the issues of concern include: what is an act of cyber war; what is a propor- tionate reaction to an act of cyber war; how should one treat intellectual property in cyberspace; how should one resolve differences in sovereign laws and interna- tional treaties.
It is broadly recognized that there is a need for a framework and enhanced dialogue to harmonize the efforts of civil liberties and proponents of enhanced national security. This issue is being pursed as a com- ponent of the CNCI initiative.
Finally, many studies have cited the need to ad- dress the issue of sharing of cyber information be- tween the U.S. Government and industry. However, there is still a need to provide guidance and proce- dures to clarify this issue.
21
Connect.
It is well understood that the various categories of the cyber domain are strongly interconnected. To address this problem, there is a need for a family of Measures of Merit (MoM) to provide that linkage (see Figure 2.2).
Figure 2.2. Representative Measures of Merit.
For example, cyberspace can be characterized by a set of Measures of Performance (MoPs). These might include performance in cyberspace (e.g., connectivity, bandwidth, and latency) and resistance to adversary countermeasures (e.g., resistance to distributed denial of service attacks, resistance to exfiltration attempts, and resistance to corruption of data).
In the areas of cyberpower, it is useful to think about Measures of Functional Performance (MoFP) and Measures of Effectiveness (MoE). For example, in the case of air-to-air combat, appropriate MoFP
22
might be the range at which air combatants are able to detect, identify, and characterize unknown aircraft. Similarly, loss exchange ratios may be suitable MoE.
In the area of cyberstrategy, one might use politi- cal, military, economic, social, information, and infra- structure (PMESII) measures to characterize Measures of Entity Empowerment (MoEE). Thus, for example, one could characterize the extent to which changes in cyberspace might effect changes in politics (e.g., the number of people who vote in an election), military status (e.g., the enhancement in the security of the population), economic factors (e.g., the change in un- employment statistics), social (e.g., ability of diverse social groups to live in harmony), information (e.g., the extent to which social networks support political activity), and infrastructure (e.g., the extent to which improvements in supervisory control and data ac- quisition [SCADA] systems enhance the availability of electricity and clean water). The actual MoEE will have to be tailored to the entity that is being empow- ered by changes in cyberspace. Thus, a terrorist, who seeks to, inter alia, proselytize, raise money, educate, and train, would have a different set of MoEE.
Finally, one needs to formulate MoMs that are ap- propriate for issues of governance; legal issues, civil liberties, critical infrastructure protection, and cyber reorganization. Work is currently ongoing in those fields.
Anticipate.
From the perspective of a senior decisionmaker, the key challenge is anticipating the key issues of in- terest and performing the analyses needed to make knowledgeable decisions.
23
In the area of cyberspace, it is important to perform technology projections to identify potential key break- throughs (e.g., cloud computing); explore options to enhance attribution in cyberspace; develop techniques to protect essential data from exfiltration or corrup- tion; and formulate an objective network architecture that is more secure and identify options to transition to it.
In the area of cyberpower, it is important to extend existing analyses to assess the impact of changes in cy- berspace on the other elements of power (e.g., diplo- matic and economic) and to perform risk assessments to guide future policy decisions.
In the area of cyberstrategy, additional research is needed to guide the development of “tailored deter- rence” (particularly against nonstate actors) and to explore options to thwart the efforts of key entities to perform cyber espionage.
In the area of institutional factors, the major chal- lenges are to address the legal issues associated with the cyber domain and to harmonize civil liberties and national security.
Overall, there is a need to develop assessment methods, tools, data, services (e.g., verification, vali- dation, and accreditation [VV&A]), and intellectual capital to assess cyber issues. Figure 2.3 suggests the relative maturity of key tools in the areas of cyber- space, cyberpower, cyberstrategy, and institutional factors.
24
Figure 2.3. State-of-the-Practice in Assessing Cyber Issues.
In the area of cyberspace, there are several tools that the community is employing to address computer science and communications issues. Perhaps the best known is the operations network (OPNET) simulation that is widely employed to address network architec- tural issues.12 From an analytic perspective, techniques such as percolation theory enable one to evaluate the robustness of a network.13 Looking to the future, the National Research Laboratory (NRL) has developed a Global Information Grid (GIG) Testbed to explore the myriad issues associated with linking new systems and networks.
In the area of cyberpower, the community has had some success in employing live, virtual, and construc- tive simulations. For example, in assessments of air- to-air combat, insights have been derived from the
DAPSE, COMPOEX
Cyberstrategy
Cyberpower M&S: LVC
Cyberspace M&S: OPNET
Analysis: Percolation Theory Testbeds: NRL GIG Testbed
Ins tit
ut ion
al Fa
cto rs
(e. g.,
Le ga
l Is su
es CI
P To
ols )
Legend: Black: Satisfactory White: Marginal Grey: Significant Challenges
25
live Air Intercept Missile Evaluation/Air Combat Evaluation (AIMVAL-ACEVAL) experiments, virtual experiments in the former McDonnell Air Combat Simulator (MACS), and constructive experiments us- ing tools such as TAC BRAWLER. However, the com- munity still requires better tools to assess the impact of advances in cyberspace on broader military and informational effectiveness (e.g., land combat in com- plex terrain).
In the area of cyberstrategy, a number of promis- ing initiatives are underway. In response to a recent tasking by Strategic Command (STRATCOM), a new methodology and associated tools are emerging (i.e., Deterrence Analysis & Planning Support Environment [DAPSE]).14 However, these results have not yet been applied to major cyberstrategy issues. In addition, promising tools are emerging from academia (e.g., Senturion; GMU’s Pythia) and Defense Advanced Research Projects Agency (DARPA) (e.g., Conflict Modeling, Planning & Outcomes Experimentation [COMPOEX]). However, these are still in early stages of development and application.
Finally, as noted above, there are only primitive tools available to address issues of governance, legal issues, and civil liberties. Some tools are being devel- oped to explore the cascading effects among critical infrastructures (e.g., National Infrastructure Simula- tion and Analysis Center [NISAC] system dynamics models); however, they have not yet undergone rigor- ous validation.15
KEY CHALLENGES
Theories for the “hard” sciences have taken hun- dreds of years to evolve. However, this preliminary “theory of cyberpower” is approximately only 1-year
26
old! As a consequence, there is a great deal of work that remains to be done in each of the areas of interest.
In the area of Categorize, it is understood that the preliminary framework is just one way of decompos- ing the problem. It is necessary to formulate alterna- tive frameworks to support further decomposition of the cyber domain.
In the area of Define, there has been a great deal of contention over the most basic terms (e.g., cyberspace and domain). Steps must be taken in the near term to develop a taxonomy that will formulate and define the key terms of interest.
In the area of Explain, it is understood that we are just beginning to deal with a very complex and time- variable problem set. It is vital to conduct studies to create benchmarks and to gain a deeper understand- ing of key cyber issues.
In the area of Connect, the selection of MoMs is in its infancy. We must consider all of the entities that are being empowered by changes in cyberspace and develop appropriate MoMs for them.
Finally, in the area of Anticipate, we understand the challenge in trying to predict the evolution of cy- berspace. At a minimum, we need to generate a re- search agenda to address unresolved cyber issues. This should include the development of methods, tools, data, services (e.g., VV&A), and intellectual capital to attack many of these problems.
ENDNOTES - CHAPTER 2
1. Dr. Harold R. Winton, “An Imperfect Jewel,” presented at INSS workshop on the Theory of Warfare at the National Defense University, Washington, DC, September 2006.
27
2. Deputy Secretary of Defense Memorandum, “The Defini- tion of Cyberspace,” Washington, DC: Department of Defense May 12, 2008.
3. Daniel T. Kuehl, “From Cyberspace to Cyberpower: De- fining the Problem.” in Franklin D. Kramer, Stuart H. Starr, and Larry K. Wentz, Eds., Cyberpower and National Security, Washing- ton, DC: Center for Technology and National Security Policy, Na- tional Defense University, Potomac Books, Inc., 2009, p .48.
4. Ibid., p. 40.
5. Sally Adee, “37 Years of Moore’s Law,” IEEE Spectrum, May 2008.
6. Rich Kalgaard, “Ten Laws of the Modern World,” April 19, 2005, available from Forbes.com.
7. George Gilder, “Metcalfe’s Law and Legacy,” Forbes ASAP, September 13, 1993.
8. Bob Briscoe, Andrew Odlyzko, and Benjamin Tilly, “Met- calfe’s Law is Wrong,” IEEE Spectrum, July 2006.
9. Dan Gonzales et al., “Network-Centric Operations Case Study: Air-to-Air Combat With and Without Link 16,” Santa Monica, CA: RAND Corporation, National Defense Research In- stitute, 2005.
10. Irving Lachow, “Cyber Terrorism: Menace or Myth?” Chap. 19, Cyberpower and National Security, Bethesda, MD: Po- tomac Press, 2009.
11. John Markoff, “Vast Spy System Loots Computers in 103 Countries,” New York Times, March 29, 2009.
12. Emad Aboelela, “Network Simulation Experiments Man- ual,” Amsterdam: Morgan Kaufmann Publishers, 3rd Ed., June 2003.
13. Ira Kohlberg, “Percolation Theory of Coupled Infrastruc- tures,” 2007 Homeland Security Symposium entitled “Cascading
Infrastructure Failures: Avoidance and Response,” Washington, DC: National Academies of Sciences, May 2007.
14. “Deterrence in the 21st Century: An Effects-Based Ap- proach in An Interconnected World, Vol. I,” Nancy Chesser, ed., Strategic Multi-Layer Analysis Team, USSTRATCOM Global Inno- vation and Strategy Center, October 1, 2007.
15. Colonel William Wimbish and Major Jeffrey Sterling, “A National Infrastructure Simulation and Analysis Center (NISAC): Strategic Leader Education and Formulation of Critical Infra- structure Policies,” Carlisle, PA: Center for Strategic Leadership, U.S. Army War College, August 2003.
28
29
CHAPTER 3
SURVIVABILITY OF THE INTERNET
Michael J. Chumer
INTRODUCTION
In 2007, a symposium was sponsored by the New Jersey Business Force (NJBF) and SunGard. During the symposium, a panel of experts posed a series of questions that were then addressed in detail by work- groups drawn from the symposium participants. This chapter presents the key issues identified by those is- sues that affect the resilience and survivability of the Internet during a pandemic declaration.
The use of the “commodity” Internet, referred to simply as the Internet, is the cornerstone of private and public sector communication, application access and use, information sharing, and a host of taken-for- granted usages. During the SunGard1 and NJBF2 sym- posium in 2007, the key question posed and addressed was, “Will the Internet Be There When You Really Need It?”3 The planning symposium focused on the effects on the Internet if a pandemic based upon H5N1 (the bird flu) was to break out in the United States. In addition, the symposium addressed reciprocal effects on businesses given a marginally functioning Internet.
From the middle of April 2009 to the present, the United States has been in a pre-pandemic event sug- gested by the World Health Organization (WHO) as stage 5.4 This in turn has caused many private sector organizations to review their pandemic plans and take the necessary steps to revise and adjust them in anticipation of a pandemic declaration. The virus
30
strain is called H1N1 (swine flu) instead of the H5N1, but that does not alter the business planning process or the steps that make sense for organizations to take in preparation of such a declaration.
As the symposium suggested, a pandemic plan should consider the availability of the Internet for business continuity, given that social distancing will be required. Social distancing will affect all employ- ees, to include “key” personnel. As personnel work from home, the traffic on the Internet will change in a way where certain Internet Service Providers (ISP) may encounter Internet traffic loads that were not an- ticipated.
SYMPOSIUM DATA COLLECTION
The symposium was conducted as a modified table top exercise (TTX). In the morning, presentations were given that addressed the H5N1 virus along with pre- dictions on how it might spread in the United States; who would be at risk; the role of the public sector, personal protection and the responsibility of the indi- vidual; and some initial thoughts about the role and concerns of business and business continuity planning in general. Initial presentations by 10 experts were fol- lowed by a facilitated panel discussion designed to surface issues that would later be discussed in detail by the symposium participants.
Subsequent to the panel discussion, the 110 partici- pants were divided into workgroups which engaged in a TTX that addressed in more detail the major ques- tions that surfaced during the panel discussion.
Data that resulted from the panel discussion and from the individual workgroup TTXs were captured and analyzed by a team of researchers. The key items
31
in the panel and TTX data were identified, resulting in a white paper jointly authored by the NJBF and SunGard.5 Most of the material contained in the white paper has been incorporated and reassessed in this chapter.6
In the white paper, a series of topical area issues posed as questions were developed:
• Business continuity effects due to Internet reduced availability. What are the foreseeable short-term and long-term impacts if the Inter- net either “crashes,” “goes down,” or “stops working”?
• Service provider collaboration for the collec- tive good. Explain whether existing protocols for providing collaboration and coordination between U.S. service providers (cable, tele- phone, and “last mile” providers) are sufficient enough to preserve Internet access and limit overload.
• Points of Internet failure. What must planners consider when modifying or developing busi- ness practices?
• The effects on computer applications and/or protocols. What are the effects on applications and/or protocols if the Internet slows down rather than halting during a pandemic, as well as mitigation strategies for such an event?
• Increased Internet demand. In the face of heavy demand on the Internet, which features or services should contingency planners expect to shut down or redirect to conserve or preserve bandwidth?
• Hacker Attacks. Should contingency plan- ners expect attacks from hackers during a state when the Internet is weakened?
32
• Growing Internet Reliability. Whether we as a nation are depending too much on the Inter- net and underestimating its risks for the sake of cost, convenience, and efficiency?
• Internet Resilience. Will the Internet be resil- ient enough to hold up under the onslaught of school, business, home enterprise, emergency management, and recreational users during a pandemic?
CURRENT ESCALATING SITUATION
On June 11, 2009, the WHO raised the pandemic alert level from phase 5 to phase 6, which indicates the start of a full-fledged worldwide pandemic. This declaration, in turn, suggests that certain actions or behaviors should be “triggered” within organizations (the public and/or private sector). The general discus- sion that follows in the next section reveals answers to questions about the effects of a pandemic declaration on the Internet. Many business organizations, in turn, are reviewing their current continuity of operations plans (COOPS), and public sector organizations also are reviewing their continuity of government plans (COOGS). The next section also provides guidance to organizations about what issues they need to address to ensure that business can continue to function and continue to survive during a pandemic.
That section also indicates that the “commodity” Internet plays a significant and vital role in the abil- ity of business to do business. The Internet is a critical component within the supply-and-value chain of each organization, linking businesses as the producers of products and/or the providers of services to the cus- tomers that benefit from those products and services.
33
The reliance on the Internet has grown over the past 16 years (the backbone of the Internet was contracted in 1993 or outsourced by the National Science Founda- tion to the private sector). This growth has been expo- nential and, along with it, a growing dependency and interdependency has occurred, with the tacit belief that the Internet will always be there. Businesses have developed processes and procedures where the Inter- net is a critical component. If the Internet slows down significantly, which may occur during a pandemic, or even cease to function in certain parts of the country due to unexpected traffic patterns, coupled with deni- al of service attacks, business and governments need to be prepared. This will not be an easy task.
GENERAL DISCUSSION
The sections that follow discuss in detail the an- swers to the questions that were posed to symposium attendees through the panel discussion and the subse- quent TTX. Each section provides planning guidance to both organizational planners and organizational emergency management/security functions.
Business Continuity Effects Due to Internet Reduced Availability with Examples of Healthcare and Education.
The symposium data suggested that healthcare and education would be greatly impacted over the long term during periods of reduced availability. In 2006, healthcare approached one-sixth of the gross domestic product (GDP), inferring that the economic impact during periods of reduced Internet availability would be significant. The amount of communication
34
being passed over the Internet due to patient electron- ic records, clinical data being shared geographically, and the bandwidth of clinical data, especially those requiring visualization, would all suffer time lags and delays with the ultimate potential of affecting patient diagnostics and treatment protocols.
A significant percentage of education from K-12 is still done face-to-face (F2F), suggesting that dur- ing periods of social distancing, essential delivery of education material would not occur. When education delivery is viewed at the community college or col- lege level, we do see a movement toward both dis- tance learning and hybrid (blended learning) course delivery. However, the majority of distance learning courses are delivered over home-to-school Internet connections, suggesting that some delays in the deliv- ery of course content would occur during periods of reduced Internet availability.
In addition, over the short term, e-mails—which in 2006 averaged 84 billion per day—voice over Internet protocol (VOIP), and instant messaging would be af- fected. This will leave those people whose social net- works are tied to a virtual space to seek out different forms of social networking. It might be very difficult during periods of social distancing for those individu- als and collectives that rely on virtual communication to adapt to both physical and virtual isolation.
Service Provider Collaboration for the Collective Good.
The symposium discussed whether existing pro- tocols for providing collaboration and coordination between U.S. service providers (cable, telephone, and “last mile” providers) are sufficient enough to pre-
35
serve Internet access and limit overload. Discussion for this topic was robust. It is clear that the ownership of the Internet resides with the private sector and, in that vein, there is some but not a lot of coordination between Internet “backbone” providers to ensure that infrastructure “build-outs” keep up with capacity demands. However, during a pandemic or any emer- gency situation which may require a reduction of In- ternet traffic, existing protocols are either insufficient or do not exist. Furthermore, the symposium data suggested,
To date the private sector has established no definitive industry standards governing Internet user priorities and preferences in the event of a catastrophic event or an ‘incident of national significance.’7
This gets into the entire notion of establishing pri- orities during periods of reduced Internet availability. Recommendations emerging from the symposium in- clude the following:
• In emergency situations; forming an advisory group comprising Internet Service Providers and Government representatives to address key issues;
• Expanding the role of existing ISP groups (FIS- PA) to include formulating policies.
As the discussion moved forward, a further sug- gestion was that, during a pandemic or a national emergency, each organization should “voluntarily” reduce their Internet traffic by 10 percent below peak levels. Additional symposium recommendations in this area were:
• limiting video streaming and VoIP; • adopting off-hour business solutions;
36
• prioritizing business applications; • blocking noncritical Internet traffic.8
This is certainly an area open to more debate, such as addressing the role government should play in In- ternet traffic regulation during emergency situations and/or periods of reduced Internet availability. The consensus was that the government should be a part- ner with the private sector with limited intervention.
Points of Internet Failure.
The symposium data indicated that planners must consider access infrastructure and bandwidth as they develop business practices that focus on their conti- nuity of operations. Access infrastructure must be planned from business locations to the first ISP and also from a “critical” employee location to that em- ployee’s primary ISP. Businesses for the most part do a good job in monitoring their network traffic to include their Internet access points. There are often “first” and “last mile” issues which suggest that redundancy of access becomes a critical part of the plan. However, what is often overlooked is the access that critical em- ployees should have from their home location. This becomes an important planning consideration during social distancing when the tacit expectation is that an employee can access organizational applications from their home location as they would from their work location. For employees, the issue of “first” and “last mile” redundancy becomes salient as well. This sug- gests that organizational planners should possess an inventory of critical employee home access capabili- ties which might suggest redundant Internet access from a home location.
37
Bandwidth is the second item that planners must consider. Again, this is important at business locations, but becomes more important when employees work at home. We are in an era where audio, video, and graphics are transmitted over Internet infrastructures. Many organizational applications are developed for a thin client architecture where most of the processing is performed on organizational servers. This architec- ture suggests that significant bandwidth capacity may be required to access web-based organizational appli- cations.
The symposium data indicated that the follow- ing are the least likely points of failure: “Among the least likely points of failure are Domain Name Serv- ers (DNS), corporate high-capacity bandwidth, local exchange carrier, and redundant corporate routing.”9
The Effects on Computer Applications and/or Protocols.
What are the effects on applications and/or pro- tocols if the Internet slows down rather than halting during a pandemic, as well as mitigation strategies? Symposium data suggested that this question is tight- ly coupled to the role that the Internet plays within organizational supply and value chains.10 Much of or- ganizational supply and value chains are outsourced to different organizations (vendors or partners) re- quiring “tight coupling”11 from a communication perspective. This suggests that access and bandwidth considerations that were previously addressed take on a significant level of importance.
In conjunction with supply and value chain con- siderations unique to the specific organization, there is the entire issue of supply/value chain interdependen-
38
cies and critical application access.12 Business environ- ments where a “just in time” mentality has developed suggests a business continuity focus on stabilizing the supply chain during a pandemic or incident of national significance. The symposium indicated that the supply/value chain issue should be stabilized first before employee essential needs of “food, water, and healthcare” should be addressed.13
Increased Internet Demand.
In the face of heavy demand on the Internet, which features or services should contingency planners ex- pect to shut down or redirect to conserve or preserve bandwidth? The Internet has become less of an “ame- nity” and more of an “expectation.”14 Witness that what began as a service that hotels would offer to gain a competitive advantage has now become a common expectation of business travelers. Since the expecta- tion for robust and ubiquitous Internet services has been set, restricting usage would be met by a general resistance from the public writ large. This resistance could be somewhat overcome by requesting the pub- lic to engage in behavior directed toward voluntary restrictions on their Internet use. However, the sym- posium indicated that “Voluntary restrictions would have to be imposed for limited periods, applied eq- uitably, and based on established priorities.”15 It was recommended that the public sector, especially the individual states, develop a list of priority users and suggested the following:
• “Urgent (utilities, public service networks, gov- ernment),
• Priority (commodity transportation, food, medicine, relief supplies),
• Normal (those not listed above).”16
39
What was not mentioned at the symposium but has relevance here is the development of a priority switching scheme for critical Internet services. At pres- ent there is “Internet 2”17 and “The National Lambda Rail.”18 Both are services that possess fiber backbones which are separate from the basic backbone infra- structure of the commodity Internet. Once developed, urgent and priority services could benefit by being switched during an emergency to one of these high bandwidth, high capacity services.
Hacker Attacks.
Should contingency planners expect attacks from hackers during a state when the Internet is weakened? The symposium data indicated that the cyber infra- structure used by organizations is always at risk from hackers and from a variety of sources initiating un- wanted intrusions. During a pandemic, it was agreed that the weakened state of the commodity Internet has the potential of putting organizations at a higher level of risk. The greatest vulnerabilities will be in the areas of online banking and the movement of critical opera- tions to the commodity Internet.
It is expected that during periods of social distanc- ing, online banking activity will increase significantly which would open up opportunities for hacking. Ad- ditionally, as more organizationally “critical” applica- tion functions move to the Internet due to employees performing telework, this will become a target for hacking activity as well. Hackers are not averse to tak- ing advantage of other vulnerabilities. It was agreed that identify theft activities would increase signifi- cantly, especially targeting people who died as a re-
40
sult of the pandemic. Finally, the weakened state of the Internet could spawn denial of service activity. The white paper suggested the following as potential remedies:
Businesses should consider adding varying degrees of redundancy and security during their preparations. They can improve the security of online, networked operations during the mass migration of critical func- tions and services, including telecommuting, to the Internet. Specifically, companies can step up enforce- ment of standard security controls and policies (e.g., firewalls).
They also can install encryption software, limit em- ployee access and privileges to e-mail, and control ac- cess to major non-mission-critical business processes. They can increase the frequency of mandatory pass- word resets, require two-factor authentication, set tighter controls over extra-net partners, implement more aggressive patch management, and increase monitoring of the cyber or virtual environment.19
Growing Internet Reliability.
Are we as a nation becoming too dependent on the Internet and underestimating its risks for the sake of cost, convenience, and efficiency? Internet depen- dency has been growing since the National Science Foundation allowed the commercialization of the In- ternet backbone in 1993. E-mail communication has increased significantly each year, and services like “Facebook”20 and “Twitter”21 are beginning to rede- fine technology based “social networking.” Blogging activity is increasing, as well as online shopping. So we as a nation and as a society have become very de- pendent upon the Internet and have incorporated its
41
use into everyday life. The Internet has become ex- tremely convenient.
The convenience of the Internet needs to be bal- anced against potential risks. An understanding of this balance and the steps that should be taken by people in general, and organizational employees specifically, suggest focus and constant reinforcement on educa- tion. This education should address and develop an understanding of the risks of the Internet and its coun- terbalance—the rewards of Internet use.
A list of planning guidelines that organizations should follow for both educating themselves as well as educating their employees is included in the appen- dix. During the symposium, the value of developing a risk–reward education program was stressed in order to further develop an understanding of the risks and vulnerabilities of Internet use and access.
Internet Resilience.
Will the Internet and ISPs be resilient enough to hold up under the onslaught of school, business, home enterprise, emergency management, and recreational users during a pandemic?22 The ability for ISPs to en- gineer their capacity in such a way where they are able to accommodate this surge becomes important. It is expected that the Internet will not “break” during a pandemic, but it will certainly “bend” under the surge in expected use.
The white paper suggested areas that need to be addressed to begin to ensure that the Internet is as re- silient as possible. These are:
The goal would be to avoid or eliminate single points of failure; establish reliability standards; have multi- ple geographically isolated Post Office Protocal (POP)
42
servers; and ensure redundancy using non-terrestrial communications to geographically diverse ground stations. In addition, Tier 1 and 2 providers could manage bandwidth for Tier 3 and 4 providers, allow- ing maximum efficiency in meeting the expected surge in demand for Internet bandwidth.23
CONCLUSION
In general, it was concluded that the backbone of the Internet is fairly “robust” and should be capable of withstanding the surge that would be expected during the initial stages of a pandemic declaration. However, the points of backbone access and the ability to ad- dress local surge issues may cause the Internet to bend to levels that may be unacceptable to local users. The white paper that followed the symposium concluded with the following recommendation, included here in its entirety:
In the U.S., the Internet is analogous to private and commercial cars and trucks, i.e., it is indispensable. Continuity of Operations (COOP) planners must take threats to Internet availability as seriously as they would take threats to the availability of gasoline.
The direct and indirect threats a pandemic would pose to the Internet are genuine.
The potential for hostile human interference—for ex- ample, terrorist attacks or other disruptive behavior— during a pandemic should be factored into continuity plans. The U.S. economy remains a high-value target, and America’s enemies probably would attempt to ex- ploit a pandemic through asymmetrical warfare (e.g., cyber attacks) to further weaken the economy and therefore the country.
43
Degradation or loss of Internet service during a pandemic may reduce businesses to a state Herbert Spencer described as ‘survival of the fittest.’ In this environment, organizations that were well prepared beforehand will have the best chance of prevailing. To improve their chances, companies can: • Engineer systems for peak usage by expanding
capacity or reserving additional bandwidth, • Eliminate or reduce vulnerabilities, and • Educate employees to take care of themselves.
Internet Service Providers (ISPs) and government representatives should form a joint task force to de- velop an Internet assurance strategy and voluntary guidelines for implementation during a pandemic. However, while the private sector probably would accept voluntary controls over Internet use during a pandemic, as long as limitations and restrictions are justifiable and equitably applied, government-direct- ed mandates could be opposed as Marshall Law.
Identify potential problems now by conducting com- prehensive exercises that would stress IT systems. Companies could conduct tests locally at first, adopt- ing a process of continuous review that would inte- grate technology issues into overall planning efforts, incorporate the legal and human resources functions into the planning process, ensure that critical em- ployees have primary and secondary means of com- munication, develop policies and standard operating procedures for mission critical functions, and establish a worst-case scenario as a baseline for testing. Com- panies could then coordinate regional exercises with government and other businesses.
The supply chain is a national center of gravity, and the Internet is an integral component of America’s economic engine. These are a foundation of business and workforce survival; therefore, protecting them is essential for Continuity of Community and economic
44
recovery. Because the ‘social fabric’ may unravel in the event of a supply chain meltdown, companies should organize mitigation measures around supply chain failures and the reduced availability of critical work- ers. These Page measures are an essential underpin- ning for successful voluntary home isolation policies.
There are non-intrusive steps the private sector can take to prevent Internet overload and preserve capac- ity. These include voluntary conservation guidelines, in-house measures and protocols to limit consumption of bandwidth, and employee understanding and com- pliance.
Companies and government should prepare the gen- eral public for Internet disruptions. This preparation can include promoting civic responsibility to gain co- operation for Internet emergency measures, explain- ing Internet prioritization schemes, and trying to take the mystique out of information technology (i.e., per- suade people that IT is a utility or resource, not much different from electricity or transportation).
Companies, government, and the general public should strive to understand a pandemic’s physi- ological and technological challenges, and then adopt multi-faceted approaches to physical, cyber, and per- sonnel protection.24
These recommendations frame the type of “pre- paredness” thinking that should go into the develop- ment of plans due to a pandemic declaration (we are now in WHO, phase 6). The appendix provides im- portant and specific guidance to planners given the uncertainty of H1N1.
45
ENDNOTES - CHAPTER 3
1. SunGard, available from www.sungard.com/.
2. New Jersey Business Force, www.njbusinessforce.org/.
3. New Jersey Business Force/SunGard White Paper, “Will the Internet Be There When You Really Need It?” Pandemic Sym- posium sponsored by the New Jersey Business Force and Sun- Gard, 2007.
4. World Health Organization, www.who.int/en/.
5. New Jersey Business Force/SunGard White Paper.
6. Ibid.
7. Ibid., p. 4.
8. Ibid.
9. Ibid., p. 4.
10. M. E. Porter, “How Competitive Forces Shape Strategy,” Harvard business Review, March/April 1979; M. E. Porter, Competi- tive Strategy, New York: Free Press, 1980; M. E. Porter, Competitive Advantage, New York: Free Press, 1985.
11. M. J. Chumer and M. Turoff, “Command and Control (C2): Adapting the Distributed Military Model for Emergency Re- sponse and Emergency Management,” 11th ICCRTS, 2006, avail- able from www.dodccrp.org/events/11th_ICCRTS/html/papers/005. pdf.
12. Porter, “How Competitive Forces Shape Strategy”; Porter, Competitive Strategy; Porter, Competitive Advantage.
13. New Jersey Business Force/SunGard White Paper, p. 5.
14. Ibid., p. 7.
15. Ibid., p. 7.
46
16. Ibid., p. 7.
17. Internet 2, available from www.internet2.edu/.
18. National Lambda Rail, available from www.nlr.net/.
19. New Jersey Business Force/SunGard White Paper, p. 8.
20. Facebook, available from www.facebook.com/.
21. Twitter, available from twitter.com/.
22. Robert Stephan, Statement for the Record, 2008, available from homeland.house.gov/SiteDoments/20080514143442-12325.doc.
23. New Jersey Business Force/SunGard White Paper, p. 10.
24. Ibid., pp. 11-12.
47
APPENDIX
The 10 items listed in this appendix are drawn directly from the white paper and are offered here as guidance for all organizations to follow in developing a resilient COOP that focuses upon Internet vulnerabilities.1
Planning Guidelines.
1. System and staff redundancy, enhancing re- dundancy by purchasing diverse equipment and systems.
2. Survivability based on the Continuity of Com- munity concept.
a. Plans, policies & procedures to ensure the resiliency of: i. Economy ii. Government iii. Society iv. Family v. Nuclear and Extended vi. The Individual b. Information technologies take on increasing
importance when employing emergency measures to contain pandemic outbreaks,
c. Quarantines, d. Social distancing.
3. Preparation combined with prevention, a. Ensuring multiple means of Internet access,
and, b. Assessing existing bandwidth against
potential surge requirements.
48
4. Identification of essential systems and people.
5. Education, training, exercising, and testing of IT systems in concert with continuity plans.
a. Preparing employees to telecommute, including encouraging them to embrace mobile (i.e., handheld) and personal computing platforms,
b. Educating, training, and testing employees on recovery responsibilities,
c. Examining security issues.
6. Staffs that are important to the continuity effort, including Human Resources, Legal, and Information Technology.
7. Cascading impacts. a. Looking at service provider plans and the
capacities and capabilities they possess, b. Determining whether first- and last-mile
connections are potential points of failure.
8. Systems security in all facets of operations. a. Checking personnel, firewalls, passwords,
etc., b. Maintaining security’s priority over urgency, c. Enforcing rules/procedures across all organ-
izational levels, d. Remaining vigilant against cyber threats.
9. The balance between mitigation measures and demand for IT and Internet services. a. Reducing non-essential usage to prevent overloading,
49
b. Addressing problems at the source to lower unrealistic expectations,
c. Making concerted public relations and customer relations effort.
10. Realistic expectations. a. Planning and reinforcing what you can
control, b. Accepting and trying to influence what you
cannot, c. Proceeding without waiting for government
or anyone else to tell you what to do.
ENDNOTES - APPENDIX
1. New Jersey Business Force/Surguard White Pages, pp. 9-10.
50
REFERENCES
Chumer, M. J., and M. Turoff, Command and Control (C2): Adapting the Distributed Military Model for Emergency Response and Emergency Management, 11th ICCRTS, 2006, available from www. dodccrp.org/events/11th_ICCRTS/html/papers/005.pdf.
Facebook, available from www.facebook.com/.
Internet 2, available from www.internet2.edu/.
National Lambda Rail, available from www.nlr.net/.
New Jersey Business Force, available from www.njbusiness- force.org/.
New Jersey Business Force/SunGard White Paper, “Will the Internet Be There When You Really Need It?” Pandemic Sympo- sium Sponsored by the New Jersey Business Force and SunGard, 2007.
Porter, M. E., “How Competitive Forces Shape Strategy,” Har- vard Business Review, March/April, 1979.
____________, Competitive Strategy, New York: Free Press, 1980.
____________, Competitive Advantage, New York: Free Press, 1985.
Stephan, Robert, Statement for the Record, 2008, available from homeland.house.gov/SiteDocuments/20080514143442-12325.doc.
SunGard, available from www.sungard.com/.
Twitter, available from twitter.com/.
World Health Organization (WHO), available from www.who. int/en/.
51
CHAPTER 4
ARE LARGE-SCALE DATA BREACHES INEVITABLE?
Douglas E. Salane
INTRODUCTION
Despite heightened awareness, large-scale data breaches continue to occur and pose significant risks to both individuals and organizations. An examina- tion of recent data breaches shows that fraudsters increasingly are targeting institutions that hold large collections of credit card and social security numbers. Particularly at risk are card payment processors and retailers who do not properly secure their systems. Frequently, breached data winds up in the hands of overseas organized crime rings that make financial data available to the underground Internet economy, which provides a ready market for the purchase and sale of large volumes of personal financial data. This chapter concludes that strong data breach notification legislation is essential for consumer protection, and that the direct and indirect costs of breach notification provide significant economic incentives to protect data. Also needed are standards for end-to-end en- cryption, enterprise level methods for quickly patch- ing and updating information systems, and enhanced privacy standards to protect sensitive financial infor- mation.
A data breach occurs when an organization loses control over who has access to restricted information. The Privacy Rights Clearing House, a nonprofit pri- vacy advocacy organization, maintains a partial list
52
of the breaches reported since 2005.1 Losses of tens of thousands of records now occur almost on a weekly basis. Large-scale breaches at data aggregators, credit card payment processors, and national retail chains have compromised the sensitive personal and finan- cial data of millions individuals. Currently, 44 states have data breach notification laws that require or- ganizations to notify the individuals affected by a breach. For organizations holding data on individuals, breaches are no longer an internal matter and can be quite costly, both in terms of breach notification costs and the loss of confidence of customers and business partners.
Data breaches exposing information that can be used to commit fraud are of particular concern. Such breaches typically involve sensitive financial informa- tion such as credit card and bank account numbers. Often causing even greater harm, however, is the loss of personally identifiable information (PII) such as driver license or social security numbers. Unlike compromised credit card and account numbers, it is difficult to know how thieves will use a social security number or other PII to commit fraud. A growing de- mand for the stolen PII now provides a ready market for both types of information, and data thieves have ample incentive to steal both.
The scale and scope of data breaches during this decade has been alarming. From 2003 to 2005, each of the three leading data aggregation companies, Acxi- om,2 LexisNexis,3 and ChoicePoint,4 suffered serious data breaches by failing to control business partners who had access to their databases.5 In 2005, Choice- Point inadvertently released the financial records of 163,000 persons by making the data available to iden- tity thieves who posed as legitimate clients. In 2003
53
and 2004, in two separate incidents, Acxiom subcon- tractors stole information in the company’s databases. In one case, the subcontractor stole over one billion records. From 2003 to 2005, LexisNexis found that un- authorized persons used identification of legitimate users to obtain social security numbers, driver’s li- cense numbers, and the names and addresses of over 310,000 individuals in its databases. In a May 2009 announcement, the company notified over 40,000 in- dividuals that credit card data that it held may have been compromised in 2007.
During the past 4 years, several major retailers and card payment processing companies have had extremely large data breaches. In June 2005, Master Card disclosed that a card processor, CardSystems Solutions, suffered a data breach that compromised the credit card information of over 40 million card holders.6 In the widely publicized TJX Companies breach that occurred from 2005 to 2007, thieves stole over 45 million credit card numbers.7 According to the Massachusetts Bankers Association, the breach affected the credit records of over 20 percent of New Englanders. In March 2008, Hannaford Brothers Co. disclosed that malicious software in its payment sys- tems compromised at least 4.2 million credit and debit card accounts.8 In December 2008, payment processor RBS Wordplay said a breach of its payment systems affected more than 1.5 million people.9 Security and law enforcement experts are still trying to determine the extent of the Heartland Payment System Breach discovered in December 2008. Heartland processes over 100 million credit/debit transactions per month and is one of the top 10 payment processors. For over 18 months, malicious software on a Heartland server intercepted unencrypted Track 2 (information on the
54
magnetic strip of a credit or debit card). The company became aware of the breach when Visa reported ex- cessive fraudulent activity in credit card transactions processed by Heartland.10
Although large-scale breaches attract the most at- tention, smaller targeted breaches can result in signifi- cant losses since they often provide thieves with the information needed to commit fraud. Recently thieves installed skimmers on automatic teller machines (ATMs) in New York City and positioned concealed cameras near the machines to record Personal Identifi- cation Numbers (PINs). After fabricating credit cards with the stolen information, the thieves were able to steal over $500,000 from about 200 victims.11 Thieves then attempted to withdraw the maximum allowable amount from each account for as many days as pos- sible. Skimmers for capturing the card’s Track 2 data and devices for fabricating cards are available on the Internet. This type of crime no longer requires excep- tional technical skills, and ATM frauds that use this equipment are becoming increasingly common.
Due to the potential impact of breaches on con- sumers, organizations, and commerce, data breach research is an active area. Two organizations that pro- vide breach information are the Open Security Foun- dation, through its DataLossDB Project, and the pre- viously mentioned Privacy Rights Clearing House.12 The DataLossDB Project maintains a downloadable database of incidents and provides aggregate statistics on breaches since 2005. The primary sources of infor- mation on data breaches are breach notification letters sent to state attorneys general, which typically are re- quired under state breach notification laws. Copies of breach notification letters are then sent to individuals whose information has been compromised. Press re-
55
ports, SEC filings, and company statements are other important sources. Despite California’s landmark breach notification legislation in 2003 and the adop- tion of breach notification legislation in 44 states, de- tailed information on a data breach is seldom made public or shared with the larger security community at the time of a breach.
Data breaches, particularly large-scale breaches in- volving PII, raise many questions. Unfortunately, the secrecy that typically surrounds a data breach makes answers hard to find. Detailed information, which may be essential for threat detection throughout a particular industry, is seldom made available at the time a breach occurs. In fact, the details surrounding a breach may not be available for years since large- scale breaches usually result in various legal actions. The parties involved typically have no interest in re- leasing any more information than the law requires. Ironically, detailed breach information often becomes available in the course of a legal action when it be- comes part of the public record. Thus the exact means by which a breach occurred often is not known until long afterward, if ever. Moreover, information about perpetrators and what exactly they do with the infor- mation is difficult to obtain. Such information may only come to light years later, if at all, in the course of criminal prosecutions. In addition, it is often not clear how to quantify the harm that may be caused by a breach—if 40 million records are compromised, how many of those records will likely to be used to com- mit fraud? What information should be made avail- able to affected individuals, and how should they be instructed to protect themselves? Who bears the costs? In industries where multiple parties process data, who should be held responsible for a breach?
56
The remainder of this chapter examines notable large-scale breaches in the data aggregation, card payment processing, and retail industries. It explores remedies and practices that have been suggested to mitigate breaches, particularly in the card payment in- dustry. The chapter also discusses the costs of notable large breaches, both to individuals and the companies involved. It describes the research and developments needed to improve data breach detection, deterrence, and response.
NOTABLE BREACHES: INSTITUTIONS, CAUSES, AND COSTS
By 2005, largely through acquisitions of smaller data management companies, Acxiom, ChoicePoint, and LexisNexis had grown to be the world’s three largest aggregators and providers of individual, data, each with revenues of over $1 billion annually. These organizations leveraged their significant analysis and processing capabilities, gleaned over many years of managing data for large corporate clients, to provide detailed information on, and profiles of, individu- als to insurers, collection agencies, direct marketers, employment screeners and government agencies, in- cluding state and local law enforcement agencies. The website of Accurint, the information subsidiary of Lex- isNexis, indicates the detailed information held and made available.13 For example, one product provided by the company, “People at Work,” holds information on 132 million individuals including addresses, phone numbers, and possible dates of employment. The site advertises the ability to find people, their relatives, associates, and assets. Large-scale breaches at each of these data aggregators earlier in this decade raised a
57
great deal of attention among privacy advocates and prompted calls for regulation of the activities of the data aggregation industry.14
During 2002 and 2003, Acxiom suffered two sepa- rate serious data breaches that involved Acxiom busi- ness partners who had legitimate password access to the company’s databases.15 The first involved the sys- tem administrator of a small company who provided services to Acxiom and who routinely downloaded files from an Acxiom FTP server. The administrator exceeded his authority on the server and was able to download and decrypt a file containing passwords. He obtained a master password that allowed him to then download files belonging to other companies. The administrator sealed his fate when he told a hacker friend in a chat room that he had been able to obtain access to a local telephone company database. A subsequent investigation of the hacker friend led to the administrator. As part of the same investigation, Acxiom technicians came upon a second more serious breach that involved theft by a subcontractor to an Acxiom contractor. From January 2001 to June 2003, the subcontractor, who owned a firm that provided e-mail advertising services, accessed over one billion records in Acxiom’s databases by extending his au- thorized access. The individual was later arrested and convicted on various federal charges that included 120 counts of unauthorized access of a protected com- puter.16 Prosecutors claim he used the data in his own e-mail advertising business and eventually planned to sell his company and its newly expanded database to a credit rating company.
The ChoicePoint breach occurred in the fall of 2004 and involved the theft of 145,000 consumer records— the number was later revised upward to 163,000 re-
58
cords.17 Under California’s breach notification law, ChoicePoint had to disclose the breach to California residents. Shortly afterward, attorneys general in 38 states demanded that ChoicePoint disclose the breach to victims in all states.18 The breach led to numerous calls for an investigation of how information held by aggregators might be used to harm individuals.19 The breach cost ChoicePoint $2 million just in notification fees and over $10 million in legal fees. In February 2005, the Company said about 750 individuals had been victims of identity theft. The company stated at the time that the breach did not involve a compromise of its networks or hacking, but was carried out by a few individuals who posed as legitimate business cus- tomers and were given access to the data, which in- cluded personal financial information. The company stated that financial fraud conducted by seemingly legitimate businesses is a pervasive problem. The Fed- eral Trade Commission (FTC) later determined that ChoicePoint was in violation of the Fair Credit Report- ing Act. The company settled with the FTC by pay- ing $10 million in fines and $5 million for consumer redress. One of the perpetrators, a Nigerian national living in California, was later arrested and tried under California law on charges of identity theft and fraud. He was sentenced to 10 years in prison and ordered to make restitution of $6 million. The incident led to dramatic changes in the way ChoicePoint safeguards sensitive personal information and how it screens po- tential business customers.
In 2005, LexisNexis, another leading data aggrega- tor, announced a major breach that exposed the per- sonal information of 310,000 individuals.20 LexisNexis found after analyzing data over a 2-year period that unauthorized people used identification and pass-
59
words of legitimate customers to obtain consumer social security numbers, driver’s license numbers, names, and addresses. The company stated that the breach involved 59 incidents of improper access to data. The company added that various techniques were used to gain access to the data, including, col- lecting identification and passwords from machines infected with viruses, using computer programs to generate passwords and identification that matched those of legitimate customers, and unauthorized ac- cess by former employees of companies with legiti- mate access to LexisNexis data. The incident appeared to be not one breach, but a series of breaches that oc- curred over a multi-year period and involved several different groups.
In May 2009, LexisNexis disclosed a breach that exposed the personal information of 40,000 individu- als and compromised names, birthdates, and social security numbers.21 The breach appears to have taken place from June 2004 to October 2007. The company breach letter said the thieves, who were once legiti- mate LexisNexis customers, used mailboxes at com- mercial mail services and PII taken from LexisNexis to set up about 300 fraudulent credit cards. The breach letter indicated that LexisNexis learned of the breach from the U.S. Postal Inspection Service, which was in- vestigating the fraudulent credit cards.22
In congressional testimony in 2005, Acxiom’s chief privacy officer discussed the company’s data breach- es.23 She claimed that most information obtained was of a nonsensitive nature, and none of it was used to com- mit identity fraud. She noted that the company would henceforth require stronger passwords and keep data on servers only for the period for which it is needed. She mentioned that Acxiom had decided to appoint a
60
chief information security officer, a position now com- mon in most large organizations. From her testimony, it was obvious that this breach was an embarrassment for a company that obtains over 80 percent of its rev- enues from managing data for large corporations and large public agencies. She indicated that Acxiom was in the process of participating in dozens of audits by clients, whose trust in the company had certainly been diminished. The privacy officer reflecting the words of the then FTC commissioner said there is no such thing as perfect security and that breaches will hap- pen even when all precautions are taken. The pri- vacy officer’s testimony underscored the importance of removing data when it was no longer needed and effectively monitoring contractors and vendors with access to company data. At a recent presentation at John Jay College, the chief security officer of Time Inc. indicated that vendor management now was one of his major responsibilities.24
The retail and card payment processing industries have suffered a number of large-scale breaches during the past 5 years. Unlike the data aggregation industry, breaches in these industries appear to have involved malware on servers that collected data and transmit- ted it outside the company. These breaches, how- ever, also involved individuals with detailed insider knowledge of the systems that were compromised. Although the credit card industry and retail industries have not reported significant rises in the rates of credit card fraud, the scope of recent payment card breaches, the rapidity with which stolen credit information was used, and the geographical scope of the fraud, raise concerns that data thieves are now taking advantage of the capabilities afforded by worldwide crime or- ganizations to monetize vast collections of breached financial information.25
61
One of largest breaches of a payment processor oc- curred at CardSystems Solutions, a company that pro- cessed both credit and debit credit card transactions. According to the FTC,26 in 2005 the company handled over 210 million card purchases worth $15 billion for more than 119,000 small and mid-size merchants. The company’s CEO admitted in congressional testimony that the data thieves captured Track 2 information be- longing to 263,000 individuals.27 Security experts later determined that credit and debit information of over 40 million customers may have been compromised. Despite the incredible volume of transactions pro- cessed by the company, at the time, the company had only 115 employees. The breach was not discovered by CardSystems, but by MasterCard security while tracking fraudulent card activity.28
The FTC charged CardSystems Solution with vio- lation of Section 5 of the FTC Act, which prohibits un- fair or deceptive business practices.29 The FTC claimed that the company violated the Act by failing to adopt widely accepted, easily deployed security standards that would have prevented the exposure of the sensi- tive financial data of tens of millions of individuals. The FTC further charged that the company neglected industry security polices with respect to the type of data it collected and the amount of time it held the data.
A forensic investigation of the breach found nu- merous security lapses both in the company’s systems and procedures. The company violated it own indus- try security polices by storing data in unencrypted format on a server accessible from a public network. Data thieves were able to execute a Structured Query Language (SQL) injection attack that allowed an un- authorized script to be placed on a WebFacing server.
62
The script exported data to an external FTP site every 4 days. In addition, data was retained for purposes other than payment processing, another violation of industry policy. Furthermore, the company did not adequately assess its system vulnerabilities to com- monly known attacks, did not use strong passwords, and did not implement simple, widely used defenses to thwart SQL attacks. The CEO also added in con- gressional testimony that the company stored Track 2 data for later analysis, another violation of industry security standards.30
The breach raised new levels of security aware- ness within the card payment processing industry and provided significant impetus for compliance with the industry’s newly developed Payment Card Industry Data Security Standard (PCI DSS or simply PCI).31 To- day, loss of PCI certification can put a payment proces- sor out of business, because it means that the company failed to comply with information security standards, which undermines the confidence of customers and partners. Shortly after the CardSystems breach, Visa and American Express stopped processing with the company. After revising security policies, upgrading systems, and implementing end-to-end encryption on its backend systems and networks, the company even- tually gained PCI certification. PayByTouch, another payment processor, then purchased the company at a steep discount.32 The largest breach of a retailer’s pay- ment processing systems occurred at TJX Companies from 2005 to 2007.33 Intruders had access to the sys- tems for over 18 months. In filings with the SEC, the company said 45.6 million card numbers may have been taken. Card issuing banks later raised the total to 94 million. In addition, thieves captured personal information such as driver’s license numbers, which
63
was used to track merchandise returns.34 According to industry estimates, a card replacement can cost between $5 and $15 dollars, and a breach notification may cost up to $35 per notification. Shortly after the compromise, thieves used the card numbers to make purchases in Georgia, Florida, and Louisiana in the United States, as well as in Hong Kong and Sweden. By September 2007, the breach had cost the company over $150 million, and the company still faced numer- ous class action law suits.
TJX believes a flaw in its wireless networks may have allowed malware to be placed on one of its Retail Transaction Switch Servers (RTS) that processes and stores information on customer purchases and charge backs for its stores throughout North America. At the time TJX was in the process of upgrading its wireless security from the weaker Wired Equivalent Privacy (WEP) standard to the stronger WiFi Protected Access (WPA) standard.35 TJX admits that intruders had ac- cessed the system at times from July 2005 to January 2007.
A report by the Office of the Privacy Commissioner of Canada36 provides a summary of the security lapses of TJX Companies that led to the breach. The privacy commission found that the TJX intruders gained ac- cess to the names, addresses, driver’s license num- bers, and provincial identification numbers of over 330 persons with addresses in Canada. According to Canadian privacy law, TJX should not have collected this information in card transactions. Citing analyses of the incident, the commission found that the compa- ny did not have in place adequate logging procedures to do a proper forensic analysis of the incident. The data thieves actually deleted information so it was difficult to tell what information was compromised.
64
The commission also faulted the company for not be- ing fully compliant with industry standards and prac- tices such as PCI. The commission noted that as far back as 2003, the Institute of Electrical and Electronics Engineers (IEEE) standards committees had recom- mended migration from the WEP security standard to the stronger WPA standard, yet the company had at the time of the breach failed to complete the migra- tion. Even though the commission found that TJX had an adequate organizational security structure in place, it faulted the company for collecting too much data, holding it too long, using a weak security protocol, and not having adequate monitoring in place to detect a breach in progress or to determine the extent of the breach after the fact.
Another payment processor, RBS World Pay of Scotland, suffered a serious breach in December 2008 that involved over 1.5 million financial records.37 Ac- cording to the Federal Bureau of Investigation (FBI), thieves stole Track 2 data from debit cards that were used to pay employees. They also may have accessed the social security numbers of one million customers. The FBI said the thieves worked with cashiers in 49 cities, including Atlanta, Chicago, New York, Mon- treal, Moscow, and Hong Kong, to withdraw over $9 million from accounts. The cashiers locally fabricated cards and made withdrawals from local ATMs. Tim- ing is critical in these frauds. If good fraud monitor- ing is deployed, the information has to be monetized quickly before cards are cancelled.
In January 2009, Heartland Payment Systems Inc. announced the largest data breach to date of a pay- ment processor, over 100 million cards compromised. Heartland is among the top 10 card payment proces- sors and handles over 100 million credit and debit
65
card transactions per month. The breach was detected not by Heartland, but by VISA’s security organiza- tion, which noticed an increase in fraudulent activity on cards processed by Heartland. The source of the breach was malware on a Heartland system, which intercepted payment information sent to Heartland from thousands of retail merchants. At the time of the breach announcement, Heartland claimed no social se- curity numbers, unencrypted PIN numbers, address- es, or telephone numbers were revealed.38 Thieves, however, were able to intercept the Track 2 informa- tion, which is sufficient to fabricate a duplicate credit card. At the time, the company said it did not know how long the malware was in place, how it got there, or how many accounts were compromised. A security analyst at Gartner Inc. noted that the company was probably not doing file integrity monitoring to detect unauthorized changes in files and directories.39
The losses in this breach are significant. Thus far, the breach has cost the company $12 million, includ- ing a $7 million fine imposed by MasterCard. Given the number of compromised cards, banks would be unlikely to cancel and reissue all of them since the costs could be between $600 million to $1 billion, which is bigger than any anticipated fraud. Heartland, however, faces a class action lawsuit filed on behalf of financial institutions that have reissued credit and debit cards and now are attempting to recover these and other expenses associated with the breach. The loss of confidence on the part of customers and part- ners is also a major issue the company is attempting to address.40
Thus far, this report has focused on breaches by companies in the data aggregation and payment pro- cessing industries. Large-scale breaches, of course,
66
can occur in any organization that maintains large data repositories or does high volume transaction pro- cessing. The Open Security Foundation DataLossDB website shows a dramatic increase in the number of breach incidents since 2000, which is most likely due to the widespread adoption by states of breach noti- fication laws beginning in 2005.41 Statistics available on that the DataLossDB site show that educational institutions and government agencies account for 42 percent of reported incidents, while nonmedical busi- nesses account for about 46 percent. Rather than ma- licious attempts to steal data, many breaches, about 29 percent of those reported, are simply the result of lost or stolen storage media (tapes, jump drives, and laptops). The site also shows that breaches involving third parties, common in the payment processing in- dustry, often result in a greater numbers of records lost than those that do not involve third parties.
MONETIZING THE CRIME
What makes large-scale data breaches so danger- ous is that modern organized crime has developed efficient mechanisms for the sale and widespread distribution of large collections of identities and per- sonal financial information.42 So-called carding forum websites provide repositories for credit information for cyber thieves around the world. These sites often make available both Track 1 and 2 data from a card. In addition, there are sites that include full informa- tion about a victim, so-called “fulls,” which include name; address; telephone, social security, credit, or debit card numbers; PINs; and a possible a credit his- tory report. This information is, of course, more costly
67
than just credit card or account numbers. Thieves know that there is a ready market for the proceeds of a large-scale breach of financial information or PII that can be used to commit fraud.
Carders (those who run carding sites) typically buy information from hackers who are responsible for the breach. Carders can break the data into smaller packages and distribute it to lower level carders who may assume the more risky task of making the card’s information available to end users. End users, some- times known as cashers, ultimately monetize the sto- len information, which involves the most risk and dif- ficulty (fabricating a card, changing an address, etc.). In some card account heists, a worldwide network of cashers fabricates cards and makes withdrawals at ATMs around the world shortly after the breach. The Shadow Crew site, for example, which was disman- tled by the U.S. Secret Service in 2004, had over 4,000 members throughout the world, trafficked in at least 1.7 million credit cards, and caused losses estimated at $4.3 million.43 Many considered the Shadow Crew to be a loose configuration of cyber criminals, not a highly organized crime group.
A ready market for a large collection of account in- formation creates serious response issues for financial institutions. In a small-scale breach that involves 200 accounts, banks can simply reissue cards with new ac- count numbers. The cost to reissue 45 million compro- mised cards, however, is probably going to be more than any credit fraud so banks will not reissue cards in such a large breach. Thus compromised cards may stay active and available at carding sites long after the breach. Losses to individuals, merchants, and banks may continue for some time. ID Analytics, a firm that investigates credit fraud, found in one breach they studied that breached information was used sparingly
68
at first, probably to avoid fraud detection.44 Soon af- ter the breach was discovered, however, there was an immediate increase in activity in the use of breached identities, followed by a sharp drop off in use after the breach was publicly announced.
Recently, a site known as Dark Market was closed down by its alleged operator. Besides credit card in- formation, the site offered ATM skimmers and other hardware needed for fraud operations. The site’s op- erator said he was closing it because too many law enforcement agents and reporters had gained access to the site, and it was proving difficult to be sure that their accounts had been eliminated. Dark Market even provided review mechanisms that allowed users to evaluate merchandise and weed out so-called “rip- pers,” or those who rip off other fraudsters. In recent congressional testimony, Rita Glavin, Acting Assistant Attorney General, expressed concern that internation- al carding forums provided a ready market for large- scale data breach contraband.45 She noted that at its height, Dark Market had 2,500 members worldwide. Late in 2008, in connection with the Dark Market site, the FBI announced the arrests of 60 people from six different countries including the United States, Esto- nia, and the People’s Republic of China. Investigators found more than 40 million credit cards, including some from the TJX breach. An FBI undercover agent who penetrated the site provided further details of the Dark Market operation at the April RSA security con- ference.46
CHALLENGES AND REMEDIES
Each industry presents its own data security chal- lenges. Notable large-scale breaches in the data aggre-
69
gation industry indicate the need to prevent insiders from exceeding authorized access, this is a challenge in an industry where revenue comes from making data available to partners and clients. In the card pay- ment processing industry, the complexity of the data flow and systems in use make securing data a vexing task. In this section, we focus primarily on remedies proposed and existing challenges in the payment pro- cessing industry, which has experienced the largest breaches of sensitive financial information.
In 2006, the payment processing industry adopted the Payment Card Industry Data Security Standard.47 The standard addresses the following areas: network security, protection of card holder data, management of vulnerabilities in system and application software, access control measures, monitoring and testing of network resources, and organizational information security policies. The goal is that all organizations involved in the processing of payment transactions, i.e., card issuing banks, merchants, acquiring banks, and card brand associations, will eventually comply with the PCI standard. An industry supported coun- cil oversees continued development of the standard, certifies organizations as compliant, and certifies PCI auditors who monitor compliance.
Recent congressional testimony on PCI standards by representatives of the card associations, a major re- tailer, and the National Retailers Association indicate the difficulty of establishing, implementing, and mon- itoring compliance of security standards in an indus- try as complex as the payment processing industry.48 For example, the head of fraud control at Visa pointed out that the company serves as the connection point between 1.6 billion payment cards, 16,600 financial in- stitutions, and 29 million merchants in 170 countries.
70
He could have also added that this system includes hundreds of payment processors such as Heartland and RBS who provide the electronic delivery path that connects merchants, card organizations like Visa and MasterCard, and the financial institutions who provide the funds. In addition, these payment proces- sors also handle ATM card and debit transactions for financial institutions. In these transactions, they hand data over to organizations such as NYCE, which acts as a clearing house for ATM transactions.49 The card payment system includes larger retailers such as Wal- Mart, with adequate budgets for data security, as well as small corner stores that have very limited resources. It is not surprising that rates of PCI compliance vary considerably throughout the industry.50
One frequent criticism of the PCI standard is the requirement for data to be encrypted only on pub- lic networks, or if stored on devices accessible from public networks. Data on private networks does not need to be encrypted. In fact, typically Track 2 data delivered by retailers to payment processors is not en- crypted. In recent congressional testimony, the head of the National Retailers Association and the CEO of a major retail chain both stated that their organizations would prefer to deliver data in encrypted format. Cur- rently, this is not feasible since there is no industry- wide encryption standard. After the CardSystems breach and the more recent Heartland breach, both organizations proposed either encryption in back end systems or end-to-end encryption as solutions. The Accredited Standards Committee X9 (ASC X9) of the American National Standards Institute (ANSI) is cur- rently working with payment processing industry to develop the end-to-end standard.51 The cost would be considerable since merchants would have to upgrade
71
all point of sale equipment to comply with the stan- dard. Some large retailers, however, believe that the cost of large-scale breaches makes the case that there is a potentially significant return on investment as a result of acquiring the required equipment upgrades.52
Retailers criticize the card payment system be- cause it requires them to retain too much data on their systems. Charge-backs present a difficult challenge for the industry since retailers must retain PII in ad- dition to credit card data to uniquely identify trans- actions and prevent charge-back fraud. Frequently, retailers retain a card number and an address, which might provide credentials for a purchase. Rather than maintain data to track the transaction, retailers would like the payment processor and the card association to have systems that can provide them with records of the transaction so they only have to store a signature and a number that identifies the transaction. The Ca- nadian Privacy Commission examination of the TJX Companies breach faulted the company for storing driver’s license numbers and provincial identification numbers, which were taken from about 300 people in Alberta, Canada, during the breach and used to com- mit fraud.53
To prevent and respond to data breaches on an industry-wide level, the security community in an industry must have detailed knowledge of incidents and vulnerabilities as soon as possible. For most commercial and open source software, information sharing and collaboration regarding software vulner- abilities and available patches have been the norm for some time.54 In the payment processing industry, where a vulnerable software component could be in use throughout the industry, such information shar- ing and response capabilities are only beginning to
72
be considered. In March 2009, The Financial Services Information Sharing and Analysis Center (FS-ISAC) formed the Payments Processing Information Shar- ing Council (PPISC), a forum for sharing information about fraud, threats, vulnerabilities, and risk mitiga- tion practices.55 At the council’s first meeting in May 2009, the CEO of Heartland handed out USBs with the malware found on Heartland’s systems so other pay- ment processors could try to determine if it was on their systems.56 Effective deterrence and response re- quire that knowledge of software vulnerabilities and malware be made available, at least to the security community, as soon as it is available.
Card companies increasingly are promoting op- tional passwords to use with cards.57 Only a few par- ticipating merchants now accept password protected cards, but the number of merchants is increasing. Password protected cards may be particularly attrac- tive to merchants who accept online purchases and international transactions. Unlike card present trans- actions where fraud rates have dropped during the past 10 years, credit card fraud associated with online and international purchases is a continuing problem for the industry.
The card associations MasterCard and Visa have long used fraud detection systems based on usage pat- terns to detect anomalous transactions. Their systems store examples of valid transactions and constantly update cardholder data to create a current usage pro- file. Each new transaction is evaluated against the in- dividual’s transaction history. For example, card pres- ent purchases of certain types of items outside of an individual’s geographic region trigger an alert. These anomalous detection systems have to be consistently updated as thieves consistently find ways to circum-
73
vent them. A recent trend is the use of a botnet com- puter to make an online purchase from an IP address that is within the card holder’s geographical region.58
Breach prevention, detection, and response present challenges to law enforcement agencies, the IT indus- try, and those charged with formulating information security policy. Based on the breaches examined here, the following is a brief summary of the challenges:
Law Enforcement: (1) Immediate notification in the event of a breach. (2) Enhanced knowledge of card- ing sites and the role that organized criminal activity plays in monetizing large-scale breaches. (3) Coop- eration among law enforcement agencies and govern- ments throughout the world to facilitate breach inves- tigations.
IT Industry: (1) Tracking data in large complex sys- tems. (2) Capabilities for rapid system wide updating and patching. (3) Automated fraud detection tools. (4) Maintaining the integrity of software and systems. (5) Standards for end-to-end encryption in complex distributed systems. (6) Industry-wide clearing hous- es to share breach information and coordinate an in- dustry wide response to a breach.
Information Security Polices: (1) Limiting data collec- tion and retention versus maintaining data for market- ing and other activities. (2) Protecting data when there is commingling of proprietary systems and networks with those attached to the Internet. (3) Authorization and auditing polices that address the ease with which large data repositories can be copied.
National breach notification legislation is now before Congress.59 In addition to notification, the bill would force companies holding PII to follow data pri- vacy policies established by the Federal Trade Com- mission. Proponents claim several advantages of the
74
proposed law: (1) It simplifies breach notification re- quirements for organizations; (2) It establishes stan- dards for protecting data; and (3) It provides uniform standards by which individuals could check data held for accuracy. Previous attempts at national breach no- tification legislation raised concerns among privacy advocates because the proposed federal legislation had a lower threshold for breach notification than most state laws, which the bill would have preempted.
The Federal Stimulus bill passed in February 200960 requires notification of health care data breaches. The bill requires all medical providers, health plan ad- ministrators, and medical clearing houses covered by HIPPA, and even organizations not covered by HIP- PA, e.g., the online health record services proposed both by Google and Microsoft, to provide information on breached medical data. Moreover, the law requires the Department of Health and Human Services to is- sue guidelines for protection of sensitive medical data. Given the rash of large-scale data breaches during the past decade, it is not surprising that recent national breach notification legislation includes provisions for increased government oversight of the use of PII.
CONCLUDING REMARKS
Data breaches must be understood within the in- dustries and organizations within which they occur. Notable breaches in the data aggregation industry involved insiders such as contractors who extended their authorized access. Breaches in the payment processing industry made use of malware that re- layed sensitive personal financial information to data thieves. Regardless of the industry, however, basic privacy policies that; (1) limit the amount of data col-
75
lected, (2) limit where data is stored and the time for which it is stored, and (3) restrict the use of data to the task for which it was collected, play a critical role in preventing breaches. Large-scale breaches are expen- sive, especially if the lost information involves sensi- tive personal financial data. Breaches in the payment industry can exact extremely high costs, particularly to organizations such as card processors whose busi- nesses depend on the trust of partners and customers. Breach notification laws, which keep both consumers and business partners aware of what is happening with their data, are changing the way all industries and organizations view information security.
ENDNOTES - CHAPTER 4
1. Privacy Rights Clearing House, available from www. privacyrights.org/.
2. About Acxiom, available from www.acxiom.com/about_us/ Pages/AboutAcxiom.aspx.
3. LexisNexis – About Us, available from www.lexisnexis.com/ about-us/.
4. ChoicePoint, available from www.choicepoint.com/.
5. Reed Elsevier, the parent company of LexisNexis, pur- chased ChoicePoint in 2008.
6. T. Zeller, “MasterCard Says Security Breach Affects Over 40 Million Cards,” The New York Times, June 5, 2005.
7. J. Vijayan, “TJX data breach: At 45.6 million card numbers, it’s the biggest ever,” Computerworld, March 29, 2007.
8. J. Vijayan, “Hannaford says malware planted on its store servers stole card data,” Computerworld, March 28, 2008.
76
9. B. Krebs, “Data Breach Led to Multimillion Dollar ATM Heists,” Security Fix, The Washington Post, February 5, 2009.
10. B. Krebs, “Payment Processor Breach May be Largest Ever,” Security Fix, The Washington Post, January 20, 2009.
11. A. Gendar, “ATMs on Staten Island rigged for identity theft; bandits steal $500G,” The Daily News, May 11, 2009.
12. Open Security Foundation, DataLossDB Project, available from datalossdb.org/.
13. Accurint, available from www.accurint.com/.
14. D. Solove and C. J. Hoofnagle, “A Model Regime of Pri- vacy Protection,” University of Illinois Law Review, February 2006, pp. 375-404.
15. K. Poulsen, “Chats led to Acxiom hacker bust,” SecurityFocus, December 19, 2003, available from www.securityfocus.com/news/7697; B. J. Gillette, “Data thief exposes flimsy security, nets 8 years,” Email Battles, February 24, 2006, available from www.emailbattles.com/.
16. United States Code, Section 1030 (a) (2) (c), available from www.law.cornell.edu/uscode/18/1030.html.
17. L. Rosencarnce, “ChoicePoint says data theft cost is $6 Million,” Computerworld, July 21, 2005.
18. T. R. Weiss, “State officials push choice point on ID theft notifications,” Computerworld, February 18, 2005.
19. G. Gross, “Lawmakers call for ChoicePoint investigation,” Computerworld, March 3, 2005.
20. J. Krim, “LexisNexis data breach bigger than estimated,” The Washington Post, April 13, 2005.
21. A. Westfeldt, “LexisNexis warns 32,000 people about data breach,” SanFrancisco Chronicle, May 1, 2009.
77
22. LexisNexis Breach Notification Letter, available from privacy.wi.gov/databreaches/pdf/LexisNexisLetter050509.pdf.
23. J. Barret, Acxiom Corporation, Testimony before House Committee on Energy and Commerce, Subcommittee on Com- merce, Trade and Consumer Protection, May 11, 2005, available from archives.energycommerce.house.gov.
24. R. Duran and F. Garcia, “Information Security and Pri- vacy: Challenges in a Bad Economy and Difficult Legislative En- vironment,” presentation at the Center for Cybercrime Studies, John Jay College of Criminal Justice, March 10, 2009.
25. CyberSource Corporation, “Online Fraud Report: Online Payment Fraud Trends, Merchant Practices and Benchmarks,” available from www.cybersource.com.
26. Federal Trade Commision, “CardSystems Solutions Set- tles FTC Charges,” February 23, 2006, available from www.ftc.gov/ opa/2006/02/cardsystems_r.shtm.
27. J. Perry, CardSystems Solutions, Testimony before House Subcommittee on Oversight and Investigations of the Committee on Financial Services, July 21, 2005, available from www.house.gov.
28.T. Krazit, “MasterCard Blamed a Third Party Processing Firm,” Computerworld, June 17, 2005.
29. Federal Trade Commission, “Enforcing Privacy Promises: Section 5 of the FTC Act,” available from www.ftc.gov/privacy/privacyinitiatives/promises.html.
30. Perry.
31. PCI Security Standards Council, “About the PCI Data Security Standard (PCI DSS),” available from https://www. pcisecuritystandards.org/security_standards/pci_dss.shtml.
32. M. Mimoso, “Cleaning up after a data attack,” Information Security, April 14, 2006.
78
33. Vijayan, “TJX Data Breach at 45.6M card numbers.”
34. J. Vijayan, “Breach at TJX puts card info at risk,” Comput- erworld, January 22, 2007.
35. Sans Institute, “The Evolution of Wireless Security Stan- dard in 802.11 Networks: WEP, WPA, and 802.11 Standards,” 2003, available from www.sans.org.
36. Office of the Privacy Commissioner of Canada, “Report of an Investigation into the Security, Collection, and Retention of Personal Information: TJX Companies,” September 25, 2007, available from www.priv.gc.ca/cf-dc/2007/TJX_rep_070925_e.cfm.
37. Vijayan, “Hannaford Says Malware...”
38. E. Mills, “Payment Processor Heartland Reports Breach,” CNET News, January 20, 2009, available from news.cnet.com/8301- 1009_3-10146275-83.html.
39. J. Vijayan, “Heartland Data Breach Sparks Security Con- cerns in Payment Industry,” Computerworld, January 22, 2009.
40. Heartland Payment Systems, “Heartland Payment Sys- tems Returns to Visa’s list of PCI-DSS Validated Service Provid- ers,” May 1, 2009, available from www.iteotlandpaymentsystems. com.
41. Open Security Foundation DataLossDB Project, Data Loss Statistics, available from datalossdb.org/statistics.
42. K. Perreti, “Data Breaches: What the Underground World of Carding Reveals,” Santa Clara Computer and High Tech Law Jour- nal, Vol. 25, No. 2, 2009, pp. 375-413.
43. D. Gage, “Head of Shadowcrew Identity Theft Ring Gets Prison Time,” Security Baseline, June 30, 2006, available from www. baselinemag.com.
44. ID Analytics, Inc., available from www.idanalytics.com/.
79
45. U.S. House of Representatives, “Do Payment Card Indus- try Data Standards Reduce Cybercrime?” Hearing of the Commit- tee on Homeland Security, Subcommittee on Emerging Threats, Cybersecurity, Science and Technology, March 31, 2009, available from www.usdoj.gov.
46. S. Nicholas, “FBI Agent discusses big cybercrime bust,” iTnews, April 23, 2009, available from www.itnews.com.au.
47. PCI Security Standards Council.
48. Nicholas.
49. NYCE Payments Network, LLC, available from www.nyce. net/about.jsp.
50. A.Conry-Murray, “PCI and The Circle of Blame,” Informa- tion Week, February 25, 2008, pp. 31-36.
51. Heartland Payment Systems, “Accredited Standards Committee X9 Developing New Merchant Data Security Technol- ogy Standards,” April 29, 2009, available from www.heartlandpay- mentsystems.com.
52. L. McGlasson, “Heartland Databreack: Is End-to-End En- cryption the Answer?,” BankInfo Security, May 11, 2009, available from www.bankinfosecurity.com/articles.php?art_id=1455&pg=1.
53. Office of the Privacy Commissioner of Canada, “Report of an Investigation into the Security, Collection and Retention of Personal Information: TJX Companies, Inc.,” September 25, 2007, available from www.priv.gc.ca/cf-dc/2007/TJX_rep_070925_e.cfm.
54. Financial Services Information Sharing and Analysis Cen- ter, “Payments Processing Information Sharing Council Forms to Foster Information Sharing among Payment Processors,” avail- able from www.ppisc.com/InTheNews.asp.
55. U.S. CERT, “Technical Cybersecurity Alerts,” available from www.us-cert.gov/cas/techalerts/index.html.
56. R. Vamosi, “Heartland Comes out swinging after datab- reach,” Computerworld, May 12, 2009.
80
57. A. Mahtab and M. Bokhari, “Information Security Policy Architecture,” International Conference on Computational Intel- ligence and Multimedia Applications, Vol. 4, December 13-15, 2007, pp. 120-122.
58. Brett Stone-Gross et al., “Your Botnet is My Botnet: Analy- sis of a Botnet Takeover,” Technical Report, Santa Barbara, Uni- versity of California, Department of Computer Science, available from www.cs.ucsb.edu/~seclab/projects/torpig/torpig.pdf.
59. Data Accountability and Trust Act, H.R.2221, 111th Con- gress, 2009.
60. B. Bain, “Law Requires Health Data Breach Notifications,” Federal Computer Week, February 27, 2009, available from www. fcw.com/Articles/2009/02/27/Health-Data-Breach-Notification.aspx.
81
CHAPTER 5
THE ROLE OF CYBERPOWER IN HUMANITARIAN ASSISTANCE / DISASTER
RELIEF (HA / DR) AND STABILITY AND RECONSTRUCTION
OPERATIONS*
Larry Wentz
INTRODUCTION
Cyber in the context of this chapter is used in its broadest definition. It includes aspects of both infor- mation and information communications technology where information and communications technology (ICT) is defined as the convergence of telecommunica- tions and information technology. Aspects of the ICT encompass the range of technologies for gathering, storing, retrieving, processing, analyzing, and trans- mitting information that are essential to prospering in a globalized economy and establishing a knowledge culture. Additionally, ICT includes policies, process- es, infrastructure, systems, services, education, and people and, most importantly, discussions of ICT need to consider the associated information and mes- saging activities and their impact on the society and its functions.
This chapter explores the role and challenges of cyberpower (information and ICT) in humanitarian ____________ *The views expressed in this article are those of the author and do not reflect the official policy or position of the National Defense University, the Department of Defense or the U.S. Government. All information and sources for this chapter were drawn from un- classified materials.
82
assistance/disaster relief (HA/DR) and stability and reconstruction operations. It examines whether a stra- tegic use of cyber in U.S. Government (USG) engage- ment and intervention activities such as HA/DR and stability and reconstruction operations could lead to more successful results. Certainly, the information revolution has been a dynamic and positive factor in business, government, and social arenas in the West- ern world. The combination of technology, informa- tion content, and people schooled in the use of each has reshaped enterprises and activities of all types.
Complicating the challenges of HA/DR and sta- bility and reconstruction operations related to failed- state interventions is the local situation that typically consists of: spoilers interfering with the intervening forces; refugees and internally displaced persons re- quiring humanitarian assistance; buildings requiring reconstruction; roads, power, water, telecommunica- tions, healthcare, and education systems disrupted or dysfunctional; absence of a functioning government and laws, lack of regulations and enforcement mecha- nisms; widespread unemployment and poverty; and a shortage of leaders, managers, administrators, and technical personnel with 21st century technical and management skills. Additionally, there is a lack of a USG whole of government approach, a lack of trust among stakeholders, and policy, procedures, business practices, and people and organization culture differ- ences. It is not a technology challenge per se. Gener- ally, technology is an enabler if used properly.
This chapter concludes that civil-military collabo- ration and information sharing activities and smart use of information and ICT can have decisive impacts if they are treated as a core part of the nation’s overall strategy and not just as “nice to have” adjuncts to re-
83
sponses to HA/DR or to the kinetic phases of warfare and stability and reconstruction operations. It is fur- ther suggested that utilizing the elements of the infor- mation revolution and the whole of government in a strategic approach to HA/DR and stability and recon- struction operations can have positive results and sets forth the strategic and operational parameters of such an effort. Finally, enhancing the influence of USG re- sponses to HA/DR and interventions in stability and reconstruction operations will require a multifaceted strategy that differentiates the circumstances of the messages, key places of delivery, and sophistication with which messages are created and delivered, with particular focus on channels and messengers.1
ROLE OF CYBER AND CHALLENGES
Lack of effective communication, coordination, collaboration, and information sharing among mili- tary, civilian government elements, international or- ganizations (IO), intergovernmental organizations (IGO), nongovernmental organizations (NGO), pri- vate sector, and affected/host nation elements that form the network of partners and stakeholders in- volved in complex operations such as humanitarian assistance, disaster relief, security, stability, and re- construction are consistent factors impacting the abil- ity to conduct more successful operations. There are a number of reasons for this, the most common ones being the lack of a whole of government approach, a lack of trust among stakeholders, differences in poli- cies, procedures, and business practices, and people and organization culture differences. It is not a tech- nology challenge per se. Generally, technology is an enabler if used properly.2
84
A recent workshop co-hosted by the Asia Pacific Center for Security Studies, the Center of Excellence in Disaster Management and Humanitarian Assistance, and the Pacific Disaster Center focused on informa- tion sharing for crisis resilience—beyond response and recovery. The workshop out brief identified the following information sharing gaps:
• Lack of a tradition of sharing info within orga- nizations/nation/internationally
• No incentive for organizations/nations to share information/cooperate
• Knowledge: governments do not know where to get info/funding, baseline information/edu- cation/training
• Lack of overarching coordinating body • National realization that info sharing is a prior-
ity and commitment to follow-up • Resiliency/redundancy of systems • Political will and leadership • No agreed upon standard set of collaboration
tools • Lack of confidence building measures • Lack of forums for face to face networking/
dialogue • Lack of understanding between sectors • Insufficient human resource capacity • Lack of taking into account local conditions/
cultures • Lack of liaisons • Information overload (condense and concise):
double edged sword • Lack of standard lexicon/terminology • Understanding different cultures (military,
government, civilian) • Technology gaps: sending alert but a delay in
response from supporting agencies
85
• Insufficient funds for risk reduction and resil- iency
• Assessment of current condition (need to agree on where we are and where we want to be)
• Ability of government to disseminate informa- tion internally and to receive from outside
• Lack of standards and data compatibility (not geospatial referenced) — No central repository — Need better knowledge management — Example of a solution: Aid Management
Platform and AiDA (accessible database of activities and programs)
— Development Gateway — Reliability and validity
• Too much data (yellow pages on data about data) and information saturation of users
• Gaps in ability for decision makers to focus on the appropriate information
• Ability to identify and communicate with high- ly vulnerable groups
• Models are insufficient for leaders to make de- cisions before, during and after a disaster
• Language gaps • Understanding culture and policy effects on di-
saster preparedness • Ownership of information • Building relationships between private and
public sectors • Gaps in how society responds to the informa-
tion given — Trust in government/sector — Education — Cultural reasons
86
The gaps noted above should not come as a sur- prise and illustrate that much work still needs to be done to create and deploy collaborative information environments to achieve “unity of effort” across the civil-military boundaries. The underlying issues are intellectual, cultural, and social, not technical. Infor- mation-rich, easily accessed networks have become a critical commodity—essential service. Today the responder community increasingly demands that all stakeholders in complex operations be able to share situational awareness, reach back in time and dis- tance for unforeseen data requirements, create and ex- change data, and collaborate virtually across domains and boundaries.
Prior to a crisis, ICT and related networks need to be self-organizing, flat, robust, and open in order to maintain awareness, develop proactive responses, provide ground truth, and amplify social networks. During a crisis, these same networks need to be de- ployable in an ad hoc fashion, hastily pushed out or set up in areas that may have been ravaged by war or natural disaster. Networks with nontraditional part- ners need to be set up and function in the most ad- verse conditions, using come with what you have ICT or assets indigenous to the crisis area. The informa- tion content will no longer be determined by a small handful of experts but by the users themselves. The complexity will drive the practitioners to settle for networks that will simply help them make sense of the situation—sense making—rather than seeking to gain information dominance and clarity. The new informa- tion age means ICT is no longer just good to have but essential. The emerging architecture is one of partici- pation, strong social and knowledge networking, and agility to use all available means to communicate—
87
connectivity increases effectiveness, free revealing makes sense, the community generates content, and the lead user drives the market.
Experience from recent real world operations sug- gests there is an urgent need to review and revise existing policies, doctrine, procedures, and business practices, and to explore more effective use of infor- mation and ICT as an enabler. ICT can be used to over- come current short falls in order to improve the ability of stakeholders to more efficiently and effectively re- spond, to build trust among diverse groups, to pro- mote unity of effort across civil-military boundaries, and to develop and leverage ICT tools and systems. ICT as an enabler can facilitate seamless information flow to support shared situational awareness, col- laboration, coordination, and information sharing as needed.
There are a number of Department of Defense (DoD), Department of State (DoS), U.S. Agency for International Development (USAID), and policy, doctrine, and guidance documents from other orga- nizations that need to be considered in the process of institutionalizing change in how the U.S. military and civilian elements view and integrate ICT into warfighting operations and support of HA/DR and stability and reconstruction operations. Figure 5.1 is an attempt to identify and map the relationship of the existing policy, doctrine, and guidance documents that form the basis for guiding the planning for, and execution of, HA/DR and stability and reconstruc- tion operations. It should be noted, the documents identified do not specifically refer to ICT as an “essen- tial service,” although some, such as DoD Directive (DoDD) 3000.05, “Military Support of Stability Opera- tions”; DoD Instruction (DoDI) 8220.02, “ICT Support
88
to Stability Operations”; and Field Manual (FM) 3-07, Stability Operations, certainly imply its importance. None address ICT as a “smart power” tool and as an enabler for HA/DR and stability and reconstruction operations. The National Security Strategy Directive (NSPD)-44, “Management of Interagency Stability Operations”; DoDD 3000.05; DoDI 8220.02; and FM 3-07 are significant steps forward and give ICT much needed attention, but much remains to be done to provide the necessary policy and doctrine guidance required to use ICT operationally as a “smart power” enabler of stability and reconstruction operations. ICT also is a critical enabler of other “smart power” missions such as HA/DR and building partnership capacity (BPC) overseas and defense support to civil authorities (DSCA) at home.
Figure 5.1. Mapping of Policy and Doctrine Documents and Ad Hoc Solutions.
89
The net effect of shortfalls in policy and doctrine guidance has been the need to use ad hoc approaches tailored to fill real world operational gaps. Examples include creation of various USG ad hoc reconstruc- tion-oriented organizations (a combination of DoS and DoD personnel) in both Iraq (e.g., Iraq Reconstruction Management Office) and Afghanistan (e.g., Afghan Reconstruction Group) and the DoS’s employment of senior telecom advisors (STA) at the embassies as a temporary measure to provide senior leadership in the use of commercial ICT, to provide advice to in-country USG civilian and military elements, and to deal with affected nation counterparts— there is a need to have senior civilian professionals dealing with profession- als. In the absence of a coordinated USG approach, DoD implemented special arrangements, such as the Multi-National Force-Iraq (MNF-I) Communications and Information Systems (OIS) Iraq Communications Coordination Element (ICCE), created to facilitate co- ordination and information sharing among civilian- military ICT stakeholders, to provide ICT advice and planning focus for the use of ICT including the U.S. military use of Iraqi ICT, and to work with the Iraqi ICT counterparts. In Afghanistan, the first STA at the Kabul Embassy established an Integration-Team (I-Team) that was used to facilitate coordination and information sharing among civilian and military ICT stakeholders. He also created two reachback arrange- ments, one USG-focused and the other U.S. ICT indus- try-focused. DoD also created an Iraq and Afghanistan Reachback Office in the Pentagon to provide recon- struction assistance to all sectors. Some of the various ad hoc arrangements used in Iraq and Afghanistan are illustrated in Figure 5.1 (shown in shades of gray). Ex- perience suggests that all of these ad hoc efforts had
90
varying degrees of success, and their best practices need to be captured, documented, assessed, and then applied as appropriate in future operations.
A related important task at hand that is being ac- tively worked is to incorporate ICT as an “essential ser- vice” and as “critical infrastructure” in the appropri- ate policy and doctrine guidance. Additionally, efforts have been initiated to capture the best practices and key lessons from experiences in Iraq and Afghanistan and to codify and insert those lessons into appropri- ate policy, doctrine, planning, and operational guid- ance documents. While this would drive immediate effects in both of these areas of responsibility (AORs), the more important effect is to embody this policy and doctrine at the departmental level and more specifi- cally, the Services and the combatant commands. We need to change the way we do business in the future.
Over the past 30 years, the information revolution had an important impact on the conduct of military operations. In the United States, it produced what is often called “netcentric warfare” or “netcentric opera- tions”—the combination of shared communications, key data, analytic capabilities, and people schooled in using those capacities—that has enabled enhanced joint activities, integrated distributed capabilities, sup- ported greater speed, and more effective maneuver. The result has been that the United States and its allies have been able to conduct very effective combat op- erations under a range of conditions, including quick insertion (Panama), maneuver warfare (major combat operations in Iraq), an all-air campaign (Kosovo), and a Special Forces–led effort (Afghanistan).
At the same time that major combat operations have proceeded so successfully, the United States and its allies have undertaken a variety of humanitarian assistance, disaster relief, stability, and reconstruction
91
operations in Somalia, Haiti, Bosnia, Kosovo, East Timor, several African countries, Afghanistan, and Iraq. These operations generally have included both economic and governance reconstruction and have spanned the full security gamut from nonviolent hu- manitarian assistance and peacekeeping to full-blown counterinsurgency. Not one of these operations has approached the success achieved in combat opera- tions undertaken during the same period.
U.S. military doctrine recognizes the importance of building broad coalitions of stakeholders in complex contingencies. But, in practice, the focus of military communicators usually is on the needs of the joint or coalition force rather than on external links with civilian participants in the operation. Such external links demand that unclassified information be shared in both directions. Thus, the challenge is twofold: (1) How to encourage the military to engage more with civilians, and (2) how to encourage civilians to link better to the military or local stakeholders? How- ever, there are other factors that need to be consid- ered. In humanitarian operations, there are the guid- ing principles of impartiality, neutrality, humanity, and independence from political considerations and associated sensitivities to military involvement and intent that need to be carefully considered and man- aged. Caution needs to be exercised in circumstances where there is a risk that military actions may be per- ceived as reflecting political rather than humanitarian considerations.
Civilian organizations, including the U.S. DoS and USAID elements, believe rather strongly that the mili- tary should not be the first choice option for interven- tion when civilian relief activities are already there or are being put in place. International organizations
92
such as the United Nations (UN) and NGOs also ques- tion whether under the Oslo guidelines, the military should be involved at all in disaster relief activities.3 Most view the use of the military as complementing civilian relief activities and should be requested only where there is no comparable civilian alternative. They argue that it is capabilities versus needed capabilities, and in the latter case, civilian assets may be adequate to get the job done. There are also concerns about mix- ing the use of the terms stability and humanitarian op- erations and in turn doing things under the banner of stability operations that are humanitarian assistance, creating misperceptions and unnecessary confusion about the purpose or the use of military assets.
There is a strong view within the civilian commu- nity that the military needs to be better informed of ci- vilian roles, responsibilities, and capabilities, and that ambassadors need to be better informed about when it is appropriate to request military assistance. Use of the military is a more costly option. Catastrophic di- sasters obviously require military assistance since they are the only responder element that has the means. There is also a need to educate the civilian community about military roles, responsibilities, capabilities, and business processes. A lack of shared understanding about the civil-military stakeholder roles, responsi- bilities, capabilities, and limitations is a key factor that needs to be addressed through improved education and training programs and exercises that involve both military and civilian element participation—this will build a more informed and shared understanding of each other and create trust relationships before they will have to work together in a real disaster response.
Historically, ICT has proven to be a basic enabler of informal social and economic discourse, leading to
93
a strengthening of civil society and the promotion of security, internal stability, job creation, and economic solidity in affected nations. It is a demonstrated en- abler of national transformations. There is little doubt that ICT is an engine for economic growth, a means to shape the information environment, and a means to improve social wellbeing. Advances have progres- sively reduced the costs of managing information, enabling individuals and organizations to undertake information-related tasks much more efficiently and have introduced innovations in products, processes, and organizational structures. ICT enables the genera- tion of new ways of working, market development, and livelihood practices. Additional arguments as to why ICT, and host nation ICT in particular, is impor- tant in stability and reconstruction operations include but are not limited to:
• ICT can be used to help create a knowledgeable intervention, organize complex activities, and integrate stability and reconstruction opera- tions with the affected nation.
• Affected nation ICT provides an alternative source of ICT capabilities for use by U.S. Gov- ernment and coalition partners.
• ICT provides opportunities to shape the envi- ronment for stability and reconstruction opera- tions.
• ICT is essential for prospering in a globalized economy and for establishing a knowledge cul- ture.
• ICT can significantly change key parts of affect- ed nation society, particularly providing young people access to global knowledge that changes sectarian attitudes and behaviors.
• ICT provides affected nation transparency to
94
help reduce corruption and enhance govern- ment legitimacy.
• ICT provides the best way to help every sec- tor at once through realistic and modern e-Gov methods (security, governance, distance learn- ing, telemedicine, geographic information sys- tem (GIS)-based agriculture, finance, power and water management, and e-commerce).
• ICT allows the U.S. Government to positively influence attitudes of the leadership and the general population of the affected nation.
• ICT is demonstrated to be one of the best gen- erators of jobs and revenues for the affected na- tion.
• ICT gives situational awareness of the affected nation’s forces, capabilities, and threats, which can save lives.
Numerous studies of the HA/DR and stability and reconstruction operations suggest that the strategic use of information and related technology can sig- nificantly increase the likelihood of success in affected nation cross-sector reconstruction and development. This is possible if information and ICT are engaged at the outset as part of an overall strategy that coor- dinates the actions of outside interveners and focuses on generating effective results for the affected nation. This has certainly been the case in business, govern- ment, and social arenas in the Western world where the information revolution has been a dynamic and positive factor. The combination of technology, infor- mation content, and people schooled in the use of each has reshaped enterprises and activities of all types around the world.
An ICT business model like that suggested in Fig- ure 5.2, coupled with the smart use of information and
95
ICT, could be employed to help create a knowledge- able intervention; facilitate appropriate integration of intervener ICT reconstruction and development initia- tives with the affected nation ICT strategy and plans; help organize complex activities; and enable coordina- tion, information sharing, and implementation activi- ties among interveners and with the affected nation, making the latter more effective. Additionally, ICT can be used to link constituent parts of an integrated multinational reconstruction and capacity-building effort, can help multiple sectors simultaneously (e.g., security, governance, education, health, agriculture, finance, and commerce) and can be used to enhance situational awareness of cross-sector reconstruction and development activities.
Figure 5.2. ICT Business Model.
Experiences from recent U.S. Government and co- alition interventions in the Balkans, Afghanistan, and
Iraq have repeatedly demonstrated that ICT activities supporting stabilization, reconstruction, and develop- ment operations in the affected nation can be prob- lematic. These activities suffer from a lack of adequate understanding of the affected nation information cul- ture and related ICT business culture. There is no clear mapping of the organizational roles and responsibili- ties of the responding stakeholders. Program devel- opment, project coordination, information sharing, and ICT implementation are largely uncoordinated and nonstandard. There is no agreed architecture and plan for affected nation ICT reconstruction. A coher- ent ICT-oriented civil-military strategy and plan for intervening nations and responding IO and NGO or- ganizations is lacking as well, and there are no agreed mechanisms and procedures to enable effective civil- military coordination and information sharing among participants and with the affected nation. Finally, do- nors and interveners do not consistently view ICT as a high priority need to be addressed early and as an en- abler of cross-sector reconstruction and development.
New metrics are needed for measuring progress in complex operations. The U.S. Army Corps of En- gineers project, Measuring Progress in Conflict Envi- ronments (MPICE), is a good start but needs to more effectively incorporate the ability to measure the im- pact of information and ICT as an enabler of sector reconstruction. MPICE is based on the methodology and framework proposed in the United States Insti- tute of Peace (USIP) book, The Quest for Viable Peace.4 Other tools are needed for collecting and analyzing information exchange data. For example, modeling and simulation tools to support planning and training (e.g., DARPA’s Conflict Modeling, Planning, and Out- comes Experimentation [COMPOEX] program that is
96
97
a suite of tools to help military commanders and their civilian counterparts to plan, analyze, and conduct complex operations), improved processes and tools for imagery sharing (products versus raw data), and visualization tools for displaying analysis and shared situational awareness such as GIS, imagery products, and annotation, and mapping tools.
COMMERCIAL ICT CAPABILITY PACKAGES5
The efficient and effective deployment of com- munications assets into austere environments contin- ues to be a key aspect and an important challenge of crisis response. Rapidly deployable ICT capabilities such as very small aperature terminals (VSAT) like the ground-to-air transmit and receive (GATR) and broadband global area network (BGAN) terminals, satellite phones, cell phones, voice-over Internet pro- tocol (VoIP) phones, hand-held radios, and devices that allow disparate communications equipment to in- teroperate (such as the AC-1000 IP bridge) are readily available to assemble as ICT fly-away kits. However, there is no agreed upon architecture and strategy that can be used to guide responders on how to assemble deployable ICT packages and build hastily formed networks in the crisis area. It is largely an ad hoc plug and play exercise. Hence, there remains the need to help responders determine the right set of items to in- clude in their fly-away ICT package that are simple to use and will interoperate with the ICT that others bring to the crisis.
New collaboration tools are needed that can be employed in disadvantaged information and ICT en- vironments to facilitate collaboration (inexpensive, simple to use, and low bandwidth) and asynchronous
98
information sharing (need to have tools that do not overload limited bandwidth data links when synchro- nizing databases). Some of the existing tools include Groove, Sahana, and WebEOC. Other tools are need- ed that can be used to help breakdown organizational culture, business processes, and technology barriers by creating virtual communities of interest (including language translation) and open collaborative informa- tion environments. Web 2.0 tools such as wikis, blogs, Facebook, LinkedIn, Twitter, and YouTube need to be more broadly adopted by civil-military crisis re- sponders. Other off-the-shelf tools to be considered include Toozl (open office on a memory stick) and smart phones (such as the iPhone and the BlackBer- rys), and global positioning systems (GPS). Presently, there are numerous Internet websites employed dur- ing a crisis response, such as the U.S. Pacific Com- mand (USPACOM) Asia-Pacific Advanced Network (APAN), and UN OCHA websites, such as ReliefWeb and the Virtual On-Site Operations Coordination Cen- ter, but there are no agreed guidelines for developing and populating these websites or related database standards. UN OCHA has also created an Emergency Telecoms Cluster to facilitate the deployment of ICT capability packages in disaster areas. Telecom NGOs such as NetHope and Telecoms sans Frontiers have emerged to help provide ICT capabilities in disaster areas for NGO use. All of these ICT capability pack- ages are based on off-the-shelf commercial products and open source products on the Internet.
There is a need to develop a knowledge reposi- tory of these capabilities and best practices that can be openly shared with the broader community and is kept current with changing technology. The National Defense University (NDU) Center for Technology and National Security Policy-led project STAR-TIDES has
99
as part of its research program the development of a knowledge repository for ICT and the plan is to post it on the project website.6
ICT STRATEGY FOR STABILITY AND RECONSTRUCTION OPERATIONS- AFGHANISTAN EXAMPLE7
The fundamental task of an ICT strategy is to en- hance affected nation capacity. That is the critical re- sult for which the complex operation is undertaken. To achieve that result in an effective fashion, the strat- egy needs to accomplish two tasks, each is familiar to the international community: first, assess the affected nation and, second, establish a goal toward which to build. To put it more in the vernacular, a cure with- out a diagnosis will be improbable; directions without destination will be random. In short, an effective ap- proach will require an information business plan for the affected nation. Unfortunately, the reality is that there is no agreed international or USG ICT strategy and plan, or information business plan for respond- ing to a crisis or for engagement in a failed state inter- vention. Furthermore, there is little attention given to the role that information and the consideration of ICT play as essential services, as critical infrastructure, and as enablers of cross-section reconstruction. How to work with and leverage the private sector is also a deficiency in current USG civil-military thinking—it is not part of the current U.S. civilian and military gov- ernment culture. There is an urgent need for the USG to change the way it does business in the information age. Some changes are starting to happen as a result of policy and doctrine changes, such as DoDD 3000.05 and DODI 8220.02, but changing culture takes time to affect TTPs and mindsets.
100
The assessment phase of an information and com- munications business plan should begin before the intervention. It must include analyses of both the in- formation requirements and the available information technology as well as ICT business practices and gov- ernment regulations and laws. Humanitarian assis- tance and disaster relief responses may not afford the opportunity to do a detailed assessment in advance, but even so, there is a need to do either some assessment in advance of a possible disaster, which can be used for crisis response planning, or to do a quick assess- ment that draws upon readily available information. Understanding what ICT capabilities might be avail- able and whether the affected nation is a signature of the Tampere Convention,8 is important in order to de- termine if and what type of ICT can legally be brought into the country and used. For more complex response operations, such as a failed-state intervention, there is generally a buildup period so there is time to prepare. An assessment should consider the pre-intervention state of information technology, infrastructure and services (voice, data, and Internet access), and the ICT business culture and information usage in the affected nation. It is important to recognize that baselines will differ in different affected nations and as a result of hostile actions.
Additionally, key elements of an information as- sessment will include evaluation of the affected na- tion’s telecommunications laws and regulations, telecoms and IT services, and communication infra- structures—land line telephone system, cell phone capacity, Internet availability, cable, microwave and fiber networks, and satellite systems. It should also address usage patterns, language and literacy issues, technical and business training of locals, and financial resources.
101
Once an assessment has been undertaken, goals will need to be set for operationalizing the informa- tion business plan. Generally, it will be useful to time- phase the goals into an initial deployment phase, a middle phase (getting-things-going phase), and a long-term phase (exit-by-interveners). A critical point throughout is that the interveners’ information busi- ness plan goals need to support the overall goals of the affected nation, and the affected nation will need to generate those goals as promptly as possible—the interveners can certainly help with developing affect- ed nation goals.
The initial deployment phase will require the inter- veners to consider what deployable capabilities will be useful to help establish an affected-nation recov- ery. There are both structural information capabilities; such as deployable cell phone capacities, like “cell on wheels”; and the use of transportable satellites, like VSATs; and functional capabilities, like “health care in a box,” shelters, renewable power, water purifica- tion, sanitization, lighting, and other capabilities that all need to be considered.
The virtue of preplanning is that key interveners can rationalize their capacities in the early, usually chaotic, days of an intervention by considering which capabilities each intervener might focus on. Equally important is to undertake such a discussion remem- bering that, first, numerous entities will already be in country with some capacities that can be utilized and, second, affected countries will likely have some capacity, and potentially significant capacity. Over the entirety of the intervention, the implementation of the information business plan will likely mean that the lead on different aspects of the plan will change. Broadly, one might expect a a progressive transition
102
from military interveners to civilian interveners to the affected nation, although the reality is likely to be more complicated and complex because such a pro- gression will not likely be an easily identifiable or set sequence of actions. The transitions will occur over time, so there will be overlaps that need to be care- fully managed. If it is understood from the beginning that there will be complex transitions in the way the plan is implemented, it will make for a more realistic and effective approach to be made part of the strategy and plan.
The middle phase of an information business plan for the affected country will focus on five key elements. The first element is to align the affected country so that it is connected to the collaborative mechanisms used by the interveners in some fashion. While the key interveners likely can use high-tech means, it may be that the af- fected country will not be able to do so. An important task of an information business plan will be to allow for low-tech to high-tech connectivity. For example, in Afghanistan, the literacy rate is so low that Internet use is necessarily limited and cell phone connectivity may be much more important. In fact, in Afghanistan, the cell phone is the lifeline communications capabil- ity. These points can be more broadly generalized: if the information business plan is to succeed, it must take account of the affected nation’s information cul- ture and the related information technology culture and the skill sets of the managers, technical personnel, and the population in general.
The second element is to help establish working government agencies. Depending on the overall strat- egy, these could be a mix of central ministries to start with and then local/district/provincial offices. Infor- mation communications technology can be used to
103
improve ministry effectiveness through facilitating collaboration and information sharing and extend- ing government services from capital to urban areas to provincial and district centers to local officials. ICT and e-governance also allows for an analytic approach through budgeting and transparency of expenditures. These are crucial functions for the establishment of le- gitimate governance, and information technology can help each.
The creation of a viable telecom and IT business environment is key to setting the initial conditions needed to use ICT as an enabler of cross-sector recon- struction. The affected nation or host nation govern- ment needs to take important actions at the outset of the rebuilding process. A competent Minister of Com- munications with the intellectual and business exper- tise needs to be appointed to set in motion the nation’s vision, strategy, and plans to grow and modernize its telecoms and IT infrastructure and services so as to become a part of the global information society. Tele- com and IT laws need to be created and passed early on. A viable regulatory authority needs to be created and empowered and mechanisms need to be put in place to enforce the laws. Public sector telecoms and IT run services may be necessary to jump-start sup- port to governance and civil security and to provide limited services to a broader population—contribut- ing to the establishment of legitimacy, transparency, and to reduce corruption. However, it will also be necessary to consider early on the need to privatize state run enterprises as soon as it makes sense to do so to reduce corruption and provide a level playing field for private investments. Good public-private sec- tor partnerships are important to enable the private sector to invest in growing the infrastructure and of-
104
fering affordable service with a state of the industry level quality of performance. Two recent real world events illustrate the benefits of initially taking the right steps, and the resulting challenges, from not do- ing so. For example, Afghanistan ICT is one of the ma- jor success stories emerging after years of conflict and open warfare. On the other hand, Iraq has progressed somewhat more slowly due to the continuing security situation, but things are beginning to improve and telecoms reconstruction may emerge as one of Iraq’s success stories as well.
A real world example of an ICT business model that worked is Afghanistan. Significant progress has been made in the telecommunications and IT sector in Afghanistan, and it is truly a “success story” emerg- ing out of the recovery of a country left dysfunctional from 23 years of war. Progress towards bridging the digital divide and moving Afghanistan into the 21st century information age has not been accidental but is largely due to having the right people at the right place with the right vision, energy, and expertise to make reasonable decisions and to take action to make things happen. Donor intervention to provide re- sources to support ICT reconstruction was a key factor as well. Afghanistan ICT success was and continues to be enabled by a number of factors:
• A Government of the Islamic Republic of Aghanistan (GIRoA) understanding of the im- portance of ICT as an engine of economic de- velopment and its role as an enabler of cross- sector reconstruction.
• Early GIRoA establishment of ICT policies, regulations, laws, and a regulatory authority.
• Knowledgeable and experienced Minister of Communication (MoC).
105
• An agreed MoC vision, strategy, and plan for moving Afghanistan ICT into the 21st century information age supported at the highest level of government, by President Hamid Karzai: — Five-year MoC development plan states that
GIRoA should: a. Use the private sector and appropriate
regulations to help jump-start economic recovery through enabling private-sector investments in the rapid expansion of mobile voice services and introduction of Internet service.
b. Use the government to develop the public ICT for governance and make affordable ICT services accessible to the broader population.
c. Consideration the early of privatization of government owned telecom and IT. — Early International and Regional communi-
cations access: a. Satellite, fiber optic and digital microwave
access. b. Private sector international and regional
gateways. — Robust terrestrial backbone network such as
the fiber optic ring and digital microwave. — Early emphasis on ICT capacity building,
including the establishment of related edu- cational institutions, training facilities, and capabilities.
• Proactive MoC provision of an ICT Strategy for the Afghan National Development Strategy that sets ambitious goals for extension of tele- com and IT services to the population in gen- eral and to improve governance, national and civil security, drive economic development, and improve quality of life.
106
• Establishment of a good public-private partner- ship that enables private ICT investments and rapid growth of their networks.
• International and U.S. Government community support. — Placed early emphasis on ICT capacity build-
ing, including the establishment of related educational institutions, training facilities, and capabilities.
— Willingness to invest in and support Afghan MoC creation of a national telecommunica- tions and IT network with early internation- al access.
Differences between Afghanistan and Iraq relate largely to host country government ICT institutions, leadership, strategies, and plans for modernizing the national ICT network. There are also differences in the state of integration of affected nation ICT infrastructure and capabilities. For example, in Afghanistan the MoC is an experienced ICT professional who has a vision, strategy, and a nationally agreed plan for moderniz- ing Afghanistan ICT, and his proactive leadership is making things happen. Additionally, he has been in place since the 2002-03 timeframe and has the support of the Afghan President and other senior government representatives. Telecom and IT laws were enacted by the Afghan parliament early on, and an independent and transparent Afghan telecom regulatory author- ity was established early as well. Although an MoC state-owned telecom company, Afghan Telecom, was established initially to support government commu- nications at provincial and district levels, and to ini- tially provide local voice and Internet access services (telekiosks) down to district level, it has already been
107
corporatized and is in the process of being privatized. With the move to privatize Afghan Telcom, the MoC has changed its name to Ministry of Communications and Information Technology (MCIT) and re-refocused its efforts on the use of ICT to improve Government and social services and initiatives including extension to the rural areas so the country can benefit further from ICT by becoming part of the global information society.
The ICT infrastructure of Afghan Telecom and private cellular providers is interconnected and calls can be made between the networks. The MCIT has in- vested in the construction of a national fiber optic ring around the country linking urban areas and provid- ing regional cross-border and international gateway access. Cable is being implemented in urban areas and digital microwave links are being implemented throughout the country that will also have some ac- cess links to regional countries bordering Afghanistan. The private cellular providers are also building digi- tal microwave backbone networks that include access links to regional countries. Satellite access is also used to provide connectivity and international gateway ac- cess. Finally, a good public-private partnership was created that enables the private sector to invest while discouraging unnecessary state interference.
In Iraq, the situation seems to be more problem- atic. The Iraqi MoC has had three different ministers in the last couple of years, and the most recent min- ister before the current minister was “acting,” all of which negatively impacted the early leadership and decisionmaking process. A new minister has been ap- pointed but is not a telecoms and IT experienced busi- ness person. There does not appear to be an agreed overall Iraq ICT strategy and plan, but one may emerge
108
in the near future. On the other hand, the Kurdish re- gion MoC has a strategy and plan, and progress is be- ing made in their area to modernize ICT and improve services including regional and international access. Planning for the initial network included an assump- tion that demand would be 90 percent voice and 10 percent data, but in reality the demand is just the op- posite and the networks have not yet been adapted to meet reality. Furthermore, the networks that have emerged are independent and not interconnected, and roaming is not allowed. Calls from one network to the other must go through an international gateway. The Communications and Media Commission (CMC), the Iraq telecom and IT regulatory authority, has been without strong leadership for some time, and there are concerns about its ability to function and enforce regulations. There are also concerns about its open- ness and transparency. The telecom law set forth in CPA 65 remains in use since the Iraqis have not yet been able to get their own law enacted by parliament. Privatization of the state own telecom and IT provid- ers, ITPC and SCIS, has been discussed, but no real actions have yet been taken to start the process. It has been suggested that the existence of state-owned en- terprises has created perceptions and concerns on the part of the private sector about possible unfair com- petition. Additionally, the ITPC span of control ap- pears to be limited, with regional elements apparently operating autonomously. In contrast, in Afghanistan, Afghan Telecom has network-wide and regional con- trol of plans, implementation, and operations of the government owned public network.
A good public-private sector partnership does not appear to have yet been created in Iraq, and this makes outside investors nervous as well. It has been
109
noted by some private sector investors that they are more concerned about the Iraqi government than they are about the insurgents and, as such, this is not a situ- ation that lends itself to promoting outside investment in Iraq. Although corruption is a common thread in both countries, it seems to be more of a concern in the Iraq ICT sector than in Afghanistan. Concerns have also been expressed regarding enough avail- ability of Iraqi ICT trained expertise to support sustain- ing the operation of U.S. civil and military networks which will be turned over to the Iraqi government. The availability of ICT trained technical and manage- ment personnel is a shortfall in both Iraq and Afghani- stan. Finally, in Iraq and Afghanistan the stove-piped operational performance and cost of service of the public-private sector ICT networks and services suffer from the lack of roaming among service providers and in Iraq, there is a lack of interconnection and adequate regional and international access and cost-effective service.
Use of embedded subject matter experts (SMEs) in the MCIT/MoC and regulatory authorities are also the common threads, but SMEs seemed to have been less successful in Iraq where they were used for only a short while and none, or few, are apparently being used at this time. The insurgent threat to SME safety has been a concern that is also a contributor to the unwillingness to provide SMEs to Ministries in the red zone. In Afghanistan, the SMEs have been embedded since 2002 in the MoC/MCIT providing trusted advice, continuity of support, and corporate memory. SMEs have also been used with success in other ministries and government organizations such as Afghan Telecom. Physical security threats have not been a major concern in the Afghan capital, but
110
SMEs are provided with contractor personal security details and they live in guarded safe houses in Kabul. Outside of Kabul it is a different story, and SMEs are not embedded in provincial or district ICT organiza- tions. In both Iraq and Afghanistan, the attacks on ICT infrastructure have occurred, but in many cases seem to be more driven by criminal acts and extortion demands than terrorist actions. There have been inci- dents where towers have been blown up, switch sites attacked, and maintenance and installation staff kid- napped or even killed. Physical security is something that needs to be planned for and implemented in high threat environments and needs to be part of a national critical infrastructure protection plan. It is not clear if such plans exist in either Afghanistan or Iraq.
The third element for many stability operations will be to increase connectivity and information flow between the central government and provincial/local governments. Information communications technology can enhance this connectivity and information flow through, for example, the two-way flow of data and finances. It can also serve to extend government services and establish legitimacy of the government at all levels. Often, the cause of the crisis will have been differences between the central government and a region of the country, and working to bring warring elements together will be important. An information business plan can be an effective part of an overall effort.
In Afghanistan, the World Bank and USAID be- came engaged in ICT sector reconstruction and grant- ed money to the Afghanistan MCIT to create a nation- al telecommunications system to connect the central government with the country’s 34 provinces and cre- ate public access centers for Internet and telephone communications at the district level. The World Bank
111
invested $16.8 million to develop the government com- munications network (GCN) and another $3.7 million to rehabilitate the International Satellite Gateway in Kabul. The GCN is a 24 node VSAT-based network that provides international voice and Internet access and communications services to support governance to the provincial capital level—governor and key ad- ministration elements, including in some cases police chiefs. USAID invested $14.2 million to develop the 365 node VSAT-based district communications net- work (DCN) to extend voice and Internet access to the district level for use by local government officials and the local population. GCN and DCN serve to enable good governance at the provincial and district levels by helping remote communities and government of- fices throughout Afghanistan communicate effectively with each other and the world. Subsequently, China, India, and Iran expressed investment interest, but outside of investments by the U.S. Government, the UN, and the World Bank there was little interest from other Western nations or international organizations. A similar government ICT infrastructure arrangement does not exist in Iraq. In this case, commercial cellu- lar and IT services are relied upon as well as ICT net- works built especially for Ministries.
Some other common threads between Afghanistan and Iraq include the need for ICT-related capacity building within ministries. This includes the estab- lishment of effective ministry CIOs and government IT business practices including the use of IT and e- Governance capabilities, and the limited ability to ef- fectively exploit the advantages of the ICT sector to en- able governance, expand economic opportunities, and improve education and healthcare services though implementation of an effective nationwide backbone
112
ICT infrastructure and leveraging e-Governance, e- Commerce, e-Education, e-Healthcare, and other e- Solutions. Additionally, there is a need for develop- ing a cyber strategy and plan and for establishing a national cyber organization and capability to protect against and respond to cyber attacks. On the Afghan private sector side, with MCIT/ATRA support GSM providers, such as Roshan, have been more progres- sive, with funding support from USAID and others, to offer e-Solutions using SMS for financial transactions (the M-PAISA system) and commodities pricing (the TradeNet system) for farmers. Roshan also has a call center in Kabul where, for a fee for service, subscrib- ers can get medical advice, weather reports, and other call-in services.
In both Afghanistan and Iraq, there is no coordi- nated strategy for implementing Ministry IT archi- tectures, capabilities, training, management, or gov- ernance. ICT projects at different Ministries are likely redundant, not integrated, and possibly not compat- ible. Some Ministries have effective enterprise net- works, while others do not. Best practices may already exist, but they are not shared due to lack of visibility and limited to no cross-Ministry coordination. Nation- al CIO Councils have been set up in both Afghanistan and Iraq to implement ICT measures supporting the government’s agenda for anti-corruption, transpar- ency in governance, and cost-effective investment in ICT capabilities, but they have had only limited suc- cess and it has been hard to maintain momentum. In Afghanistan, the National CIO Council is run by the Minister of Communications and IT, and in Iraq it has in the past been run by the Minister of Science and Technology and both report to the Prime Minister’s Office.
113
In Iraq, a shared DoS and DoD initiative to train Iraqi CIOs was initiated. In August 2008, an NDU IRMC CIO training team conducted an intensive 10- day CIO training program in Erbil for Iraqi Ministry CIOs. In early 2009, several Iraqi CIOs were brought to the United States for additional training at NDU and to provide them the opportunity to visit with U.S. CIO counterparts (both government and industry) to gain a firsthand insight into their day-to-day operations. The notion of training Afghan Ministry CIOs has been proposed several times to the Minister of Communica- tions and IT, but no real action has been taken to make this happen. There is some concern that Ministry CIOs may not yet be ready for such training.
The fourth element will often be to provide certain important greater functionalities in government services to the populace. While an information business plan may not be able to improve all functionalities significantly, health and education are two arenas of consequence in which such a plan can make an important differ- ence. In the health arena, information technology can be used to build up and interconnect local centers of health care, such as hospitals and rural health care centers; support training of health care workers; and provide valuable functionalities, such as health sur- veillance systems and reach back to health care sub- ject matter experts and medical library services. In the education arena, information technology can support the development of curriculum and the provision of instruction, as well as the training of teachers. For ex- ample, in Afghanistan, ICT is used in some limited in- stances to connect hospitals with medical schools and with health care centers, universities such as Kabul and Khost have Computer Science programs, univer- sities such as Kabul have partnership programs and
114
alliances with universities outside of Afghanistan, CISCO academies have been set up to train young girls and boys how to use computers and the Internet, and the MoC set up ICT technician training centers. There are other computer training centers emerging in the private sector as well.
The Afghanistan Ministry of Communications and IT recently initiated a Digital Inclusion Program that will enable the government of Afghanistan to adopt the modern culture of offering services to the public. The re-enabled administrative and governance system will bring transparency, efficiency, and reduce bureau- cracy, but this will take some time to implement. The program will install and implement infrastructure, projects, and policies for the introduction of e-govern- ment in Afghanistan, which will empower the pub- lic to access information, communicate with govern- ment, take part in government decisionsmaking, and benefit from the economical opportunities brought by the new culture. The MCIT has also been exploring the use of the DCN as a means to provide voice and data services for health care and educational services in rural areas, as well as general public access to voice services. The wireless local loop contracts have a pro- vision that encourages providers to also make Inter- net service available to schools in the areas they serve. The MCIT is also looking to use the Afghan Telecom Development Fund (based on a 2.5 percent tax on pri- vate sector cell phone calls) to extend access to ICT services to the rural areas. Similar initiatives do not appear to yet exist in Iraq, especially in rural areas. Both Afghanistan and Iraq ICT services for health care and education, and the extension of access to ICT ser- vices in rural areas, remain key challenges requiring more active host government attention.
115
The fifth element is to provide for the private-sector development of information capabilities. Two of the most important issues are informed regulatory mechanisms and useful seed financing. An overly constrained reg- ulatory environment will make it difficult for private enterprise to operate at a profit. A properly structured set of incentives can help create an environment in which profit-making companies can contribute im- portantly to economic reconstruction. Seed money may be very important, especially in the early days of a stability operation, particularly to get local involve- ment in the development of the information business plan.
The middle phase of the plan often may be the equivalent of the medical “golden hour” for establish- ing a framework for effective use of ICT for the affect- ed nation. While the information flow may be limited, meeting the expectations of the affected government and its population during this middle phase will be very important for long-term success. This lends itself to the need for a good strategic communications plan to tell the ICT story and help set and manage expecta- tions, both ours and theirs.
The middle phase will naturally flow over into the long-term phase for the affected nation and the exit strategy for the interveners. That part of the informa- tion business plan strategy should have at least three key elements. First, as noted above, the private sector should become a key element. Early establishment of a good public-private sector partnership is essential for success. In this regard, creating an environment in which there are commercial opportunities for in- formation communications technology solutions will encourage private sector telecom and IT firms to help seed economic revitalization. Second, the affected na-
116
tion will need to consider what role it will play in the development of a national information technology infrastructure. Models range from full privatization to early phase ownership to ongoing involvement. If state owned telecom and IT institutions are employed at the outset, it is important to have a clear agree- ment to privatize and plan for doing this in a timely manner—the earlier the better. Third, as part of their in-country effort, interveners will have to establish IT capabilities to satisfy their needs, but at the same time, these capabilities can also serve to jump-start the affected nation’s capabilities and in turn to enable it to start the recovery process. Hence, such facilities and datasets should not be automatically dismantled as the interveners leave. Rather, they should be built with the intent to be used as leave-behinds for local partners, both governmental and nongovernmental, whether commercial or nonprofit. Part of the leave- behind is the need for capacity building plans to en- sure that the needed affected-country ICT and man- agement skills are available to sustain operations.
An ICT strategy includes people, content, and technology. In complex operations, the information needs—the content of what must be provided in addi- tion to the connectivity—of the affected nation require consideration. Broadly speaking, those information content needs will fall into the categories of security, humanitarian, economic, governance/rule of law, and social.
In analyzing how such information needs should be fulfilled, an ICT strategy will recognize that the in- formation element will support functional strategies for each of these arenas—all of which will have signifi- cant subparts. For example, the establishment of prose- cutorial, court, and prison functions will have security
117
and rule of law/governance aspects. Significant pro- grams will be under way to help create each of these elements as part of a stability operation. Responding to the information needs of those programs has to be an affiliated strategic effort or, to use the terms of the international community, needs to be aligned with the overall aims of the functional programs.
The specific needs may be provided with the use of information from one or more of the interveners. In a variety of ways, information technology can be uti- lized to provide expert assistance. A simple example is maintaining an online list of experts. More sophisti- cated efforts can be established, such as a call-in cen- ter for the provision of various kinds of information. Research arrangements can be set up online, as can connectivity with key national and international orga- nizations, both governmental and nongovernmental, that are willing and able to provide assistance.
As is true for the technology itself, information needs change over time. In fact, the ability to provide information may become more important as the af- fected nation develops its own capacities. The capacity to access such information may be developed in two parallel fashions. First, in a traditional approach there could be an office to help facilitate access to expert management. More recently, a distributed approach, such as wikis and blogs, may be able to make a great deal of expert information available without a specific data manager, if the right information tools are pro- vided. Issues of trust and reliability will arise, but the community approach to providing information via the Internet and Web 2.0 tools has been very power- ful in other arenas, and its use in complex operations should be encouraged.9
118
The discussion of the management of information needs raises the important question of how to manage the ICT strategy in the course of the stability and re- construction operation and how to mange the overlaps and transition from military to civilian lead. Adoption of a strategic approach and even operational activities will be greatly facilitated by the establishment of a for- ward field organization. Ideally, this would be a joint DoS-DoD function with the task of carrying out the information and ICT strategies and plan in country. In complex operations, the organization likely would initially be collocated with the military command ac- tivity and at some point transitioned to DoS/Embassy. Ad hoc arrangements such as the Afghan Reconstruc- tion Group and the Iraq Reconstruction Management Office/Iraq Transition Assistance Office, along with their respective senior telecom advisor positions, are models worth reviewing for future operations. Addi- tionally, the role and effectiveness of the I-Team and the reach back support to the Afghanistan ICT and the Iraq ICCE are other models to review. There is certainly a need to institutionalize the USG ICT sup- port process for future operations and to revisit the creation of a senior telecoms advisor position to focus USG support on the affected nation ICT reconstruc- tion and its use as a cross-sector enabler. There is also a need to develop an agreed approach to establishing a civil-military collaborative information environment to support complex operations collaboration and in- formation sharing and shared reconstruction-oriented situation awareness with ICT as a key element to be tracked. Also, there is a need to include a strategic communications program to tell the ICT success sto- ries and to make information available to stakehold- ers using open source technology such as portals and Web 2.0 and beyond capabilities. 10
119
The role of the organization would include carry- ing out the USG aspects of the ICT strategy and plan. In addition, the organization would collaborate with the organizations with which preplanning took place, including key countries, the UN, the World Bank, and major NGOs. As promptly as possible, the organiza- tion would want to begin to work with the affected nation, though precisely what that means will depend on the unique circumstances of the operation. As a forward community of interest is being set up, the or- ganization will want to create mechanisms that add additional entities to the effort that have not been part of the preplanning. The DoD is encouraging the devel- opment of an open-source, collaborative arena, tenta- tively called “the hub,” that would use blogging, file- sharing, and Wikipedia-type and Web 2.0 approaches to create an open space for collaborative sharing.11 This hub type approach may be very valuable, as may more structured relationships. In addition, the orga- nization will want to work with the public affairs of- fice (PAO) to facilitate interaction with the media and, most importantly, information for the public at large. For example, U.S. commanders in Afghanistan recent- ly launched their “social networking strategy” for Af- ghanistan using the hugely popular website Twitter to release information about some of their operations,12 a Facebook page,13 and the popular YouTube video sharing site14 to post videos about their work and the daily lives of U.S. troops. The decision to use the latest Internet fad was meant to “engage non-traditional au- diences directly with news, videos, pictures, and other information from Operation Enduring Freedom,” the U.S. military said, and to “preempt extremist propaganda.”15
120
OBSERVATIONS
ICT can be important components for success in complex operations. To achieve successful results re- quires that a purposeful strategy be adopted to use these capabilities to achieve the desired end of facili- tating recovery and building up the affected nation and to develop operational activities that effectively implement the strategy. A strategic approach causes coalition participants to undertake five key activities:
1. Conduct pre-event activities with partners, 2. Implement improved collaboration, 3. Ensure improved data usability, 4. Develop an information toolbox, and 5. Create a forward field information office.
Also, creating an overall focus to generate an ef- fective affected nation information business plan con- sists of four actionable items:
1. Assess the affected nation information capacity and culture and business processes,
2. Build an affected nation information goal, 3. Create immediate, medium, and long-term in
formation capacities, and 4. Analyze information needs and develop meth-
ods to fulfill those needs.
Civil-Military collaboration and information shar- ing activities can have decisive impacts in complex operations. To more effectively address shortfalls in responder activities, they need to be treated as a core part of the nation’s overall strategy and, as noted ear- lier, not just as “nice to have” adjuncts to the kinetic phases of warfare. U.S. military and civilian govern- ment agencies need to start to “think” information
121
and ICT. Key points to consider for future operations include:
• “Think” Information and Information Commu- nications Technology (ICT) — Collaboration and information sharing — Enabler of cross-sector reconstruction — Influence operations — Enabler of “unity of effort” across the civil-
military boundaries; • Think and do “whole of government”
— Diplomacy, defense, and development — Enable the “affected nation” do not do it for
them; • View ICT as an “essential service” and as “criti-
cal infrastructure”; • Engage and leverage the “new media” such as
Web 2.0 and beyond; • Metrics for ICT need to measure “outcomes”
not just outputs; • Employ information and ICT capabilities as a
means to inform, influence, and build trust.
Furthering this argument, in complex operations the United States cannot achieve the social, political, and economic goals for which its military forces are committed unless the overall U.S. Government can en- gage effectively with local governments, businesses, and members of civil society.16 Additionally, improve- ments in information sharing will need to proactively address changes that reflect:
• Culture: “The Will to Share”; • Policy: “The Rules for Sharing”; • Governance: “The Environment to Influence
Sharing”; • Economics and Resources: “The Value of Shar-
ing”;
122
• Technology and Infrastructure: “The Capabil- ity to Enable Sharing.
As noted, Information and ICT can significantly increase the likelihood of success in complex opera- tions—if they are engaged as part of an overall strat- egy that coordinates the actions of the whole of U.S. Government (interagency) and, as appropriate, out- side IO, IGO, NGO, international business, and other civil-military stakeholders. The focus also needs to be on generating effective results for the host or affected nation—enable the host or affected nations to be suc- cessful. Properly utilized, ICT can help create effective initiatives and knowledgeable interventions, organize complex activities, and integrate complex operations with the host or affected nation, making the latter more effective.
Key to these results is a U.S. Government strategy that requires that: (1) the U.S. Government must give high priority to such a whole of government approach and ensure that the effort is a joint civilian-military activity; (2) the military and other U.S. Government elements need to “think” information and ICT and treat ICT as an “essential service” and make it a part of policy and doctrine for and the planning and ex- ecution of complex operation; (3) preplanning and the establishment of ICT partnerships is undertaken with key regular participants in complex operations, such as NATO, the United Nations (UN), the World Bank and others such as regional nations in affected nation area; (4) the focus of initiatives and complex interven- tions, including the use of ICT, is on supporting and enabling the host or affected nation governmental, security, societal, and economic development; and (5) key information technology capabilities are harnessed
123
to support the strategy. Implementing the strategy will include: (1) development of an information busi- ness plan for host and affected nations so that ICT is effectively used to support security cooperation, ca- pacity building, and stabilization and reconstruction; (2) agreements among complex operations stakehold- ers on data-sharing and collaboration, including data- sharing on a differentiated basis; and (3) use of com- mercial IT tools and data provided on an unclassified basis as appropriate.17
Enhancing the influence of U.S. Government re- sponses to HA/DR and interventions into stability and reconstruction operations will require a multifac- eted strategic communications strategy that differenti- ates the circumstances of the messages, key places of delivery, and sophistication with which messages are created and delivered, with particular focus on chan- nels and messengers. To improve in these areas, the U.S. Government must focus on actions that include discerning the nature of the audiences, societies, and cultures into which messages will be delivered; in- creasing the number of experts in geographic and cul- tural arenas, particularly in languages; augmenting resources for overall strategic communications and ICT influence efforts; encouraging long-term commu- nications and ICT influence efforts along with short- term responses; and understanding that successful strategic communications and ICT influence opera- tions cannot be achieved by the U.S. Government act- ing on its own; allies and partners are needed both to shape our messages and to support theirs.18
124
ENDNOTES - CHAPTER 5
1. Frank Kramer, Stuart Starr, and Larry Wentz, Cyberpower and National Security, Washington, DC: Center for Technology and National Security Policy, National Defense University (NDU) Press, 2009.
2. Larry Wentz, An ICT Primer: ICT for Civil-Military Coordina- tion in Disaster Relief and Stabilization and Reconstruction, Defense and Technology Paper 31, Washington, DC: Center for Technol- ogy and National Security Policy, National Defense University, July 2006.
3. See UN OCHA website for details on use the of foreign military assets in disaster relief, available from ochaonline.un.org/ A b o u t O C H A / O r g a n i g r a m m e / E m e r g e n c y S e r v i c e s B r a n c h E S B / CivilMilitaryCoordinationSection/PolicyGuidanceandPublications/ tabid/1403/language/en-US/Default.aspx.
4. Jock Covey, Michael Dziedzic, and Leonard Hawley, eds., The Quest for Viable Peace: International Intervention and Strategies for Conflict Transformation, Washington, DC: U.S. Institute for Peace Press, May 2005.
5. Wentz.
6. Website address is www.star-tides.net.
7. Frank Kramer, Stuart Starr, and Larry Wentz, “I-Power: Using the Information Revolution for Success in Stability Opera- tions,” Defense Horizons, No. 55, January 2007, pp. 1-8.
8. For nations that have ratified the Tampere Convention, regulatory barriers are waved for telecommunications to be used in disasters, available from www.itu.int/ITU-D/emergencytelecoms/ tampere.html.
9. Mark Drapeau and Linton Wells II, Social Software and Na- tional Security: An Initial Net Assessment, Defense and Technology Paper 61, Washington, DC: Center for Technology and National Security Policy National Defense University, April 2009.
125
10. Kramer, Starr, and Wentz, Cyberpower and National Secu- rity.
11. Drapeau and Wells, Social Software and National Security.
12. Available from twitter.com/usfora.
13. Available from tiny.cc/MJtsf.
14. Available from www.youtube.com/usfora.
15. Paul Tait and Jerry Norton, “U.S. Military Turns to Twit- ter for Afghan Hard News,” Reuters, June 2, 2009, available from Reuters.com/article/idussp477109.
16. Hans Binnendijk and Patrick M. Cronin, Civilian Surge: Key to Complex Operations, Washington, DC: Center for Technol- ogy and National Security Policy, National Defense University, December 2008.
17. Kramer, Starr, and Wentz, I-Power.
18. Franklin D. Kramer and Larry Wentz, “Cyber Influence and International Security,” Defense Horizons, No. 61, January 2008, pp. 1-11.
PART II:
SOCIAL AND LEGAL ASPECTS
127
129
CHAPTER 6
THE INFORMATION POLITY: SOCIAL AND LEGAL FRAMEWORKS FOR
CRITICAL CYBER INFRASTRUCTURE PROTECTION
Michael M. Losavio J. Eagle Shutt
Deborah Wilson Keeling
INTRODUCTION
This chapter examines how public policy may evolve to adequately address cybercrime. Traditional legal protections against criminal activity were devel- oped in a world wherein any criminal violation was coupled with physical proximity. Global informa- tion networks have created criminal opportunities in which criminal violation and physical proximity are decoupled.
We argue that cyberspace public policy has not adequately incentivized and supported protective behaviors in the cyber community. We examine the roles that user-level/consumer-level conduct, social engagement, and administrative policy play in pro- tecting information infrastructure. We suggest proac- tive work with laws and administrative/citizen-level engagement to reform the cyberspace community. To that end, we examine applicable legal and transna- tional regimes that impact such a strategy and options for expanding administrative and citizen engagement in the cyber security enterprise.
The cyber infrastructures of the United States and Europe offer inviting targets for attack, whether for
130
profit, malice, or state objectives. The enmeshing na- tures of computer networks have changed the calculus for both delineating and protecting critical cyber in- frastructure. The boundaries between such infrastruc- ture and external systems using the infrastructure have become so intertwined that it may be impossible to separate them. Those external systems may become threat vectors themselves.
This enmeshing has blurred the identity between physical and “logical” frontiers for purposes of state boundaries, jurisdiction, and sovereignty. Cyber secu- rity issues move quickly past the national level to that of provinces, states, localities, businesses, and citizens.
Carolyn Pumphrey discussed in detail how local law enforcement strategies might effectively be blend- ed with military/homeland security efforts to protect cyber systems. She noted that transnational threats, including those of cyber security, straddle “domestic and foreign spheres” that present “profound constitu- tional and security challenges” for the United States.1
Public security is a function of several factors, including law and effective law enforcement, social norms, and technical protections. Effective security in cyberspace requires a similar configuration. A neigh- borhood where neighbors watch out for each other and discourage criminality; timely response by police and the courts; and where residents lock their win- dows and doors will be much more secure. Together, the community’s norms, habits, and formal institu- tions serve protective functions.
The conceit we call cyberspace can equally benefit from an equivalent set of protective elements. Yet ef- forts to incentivize such protective elements have not been sufficiently developed. Of particular concern are the capabilities of local law enforcement, business,
131
and individuals to play their part in cyber security as a necessary component of protection of all cyber infra- structures.
Law, norms, and technology impact these capabili- ties. At the same time, they may raise issues relating to the preservation of rights and liberties of liberal West- ern countries seeking to respond to external threats.
Review of laws and administrative systems can avoid misunderstandings as to proper conduct in in- vestigating the misuse of computers and networks. It can also aid in protecting researchers from legal prob- lems in their work, especially for research done out- side of government.
The significance of the threat is seen in the March 29, 2009, GhostNet cyber espionage study and analysis report of the Information Warfare Monitor on distrib- uted malware attacks originating out of China.2 These attacks use a combination of Trojan malware-Gh0st RAT (Remote Access Tool) and social engineering via e-mail to infect vulnerable machines. The key findings were:
• Compromise of at least 1,295 computers in 103 countries, of which nearly 30 percent might be high-value targets,
• GhostNet penetration of sensitive computer systems of the Dalai Lama and other Tibetan targets, and
• GhostNet is a covert, difficult-to-detect system capable of taking full control of affected sys- tems.3
Compromised systems included government of- fices of Iran, Bangladesh, Latvia, Indonesia, Philip- pines, Brunei, Barbados, Bhutan, and embassies of In- dia, South Korea, Indonesia, Romania, Cyprus, Malta,
132
Thailand, Taiwan, Portugal, Germany, and Pakistan. This report comes on the heels of U.S. Government
reports that computing systems at power utility com- panies where compromised by overseas attacks.4
The GhostNet report further suggests that cyber security outside of classified government operations is woefully inadequate, whether in commercial or civic organizations.
We suggest a proactive strategy that blends law enforcement, military, and citizen engagement for the protection of the cyber infrastructure and enhance- ment of cyber security. To that end, we examine appli- cable legal and transnational regimes that impact such a strategy and options for expanding administrative and citizen engagement in the cyber security enter- prise. These options may offer a vital complementary element to the cyber security of the United States as well as other countries.
JURISDICTION AMONG DISTRIBUTED SOVEREIGNS
The exclusive power and jurisdiction to regulate is a jealously guarded prerogative of sovereign nations. Jurisdiction may refer to a particular entity asserting a right to regulate conduct, such as a nation or a prov- ince, and in addition to the right of that entity to regu- late conduct, but also to punish conduct. The right to regulate is usually bounded by a grant of rights itself limited by physical boundaries, such as the boundar- ies of a nation, state, province, or locality. It encom- passes regulation through substantive criminal law that defines wrongful conduct, procedural criminal law that defines how the law is enforced, and laws for resolving problems between jurisdictions, e.g., extra-
133
dition and transfer of an offender found in one juris- diction to another jurisdiction for offenses committed in that latter state.
A state may also assert the right to act against con- duct outside of its boundaries that has an impact in- side those boundaries. It may assert jurisdiction over acts of its citizens that occur abroad. It may assert ju- risdiction based on treaties, maritime law, or interna- tional law.
In the distributed, transnational environment of cyberspace, the assertion of a right to regulate must still address the practical problems of enforcement in foreign jurisdictions. If the domestic cyber infrastruc- ture is attacked by someone operating in another juris- diction, cooperation by the authorities in that foreign jurisdiction may be needed. If investigative data on an attack are to be found in a foreign jurisdiction, even if the attacker is in yet another jurisdiction, speedy lo- cal cooperation is needed. Obtaining this cooperation may be difficult.
For example, in the Gorshkov/Ivanov cases, the defendants broke into various U.S. corporate comput- er systems from their home base in Russia; they then offered their computer security expertise for hire.5 To simplify the jurisdictional problems, the U.S. Federal Bureau of Investigation (FBI) convinced them to dem- onstrate these skills in a meeting in the United States that was videotaped and keylogged. After logging in to his home machine to download his toolkit, Ivanov was arrested. The agents then took the keylogger data, logged into Ivanov’s home machine in Russia, and downloaded files evidencing his illegal access to ma- chines in the United States. Both were convicted and sentenced to prison. However, Russian authorities were not happy with the actions of the U.S. authori-
134
ties and initiated criminal proceedings against the two FBI agents involved in the remote (but unauthorized) access to Ivanov’s machine in Russia.
The complexity of transnational actions increases with other issues of data and computing regulation in each country. The most effective tool to remedy this is cooperation, which may be manifested in treaty law promoting mutual benefit. This may not be possible with any country that expressly or implicitly con- dones cyber attacks against foreign targets. But it can still be effective in rallying countries to work together and set a foundation for diplomatic solutions. First, we provide a general discussion of local law in this area and then proceed to the use of treaty law to create a more effective transnational regime.
LOCAL SUBSTANTIVE CRIMINAL LAW AND THE EXERCISE OF SOVEREIGNTY
Criminal and delictual law adapt to injuries and misconduct with new technologies, particularly where those technologies threaten rights in new and unfore- seen ways. The legal regime for computer misuse ad- dresses the core function of these machines; their abil- ity to store, manipulate, and transmit information.
A traditional crime may be committed with a new computer tool, such as murder by entering false in- formation in a medical database.6 Crimes previously the province of technical specialists, such as criminal copyright infringement, may now easily be commit- ted by laypersons. Some crimes require new, sui ge- neris statutes to control misconduct unseen before the rise of computing technologies.
Review of computer misuse must consider several issues:
135
• Misuse may fit traditional criminal law ele- ments. For example, a computer can be used to store or transmit information on terrorist activ- ity or other criminal dealings, like a notebook.
• Computer misuse may only partially corre- spond to traditional criminal law elements, requiring legal revisions to correspond to tech- nical facts of computers and networks. For ex- ample, a computer may be used to copy and transmit information in violation of intellectual rights and for industrial espionage, violations that in the past required significant time and resources.
• Or that misuse may not fit within the elements of standard crimes, requiring use of new crimi- nal statutes to address the danger. For example, a computer can be used to transmit information that, while harmful, does not fit the elements of traditional crimes requiring proximity of the offender to the target or financial motive. The Filipino computer student who wrote the “I Love You” computer virus was not prosecuted because the Philippines had no law at the time criminalizing such conduct.7
The intersection of the old and the new with cyber- crime make for an evolving area of practice. Review of incidents of computer misuse will require a combina- tion of both traditional and innovative case analysis in law enforcement, especially where the computer crime itself shares elements of old and new types of offenses, as seen in Figure 6.1.
136
Figure 6.1. Evolving Law Enforcement Practice.
Examples of Local Substantive Criminal Laws.
The issue of jurisdiction and sovereignty plays a major role in the promulgation of laws as each sov- ereign may choose to create its own set of criminal laws relating to computer misconduct. They may do so with little regard for what any other jurisdictions may choose to regulate.
The general categories of regulation in this area are exemplified by the Council of Europe’s Conven- tion on Cybercrime, discussed further below. Those categories are:
• Unauthorized access to computer, (this includes exceeding authorized access to a computer),
• Unauthorized interception of data, • Unauthorized interference with data, • Unauthorized interference with a system, • Misuse of devices.
Different jurisdictions may adopt criminal laws in each of these areas or only some of them; the particular provisions may vary from one jurisdiction to another.
137
Some primary U.S. federal criminal statutes relat- ed to computer intrusions that reflect these categories are:
• 18 U.S.C. § 1029. Fraud and Related Activity in Connection with Access Devices
• 18 U.S.C. § 1030. Fraud and Related Activity in Connection with Computers
• 18 U.S.C. § 1362. Communication Lines, Sta- tions, or Systems
• 18 U.S.C. § 2510 et seq. Wire and Electronic Communications Interception and Interception of Oral Communications
• 18 U.S.C. § 2701 et seq. Stored Wire and Elec- tronic Communications and Transactional Re- cords Access
• 18 U.S.C. § 3121 et seq. Recording of Dialing, Routing, Addressing, and Signaling Informa- tion.
Each of the American states has its own computer crime laws that may reflect some or all of these issues. For example, Kentucky statutes focus on unlawful ac- cess to a computer:
• KRS 434.845 Unlawful access to a computer in the first degree (fraud).
• KRS 434.850 Unlawful access to a computer in the second degree (damage).
• KRS 434.851 Unlawful access in the third de- gree (damage).
• KRS 434.852 Unlawful access in the fourth de- gree (access).
• KRS 434.855 Misuse of computer information. • KRS 150.363 Computer-assisted remote hunt-
ing unlawful—Citizens with disabilities.
138
While its primary focus is on unlawful access, Kentucky’s prohibition on computer-assisted remote hunting is a good example of how special local con- cerns may lead to unique laws on computing.
Similarly, other countries have laws designed to regulate various types of misconduct with computing devices, such as:
• Canada — Unauthorized use of computer interception
of communications • United Kingdom
— Computer Misuse Act 1990, as amended — Data Protection Act 1998
• India — Information Technology Act 2000
• Germany — Unauthorized acquisition of data — Unauthorized circumvetion of
system security
This structure for substantive criminal laws that define prohibited conduct is also matched by systems of procedural laws by which the substantive law is enforced. These laws may vary between jurisdictions.
Procedural Criminal Laws.
Enforcement of substantive criminal law is guided by rules of procedure that seek to assure reliability and fairness in the administration of justice. They may also reflect national interests in the protection of certain rights of citizens. As with substantive criminal law, criminal procedure may vary between jurisdictions.
One area of procedure deals with the proper use of evidence. Electronic evidence alone or matched with other evidence may indicate a crime and additional
139
evidence of that crime. That additional evidence, once obtained, can correlate the electronic record with other actions. This correlation and development role is par- ticularly important for remote data collected over net- works; correlation to other evidence is a key function of electronic evidence in prosecuting a digital crime.
Another area addresses the protection of privacy rights of citizens from government intrusion. For ex- ample, absent special circumstances, the search or seizure of a person or his effects without consent is illegal in the United States unless an application un- der oath is made before a neutral magistrate that sets out facts to establish “probable cause” to believe a crime has been committed and evidence of that crime will be found in the place searched and things seized. Probable cause itself means a fair probability under a commonsense analysis that evidence is to be found at the place to be searched. This and other rules define procedural law for law enforcement and prosecution in the United States.
For example, Figure 6.2 shows a diagram of the process by which computational forensic data may be used within the criminal justice process in the United States.
Meeting the procedural requirements of each ju- risdiction may slow computer crime investigation across multiple jurisdictions. It may, in fact, render an investigation impossible. To counter investigative obstacles, a transnational legal regime is developing through bilateral and multilateral treaties to harmo- nize substantive and procedural criminal law between countries and to create a system for mutual assistance and cooperation in cybercrime investigation and pros- ecution. That developing regime is seen in coopera- tion between nations as outlined by the Convention on Cybercrime of the Council of Europe.
140
Figure 6.2. The Use Path for Computational Forensic (CF) Results.8
A TRANSNATIONAL LEGAL REGIME AND COOPERATION ACROSS FRONTIERS—THE CONVENTION ON CYBERCRIME
Miles Townes and others argue that an interna- tional regime to protect our interconnected informa- tion infrastructure is needed.9 Nicholas Seitz, Townes,
141
and Lorenzo Valeri all support the premise that an in- ternational regime of information assurance is essen- tial; Valeri calls for “specific international ‘clusters of rules or conventions,’ the content of which cannot be just independently devised by states or international businesses.”10
The Council of Europe’s Convention on Cyber- crime11 is a primary component of such an evolving regime. This treaty emerged after lengthy negotia- tions between members of the Council of Europe and nonmember states; Canada, Costa Rica, Dominican Republic, Japan, Mexico, Philippines, South Africa, and the United States.
The Convention is structured to address the issues of substantive criminal law, procedural criminal law, and interjurisdiction relations. By harmonizing these three areas, the Convention promotes greater unifor- mity between national laws and facilitates coopera- tion between states, vital for the preservation of time- sensitive, evanescent electronic evidence. It does this by requiring each country joining the Convention to:
• adopt criminal laws that define crimes in five fundamental areas of computer and network misuse, creating a common base of substantive criminal law;
• adopt and implement procedures for investi- gation, evidence collection, evidence preserva- tion, and prosecution of digital crime and use of electronic evidence, building a common base of procedural criminal law across countries; and,
• Building on the common foundation in both substantive and procedural criminal law, states must then adopt measures to assure interna- tional cooperation and mutual assistance in
142
investigations involving multiple jurisdictions, addressing particularly difficult problems of the preservation and disclosure of data and the extradition of citizens to foreign jurisdictions.
The five key areas for substantive crimes where each state must adopt criminal laws are:
1. Unauthorized access to computer, (this includes exceeding authorized access to a computer),
2. Unauthorized interception of data, 3. Unauthorized interference with data, 4. Unauthorized interference with a system, and 5. Misuse of devices.
The Convention looks at intentional conduct “without right.”
The Convention permits variations between na- tions. In our earlier list of U.S. laws, these five areas are addressed by those statutes; 18 U.S.C. § 1030. “Fraud and Related Activity in Connection with Computers,” in particular, addresses unauthorized access and in- terference with data and systems.
The common procedural criminal law for law en- forcement investigative and prosecutorial activities include the preservation, acquisition, and use of elec- tronic evidence. The most sensitive of the three areas relates to requirements for international cooperation and mutual legal assistance. Cross-jurisdictional law enforcement efforts entail risks that range from differ- ent procedures to different communications protocols to challenges to national sovereignty. The Convention seeks to minimize these problems by first harmoniz- ing criminal laws and then having states adopt pro- cedures and practices for cooperation and mutual assistance between countries on cybercrime matters.
143
These procedures should address assistance and co- operation in data preservation and disclosure and the extradition of suspects.
The Convention creates a foundation for coopera- tion between countries in investigating cybercrime be- tween countries, including activities impacting crimi- nal cyber infrastructure. But this foundation must be supplemented by other human participant elements within the cyber community. The enmeshed nature of our cyber-information world has made the home front the frontier of cyber conflict. Local matters of law en- forcement and public security are intertwined with those of national cyber security.
We discuss possible ways to incentivize protective behaviors in the following section.
SOCIAL NORMS AND CRIMINOLOGICAL THEORY
Law enforcement is not the sole factor in assuring public security. The values and actions of a communi- ty contribute to its security. As Stanley Cohen argues, the strength of social control depends on formal and informal social control.12 Laws and law enforcement represent formal social control, whereas the attitudes and actions of individuals represent informal social control. Both spheres can impede unlawful activities, but states with strong overall levels of social control will have high degrees of both formal and informal social control.
The opportunity theory perspective provides a useful way of conceptualizing the potential effect of informal social control on cyber security. Routine ac-
144
tivities theory (RAT) is made up of three distinctive elements:
1. A suitable target is available, 2. There is a lack of a suitable guardian, and 3. There is a motivated offender.13
Where all of these elements are present, the risk of criminal conduct increases. Conversely, the absence of one of these elements reduces the risk of misconduct.
In the context of cyber security, there is an abun- dance of suitable targets and a lack of suitable guard- ians. However, changes in attitudes, present in the informal sphere of social control, can increase rates of suitable guardianship.
Attitudes have been used to explain a wide range of behaviors, including racism, prejudice, voting, and attraction. There is no universal definition of attitude, and the concept itself has been measured in hundreds of ways. As M. Fishbein and I. Azjen write, “[A] defi- nition of attitude appears to be a minimal prerequisite for the development of valid measurement proce- dures.”14 J. M. Olson and M. P. Zanna define an atti- tude as favorable or unfavorable evaluative reactions toward an object which may be manifested through beliefs, feelings, or inclinations toward action.15
Social psychological research in value diffusion16 and norms17 suggest that attitudes can be manipulated via intervention. Boyd and Richerson argue that val- ues can differentially spread in a population based on biasing factors. When an individual is exposed to different values, an individual’s decision to adopt one of the values and not the other may be biased from randomness by properties of the social context which render the selected value more appealing. Preferential value diffusion has been borne out in economics and diffusion of innovations research.18
145
A norm favoring a particular value may cause that value to become ubiquitous in a population. There is no universally agreed upon definition of “norm”: the Merriam-Webster Dictionary defines a norm as “a principle of right action binding upon the members of a group and serving to guide, control, or regulate proper and acceptable behavior.” A norm has two pri- mary subtypes, social and legal. A social norm, unlike a legal norm, is informal and appears to arise and be enforced19 without deliberate planning, writing, or en- forcement.20
In the externality model of norm development, norms emerge when the actions of individuals pro- duce either costs or benefits to others.21 When indi- vidual X does an act that individual Y does not like or perceives as harmful, Y may respond negatively, often reasoning that “you shouldn’t do that.” An in- dividual’s being harmed is not enough to generate a norm; however, if enough similarly situated individu- als perceive the same harm, this response will become a norm and have a constraining effect on behavior. As long as the benefit/harm is easily identified (such as death, theft, or pollution), the externality model ac- counts for why certain deviant behaviors are punished (they are viewed as harmful rather than harmless) and punished to varying degrees (certain behaviors are viewed as extremely harmful or intolerable); in many cases, however, the benefit/harm is often culturally defined and subject to debate.
Using the externality model puts an onus on infor- mation because an externality is socially constructed: Individuals need to decide what is harmful, and defi- nitions thereof may vary depending on social and con- textual factors. For example, the linking of complex is- sues such as cyber security and individual autonomy
146
may be hotly debated. For example, some individuals may argue that individuals are responsible for others but bear no responsibility for others’ cyber security (referred to hereinafter as isolationist norm). By con- trast, others may argue that such an orientation is too myopic and is subject to the freeloader fallacy. While such an approach would be effective for a security- minded individual if everyone else was like-minded, such an approach is suboptimal if others fail to con- sider cyber security. In that case, the community’s cyber security vulnerabilities will create widespread opportunities for network-based attacks, which ulti- mately may compromise the isolationist individual’s cyber security.
Based on this externality model, we argue for cy- ber security policy changes to foster information that supports an integrationist norm, wherein individuals recognize that their failure to be proactive in pursuing cyber security is morally irresponsible and exposes them and others to harm. Successful informational campaigns have changed public norms. For example, public awareness of harms created by littering and second-hand smoking have largely emerged over the last 40 years as a result of commercials, scientific studies, and laws. National awareness of littering was heightened by commercials featuring a weeping Na- tive American surveying a litter-strewn American landscape. Such commercials transformed littering from a local problem to a collective problem. The act of littering acquired a moral dimension and was re- conceptualized as harmful and disrespectful to others. Littering itself may be punished informally by others via informal sanctions, such as rude responses. Cur- rent informal norms disfavor littering in many con- texts, and many children are taught not to litter from early ages.
147
In cyber security contexts, information campaigns could foster integrationist norms by presenting cyber security as a moral obligation of personal responsibil- ity, wherein the failures of the few may lead to great harm for others. Recent cyber attacks have utilized cyber security flaws on un-updated computers to cre- ate drones of attack computers. Educating the public about operating such computers would harden tar- gets by presenting such actions as not only foolish and shortsighted but leading to the harm to others.
Ultimately, optimal public policy changes social values relating to personal responsibility. Information campaigns could be reconceptualized as moral imper- atives. In so doing, motivated individuals will harden cyber targets by proactively pursuing cyber security.
ADMINISTRATIVE ENGAGEMENT— MARSHALLING AND ENABLING EXISTING LAW ENFORCEMENT
Enabling local law enforcement to address cyber- crime matters can increase the presence of “suitable guardians” and reduce the motivations of some of- fenders. U.S. law enforcement at the local level ex- pects growth in the use of electronic evidence as proof of system misuse. Lawyers and judges have also ex- pressed the desire for better training in this area. This reflects the vast expansion of consumer computing devices in society.
It also reflects a dangerous skills gap in law en- forcement relating to consumer computing and tele- communications devices. For example, in 2006 cellu- lar telephones were recovered in investigations in a majority of violent crimes and in over 80 percent of drug crimes.22 See Figure 6.3.
148
Figure 6.3. Involvement of Cell Phones In Violent Crimes.23
Yet a majority of police executive officers also re- ported an inability to use evidence from those systems due to lack of training or access to forensic specialists. See Figure 6.4.
Figure 6.4. Inability to Search for Cell Phone Evidence Due to Timely Access to Forensic
Examiners and Lack of Forensic Skills.24
149
Similar surveys relating to general electronic evi- dence and systems produced indications of expecta- tions of increased use and desire for training in this area among judges, attorneys, and even corrections officers.25
If the resources to address cybercrime at all levels are to be marshaled at all levels, we must enable local law enforcement to address these threats.
Expanded Law Enforcement Engagement.
Expanded law enforcement engagement may be achieved through cross-disciplinary training for nec- essary skills and for the support of their use via lo- cal capacity-building. This engages law enforcement, public defenders, prosecutors, corrections, and the judiciary in the training and support services.
Training would focus on: • Law enforcement training. Computer foren-
sic examination training on how and where to manually locate data on digital media storage devices, use of automated computer forensic tools locate, identify, and report information of evidentiary value, including specific informa- tion in formats such as hexadecimal or binary within data sets, carve information from the data set in a forensically sound manner, and articulate the findings.
• Law enforcement training. Digital evidence col- lection training to provide a measurable profi- ciency in digital evidence recognition, seizure, packaging, transportation, and storage.26
• Law enforcement administrative officer train- ing. Training for administrative officers on managing and supervising their people on the
150
use and analysis, collection and preservation of digital evidence, particularly from cell phones and other portable electronic devices.
• Defender training. Support for training public defenders in the effective assistance of counsel in cases involving digital evidence.
• Prosecutorial training. The prosecutorial use of computer forensic data in the courtroom.
• Judicial training. Judicial practice relating to the use of computer forensic data in the court- room.
Support services should include statewide net- works of resources, such as self-service digital forensic workbenches available to local law enforcement that may not be able to afford their own forensic systems but continue to collect digital evidence repositories. Where evidentiary issues may require higher-level analysis, this workbench system would support chain- of-custody valid transmittal to regional computer fo- rensic laboratories and other forensic analysts capable of such high-level analysis.
This distributed local investigative capacity would expand the protective capabilities needed to protect systems from cyber attack. Feeding local investigative results into the system of transnational cooperation envisioned by the Convention on Cybercrime would speed response while effectively leveraging all re- sources in what is already an asymmetric risk envi- ronment.
Given the cross-jurisdictional issues noted earlier, such a system could use national and state-level orga- nizations to mobilize collaboration. Law enforcement, prosecutors, and judges all have national organiza- tions to help implementation at the state level. Simi-
151
larly, these groups have statewide organizations that can carry implementation to local jurisdictions.
Many states have resources within the computer science, computer engineering, and computer infor- mation systems departments of state universities to further support this effort with their expertise. The expertise and experience developed within these de- partments is a significant resource that will decrease the cost of training development and delivery, and resource development.
Sustainability and expansion will depend on the selection of state and local law enforcement, prosecu- tors, and judicial professionals who themselves will serve as resources and future trainers to maintain and further the skills relating to computer forensics, cell phone forensics, and digital evidence.
CITIZEN ENGAGEMENT
The home front is the frontier in this conflict. The citizen computer user must be engaged in this pro- cess. Risk can evolve when home/business systems “. . . are being increasingly subverted by malicious ac- tors to attack critical systems.”27 Community aware- ness and training on basic cyber security are needed for home and small business users; the threat man- dates such action.28 The strategy emphasizes the role of public-private engagement.29
This framework encompasses all who use com- puter systems. The National Institute of Standards and Technology (NIST) has outlined standards on technical security and security training and aware- ness for nontechnical users of computer systems.30 NIST’s Computer Security Resource Center (CSRC), the Small Business Administration (SBA), and the
152
National Infrastructure Protection Center (Infragard) have together advocated computer security trainings for small businesses.31 Educause, the association for IT in education, advocates starting cyber security educa- tion in kindergarten.32 The Awareness and Outreach Task Force of the National Cyber Security Partner- ship, an industry association, recommends the devel- opment and distribution of cyber security guidebooks and toolkits for small business and home computer users.33
Collaboration between government, business, schools, and consumers improves security by mitigat- ing the exploitation of home and small business sys- tems for computer security attacks. It prevents the use of compromised home computers to help storm the security bastions of any other computer on the Inter- net in a coordinated, multitiered, and destructive at- tack. It limits risks of compromise to critical systems, such as medical and mechanical systems, that are real, mortal threats.
Direct Engagement—A Training Response.
There must be direct engagement of school, home, and small businesses in securing computers and broadband connections from attack and compromise. This engagement requires the training of users for their own protection and the protection of others.
Three barriers hinder that engagement. As a mat- ter of cost, home and small business users may not be able to hire expertise for computer security. As a mat- ter of training, the generally low-level of computing literacy makes it difficult for home and small business users to implement secure practices themselves. As a matter of culture, school, home, and small business
153
users may defer to others in reference to their sys- tems’ operations.
These are overcome by basic computer security training for consumers and by ongoing efforts of busi- ness and government to provide security tools for the home and small business computer user. A cost- effective model of such training was proposed by the University of Louisville student chapter of the Asso- ciation for Computing Machinery (ACM). 34
First, training identifies the threats to home and small business systems. Often, even with news cover- age of virus and worm outbreaks, consumers are un- aware of the level of threat associated with Internet and broadband usage. Second, training looks to “best practices” with the use of; (a) protective technology, and (b) safe user practices. System maintenance prac- tices, though inconvenient, offer better security for systems. Safe personal computer use practices secure the users themselves, especially children.35
The Benefits of Engagement.
Citizen engagement has the dual benefit of harden- ing the vast distributed set of available targets and de- veloping new guardians in the form of the computer users themselves. Securing home and small business computers can only happen with the engagement of citizens in the security enterprise. By the very nature of the Internet, individuals must be active participants in the security of their own systems. Civil engagement highlights the need for all Americans, in their homes and businesses, schools and churches, to be part of the security solution. Personal responsibility in this effort is essential for success.
This requires the computer security community to educate the public about personal security efforts.
154
Information technology is not a profession and is not bound by proactive professional ethical mandates,36 even though proactive attention to safety and security may be expected.37
This training solution promotes safety, security, and social responsibility by advancing the under- standing of computing in the critical area of security.38
CONCLUSION
Cyber infrastructure needs security that can only happen via collaboration between citizens/system us- ers, businesses, law enforcement agencies, and civil institutions that provide the knowledge and improved technologies needed for secure computing. Should such collaboration fail to develop, computing in our country, and its benefits, will suffer.
As a collaborative effort, cyber security requires personal responsibility from citizens and institutions. Protective factors in cyber security are minimized when participants blindly delegate all responsibility to others and continue to deploy and use networked systems.
Optimally, public policy will foster both law en- forcement and citizen engagement in information se- curity. Failure to engage these resources will continue to leave gaps in protection and create opportunities for harm to our people and our country.
155
ENDNOTES - CHAPTER 6
1. Carolyn Pumphrey, “Introduction,” in Carolyn Pumphrey, ed., Transnational Threats: Blending Law Enforcement and Military Strategies, Carlisle, PA: Strategic Studies Institute, U.S. Army War College, 2000, pp. 1-17, available from www.strategicstudiesinsti- tute.army.mil/pubs/display.cfm?pubid=224.
2. Ron Deibert and Rafal Rohozinski, “Tracking GhostNet: Investigating a Cyber Espionage Network,” Information Warfare Monitor, March 29, 2009, available from www.infowar-monitor.net/ ghostnet.
3. Ibid., p. 6.
4. Justin Blum, “Hackers Target U.S. Power Grid: Govern- ment Quietly Warns Utilities To Beef Up Their Computer Secu- rity,” Washington Post, March 11, 2005, p. E01.
5. Art Jahnke, “Alexey Ivanov, and Vasiliy Gorshkov: Russian Hacker Roulette,” CSO Online, January 1, 2005, available from www.csoonline.com/article/219964/Alexey_Ivanov_and_Vasiliy_Gor- shkov_Russian_Hacker_Roulette.
6. Susan Brenner, “Cybercrime Metrics: Old Wine, New Bot- tles?” Virginia Journal of Law and Technology, Vol. 9, No. 13, Fall 2004.
7. Wayne Arnold, “TECHNOLOGY; Philippines to Drop Charges on E-Mail Virus,” New York Times, August 22, 2000, available from www.nytimes.com/2000/08/22/business/technology- philippines-to-drop-charges-on-e-mail-virus.html.
8. C-T Li, Handbook of Research on Computational Forensics, Digi- tal Crime and Investigation: Methods and Solutions, Hershey, PA: IGI Global, 2010.
9. Miles Townes, “International Regimes and Information In- frastructure,” Stanford Journal of International Relations, Vol. 1, No. 2, Spring 1999.
156
10. Ibid.; Nicholas Sietz, “Transborder Search: A New Per- spective on Law Enforcement?” International Journal of Common Law and Policy, Vol. 9, No. 2, Fall 2004; Lorenzo Valeri, “Securing Internet Society: Toward an International Regime for Information Assurance,” Studies in Conflict & Terrorism, Vol. 23, Iss. 2, January 2000, pp. 129-146, particularly p. 141.
11. Council of Europe CETS No. 185 Convention on Cyber- crime, opened for signature November 23, 2001, available from conventions.coe.int/Treaty/en/Treaties/Html/185.htm, signed and ratified by 27 states.
12. Stanley Cohen, Visions of Social Control: Crime, Punishment, and Classification, Cambridge, UK: Polity Press, 1985.
13. M. Ouimet, “Internet Crime and Trends,” in F. Schmallag- er and M. Pittaro, eds., Crimes of the Internet, Upper Saddle River, NJ: Pearson Education Inc., 2009, pp. 408-416.
14. M. Fishbein and I. Azjen, Belief, Attitude, Intention and Be- havior: An Introduction to Theory and Research, Reading, MA: Addi- son-Wesley, 1975.
15. J. M. Olson and M. P. Zanna, “Attitudes and Attitude Change,” Annual Review of Psychology, Vol. 86, 1993, pp. 852-875.
16. Robert Boyd and Peter J. Richerson, The Origin and Evolu- tion of Cultures, Oxford, UK: Oxford University Press, 2005.
17. Christine Horne, “Sociological Perspectives,” in Michael Hechter and Karl-Dieter Opp, eds., Social Norms, New York: Rus- sell Sage, 2001, pp. 3-34.
18. Everett Rogers, The Diffusion of Innovations, New York: Free Press, 1983.
19. Robert C. Ellickson, “The Evolution of Social Norms: A Perspective from the Legal Academy,” in Michael Hechter and Karl-Dieter Opp, eds., Social Norms, New York: Russell Sage, 2001, pp. 35-75.
157
20. Michael Hechter and Karl-Dieter Opp, “Introduction,” in Michael Hechter and Karl-Dieter Opp eds., Social Norms, New York: Russell Sage, pp. xi-xx.
21. Harold Demsetz, “Toward a Theory of Property Rights,” American Economic Review, Vol. 57, No. 2, 1967, pp. 347-359.
22. Michael Losavio, Deborah Wilson, and Adel Elmaghraby, “Prevalence, Use and Evidentiary Issues of Digital Evidence of Cellular Telephone Consumer and Small Scale Digital Devices,” Journal of Digital Forensic Practice, Vol. 1, December 2006, pp. 291- 296.
23. Ibid.
24. Ibid.
25. Michael Losavio, Julia Adams, Marc Rogers, “Gap Analy- sis: Judicial Experience and Perception of Electronic Evidence,” Journal of Digital Forensic Practice, Vol. 1, March 2006, pp. 13-18; Michael Losavio, Deborah Wilson, Adel Elmaghraby, “Implica- tions of Attorney Experiences with Digital Forensics and Elec- tronic Evidence in the United States,” Third International Work- shop on Systematic Approaches to Digital Forensic Engineering, Institute of Electrical and Electronic Engineers (IEEE), May 22, 2008, Berkeley, CA; Survey of digital forensics session attendees of the Kentucky Council on Crime and Delinquency, September 2008 (unpublished); Survey of attendees at federal defender train- ing, New Orleans, LA, February 2008 (unpublished).
26. See Technical Working Group for Electronic Crime Scene Investigation, Electronic Crime Scene Investigation: A Guide for First Responders, Washington, DC: National Institute of Justice, July 2001.
27. Michael Losavio et al., The Key Asset Protection Partnership: Computer Security, Homeland Security and Community Engagement, The American Community Preparedness Conference, Louisville, KY, May 12, 2004, p. 38.
28. Federal Information Processing Standards (FIPS) Publica- tion 199, Standards for Security Categorization of Federal Information
158
and Information Systems, Gaithersburg, MD: National Institute of Standards and Technology, February 2004, as applied to the col- lateral impact of home system compromise on infrastructure.
29. Ibid., p. ix.
30. M. Wilson, and J. Hash, NIST Special Publication 800-50, Building An Information Technology Security Awareness and Training Program, Gaithersburg, MD: National Institute of Standards and Technology, October 2003.
31. Available from csrc.nist.gov/securebiz/index.html; presenta- tion of Dr. Alicia Clay of NIST to the Department of Computer Engineering and Computer Science, Speed School of Engineering, University of Louisville, March 2004.
32. R. Peterson, Protecting Our Nation’s Cyber Space: Education- al Awareness for the Cyber Citizen, Testimony before the Subcom- mittee on Technology, Information Policy, Intergovernmental Relations and the Census, Committee on Government Reform, United States House of Representatives, 2004, available from www.educause.edu/ir/library/pdf/SEC0407.pdf. In his remarks, Peter- son notes that training is not sufficient; secure technology must be an objective of all software development.
33.. Awareness and Outreach Task Force of the National Cy-
ber Security Partnership, 2004 Task Force Report, 2004, available from www.educause.edu/ir/library/pdf/SEC0403.pdf.
34. CyberBlockWatch, available from www.speedacm.org/dhs.
35. Available from www.staysafeonline.info/.
36. J. L. Linderman and W. T. Schiano, “Information Ethics in a Responsibility Vacuum,” The DATA BASE for Advances in Infor- mation Systems, Vol. 32, No. 1, 2001, pp. 70-74.
37. P. J. Denning, “Who Are We?” Communications of the ACM, Vol. 44, No. 2, 2001, pp. 15-19.
38. M. Losavio, “Cybersecurity and Homeland Security,” Kentucky Bench and Bar, Vol. 67, No. 6, 2003, pp. 36-38.
159
CHAPTER 7
THE ATTACK DYNAMICS OF POLITICAL AND RELIGIOUSLY MOTIVATED HACKERS
Thomas J. Holt
INTRODUCTION
There is a significant body of research focused on mitigating cyber attacks through technical solutions. Though these studies are critical to decrease the im- pact of various vulnerabilities and hacks, researchers still pay generally little attention to the affect that mo- tivations play in the frequency, type, and severity of hacker activity. Economic gain and social status have been identified as critical drivers of computer hacker behavior in the past, but few have considered how na- tionalism and religious beliefs influence the activities of some hacker communities. Such attacks are, how- ever, gaining prominence and pose a risk to critical infrastructure and web based resources. For example, a number of Turkish hackers engaged in high profile web defacements against Danish websites featuring a cartoon of the prophet Muhammad in 2005. In order to expand our understanding of religious and nationalist cyber attacks, this chapter will explore the active and emerging hacker community in the Muslim majority nation of Turkey. Using multiple qualitative data sets, including interviews with active hackers and posts from multiple web forums, the findings explore the nature of attacks, target selection, the role of peers in facilitating attacks, and justifications through the lens of religious and national pride. The results can benefit information security professionals, law enforcement,
160
and the intelligence community by providing unique insights on the social dynamics driving hacker activ- ity.
The growth and penetration of computer technol- ogy has dramatically shifted the ways that individuals communicate and do business around the world. The beneficial changes that have come from these tech- nologies have also led to a host of threats posed by computer criminals generally, and hackers specifical- ly. In fact, the number of computer security incidents reported to the U.S. Computer Emergency Response Team (CERT) has grown in tandem with the number of individuals connected to the Internet.1 Data from CERTs around the world suggest that the number of computer attacks have increased significantly since 2001.2 Computer attacks are also costly, as unauthor- ized access of computer systems cost U.S. businesses $20 million dollars in 2006 alone.3
Research from the social sciences has explored computer attackers and malware writers in an attempt to understand their reasons for engaging in malicious activity. Criminological examinations of hacker sub- culture found that computer hackers value profound and deep connections to technology, and judge others based on their capacity to utilize computers in unique and innovative ways.4 Similar research on virus writ- ers suggests they may share hackers’ interests in tech- nology, though they are driven by more malicious interests.5
A small body of research has also considered the motives that drive the hacker community.6 The Hon- eynet Project argues that there are six key motivations in the hacker community: money, entertainment, ego, cause, entrance to a social group, and status. A num- ber of studies have identified the significant financial
161
gain that can be made by hacking databases to steal credit cards and financial information.7 Additionally, a burgeoning market has developed around the sale of malicious software and stolen data, particularly in Eastern Europe and Russia.8 Additionally, research on the enculturation process of hacker subculture has found that peer recognition is vital to gain status and recognition.9
Research on cause-based hacking has, however, increased in recent years as more countries become connected to the Internet. Mainstream and alterna- tive political and social movements have grown to depend on the Internet to broadcast their ideologies across the world. Groups have employed a range of tactics depending on the severity of the perceived injustice or wrong that has been performed.10 For ex- ample, the native peoples, called Zapatistas, in Chi- apas, Mexico, used the Internet to post information and mobilize supporters to their cause against gov- ernmental repression.11 Chinese hackers frequently engage in cyber attacks against government resources in the United States and other nations to obtain sen- sitive information and map network structures.12 Fi- nally, a massive online conflict developed between Russian and Estonian factions in April 2006 when the Estonian government removed a Russian war monu- ment from a memorial garden.13 This conflict became so large in scope that hackers were able to shut down critical components of Estonia’s financial and govern- ment networks, causing significant economic harm to citizens and industry alike.14
Though there is a growing body of research con- sidering hacking as a means to a political or patriotic end, few have considered the ways that religion af- fects hacker behavior. This is a particularly salient is-
162
sue when considering the growing number of Muslim nations connecting to the Internet. The penetration of high speed Internet connectivity and computer tech- nology in Muslim-majority nations is changing the landscape of the Internet, enabling political and reli- gious expression and global exposure to various per- spectives.
These benefits are, however, offset by the growth of hacker communities that are motivated by religious beliefs. For example, a Danish newspaper published a cartoon featuring the prophet Muhammad with a bomb in his turban in 2005.15 This image was deemed offensive by the Muslim community, and the news- paper’s website was defaced repeatedly, along with any other site that featured the cartoon.16 Thousands of websites were hacked or defaced by Turkish hack- ers, who in turn received a great deal of attention by the press for their efforts.17 As a consequence, Turk- ish hacker groups have become active participants in a range of attacks against various targets across the globe.18
In light of the potential threats and the under-ex- amined nature of this problem, this chapter explores the ways that the specific motives of religion and na- tionalism affect hacker attitudes and activities. Using multiple qualitative data sets collected from active Turkish hackers, the findings consider how political and religious ideologies shape perceptions and justifi- cations of hackers within this community.
DATA AND METHOD
The data for this chapter consists of two unique re- sources: a series of 10 in-depth interviews conducted via e-mail or instant messaging with prominent hack-
163
ers in the Turkish community, and explorations of six websites operated by and for Turkish hackers.
The first data set consists of interviews that probe individuals’ experiences and impressions of the Turk- ish hacker community on and offline. They were asked to describe their experiences with hacking, in- teractions with others in on and offline environments, and their direct opinions on the presence of a hacker subculture in Turkey.
Interviewees were identified and contacted through the use of two fieldworkers with significant status among Turkish hackers. Individuals who re- sponded to the solicitation were sent a copy of the survey protocol, allowing the respondent to complete the instrument at their leisure. In addition, individu- als were given the option to complete the instrument in either Turkish or English. Interviews completed in Turkish were transcribed from Turkish to English by a certified translator to ensure accurate and reliable data.
To gain more insight into the Turkish hacker com- munity, ethnographic observations were conducted in six Turkish hacker web forums where the interview- ees claimed to visit or post content on a regular basis. Participants in these forums interact with one another by posting on “threads” within the forum. Threads are textual conversations that are organized chronologi- cally within the forum.19 These posts are cultural ar- tifacts that are amenable to analysis as they resemble a running conversation between participants.20 These sites were also publicly accessible, in that anyone could access the forum content without the need to register with the site. This sort of publicly accessible web fo- rum is common in online ethnographic research, as individuals who are unfamiliar with a certain form of behavior may be most likely to access a public fo-
164
rum first.21 Specific web addresses and names of these sites are not provided to protect the anonymity of the users. The content of these sites were translated us- ing machine translation programs to ensure accurate translation.
Both data sets were printed and analyzed by hand using the three-stage inductive analysis methodol- ogy derived from grounded theory.22 This coding and analysis scheme is particularly useful as it permits the researcher to develop a thorough, well-integrated examination of any social phenomena. Any concepts found within the data must be identified multiple times through comparisons to identify any similari- ties.23 In this way, findings are validated by their re- peated appearances or absences in the data, ensuring they are derived and grounded in the data.
For this analysis, the techniques of hacking and significance of religion and national values were in- ductively derived from the repeated appearance of specific actions, rules, or ideas in the data. The value of these concepts is generated from positive or nega- tive comments of the respondents. In turn, theoreti- cal links between these concepts are derived from the data to highlight the value of nationalism, Islam, or other interests that structures the behavior of hackers. The findings are discussed using direct quotes from both data sets where appropriate.
FINDINGS
Knowledge Among Turkish Hackers.
To understand the Turkish hacker community, it is necessary to first consider how individuals relate to computer technology, and their peers. To that end, Turkish hackers suggested that their ability to target
165
and engage in attacks depended on their knowledge of computers and networked systems. Those with a deeper understanding were able to engage in more successful and novel attacks than others.24 Hackers across the data sets gained knowledge on computer systems in two ways: personal experience and through peer mentoring. The interviewees argued that learn- ing through practice and trial and error are essential to increase knowledge of computer systems, in keep- ing with research on hacker communities around the globe.25 For example, “Agd_Scorp” stated that he learned computer systems and hacking through “trial and error, and some documents on the Internet. But trial and error is the best method.”26 Similarly, “The Bekir” described gaining access to information on- line, but needed to expand his knowledge through firsthand experience: “In the beginning I looked at il- lustrated explanations on the web and acted accord- ingly, but they were not sufficient for me. I wanted to learn how this was done, how these were provided and I fiddled about with them a lot until they broke down.”27
Several of the individuals interviewed also stated that they gained practical knowledge through direct and indirect assistance from others in the hacker com- munity. Individuals could gain indirect assistance from their peers by accessing videos or documents posted in a number of outlets online. These materials provide detailed information on system processes, as well as step-by-step instructions on methods of hack- ing. For example, “Iscorpitx” made video tutorials on web defacements in order to help the community. He succinctly explained his reasons, stating: “In general, I like sharing the things I do after a while. A lot of vid- eos I recorded while defacing online were very useful
166
for a lot of people who are on the security side of this business. Of course, you can’t be skilled and informed in every subject. Everybody needs help.”28 Similarly, “Axe” stated that his hacking activities began in ear- nest when he felt “it was the time to apply what I saw in the videos I watched.”29
Forums are also an important resource for infor- mation since they act as repositories for information on computers and hacking. All of the forums in this sample had sections devoted to computer security, networking, and hacking, with distinct subsections centered on specific operating systems, programming languages, and tools. Thus, visiting a forum enabled an individual to learn on his own by reading the vari- ous materials posted. Forums also provide individu- als with indirect assistance through tutorials written by skilled hackers that provide direct information on the process of engaging in attacks. For example, two of the forums in this sample had how-to guides on struc- tured query language (SQL) injection and the process of defacing websites. Three others had detailed tuto- rials on how to perform cross-site scripting attacks against a variety of sites. These resources are written so as to inform other hackers, and provide clear advice to the larger population of hackers. Thus, myriad re- sources are available to facilitate indirect social learn- ing in the Turkish community.
Direct interactions with others online are also im- portant to the development of Turkish hackers. Only three interviewees suggested that they were directly taught how to hack by their peers, suggesting this is an infrequent practice among Turkish hackers. For example, “Blue Crown” described his introduction to hacking through a unique interaction:
167
I had some interest in hacking but I wasn’t planning to get involved in this business. One day, an interview with a hacking group on television caught my atten- tion. . . I turned on my computer and immediately started to browse. I met a hacker with a code name SheKkoLik in Ayyildiz Tim. I owe him/her a lot. . . I thought I couldn’t do anything but s/he helped me and taught me a few things. I learned quickly thanks to the interest I had.30
Online discussions with other hackers were, how- ever, very common and critical to provide useful in- formation on technology and hacking. In fact, the ma- jority of respondents suggested that they visited either forums or chatted with others using Microsoft (MSN) Instant Messaging. Forums enable individuals to con- nect with and ask questions of other hackers. When an individual asked a question, forum users would give web links that would help answer the question. These links provided specific information about an is- sue or topic discussed in the string without repetition or wasted time for the other posters. This would also encourage self-discovery as the user would have to actively open the link and read to find their answer. Some users would also provide brief instructions that would help to address the issue, though this could of- ten encourage debate over the accuracy of the answer. In fact, “The Bekir” espoused the value of forums, stating: “There was a web forum, which was created by a very close friend of mine. I was in that forum for 2-3 years and it was quite nice . . . I learned a lot of things at that site and helped them to learn a lot of things as well.”31 This suggests knowledge is vital to facilitate attacks and develop skills within the Turkish hacker community.
168
Knowledge and Attack Methods.
The process of acquiring knowledge of comput- ers and hacking has a critical impact on the types of attacks individuals perform. Those with greater skill could complete more sophisticated attacks. “Iscor- pitx” succinctly described this issue, stating:
If a hacker wants to harm a site where s/he has an obsession, s/he will. If s/he can’t, s/he can get help. If s/he can’t do anything, s/he can stop the publi- cation of the website using a DDoS attack. But if s/ he wants, s/he can cause harm. The ones who have enough knowledge and information can manage this; otherwise it is very difficult. The ones who don’t have enough knowledge can’t get help as well.32
This statement emphasizes the range of attacks that hackers can engage in. In fact, “Amon” was a very skilled hacker who indicated he could complete hacks related to “ASP, SQL union, update, Linux root, etc. It is easy to use if you know what you are doing. Of course, I generally use my own tools.”33
The types of tools used also depend on the target and end goal of the hack. For example, “Crazy King” suggested that he and his colleagues:
use a key logger and trojan in personal and special/ private attacks. We use bots to overstrain the server and put it out of operation in transcendent systems . . . They are the sources that we develop ourselves and belong to us.34
“Blue Crown” made a similar point, suggesting:
When I’m going to perform a personal hack, I need an undetected keylogger or trojan. Some trojans
169
are subject to payment and some of them are free of charge. The only difference between these two trojan types is that trojans subject to payment are undetect- able (they can’t be caught). I can make a free of charge trojan “undetectable” by using some Crypt programs. Friends who develop the Crypter work for this. They usually use well-known and existing weak points/ holes. If Turkish hackers find a hole/weak point, they share this after exploiting it.35
The notion that Turkish hackers use existing flaws and weaknesses is an important point due to the fact that the forums also provided access to a variety of resources and attack tools. Individuals could quickly and efficiently download a variety of malware, such as Turkojan. This tool is an efficient Turkish made trojan that is designed to “steal passwords, act as a remote viewing tool, and efficiently alter system processes.”36 Multiple versions of this tool were available, as were a variety of other programs, such as password sniff- ers, rats, virus code, and rootkits made by hackers in other countries. Thus, access to web forums coupled with a strong knowledge of computer technology en- able Turkish hackers to engage in a variety of attacks against global targets.
Religion, Politics, and Hacking.
Turkish hackers across the data sets placed signifi- cant emphasis on using their knowledge to support “the mission.” In this case, the mission referred to at- tacks against a variety of targets based on religious and national beliefs. The importance of a mission was evident across interviewees, and reflected these beliefs. For example, “Amon” suggested that “every- thing is for the mission. . . . Which other nation is as
170
patriotic as Turks.”37 “Ghost 61” also described how the mission makes Turkish hackers unique relative to other communities: “everyone does this [hacking] for money and financial benefits, but Turkish hackers do it for the flag, for the homeland.”38 “Iscorpitx” also re- flected on the range of interests and missions evident in the Turkish hacker community:
Among Turkish hacker groups, we can count Islamic groups, revolutionist groups, groups with ideas sup- porting Ataturk, nationalist groups, etc. There are very talented and skilled young people. . . But these talents are very rare. They have much respect for their national and moral values.39
The forums also supported the notion of a mili- tary-style mission, as individuals regularly evoked nationalistic and religious symbols as part of their avatar, or personal image. Forum users across the sites used images of the Turkish flag as part of their avatar background, or featured pictures of the national soc- cer team players because of their pride in the team. Others’ avatars used military images, such as soldiers carrying rifles, bombs, or missiles. Some used pictures of masked militants holding rifles or making threaten- ing gestures with swords or knives.
The mission within the Turkish hacker community affects the nations targeted in their attacks. Several of the individuals interviewed argued that they target resources in countries that are perceived as threats to or enemies of Muslim nations. For example, “Ghost 61” stated “I determine it [targets] according to the agenda; usually they are countries like the USA, Is- rael, Russia, in other words, enemies of Muslims.”40 “Agd_Scorp” echoed this sentiment stating that he tar- geted those countries that “deliberately attacks Mus-
171
lims . . . America is the country which killed the most Muslims in the world. And United Nations also killed many Muslims and innocent people.”41 In fact, “Blue Crown” noted that Danish websites were a particu- larly large target due to their portrayal of the prophet Mohammed in a disparaging cartoon. He indicated that “nearly HALF of the sites with the .dk extension were hacked by Turkish hackers in order to protest the disgusting and dreadful cartoons by Denmark.”42
The types of sites Turkish hackers targeted were also impacted by the mission. Individuals actively at- tacked websites and resources that are perceived as either against Islamic religious precepts or actively harmed Turkish interests. For instance, “The Bekir” wrote that: “I determine my targets in terms of hits. I was working on hacking websites that were involved in terrorism; if the hacked website is big then it makes a greater splash, I’m usually working on hacking ter- rorism sites, etc.”43 “Blue Crown” suggested that he and his peers “hack PKK and pornographic sites.”44
One of the most important and common forms of attacks used to support the mission are web deface- ments. This involves using an exploit or vulnerability to replace or remove a web page with a new image of the hackers’ choosing.45 Defacements enable hack- ers to post messages and images that indicate their perspectives and beliefs, as well as gain status by list- ing their name and group affiliation. To that end, the interviewee “Iscorpitx” held a world record for mass defacements and used this type of attack as a means to support his religious agenda. He actively selected sites that act in opposition to Islamic tenets, particu- larly “gambling sites, child pornography and disgust- ing pornography were always my targets. . . I think there’s no other defacer who harmed sites in these sec- tors as much.”46
172
The forums also had teams that operate in support of web defacements. One such forum had an “opera- tions” section dedicated to discussions and listings of all the sites that the group’s members have defaced. The titles of threads within this subforum clearly in- dicate the diverse range of targets defaced by Turk- ish hackers, and to a lesser extent, their connection to Islam:
• Threat to French Site • Korean Yahoo Sites – “I have defaced a famous
Korean site.” • The group has defaced 1,000 sites! • Join our site and help deface • Our martyrs have defaced many sites • Deface Announcements • We will eliminate the world (world wide web) • Web sites hacked • 20 web site templates hacked • Adina Hotel hacked • 20 Video Sites Hacked • English Receiving Site Hacked • USA Enterprises Hacked • Buddhism and Satanism Sites Hacked.47
The importance of “the mission” also affects so- cial organization practices among Turkish hackers. Though many individuals stated they hacked by themselves, they would work with others depending on the size and scope of the target. “Amon” empha- sized this point, writing:
They [Turkish hackers] form groups. It doesn’t take long, it is done quickly. They do not team-up for a sin- gle website. Then somebody comes up and announces that he broke into a site...You check it and it is really broken... But then it becomes a team job, although a single person discovers it usually.48
173
“Crazy King” also elaborated on this point, writing:
If popular events (like war) are the case, they come together as a team in order to harm the systems with country extensions. Individually they target large sys- tems and work individually in order to leave protest- ing messages. They do this by telling their common actions to each other or with the documents they write in the forums or videos or texts. If there is a very im- portant event involving the world and people, they can immediately come together.49
The forums also provided some important insights into organizational hierarchies. For example, one site established its leadership and attack command struc- ture based on individual performance in a hacking challenge set up through their website. Individuals must progress through 13 missions, and their per- formance establishes how they will participate in the larger group. The missions include the following ac- tivities:
1. HTML code 2. SQL Injection 3. RC4 Encryption 4. Zip Crack 5. Page Redirect 6. PWL Crack 7. Secret Question 8. VB Script Encode 9. JS Password 10. Serv-U FTP 11. ICQ Dat Crack 12. Front Page 13. Carefully
174
All of the forums also provide a detailed command structure for their forums, composed of administra- tors who supervise and control the sites that house the forums, co-administrators who handle certain aspects of the site and forums, super-moderators who man- age the entire web forum, and forum moderators who deal with content-specific subforums. This structure ensures easy operation and management, and estab- lishes clear levels of respect and status that must be afforded to the management structure. One site even provided a flow chart to specify forum operations and dictate how complaints and suggestions move through the chain of command. Thus, religion and national pride clearly affect the actions, targets, and practices of Turkish hackers.
DISCUSSION AND CONCLUSION
This chapter sought to explore the impact of re- ligious and political motives on the activities of the Turkish hacker community. The findings indicate that they place significant value on understanding com- puter technology because their level of knowledge impacts their ability to hack. Hackers could increase their understanding of computer systems by working with various technologies on their own, or by reading tutorials and watching videos posted online. Interact- ing with other hackers in forums is also important as these relationships can foster an individual’s devel- opment as a hacker. In this way, the Turkish hacker community reflects the critical role of technology in structuring hacker and virus writer behavior across the globe.50
The interviewees and forum users also indicated that they were heavily influenced by their religious
175
and national affiliations. In fact, the importance of Is- lam for the Turkish community cannot be understated as it provided a “mission” that must be completed. The types of attacks that Turkish hackers engaged in also appeared to encompass the entire spectrum of the global hacker community. Individuals used malware, SQL injection attacks, and web defacements in order to attack various resources. The scope of their attacks were, however, heavily focused on websites and re- sources in countries that are perceived to either slight the Muslim community, or Turkey specifically.
As a result, it may be that cause-driven hackers are apt to attack high value or visibility targets, rather than large populations of computer users and general resources. This is quite different from the practices of financially motivated hackers, such as in Russia and Romania.51 As such, further comparative research is needed with a sample of hackers from a variety of Muslim-majority nations to understand the signifi- cance of political and religious ideology on hacker activity.
In addition, there may be some distinctive attack signatures that can be developed based on cause-driv- en attacks. The consistent recognition of “the mission” across the data sets, and the organizational hierarchies present in the forums and interviewee experiences suggest that the tactics employed by religious or polit- ically motivated hackers may differ from those driven by other agendas. Thus, there may be value in devel- oping baseline predictive models of attacker behavior using log files from actual incidents. Future research analyzing multiple real world attacks may be useful in developing technical solutions to mitigate attacks against critical infrastructure and computer resources. Yet there is a strong likelihood that the form and shape
176
of hacker activity varies across countries and political ideologies. Thus, it is essential that researchers begin to focus on computer attackers in a global context to better understand the individuals that attempt to compromise computer systems.
ENDNOTES - CHAPTER 7
1. T. A. Longstaff, J. T. Ellis, S. V. Hernan, H. F. Lipson, R. D. McMillian, L. Hutz Pesante et al., “Security of the Internet,” in M. Dekker, ed., The Froehlich/Kent Encyclopedia of Telecommunications, Vol. 15, 1997, pp. 231-255.
2. T. J. Holt, “Examining a transnational problem: An analy- sis of computer crime victimization in eight countries from 1999 to 2001,” International Journal of Comparative and Applied Criminal Justice, Vol. 27, 2003, pp. 199-220.
3. Computer Security Institute, “Computer Crime and Securi- ty Survey,” 2007, available from www.cybercrime.gov/FBI2007.pdf.
4. T. J. Holt, “Subcultural evolution? Examining the influence of on- and off-line experiences on deviant subcultures,” Deviant Behavior, Vol. 28, pp. 171-198, 2007; T. Jordan and P. Taylor, “A Sociology of Hackers,” The Sociological Review, Vol. 40, pp. 757-80, 1998; P. A. Taylor, Hackers: Crime in the Digital Sublime, New York: Routledge, 1999; D. Thomas, Hacker Culture, Minneapolis: Univer- sity of Minnesota Press, 2002.
5. A. Bissett and G. Shipton, “Some human dimensions of computer virus creation and infection,” International Journal of Human—Computer Studies, Vol. 52, 2000, pp. 899-913; S. Gordon, “Virus Writers: The End of the Innocence?” 2000, available from www.research.ibm.com/antivirus/SciPapers/VB2000SG.pdf; S. Gor- don and Q. Ma, Convergence of Virus Writers and Hackers: Fact or Fantasy? Cupertine, CA: Symantec, 2003.
6. A. Bissett and G. Shipton, “Some human dimensions of computer virus creation and infection”; Gordon, “Virus Writers”; The Honeynet Project, Know Your Enemy: Learning About Security Threats, 2nd Ed., Boston, MA: Addison-Wesley, 2004.
177
7. S. Furnell, Cybercrime: Vandalizing the Information Society, Boston, MA: Addison-Wesley, 2002; G. Newman and R. Clarke, Superhighway robbery: Preventing e-commerce crime. Cullompton, UK: Willan Press, 2003; L. James, Phishing Exposed, Rockland, MA: Syngress, 2005.
8. James, Phishing Exposed; Honeynet Research Alliance, “Pro- file: Automated Credit Card Fraud,” Know Your Enemy Paper se- ries, 2003; R. Thomas and J. Martin, “The underground economy: Priceless”; login, Vol. 31, pp. 7-16, 2006; T. J. Holt and E. Lampke, “Exploring stolen data markets online: Products and market forc- es,” Criminal Justice Studies, Forthcoming.
9. Holt, “Subcultural evolution”; Jordan and Taylor, “A So-
ciology of Hackers”; Taylor, Hackers; Thomas, “Hacker Culture.”
10. D. E. Denning, “Activism, hacktivism, and cyberterrorism: The Internet as a tool for influencing foreign policy,” in J. Arquilla and D. Ronfeldt, eds., Networks and Netwars: The Future of Terror, Crime, and Militancy, Santa Monica, CA: RAND, 2001, pp. 239-288; T. Jordan and P. Taylor, Hacktivism and Cyberwars: Rebels With a Cause, New York: Routledge, 2004.
11. Denning, “Activism, hacktivism, and cyberterrorism”; R. Cere, “Digital counter-cultures and the nature of electronic social and political movements,” Y. Jewkes, in Dot.cons: Crime, deviance and identity on the Internet, Portland, OR: Willan Publishing, 2003, pp. 147-163.
12. Denning, “Activism, hacktivism, and cyberterrorism”; S. W. Brenner, Cyberthreats: The Emerging Fault Lines of the Nation State, New York: Oxford University Press, 2008.
13. Brenner, Cyberthreats; G. Jaffe, “Gates Urges NATO Min- isters To Defend Against Cyber Attacks,” The Wall Street Jour- nal On-line, June 15, 2006, available from online.wsj.com/article/ SB118190166163536578.html?mod=googlenews_wsj; M. Landler and J. Markoff, “Digital Fears Emerge After Data Siege in Estonia,” The New York Times, May 24, 2007, available from www.nytimes.com/2007/05/29/technology/29estonia.html.
178
14. Brenner, Cyberthreats; Landler and Markoff “Digital Fears Emerge After Data Siege in Estonia.”
15. M. Ward, “Anti-cartoon protests go online,” BBC News, February 8, 2006, available from news.bbc.co.uk/2/hi/technolo- gy/4692518.stm.
16. Ibid.
17. Ibid; D. Danchev, “Hundreds of Dutch web sites hacked by Islamic hackers,” ZDNet, available from blogs.zdnet.com/ security/?p=1788.
18. Danchev, “Hundreds of Dutch web sites hacked by Islam- ic hackers.”
19. D. Mann and M. Sutton, “Netcrime: More Change in the Organization of Thieving,” British Journal of Criminology, Vol. 38, pp. 201-29, 1998.
20. Ibid.; Holt, “Subcultural evolution.”
21. Holt, “Subcultural evolution.”
22. J. Corbin and A. Strauss, “Grounded Theory Research: Procedures, Canons, and Evaluative Criteria,” Qualitative Sociol- ogy, Vol. 13, 1990, pp. 3-21.
23. Ibid.
24. Holt, “Subcultural evolution”; Jordan and Taylor, “A So- ciology of Hackers”; Taylor, Hackers: Crime in the Digital Sublime; Thomas, Hacker Culture.
25. Ibid.
26. Agd-Scorp, Interview, personal email, August 8, 2008.
27. The Bekir, Interview, personal email, July 29, 2008.
28. Iscorpitx, Interview, personal email, July 30, 2008.
179
29. Axe, Interview, personal email, August 1, 2008.
30. Blue Crown, Interview, personal email, July 30, 2008.
31. The Bekir, Interview.
32. Iscorpitx, Interview.
33. Amon, Interview, personal email, August 10, 2008.
34. Crazy King, Interview, personal email, August 10, 2008.
35. Blue Crown, Interview.
36. Forum, address withheld.
37. Amon, Interview.
38. Ghost GI, Interview, personal emails, August 9, 2008.
39. Iscorpitx, Interview.
40. Ghost GI, Interview.
41. Agd-Scorp, Interview.
42. Blue Crown, Interview.
43. The Bekir, Interview.
44. Blue Crown, Interview.
45. James, Phishing Exposed; Brenner, Cyberthreats.
46. Iscorpitx, Interview.
47. Forum, address withheld.
48. Amon, Interview.
49 . Crazy King, Interview.
180
50. Holt, “Subcultural evolution”; Jordan and Taylor, “A So- ciology of Hackers”; Taylor, Hackers: Crime in the Digital Sublime; Thomas, Hacker Culture; Gordon, “Virus Writers”; Gordon and Ma, Convergence of Virus Writers and Hackers.
51. James, Phishing Exposed; Honeynet, “Profile”; Thomas and Martin, “The underground economy”; Brenner, Cyberthreats.
PART III:
TECHNICAL ASPECTS
181
183
CHAPTER 8
RESILIENCE OF DATA CENTERS
Yehia H. Khalil* Adel S. Elmaghraby*
INTRODUCTION
Data centers (DC) are the core of the national cyber infrastructure. With the incredible growth of critical data volumes in financial institutions, government organizations, and global companies, data centers are becoming larger and more distributed posing more challenges for operational continuity in the presence of experienced cyber attackers and occasional natural disasters. The need for resilience assessment emerged due to the gap in existing reliability, availability, and serviceability (RAS) measures. Resilience as an evalu- ation metric leads to better proactive perspective in system design and management. An illustration of the need for resilience evaluation and a survey of relevant research are presented.
Many organizations now depend on their ability to access their data for their daily operations. Despite the increased power of personal computers and depart- mental workstations, we notice an increased depen- dency on centralized data centers due to the needs for data integration, data consistency, and data quality. With the enormous growth of critical data volumes
________ * This work was partially funded by a grant from the U.S. Depart- ment of Treasury through a subcontract from the University of Kentucky. The opinions and conclusion in this paper are the sole responsibility of the authors.
184
for financial, global, institute, and governmental or- ganizations, data centers have evolved to become the key nerve center of the operations of these organiza- tions. A data center is a facility used for housing a large number of servers/workstations, data storages devices, communications equipment, and monitoring devices as shown in Figure 8.1. The complex archi- tecture of a data center and the variety of data types hosted or processed in a data center complicates their design, planning, and management.1
Figure 8.1. A Typical Data Center.
The fundamental purpose of any data center is to furnish application data access requirements; data center design must include operational requirements such as:
• Physically secure and safe location. • Afford reliable and dependable power supply. • Healthy environment to run these devices
safely.
185
• Afford communications within the data center and with the outside world.
A well designed data center will have the follow- ing properties:
• Flexibility: The ability of a DC to support new applications, services, and hardware substitu- tion without major technology compatibility problems.
• Availability: There is no room for risk with crit- ical applications so a DC should be in a good running condition all the time and maintain a high service level without any unplanned shut- downs related to hardware failures.
• Scalability: Variations in the data volume should not affect the DC’s quality of service.
• Security: It maintains different factors; physi- cal, operational, communication network, data storage, and application security.
• Manageability: Simplicity makes it easier for technical support, administration staff, and for troubleshooting errors.2
In many scenarios, the data center is used as a standalone facility which is not always the case; data centers can play different roles for cyber legacy infra- structure. Data center sites can be classified as having one of three main roles:
1. Active Site: The main data center which process- es all client requests and maintains local data backups.
2. Stand-by Site: This data center is ready to pro- cess client requests at any point of time if any request was redirected to it for load balancing. It is connected to the active site thought fiber optics to perform syn- chronous data replication and it is located within a small distance from the active site.
186
3. Disaster Recovery Site: It is located geographi- cally far away from the active site for security reasons; it is not ready to process user clients while the active site is up; and it is connected to the active site to per- form asynchronous data replication.3
In some scenarios, those roles can be combined based on system requirements and the need to imple- ment designer goals and objectives as shown in Figure 8.2.
Figure 8.2 . Data Center Roles Summary.
To ensure the operational continuity of critical ap- plications it is mandatory for the data center to pro- vide satisfactory levels of data availability, integrity, and consistency. Yet the growing challenges that data centers face necessitate new methodologies and ap-
187
proaches to ensure data center operational continuity, and threats like natural and man-made disasters and industrial spying elevate the necessuty for extremely resilient data centers. Elements of rational data centers include computer networks, data storage, security, and data mirroring as shown on Figure 8.3.
Figure 8.3. Data Center Rational Elements.
Cyber system infrastructure evaluation is a sig- nificant process toward systems enhancement and management. Conventional computer system evalua- tors intend to examine levels of RAS for their systems where:
• A reliable system does not deliver results that include uncorrected corrupted data, and it works to correct the corruption if applicable or shuts the system down.
• Availability is the uptime of device operating as the percentage of total time.
• Serviceability measures the ease to maintain, diagnose, and repair the system.
188
With new and emerging technologies, system complexity, data volumes, and new threats confirm the need for novel methodologies and approaches to assess of the resilience of data centers.
Resilience is the ability of a system to resist illegiti- mate activity and its ability to effect a speedy recovery as shown in Figure 8.4.4 The main aspect is to show how the system will be affected by the variation of the operational environment circumstances. However, it is used quite differently in different fields, for exam- ple, computer network resilience is the ability of the network to provide and maintain an acceptable level of service under different fault or an abnormal con- ditions caused by cyber threats or any other threats. While in business, resilience is the ability of a com- pany, resource, or structure to sustain the impact of a business interruption, recover, and resume its opera- tions to continue to provide minimum services.
Figure 8.4. DC Facility Failure Process Summary. The current data center metrics cover many of the
concerns of data center designers and mangers, how- ever there is still another set of concerns that lacks answers. All of the current metrics evaluate systems while they are operating or after a failure has oc-
189
Criteria SAN NAS
Cost Expensive Inexpensive
Setup Complicated Straightforward
Management Easy Complicated for large environment
Environment size Better for large Better for small
Disk system compatibility
Any Device orientated
Impact on network None Can swamp a network
curred. A proactive metric is needed to evaluate a sys- tem during all of its stages: launched attacks, resist- ing/adaptation to attacks, failure and recovery time, and patterns.
STATE OF THE ART
Storage Research and Technologies.
Data storage is an integral part of the architecture of a data centers, over the years several storage solu- tions have been developed to satisfy applications re- quirements and demands.5 Storage Area Networks (SAN) and Network Area Storage (NAS) are dominat- ing data center storage alternatives.
NAS are data storage devices that are connected- directly to the network with their own IP addresses, while SANs are storage devices which are connected to each other and connected to a server or a group of servers which act as access points for clients.6 Table 8.1 presents preliminary guidelines for a storage solution selecting process.
Table 8.1. SAN vs. NAS Summary.
190
SAN setup costs are getting cheaper and with less complicated management, so the future of SAN is more promising for data centers which make it the focus of this work. Rationally, SAN solutions have two components: storage servers and storage clients. The physical elements of SANs are as shown in Figure 8.5:
1. Disks can be connected as point-to-point with- out an interconnection device or they can be a part of server-storage model. SANs are independent from disk types; disks, tapes, RAIDs, and file servers can be used.
2. Servers are fundamental elements of a SAN, which can be a mix of platforms and OS.
3. Communications are implemented by a fiber channel, where data loss rate is zero, and there is a high throughput rate.
Figure 8.5. Elements of Storage Area Networks.
191
Regardless of which type of storage technology is used within data center, storage devices are required to: support data Access; Protect; Store; Move; and Recover with minimum cost (management and setup). Tradi- tionally researchers and engineers utilized Latency as a performance metric, which naturally characterizes hard drive access time. Input/Output (I/O) issues are a critical aspect of any storage solution, the gap be- tween the server processing rate and the I/O rate is large. SAN producers aim to overcome this limitation by improving Cache memory size and Caching algo- rithms. Yet, on the other hand, latency did not show how storage solutions protect & recover data, hence resilience metrics are required.
It is highly recommended designating between two categories of the data hosted in a data center:
1. In use data: which are accessed, modified and up- dated.
2. In rest data: which are not used at the moment and only stored to be used later or for recovery purposes.
Normally, “Data In Rest” is easier to protect and recover while “Data In Use” requires more effort. Data storage solution resilience evaluation results in the following concerns:
1. Availability of alternative routing paths within the fabric cloud.
2. Routing protocols’ capability to utilize an alter- native path with minimum cost (converging time and routing table size).
3. Optimum number of local disk images, backups to ensure fast recovery.
4. Data backup/ mirroring process frequency. 5. Mirroring approach impact on response time. 6. Protection techniques strength and overhead.
192
A resilient storage solution will not only provide the optimum answer for the concerns highlighted above, but will also tune them up jointly, to achieve the maximum resilience level.
Data Mirroring Techniques and Methodologies.
Data mirroring, data replication, and data backup are popular terms used in the context of data availabil- ity, consistency, and recovery. It is vital to differentiate their usage, limitation, and challenges to utilize them for a resilient data center.7 By definition, Data Backup is the process of copying data (files/databases) into other data storage to be retrieved when needed in case of device failure. It is considered a regular process of system management and usually done overnight, which means a full working day’s data may be lost in case of a device failure. For critical applications, this amount of lost data is unacceptable.8
Data Replication is the act of increasing the num- ber of database servers which are available for clients, mainly for load balancing. Data replication can be done within or off the facility. For speedy recovery and critical data application, Data Mirroring is manda- tory. Data mirroring is the copying of data from one location to a storage device or different location in real time. It is always a good idea to have the mirroring site a safe distance from the main site.9
For resilient data centers, in addition to data rep- lication, data mirroring is mandatory. Data mirroring can be implemented as synchronous or asynchronous. In the case of synchronous mirroring, each transaction is sent to the mirror site and the clients do not get a re- sponse until the main site gets acknowledgment from the mirror site as shown in Figure 8.6. This approach
193
affects the system performance and increases service response time.
Figure 8.6. Synchronous Data Mirroring Process.
Also, data mirroring can be implemented as asyn- chronous where the main site receives the client’s request, processes it, responds to the client, and then sends updates to the mirror site as shown in Figure 8.7. In this case, the mirror site will be a few transac- tions behind; but the system performance will not be affected.
194
Figure 8.7. Asynchronous Data Mirroring Process.
Many database mirroring technologies are avail- able on the market which require detailed investiga- tion for the following aspects to simplify selection processes:
1. Supported Platforms: Multiple platforms pro- vide more flexibility for data centers.
2. Change Check Capability: Current tools focus on only the net data change after the last mirroring process occurrence.
3. Computability Issues: Most of the current tools work as “plug-in” with no change required for data- base scheme and support several network topologies (server-server, hub-and-spokes).
4. Public Networks: New challenges for mirroring tools are raised when data are transmitted over public networks. These include: data security, TCP/IP vul- nerability, and firewalls.
195
5. Scalability: Adding/removing sites is always needed regardless of how easy the reconfiguration process is.
For resilient data center systems, remote sites are mandatory which infuses the need for powerful mir- roring tools over public networks/Internet where a “hand-shaking” process requires more effort. Also sequential data block transmission is not appropri- ate because of the public network/Internet nature. IBM Global Mirroring employs flash copy technol- ogy which permits data blocks to be partitioned into smaller portions by sending them to the mirror site, reassembling it, and writing it to the database.
Mirroring time is the time required to mirror data to the remote site while pause time is where the mir- roring tool is inactive. For many mirroring tools, those parameters can be controlled either by direct or in- direct ways. Figure 8.8 illustrates two scenarios that show how critical the tuning of those parameters can be in combination with the detection time of malicious activities for system resilience.
Figure 8.8. Data Mirroring Parameters and Attack Scenarios.
196
In scenario A, data mirroring parameters worked together with malicious activities detection time to ensure that the data sent to the mirror site were er- ror free, while in scenario B the parameters were not correctly tuned, which resulted in sending malicious data to the mirror site. Mirroring corrupted data to the recovery site ruins the objectives of the recovery site and system resilience.
Network Connectivity Alternatives.
Network connectivity represents a significant por- tion of data center architecture, for Interconnection, Data Storage, Mirroring, and Public Access as shown in Figure 8.9. Also, computer network subelements (topologies, links, connecting devices, routing proto- cols and load balancing) are very critical aspects of computer network performance and resilience level.10
Figure 8.9. Data Center Network Roles Summary.
Resilience, Redundancy, and Fault Tolerance are widely used terms within computer network assess- ment and design context. For decades network de- signers and analysts used redundancy to improve network availability and reliability. It is essential to define each term. Redundancy is the process of install- ing extra equipment to overcome any node failure.
197
It requires having a plan and tools to direct traffic through the replacement node, thus redundancy can- not enhance network resilience by itself. The main idea of Fault Tolerance is to recognize how a node or device can fail and therefore take the necessary steps to prevent the failure. The definition of Resilience is the ability of a system to maintain any disturbance with minimum change on performance efficiency, and to effect a speedy recovery from any disturbance.
For critical applications and legacy systems, con- nectivity failure is an extremely hazardous situation because it revokes system integrity and operational continuity. In addition, the nature of connectivity fail- ures is different than other computer system failures in the following aspects:
1. Detection: In some cases it is a complicated pro- cess. For instance, chronic failure detection is harder than sudden (crash) failure detection.
2. Cascading Nature: A simple failure can affect a large number of services or clients. In addition, this simple failure can overload other parts of the network, causing the system to crash resulting in more harm.
3. Origin: The same failure can be originated by many factors, for example, a node failure can be caused by power outage, software failure, or mali- cious activities.
Network resilience assessment comprises two main aspects:
1. Alternatives: It is very critical to have alterna- tives for network elements which are not limited only to redundant equipment but also include alternative traffic routing paths. The alternative paths must be reserved only for major failures and ensure approxi- mately the same cost of original route in terms of laten-
198
cy and response time without causing other network parts failures.
2. Recovery Tools: Redundancy is mandatory for resilience, in addition to tools to employ those devices in timely manner; routing protocols (RP) and load balancing algorithms (LBA) are fundamental tools to ensure network resilience. The ability of RP to utilize alternative routing paths with minimum converging time is essential for a resilient network. The ability of LBA to detect failed/recovered servers in a minimum amount of time is a critical issue for network resilience.
Consider the following scenario; a system that is using LBA with less than optimal parameter tuning as shown in Figure 8.10. In the first case traffic is sent to the server while it is down, in the second case no traffic is sent to server after recovery. In both cases it offers poor resilience level for server failure and re- covery.11
Figure 8.10. Load Balancing with a Poor Parameters Tuning Scenario.
199
One of the vital parameter routing protocols chal- lenged by multiple failures of network parts, is the route cost. Consider traffic sent from point A to point B; assuming that main route R1=(x1, x2, x7) and the al- ternatives routes are R2=(x4, x5, x6) and R3=(x4, x3, x7) as shown in Figure 8.11. It is clear that x4 is common for both alternative routes which is not conventional particularly in the case of an x4 failure. Also alterna- tive routing costs might lead to an overload of certain parts of the network causing even more failures.
Figure 8.11. Routing Protocols Concerns Summary.
Security Challenges and Opportunities.
The fact that the data center is the core of any legacy system and it hosts large critical data volumes make it a target for all type of attacks, physical or cyber. Sur- veillance cam, high-tech doors, and other technologies improve the data center’s physical security. However, on the other hand, data center cyber security is a much more challenging process.12
Potential network Vulnerabilities, Threats, and At- tacks must be identified to minimize security concerns. System Vulnerabilities refer to weaknesses in the system that can be attacked, while Threats are the potential to cause damage to data center resources. Attacks are the
200
actual use of system Vulnerability to put Threats into action. System hacking is a continuous process where hackers continue to discover system vulnerabilities to develop attacks as depicted in Figure 8.12.
Figure 8.12. Developing Attacks Process.
Enumerating all possible data center vulnerabili- ties, threats, and attacks in an exact list is not feasible, yet they can be categorized as Table 8.2 shows.
201
Table 8.2. Vulnerabilities, Threats, and Attacks Categories Summary.
Even as the hacker is working hard to elude data center security, data center designers, venders, and security teams are working just as hard to ensure data center safety and security. Their efforts have produced many technologies such as firewalls, intrusion detec- tion and prevention tools, DoS and DDoS detection and mitigation, access lists, and access restriction.
Data center security has three layers: (1) networks, (2) applications, and (3) databases. Figure 8.13 dem- onstrates the security mechanisms that are currently available.
Vulnerabilities Threats Attacks
Designing Intrusion Denial of Service (DoS) and Distributed DoS (DDoS)
Technologies Spam Un-authorized Access
Applications Worm Information Tampering
Database Virus Cross-site Scripting
Networks Malware IP Spoofing
Monitoring tools Spyware Insider Malicious Activities
202
Figure 8.13. Security Layers Summary.
Security evaluation is done for different purposes: 1. Products, organization, application accredita-
tion. 2. For the development and enhancement of secu-
rity policies, methodologies, and technologies.
Researchers and system developers focus on the second perspective: Legacy system security assess- ment is a very complex process for many reasons:
• Data Characteristics: Each data type is targeted by certain hackers and attacks, as in the case of financial, military, and industrial data.
• Data Status: Data that is in an Operation mode is harder to protect, while data in a Rest mode requires less effort.
• System Design: Used for utilities, manufactur- ing companies. These systems will have two networks: business and control. This type of design increases system vulnerabilities and re- quires special arrangements to ensure network isolation.
203
For a resilient data center, security technologies and methodologies are expected to guarantee system functionality, information assurance, events manage- ment, and correlations. Consequently, security poli- cies must ensure a speedy detection process and the ability to utilize system resources to mitigate attack effects.
CONCLUSION
The assessment process of cyber infrastructure se- curity requires a number of metrics including perfor- mance, availability, and reliability. The rapid growth of data volumes, increased complexity of cyber infra- structure, and the heightened levels of threat highlight the gap in existing evaluation metrics. Increased aware- ness for a proactive approach addressing resilience in various systems including data centers demands a new evaluation approach. Resilience measurement of alternative data center designs assesses their ability to face man-made and natural disasters. Data center subsystems must be considered for a comprehensive resilience evaluation in addition to recovery plans and policies. The proposed resilience metric is proac- tive and assesses system behavior before, during, and after an attack.
204
ENDNOTES - CHAPTER 8
1. Mauricio Arregoces and Maurizio Portolani, Data Center Fundamentals, Cisco Press, 2004, available from www.cisco.com/ web/about/ac123/ac220/about_cisco_cisco_press_book_series.html.
2. Ibid.
3. Kehia H. Khalil, Anup Kumar, and Adel Elmaghraby, “De- sign Considerations for Resilient Distributed Data Centers,” ISCA 20th International Conference on Parallel and Distributed Com- puting Systems (PDCS), 2007, pp. 51-55.
4. The definition of resilience is available from www.merriam- webster.com/.
5. Richard L. Villars, “IBM Total Storage Software: Building Storage Solutions in Alignment with Current and Future Business Requirement,” White paper sponsored by IBM, 2004.
6. Gary Orenstein, IP Storage Networking: Straight to the Core, A d d i s o n - W e s l e y , 2 0 0 3 , a v a i l a b l e f r o m www.pearsoned.co.uk/imprints/addison-wesley/.
7. Jim´Enez-Peris, R. Pati, M. ˜No-Mart´Inez, G. Alonso, and B. Kemme, How to Select a Replication Protocol According to Scal- ability, Availability, and Communication Overhead, The International Symposium on Reliable Distributed Systems (SRDS), New Or- leans, LA: IEEE Computer Society Press, 2001, pp. 24–33.
8. Wang Changxu and Xu Rongsheng, “Analysis and Re- search of Data Backup System in Corporation,” Computer Applica- tions and Software, Vol. 25, No. 10, 2008, pp. 121–123.
9. M. Wiesmann, F. Pedone, A. Schiper, B. Kemme, and G. Alonso, “Understanding Replication in Databases and Distrib- uted Systems,” the 20th International Conference on Distributed Computing Systems, 2000, pp. 464-486.
205
10. Alberto Leon-Garcia, and Indra Widjaja, Communication Networks: Fundamental Concepts and Key Architectures, New York: McGraw-Hill Professional, 2004.
11. Yehia H. Khalil and Adel Elmaghraby, “Evaluating Serv- er Load Balancing Algorithms For Data Center’s Resilience En- hancement,” New Orleans, LA: ISCA 21st International Confer- ence on Parallel and Distributed Computing and Communication Systems, September 2008, pp. 111-116.
12. Merrill Warkentin and Rayford Vaughn, “Enterprise In- formation Systems Assurance and System Security: Manage- rial and Technical Issues,” Idea Group Pub., 2006, available from www.igi-global.com/.
13. Shoukat Ali, Anthony A. Maciejewski, Howard Jay Siegel, and Jong-Kook Kim, “Measuring the Robustness of a Resource Al- location,” Transactions on Parallel And Distributed Systems, 2004, Vol. 15, No. 7, New York: IEEE, pp. 630-641.
14. R. Jain, The Art of Computer Systems Performance Analysis, New York: John Wiley & Sons, 1991.
15. Denis Trček, Managing Information Systems Security and Privacy, Basel, Switzerland: Birkhäuser, 2006.
16. M. Castro, P. Druschel, A.-M. Kermarrec, and A. Row- stron, “A Large-scale and Decentralized Application-level Mul- ticast Infrastructure,” Journal on Selected Areas in Communication (JSAC), 2002, New York: IEEE, pp. 20-27.
17. Albert Greenberg, Parantap Lahiri, David A. Maltz, Parveen Patel, and Sudipta Sengupta, “Towards a Next Genera- tion Data Center Architecture: Scalability and Commoditization,” ACM workshop on programmable routers for extensible services of tomorrow, Seattle, WA, 2008, pp. 57-62.
207
CHAPTER 9
DEVELOPING HIGH FIDELITY SENSORS FOR INTRUSION ACTIVITY
ON ENTERPRISE NETWORKS
Edward Wagner and Anup K. Ghosh
INTRODUCTION
Future success in cyber will require flexible secu- rity, which can respond to the dynamic nature of cur- rent and future threats. Much of our current defenses are based upon fixed defenses that attempt to protect internal assets against external threats. Appliances like firewalls and proxies positioned at network seg- ment perimeters similar to the Maginot Line attempt to prevent outsiders from breaking in. There are other mechanisms such as Public Key Infrastructure and antivirus software, which also provide security. This added layer is referred to as a “Defense in Depth” methodology. However, in each component of our security architecture vulnerabilities are revealed over time. These defenses lack any agility. Our defenses must become agile and responsive.
In large-scale enterprise network defense, intru- sions are detected by monitoring network flows from untrusted sources. Primarily, network intrusion detec- tion systems examine traffic at Internet gateways, and then again at individual enterprise units or at enclave routers. Intrusions detected at lower organizational structures are detected then reported to higher report- ing entities. The current approach to detecting intru- sions suffers from two main problems: (1) intrusion
208
sensors are placed in locations that do not allow high fidelity examination of intrusion behavior; and (2) intrusions are detected by comparing network traffic to known malicious intrusion patterns. In this chap- ter, we propose a supplemental method to correct for these two deficiencies. We propose high fidelity sen- sors in the form of virtualized applications on each user’s machine to complement network-based sen- sors. In addition, we equip each user such that even as they are reporting intrusions, their machine and data is protected from the intrusions they are reporting. Our approach will protect users from broad classes of malicious code attacks, while being able to detect and report both known and unknown attack code.
One of the core strengths of our approach is that most attacks are realized at the endpoint. Attack code is often embedded and obfuscated in network traffic that often flies by network sensors unnoticed. When reaching a vulnerable host, the code is executed. Our contention is that the endpoint (host) is the best place to detect most attack codes because it is at this point that the behavior of the attack codes can be observed. Of course, once the attack code runs, it poses a high potential risk to the host and network, so we virtualize networked applications to protect the host from the attack code.
The user operating environment can remain on the existing infrastructure, but operate in a virtual workspace. Bringing virtual computing to the host will allow compartmentalization of the environment, wherein untrusted applications or applications that run untrusted content are partitioned from the trusted host itself. If the untrusted application environment is compromised, the underlying host will remain un- compromised. We also leverage sensor technology in
209
the virtualized environment to detect illicit changes and then report these to a database. The environment is then “refreshed” removing any persistent presence of a threat. The environment can be configured and updated frequently, then copied and distributed en mass. Since the provisioning of the virtual environ- ment is done centrally, changes to the environment can be easily identified and captured.
This new environment becomes agile and dynam- ic. It regains the initiative that the threat has taken and retained for over a decade. Malware can be stamped and collected as it appears. Malicious or compromised websites can be identified and blocked if desired, or monitored for intelligence purposes.
CURRENT ISSUES
According to the Center for Strategic and Interna- tional Studies report on Cybersecurity prepared for President Barack Obama, potential adversaries have compromised and penetrated computer networks in the United States. These perpetrators have accessed and retrieved large quantities of information. In 2007, the compromises included the unclassified e-mail ac- count of the Secretary of Defense and the exfiltration of terabytes of data from the Department of State. The report says that the loss of government data and intel- lectual property threatens our economic and national security.1
Given this threat environment, there are signifi- cant efforts to monitor networks. The current array of Intrusion Detection Systems (IDS) and Intrusion Pre- vention Systems (IPS) are dependant on the continual development of signatures to find threats operating within the network. IDS are devices that monitor net-
210
work segments with a set of signatures to match ne- farious activity. An alert is created when a match is found. Analysts monitoring these systems must make a subjective decision whether or not to investigate the alert. Even if the information is correlated with other security devices such as firewall alerts in an Enterprise Security Management tool, the assessment of risk is imprecise. The IPS is different because it will drop the packets of the related session when the signatures match. The dropping of packets is the equivalent of disrupting the attack. This prevents the attack from being successful. While there has been continuous in- novation to improve the ability to identify threat activ- ity, this capability is limited by the signature’s ability to know the method of attack.
The use of antivirus suffers from the same inherent limitations of a signature-based system. The volume of malware is frequently described as an antivirus prob- lem but, in fact it affects the entire system. According to multiple reports released in the beginning of 2008, the number of unique malware files is increasing at an alarming rate. One study said it found almost 5.5 mil- lion unique files, up from approximately 973,000 in the previous year.2 The development of signatures cannot keep pace in a timely manner, neither can the ability to distribute, store, and analyze files on client hosts from these large databases. Thus, signature-based antivirus suffers from the temporal dynamics of rate of change of malware, the broad proliferation of malware, and the scalability of the distribution and storage of anti- virus signatures. Attacks will frequently elicit the as- sistance of users through an e-mail directing them to a website with malware. At other times, legitimate websites are unknowingly compromised. One study of 145,000 commonly visited Chinese websites found 2,149, or 1.49 percent, had malicious content.”3
211
The development of signatures requires the invest- ment of resources to analyze attacks to understand the tactics, techniques, and procedures and then develop corresponding signatures. The cycle typically begins with actors identifying vulnerabilities, it next moves to the development of exploit code where defenders are continually seeking the formulation of mitigation strategies to prevent attacks.
There are huge resources poured into the discov- ery of vulnerabilities. Those who seek information on vulnerabilities are both network attackers and de- fenders alike. Sutton and Nagle describe the emerging economic market of identifying vulnerabilities in their paper to the Workshop on Economics of Information Security, 2006 titled: “iDefense gains revenue by di- rectly reselling the information, while TippingPoint profits by offering exclusive protection against the vulnerabilities they purchase via their intrusion de- tection system (IDS) product.”4 Frequently, observers focus on the price paid as a result of cyber attacks, but few recognize the transactions occurring to develop signatures and other network defense measures ver- sus the effort to exploit them.
Large organizations spend considerable resources to maintain their IDS/IPS infrastructure and the cor- responding signature base. Smaller organizations fre- quently outsource some of the effort through signature subscription services. In order to support the develop- ment of signatures, there is a heavy dependence on analytical work to find anomalies, collect malware, reverse engineer them, and finally develop signatures.
Companies that provide this service do so in two ways. Some companies provide a fee for service. They rely on their own collection infrastructure to collect malware traversing the Internet. They may use a net- work of “honeypots” to collect the malware. Once
212
collected they analyze the malware and develop a signature. These signatures and the associated threat warnings are then provided to their customers.
Other companies provide analytical support di- rectly to organizations and rely on the collection infra- structure of the supported organization. Many organi- zations object to completely outsourcing their security services due to information disclosure concerns. The Department of Defense follows this example. The col- lection of information and resulting analysis is com- plex and laborious. Colonel Barry Hensley, Director of the Army Global Network Operations Security Center, described the growing demand for forensic analysis at the Army LandWarNet conference in 2008. He said, “People don’t realize the forensics handling process involved with identifying malicious code. . . . It can take weeks or months.”5
Consumers of signature support and services finds it difficult to measure the effectiveness of their pur- chase. There are many key questions for example: How many attacks were never detected because a sig- nature was never developed? Were any of the signa- tures ignored by a poorly trained IDS analyst?
Victor Oppleman, Oliver Friedrichs, and Brett Watson further describe the breadth and width of the problem with IDS/IPS in Extreme Exploits: Advanced Defenses Against Hardcore Hacks. They identify three significant reasons for the problem: (1) “The granular- ity of the signature syntax,” (2) “Whether the signature detects a specific exploitation of a vulnerability or the core vulnerability itself,” and (3) “The author of the signature and the protocol knowledge he possesses.”6
Some signatures are more effective than others. Some signatures will alert to real threats as well as other traffic, which is not actually an attack. Frequently this
213
is referred to as a false positive rate. A more granular signature can frequently address this problem. Some signatures are written based on known exploit code, but there may be other exploit codes that attack the same vulnerability, but do not alert the same signa- ture. Finally, the effectiveness of a signature can be a reflection of the skill and knowledge of its author.
The problems with IDS/IPS do not simply stem from the development and deployment of effective signatures. Potential attackers are constantly look- ing for ways to avoid detection. In “Insertion, Eva- sion, and Denial of Service: Eluding Network Intru- sion Detection,” Ptacek and Newsham provide three examples of how threats will attempt to elude IDS at the network (IP) and transport (TCP) layer. The three examples are “IP Checksum, IP TTL, and IP Fragmen- tation.”7
In the IP Checksum example, the method data is verified when it travels across the Internet and can be manipulated to confuse an IDS/IPS. If the IDS/IPS does not conduct a checksum validation, it will accept data in an invalid packet, which would normally be dropped. This may result in fake data being used to throw off packet inspection.
The second method is when an IDS/IPS accepts a packet with an invalid Time-To-Live (TTL) value in the IP header. Normally the endpoint would drop the packets with an invalid value; however, the IDS/IPS placed at various points in the architecture may accept packets with an invalid value. The result is the com- plication of the data inspection process.
The third example of obfuscation is IP Fragmenta- tion. Threats can cause an IDS/IPS to accept inserted or crafted fragmentation packets for inspection that would normally be discarded by the endpoint. In each of these examples, the threat is adding packets for
214
inspection that are used to confuse the inspection of other packets used in an attack.
These examples are just three ways that threats can avoid detection by signature-based IDS/IPSs. There are many more, and the number of attack techniques are only limited by the imagination of the attacker. The limitations of signature-based IDS/IPSs described thus far do not consider the evolutionary nature of the attack themselves. The shift from targeting hosts with exploit codes to targeting users with phishing e-mails highlights the difficulty in detecting attacks.8 The attacker may target individual users or large groups of users with malware attached to an e-mail message. The malware can compromise the host and initiate a communication request to an external host controlled by the attacker. This reverses the attack sequence that IDS/IPSs look for when an external host attacks an internal host.
If an attacker establishes an encrypted connection between his jump off point and the compromised friendly host, the traffic is never assessed. IDS and IPSs are not able to decrypt such traffic, no signature will cause an alert and the analyst is never able to as- sess the connection.
THE VIRTUAL ENVIRONMENT
Using the innovation of the Internet Cleanroom, developed previously at GMU,9 the user can operate in a virtualized environment. This provides the first level of protection by isolating the user from the underlying host. Tools to monitor and collect information about threats operate in the separate host operating system (OS), which provides integrity to the collection of threat information. In signature based monitoring ef- forts, the volume of data is enormous and unmanage-
215
able. Since the virtual environment presents a known good, changes from that state can easily be identified and logged. This reduces the volume of monitoring data.
Figure 9.1 displays the architecture of the Internet Cleanroom. It shows the separation of OSs, which is the basis for the reliability of collected data. It also shows the ability to compartmentalize the user’s environment.
Figure 9.1. Internet Cleanroom Architecture.10
The collection architecture that is possible in this environment is displayed in Figure 9.2. Segmentation of the collection mechanism and user environments is achieved through the use of virtualization. Another benefit to collecting compromised URLs at the host is the easy identification of the host involved in the in- cident. Currently, the collection of data occurs at the network perimeter. The Domain Name Service (DNS) architecture begins below the collection point and the volume of name resolution prevents logging, there- fore many hosts visiting known compromised web- sites cannot be identified. Even if the URL is identified and blocked a host possessing malware may operate on the network indefinitely without remediation.
216
Figure 9.2. Collection Architecture.
The Internet Cleanroom is best deployed to coin- cide with an existing security architecture as shown in Figure 9.3. To maximize protection, monitoring at the enclave access points should continue. As noted before, the use of traditional IDS/IPS tools remain limited in their ability to detect new and sophisticated threats. Alternatives like extensive review of router logs and netflow can be very helpful. The integration of the Internet Cleanroom into the Security Informa- tion Manager architecture allows the correlation of host data from the Internet Cleanroom with network alerts from IDS/IPS. The combination of these two technologies brings more accurate alerts to the SIM analyst. In the past, information security professionals have desired to have access to full packet capture and host logs in near real time. However, the data stor- age requirements outweighed the usefulness of the
Browser
BHO
Capture Client
Guest OS
Canary Server
Host OS Analysis Engine
217
data. Additionally, it overwhelms the analyst with too much data to review. The Internet Cleanroom’s abil- ity to gather specific information about threats as it is integrated into a SIM enables greater responsiveness for network defense.
Figure 9.3. Security Architecture.
Making Granular Data Capture Meaningful.
The Internet Cleanroom addresses the capture problem by logging change data. Since the host is pro- visioned in a VM Client, changes can be easily logged and sent to a SIM via a syslog. Though the number of host remains large, smart data capture makes this type of collection feasible.
Figure 9.4 shows the analyst’s view of summary information for hosts including infections that were downloaded and infected websites. The infected web- sites information provides actionable information in a more timely manner. This information can be pro- vided immediately to any program to block access to those websites.
218
Figure 9.4. Analyst’s Report View.
While the bad URLs remain of interest, the MD5 Hash of any malware downloaded by the host is of great interest to the defenders of the network. To gather this information typically requires a forensic collection on an individual host. This is a manual and time intensive process. However, much of this collec- tion can now be automated in the Internet Cleanroom.
As noted in Figure 9.5, the Internet Cleanroom is able to automate the collection of MD5 Hash of mal- ware and that information is immediately available to the analyst. Instead of the lengthy analysis of forensic media to collect this information, it can be obtained as it happens. If shared with scanning tools, which search for malware by MD5 Hash, network defend- ers can be more responsive in their ability to identify infected hosts.
219
Figure 9.5. MD5 Hash of Malware.
The discovery of malware in near real time can as- sist in the recognition of new threat trends. Adjust- ments to perimeter defenses can be made before the loss of the initiative. This type of dynamic defense changes the static intransient defense that has been unable to respond in time to developing threats.
220
CONCLUSIONS
Current defenses largely rely on signature-based mechanisms in the network or on the host to detect attacks. These techniques have become largely ineffec- tive as the proliferation of malicious software shows. The primary reason for their ineffectiveness is because malware changes its signatures faster than the mecha- nisms have been developed to capture malware, and then create and distribute those signatures. In addi- tion, we argue that network-based sensors are not adequate for detecting threats against networks. To address these deficiencies, we propose that the enter- prise computer network defense architecture should include a virtualized application solution that: (a) protects users from unknown future infections (sig- nature-free defenses), and (b) provides detecting and reporting of unauthorized system changes to a collec- tion database.
The most obvious example of our proposed ap- proach is a virtualized browser that users employ just as they use their native browser. The proposed virtu- alized browser, Internet Cleanroom, protects the user from malicious web content, while also monitoring the virtual OS for any unauthorized changes that may occur as a result of browsing. The virtualized archi- tecture effectively partitions untrusted applications and content from the underlying operating system and other applications. Any unauthorized changes are noted, then the virtual OS is discarded, and a pristine environment restored, all without any virtualization expertise required. The proposed approach provides high-fidelity detection of malicious code threats that can be later analyzed in forensic detail, while also pro- tecting the user from currently unknown threats.
221
ENDNOTES - CHAPTER 9
1. Co-Chairs, Representative James R. Langevin, Represen- tative Michael T. McCaul, Scott Charney, Lieutenant General (USAF, Ret.) Harry Raduege, and Project Director James A. Lewis, “Securing Cyberspace for the 44th Presidency,” Washington, DC: Center for Strategic and International Studies, December 2008.
2. T. Wilson, “Malware Quietly Reaching Epidemic Levels: New Reports Say Malware Increased by a Factor of Five to 10 in 2007,” Dark Reading, January 16, 2008, available from www.darkreading. com/security/vulnerabilities/showArticle.jhtml?articleID=208803810.
3. Jianwei Zhuge, Thorsten Holz, Chengyu Song, Jinpeng Guo, Xinhui Han, and Wei Zou, “Studying Malicious Websites and the Underground Economy on the Chinese Web,” Workshop on the Economics of Information Security, WEIS, 2008, available from weis2008.econinfosec.org/papers/Holz.pdf.
4. Michael Sutton and Frank Nagle, “Emerging Economic Models for Vulnerability Research,” Workshop on the Econom- ics of Information Security, WEIS, 2006, available from weis2006. econinfosec.org/docs/17.pdf.
5. Wyatt Kash, “Army cyber ops faces forensic backlog,” Gov- ernment Computer News (GCN), August 20, 2008, available from www.gcn.com/online/vol1_no1/46946-1.html.
6. Victor Oppleman, Oliver Friedrichs, and Brett Watson, “Chapter 7, Intrusion Detection and Prevention,” Extreme Ex- ploits: Advanced Defenses Against Hardcore Hacks, Emeryville, CA: McGraw-Hill/Osborne, 2005, available from common.books24x7. com/book/id_11979/book.asp.
7. Thomas H. Ptacek and Timothy N. Newsham, “Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detec- tion,” available from insecure.org/stf/secnet_ids/secnet_ids.html.
8. “Chapter XII, Deception in Cyber Attacks,” in Lech J. Janc- zewski and Andrew M. Colarik, eds., Cyber Warfare and Cyber Terrorism, Hershey, PA: IGI Publishing, 2008, available from common.books24x7.com/book/id_20791/book.asp.
222
9. Wang Jiang, Anup K. Ghosh, and Huang Yih, “Internet Cleanroom: A System to Use On-Demand Virtualization to En- hance Client-Side Security,” Washington, DC: Center for Secure Information Systems (CSIS), George Mason University, June 6, 2008.
10. Wang Jiang, Anup K. Ghosh, and Huang Yih, “Web Ca- naries: a Large-scale Distributed Sensor for Detecting Malicious Web Sites via a Virtualized Web Browser,” Washington, DC: Cen- ter for Secure Information Systems (CSIS), George Mason Univer- sity, November 2008, p. 6, available from CollaborateCom.org/2008/ program.php.
223
CHAPTER 10
VOICE OVER IP: RISKS, THREATS, AND VULNERABILITIES*
Angelos D. Keromytis
INTRODUCTION
Voice over Internet Protocol (VoIP) and Internet Multimedia Subsystem (IMS) technologies are rapidly being adopted by consumers, enterprises, govern- ments, and militaries. These technologies offer higher flexibility and more features than the traditional pub- lic-switched telephone network (PSTN) infrastruc- ture, as well as the potential for lower cost through equipment consolidation and, for the consumer mar- ket, new business models. However, VoIP/IMS sys- tems also represent a higher complexity in terms of architecture, protocols, and implementation, with a corresponding increase in the potential for misuse. Here, we begin to examine the current state of affairs on VoIP/IMS security through a survey of known/ disclosed security vulnerabilities in bug-tracking da- tabases. This chapter should serve as a starting point for understanding the threats and risks in a rapidly evolving set of technologies that are more frequently being deployed and used. Our goal is to gain a better understanding of the security landscape, with respect to VOIP/IMS, to encourage future research toward this and other similar emerging technologies.
The rate at which new technologies are being in- troduced and adopted by society has been steadily ____________
*This work was supported by the French National Research Agency (ANR) under Contract ANR-08-VERS-017.
224
accelerating throughout human history. The advent of pervasive computing and telecommunications has reinforced this trend. In this environment of constant innovation, individuals, governments, and organiza- tions have been struggling to manage the tension be- tween reaping the benefits of new technologies while understanding and managing their risks. In this strug- gle, cost reductions, convenience, and new features typically overcome security concerns. As a result, security experts (but also the government and courts of law) are often left with the task of playing “catch up” with those who exploit flaws to further their own goals. This is the situation we find ourselves in with respect to one popular class of technologies collective- ly referred to as VoIP. VoIP, sometimes also referred to as Internet Multimedia Subsystem (IMS), refers to a class of products that enable advanced communica- tion services over data networks. While voice is a key aspect in such products, video and other capabilities (e.g., collaborative editing, whiteboard file sharing, and calendaring) are all supported. The key advan- tages of VoIP/IMS are flexibility and low cost. The former derives from the generally open architectures and software-based implementation, while the latter is due to new business models, equipment, network- link consolidation, and ubiquitous consumer-grade broadband connectivity. Due to these benefits, VoIP has experienced a rapid uptake in both the enterprise and consumer markets. An increasing number of en- terprises are replacing their internal phone switches with VoIP-based systems, both to introduce new fea- tures and to eliminate redundant equipment. Con- sumers have embraced a host of technologies with dif- ferent features and costs, including Peer to Peer (P2P) calling, Internet-to-phone network bridging, and
225
wireless VoIP. These new technologies and business models are being promoted by a new generation of startup companies that are challenging the traditional status quo in telephony and personal telecommunica- tions. As a result, a number of PSTN providers have already completed or are in the process of transition- ing from circuit-switched networks to VoIP-friendly packet-switched backbones. Finally, as the commer- cial and consumer sectors go, so do governments and militaries due to cost reduction concerns and the gen- eral dependence on Commercial-off-the-Shelf (COTS) equipment for the majority of their computing needs. However, higher complexity is often the price we pay for more flexibility. In the case of VoIP/IMS technolo- gies, a number of factors contribute to architectural, protocol, implementation, and operational complexity.
The number and complexity of the various features integrated in a product are perhaps the single largest source of complexity. For example, voice and video transmission typically allow for a variety of codecs which may be used in almost-arbitrary combinations. Since one of the biggest selling points for VoIP/IMS is feature-richness and the desire to unify personal com- munications under the same umbrella, this is a par- ticularly pertinent concern.
Openness and modularity, generally considered desirable traits, allow for a number of independent implementations and products. Each of these comes with its own parameters and design choices. Interop- erability concerns and customer feedback then lead to an ever-growing baseline of supported features for all products. A compounding factor to increasing com- plexity for much of the open VoIP is the “design-by- committee” syndrome, which typically leads to larger, more inclusive specifications than would otherwise
226
be the case (e.g., in a closed, proprietary environment such as the wire line telephony network from 20 years ago).
Because VoIP systems are envisioned to operate in a variety of environments, business settings, and network conditions, they must offer considerable configurability, which in turn leads to high complex- ity. Of particular concern are unforeseen feature in- teractions and other emergent properties. Finally, VoIPs are generally meant to work over a public data network (e.g., the Internet), or an enterprise/operator network that uses the same underlying technology. As a result, there is a substantial amount of non-VoIP infrastructure that is critical for the correct operation of the system, including such protocols/services as Dynamic Host Configuration Protocol (DHCP),1 Do- main Name System (DNS),2 Trivial File Transfer Pro- tocol/Bootstrap Protocol (TFTP/BOOTP),3 Network Address Translation ([NAT],4 and NAT traversal pro- tocols such as Simple Traversal of UDP through NATs [STUN]),5 Network Time Protocol (NTP),6 Simple Network Management Protocol (SNMP),7 routing the web (HTTP,8 LS/SSL,9 etc.), and many others. As we shall see, even a “perfectly secure” VoIP system can be compromised by subverting elements of this infra- structure. Because of this complexity, which manifests itself both in terms of configuration options and size of the code base for VoIP implementations, VoIP sys- tems represent a very large attack surface. Thus, one should expect to encounter, over time, security prob- lems arising from design flaws (e.g., exploitable proto- col weaknesses), undesirable feature interactions (e.g., combinations of components that make new attacks possible or existing/known attacks easier), unfore- seen dependencies (e.g., compromise paths through
227
seemingly unrelated protocols), weak configurations, and, not least, implementation flaws. In this chapter, we attempt a first effort at mapping out the space of VoIP threats and risks by conducting a survey of the “actually seen” vulnerabilities and attacks, as reported by the popular press and by bug-tracking databases. Our work is by necessity evolutionary in nature, and this chapter represents a current (and limited) snap- shot of the complete space. Nonetheless, we believe that it will serve as a valuable starting point for under- standing the bigger problem and as a basis for a more comprehensive analysis in the future.
Chapter Organization.
The remainder of this chapter is organized as fol- lows. The second section contains a brief over view of two major VoIP technologies, Session Initiation Proto- col (SIP) and Unlicensed Mobile Access (UMA). While we refer to other VoIP/IMS systems throughout the discussion, we focus on the specific two technologies as they are representative, widely used, and well-doc- umented. We discuss VoIP threats in the third section, placing known attacks against VoIP systems within the taxonomy proposed by the VoIP Security Alli- ance. We analyze our findings in the fourth section. In the final section, we conclude with some preliminary thoughts on the current state of VoIP security, and on possible future directions for security research and practices.
228
VOIP TECHNOLOGIES OVERVIEW
In their simplest form, VoIP technologies enable two (or more) devices to transmit and receive real- time audio traffic that allows their respective users to communicate. In general, VoIP architectures are parti- tioned in two main components: signaling and media transfer. Signaling covers both abstract notions, such as endpoint naming and addressing, and concrete protocol functions such as parameter negotiation, ac- cess control, billing, proxying, and NAT traversal.
Depending on the architecture, quality of service (QoS) and device configuration/management may also be part of the signaling protocol (or protocol family). The media transfer aspect of VoIP systems generally includes a comparatively simpler protocol for encapsulating data, with support for multiple co- decs and (often, but not always) content security. A commonly used media transfer protocol is Real-time Transport Protocol (RTP),10 with a version supporting encryption and integrity, Secure Real-time Transport Protocol (SRTP),11 defined but not yet widely used. The RTP protocol family also includes RTP Control Protocol (RTCP), which is used to control certain RTP parameters between communicating endpoints. However, a variety of other features are also gener- ally desired by users and offered by providers as a means for differentiation by competing technologies and services, such as video, integration with calendar- ing, file sharing, and bridging to other networks (e.g., to the “regular” telephony network). Furthermore, a number of different decisions may be made when designing a VoIP system, reflecting different require- ments and approaches to addressing, billing, mobil- ity, security and access control, usability, and other
229
issues. Consequently, there exists a variety of differ- ent VoIP/IP Multimedia Subsystem (IMS) protocols and architectures. For concreteness, we will focus our attention on a popular and widely deployed technol- ogy: the Session Initiation Protocol (SIP).12 We will also discuss the UMA architecture,13 as a different ap- proach to VoIP that is gaining traction among wireless telephony operators. In the rest of this section, we give a high-level overview of SIP and UMA, followed by a brief description of the salient points of a few other popular VoIP systems, such as H.323 and Skype. We will refer back to this overview in the third section of this chapter when we provide a discussion of the the threat and specific vulnerabilities.
Session Initiation Protocol (SIP).
SIP is a protocol standardized by the Internet Engi- neering Task Force (IETF) and is designed to support the setup of bidirectional communication sessions in- cluding, but not limited to, VoIP calls. It is similar in some ways to HTTP in that it is text-based, has a re- quest-response structure, and even uses a mechanism based on the HTTP Digest Authentication14 for user authentication. However, it is an inherently stateful protocol that supports interaction with multiple net- work components (e.g., middle boxes such as PSTN bridges). While its finite state machine is seemingly simple, in practice it has become quite large and com- plicated, an observation supported by the fact that the main SIP Requests for Comments (RFC) 15 is one of the longest ever defined. SIP can operate over a number of transport protocols, including Tranmission Control Protocol (TCP),16 User Datagram Protocol (UDP),17 and Stream Control Transmission Protocol (SCTP).18 UDP
230
is generally the preferred method due to simplicity and performance, although TCP has the advantage of supporting Transport Layer Security (TLS) protection of call setup. However, recent work on Datagram TLS (DTLS)19 may render this irrelevant. SCTP, on the oth- er hand, offers several advantages over both TCP and UDP, including Denial of Service (DoS) resistance,20 multi-homing and mobility support, and logical con- nection multiplexing over a single channel. In the SIP architecture, the main entities are endpoints (whether soft phones or physical devices), a proxy server, a reg- istrar, a redirect server, and a location server. Figure 10.1 shows a high-level view of the SIP entity interac- tions.
Figure 10.1. Session Initiation Protocol (SIP) Entity Interactions.
The User, Alice, registers with her domain’s Reg- istrar (1), which stores the information in the Location Server (2). When placing a call, Alice contacts her Lo- cal Proxy Server (3), which may consult the Location Server (4). A call may be forwarded to another Proxy
231
Server (5), which will consult its domain Location Server (6) before forwarding the call to the final recipi- ent. After the SIP negotiation terminates, RTP is used directly between Alice and Bob to transfer media con- tent. For simplicity, this diagram does not show the possible interaction between Alice and a Redirection Server (which would, in turn, interact with the Loca- tion Server). The registrar, proxy, and redirect servers may be combined, or they may be separate entities op- erated independently. Endpoints communicate with a registrar to indicate their presence. This information is stored in the location server. A user may be regis- tered via multiple endpoints simultaneously. During call setup, the endpoint communicates with the proxy which uses the location server to determine where the call should be routed. This may be another endpoint in the same network (e.g., within the same enterprise), or another proxy server in another network. Alterna- tively, endpoints may use a redirect server to directly determine where a call should be directed and, redirect servers consult with the location server in the same way that proxy servers operate during call setup.
Once an end-to-end channel has been established (through one or more proxies) between the two end- points, SIP negotiates the actual session parameters (such as the codecs, RTP ports, etc.) using the Session Description Protocol (SDP).21 Figure 10.2 shows the message exchanges during a two-party call setup. Al- ice sends an INVITE message to the proxy server, op- tionally containing session parameter information en- coded within SDP. The proxy forwards this message directly to Bob, if Alice and Bob are users of the same domain. If Bob is registered in a different domain, the message will be relayed to Bob’s proxy, and from there to Bob. Note that the message may be forwarded
232
to multiple endpoints if Bob is registered from mul- tiple locations. While these are ringing (or otherwise indicating that a call setup is being requested), RING- ING messages are sent back to Alice. Once the call has been accepted, an OK message is sent to Alice contain- ing Bob’s preferred parameters encoded within SDP. Alice responds with an ACK message. Alice’s session parameter preferences may be encoded in the INVITE or the ACK message. (See Figure 10.2.)
Figure 10.2. Message Exchanges During an SIP- Based Two-Party Call Setup.
Following this exchange, the two endpoints can begin transmitting voice, video, or other content (as negotiated) using the agreed-upon media transport protocol, typically RTP. While the signaling traffic
233
may be relayed through a number of SIP proxies, the media traffic is exchanged directly between the two endpoints. When bridging different networks, e.g., PSTN and SIP, media gateways may disrupt the end- to-end nature of the media transfer. These entities translate content (e.g., audio) between the formats that are supported by the different networks.
Because signaling and media transfer operate in- dependent of each other, the endpoints are respon- sible for indicating to the proxies that the call has been terminated, using a BYE message which is relayed through the proxies along the same path as the call setup messages. There are many other protocol inter- actions supported by SIP that cover many common (and uncommon) scenarios including call forwarding (manual or automatic), conference calling, voicemail, etc. Typically, this is done by semantically overload- ing SIP messages such that they can play various roles in different parts of the call. The third section contains examples of how this flexibility and protocol modu- larity can be used to attack the system. All SIP traffic is transmitted over port 5060 (UDP or TCP). The ports used for the media traffic, however, are dynamic and negotiated via Session Description Protocol (SDP) dur- ing call setup. This poses some problems when NAT or firewalls are traversed. Typically, these have to be stateful and understand the SIP exchanges so that they can open the appropriate RTP ports for the media transfer. In the case of NAT traversal, endpoints may use protocols like STUN to enable communication. Al- ternatively, the Universal Plug-and-Play (uPnP) pro- tocol 2 may be used in some environments, such as residential broadband networks consisting of a single subnet behind a NAT gateway. Authentication be- tween endpoints, the registrar, and the proxy typically uses HTTP Digest Authentication, as shown in Figure
234
10.3. This is a simple challenge-response protocol that uses a shared secret key along with a username, do- main name, a nonce, and specific fields from the SIP message to compute a cryptographic hash. Using this mechanism, passwords are not transmitted in plain- text form over the network. It is worth noting that au- thentication may be requested at almost any point.
Figure 10.3. SIP Digest Authentication.
Later, we will see an example where this protocol can be abused by a malicious party to conduct toll fraud in some environments. For more complex authenti- cation scenarios, SIP can use Secure/Multipurpose Internet Mail Extensions (S/MIME) encapsulation22 to carry complex payloads, including public keys and certificates. When TCP is used as the transport protocol for SIP, TLS can be used to protect the SIP
235
messages. TLS is required for communication among proxies, registrars, and redirect servers, but only rec- ommended between endpoints and proxies or reg- istrars. Alternatively, IPsec23 may be used to protect all communications, regardless of the transport pro- tocol. However, because few implementations inte- grate SIP, RTP, and IPsec, it is left to system admin- istrators to figure out how to setup and manage such configurations.
Unlicensed Mobile Access.
UMA is a 3 Generation Partnership Project (3GPP) standard for enabling transparent access to mobile circuit-switched voice networks, packet-switch data networks, and IMS services using any IP-based sub- strate. Handsets supporting UMA can roam between the operator’s wireless network (usually referred to as a Radio Access Network, or RAN) and the Internet without losing access. For example, a call that is initi- ated over the RAN can then be routed without being dropped and with no user intervention over the public Internet if conditions are more favorable (e.g., stron- ger WiFi signal in the user’s premises, or in a hotel wireless hotspot while traveling abroad). For consum- ers, UMA offers better connectivity and the possibility of lower cost by enabling new business models and reducing roaming charges (under some scenarios). For operators, UMA reduces the need for additional spectrum; cell phone towers and related equipment. A variety of cell phones supporting UMA over WiFi currently exist, along with home gateways and USB- stick soft phones. More recently, some operators have introduced femto cells (ultra-low power RAN cells intended for consumer-directed deployment)
236
that can act as UMA gateways, allowing any mobile handset to take advantage of UMA where such de- vices are deployed. The basic approach behind UMA is to encapsulate complete Global System for Mobile (GSM) and 3rd Generation (3G) radio frames (except for the over-the-air crypto) inside IP packets. These can then be transmitted over any IP network, includ- ing the Internet. This means that the mobile operator can continue to use the existing back-end equipment; all that is needed is a gateway that encapsulates the GSM/3G frames and injects them to the existing cir- cuit-switched network (for voice calls), as can be seen in Figure 10.4. To protect both signaling and media traffic confidentiality and integrity while traversing un-trusted (and untrustworthy) networks, UMA uses Internet Protocol Security (IPSec). All traffic between the handset (or, more generally, UMA endpoint) and the provider’s UMA Network Controller (or a firewall/Virtual Private Network [VPN] concentrator screening traffic) is encrypted and integrity-protected using Encapsulating Security Payload (ESP).24
Figure 10.4. Unlicensed Mobile Access (UMA) Conceptual Architecture During a Call Setup.
237
The use of IPSec provides a high level of security for network traffic, once keys and other parameters have been negotiated. For that purpose, the Internet Key Exchange version 2 (IKEv2) key management protocol25 is used. Authentication uses the Extensible Authentication Protocol method for GSM Subscriber Identity Module (EAP-SIM)26 (for GSM handsets) and Extensible Authentication Protocol method for UMTS Authentication and Key Agreement (EAP-AKA)27 (for UMTS handsets) profiles. Authentication is asymmet- ric: the provider authenticates to the handset using digital signatures and public key certificates, while the handset authenticates using a SIM-embedded se- cret key. It is worth pointing out that UMA provides stronger authentication guarantees than the baseline cell phone network in that the provider does not au- thenticate to the handset in a RAN. Furthermore, the cryptographic algorithms used in IPSec Advanced Encryption Standard and 3 Data Encryption Standard (AES and 3DES) are considered significantly stronger than the on-the-air algorithms used in GSM. Despite the use of strong cryptography and sound protocols, UMA introduces some new risks in the operator net- works, since these now have to be connected to the public Internet in a much more intimate fashion. In particular, the security gateway must process IPSec traffic, including the relatively complex IKEv2 pro- tocol, and a number of UMA-related discovery and configuration protocols. These significantly increase the attack surface and overall security exposure of the operators.
238
Other VoIP/IMS Systems.
H.323 is an ITU defined protocol family for VoIP (audio and video) over packet-switched data net- works. The various sub protocols are encoded in Ab- stract Syntax Notation One (ASN.1) format. In the H.323 world, the main entities are terminals (software or physical phones), a gateway, a gatekeeper, and a back-end service. The gate keeper is responsible for ad- dress resolution, controlling bandwidth use, and oth- er management functions while the gateway connects the H.323 network with other networks (e.g., PSTN, or a SIP network). The back-end service maintains data about the terminals, including configuration, ac- cess billing rights, etc. An optional multipoint control unit may also exist to enable multipoint communica- tions, such as a teleconference. To setup an H.323 call, terminals first interact with the gatekeeper using the H.225 protocol over either TCP or UDP to receive au- thorization and to perform address resolution. Using the same protocol, they then establish the end-to-end connection to the remote terminal (possibly through one or more gateways). At that point, H.245 over TCP is used to negotiate the parameters for the actual me- dia transfer, including ports, which uses RTP (as in the case of SIP). Authentication may be requested at several steps during call setup, and typically depends on symmetric keys but may also use digital signa- tures. Voice encryption is also supported through SRTP and MIKEY.28 Unlike SIP, H.323 does not use a well-known port, making firewall traversal even more complicated. Skype3 is a P2P VoIP system that was originally available as a soft phone for desktop com- puters but has since been integrated into cell phones and other handheld devices, either as an add-on or
239
as the exclusive communication mechanism. It offers voice, video, and text messaging to all other Skype users free of charge, and provides bridging (typically for a fee) to the PSTN both for outgoing and incoming calls and text messages (SMS). The underlying proto- col is proprietary, and the software itself incorporates several anti-reverse engineering techniques. Nonethe- less, some analysis29 and reverse engineering30 have taken place, indicating both the ubiquitous use of strong cryptography and the presence of some soft- ware bugs (at the time of the work). The system uses a centralized login server but is otherwise fully dis- tributed with respect to intra-Skype communications. A number of chat (IM) networks, such as the AOL In- stant Messenger, Microsoft’s Live Messenger, Yahoo! Messenger, and Google Talk offer voice and video ca- pabilities as well. Although each network uses its own (often proprietary) protocol, bridges exist between most of them, allowing inter-IM communication at the text level. In most of these networks, users can place outgoing voice calls to the PSTN. Some popular IM clients also integrate SIP support.
VOIP THREATS
In trying to understand the threat space against VoIP, our approach is to place known vulnerabilities within a structured framework. While a single taxon- omy is not likely to be definitive, using several differ- ent viewpoints and mapping the vulnerability space along several axes may reveal trends and other areas that merit further analysis. As a starting point, we use the taxonomy provided by the Voice over IP Security Alliance (VOIPSA). VOIPSA is a vendor-neutral, not for profit organization composed of VoIP and security
240
vendors, organizations, and individuals with an inter- est in securing VoIP protocols, products, and installa- tions. In addition, we place the surveyed vulnerabili- ties within the traditional threat spa of confidentiality, integrity, and availability (CIA). Finally, we ascertain whether the vulnerabilities exploit bugs in the proto- col, implementation, or system configuration. In fu- ture work, we hope to expand the number of views to the surveyed vulnerabilities and to provide more in-depth analysis. The VOIPSA security threat tax- onomy31 aims to define the security threats against VoIP deployments, services, and end users. The key elements of this taxonomy are:
1. Social threats are aimed directly against hu- mans. For example, misconfigurations, bugs, or bad protocol interactions in VoIP systems may enable or facilitate attacks that misrepresent the identity of ma- licious parties to users. Such attacks may then act as stepping stones for further attacks such as phishing, theft of service, or unwanted contact (spam).
2. Eavesdropping, interception, and modification threats cover situations where an adversary can un- lawfully and without authorization from the parties concerned listen in on the signaling (call setup) or the content of a VoIP session, and possibly modify aspects of that session while avoiding detection. Examples of such attacks include call re-routing and interception of unencrypted RTP sessions.
3. Denial of service (DoS) threats have the poten- tial to deny users access to VoIP services. This may be particularly problematic in the case of emergencies, or when a DoS attack affects all of a user’s or an organiza- tion’s communication capabilities (i.e., when all VoIP and data communications are multiplexed over the same network which can be targeted through a DoS
241
attack). Such attacks may be VoIP-specific (exploiting flaws in the call setup or the implementation of ser- vices), or VoIP-agnostic (e.g., generic traffic flooding attacks). They may also involve attacks with physical components (e.g., physically disconnecting or sever- ing a cable) or through computing or other infrastruc- tures (e.g., disabling the DNS server, or shutting down power).
4. Service abuse threats covers the improper use of VoIP services, especially (but not exclusively) in those situations where such services are offered in a com- mercial setting. Examples of such threats include toll fraud and billing avoidance.32
5. Physical access threats refer to inappropriate/ unauthorized physical access to VoIP equipment, or to the physical layer of the network (following the ISO 7-layer network stack model).
6. Interruption of services threats refer to nonin- tentional problems that may nonetheless cause VoIP services to become unusable or inaccessible. Examples of such threats include loss of power due to inclement weather, resource exhaustion due to oversubscription, and performance issues that degrade call quality.
In our discussion of vulnerabilities (whether theo- retical or demonstrated) that follows, we shall mark each item with a tuple (V, T, K), where: V ∈ {1, 2, 3, 4, 5, 6}, where each number refers to an element in the VOIPSA threat taxonomy from above; T ∈ {C1 , I1 , A1}, referring to confidentiality, integrity and availability, respectively; K ∈ {P2 , I2 , C2 }, referring to protocol, implementation, and configuration respectively; and confidentiality via a configuration problem or bug. In some cases, the same underlying vulnerability may be used to perform different types of attacks. We will be discussing all such significant attack variants.
242
Disclosed Vulnerabilities.
Threats against VoIP system availability that ex- ploit implementation weaknesses are fairly common. For example, some implementations were shown to be vulnerable to crashes or hanging (live clock) when giv- en empty, malformed, or large volumes of33 INVITE or other messages (3, A1, I2). It is worth noting that the same vulnerability may be present across similar pro- tocols on the same platform and product34 due to code sharing and internal software structure, or to systems that need to understand VoIP protocols but are not nominally part of a VoIP system.35 The reason for the disproportionately large number of denial of service vulnerabilities is because of the ease with which such failure can be diagnosed, especially when the bug is discovered through automated testing tools (e.g., fuzz- ers). Many of these vulnerabilities may in fact be more serious than a simple denial of service due to a crash, and could possibly lead to remote code injection and execution. Unexpected interactions between different technologies used in VoIP systems can also lead to vulnerabilities. For example, in some cases cross-site scripting (XSS) attacks were demonstrated against the administrator- and customer-facing management in- terface (which was web-based) by injecting malicious Java script in selected SIP messages36 (1, I1, I2), often through Structured Query Language (SQL) injection vulnerabilities.37 The same vulnerability could also be used to commit toll fraud by targeting the underly- ing database (4, I1, I2). XSS attacks that are not web- oriented have also been demonstrated, with one of the oldest VoIP-related vulnerabilities38 permitting shell command execution. Another web-oriented attack
243
vector is Cross Site Request Forgery (CSRF), whereby users visiting a malicious page can be induced to auto- matically (without user intervention, and often with- out any observable indications) perform some action on the web servers (in this case, VoIP web-based man- agement interface) that the browser is already authen- ticated to).39 Other privilege-escalation vulnerabilities through the web interface also exist.40 The complexity of the SIP finite state machine has sometimes led to poor implementations. For example, one vulnerabil- ity41 allowed attackers to confuse a phone receiving a call into silently completing the call, which allowed the adversary to eavesdrop on the device’s surround- ings.
The same vulnerability could be used to deny call reception of the target, since the device was already marked as busy. In other cases, it is unclear to devel- opers what use of a specific protocol field may be, in which case they may silently ignore it. Occasionally, such information is critical for the security of the pro- tocol exchange, and omitting or not checking it allows adversaries to perform attacks such as man-in-the- middle, or traffic interception,42 or bypass authentica- tion checks.43
Since SIP devices are primarily software-driven, they are vulnerable to the same classes of vulnerabili- ties as other software. For example, buffer overflows are possible even against SIP “headphones,” much less soft phones, allowing adversaries to gain complete control of the device.44 Such vulnerabilities typically arise from a combination of poor (nondefensive) pro- gramming practices, insufficient testing, and the use of languages, such as C and C++ that support unsafe operations. Sometimes, these vulnerabilities appear in software that is not directly used in VoIP but must be
244
VoIP-aware, e.g., fire walls45 or protocol analyzers.46 It is also worth noting that these are not the only types of vulnerabilities that can lead to remote code execution.47 Other input validation failures can allow attackers to download arbitrary files from a user’s machine (1, C1, I2) or to place calls48 (1, I1, I2) by supplying specially encoded URIs49 or other parameters. A significant risk with VoIP devices is the ability of adversaries to mis- represent their identity (e.g., their calling number). Such vulnerabilities50 sometimes arise due to the lack of cross-checking of information provided across sev- eral messages during call setup and throughout the session (1, I1, I2).
Similar failures to crosscheck and validate infor- mation can lead to other attacks, such as indicating whether there is pending voicemail for the user51 (1, I1, I2), or where attackers may spoof incoming calls by directly connecting to a VoIP phone52 (1, I1, I2).
Undocumented, on-by-default features are anoth- er source of vulnerabilities. These are often remnants from testing and debugging during development that were not disabled when a product shipped.53 As a result, they often offer privileged access to ser- vices and data on a device that would not otherwise be available54 (1, C1, I2). One particularly interesting vulnerability allowed an attacker to place outgoing calls through the web management interface55 (4, I1, C2). A significant class of vulnerabilities in VoIP de- vices revolves around default configurations, and in particular default usernames and passwords56 (2, C1 + I1, C2). Lists of default accounts are easy to find on the Internet via a search engine. Users often do not change these settings; this seems to be particularly so for administrative accounts, which are rarely (if ever) used in the home/Small Office Home Office (SOHO)
245
environment. Other default settings involve Network Time Protocol (NTP) servers57 and DNS servers58 (2, C1 + I1, C2). Since the boot and VoIP stacks are not necessarily tightly integrated, interaction with one protocol can have adverse effects (e.g., changing the perceived location of the phone) in the other proto- col59 [2, C1, I2]). Other instances of such vulnerabili- ties involve improper/insufficient credential checking by the registrar or proxy60 or by the SNMP server,61 which can lead to traffic interception (2, C1, I2) and user impersonation (1, I1, I2). The integration of sev- eral capabilities in VoIP products, e.g., a web server used for the management interface, can lead to vulner- abilities being imported to the VoIP environment that would not otherwise apply. In the specific example of an integrated web server, directory traversal bugs62 or similar problems (such as lack of proper authen- tication in the web interface)63 can allow adversaries to read arbitrary files or other information from the device (1, C1, I2). SIP (or, more generally, VoIP) com- ponents integrated with firewalls may also interact in undesirable ways. For example, improper handling of registration requests may allow attackers to receive messages intended for other users64 (2, C1, I2). Other such examples include failure to authenticate server certificates in wireless environments, enabling man- in-the-middle and eavesdropping attacks65 (2, C1, I2).
Predictability and lack of proper use (or sources) of randomness is another vulnerability seen in VoIP products. For example, predictable values in SIP head- er messages66 allows malicious users to avoid register- ing, but continue using the service (4, I1, I2). Protocol responses to carefully crafted messages can reveal in- formation about the system or its users to an attacker. Although this has been long understood in limited-
246
domain protocols (e.g., remote login), with measures taken to normalize responses such that no information is leaked, the complexity of VoIP (and other) protocols make this infeasible. As a result, information disclo- sure vulnerabilities abound67 (1, C1, I2).
Some of the most serious nonimplementation type of vulnerabilities are those where the specification permits behavior that is exploitable. For example, cer- tain vendors permit the actual Uniform Resource In- dentifier (URI) in a SIP INVITE call and the URI used as part of the Digest Authentication to differ, which (while arguably permitted by the specification) allows credential reuse and toll fraud68 (4, I1, P2). While rare, protocol-level vulnerabilities also exist. These repre- sent either outright bugs in the specification, or un- seen interaction between different protocols or proto- col components. For large, complicated protocols such as SIP and H.323, where components (code, messages, etc.) are semantically overloaded and reused, it is perhaps not surprising that such emergent properties exist. One good example is the relay attack that is pos- sible with the SIP Digest Authentication,69 whereby an adversary can reuse another party’s credentials to obtain unauthorized access to SIP or PSTN services (such as calling a premium or international phone line) (4, I1, P2). This attack is possible because in an authentication attack, both depicted in Figure 10.5, an authentication may be requested in response to an IN- VITE message that is not usable in, for example, plac- ing fraudulent calls.
247
Figure 10.5. SIP Relay Attack.
DISCUSSION
Looking at the vulnerabilities we have consid- ered, a few patterns emerge. First, as we can see in our informal classification of vulnerability effects shown in Figure 10.6, half of the problems lead to a denial of service in either an end-device (phone or soft phone) or a server (proxy, registrar, etc.). This is not altogether surprising, since denial of service (espe- cially a crash) is something that is easily diagnosed. In many cases, the problem was discovered by auto- mated testing, such as protocol or software fuzzing; software failures are relatively easy to determine in such settings. Some of these vulnerabilities could in
248
fact turn out to be more serious, e.g., a memory cor- ruption leading to a crash could be exploitable to mount a code injection attack. The second largest class of vulnerabilities allows an adversary to control the device, whether by code injection, default passwords and services, or authentication failures. Note that we counted a few of the vulnerabilities (approximately 10 percent) more than once in this classification. The same pattern with respect to the predominance of de- nial of service vulnerabilities holds when we look at the breakdown according to the VOIPSA taxonomy, shown in Figure 10.7. It should not be surprising that, given the nature of the vulnerabilities disclosed in Common Vulnerabilities and Exposures (CVE), we have no data on physical access and (accidental) inter- ruption of services vulnerabilities. Furthermore, while “Access to Services” was a non-negligible component in the previous breakdown, it represents only 4 per- cent here. The reason for this apparent discrepancy is in the different definitions of service: the specific ele- ment in the VOIPSA taxonomy refers to VoIP-specific abuse, whereas our informal definition covers lower- level system components which may not be usable in, for example, placing fraudulent calls. One state (data) resident on the system falls into the “access to data” category. The other observation here, is that while the VOIPSA taxonomy covers a broad spectrum of con- cerns or VoIP system designers and operators, its categories are perhaps too broad (and, in some cases, imprecise) to help with characterizing the types of bugs we have examined.
249
Figure 10.6. Vulnerability Breakdown Based on Effect.
Figure 10.7. Vulnerability Breakdown Based on VOIPSA Taxonomy.
250
Most categories are self explanatory; “attack the user” refers to vulnerabilities that permit attackers to affect the user/administrator of a device without necessarily compromising the system or getting ac- cess to its data or services. XSS attacks and traffic eavesdropping attacks fall in this category, whereas attacks that compromise state (data) resident on the system fall in the “access to data” category.
The vulnerability breakdown according to the tra- ditional CIA security concerns again reflects the pre- dominance of denial of service threats against VoIP systems, as seen in Figure 10.8. However, we can see that integrity violations (e.g., system compromise) are a sizable component of the threat space, while confidentiality violations are seen in only 15 percent of disclosed vulnerabilities. This represents an inver- sion of the perceived threats by users and adminis- trators, who (anecdotal evidence suggests) typically worry about such issues as call interception and eaves- dropping. Finally, Figure 10.9 shows the breakdown based on source of vulnerability. The overwhelming majority of reported problems arise from implemen- tation issues, which should not be surprising given the nature of bug disclosure. Problems arising from configuration represented 7 percent of the total space, including such items as privileged services left turned on and default username/passwords. However, note that the true picture (i.e., what actually happens with deployed systems) is probably different in that configuration problems are most likely undercount- ed: such problems are often site-specific and are not reported to bug-disclosure databases when discov- ered. On the other hand, implementation and pro- tocol problems are prime candidates for disclosure. What is surprising is the presence of protocol vulner- abilities; one would expect that such problems were
251
discovered and issued during protocol development, specification, and standardization. Their mere exis- tence potentially indicates high protocol complexity. The vulnerability analysis contained in this chapter is, by its nature, static: we have presented a snapshot of known problems with VoIP systems, with no correla- tion with (and knowledge of) actual attacks exploiting these, or other vulnerabilities. A complete analysis of the threat space would also contain a dynamic compo- nent, whereby attacker behavior patterns and trends would be analyzed vis-à-vis actual, deployed VoIP systems or, lacking access to such, simulacra thereof.70
Figure 10.8. Vulnerability Breakdown Based on Source (I2, C2, P2).
252
Figure 10.9. Vulnerability Breakdown Based on Source (I2, C2, P2).
CONCLUSIONS
We can draw some preliminary conclusions with respect to threats and potential areas for future re- search based on the data examined so far. These can be summarized as follows:
1. The large majority of disclosed threats focused on denial of services attacks are based on implemen- tation issues. While fault-tolerance techniques can be applied in the case of servers (replication, hot standby, Byzantine fault tolerance, etc.), it is less clear how to provide similar levels of protection at acceptable cost and usability to end user devices. Unfortunately, the ease with which mass DoS attacks can be launched over the network against client devices means that they represent an attractive venue for attackers to achieve the same impact.
253
2. Code injection attacks in their various forms (buffer overflow, cross-site scripting, SQL injection, etc.) remain a problem. While a number of techniques have been developed, we need to do a better job at de- ploying and using them where possible, and devising new techniques suitable for the constrained environ- ments that some vulnerable VoIP devices represent.
3. Weak default configurations remain a problem, as they do across a large class of consumer and en- terprise products and software. The situation is likely to be much worse in the real world, considering the complexity of securely configuring a system with as many components as VoIP. Vendors must make an ef- fort to provide secure-by-default configurations, and to educate users on how to best protect their systems. Administrators are in need of tools to analyze their existing configurations for vulnerabilities. While there are some tools that dynamically test network compo- nents (e.g., firewalls), we need tools that work higher in the protocol and application stack (i.e., interact- ing at the user level). Furthermore, we need ways of validating configurations across multiple components and protocols.
4. Finally, there is simply no excuse for protocol- level vulnerabilities. While techniques exist for ana- lyzing and verifying security protocols, they do not seem to cope well with complexity. Aside from using such tools and continuing their development, protocol designers and standardization committees must con- sider the impact of their decisions on system imple- menters, i.e., whether it is likely that a feature or as- pect of the protocol is likely to be misunderstood and/ or misimplemented. Simpler protocols are also desir- able, but seem incompatible with the trends we have observed in standardization bodies. Our plans for fu- ture work include expanding the data set we used for
254
our analysis to include findings from academic work, adding and presenting more views (classifications) to the data, and developing dynamic views to VoIP- related misbehavior.
ENDNOTES - CHAPTER 10
1. R. Droms, “Dynamic Host Configuration Protocol,” RFC 2131 (Draft Standard), March 1997, Updated by RFCs 3396, 4361, 5494.
2. P. V. Mockapetris, “Domain Names—Concepts and Facili- ties,” RFC 1034 (Standard), November 1987, Updated by RFCs 1101, 1183, 1348, 1876, 1982, 2065, 2181, 2308, 2535, 4033, 4034, 4035, 4343, 4035, 4592; P. V. Mockapetris, “Domain Names—Im- plementation and Specification,” RFC 1035 (Standard), November 1987, Updated by RFCs 1101, 1183, 1348, 1876, 1982, 1995, 1996, 2065, 2136, 2181, 2137, 2308, 2535, 2845, 3425, 3658, 4033, 4034, 4035, 4343.
3. K. Sollins, “The TFTP Protocol (Revision 2),” RFC 1350 (Standard), July 1992, Updated by RFCs 1782, 1783, 1784, 1785, 2347, 2348, 2349; R. Finlayson, “Bootstrap loading using TFTP,” RFC 906, June 1984.
4. P. Srisuresh and K. Egevang, “Traditional IP Network Ad- dress Translator (Traditional NAT),” RFC 3022 (Informational), January 2001.
5. J. Rosenberg, R. Mahy, P. Matthews, and D. Wing, “Session Traversal Utilities for NAT (STUN),” RFC 5389 (Proposed Stan- dard), October 2008.
6. D. Mills, “Network Time Protocol (Version 3) Specifica- tion, Implementation and Analysis,” RFC 1305 (Draft Standard), March 1992.
7. D. Harrington, R. Presuhn, and B. Wijnen, “An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworks,” RFC 3411 (Standard), December 2002, Updated by RFC 5343.
255
8. T. Berners-Lee, R. Fielding, and H. Frystyk, “Hypertext Transfer Protocol – HTTP/1.0,” RFC 1945 (Informational), May 1996; R. Fielding, J. Gettys, J. Mogul, H. Frystyk, L. Masinter, P. Leach, and T. Berners-Lee, “Hypertext Transfer Protocol – HTTP/1.1,” RFC 2616 (Draft Standard), June 1999, Updated by RFC 2817.
9. T. Dierks and E. Rescorla, “The Transport Layer Security (TLS) Protocol Version 1.2,” RFC 5246 (Proposed Standard), Au- gust 2008.
10. H. Schulzrinne, S. Casner, R. Frederick, and V. Jacobson, “RTP: A Transport Protocol for Real-Time Applications,” RFC 3550 (Standard), July 2003, Updated by RFC 5506.
11. I. Johansson and M. Westerlund, “Support for Reduced- Size Real-Time Transport Control Protocol (RTCP): Opportunities and Consequences,” RFC 5506 (Proposed Standard), April 2009.
12. J. Rosenberg, H. Schulzrinne, G. Camarillo, A. Johnston, J. Peterson, R. Sparks, M. Handley, and E. Schooler, “SIP: Session Initiation Protocol,” RFC 3261 (Proposed Standard), June 2002, Updated by RFCs 3265, 3853, 4320, 4916, 5393.
13. 3GPP, “Generic Access Network,” available from www.3gpp. org/ftp/Specs/html-info/43318.htm, 2009.
14. J. Franks, P. Hallam-Baker, J. Hostetler, S. Lawrence, P. Leach, A. Luotonen, and L. Stewart, “HTTP Authentication: Basic and Digest Access Authentication,” RFC 2617 (Draft Standard), June 1999.
15. Rosenberg, Schulzrinne, Camarillo, Johnston, Peterson, Sparks, Handley, and Schooler, “SIP: Session Initiation Protocol.”
16. J. Postel, “Transmission Control Protocol,” RFC 793 (Stan- dard), September 1981, Updated by RFCs 1122, 3168.
17. J. Postel, “User Datagram Protocol,” RFC 768 (Standard), August 1980.
256
18. L. Ong and J. Yoakum, “An Introduction to the Stream Control Transmission Protocol (SCTP),” RFC 3286 (Information- al), May 2002.
19. E. Rescorla and N. Modadugu, “Datagram Transport Lay- er Security,” RFC 4347 (Proposed Standard), April 2006.
20. M. Handley, E. Rescorla, and IAB, “Internet Denial-of-Ser- vice Considerations,” RFC 4732 (Informational), December 2006.
21. M. Handley, V. Jacobson, and C. Perkins, “SDP: Session Description Protocol,” RFC 4566 (Proposed Standard), July 2006.
22. B. Ramsdell, “Secure/Multipurpose Internet Mail Exten- sions (S/MIME) Version 3.1 Message Specification,” RFC 3851 (Proposed Standard), July 2004.
23. S. Kent and K. Seo, “Security Architecture for the Internet Protocol,” RFC 4301 (Proposed Standard), December 2005.
24. S. Kent, “IP Encapsulating Security Payload (ESP),” RFC 4303 (Proposed Standard), December 2005.
25.C. Kaufman, “Internet Key Exchange (IKEv2) Protocol,” RFC 4306 (Proposed Standard), December 2005, Updated by RFC 5282.
26. H. Haverinen and J. Salowey, “Extensible Authentication Protocol Method for Global System for Mobile Communications (GSM) Subscriber Identity Modules (EAP-SIM),” RFC 4186 (Infor- mational), January 2006.
27. J. Arkko and H. Haverinen, “Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA),” RFC 4187 (Informational), January 2006.
28. J. Arkko, E. Carrara, F. Lindholm, M. Naslund, and K. Norrman, “MIKEY: Multimedia Internet KEYing,” RFC 3830 (Proposed Standard), August 2004, Updated by RFC 4738.
29. Tom Berson, “Skype Security Evaluation,” Tech. Rep., October 2005; S. A. Baset and H. Schulzrinne, “An Analysis of
257
the Skype Peer-to-Peer Telephony Protocol,” in Proceedings of INFO- COM, April 2006.
30. P. Biondi and F. Desclaux, “Silver Needle in the Skype,” in BlackHat Europe Conference, March 2006, available from www. blackhat.com/presentations/bh-europe-06/bh-eu-06-biondi/bh-eu-06- biondi-up.pdf.
31. VoIP Security Alliance, “VoIP Security and Privacy Threat Taxonomy, version 1.0,” October 2005, available from www.voipsa. org/Activities/taxonomy.php.
32. “Two charged with VoIP fraud,” The Register, June 2006, available from www.theregister.co.uk/2006/06/08/voip fraudsters nabbed/; “Fugitive VOIP hacker cuffed in Mexico,” The Register, February 2009, available from www.theregister.co.uk/2009/02/11/ fugitive voip hacker arrested/.
33. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2007-4753; CVE- 2007-0431; CVE-2007-4553; CVE-2003-1114; CVE-2006-1973; CVE- 2007-0648; CVE-2007-2270; CVE-2007-4291, 4292; CVE-2008-3799, 3800, 3801, and 3802; CVE-2009-1158; CVE-2004-0054; CVE-2001- 0546; CVE-2002-2266; CVE-2004-0498; CVE-2004-2344; CVE-2004- 2629; CVE-2004-2758; CVE-2007-4429; CVE-2006-5084; CVE- 2005-3267; CVE-2004-1777; CVE-2003-1108-1113; CVE-2003-1115; CVE-2004-0504; CVE-2005-4466; CVE-2006-5445; CVE-2006-2924; CVE-2006-0739, 0738, and 0737; CVE-2007-6371; CVE-2007-5583; CVE-2007-5537; CVE-2007-4924; CVE-2007-4459; CVE-2007-4455; CVE-2007-4382; CVE-2007-4366; CVE-2007-3441-3445; CVE- 2007-3436 and 3437; CVE-2007-3369, 3368; CVE-2007-3361-3363; CVE-2007-3348-3351; CVE-2007-3322 and 3321; CVE-2007-3318 and 3317; CVE-2007-2297; CVE-2007-1693; CVE-2007-1650; CVE- 2007-1594; CVE-2007-1590; CVE-2007-1561; CVE-2007-1542; CVE-2007-1306; CVE-2007-0961; CVE-2008-0095; CVE-2008-0263; CVE-2008-1249; CVE-2008-1741; CVE-2008-1745; CVE-2008-1747 and 1748; CVE-2008-1959; CVE-2008-2119; CVE-2008-2732; CVE- 2008-2733; CVE-2008-2734 and 2735; CVE-2008-3157; CVE-2008- 3210; CVE-2008-3778; CVE-2008-4444; CVE-2008-5180; CVE-2008- 6140; CVE-2008-6574 and 6575; CVE-2009-0871; CVE-2009-0636; CVE-2009-0630; CVE-2009-0631; CVE-2007-5591; CVE-2007-5556; CVE-2007-5369; CVE-2007-2886; CVE-2006-7121; CVE-2006-6411;
258
CVE-2006-5233; CVE-2006-5231; CVE-2005-3989; CVE-2004-1977; CVE-2002-0882; CVE-2002-0880; CVE-2002-0835;
34. “CVE-2007-4291,” 2007, available from cve.mitre.org/ cgi-bin/cvename.cgi?name=CVE-2007-4291.
35. “CVE-2005-4464,” 2005, available from cve.mitre.org/ cgi-bin/cvename.cgi?name=CVE-2005-4464.
36. “CVE-2007-5488,” 2007 available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2007-5488. CVE-2007-5411, CVE-2008- 0582, CVE-2008-0583, CVE-2008-0454, CVE-2006-2925, CVE-2007- 2191.
37. “CVE-2008-6509,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-6509. “CVE-2008-6573,” 2008, avail- able from cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6573.
38. “CVE-1999-0938,” 1999, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-1999-0938.
39. “CVE-2008-1250,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-1250.
40. “CVE-2008-6708,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-6708.
41. “CVE-2007-4498,” 2007, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2007-4498.
42. “CVE-2007-3319,” 2007, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2007-3319.
43. “CVE-2007-3177,” 2007, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2007-3177, 2007. “CVE-2007-0334,” avail- able from cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0334.
44. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2003-1114, CVE-2003-1110, CVE-2003-1111, CVE-2005-4050, CVE-2007-4294, CVE-2007-4295, CVE-2004-0056, CVE-2004-0117, CVE-2005-3265, CVE-2004-1114, CVE-2003-0761, CVE-2006-4029, CVE-2006-3594,
259
CVE-2006-3524, CVE-2006-0359, CVE-2006-0189, CVE-2007-5788, CVE-2007-3438, CVE-2007-2293, CVE-2007-0746, CVE-2008-0528, CVE-2008-0530, CVE-2008-0531, CVE-2008-2085, CVE-2007-4489, CVE-2005-2081.
45. “CVE-2003-0819,” 2003, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2003-0819.
46. “CVE-2005-1461,” 2005, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2005-1461.
47. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2006-5084, CVE- 2008-2545, CVE-2008-1805, CVE-2007-5989, CVE-2007-3896, CVE- 2008-6709.
48. “CVE-2008-1334,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-1334.
49. “CVE-2006-2312,” 2006, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2006-2312.
50. “CVE-2005-2181,” 2005, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2005-2181.
51. “CVE-2005-2182,” 2005, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2005-2182.
52. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2007-5791, CVE- 2007-3347, CVE-2007-3320.
53. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2006-0305, CVE- 2006-0302, CVE-2005-3804, CVE-2005-3724, CVE-2005-3715.
54. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2006-0360, CVE- 2007-3439, CVE-2006-0374, CVE-2005-3723, CVE-2005-3721, CVE- 2005-3718.
260
55. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2007-3440, CVE- 2008-1248.
56. Examples of Common Vulnerabilities and Exposures are available from: cve.mitre.org/cve/index.html; CVE-2005-3718, CVE- 2006-5038, CVE-2008-4874, CVE-2007-3047, CVE-2008-1334, CVE- 2006-0834, CVE-2005-3803, CVE-2005-3719, CVE-2005-3717, CVE- 2005-3716, CVE-2005-0745, CVE-2002-0881.
57. “CVE-2006-0375,” 2006, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2006-0375.
58. “CVE-2005-3725,” 2005, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2005-3725.
59. “CVE-2007-5361,” 2007, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2007-5361.
60. “CVE-2008-5871,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-5871.
61. “CVE-2005-3722,” 2005, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2005-3722.
62. “CVE-2008-4875,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-4875.
63. “CVE-2008-6706,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-6706, 2008. “CVE-2008-6707,” avail- able from cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6707.
64. “CVE-2007-6095,” 2007, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2007-6095.
65. “CVE-2008-1114,” 2008, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2008-1114, 2008. “CVE-2008-1113,” avail- able from cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1113.
66. “CVE-2002-1935,” 2002, available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2002-1935.
261
67. “CVE-2006-4032,” available from cve.mitre.org/cgi-bin/cvename. cgi?name=CVE-2006-4032, 2006. “CVE-2008-3903,” 2008, available from cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3903.
68. “CVE-2007-5469,” available from cve.mitre.org/cgi-bin/ cvename.cgi?name=CVE-2007-5469, 2007. “CVE-2007-5468,” 2007, available from cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007 -5468.
69. R. State, O. Festor, H. Abdelanur, V. Pascual, J. Kuthan, R. Coeffic, J. Janak, and J. Loroiu, “SIP Digest Authentication Relay Attack,” March 2009, available from tools.ietf.org/html/draft-state- sip-relay-attack-00.
70. M. Nassar, R. State, and O. Festor, “VoIP Honeypot Ar- chitecture,” in Proceedings of the 10th IFIP/IEEE International Symposium on Integrated Network Management, May 2007, pp. 109–118.
263
CHAPTER 11
TOWARD FOOLPROOF IP NETWORK CONFIGURATION ASSESSMENTS*
Rajesh Talpade
INTRODUCTION
Internet protocol (IP) networks have come of age. They are increasingly replacing leased-line data infra- structure and traditional phone service, and are ex- pected to offer Public Switched Telephone Network (PSTN) - quality service at a much lower cost. As a re- sult, there is an urgent interest in ensuring IP network security, reliability, and quality of service (QoS). In fact, regulators are now requiring compliance with IP- related mandates. This chapter discusses the complex nature of IP networks and how that complexity makes them particularly vulnerable to faults and intrusions. It describes regulatory efforts to mandate assessment, explains why many current approaches to IP assess- ment fall short, and describes the requirements for an effective solution to satisfy business, government, and regulatory requirements.
IP networks throughout the public and private sectors are now mainstream. Everyday, IP networks are responsible for transporting real-time and critical voice, video, and data traffic. As a result, it is no lon- ger acceptable for IP networks to deliver “best-effort” service. They are expected to perform at carrier-grade level. However, it is enormously challenging to deploy __________
* This work was supported in part by the U.S. Department of Homeland Security Science & Technology Directorate under Con- tract No. NBCHC050092.
264
IP networks and assure consistent, and high quality service delivery, given that they are such complex and dynamic environments.
IP networks are comprised of devices such as rout- ers, switches, and firewalls that are interconnected by network links. These devices are not “plug-and-play,” rather, they must be provided with specific instruc- tions, also known as scripts or configurations, which indicate exactly how they are to interact with each other to provide the correct end-to-end IP network service. This is why we refer to IP device configura- tions as the DNA of the network—they literally con- trol the network’s behavior.
Unfortunately, there is nothing simple or standard about these configurations. Each one must be manu- ally programmed into the network devices, and every vendor uses a different configuration language for its devices. Furthermore, device configurations change virtually everyday in response to new application deployments, organizational or policy changes, new device or technology deployments, device failures, or any number of other reasons. Device configura- tions have an average of 500 lines of code per device. A Fortune 500 enterprise that relies on an IP can eas- ily have over 50 million lines of configuration code in its network. But numbers of devices and lines of code are only part of the problem. Configurations can contain parameters for about 20 different IP protocols and technologies that need to work together. Those protocols and technologies must satisfy various, con- stantly changing service requirements, some of which are inherently contradictory, such as security and con- nectivity with the Internet. So configuration errors can easily occur due to entry mistakes, feature interaction, poor process, or lack of a network-wide perspective.
265
The labor-intensive and constantly changing na- ture of IP network operations is analogous to software development. The key difference, as illustrated in Fig- ure 11.1, is that software development has matured to the point where errors are significantly reduced by having different people responsible for requirements, code writing, and testing. More importantly, testing in software development is a well-established process, while there is no similarly rigorous process in IP net- work deployment and operation. The impacts of con- figuration errors are well documented. The National Security Agency (NSA) found that 80 percent of the vulnerabilities in the Air Force were due to configura- tion errors, according to a recent report from Center for Strategic and International Studies (CSIS).1 British Telecom (BT)/Gartner has estimated that 65 percent of cyber attacks exploit systems with vulnerabilities in- troduced by configuration errors.2 The Yankee Group has noted that configuration errors cause 62 percent of network downtime.3 A 2006 Computer Security Institute/FBI computer crime survey conservatively estimates average annual losses from cyber attacks at $167,000 per organization. 4
Figure 11.1. Inadequate Testing in IP Network Deployment Compared to Software Development.
266
CONFIGURATION ERRORS FOUND IN OPERATIONAL IP NETWORKS
IP network configuration errors are hard to detect since they can require validation of multiple protocols and device configurations simultaneously. These er- rors typically remain latent until they are exploited by cyber attackers, discovered by auditors, or result in network failures. Below are specific examples of configuration errors, and their potential impact on the organization. Many of these errors have been discov- ered in operational networks while performing con- figuration assessments.
Reliability.
Organizations that depend on the IP network to provide a very reliable service have to ensure that there are no single points of failure in the network. It is not sufficient to just provide redundant net- work devices and links at the physical level. It is also critical to ensure that the configurations of the network devices make use of the available redundant physical resources, and that the redundancy is ensured across multiple layers. Examples of misconfigurations that result in single points of failure include:
• Mismatched device interface parameters. This mismatch prevents devices from establishing logical connectivity even though physical con- nectivity exists.
• Hot Standby Routing Protocol (HSRP) incon- sistently configured across two routers that are expected to mirror each other. The standby router will not take over when the main router fails.
267
• Access Control Lists (ACLs) or firewall rules stop specific application traffic on a path. Even if the path provides redundancy in general, the ACLs/rules still are a cause for a single point of failure to exist for the specific application traf- fic.
• Use of a single Open Shortest Path First (OSPF) Area Border Router (ABR). The OSPF areas that are connected by the ABR will become isolated if the ABR fails.
• Multiple VPN connections sharing a single physical link or device. The redundancy ex- pected from the multiple VPN connections is not provided due to their dependence on a single physical resource.
In addition to the errors that introduce single points of failures as described above, other errors in configuration of IP routing protocols, such as Open Shortest Path First (OSPF), Border Gateway Protocol (BGP), Multi-Protocol Label Switching (MPLS), and Intermediate System to Intermediate System (IS-IS), can also impact network reliability. Examples of such errors include:
• Inconsistent routing parameters such as OSPF Hello and Dead interval across multiple rout- ers. OSPF will not function efficiently if such parameters are inconsistent, resulting in ephemeral traffic loops and poor network per- formance.
• Best practices that are proposed by vendors and experts for routing protocols, such as the use of a full-mesh to connect all internal BGP (iBGP) routers, and that OSPF route summarizations should include IP addresses of all interfaces ex-
268
cept the loopback interface of a router, are not followed. Not adhering to best practices gen- erally results in an unstable network that will have intermittent connectivity issues that are difficult to debug.
• Use of inappropriate IP addresses, such as ad- dresses assigned to other organizations, or pri- vate addresses in parts of the network directly exposed to the Internet. Such networks will start advertising routes for IP addresses they do not own, resulting in Internet routing issues.
Security.
The most obvious configuration errors in this cat- egory can be found in firewalls, in the form of “holes” that are inadvertently left in firewall configurations. These holes are actually rules that permit specific application traffic to pass temporarily through the firewall, and then these rules are not removed after they are no longer needed. Cyber attackers scanning enterprise networks discover these holes and craft their attacks on the enterprise infrastructure through them. Apart from the obvious firewall holes, there are several other examples of errors that impact security, such as:
• Static route on device does not direct applica- tion traffic into IPSec tunnel. This results in sensitive traffic remaining unprotected as it transits the network instead of flowing through the secure IPSec tunnel.
• Best practices for Virtual LAN (VLAN) secu- rity, such as disabling dynamic-desire and us- ing root-guard and Bridge Protocol Data Unit (BPDU)-guard on switch access ports, are not
269
followed. Leaving the dynamic-desire VLAN feature enabled in a switch allows an attacker that connects to the switch to monitor all traffic passing through the switch.
• Link left active between devices. If the devices belong to network segments that are not meant to have a direct connection, then a backdoor has been introduced that can be exploited by attackers.
• Mismatched IPSec end-points. This results in sensitive traffic remaining unprotected as it transits the network instead of flowing through the secure IPSec tunnel.
• Adequate authentication is not used between devices for exchanging routing protocol infor- mation. An attacker can connect to a network device and extract or inject spurious routing information.
Quality of Service.
IP traffic with demanding network latency and packet-loss rate requirements, such as Voice over IP (VoIP) and financial services applications, requires appropriate Differentiated Services and other QoS configurations in the network devices. In a large net- work, it is easy to make errors in the QoS configura- tions. Examples of such errors include:
• Incorrect bandwidth or queue allocation on de- vice interfaces for higher priority traffic. Dur- ing high-load periods, higher priority traffic will not receive its due bandwidth or queue, resulting in higher latency or packet-loss.
• Inconsistent QoS policy definitions and usage across multiple devices. The same QoS policy
270
may be implemented differently across mul- tiple devices, resulting in application traffic receiving different treatment at the different devices, which can impact latency and packet- loss during periods of high-load.
REGULATORS EXPECT COMPLIANCE
The world’s growing reliance on IP and the highly networked nature of government computing environ- ments have also motivated a wave of regulations to improve security, reliability, and QoS.
In the United States, the Federal Information Se- curity Management Act (FISMA) of 2002 requires fed- eral agencies to develop, document, and implement security programs.5 Office of Management and Bud- get (OMB) Circular A-130 (an implementation guide- line for FISMA), establishes, among other things, a minimum set of controls to be included in automated, inter-connected information resources.6 The National Institute of Standards and Technology (NIST) has promulgated security requirements, for protecting the confidentiality, integrity, and availability of fed- eral information systems and the information handled and transmitted by those systems.7 NIST’s “Guideline on Network Security Testing”8 recommends that se- curity testing be a routine part of system and network administration. It also directs organizations to verify that systems have been configured based on appropri- ate security mechanisms and policy. In addition, laws such as the Sarbanes-Oxley Act and Health Insurance Portability and Accountability Act, among others, are fueling the push for network protection.
Outside the United States, organizations such as the British Standards Institute (BSI), International Or-
271
ganization for Standardization (ISO), and Information Technology Infrastructure Library (ITIL) recognize the complexity of IP networks and the importance of security. In 2006, BSI published “Delivering and Man- aging Real World Network Security,” which explains that networks must be protected against malicious and inadvertent attacks and “meet the business re- quirements for confidentiality, integrity, availability, non-repudiation, accountability, authenticity and reli- ability of information and services. 9
MANY ASSESSMENT APPROACHES PROVE DEFICIENT
Many of the solutions for IP network configura- tion assessment have proven woefully inadequate. They fall generally into three categories: manual as- sessment, invasive systems, and noninvasive systems.
Manual Assessments.
In many organizations IP device configurations are large, complex software systems that depend on a hands-on, highly skilled administrator base for cre- ation, update, and troubleshooting. Given the size of many networks and the cost of labor, the manual ap- proach has obvious limitations. One large U.S. federal agency, for example, has 10 five-person teams han- dling manual analysis of device configurations for its 120 locations.
Invasive Systems.
Invasive scanning solutions, such as ping, trace- route, and their commercial variants, send traffic to
272
devices in the network and use the responses to assess compliance. Such approaches work for simple usage, such as demonstrating IP connectivity between net- work nodes and identifying the software version on the devices. However, when it comes to rigorous as- sessment, they have serious shortcomings, including:
• No root-cause analysis. They can detect prob- lems, but offer little, if any, help in diagnosing the configuration errors that caused them.
• Nonscalable. They cannot deliver “all” or “none” results, which generally require a huge number of tests. For example, to confirm that “There is connectivity between all pairs of in- ternal subnets,” connectivity tests are required for the number of subnets squared.
• No testing requirements on contingencies. Contingencies may be security breaches, com- ponent or link failures, changes in traffic condi- tions, or changes in requirements themselves. It is impractical to simulate contingencies on a network that supports real-time and critical services. For example, to detect the existence of a single point of failure, one would have to fail each device and check whether the end-to-end requirement still holds.
• Potential to disrupt network operations. Inva- sive scanning can introduce malware into a net- work, or inadvertently exploit a vulnerability that brings down a device.
Noninvasive Systems.
Noninvasive solutions include network simula- tion tools and Network Change and Configuration Management (NCCM) systems, which are analogous to software version control systems like Concurrent
273
Versioning System (CVS) and Source Code Control System (SCCS). Such systems tend to treat configu- rations as “blobs,” and support IP device configura- tion backups, upgrades, controlled rollbacks, and maintainability of device configurations. While these capabilities are important, they are not sufficient for detecting issues that must be proactively resolved to ensure that the network continuously satisfies service requirements.
Noninvasive assessment is preferable to manual and invasive assessment because it does not impact ongoing network operations, but many of the existing systems have limitations, including:
• Individual-device assessments. Configuration management tools assess individual devices in isolation using a template-based approach, even though structural vulnerabilities are of- ten created by interactions between protocols across multiple devices. Even nonsecurity pro- tocols can interact improperly to create struc- tural vulnerabilities. For example, if redundant tunnels traverse the same physical router and that router fails, all tunnels fail.
• Nonscalable. Certain types of requirements, such as reachability, can be assessed by net- work simulation tools; however they can take hours to compute reachability for networks with more than 50 devices, because they simu- late each and every transition of the state ma- chine of each protocol, whether it is for routing, security, reliability, or performance.
274
TOWARD A SOLUTION THAT WORKS
Building on our long history of involvement in assuring all types of communications networks, Tel- cordia has spent years researching the issues of IP network reliability and security. Part of this work was funded by the Department of Homeland Security’s HSARPA office. That work has yielded important in- sight into the features and functions that an effective IP network configuration assessment solution must have, and all are capabilities that are achievable today.
Desirable Features of a Solution.
A scalable and effective solution for performing IP network assessments to detect configuration errors needs to possess the following features:
• Automatic and proactive network-wide, multi- device, and multivendor assessments against a comprehensive and updatable knowledge base that considers the network in its entirety and not just at a per-device level. The knowledge base should include rules for best current prac- tices, regulatory compliance, and customer- specific requirements.
• Findings should visualize noncompliant rules and devices down to the “root” cause, eliminat- ing speculation about cause.
• Nonintrusive, detailed, multilevel visualiza- tions for physical connectivity, IP subnets, routing, VLAN, VPN, and MPLS. These visu- alizations, and the service reachability analy- sis mentioned below, can be computed using graph theory algorithms on data from the con- figurations.
275
• Service reachability analysis that visualizes path and single points of failure between net- work devices without generating traffic on the network.
• Network change impact analysis using the rules knowledge base, so new or changed con- figurations can be analyzed to detect errors be- fore deployment to devices.
• Automated reconciliation of configuration and inventory information to identify and eliminate inconsistencies and errors.
Configuration Extraction.
Network and security administrators are generally reluctant to share IP network device configurations be- cause they include sensitive information such as pass- words and IP addresses. IP address anonymization and password obfuscation tools are of limited benefit since their usage tends to result in critical information being removed and lost from the configurations. The loss of this information makes the configuration as- sessments less effective. So for any configuration as- sessment solution to obtain complete configurations from administrators, it needs to provide assurances that their configurations will be adequately protected.
The most effective approach for acquiring configu- rations is for the configuration assessment solution to have direct read-only access to the IP network devices for extracting the configurations using device vendor- supported technologies such as secure FTP or remote copy. This direct approach ensures that the most cur- rent configuration information is securely retrieved without modification by administrators, and any other device-specific data relevant for validation can also be
276
retrieved. Another approach is to rely on backups of device configurations from a file-system. Most organi- zations maintain versions of their IP network device configurations on a file system as backups, to be used to recover a device after its failure or for rolling-back configurations after an unsuccessful configuration change. The configuration assessment solution can ac- quire these backed-up configurations automatically, either periodically or every time new configurations appear in the backup file-system.
Configuration Adaptors.
Supporting the desirable features identified above requires detailed information from the device con- figurations. Since every IP network device vendor has their individual configuration language, software adaptors are needed that can extract the detailed in- formation from vendor-specific format (e.g. Cisco IOS, Checkpoint, etc.), and convert the information into a vendor-neutral representation. Based on our expe- rience, the adaptors need to extract as many as 750 attributes from a single configuration to support the desired features, as compared to less than 100 that are extracted by NCCM systems.
Telcordia IP Assure.
Telcordia’s IP Assure solution (www.telcordia. com/products/ip-assure) satisfies many of the re- quirements discussed previously for IP network con- figuration validation. Figure 11.2 illustrates the high- level information flow that is supported in IP Assure. Solution details can be obtained by contacting the au- thor.
277
Figure 11.2. Telcordia IP Assure Information Flow.
SUMMARY
IP networks are no longer optional throughout the business and government sectors. This fact, along with the emergence of international regulations on security, reliability, and QoS, means that IP network assessment is a necessity. Many existing solutions on the market, including troubleshooting by skilled ad- ministrators, traffic-based vulnerability and penetra- tion testing, NCCM software, and network simulation tools, do not (and cannot) fulfill the world’s increas- ingly rigorous objectives. However, the technology exists today for a nonintrusive and comprehensive IP network assessment solution. Such a solution can provide auditable validation of regulations, eliminate IP network downtime caused by configuration errors, and stop the cyber attacks that exploit those errors. Telcordia IP Assure is an example of such a solution that is available today.
278
ENDNOTES - CHAPTER 11
1. “Securing Cyber Space for the 44th Presidency,” Wash- ington, DC: The Center for Strategic and International Studies (CSIS), December 2008, available from www.csis.org/media/csis/ pubs/081208_securingcyberspace_44.pdf.
2. British Telecom/Gartner Study, “Security and business continuity solutions from BT,” available from www.btnet.cz/ business/global/en/products/docs/28154_219475secur_bro_single.pdf.
3. Ibid.
4. L. Gordon et al., CSI/FBI Computer Crime and Security Survey, 2006, available from www.cse.msu.edu/~cse429/readings06/ FBI2006.pdf.
5. Federal Information Security Management Act (FISMA) of 2002, available from csrc.nist.gov/policies/FISMA-final.pdf.
6. “Security of Federal Automated Information Resourc- es,” OMB Circular A-130, Appendix III, available from www. whitehouse.gov/omb/circulars/a130/a130appendix_iii.html.
7. “Minimum Security Requirements for Federal Information and Information Systems,” FIPS-200, published by NIST, available from csrc.nist.gov/publications/fips/fips200/FIPS-200-final-march.pdf.
8. “Guideline on Network Security Testing,” SP800-42, published by NIST, available from csrc.nist.gov/publications/nistpubs/800-42/ NIST-SP800-42.pdf.
9. “Delivering and Managing Real World Network Secu- rity,” British Standards Institute, 2006, available from www. bsi-global.com/en/Standards-and-Publications/Industry-Sectors/ICT/ ICT-standards/BIP-0068/.
279
CHAPTER 12
ON THE NEW BREED OF DENIAL OF SERVICE (DOS) ATTACKS IN THE INTERNET
Nirwan Ansari Amey Shevtekar
INTRODUCTION
Denial of Service (DoS) attacks impose serious threats to the integrity of the Internet. These days, attackers are professionals who are involved in such activities because of financial incentives. They bring higher sophistication to the attack techniques that can evade detection. A shrew attack is an example of such a new threat to the Internet; it was first reported in 2003, and several of these types of attacks have emerged since. These attacks are lethal because they can evade traditional attack detection systems. They possess several traits, such as low average rate and the use of TCP as attack traffic, which empowers them to evade detection. Little progress has been made in mitigating these attacks. This chapter presents an overview of this new breed of DoS attacks along with proposed detection systems for mitigating them. The analysis will hopefully lead to a better understanding of these attacks, and help to stimulate further devel- opment of effective algorithms to detect such attacks and to identify new vulnerabilities which may still be dormant.
The Internet has become an integral part of various commercial activities like online banking, online shop- ping, etc. However, the Internet has been plagued by a variety of security threats over the past several years.
280
The Distributed Denial of Service (DDoS) attacks re- ceived much attention after 2000 when yahoo.com was attacked. After that event, DDoS attacks have been rampaging throughout the Internet. DDoS News,1 has since been keeping track of DDoS related news. A tre- mendous amount of work has been done in the indus- try and academia to mitigate DDoS attacks, but none have been able to successfully eradicate them. The motivations for launching attacks have shifted signifi- cantly. Initially, they were for publicity, but now they are for economic or political incentives. Thus, DDoS attacks are a prevalent and complex problem.
Figure 12.1 depicts the trend of DDoS attacks in the Internet. The x-axis indicates the efficiency of the at- tack, indicating how much damage it can cause to the good traffic. The y-axis indicates the detectability of the attack, indicating the exposure of the attack to de- fense systems. The early brute force attacks relied on sending high rate attack traffic continuously to a web- site. They are now easily detected because many de- fense systems can distinguish such anomalous attack traffic.2 The shrew and Reduction of Quality of Ser- vice (RoQ) attacks are emerging low rate DoS attacks that are difficult to detect as compared to the brute force attack, but they primarily affect only long-lived TCP traffic. One major contribution of this chapter is to forewarn and model the emerging sophisticated at- tacks, because attacks have a higher impact on good traffic and yet they are very evasive.
281
Figure 12.1. The Trend of DDoS Attacks in the Internet.
TRADITIONAL BRUTE FORCE ATTACKS
A Denial of Service (DoS) attack is defined as an attack that prevents a network or a computer from providing service to the legitimate users.3 It typically targets the bandwidth of the victim. A DDoS attack is defined as an attack that uses multiple unwilling computers to send the attack traffic to the victim. A DDoS attack is more lethal since it exerts a large ca- pacity of attack traffic as compared to a DoS attack. These attacks are also referred to as brute force at- tacks, since they send attack traffic at high rates and lack characteristics required to be stealthy. There are several types of brute force DDoS attacks that have been reported in the literature, a few of the commonly used attacks are described below. DDoS attacks can be characterized as shown in Figure 12.2.4 DDoS attacks can be classified by the degree of automation, i.e., the level of sophistication of the attack mechanism.
282
Figure 12.2. Classification of DDoS Attacks.
Early attacks were manual, and were improved gradually. In a manual attack,5 the victims are scanned for a particular vulnerability which is exploited by the attacker to gain access into the victim’s system. An at- tacker then use commands to control the victim dur- ing the attack. In a semi-automatic attack, some steps of the attack procedure, which were originally manu- ally performed become automated; for example, some of the victims are compromised to act as attack agents who coordinate the attack by issuing commands to con- ceal the identity of the real attacker even if the attack is detected.6 The attack agents are preprogrammed with the necessary required commands. All of the recent attacks have been highly automatic requiring minimal communication between the attacker and the compro- mised machines once the attack was launched. All the attack steps are preprogrammed and delivered as a payload to infect clients, also referred to as zombies or
283
bots. Some new attack payloads, which fail to detect a specific vulnerability in a victim machine, will au- tomatically scan for another vulnerability in the same machine. Recent botnet attacks on Estonia’s websites employed fully automated mechanisms.7 Botnet is a network of bots or zombies controlled by a botmaster.8
Classification of DDoS attacks based on an exploit- ed vulnerability takes into account the property of the network or the protocol used in the attack. The catego- ry to which the flood attack belongs is the simplest of all categories and is one in which an attacker relies on denying the network bandwidth to the legitimate us- ers. The common example of this category is the UDP flood attack.9 In a UDP flood, an attacker sends UDP packets at a high rate to the victim so that the network bandwidth is exhausted. UDP is a connectionless protocol, and therefore it is easy to send UDP pack- ets at any rate in the network. Another attack in this category is the ICMP echo flood; it involves sending many ICMP echo request packets to a host. The host replies with an ICMP echo reply to each of the two ICMP echo request packets, and many such requests and reply packets fill up the network bandwidth.
In the category of amplification attack, an attacker exploits a protocol property such that few packets will lead to amplified attack traffic. The DDoS “SMURF” attack, which exploits the ICMP protocol,10 falls in this category. It involves replacing a source IP address of the ICMP echo request packet with the address of the victim. The destination address of the ICMP echo re- quest is the broadcast address of the LAN or so-called directed broadcast addresses. On receiving such a packet, each active host on a LAN responds with an ICMP echo reply packet to the victim. Typically, a LAN has many active hosts, and so a tremendous amount
284
of attack traffic is generated to cripple the victim. To avoid such an attack, most system administrators are advised to disable the directed broadcast addresses.
In the category of protocol exploit, a property of the protocol is exploited. The SYN attack11 exploits the TCP protocol’s three-way handshake mechanism. Web servers use port 80 to accept incoming HTTP traffic that runs on top of the TCP protocol. When a user wants to access a webpage, it sends a SYN packet to the web server’s open port 80. The web server does not know the user’s IP address before the arrival of the SYN packet. The server, upon receipt of a SYN packet, sends a SYN/ACK packet, and thus puts the connec- tion in the LISTEN state. A legitimate user’s machine replies to the web server’s SYN/ACK packet with an ACK packet and establishes the connection. However, if the SYN packet has been sent from an attack machine which does not respond to the server with an ACK packet, the web server never gets an ACK packet and the connection remains incomplete. Every web server has a finite amount of memory resources to handle such incomplete connections. The main goal of the SYN attack is to exhaust the finite amount of memory resources of a web server by sending a large number of SYN packets. Such an attack causes the web server to crash. Another similar protocol exploit attack is the PUSH + ACK attack,12 which also falls in this category.
In the category of malformed packet attack, the packet header fields are modified to instigate a crash of the operating system of the receiver. An IP packet having the same source and destination IP address is a malformed packet.13 In another kind of malformed packet attack, the IP options fields of the IP header are randomized, and the type of service bit is set to one. A ping of death attack involves sending a ping
285
packet larger than the maximum IP packet size of 65535 bytes.14 Historically, a ping packet has a size of 56 bytes, and most of the systems cannot handle ping packets of a larger size. Operating systems take more time to process such unusual packets, and a large quantity of such packets can crash the systems.
DDoS attacks can also be classified by their attack rates, namely: continuous vs. variable. Likewise, they can also be classified by their impacts: disruptive vs. degrading. Disruptive attacks aim for denial of service while degrading attacks aim for reduction of quality.
NEW BREED OF STEALTHY DoS ATTACKS
Internet security is increasingly more challenging as more professionals are getting into this lucrative business. An article in the New York Times,15 describes one such business of selling the software exploits. Attacks are also getting more sophisticated, as the attackers are not merely interested in achieving pub- licity. The shrew attack is one such intelligent attack, which was first reported in Low-Rate TCP-Targeted Denial of Service Attacks in “The Shrew vs. the Mice and Elephants,”16 followed by a series of variants.17 This study considers these attacks as low rate DoS at- tacks. It is typically illustrated by a periodic waveform shown in Figure 12.3, where T is the time period, t is the burst period, and R is the burst rate.
286
Figure 12.3. An Example of a Generic Low Rate DoS Attack Pattern.
A shrew attack exploits widely implemented mini- mum RTO,18 property of the TCP protocol. The follow- ing characterize the low rate TCP DoS attack:
• It sends periodic bursts of packets at one-sec- ond intervals.
• The burst rate is equal to or greater than the bottleneck capacity.
• The burst period is tuned to be equal to the round-trip times of the TCP connections; this parameter determines whether the attack will cause DoS to the TCP connections with small or long round-trip times.
• The exponential back off algorithm of the TCP’s retransmission mechanism is eventually exploited.
In a Reduction of Quality of Service (RoQ) attack,19 the attacker sends high rate short bursts of the attack traffic at random time periods, thereby forcing the adaptive TCP traffic to back off due to the temporary congestion caused by the attack bursts. In particular, the periodicity is not well defined in a RoQ attack, thus allowing the attacker to keep the average rate of the attack traffic low in order to evade the regu- lation of adaptive queue management like RED and
287
RED-PD.20 By sending the attack traffic, the RoQ attack introduces transients and restricts the router queue from reaching the steady state. The awareness of these stealthy attacks demands early fixes. For simplic- ity, the term “low rate DoS attack” refers to both the shrew and the RoQ attack, unless otherwise stated as shown in Figure 12.3. The attacker can also use differ- ent types of IP address spoofing to evade several other detection systems. Owing to the open nature of the In- ternet, IP address spoofing can still evade ingress and egress filtering techniques at many sites.21 A low rate DoS attack can use IP address spoofing in a variety of ways like random IP address spoofing and continuous IP address spoofing.22 The use of IP address spoofing most importantly divides the high rate of a single flow during the burst period of the attack among multiple flows with spoofed identities. This way, an attacker can evade detection systems that concentrate on find- ing anomalous traffic rate. The detection systems that rely on identifying periodicity of the low rate DoS at- tack in the frequency domain can detect the periodic- ity, but they fail to filter the attack traffic because it is difficult to know the IP addresses that an attacker will use in the future.
This problem is further exacerbated by the use of botnets; a botnet is a network of compromised real hosts across the Internet controlled by a master.23 Since an attacker using botnets has control over thou- sands of hosts, it can easily use these hosts to launch a low rate DoS attack; this is analogous to a low rate DoS attack that uses random or continuous IP ad- dress spoofing. Now, with the use of botnets, the IP addresses of bots are not spoofed and so these packets cannot be filtered by spoofing-prevention techniques. In fact, these attack packets are similar to the HTTP
288
flows. This random and continuous IP address spoof- ing problem described above is unique to the low rate DoS attacks, and is different from other types of DDoS attacks. These attacks24 can be launched from any routers in the Internet; the edge routers can be easy targets as their capacities are small, and hence attack- ers can easily incite denial of service to the VoIP users traversing those routers. Low rate DoS attacks fall in the DDoS attack category of variable attack rate and degrading impact.
The perfect attack25 is the latest attack model which is extremely lethal as compared to the attack models discussed before. The perfect attack has the ability to disguise itself as a normal traffic, thereby making detection difficult. It relies on using readily available botnets to send the attack traffic. Botnets are formed at an alarming rate today because of increasing vulner- abilities in various software applications. The users of these applications are often average users who are not security conscious, thus leaving their systems exposed to exploitations. Social engineering attacks are also used to increase the bot population. Thus, all these conditions create a breeding ground for rogues to de- velop new attacks. The perfect attack model consists of two parts: an initial, short, deterministic high-rate pulse, and a feedback-driven sustained attack period with a network-adaptive attack rate, as depicted in Figure 12.4.
289
Figure 12.4. Attack Traffic for a Perfect DDoS Attack.
To accomplish the objectives identified above, a perfect attack is envisioned to be executed as follows. The attack traffic is injected from a botnet toward a target with a bottleneck queue as described in Figure 12.4. Initially, a high-rate pulse is sent at a rate of r for a duration of t that overflows the buffer such that all packets are dropped. This pulse is similar to a shrew pulse, with the main difference that it only occurs at the beginning, once or twice, to drop all the packets in the queue. Thus, after this pulse, it is assumed that all long-lived TCP flows are in a timeout state, and thus do not send traffic. The only legitimate traffic that ar- rives immediately after the pulse is flow that is being established.
Thus, in the phase after the pulse, the attacker must fill the bottleneck queue with its own traffic as fast as possible and to sustain this level. Ideally, this filling ensures that only a small fraction of legitimate packets ever passes the bottleneck. Such a high drop rate per flow implies that: (1) a large number of SYN packets are dropped; (2) TCP flows experience packet loss already in slow start; and (3) other non-TCP traf- fic incurs significant packet loss. Thus, in this second
290
phase, the attack traffic is sent according to the follow- ing pattern. Denote B(t) as the available bandwidth at the bottleneck and C as the link capacity of the at- tack target link. Then, the sustained attack traffic N(t) Equation (1) is: N(t) = C + B(t)
Under the assumption that all or the vast majority of the bottleneck bandwidth is consumed by the at- tack traffic, Equation (1) aims at maintaining a steady consumption. This attack traffic is the TCP traffic at a rate equivalent to the link capacity C. To fill the bottle- neck and to compensate for drops in the TCP attack rate, UDP traffic at a rate of B(t) is injected into the network. Note here that the UDP traffic is a function of the available bandwidth rather than the capacity as in a shrew attack or an RoQ attack. N(t) is periodically updated and adjusted with the time period T. The up- date contains a rate adaptation but also the chance to exchange the zombies in the attack to create a diverse traffic pattern from different traffic sources. Thus, at the bottleneck, N(t) creates a traffic pattern consisting of a superposition of many TCP flows, with a small fraction of UDP traffic, whose sources vary over time. After each period T, a new set of TCP flows are di- rected at the bottleneck link. These TCP flows begin in the slow start phase of TCP and end in the slow start phase as well. It is important to keep the attack TCP flows in slow start because they have been shown to affect long-lived TCP flows on shorter timescales, and also introducing a new TCP connection allows the congestion window to grow rapidly, otherwise attack TCP flows will enter congestion avoidance phase and will try to share the bandwidth with the legitimate TCP flows. The period T can be random so as to evade detection particularly for systems that try to find the deterministic attack pattern. Note that this interplay
291
between TCP and UDP further complicates the detec- tion. In contrast to the shrew attack where the repeti- tive pulses can be relatively detected, the perfect at- tack does not create such a repetitive pattern. Instead, the dynamics lead to an ever changing traffic pattern that cannot be observed and captured by the defense.
DEFENSE SYSTEMS
Mitigating DDoS attacks is a widely studied prob- lem, and some of the popular approaches are de- scribed below. Defense systems can be broadly clas- sified based on their functions. There are four main categories of defense systems: intrusion prevention, intrusion detection, intrusion response, and intrusion mitigation.26
Intrusion prevention systems prevent an attack from occurring. Ingress and egress filtering control IP address spoofing that is used in the attack. Ingress filtering only allows packets destined for the source network to enter the network, thereby filtering all other packets. It is implemented at the edge routers of the network, and it limits the attack traffic from enter- ing the network. Egress filtering is an outbound fil- ter that allows only packets with source IP addresses originated from the source network to exit the source network. Use of egress filtering controls attack traffic going to destination networks.27 Disabling IP broad- casts prevents smurf attacks. Honeypots are network decoys,28 that study attack behavior before the onset of an attack. Honeypots act as early warning systems. Honeypots mimic all aspects of a real network like a web server and a mail server to lure attackers. The primary goal of the honeypots is to determine/derive the exploit mechanism of the attack in order to build
292
defense signatures against the exploit. Intrusion pre- vention systems cannot completely prevent an attack, but they contain the damage of the attack. They allow building better defense systems by analyzing the at- tack.
Intrusion detection systems detect an attack based on attack signatures or anomalous behaviors. Snort is a popular signature based network intrusion detec- tion system.29 It performs protocol analysis and con- tent matching to passively detect a variety of attacks like buffer overflows, port scans, and web application attacks. Snort uses Berkeley’s libpcap library to sniff packets. It uses a chain structure to maintain rules. The header of each chain is a tuple of source IP address, destination IP address, source port, and destination port. Various rules are then attached to the header so that packet information is matched to a header and the corresponding rules to detect an intrusion.
Anomaly detection systems rely on detecting shift in the normal traffic patterns of the network. The Reference A network management system is widely deployed in the Internet and is effectively used for intrusion detection. Consider the ping flood attack in which many ICMP echo request packets are sent to the target. The SNMP ICMP MIB group has a variable icmpInEchos, which shows the sudden increase in its count during the ping flood attack. During the UDP flood attack, SNMP UDP MIB group’s udpInData- grams shows a similar increase in its count. To detect localized variations in important MIB variables, a time series is segmented in small sub-time series which are compared to the normal profiles. In a DDoS attack, variations are so intense that averaging the time series on properly chosen time intervals enables anomaly detection.
293
The examples discussed above are network based intrusion detection systems, but intrusion detection can also be performed at a host. A data mining based approach is one such method.30 Datasets consisting of normal and abnormal data points are gathered and fed to a classification algorithm to obtain classifiers. Once trained on these classifiers the training datasets are then used to find abnormal data points. D-WARD31 is an intrusion detection system to be installed at the network edges to detect attack sources. It monitors network traffic rates to determine asymmetry in the traffic rate. Typically in a DDoS attack like the SYN at- tack, there are more SYN packets leaving the network as compared to ACK packets entering the network. D-WARD attempts to stop the attacks close to the sources so that network congestion is reduced. Attack traffic even affects traffic not intended for the victim, and thus D-WARD also minimizes the collateral dam- age from the attack. Figure 12.5 shows the conceptual diagram of the PPM scheme where each router marks packets probabilistically so that the victim can recon- struct the entire path from the source router.32
Intrusion response systems are required to find the source of the attack in order to stop the attack. Blocking the attack traffic is sometimes done manually by con- tacting network administrators who change the filtering policies to drop the attack traffic at routers. If an attack- er is using source IP address spoofing, manual filtering is not useful and schemes like IP traceback are required. IP traceback traces the IP packets back to their sources and helps reveal attack sources.33 In probabilistic packet marking (PPM)34 shown in Figure 12.5, routers mark their addresses on packets that traverse through them. Packets are selected randomly with some fixed prob- ability of marking. Upon receiving many packets a vic-
294
tim can construct the route back to the sources by read- ing router marks. Router vendors need to enable the marking mechanism, so ISP participation is required. This scheme does not require additional overhead bandwidth, which is an important advantage of this scheme. In contrast, a scheme referred to as determin- istic packet marking (DPM),35 shown in Figure 12.6, only marks packets passing through edge routers of the network. At the victim, a table is maintained for mapping between source addresses and router in- terface addresses. This facilitates the reconstruction and identification of the source of the packets. Some countermeasures to mitigate the low rate DoS attacks in the Internet have been reported although none of them has made a comprehensive attempt to address such attacks with IP address spoofing.
Figure 12.5. Conceptual Diagram of the PPM Scheme.
295
Figure 12.6. Conceptual Diagram of the DPM Scheme.
Pushback, also known as aggregate congestion control scheme (ACC),36 drops DDoS attack traffic by detecting the attack and sends signals to drop the attack traffic closer to the source as shown in Figure 12.7. The rationale behind the pushback scheme is that the attack traffic has a unique signature in an attack, where the signature consists of identifiers such as port numbers, IP addresses, and IP prefixes. By detecting a signature in the aggregate attack traffic, upstream routers can be instructed to rate-limit flows that match the signature. A router in a pushback scheme has two components: a local ACC mechanism and a pushback mechanism.
The local ACC mechanism is invoked if the packet loss percentage exceeds a threshold of 10 percent. It then tries to determine the aggregate congestion sig- nature and correspondingly tries to rate limit the ag- gregate traffic. If the rate limiting does not reduce the arrival rate of the attack traffic below a predefined target rate, ACC invokes the pushback mechanism which sends pushback messages to the upstream rout- ers to filter the attack traffic. By repeating this scheme upstream, pushback aims at rate-limiting the attack traffic at the source network. Throttling is another approach to defend web servers from a DDoS
296
Figure 12.7. Conceptual Diagram of the Pushback Scheme.
attack. It uses max-min fairness algorithm to compute the rate to drop excess traffic. Upstream routers also participate in the scheme so as to drop the attack traf- fic near the source. There have been several ways to mitigate specific DDoS attacks like SYN attacks. A technique, referred to as a SYN cookie, avoids giving server resources to the SYN packet until a SYN/ACK is received.37
The autocorrelation and dynamic time warping al- gorithm38 relies on the periodic property of the attack traffic to detect the low rate DoS attacks. It proposes a deficit round-robin algorithm to filter the attack flows; however, it fails to drop attack packets when the at- tacker uses the continuous cycle and randomized IP address spoofing since each attack flow is a combi- nation of multiple flows and each will be treated as a new flow. Thus, the attacker can easily evade the filtering mechanism. The randomization of RTO pro- posed to mitigate the low rate TCP DoS attack cannot
297
defend against the RoQ attack, which targets the net- work element rather than the end host. The main idea reported in “Collaborative Detection and Filtering of Shrew DDoS Attacks using Spectral Analysis,” Journal of Parallel and Distributed Computing,39 is to randomize the minimum RTO instead of setting it to be one sec- ond. However, it ignores the advantages of having the minimum RTO of one second, which was chosen as a balance between an aggressive value and a conserva- tive value.
The Collaborative Detection and Filtering scheme proposed in, “Collaborative Detection and Filtering of Shrew DDoS Attacks using Spectral Analysis,”40 involves cooperation among routers to throttle and push the attack traffic toward the source. They rely on the autocorrelation property to distinguish the peri- odic behavior of attack traffic from legitimate traffic. Thus, it needs extra DSP hardware for implementa- tion and extra memory to store the flow information of the attack packets to be dropped. The scheme main- tains a malicious flow table and a suspicious flow table, which can be overwhelmed under the presence of the IP address spoofing. The novel part is the cu- mulative traffic spectrum that can distinguish traffic with and without the attack. In the traffic spectrum with the attack, the energy is found more localized at lower frequencies. The attacker can randomize the attack parameters in the RoQ attack. This work does not provide clear guidelines to activate the filtering of attack packets.
The wavelet based approach identifies the abnor- mal change in the incoming traffic rate and the out- going acknowledgments to detect the presence of low rate TCP DoS attacks.41 This approach cannot regulate the buffer size so that the attack flows can be detected as high rate flows by the RED-PD filter, and therefore
298
the approach was subsequently dropped.42 This work does not consider the RoQ attack in their analysis; it is difficult for this approach to detect the RoQ attack because the average rate of an RoQ attack is very low. The buffer sizing scheme fails if an attacker uses IP address spoofing because the high rate attack flow is a combination of multiple low rate individual flows. A modified AQM scheme referred to as HAWK43 works by identifying bursty flows on short timescales, but lacks good filtering mechanisms to block the attack flows that can use the IP address spoofing. This ap- proach can penalize the legitimate short bursty flows, thereby reducing their throughput. A filtering scheme similar to HAWK is proposed to estimate the bursty flows on shorter and longer time scales.44 The main idea is to use per-TCP flow rate as the normal rate, and anything above that rate is considered abnormal. The identification of flow rates is done online. On a shorter time scale, it is very easy to penalize a normal flow as a bursty flow. The proposal did not consider the random IP address spoofing, where every packet may have a new flow ID. It uses a very complex filter- ing technique. With the use of the IP address spoofing, it is difficult to come up with the notion of a flow, be- cause the number of packets per flow can be random- ized in any fashion during every ON period.
An edge router based detection system is proposed to detect low rate DoS attacks based on time domain technique.45 Each edge router acts as an entry and exit point for traffic originating from that local area net- work; essentially all incoming and outgoing traffic will pass through this point. The proposed detection system can be deployed at the edge routers of a lo- cal area network in which the server is present. For illustrative purposes, it is assumed that all clients are outside the local area network in which the server is
299
present, so that the detection system can monitor all flows connecting to the server.
Figure 12.8 shows the basic layout of the system. It has three basic blocks, namely, flow classifier, object module, and filter. Each block functions as follows. The flow classifier module classifies packets based on the flow ID by means of a combination of the IP source address, IP source port, IP destination address, and IP destination port. Flow information is obtained from these packets, and packets are forwarded as usual by the routing mechanism resulting in no additional de- lay apart from the lookup delay. The object module consists of various objects for each flow that is moni- tored. A flow is monitored until it is considered nor- mal. The filter is used to block flows that are identified as malicious by the object module. Consider a DoS at- tack which tries to exploit protocol shortcomings. The object module maintains per flow information by cre- ating objects per flow called flow objects. A thin data structure layer is designed to keep track of these flow objects. It maintains only those parameters which are exploited in the attack. This thin structure keeps track of information about flows classified as malicious. This information is then relayed to the filter module.
Figure 12.8. The Detection System Architecture.
300
The flow objects maintain the arrival times of pack- ets at the edge router in the pseudo transport layer. The malicious flow detection submodule of the object module computes the time difference of consecutive packets of each flow. The submodule computes the av- erage high and low of the time difference values. The average high value of the time difference repeats peri- odically for the attack flow; other flows do not exhibit this property. The malicious flow detection submod- ule then estimates the burst length of a flow based on the packet arrival times. A flow exhibiting periodicity in the time difference graph is marked malicious, since no legitimate flows will show such periodicity. The time difference technique uses a per-flow approach to store the arrival times of the packets belonging to each flow, and computes the interarrival times between the consecutive packets to detect periodicity. The attacker using IP address spoofing can easily deceive this sim- ple per-flow approach as the time difference approach will not be able to detect periodicity in the attack flow, which is no longer a single flow.
FUTURE RESEARCH DIRECTIONS
Mitigating perfect attack and low rate DoS attacks is extremely critical. Router based solutions that can identify and drop malicious attack traffic can be a pos- sible defense approach. Currently, both perfect and low rate DoS attacks are facilitated by botnets. Mitiga- tion of botnets can be another important step to pre- vent stealthy DoS attacks. Botnet detection and miti- gation is a serious challenge, because attackers find new vulnerabilities at a rapid pace. Secure software development that would be void of vulnerabilities is desirable. These research goals are known and emerg- ing everyday. On the other hand, isolating bots from
301
accessing the network by using better CAPTCHAs can be another approach to defend against botnets until such a time that we can completely eliminate bots.
CONCLUSION
In this chapter, we have presented a survey of sev- eral traditional brute force DoS attacks and examples of more recent stealthy DoS attacks. We have also in- troduced defense systems discussed in the literature, and identified some of their shortcomings. The focus of this chapter was to present some of the latest ad- vances in the area of DoS attacks to stimulate research for better defense systems and to reveal vulnerabili- ties that may exist.
ENDNOTES - CHAPTER 12
1. DDoS News, available from staff.washington.edu/dittrich/ misc/ddos/.
2. C. Douligeris and A. Mitrokotsa, “DDoS Attacks and De- fense Mechanisms: Classification and State-of-the-Art,” Computer Networks, Vol. 44, No. 5, 2004, pp. 643-666.
3. Ibid.
4. Ibid.
5. Ibid.
6. Ibid.
7. DDoS News.
8. D. Dagon, Z. Zhou, W. Lee, “Modeling Botnet Propagation Using Time Zones,” Network and Distributed System Security (NDSS) Symposium, 2006.
302
9. “UDP Port Denial-of-Service Attack,” available from www. cert.org/advisories/CA-1996-01.html.
10. “Smurf Attack,” available from www.nordu.net/articles/ smurf.html.
11. W. Eddy, “TCP SYN Flooding Attacks and Common Miti- gations,” IETF RFC 4987, 2007.
12. “Push + Ack Attack,” available from www.csie.ncu.edu. tw/~cs102085/DDoS/protocolexploit/push%2Back/description.htm.
13. Douligeris and Mitrokotsa.
14. “Ping of Death Attack,“ available from insecure.org/sploits/ ping-o-death.html.
15. “A Lively Market, Legal and Not, for Software Bugs,” available from www.nytimes.com/2007/01/30/technology/30bugs.ht ml?ex=1327813200&en=99b346611df0a278&ei=5088&partner=rssny t&emc=rss.
16. A. Kuzmanovic and E. Knightly, “Low-Rate TCP-Target- ed Denial of Service Attacks (The Shrew vs. the Mice and Ele- phants),” ACM SIGCOMM, 2003, pp. 75-86.
17. M. Guirguis, A. Bestavros, and I. Matta, “Exploiting the Transients of Adaptation for RoQ Attacks on Internet Resources,“ IEEE ICNP, 2004, pp. 184-195; S. Ebrahimi-Taghizadeh, A. Helmy, and S. Gupta, “TCP vs. TCP: a Systematic Study of Adverse Im- pact of Short-lived TCP Flows on Long-lived TCP Flows,” IEEE INFOCOM, 2005, pp. 926-937; X. Luo and R. K. C. Chang, “On a New Class of Pulsing Denial-of-Service Attacks and the Defense,” NDSS, 2005; A. Shevtekar and N. Ansari, “Do Low Rate DoS At- tacks Affect QoS Sensitive VoIP Traffic?” IEEE ICC, 2006, pp. 2153-2158; R. Chertov, S. Fahmy, and N. Shroff, “Emulation ver- sus Simulation: A Case Study of TCP-Targeted Denial of Service Attacks,” Tridentcom, 2006, pp. 316-325.
303
18. V. Paxon and M. Allman, “Computing TCP’s Retransmis- sion Timer,” IETF RFC 2988, 2000.
19. Guirguis, Bestavros, and Matta.
20. R. Mahajan, S. Floyd, and D. Wetherall, “Controlling High-Bandwidth Flows at the Congested Router,” IEEE ICNP, 2001, pp. 192-201; Y. Xu and R. Guerin, “On the Robustness of Router-based Denial-of-Service (DoS) Defense Systems,” ACM Computer Communications Review, Vol. 2, 2005, pp. 47-60; S. Floyd and V. Jacobson, “Random Early Detection Gateways for Conges- tion Avoidance,” IEEE/ACM, Transactions on Networking, Vol. 1, No. 4, 1993, pp. 397-413.
21. R. Beverly and S. Bauer, “The Spoofer Project: Inferring the Extent of Source Address Filtering on the Internet,” USENIX SRUTI, 2005, pp. 53-59.
22. Xu and Guerin.
23. Dagon, Zhou, and Lee.
24. Guirguis, Bestavros, and Matta.
25. A. Shevtekar, N. Ansari, and R. Karrer , “Towards the Per- fect DDoS Attack: The Perfect Storm,” IEEE Sarnoff Symposium, 2009, pp. 1-5.
26. Douligeris and Mitrokotsa.
27. P. Ferguson and D. Senie, “Network Ingress Filtering: Defeating Denial of Service Attacks which Employ IP Address Spoofing,” IETF RFC 2827, 2001.
28. W. R. Cheswick, “An Evening with Berferd, in Which A Cracker Is Lured, Endured, And Studied,” USENIX Winter Con- ference, 1992, pp. 163-174.
29. Snort IDS, available from www.snort.org.
30. W. Lee and S. Stolfo, “Data Mining Approaches for Intru- sion Detection,” USENIX Security Symposium, 1998, pp. 79-93.
304
31. J. Mirkovic, G. Prier, and P. Reiher, “Attacking DDoS at Source,” IEEE ICNP, 2002, pp. 312-321.
32. A. Belenky and N. Ansari, “On IP Traceback,” IEEE Com- munications Magazine, Vol. 41, No. 7, 2003, pp. 142-153.
33. Ibid.; Z. Gao, and N. Ansari, “Tracing Cyber Attacks from Practical Perspective,” IEEE Communications Magazine, Vol. 43, No. 5, 2005, pp. 123-131.
34. S. Savage, D. Wetherall, A. Karlin, and T. Anderson, “Net- work Support for IP Traceback,” IEEE/ACM, Transactions on Net- working, Vol. 9, No. 3, 2001, pp. 226-237.
35. A. Belenky and N. Ansari, “IP Traceback with Determin- istic Packet Marking,” IEEE Communication Letters, Vol. 7, No. 4, 2003, pp. 162-164.
36. R. Mahajan, S. Bellovin, S. Floyd, J. Ionnadis, V. Paxson, and S. Shenker, “Controlling High-bandwidth Aggregates in the Network,” ACM SIGCOMM CCR, Vol. 32, No. 3, 2002, pp. 62-73.
37. SYN cookies, available from cr.yp.to/syncookies.html.
38. H. Sun, J. C. S. Lui, and D. K. Y. Yau, “Defending Against Low-rate TCP Attack: Dynamic Detection and Protection,” IEEE ICNP, 2004, pp. 196-205.
39. Y. Chen, K. Hwang, and Y. Kwok, “Collaborative Detec- tion and Filtering of Shrew DDoS Attacks using Spectral Analy- sis,” Journal of Parallel and Distributed Computing, 2006, available from gridsec.usc.edu/files/publications/JPDC-Chen-2006.pdf.
40. Ibid.
41. X. Luo and R. K. C. Chang, “On a New Class of Pulsing Denial-of-Service Attacks and the Defense,” NDSS, 2005.
42. S. Sarat and A. Terzis, “On the Effect of Router Buffer Sizes on Low-Rate Denial of Service Attacks,” IEEE ICCCN, 2005, pp. 281-286.
305
43. Y. Kwok, R. Tripathi, Y. Chen, and K. Hwang, “HAWK: Halting Anomaly with Weighted ChoKing to Rescue Well-Be- haved TCP Sessions from Shrew DoS Attacks,” ICCNMC, 2005, pp. 2-4.
44. Y. Xu and R. Guerin, “A Double Horizon Defense for Ro- bust Regulation of Malicious Traffic,” SecureComm, 2006, pp. 1-11.
45. A. Shevtekar, K. Anantharam, and N. Ansari, “Low Rate TCP Denial-of-Service Attack Detection at Edge Routers,” IEEE Communication Letters, Vol. 9, No. 4, 2005, pp. 363-365.
307
ABOUT THE CONTRIBUTORS
NIRWAN ANSARI joined The New Jersey Insti- tute of Technology (NJIT) Department of Electrical and Computer Engineering as an Assistant Professor in 1988 and has been a full professor since 1997. Dr. Ansari is a senior technical editor of the IEEE COM- MUNICATIONS MAGAZINE, and also serves on the Advisory Board and Editorial Board of five other journals. He has been serving the IEEE in various ca- pacities such as: Chair of IEEE North Jersey COMSOC Chapter; Chair of IEEE North Jersey Section, Member of IEEE Region 1 Board of Governors; Chair of IEEE COMSOC Networking TC Cluster; Chair of IEEE COMSOC Technical Committee on Ad Hoc and Sen- sor Networks; and Chair/TPC Chair of several con- ferences/symposia. His current research focuses on various aspects of broadband networks and multime- dia communications. He has contributed around 30 patent applications, three have been issued and others are pending. Dr. Ansari authored Computational In- telligence for Optimization (New York: Springer, 1997, translated into Chinese in 2000) with E.S.H. Hou; and edited Neural Networks in Telecommunications (New York: Springer, 1994) with B. Yuhas. He also con- tributed over 300 technical papers, over one third of which were published in many noted journals/maga- zines. Dr. Ansari holds a B.S.E.E. (summa cum laude, gpa=4.0) degree from NJIT, Newark, NJ; an M.S.E.E. degree from University of Michigan, Ann Arbor, MI; and a Ph.D. degree from Purdue University,West La- fayette, IN.
308
MIKE CHUMER teaches and conducts research within the Information Systems Department of the New Jersey Institute of Technology. His research fo- cuses on command and control as used by the mili- tary and its application to emergency response dur- ing multi-agency collaboration such as experienced in Katrina and the recent Tsunami disasters. Dr. Chumer has written about command and control and is incor- porating that knowledge into command center opera- tions that benefit the public and private sectors during Homeland Security enabled emergency management. As a Marine Corps Officer, he started the first Systems Analysis and Design function at the United States Ma- rine Corps (USMC) Automated Services Center on Oki- nawa, Japan, and consulted with the Chinese Marines on Taiwan for the development of large mainframe and communication systems. He also worked with the C4 (command, control, communication, computers) organization at Headquarters Marine Corps, assisting in the design of satellite based battlefield information systems. He is co-editor of “Managing Knowledge: Critical Investigations of Work and Learning,” a book that investigates issues surrounding the present for- mulation of IT based Knowledge Management. Dr. Chumer holds a Ph.D. from Rutgers University in communication and information science.
ADEL ELMAGHRABY is Professor and Chair of the Computer Engineering and Computer Science Department at the University of Louisville. He has also held appointments at the SEI-CMU, and the Uni- versity of Wisconsin-Madison. He is a Senior Mem- ber of the IEEE and is active on editorial boards and conference organizations. Professor Elmaghraby’s research focus is in Network Performance and Secu-
309
rity Analysis, Intelligent Multimedia Systems, Neural Networks, PDCS, Visualization, and Simulation with applications to biomedical computing, automation, and military wargames.
ANUP GHOSH is a research professor at George Mason University and Chief Scientist in the Center for Secure Information Systems. He is also Founder and Chief Executive of Secure Command, Inc., a venture- backed security software start-up organization devel- oping next generation Internet security products. He was previously Senior Scientist and Program Manager in the Advanced Technology Office of the Defense Advanced Research Projects Agency (DARPA) where he managed an extensive portfolio of information as- surance and information operations programs. He is currently a member of the Committee on Information Assurance for Network-Centric Naval Forces for the Naval Studies Board, National Research Council. Dr. Ghosh is also author of three books on computer net- work defense.
THOMAS J. HOLT is an assistant professor in the School of Criminal Justice at Michigan State Univer- sity specializing in computer crime, cybercrime, and technology. His research focuses on computer hack- ing, malware, and the role that technology and the In- ternet play in facilitating all manner of crime and devi- ance. He is also the project lead for the Spartan Devils Chapter of the International Honeynet Project and a member of the editorial board of the International Journal of Cyber Criminology. Dr. Holt has published in academic journals, including Deviant Behavior and the Journal of Criminal Justice.
310
LOUIS H. JORDAN, JR., is the Deputy Director of the Strategic Studies Institute, U.S. Army War College, Carlisle, Pennsylvania. He recently returned from a deployment to Afghanistan where he served as Senior Military Advisor to the Afghan Deputy Minister of In- terior for Counter Narcotics. He is a graduate of Ford- ham University in the Bronx, NY, where he received a bachelor of arts degree in sociology. Colonel Jordan’s formal education includes a master’s degree in strate- gic studies from the U.S. Army War College and certi- fication in strategic planning from the American Man- agement Association. Colonel Jordan has served in aviation assignments from company through brigade and the national level including service at the Nation- al Guard Bureau as an operations officer, branch chief, and as the Deputy Division Chief of the Aviation and Safety Division. Colonel Jordan has commanded at the battalion, brigade, and joint task force level to include command of Joint Task Force Raven, the aviation task force for Operation JUMP START along the Southwest Border in Arizona.
DEBORAH WILSON KEELING is currently Chair- person of the Department of Justice Administration University of Louisville, KY, and is responsible for academic programs as well as the Southern Police In- stitute and National Crime Prevention Institute. Dr. Keeling has conducted numerous applied research projects for local, state, and federal criminal justice agencies. She has organized police training programs in the People’s Republic of China, Hungary, Roma- nia, and the Republic of Slovakia. Dr. Keeling holds a Ph.D. in sociology from Purdue University.
311
ANGELOS KEROMYTIS is an associate profes- sor in the Computer Science Department at Columbia University, New York. He is also the director of the Network Security Lab. His main research interests are in computer security, cryptography, and networking. He is an active participant in the Internet Engineer- ing Task Force and, in particular, the IPsec and IPSP working groups. He occasionally contributes to the OpenBSD operating system. He has been working on the KeyNote trust-management system and the STRONGMAN access control management system. Other projects he is/was involved in include AEGIS and SwitchWare.
YEHIA H. KHALIL worked from 1995-2005 as a researcher at the Informatics Technology Institute, Egypt, which provides IT consulting and training services. He has several publications and is a student member of IEEE. Mr. Khalil’s research is focused on methods to identify and augment cyber infrastruc- ture resiliency. He holds a B.S. in computer science and statistics from Alexandria University, Egypt, a master’s degree in operations research and computer science from the Arab Academy of Science and Tech- nology, Egypt, and is currently a Ph.D. candidate in computer science and engineering at the University of Louisville, KY.
MICHAEL LOSAVIO is an attorney working on issues of law, society, and information security in the Department of Justice Administration and the Depart- ment of Computer Engineering and Computer Science at the University of Louisville; he is also teaching and training in these areas. He holds a J.D and a B.S. in mathematics from Louisiana State University.
312
TAREK N. SAADAWI is Professor and Director of the Center for Information Networking and Telecom- munications (CINT), City College, The City Univer- sity of New York. His current research interests are telecommunications networks, high-speed networks, multimedia networks, AD-HOC mobile wireless net- works and secure communications. Dr. Saadawi has been on the Consortium Management Committee (CMC) for ARL Consortium on Telecommunications (known as Collaborative Technology Alliances on Communications and Networks, CTA-C&N), 2001- 2009. He has published extensively in the areas of telecommunications and information networks. Dr. Saadawi is a co-author of the book, Fundamentals of Telecommunication Networks (New York: John Wiley & Sons, 1994) which has been translated into Chinese. He was the lead author of the Egypt Telecommunica- tions Infrastructure Master Plan covering the fiber network, IP/ATM, DSL, and the wireless local loop under a project funded by the U.S. Agency for Inde- pendent Development. He joined the U.S. Department of Commerce delegation to the Government of Alge- ria addressing rural communications. Dr. Saadawi is a Former Chairman of IEEE Computer Society of New York City (1986-87). He holds a B.S. and M.S. from Cairo University, Egypt, and a Ph.D. from the Univer- sity of Maryland, College Park.
DOUGLAS SALANE has held positions with Exxon Corp., Sandia National Laboratories, and Ar- gonne National Laboratories. He has been a faculty member at John Jay College of Criminal Justice, The City University of New York, since 1988. For 12 years, he served as coordinator of the College’s Computer
313
Information Systems Major and is currently a mem- ber of the graduate faculty in Forensic Computing. He teaches graduate courses in network forensics and data communication security. In 2006, Dr. Salane be- came the director of the Center for Cybercrime Stud- ies at John Jay. The Center brings together expertise in law, computing, and the social sciences in an effort to understand and deter computer related criminal activity. Dr. Salane is a member of the Association for Computing Machinery (ACM), Institute of Electri- cal and Electronics Engineers (IEEE), and the Society for Industrial and Applied Mathematics (SIAM). Dr. Salane holds a Ph.D. in applied mathematics with a specialization in numerical analysis.
AMEY SHEVTEKAR completed an internship at Deutsche Telekom Laboratories, Berlin, Germany, in 2007. He has contributed several technical papers and has filed two U.S. patents. He is currently working for Lumeta Corporation. His research focuses on network security. Dr. Shevtekar holds a B.S. in electronics and telecommunications engineering from University of Mumbai, India, an M.S. degree in telecommunications from the New Jersey Institute of Technology (NJIT), and a Ph.D. in computer engineering from NJIT.
J. EAGLE SHUTT is a former prosecutor and pub- lic defender and currently is an assistant professor at the Department of Justice Administration, University of Louisville, KY. He also serves as a JAG officer with the South Carolina National Guard. His research in- terests include biosocial criminology, culture, public policy, and law. Dr. Shutt holds a J.D., an M.C.J., and a Ph.D.
314
STUART STARR is a Distinguished Research Fel- low at the Center for Technology and National Se- curity Policy, National Defense University, Fort Mc- Nair, Washington, DC. Concurrently, he serves as President, Barcroft Research Institute (BRI), where he consults on Command and Control (C2) issues, serves on senior advisory boards to defense industry (e.g., Northrop Grumman, Titan), lectures to audiences worldwide on C2 issues, and participates on Blue Rib- bon panels (e.g., member of the Army Science Board [ASB]; member of the National Research Council Task Force on Modeling and Simulation [M&S] to support the Transformation of DoD). He was a Fellow at MIT’s Seminar XXI during 1989-90. Dr. Starr holds a B.S. in electrical engineering from Columbia University, and an M.S. and a Ph.D. in electrical engineering from the University of Illinois.
RAJESH TALPADE is Chief Scientist and Direc- tor of the Information Assurance Group at Telcordia Applied Technology Solutions, with over 15 years experience in Internet, telecom, wireless, and security areas. He currently has responsibility for a new Tel- cordia software product in IP network management, and has led all product stages from concept to mar- ket. He has been the principal investigator for several Government-funded R&D projects, such as cyber at- tack traceback, IP device configuration error detection, and Distributed Denial of Service attack detection. Dr. Talpade holds and has several patents pending, has been guest editor of multiple journals, has given multiple invited talks, and has published numerous refereed papers and IETF RFC 2149. Dr. Talpade holds an M.B.A. from Columbia University and a Ph.D. in Computer science from the Georgia Institute of Tech- nology.
315
EDWARD WAGNER has worked as an informa- tion technology professional for clients within the De- partment of Defense. He has worked at the executive level within the Office of Secretary of Defense, and supported Joint and Service level programs. Mr. Wag- ner is currently a Project and Department Manager for Northrop Grumman. In addition to his professional career, he is a Reserve Lieutenant Colonel and the commander of the North East Information Operations Center. He is an adjunct professor for Strayer Univer- sity.
LARRY WENTZ is a Senior Research Fellow at the Center for Technology and National Security Policy, National Defense University, Fort McNair, Wash- ington, DC, and consults on Command and Control (C2) issues. He is an experienced manager, strategic planner, and C4ISR systems engineer with extensive experience in the areas of Nuclear C2, continuity of government C2, multinational military C2 and C3I systems interoperability, civil-military operations and information operations support to peace operations and numerous other military C4ISR activities. He also has extensive experience in business process reengi- neering, strategic planning, and commercial telecom- munications and information systems and their use in support of military C2. Mr. Wentz is a writer, author, and lecturer on multinational C4ISR systems interop- erability, information operations, and civil-military operations. He was a contributing author to the AF- CEA International Press book, The First Information War and CYBERWAR 2.0 and Canadian Peacekeeping Press book, The Cornwallis Group Series.
U.S. ARMY WAR COLLEGE
Major General Gregg F. Martin Commandant
*****
STRATEGIC STUDIES INSTITUTE
Director Professor Douglas C. Lovelace, Jr.
Director of Research Dr. Antulio J. Echevarria II
Editors Dr. Tarek Saadawi
Colonel Louis Jordan
Director of Publications Dr. James G. Pierce
Publications Assistant Ms. Rita A. Rummel
*****
Composition Mrs. Jennifer E. Nevil
Tarek Saadawi Louis Jordan, Jr. Editors
CYBER INFRASTRUCTURE
PROTECTION
CYBER INFRASTRUCTURE
PROTECTION
C y b
e r In
fra stru
ctu re
P ro
te ctio
n E d
ite d
b y
Ta re
k Sa
a d
a w
i Lo
u is Jo
rd a n
- CYBER INFRASTRUCTURE PROTECTION
- CONTENTS
- PREFACE
- CHAP 1 - INTRODUCTION by Tarek Saadawi and Louis Jordan
- STRATEGY AND POLICY ASPECTS
- LEGAL AND SOCIAL ASPECTS
- TECHNICAL ASPECTS
- ENDNOTES – CHAP 1
- PART I - STRATEGY AND POLICY ASPECTS
- CHAP 2 - DEVELOPING A THEORY OF CYBERPOWER by Stuart H. Starr
- INTRODUCTION
- ELEMENTS OF A THEORY
- Categorize.
- Figure 2.1. A Framework for Categorizing the Cyber Problem.
- Define.
- Explain.
- Connect.
- Figure 2.2. Representative Measures of Merit.
- Anticipate.
- Figure 2.3. State-of-the-Practice in Assessing Cyber Issues.
- KEY CHALLENGES
- ENDNOTES - CHAP 2
- CHAP 3 - SURVIVABILITY OF THE INTERNET by Michael J. Chumer
- INTRODUCTION
- SYMPOSIUM DATA COLLECTION
- CURRENT ESCALATING SITUATION
- GENERAL DISCUSSION
- Business Continuity Effects Due to Internet Reduced Availability with Examples of Healthcare and Education.
- Service Provider Collaboration for the Collective Good.
- Points of Internet Failure.
- The Effects on Computer Applications and/or Protocols.
- Increased Internet Demand.
- Hacker Attacks.
- Growing Internet Reliability.
- Internet Resilience.
- CONCLUSION
- ENDNOTES - CHAP 3
- APPENDIX
- ENDNOTES - APPENDIX
- REFERENCES
- CHAP 4 - ARE LARGE-SCALE DATA BREACHES INEVITABLE? by Douglas E. Salane
- INTRODUCTION
- NOTABLE BREACHES: INSTITUTIONS, CAUSES, AND COSTS
- MONETIZING THE CRIME
- CHALLENGES AND REMEDIES
- CONCLUDING REMARKS
- ENDNOTES - CHAP 4
- CHAP 5 - THE ROLE OF CYBERPOWER INHUMANITARIAN ASSISTANCE/DISASTER RELIEF (HA/DR) AND STABILITY AND RECONSTRUCTIONOPERATIONS by Larry Wentz
- INTRODUCTION
- ROLE OF CYBER AND CHALLENGES
- Figure 5.1. Mapping of Policy and Doctrine Documents and Ad Hoc Solutions.
- Figure 5.2. ICT Business Model.
- COMMERCIAL ICT CAPABILITY PACKAGES
- ICT STRATEGY FOR STABILITY AND RECONSTRUCTION OPERATIONS AFGHANISTAN EXAMPLE
- OBSERVATIONS
- ENDNOTES - CHAP 5
- PART II: SOCIAL AND LEGAL ASPECTS
- CHAP 6 - THE INFORMATION POLITY: SOCIAL AND LEGAL FRAMEWORKS FOR CRITICAL CYBER INFRASTRUCTURE PROTECTION by Michael M. Losavio, J. Eagle Shutt, and Deborah Wilson Keeling
- INTRODUCTION
- JURISDICTION AMONG DISTRIBUTED SOVEREIGNS
- LOCAL SUBSTANTIVE CRIMINAL LAW AND THE EXERCISE OF SOVEREIGNTY
- Figure 6.1. Evolving Law Enforcement Practice.
- Examples of Local Substantive Criminal Laws.
- Procedural Criminal Laws.
- Figure 6.2. The Use Path for Computational Forensic (CF) Results.
- A TRANSNATIONAL LEGAL REGIME AND COOPERATION ACROSS FRONTIERS—THE CONVENTION ON CYBERCRIME
- SOCIAL NORMS AND CRIMINOLOGICAL THEORY
- ADMINISTRATIVE ENGAGEMENT—MARSHALLING AND ENABLING EXISTING LAW ENFORCEMENT
- Figure 6.3. Involvement of Cell Phones In Violent Crimes.
- Figure 6.4. Inability to Search for Cell Phone Evidence Due to Timely Access to Forensic Examiners and Lack of Forensic Skills.
- Expanded Law Enforcement Engagement.
- CITIZEN ENGAGEMENT
- Direct Engagement—A Training Response.
- The Benefits of Engagement.
- CONCLUSION
- ENDNOTES - CHAP 6
- CHAP 7 - THE ATTACK DYNAMICS OF POLITICA LAND RELIGIOUSLY MOTIVATED HACKERS by Thomas J. Holt
- INTRODUCTION
- DATA AND METHOD
- FINDINGS
- Knowledge Among Turkish Hackers.
- Knowledge and Attack Methods.
- Religion, Politics, and Hacking.
- DISCUSSION AND CONCLUSION
- ENDNOTES - CHAP 7
- PART III: TECHNICAL ASPECTS
- CHAP 8 - RESILIENCE OF DATA CENTERS by Yehia H. Khalil and Adel S. Elmaghraby
- INTRODUCTION
- Figure 8.1. A Typical Data Center.
- Figure 8.2 . Data Center Roles Summary.
- Figure 8.3. Data Center Rational Elements.
- Figure 8.4. DC Facility Failure Process Summary.
- STATE OF THE ART
- Storage Research and Technologies.
- Table 8.1. SAN vs. NAS Summary.
- Figure 8.5. Elements of Storage Area Networks.
- Data Mirroring Techniques and Methodologies.
- Figure 8.6. Synchronous Data Mirroring Process.
- Figure 8.7. Asynchronous Data Mirroring Process.
- Figure 8.8. Data Mirroring Parameters and Attack Scenarios.
- Network Connectivity Alternatives.
- Figure 8.9. Data Center Network Roles Summary.
- Figure 8.10. Load Balancing with a Poor Parameters Tuning Scenario.
- Figure 8.11. Routing Protocols Concerns Summary.
- Security Challenges and Opportunities.
- Figure 8.12. Developing Attacks Process.
- Table 8.2. Vulnerabilities, Threats, and Attacks Categories Summary.
- Figure 8.13. Security Layers Summary.
- CONCLUSION
- ENDNOTES - CHAP 8
- CHAP 9 - DEVELOPING HIGH FIDELITY SENSORS FOR INTRUSION ACTIVITY ON ENTERPRISE NETWORKS by Edward Wagner and Anup K. Ghosh
- INTRODUCTION
- CURRENT ISSUES
- THE VIRTUAL ENVIRONMENT
- Figure 9.1. Internet Cleanroom Architecture.
- Figure 9.2. Collection Architecture.
- Figure 9.3. Security Architecture.
- Making Granular Data Capture Meaningful.
- Figure 9.4. Analyst’s Report View.
- Figure 9.5. MD5 Hash of Malware.
- CONCLUSIONS
- ENDNOTES - CHAP 9
- CHAP 10 - VOICE OVER IP: RISKS, THREATS, AND VULNERABILITIES by Angelos D. Keromytis
- INTRODUCTION
- Chapter Organization.
- VOIP TECHNOLOGIES OVERVIEW
- Session Initiation Protocol (SIP).
- Figure 10.1. Session Initiation Protocol (SIP) Entity Interactions.
- Figure 10.2. Message Exchanges During an SIP-BasedTwo-Party Call Setup.
- Figure 10.3. SIP Digest Authentication.
- Unlicensed Mobile Access.
- Figure 10.4. Unlicensed Mobile Access (UMA) Conceptual Architecture During a Call Setup.
- Other VoIP/IMS Systems.
- VOIP THREATS
- Disclosed Vulnerabilities.
- Figure 10.5. SIP Relay Attack.
- DISCUSSION
- Figure 10.6. Vulnerability Breakdown Based on Effect.
- Figure 10.7. Vulnerability Breakdown Based on VOIPSA Taxonomy.
- Figure 10.8. Vulnerability Breakdown Based on Source (I2, C2, P2).
- Figure 10.9. Vulnerability Breakdown Based on Source (I2, C2, P2).
- CONCLUSIONS
- ENDNOTES - CHAP 10
- CHAP 11 - TOWARD FOOLPROOF IP NETWORK CONFIGURATION ASSESSMENTS by Rajesh Talpade
- INTRODUCTION
- Figure 11.1. Inadequate Testing in IP Network Deployment Compared to Software Development.
- CONFIGURATION ERRORS FOUND IN OPERATIONAL IP NETWORKS
- Reliability.
- Security.
- Quality of Service.
- REGULATORS EXPECT COMPLIANCE
- MANY ASSESSMENT APPROACHES PROVE DEFICIENT
- Manual Assessments.
- Invasive Systems.
- Noninvasive Systems.
- TOWARD A SOLUTION THAT WORKS
- Desirable Features of a Solution.
- Configuration Extraction.
- Configuration Adaptors.
- Telcordia IP Assure.
- Figure 11.2. Telcordia IP Assure Information Flow.
- SUMMARY
- ENDNOTES - CHAP 11
- CHAP 12 - ON THE NEW BREED OF DENIAL OF SERVICE (DOS) ATTACKS IN THE INTERNET by Nirwan Ansari and Amey Shevtekar
- INTRODUCTION
- Figure 12.1. The Trend of DDoS Attacks in the Internet.
- TRADITIONAL BRUTE FORCE ATTACKS
- Figure 12.2. Classification of DDoS Attacks.
- NEW BREED OF STEALTHY DoS ATTACKS
- Figure 12.3. An Example of a Generic Low Rate DoS Attack Pattern.
- Figure 12.4. Attack Traffic for a Perfect DDoS Attack.
- DEFENSE SYSTEMS
- Figure 12.5. Conceptual Diagram of the PPM Scheme.
- Figure 12.6. Conceptual Diagram of the DPM Scheme.
- Figure 12.7. Conceptual Diagram of the Pushback Scheme.
- Figure 12.8. The Detection System Architecture.
- FUTURE RESEARCH DIRECTIONS
- CONCLUSION
- ENDNOTES - CHAP 12
- ABOUT THE CONTRIBUTORS
Assignement2/Vol.-3_Bellovin_Bradner_Diffie_Landau_Rexford.pdf
1 Harvard National Security Journal / Vol. 3
ARTICLE
Can It Really Work? Problems with Extending EINSTEIN 3 to Critical Infrastructure1
__________________________
Steven M. Bellovin,* Scott O. Bradner,** Whitfield Diffie,*** Susan Landau,**** and Jennifer Rexford*****
Abstract
In an effort to protect its computer systems from malevolent actors, the U.S. government has developed a series of intrusion-detection and intrusion- prevention systems aimed at monitoring and screening traffic between the internet and government systems. With EINSTEIN 3, the government now may seek to do the same for private critical infrastructure networks. This article considers the practical considerations associated with EINSTEIN 3 that indicate the program is not likely to be effective. Considering differences in scale, the inability to dictate hardware and software choices to private parties, and the different regulatory framework for government action in the private sector, this Article discusses why the government may be unable to effectively implement EINSTEIN 3 across the private networks serving critical infrastructure. Looking at what EINSTEIN aims to protect, what it is capable of protecting, and how
1 The authors would like to thank Matt Blaze, David Clark, and John Treichler for various insights and suggestions in the writing of this paper, and would also like to acknowledge useful conversations with Sandy Bacik, Vint Cerf, Tahir El Gamal, and Vern Paxson. A shorter version of this paper appeared as As Simple as Possible—But Not More So, COMMUNICATIONS OF THE ACM 30 (2011), available at http://cacm.acm.org/magazines/2011/8/114952-as-simple-as-possible-but-not-more- so/fulltext. * Professor, Department of Computer Science, Columbia University. ** University Technology Security Officer, Harvard University. *** Vice President for Information Security, ICANN and Visiting Scholar, Center for International Security and Cooperation, Stanford University. **** Written while Elizabeth S. and Richard M. Cashin Fellow, Radcliffe Institute for Advanced Study, Harvard University (2010–2011); currently Visiting Scholar, Department of Computer Science, Harvard University. ***** Professor, Department of Computer Science, Princeton University.
2011 / Can It Really Work? 2
privacy considerations affect possible solutions, this Article provides suggestions as to how to amend the EINSTEIN program to better protect critical infrastructure.
I. Introduction Effectiveness should be the measure of any deployed technology. Does the solution actually solve the problem? Does it do so in a cost-efficient manner? If the solution creates new difficulties, are these easier to handle than the original problem? In short, is the solution effective? In the rush to protect the United States after the 9/11 attacks, effectiveness was not always the primary driver in determining the value of the proposed systems. In this context we consider the potential extension to the private sector of EINSTEIN 3, a federal program to detect and prevent cyber intrusions. Providing services to the public is a fundamental role for U.S. federal civilian agencies, and beginning in the mid 1990s, many agencies turned to the Internet. This shift was not without problems. While confidentiality, integrity, and authenticity dominated early federal thinking about computer and Internet security, agencies faced multifarious threats, including phishing, IP spoofing, botnets, denials-of-service (DoS), distributed denials- of-service (DDoS), and man-in-the-middle attacks.2 Some exploits were done purely for the publicity, but others had serious purpose behind them. By the early 2000s, the growing number of attacks on U.S. civilian agency systems could not be ignored, and in 2004 the United States began an active effort to protect federal civilian agencies from cyber intrusions.3 This
2 Phishing is an attempt to direct a user to a fraudulent website (often a bank) to collect login and password information. IP spoofing puts a false address on an email in order to deceive the receiver. A botnet is a collection of hacked machines—a “bot” (short for robot)— controlled by a third party. A denial of service is a deliberate attempt to overload some service so legitimate users cannot access the service. For example, if a web site is connected to the Internet via a 10 Mbps line, the attacker might send 100 Mbps of traffic towards it, leaving no bandwidth for legitimate traffic. It may be the case that the attacker does not have a machine that can generate 100 Mbps of traffic, but can control—perhaps through a botnet—one hundred machines, each of which can send 1 Mbps of traffic to the machine being attacked. This would constitute a distributed denial-of-service attack. A man-in-the-middle attack is an unauthorized intermediary in a communication; this intermediary may modify messages as they transit from sender to recipient or may just eavesdrop. 3 DEP’T OF HOMELAND SEC., NATIONAL CYBER SEC. DIV., COMPUTER EMERGENCY READINESS TEAM (US-CERT), PRIVACY IMPACT ASSESSMENT EINSTEIN PROGRAM: COLLECTING, ANALYZING, AND SHARING COMPUTER SECURITY INFORMATION ACROSS THE FEDERAL CIVILIAN GOVERNMENT 3 (2004) [hereinafter US-CERT, EINSTEIN PRIVACY IMPACT ASSESSMENT].
3 Harvard National Security Journal / Vol. 3
classified program, EINSTEIN, sought to perform real-time, or near real- time, automatic collection, correlation, and analysis of computer intrusion information as a first step in protecting federal civilian agency computer systems.4 EINSTEIN has grown into a series of programs—EINSTEIN, EINSTEIN 2, and EINSTEIN 3—all based on intrusion-detection systems (IDS) and intrusion-prevention systems (IPS). These are based on signatures, a set of values or characteristics describing particular attacks.5 A network IDS monitors network traffic and reports suspected malicious activity, while a network IPS goes one step further by attempting to automatically stop the malicious activity (e.g., by dropping the offending traffic or automatically “fighting back” against the suspected adversary). In the original effort, EINSTEIN intrusion-detection systems were to be located at federal agency Internet access points, the intent being to gather information to protect U.S. federal government networks. If traffic appeared “anomalous,” session information would be sent to US-CERT, the United States Computer Emergency Readiness Team, a federal government clearing house for cyber intrusion information.6 Hard as it may be to believe, prior to EINSTEIN, information sharing between federal civilian agencies on cyberattacks was done purely on an ad hoc basis.7 The original EINSTEIN effort was not very successful. EINSTEIN information sharing did not happen in real time, and the voluntary nature of the 4 Id. at 4. 5 For example, the string /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN%u9090%u6858%u cbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090 %u9090%u8190%u00c3%u0003%u8b00%u531 b%u53ff%u0078%u0000%u00=a in a web request is the signature of the “Code Red” worm. Roman Danyliw & Allen Householder, CERT Advisory CA-2001-19 “Code Red” Work Exploiting Buffer Overflow in IIS Indexing Service DLL, COMPUTER EMERGENCY READINESS TEAM, SOFTWARE ENGINEERING INSTITUTE, CARNEGIE MELLON UNIVERSITY (July 19, 2001), http://www.cert.org/advisories/CA-2001-19.html. 6 US-CERT collects information from federal agencies, industries, the research community, and state and local governments, and sends out alerts about known malware. See US-CERT: UNITED STATES COMPUTER EMERGENCY READINESS TEAM, http://www.us-cert.gov/aboutus.html (last visited Oct. 16, 2011). 7 US-CERT, EINSTEIN PRIVACY IMPACT ASSESSMENT, supra note 3, at 3.
2011 / Can It Really Work? 4
program meant that many agencies did not participate. The next version, EINSTEIN 2, required the participation of all U.S. federal civilian agencies. Because real-time information sharing is fundamental to the EINSTEIN model, centralizing the intrusion detection and intrusion protection functionality is part of the EINSTEIN architecture. But while using IDS and, to a lesser extent, IPS to protect networks is not new, centralizing IDS and IPS functionality in such large networks as that of the federal civilian sector presents complex challenges. This is one reason that the EINSTEIN program deserves public scrutiny. Another is the turn the program appeared to take in September 2007 when the Baltimore Sun reported the National Security Agency (NSA) was developing classified plans for protecting private communication networks from intrusion.8 This news was more than a bit contradictory—a classified U.S. federal government program for protecting widely used private-sector systems—but little information was available about this “Cyber Initiative.”9 The result was that public comment was limited. In January 2008 the Cyber Initiative became marginally better known. The Bush Administration issued National Security Presidential Directive 54 establishing the Comprehensive National Cybersecurity Initiative (CNCI), a largely classified program for protecting federal civilian agencies against cyber intrusions. EINSTEIN was one aspect of CNCI that was made public, though large portions of the program remained classified. Public understanding of EINSTEIN's intent, how it worked, what risks it raised, and what it protected continued to be limited. In July 2010, the Wall Street Journal reported Raytheon had an NSA contract to study the value of sensors in recognizing impending cyberattacks in critical infrastructure cyber networks; Raytheon’s contract was for the initial phase of the program, known as “Perfect Citizen.”10 Public reaction
8 Siobhan Gorman, NSA to Defend Against Hackers: Privacy Fears Raised as Spy Agency Turns to System Protection, BALT. SUN (Sept. 20, 2007), http://articles.baltimoresun.com/2007-09- 20/news/0709200117_1_homeland-national-security-agency-intelligence-agencies.1A. 9 Id. 10 Siobhan Gorman, U.S. Plans Cyber Shield for Utilities, Companies, WALL STREET J. (July 8, 2010), http://online.wsj.com/article/SB10001424052748704545004575352983850463108.html.
5 Harvard National Security Journal / Vol. 3
was swift and highly critical.11 NSA responded with a statement that, “PERFECT CITIZEN is purely a vulnerabilities-assessment and capabilities-development contract. This is a research and engineering effort. There is no monitoring activity involved, and no sensors are employed in this endeavor.”12 While the project may initially have been solely a research effort, the idea of extending EINSTEIN-type protections to the private sector is increasingly being proposed by DC policy makers.13 Indeed, in June 2011, the Washington Post reported that three Internet carriers, AT&T, Verizon, and CenturyLink, had deployed tools developed by the NSA for filtering the traffic of fifteen defense contractors.14 According to the Post, officials said, “the government will not directly filter the traffic or receive the malicious code captured by the Internet providers.”15 Extending an EINSTEIN-like program to the private sector raises numerous issues. The first is scale, the second, a mismatch between the program and critical infrastructure that makes it difficult to apply the technology to critical infrastructure, the third, the legal and regulatory issues that govern critical infrastructure. Scale matters. While federal civilian systems directly serve two million employees, critical infrastructure systems in the United States serve a population of over three hundred million Americans daily. Can a program that effectively protects the communications of federal agencies with one hundred thousand employees really do the same for the communications giants that instead serve a hundred million people? The smart grid, with hundreds of communications a day to hundreds of millions of endpoints, far exceeds the traffic EINSTEIN is designed to handle.
11 Ryan Singel, NSA Denies It Will Spy on Utilities, WIRED (July 9, 2010), http://www.wired.com/threatlevel/2010/07/nsa-perfect-citizen-denial/. 12 Id. 13 See, e.g., J. Nicholas Hoover, Cyber Command Director: U.S. Needs to Secure Critical Infrastructure, INFO. WEEK (Sept. 23, 2010), http://www.informationweek.com/news/government/security/227500515http://www.inf ormationweek.com/news/government/security/showArticle.jhtml?articleID=227500515. 14 Ellen Nakashima, NSA Allies with Internet Carriers to Thwart Cyber Attacks Against Defense Firms, WASH. POST (June 16, 2011), http://www.washingtonpost.com/national/major-internet- service-providers-cooperating-with-nsa-on-monitoring- traffic/2011/06/07/AG2dukXH_story.html. 15 Id.
2011 / Can It Really Work? 6
Nor will size be the only problem in transitioning EINSTEIN systems from federal civilian agencies to the civilian sector. While the U.S. government can mandate the specific technologies used by federal agencies, the same is not typically true for systems used in the private sector. The fact that communications technologies are in a state of constant innovation further complicates such control.
Finally, expanding EINSTEIN-type technology to critical infrastructure is complicated by the complex legal and regulatory landscape of such systems. Putting it simply, there are fundamental differences between communication networks supporting the U.S. federal government and those supporting the private sector critical infrastructures. These differences create serious difficulties in attempting to extend EINSTEIN- type technologies beyond the federal sector. Such issues appear to be ignored by policy pundits in a headlong rush to protect critical infrastructure. While few doubt the value of IDS and IPS as part of a cyber security solution, can EINSTEIN really work? What attacks does EINSTEIN prevent? What will it miss? How good is EINSTEIN as a security solution? Is privacy properly protected? This paper is an attempt to provide answers to these questions, answers that are urgently needed in view of efforts to expand EINSTEIN beyond its original mandate. We begin by presenting the EINSTEIN architecture in Section II. In Section III, we discuss the technical and policy concerns raised by the use of EINSTEIN 3 by federal civilian agencies. We observe that the current EINSTEIN deployment across the federal sector raises privacy and security concerns and propose changes in policy to alleviate these concerns. In Section IV, we examine two critical infrastructures, the power grid and telecommunications. We observe that while critical infrastructure should, of course, deploy intrusion detection and intrusion prevention systems, the consolidation and real-time information sharing model central to the EINSTEIN 3 cannot effectively migrate to these private sector systems. We propose alternative methods to protect telecommunication and power grid cyber networks. In Section V, we return to EINSTEIN, proposing various technical and policy changes.
7 Harvard National Security Journal / Vol. 3
II. EINSTEIN 3 Architecture The CNCI goals were protecting against current cyber security threats and more sophisticated ones anticipated in the future.16 CNCI involved a dozen initiatives, the first being to manage the federal enterprise network as a single network. EINSTEIN was part of this, as was Trusted Internet Connections (TIC), a program that, by consolidating federal connections to the public Internet, would help ensure that these connections were professionally protected.17 Under the TIC program, federal civilian agencies use TIC Access Providers (TICAPs) to operate the TICs. Large federal agencies utilize a few TICs (generally two to four) while small agencies may share TICs. Some agencies have been certified as capable of acting as their own TICAP but most seek service from an approved TICAP.18 The reduction in external access points, from a few thousand to around one hundred, was crucial to the EINSTEIN 2 and EINSTEIN 3 efforts. EINSTEIN 2 uses devices located at TICs to monitor traffic coming into or exiting from government networks. Located at the agency's TICAPs,19 the EINSTEIN 2 sensors collect communications session data; this could include packet length, protocol, source and destination IP address and port numbers, and timestamp and duration information of communications to/from federal civilian agencies.20 The EINSTEIN 2 sensors alert US-CERT whenever traffic signatures, patterns of known malware (e.g., the IP address of a server known to be hosting malware or an attachment known to include a virus), were observed in incoming packets of traffic.21 The fact that EINSTEIN 2 sensors match signatures of incoming traffic means that the sensors are actually examining packet content, a fact that has not been made explicit in the public documentation concerning
16 NATIONAL SECURITY COUNCIL: THE COMPREHENSIVE NATIONAL CYBERSECURITY INITIATIVE, http://www.whitehouse.gov/cybersecurity/comprehensive-national- cybersecurity-initiative (last visited Oct. 22, 2011) [hereinafter CYBERSECURITY INITIATIVE]. 17 Id. 18 DEP’T OF HOMELAND SEC., US-CERT/ISS LOB, TRUSTED INTERNET CONNECTIONS (TIC) INITIATIVE—STATEMENT OF CAPABILITY EVALUATION REPORT 2 (2008). 19 Id. at 10. 20 US-CERT, EINSTEIN PRIVACY IMPACT ASSESSMENT, supra note 3, at 6–7. 21 CYBERSECURITY INITIATIVE, supra note 16.
2011 / Can It Really Work? 8
EINSTEIN 2. At first agency participation in the effort lagged, and EINSTEIN 2 was then made mandatory for federal agencies.22 To strengthen protections, EINSTEIN 2 is configured to perform real-time detection of patterns of anomalous communications behavior. Doing so requires observing large volumes of traffic so that the anomaly detector is able to develop a model of what “normal” traffic looks like. One of the purposes of consolidation was to provide sufficient data within each Internet connection for the EINSTEIN boxes to study.23 The third effort, EINSTEIN 3, will move from intrusion detection to intrusion prevention. Intrusion prevention systems devices will be located at the agency TICAPs, which will redirect traffic destined to or from the U.S. federal government network through the EINSTEIN 3 device without affecting other traffic (that is, without affecting communications not destined for U.S. federal government networks).24 As of this Article, EINSTEIN 3 is in preliminary stages, having been tested only at a single medium-sized federal civilian agency.25 Initially EINSTEIN 3 will recognize cyber threats by analyzing network traffic to determine if it matches known signatures.26 Commercial IPSs will develop signatures to be used in their devices, and it is reasonable to expect that the government will create a mechanism to use these signatures. Commercial IPSs respond to threats through two methods: by discarding suspect traffic before it reaches its destination and by sending carefully crafted messages to the perceived source of the threat. The aim of EINSTEIN 3 is “to automatically detect and respond appropriately to cyber threats before harm is done;”27 EINSTEIN 3 devices will perform deep packet inspection, examining not only transactional
22 DEPARTMENT OF HOMELAND SECURITY, UNITED STATES COMPUTER EMERGENCY READINESS TEAM (US-CERT), PRIVACY IMPACT ASSESSMENT FOR EINSTEIN 2, 3 (2008) [hereinafter PRIVACY IMPACT ASSESSMENT FOR EINSTEIN 2]. 23 OFFICE OF MGMT. & BUDGET, EXEC. OFFICE OF THE PRESIDENT, M-08-05, MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES (Nov. 20, 2007). 24 DEPARTMENT OF HOMELAND SECURITY, UNITED STATES COMPUTER EMERGENCY READINESS TEAM (US-CERT), PRIVACY IMPACT ASSESSMENT FOR THE INITIATIVE THREE EXERCISE 8-9 (2010) [hereinafter INITIATIVE THREE EXERCISE]. 25 Communication to Susan Landau (Sept. 1, 2010). 26 INITIATIVE THREE EXERCISE, supra note 24, at 5. 27 CYBERSECURITY INITIATIVE, supra note 16.
9 Harvard National Security Journal / Vol. 3
information but also packet content.28 A communications-interception analogy illustrates that EINSTEIN 2 behaves somewhat like a trap-and- trace device,29 while by collecting content of the communications, EINSTEIN 3 functions somewhat like a wiretap.30 The analogy is not perfect, however, since EINSTEIN 3 will disrupt communications believed to be carrying malware (in contrast, wiretaps simply record). By limiting the number of access points, the TICs concentrate the data, enabling a better search for “clues” about anomalous behavior. This improves the likelihood of discovering new threats. The limited number of access points makes it potentially feasible to establish a program of monitoring and intervention for all federal civilian agency access to the public Internet, and also limits the cost of the EINSTEIN effort both in terms of capital cost (e.g., fewer EINSTEIN boxes) and in operational expenditures (fewer people required to manage the system). Initial concerns about the EINSTEIN effort focused on privacy threats raised by the project. Because EINSTEIN IDSs and IPSs would operate on all traffic destined for federal networks, the system would undoubtedly intercept private communications of federal employees (e.g., if a federal employee used an agency computer to check a private email account during lunch). However, in this respect, a federal employee is no different from employees at regulated industries using company-supplied equipment for personal communications; they, and the people with whom they communicate, are also subject to company monitoring. Thus while there are privacy concerns raised by a wide use of EINSTEIN within the federal government, we believe that these are not insurmountable, and with adequate technical and policy oversight, can be properly handled. 28 Internet communications are broken into short blocks of data called packets that travel the network separately; when these packets reach the recipient, they are reassembled to recreate the longer files from which they came. 29 A trap-and-trace device captures the transactional information of an incoming communication; in the case of a phone call, this would be the phone number. A trap-and- trace device does not capture content. 30 These analogies are not exact. For example, EINSTEIN 2 and EINSTEIN 3 devices scan only a subset of communications. Minimization consists of singling out communications matching previously determined patterns or exhibiting anomalous behavior. More significantly, wiretaps do not prevent the occurrence of communications in which there is evidence of criminal activity, but the EINSTEIN 3 devices will do so. As both EINSTEIN 2 and 3 are used only for communications to/from federal civilian agencies, these interceptions are not considered electronic surveillance from a legal perspective.
2011 / Can It Really Work? 10
III. Technical and Policy Concerns Raised by the EINSTEIN 3
Architecture To understand EINSTEIN’s effectiveness, the architecture and the numbers must be examined. The EINSTEIN documents shared with the public have little detail, so we will start with a thought experiment. Consider the technical complexities of a centralized IDS/IPS system with few pipes serving multiple federal civilian agencies with two million users. The complexities include:
• Scale: Denial-of-Service (DoS) attacks can be daunting; they have been measured at 100 Gb/s.31 Consolidation provided by the TICs may assist in recognizing an ongoing DoS attack. But of course each IDS box has limits on the bandwidth it can support. If the TIC bandwidth is sufficiently high, incoming traffic will need to be divided over multiple links, diminishing the savings afforded by consolidation. In addition, consolidation may inadvertently cause collateral damage from an attack (e.g., the Patent and Trademark Office is targeted, but the attack also affects other Department of Commerce sites at the same TIC).
• Correlation ability: Correlation involves discovering previously
unknown threats in real time. If one is hoping to deter all threats— and not just previously known ones—all incoming data must be correlated and analyzed.32 But this is impossible to do in all but very small networks. The crux of the issue is that no one knows how to use a percentage of the traffic—whether compressed, diarized,33 or
31 Network Infrastructure Security Report, ARBOR NETWORKS (Feb. 1, 2011), http://www.arbornetworks.com/report. 32 By comparing aspects of the received packets to each other, in particular their “address headers,” it is usually possible to detect the presence of an attack, its method of operation, its physical source, and, in some cases, the actual attacker. Owing to the large volume of packets that travel through a network, this analysis must be statistical in nature, but examination of each packet is required both to detect known types of attacks and to determine the nuances of new ones. 33 “Diarize” is used within the trade to mean making a diary of the data; in the case of a telephone call, this might be the to/from, time, and length of the call, while for IP communications, this would be the metadata of source and destination IP addresses, TCP source and destination ports, and perhaps length of packet.
11 Harvard National Security Journal / Vol. 3
sampled—to characterize arbitrary new threats. Because all data must be scrutinized, the size of the problem quickly becomes unmanageable. Think of potential correlation solutions as having two variables: architectures can range from highly “centralized” to fully “decentralized” and sensors can be “smart” or “dumb,” that is, having the ability to perform large quantities of computation locally, or not. If analysis is performed locally at the data collection point, then the need to see all incoming data requires that all raw signals be sent to all sensors. This quickly becomes unmanageable. If there are n sensors, then each sensor must look at the data from (n-1) other sensors, and there are n(n-1)/2 pairs of data traversing the network. This is simply unmanageable when n is at all large (EINSTEIN is designed to have between one and two hundred). Note that this solution also introduces a new problem: protecting the sensors that would carry security-sensitive information. At the other end of the scale, an alternative approach would be to centralize the data to perform the correlation. Because summarizing the data cannot solve the problem, all the data must travel through the system to the centralized detector. (We note that in an IP-based environment, the packet summary information is 1.5-30% of the data.34 Summarizing the data does not provide savings in the same
34 Diarizing the data, supra note 33, means using the metadata. In the packet- communication world, this would involve the following types of data: exact time and date of the packet’s arrival down to the submicrosecond: 12 bytes; source and destination IP addresses: 8 bytes; source and destination TCP ports: 8 bytes; underlying protocol (such as http): 2 bytes; packet length: 2 bytes; and optionally layer 2 headers and/or detected content flags: maximum 4 bytes. This is a minimum of 32 bytes per transmitted packet. IP packets are variable in length, running as short as 100 bytes (e.g., VoIP) and as long as 1500 bytes (e.g., email). Thus metadata for IP/TCP communications constitutes somewhere between 1.5% (32 bytes out of 1500) and 30% (32 bytes out of 100). This constitutes a considerably higher percentage of metadata than is present in the equivalent diary for voice.
2011 / Can It Really Work? 12
scale that it would for telephone communications.) This is enormously costly for a network of any scale. Such a process would be unable to provide the millisecond response needed in a serious attack. (Of course, one could try a solution that is neither fully decentralized nor fully sharing signals. Depending on where one decides to perform the correlation, the problems above will still occur. The two alternative solutions—dumb sensors and decentralized architectures or smart sensors and centralized architectures—have the worst of both worlds: they would either miss the problems or involve enormous investment. Neither is viable.) In short, correlation at the scale and speed at which a system serving two million users is expected to operate is not achievable using common production technology.
• Device management: The devices will require periodic updates.
Protecting IDS/IPS control mechanisms and pathways against intrusion, disruption, modification, and monitoring will be very challenging.
• Signature management: Signatures are likely to be a mix of classified signatures developed by the government and unclassified signatures from commercial IDS and IPS vendors. These will have to be protected from those operating the IDS/IPS systems as well as from Internet-based attackers.
• Data security: Network communications are increasingly encrypted
through company VPNs, etc.; in some cases federal regulations require the use of encryption (e.g., in sharing medical records). In order for the IDS/IPS systems to prevent malware from reaching end users, communications transiting the IDS/IPS must be decrypted. Thus the IDS/IPS systems become a particularly ripe place for attack.
13 Harvard National Security Journal / Vol. 3
The above are issues for any IDS/IPS system centralizing monitoring and protection function through few pipes. Now consider EINSTEIN, which proposes to do the same, but at a large jump in the scale of the network being scrutinized. The Trusted Internet Connections initiative, which supports EINSTEIN, will ensure that all communications between federal civilian agencies and the Internet— both those generated by people and those by services—occur via managed connections. Since some government agencies exchange very large quantities of research data with their partners in the private sector—data sets on the order of terabytes—some connections involve quite high bandwidth. The public EINSTEIN documents provide limited details on how the technology will function, therefore thought experiments are needed—not inappropriate for a technology named EINSTEIN.
• Scaling is a problem: Although the actual performance of the EINSTEIN 3 device is not public, the cost impact of requiring a significant amount of real-time monitoring of Internet streams can be illustrated by examining a “typical” case based on the speed of products publicly available. We begin by noting that in a fully realized TIC program to minimize the number of interconnect points, the number will be more than one hundred and may be in the low hundreds. Consider a single shelf Cisco CRS-1 router of the type used both in Internet backbones and to aggregate traffic from local networks before sending it to the Internet. According to Cisco’s press releases, more than 5,000 of these routers have been sold and deployed. When fully loaded, the CRS-1 will accept 64 10 Gb/s duplex communications links, operating at a total bit rate of 1.28 terabits/second.35 While some routing nodes are smaller, some are much larger, so using a number of CRS-1s connected together handles the required load.
35 Press Release, Cisco Systems Sets Guinness World Record with the World’s Highest Capacity Internet Router (July 1, 2004), http://newsroom.cisco.com/dlls/2004/prod_070104.html; Cisco Systems, Cisco CRS-1 24-Slot Fabric Card Chassis, 1992–2007, 2009.
2011 / Can It Really Work? 14
While neither the exact nature of the algorithms planned for EINSTEIN 3 nor the equipment configuration planned for it have been disclosed, it is reasonable to assume a model in which the computation required for performing the IDS/IPS function at a federal civilian agency will be similar to that in commercial network defense products built and sold by Narus, Cloudshield, and others. It seems highly unlikely that a single EINSTEIN 3 device can run sufficiently fast so as to monitor the high-speed connections between some of the federal civilian agencies and the Internet or private sector agency partners. There are obviously differences in the details of the various industry products, but a review of their specifications reveals that a unit capable of examining, in real time, 20 Gb/s of Internet traffic costs about $80K and consumes about 2 kW (and another 2 kW for cooling). Because each CRS-1 will accept 64 10 Gb/s duplex communications links, a single half-rack CRS-1 would therefore require 64 such network defense units, at a cost of roughly $5M, roughly 250 kW of power consumption, and roughly 32 equipment racks. This has two important implications: (1) because packet content, and not just packet headers, will need to be examined, each router used for directing traffic will require 64 times as much equipment to perform EINSTEIN-type security—clearly a losing battle—and; (2) the EINSTEIN program, at least the instantiation of EINSTEIN 3, would be roughly one billion dollars solely for equipment costs.
• Device management: Installed in TICAPs, many of the EINSTEIN devices will be in non-government facilities, but will need to be remotely controlled by US-CERT. Ensuring that the control mechanisms and pathways are protected against intrusion, disruption, modification, and monitoring will be challenging. Ensuring that such control paths are isolated from the Internet is likely to be a minimum requirement, but history has shown that
15 Harvard National Security Journal / Vol. 3
isolated systems sometimes do not stay isolated.36 And, as the Stuxnet case so vividly demonstrates, even seemingly isolated systems can be vulnerable to attacks.37 EINSTEIN 3 devices are not designed to work autonomously. They are designed to be managed by, and report to, one or more control systems. A number of large Internet service providers (ISPs) and large enterprise networks have developed procedures and control systems to provide secure management of multiple network devices, such as routers or firewalls. Due to the dual requirements of being able to quickly determine an attack is underway, and to react to that attack by reconfiguring other EINSTEIN devices, the management requirements for EINSTEIN devices are likely to be far more dynamic than what is required for current ISP or enterprise network devices. Developing the tools needed to manage the EINSTEIN 3 devices may turn out to be a significant technical challenge.
• The feasibility of correlation: As we have already noted, correlation, particularly at the scale and speed at which EINSTEIN 3 is expected to operate, is simply not achievable using common production technology.
• Complexity of combining classified and non-classified signatures: Both classified and unclassified signatures will be used for intrusion detection.38 As already noted, some signatures that EINSTEIN 3 will use will be developed by the government and will be classified
36 For example, former White House cyber security adviser Richard Clarke remarked that, “[E]very time a virus pops up on the regular Internet, it also shows up on SIPRNet [Secret Internet Protocol Router Network, used for classified communications]. It is supposed to be separate and distinct, so how's that happen? . . . It's a real Achilles' heel.” P.W. SINGER, WIRED FOR WAR: THE ROBOTICS REVOLUTION AND CONFLICT IN THE 21ST CENTURY 201 (2009). 37 John Borland, A Four-Day Dive into Stuxnet’s Heart, WIRED (Dec. 27, 2010), http://www.wired.com/threatlevel/2010/12/a-four-day-dive-into-stuxnets-heart/. 38 DEP’T OF HOMELAND SECURITY, COMPUTER EMERGENCY READINESS TEAM (US- CERT), PRIVACY IMPACT ASSESSMENT FOR THE INITIATIVE THREE EXERCISE 5 (March 18, 2010).
2011 / Can It Really Work? 16
while others are likely to come from commercial IDS and IPS vendors. The protection of classified signatures and the protection of any captured network traffic will be a challenge for the EINSTEIN devices located in the TICAPs, particularly for the commercial providers. The signatures will have to be protected from the TICAP operator and from Internet-based attackers. The latter is particularly important since knowing what the EINSTEIN device is looking for would simplify an attacker's approach.
These technical complexities make it highly unlikely that EINSTEIN 3 can accomplish the purposes for which it is being designed. The use of EINSTEIN 3 also raises various policy issues. The first arises from the fact that Internet traffic is increasingly encrypted.39 Indeed, many government websites offer encrypted services (e.g., the IRS). It is to be expected that government employees will be accessing non-government encrypted services on a regular basis (e.g., banking sites), but the current set of public EINSTEIN 3 documents do not discuss how EINSTEIN 3 will handle encrypted traffic. One option would be for the EINSTEIN devices to ignore the contents of encrypted traffic, but that would provide an unmonitored attack pathway. Devices such as EINSTEIN 3 that are in the communications path can be designed to mimic cooperating websites (by using those websites’ identities and credentials) to both expose the encrypted traffic to EINSTEIN 3 and permit that traffic to be stored. These policies should be openly developed to ensure that the public understands the implications of the EINSTEIN 3 system. A second critical issue is that any IDS looking for long-term subtle attacks must store large amounts of traffic for non real-time analysis. This data could also be useful in tracking down wrongdoing by government employees or people with whom they communicate. Even if current EINSTSEIN 3 software is not designed for such analysis, the system is likely to store data that government agencies might like to use—creating danger of
39 For example, Google recently made encrypted access the default for many of its applications. Evan Roseman, Search More Securely with Encrypted Google Web Search, THE OFFICIAL GOOGLE BLOG (May 21, 2010, 12:30 PM), http://googleblog.blogspot.com/2010/05/search-more-securely-with-encrypted.html; Sam Schillace, Default Https Access For Gmail, GMAIL BLOG (Jan. 13, 2010), http://gmailblog.blogspot.com/2010/01/default-https-access-for-gmail.html.
17 Harvard National Security Journal / Vol. 3
misuse. Thus it is imperative that a detailed log is generated for all functions that the EINSTEIN 3 device has been configured to perform. Policies will have to be developed to detail legitimate uses of the EINSTEIN 3 devices. The only way to ensure, however, that such policies are followed is to produce detailed logs that cannot be altered. Logs must be out of the reach of individuals who might misuse the EINSTEIN 3 devices, and these must be regularly and automatically scanned to reveal unexpected activities. Given the technology’s potential for tracking individuals, policies should be developed to enable access to the logs if questions arise regarding how the EINSTEIN 3 devices are being used. There should be regular scrutiny of these logs by agency Inspectors General. Extending EINSTEIN 3 to non-government critical infrastructure would require similar policy development, an issue to which we now turn.
IV. Expanding EINSTEIN Capabilities to Critical Infrastructure Certain critical infrastructures such as telecommunications and the electric power grid are essential not only to the running of society, but also to the functioning of the U.S. government, and thus the federal government has a direct vested interest in the security of the computer networks supporting these infrastructures. But direct vested interest does not mean that the federal government can force its solution onto the private sector. The fact that private industry controls 85% of critical infrastructure40 means that the situation is not straightforward. In fact, it is far from straightforward. The real question is what problem is EINSTEIN attempting to solve. One possible purpose is to simply provide NSA-supplied signatures to IDSs and IPSs protecting critical infrastructure. Another is to correlate anomalous behavior on incoming traffic. A third possibility is to detect all anomalous traffic. We believe that the first, using NSA-supplied signatures to protect public communications, raises technical complexities, but can be accomplished. We believe the remaining two, applied to privately-owned critical infrastructure, are not reasonable expectations. Let us consider the issues.
40 U.S. GOV’T ACCOUNTABILITY OFFICE, GAO-07-39, CRITICAL INFRASTRUCTURE PROTECTION: PROGRESS COORDINATING GOVERNMENT AND PRIVATE SECTOR EFFORTS VARIES BY SECTORS’ CHARACTERISTICS 2 (2006).
2011 / Can It Really Work? 18
We begin by discussing the general issues involved in performing real-time intrusion detection and intrusion prevention on a nation-wide scale. We then consider two critical infrastructures—telecommunications and the power grid—in some detail. In this discussion, we are assuming the approach to be the full EINSTEIN architecture, that is: TICAPs with cross- site correlation and an automatic reaction to anomalous events. Our critiques follow from there.
A. The Complexities of Information Collection The EINSTEIN architecture forces a limited number of federal civilian agency access points to the Internet. In the federal sector this reachability to a limited number of access points was not particularly difficult to achieve or enforce. However, as much as various federal agencies might clash with one another for responsibilities and resources, ultimately these agencies serve the same customer. Even if agencies A and B compete in some spheres, it is perfectly reasonable to expect they would cooperate in enabling real-time correlation of transactional information to find that U.S. government sites are under attack. To provide EINSTEIN-type protection in the private sector would require coalescing connections to the public Internet. It is far more difficult to imagine a collaboration model here. Many suppliers of critical infrastructure are genuine competitors. The manager of an EINSTEIN device has control over the communications that run through the device. Who would run the EINSTEIN devices for competing companies? Putting company A in the control seat of connections to the public Internet makes it very powerful. Would its competitor B willingly use the services of a TICAP hosted at A? Even though B should encrypt its communications end-to-end, there are any number of nefarious activities that A might employ to impede its competitors, including using the IDS/IPS to throttle the communications of company B. Even short communications delays can have massive impacts for companies.41 Would B have to pay A for its services? A related issue is device management. Because EINSTEIN 3 devices store classified signatures, control of the private-sector systems should be handled under the aegis of the federal government (and specifically by the 41 See Peter Svensson, Comcast Blocks Some Internet Traffic, MSNBC (Oct. 19, 2007), http://www.msnbc.msn.com/id/21376597/.
19 Harvard National Security Journal / Vol. 3
agency supplying the signatures). Such a solution presents myriad complexities, and the history of real-time data sharing between the private and public sector has not been a positive one. In 1998, Presidential Decision Directive 63 (PDD-63) made protection of critical infrastructure a national objective. Since then public- private partnerships have been recommended, been created, and failed, only to be re-recommended, be re-created, and fail again. The 1998 PDD- 63 created Information Sharing and Analysis Centers (ISACs),42 but was superseded in 2003 by Homeland Security Presidential Directive 7, which made DHS responsible for coordinating plans for protecting critical infrastructure. This included developing plans for coordinating public- private partnerships. In 2006, DHS issued a National Infrastructure Protection Plan with public/private partnerships with two councils for each sector—a government one and a private sector one—to handle planning and coordination. The issue of public-private partnerships arose again in 2009 with the 60-day Cybersecurity Review43 conducted at the behest of President Obama. In 2010, the Government Accountability Office reviewed public- private partnerships, and concluded that federal partners are not consistently meeting private sector expectations, including providing timely and actionable cyber threat information and alerts, according to private sector stakeholders.44 Problems included a lack of timely information, a lack of access to secure settings in which to exchange private information, and a lack of “one-stop” shopping—one federal office from which to find out information.45 This does not bode well for private-sector use of EINSTEIN- type systems. 42 For example, the IT-ISAC was created by the IT industry for systematic sharing and exchange of information on “electronic incidents, threats, attacks, vulnerabilities, solutions and countermeasures, best security practices and other protective measures” and includes such industry leaders as CA, Computer Sciences Corporation, IBM, Intel, Juniper Networks, Microsoft, Oracle, Symatec, and Verisign. See About the IT-ISAC, https://www.it-isac.org/about_n.php (last visited Oct. 16, 2011). 43 CYBERSPACE POLICY REVIEW TEAM, CYBERSPACE POLICY REVIEW: ASSURING A TRUSTED AND RESILIENT INFORMATION AND COMMUNICATIONS INFRASTRUCTURE (May 2009). 44 U.S. GOV’T ACCOUNTABILITY OFFICE, GAO-10-628, CRITICAL INFRASTRUCTURE PROTECTION: KEY PRIVATE AND PUBLIC CYBER EXPECTATIONS NEED TO BE CONSISTENTLY ADDRESSED 13 (2010). 45 Id. at 14.
2011 / Can It Really Work? 20
One example of the types of issues that would arise is signature collection. How would signatures amassed by private parties, e.g., the critical infrastructures themselves—or the companies with which they contract—be added to the EINSTEIN devices? Concerns run from mundane issues of whether signature formats will be public to knotty management concerns. Because private parties would not control the EINSTEIN devices, presumably they would not be able to directly add signatures to the IDS and IPS. This would have the counterproductive effect of removing private companies from the process of protecting their own customers. Such lack of direct control will create various problems, and would, at a minimum, create delay in adding signatures found by the private companies onto the EINSTEIN devices. The issue of control runs deeper. Most private sector systems currently already run IPS and IDS on their networks. If EINSTEIN-type systems were deployed on their communications networks, what would happen to the systems currently in use? A possible solution would have communications relayed through two IDS/IPS systems, one supplied by the federal government, one by the company involved. The problems with this “solution” are clear. Another issue arises from deployment. U.S. telecommunications infrastructure extends outside U.S. territorial limits. Using EINSTEIN boxes at foreign endpoints creates serious security problems for the technology. For example, how would classified signatures be protected in such an environment? Moreover, placing the boxes where cables enter the United States is simply not viable; a single modern cable carries about two or more terabits/second46 and each incoming cablehead hosts several cables. EINSTEIN cannot cope with such numbers. The distributed control between government and the private sector also raises legal concerns. Who bears fiscal responsibility for attacks that occur from problems that were known—ones that the private entities had uncovered—but that had not yet been added to the system? Distributed control leaves gaps, including the issue of who would bear responsibility for attacks that neither the U.S. federal government nor the private entities had yet uncovered. In mandating an EINSTEIN-like system be used on a private network, would the federal government indemnify the owners if 46 Since most video is on national networks, this is almost entirely voice and data. There is very little video in cross-border or undersea cables.
21 Harvard National Security Journal / Vol. 3
cyberattacks occurred? Privacy would become a much greater concern were EINSTEIN technology to be extended from federal systems to the private sector. EINSTEIN 2 collects and retains transactional information in order to check for anomalous patterns. The collection includes packet length, protocol, source, and destination IP address and port numbers— information already shared with Internet routers. In Smith v. Maryland,47 the Supreme Court ruled that information such as dialed numbers shared with third parties do not require government investigators to obtain a warrant. Thus extending EINSTEIN 2-type technology to the private sector might not invoke Fourth Amendment protections.48 EINSTEIN 3 is another matter. This technology would scan and analyze not just metadata, but also content. Information would be stored on suspicion of being malware, not on the knowledge that it is so. Harvard Law School Professor Jack Goldsmith has argued that using EINSTEIN-type technologies to monitor communications for malware is akin to conducting “non-law-enforcement searches without individualized suspicion in numerous contexts,” and cited highway checkpoints and inspections of regulated businesses as precedent for such monitoring sans warrants.49 Communications form a special class however. Wiretap warrants require a higher standard of proof than standard search warrants. Goldsmith proposes handling potential invasiveness of an EINSTEIN-type system with “significant use restrictions” on the communications stored through EINSTEIN, limiting the set of crimes for which a sender could be prosecuted to computer-related and national-security offenses.50 This proposal sounds somewhat better in theory than it is likely to be in practice.
47 442 U.S. 735, 741–42 (1979). 48 See, e.g., In Re Application of the United States of America For an Order Pursuant to §2703(d), Misc. Nos. 1:11-DM-3, 10-GJ-3793, & 1:11-EC-3 (E.D. Va. Nov. 10, 2011); Brief for Jacob Applebaum, Birgitta Jonsdittor and Rap Gonggrijp in the matter of §2703(d) order relating to Twitter Accounts; Wikileaks, Rop_G, IOERRO, and Birgittaj as Amici Curi in Support of Objections of Real Parties in Interest Jacob Applebaum, Birgitta Jonsdottir and Rop Gonggrijp to March 11, 2011 Order Denying Motion to Vacate Misc U.S. District Court, Eastern District of Virginia, Alexandria Division (March 31, 2011), No. 10-4 10GJ3703. 49 JACK GOLDSMITH, THE CYBERTHREAT, GOVERNMENT NETWORK OPERATIONS, AND THE FOURTH AMENDMENT, 12 n.34 (2010), available at http://www.brookings.edu/papers/2010/1208_4th_amendment_goldsmith.aspx. 50 Id. at 15–16.
2011 / Can It Really Work? 22
Wiretap law is replete with instances where an initially restrictive collection is substantially expanded over time.
Consider, for example, the 1967 Omnibus Crime Control and Safe Streets Act.51 Title III of the act delineated the requirements for obtaining a wiretap warrant. Because of a history of law-enforcement abuse of wiretaps,52 Congress sharply limited the circumstances under which law- enforcement investigators could obtain a wiretap for a criminal investigation. The law listed twenty-five serious crimes for which a wiretap order could be obtained, and these were the only crimes for which a wiretap order for a criminal investigation could be issued. With time, that list was amended, and the number of crimes for which a wiretap warrant can be obtained now stands at slightly under one hundred.53 A similar situation occurred for the Foreign Intelligence Surveillance Act, which puts forth the requirements for a foreign-intelligence wiretap order. While some expansions were due to changes in technology (e.g., the shift to fiber optic cable that partially precipitated the FISA Amendments Act), other expansions of the law, most notably lowering the need for foreign intelligence from being “the purpose” of the order to simply being a “significant purpose”54 have substantively changed the original law. Goldsmith’s proposed limitation may not actually work very well in practice. An IDS/IPS mechanism that scanned private-sector communications networks for malware, but which used the gathered information for criminal investigations, is highly problematic from a Fourth Amendment point of view and would be unlikely to gain public support—at least if the technology’s import is made clear. Data retention raises concerns on another dimension. Given that competing firms run critical infrastructure, how would information be shared? Privacy and competition issues severely complicate such data sharing. There may be legal restrictions on disclosing personally identifiable information. New policy provisions and new laws would be needed in order to handle the information sharing that an EINSTEIN system would require
51 Pub. L. No. 903-351, 82 Stat. 197 (codified as amended in scattered sections of 42 U.S.C., 18 U.S.C., and 5 U.S.C.). 52 S. REP. NO. 94-755 (1976). 53 18 U.S.C. § 2516 (1998). 54 This change is a result of the USA PATRIOT Act of 2001, Pub. L. No. 107-56, § 218, 115 Stat. 272 (codified at 50 U.S.C. §§ 1804(a)(7)(B), 1823(a)(7)(B)).
23 Harvard National Security Journal / Vol. 3
in the broad private-sector environment (as opposed to the federal civilian agency sector). We note that as a result of the liberalization of U.S. cryptography export regulations in 2000,55 encrypted communication has become much more common. The peer-to-peer VoIP system Skype uses end-to-end encryption,56 which ensures only the sender and recipient may understand the conversation. Many large enterprises employ virtual private networks (VPNs), where communications are encrypted on a server within the corporate network then travel the public communications network and are decrypted once the communication is again within the corporate network. Indeed, while private carriers transport the confidential communications of the U.S. government, these are often encrypted end-to-end. (If federal government communications are to be secured—say if such communications from a San Francisco switching office were sent to a federal agency on the East Coast—then the communications architecture would likely enter the leased fiber-borne “T1 line” to the destination. Communications would first be encrypted according to NSA-approved or NIST-approved methods,57 then enter the T1 link. Fully protected against being read, the communication would travel the “public highway” to the East Coast, where it would be decrypted after it reaches its endpoint. This method of communications security would have advantages and disadvantages. While the architecture secures the communication during its transit, it does not ensure reliability and the arrival of the communication.58
55 Revisions to Encryption Items, 65 Fed. Reg. 2492-01 (Dep’t of Commerce, proposed Jan. 14, 2000) (to be codified at 15 CFR §§ 734, 740, 742, 770, 772, & 774). 56 P2P Telephony Explained—For Geeks Only, SKYPE, http://www.skype.com/intl/en- us/support/user-guides/p2pexplained/ (last visited Feb. 1, 2011). 57 The system used would depend on whether the communication was classified. 58 Consider, for example, the events of July 2001. Several cars on a 60-car CSX train going through the Howard Street Tunnel in Baltimore derailed, and a fire broke out. The high- temperature fire took five days to put out. During that time large amounts of road traffic in Baltimore were disrupted. Other disruptions occurred, notably the disruption of communications traffic along the East Coast. Seven of the largest U.S. ISPs used a fiber optic cable that ran through the Howard Street Tunnel and the fire burnt through the pipe housing the cable. MARK CARTER ET AL., U.S. DEP’T OF TRANS., EFFECTS OF CATASTROPHIC EVENTS ON TRANSPORTATION SYSTEM MANAGEMENT AND OPERATIONS (2003). The moral: unless the U.S. government owns the entire physical infrastructure of the communications network, U.S. government communications will always be subject to the “backhoe problem.” That said, the communications security described above is sufficient for federal civilian agencies for all practical purposes.
2011 / Can It Really Work? 24
EINSTEIN-type devices operating on encrypted communications would not be able to examine the content of the communications. EINSTEIN devices would be able to examine transactional information, but only if the communications were not traveling through a VPN or encrypted—in which case, the only information revealed during interception would be that the communications’ destination is within the corporate network.59 Information about the ultimate endpoints of the communication would become available once the traffic was within the corporate network. Because enterprise communications would likely be using VPNs, if EINSTEIN-type surveillance were to become de rigeur for telecommunications, we might find ourselves in the odd situation in which corporate communications were routinely afforded privacy from surveillance while private communications of private citizens were not. One can imagine “solutions” to this: solutions likely to complicate law- enforcement wiretapping. It is by now clear that an extension of EINSTEIN-type technology to the private sector would be remarkably complicated both from a policy and technical viewpoint. The most basic issue, however, is how to process the massive amounts of data that may traverse an EINSTEIN-type system. As is usually the case in such situations, complexity lies in the details. We turn to the potential role of EINSTEIN-type technology in two specific examples of critical infrastructure.
B. The Complexities Posed by Telecommunications By interposing an eavesdropper on all communications traveling
over the network, an EINSTEIN-type system on a public communications network would be disruptive because of both technical issues and policy concerns. We start with the technical issues.
59 This is true even if a VPN user were sending a mail to someone outside the corporation. The communication would travel from the user to the corporate VPN server, where it would be decrypted and then sent to the mail server. At that point, it would travel as mail. From the point of view of an interceptor, the communication’s destination is the corporate mail server.
25 Harvard National Security Journal / Vol. 3
Whether an EINSTEIN-type system can work in the public communications sector is completely based on the numbers: how many packets flow through an EINSTEIN device per second, how long it takes to examine these, and how many can be stored for later examination. In the 1990s the rate of communications transmission was sufficiently slow that the communications bits could be effectively examined and stored—at least if one did sampling. Fiber optics changed the equation; the technology of fiber optic transmission and packet routing has outstripped that of computation for the past twenty years, and that trend is likely to continue for the foreseeable future. Computation-based monitoring of a significant portion of the Internet is likely to be very costly and impractical in all but very special cases. The cost of storage is now dropping even faster than the rate of transmission is increasing, and instead there might be a temptation to store all questionable communication to be examined later. Recall the Cisco router described in Section III. What if, instead of examining all inputs to the CRS-1 in real time, we recorded the traffic for later examination if a threat signature were detected elsewhere. The combined input and output rate of a fully loaded single-shelf CRS-1 is 1.28 Tb/sec, which translates to 160 GBytes/sec. Thus, to store all the comings and goings for a single high- end router for a day would require storage equal to about 14 petaBytes/day. Clearly the long-term storage of a router’s traffic flow for later consideration is not practical. The numbers preclude EINSTEIN technology from sharing all the packets that pass through, though sharing abstracts, summaries, or snippets might work (depending on size and form of comparison being done). Sharing transactional information would be one way to share attack information without requiring the enormous bandwidth calculated above. Despite current limited legal protections given to transactional information, communication transactional information is itself a rich source of private information. Golle and Partridge have observed, for example, that if one can determine the home and work location of a user (easily done, for example, from determining the cell location of communications made between the hours of 11 pm and 7 am and between 9 am and 5 pm respectively), then re-identification of a previously “anonymous” user may
2011 / Can It Really Work? 26
be achieved.60 Long-term storage of transactional data for later study creates a new security risk, while centralizing the data would create an even bigger one. The latter argues for providing privacy protections to the data. How well will this work in practice? Such techniques may destroy much of the value of the data for the IDS/IPS. The final—and perhaps most important—issue arises from the role of telecommunications in society. It is appropriate for an IDS and IPS to act conservatively, and thus to prohibit those types of communications that are not explicitly allowed. So an IPS should naturally disallow a new form of communications technology, whether Instant Messaging, Skype, Twitter, Facebook, or some new application, until it is determined by the IDS/IPS designers that the new communications forms are not malware. Although there may be costs to the public if the Veterans Administration or the Department of Health and Human Services does not immediately implement the newest communications technologies such as Facebook or Twitter, such a conservative design makes sense for a federal system IDS/IPS. This approach does not make sense for an EINSTEIN-type system protecting public telecommunications. Unless the EINSTEIN technology only uses blacklisting (“prohibit communications with these signatures”), EINSTEIN-type technologies at telecommunications carriers will prevent early deployment and testing of innovative communications technologies. That would be an enormous mistake. The model of few TICs cannot apply to telecommunications infrastructure. Underlying EINSTEIN’s inapplicability is the fact that communications infrastructure has few commonalities with the U.S. federal government. Telecommunications has many, many pipes and many of those are big (10 gigabits/second—and greater).61 The U.S. has about 6500 telecommunications carriers62 and over ten thousand Internet Service
60 Philippe Golle & Kurt Partridge, On the Anonymity of Home/Work Location Pairs, Pervasive Computing, Seventh International Conference, Nara Japan (May 11–14, 2009), available at crypto.stanford.edu/~pgolle/papers/commute.pdf. 61 AT&T Expands New Generation IP/MPLS Backbone Network, AT&T (Dec. 20, 2007), http://www.att.com/gen/press- room?pid=4800&cdvn=news&newsarticleid=24888&mapcode= (last visited Oct. 13, 2011). 62 INDUS. ANALYSIS AND BUS. DIV., FED. COMMUNICATIONS COMM., TRENDS IN TELEPHONE SERVICE 4-5 (Sept. 2010).
27 Harvard National Security Journal / Vol. 3
Providers,63 which means that there are many, many more communications providers than departments of the federal government. Absent U.S. federal government requirements—which would be very hard to achieve— telecommunications players have no incentive to cooperate; indeed, because they are commercial competitors, they have a strong disincentive to do so. Meanwhile, EINSTEIN itself creates risks. Concentrating traffic anywhere—central to the EINSTEIN 3 concept of discovery—creates its own vulnerabilities.64 Various commonly used technologies for information protection, such as VPNs, will thwart the EINSTEIN model for detecting “bad” behavior. And finally, aside from the federal employees communicating using government computers, the customer—the public— has Fourth Amendment and statutory rights that are greatly threatened by this technology.
C. The Complexities Posed by the Power Grid On a first glance, it seems that the EINSTEIN technology would be an extremely good match for the power grid. The grid is heavily reliant upon computer networks, both at the consumer level, where such networks are used to bill customers, and at the grid management level, where computer networks coordinate power generation and transmission. The industry is moving towards “smart grid,” a two-way digital communication and control system in which the utilities will send messages to devices in the home and office about energy prices in real time (e.g., on a hot summer day when the temperature is causing high demand for air conditioning), and users’ systems will respond accordingly (e.g., by shutting down until prices are lower).65 We already have ample demonstration of security problems. In 2007 researchers at the Idaho National Laboratory showed how to access a power plant’s control system through the Internet. Running an emulator, the researchers destroyed a 27-ton power generator by power cycling at very short intervals.66 In 2009 there were news reports that the power grid had
63 U.S. CENSUS BUREAU, STATISTICAL ABSTRACT OF THE UNITED STATES 721 (2009). 64 18 U.S.C. § 2516 (1998). 65 LITOS STRATEGIC COMMUNICATION for the DEP’T OF ENERGY, THE SMART GRID: AN INTRODUCTION 11 (2008). 66 Jeanne Meserve, Sources: Staged Cyber Attack Reveals Vulnerability in Power Grid, CNN (Sept. 26, 2007), http://articles.cnn.com/2007-09-26/us/power.at.risk_1_generator-cyber- attack-electric-infrastructure?_s=PM:US.
2011 / Can It Really Work? 28
been penetrated by spies who might have left rogue code behind.67 In 2010 the Stuxnet worm targeted Supervisory Control And Data Acquisition (SCADA) systems used to monitor and control industrial processes— specifically those controlling Iranian nuclear centrifuges68—amply demonstrating proof of concept.69 Increasing amounts of electronic communications from the smart grid means there will be need to directly protect customers (e.g., from attackers who snoop on the communication with smart meters or, worse yet, send forged messages about electricity usage). Meanwhile the fact that the power industry is heavily regulated should help with lowering barriers to sharing cyberattack data among the energy providers. It would seem the cyber networks of the power grid would be ripe for EINSTEIN. On closer examination, the fit is less clear. The power grid cyber network is actually four networks with different users, different levels of protection, and different protection needs. We begin by enumerating these networks: • Providing customers with data about electricity usage: Consumers often
have web access to account information, such as their latest bill and summaries of electricity usage. This communication takes place over the Internet and relies on the customer's own Internet connection.
• Providing utilities with information about electricity usage: Utilities increasingly rely on computer networks to remotely read customer electricity meters. Many utilities build and deploy their own networks over many kinds of low-bandwidth “last mile” technologies; these include microwave, power line, radio, cellular, and wireless mesh
67 Siobhan Gorman, Electricity Grid in U.S. Penetrated by Spies, WALL ST. J. (Apr. 8, 2009), http://online.wsj.com/article/SB123914805204099085.html. 68 William J. Broad & David E. Sanger, Worm Was Perfect for Sabotaging Centrifuges, N.Y. TIMES (Nov. 18, 2010), http://www.nytimes.com/2010/11/19/world/middleeast/19stuxnet.html?. 69 The worm was apparently introduced through an infected USB flash drive. Derek S. Reveron, Cyberattacks After Stuxnet, NEW ATLANTICIST (Oct. 4, 2010), http://www.acus.org/new_atlanticist/cyberattacks-after-stuxnet), but could both update itself and spread through the Internet. Symantec, How Stuxnet Spreads, N.Y. TIMES (Jan. 16, 2011), http://www.nytimes.com/imagepages/2011/01/16/world/16stuxnet_g.html?ref=middlee ast.
29 Harvard National Security Journal / Vol. 3
networks. User privacy is important to avoid revealing sensitive information, such as whether and when customers are at home.70
• Controlling the customers' smart devices: With the move toward a smart
grid, utilities will increasingly communicate directly with devices such as refrigerators, dish washers, or air conditioners at the customer sites, in order to adapt electricity usage to current demands. The technologies for smart devices are still in an early stage. Rather than the utilities supporting a diverse array of communication media, devices are likely to rely on customers' Internet connections for communication with the utilities.
• Managing the power grid: Communication networks play an important
role in managing power generation and distribution, including coordination between various electricity providers, operations, economic markets, and transmission systems. While this communication could take place over private networks, in practice many companies rely on the public Internet in one form or another. Some utility companies may also rely on the "cloud"—servers hosted in data centers—to run their management systems and share data with third parties.
The first and third cases—customers and devices communicating with the utilities over the Internet—is a telecommunications issue, and one we have already discussed with respect to EINSTEIN’s applicability. We focus instead on the networks for reading and controlling customer usage and for managing the grid. Deploying EINSTEIN 3 would face many difficult challenges. The first of these is complexity. There are a large (and growing) number of energy providers communicating in complex ways over a mix of public and private networks. According to Lockheed Martin, by 2015 the smart grid will offer up to 440 million potential points of attack.71 Not only is power highly distributed to millions of customers, but also power generation is increasingly distributed,
70 See, e.g., Mikhail A. Lisovich, Deirdre K. Mulligan & Stephen B. Wicker, Inferring Personal Information from Demand-Response Systems, 8 IEEE SECURITY AND PRIVACY 11, 11–20 (2010). 71 Darlene Storm, 440 Million New Hackable Smart Grid Points, COMPUTERWORLD BLOG (Oct. 27, 2010, 3:11 PM), http://blogs.computerworld.com/17120/400_million_new_hackable_smart_grid_points?s ource=rss_blogshttp://smartgrid.ieee.org/news-ieee-smart-grid-news/1663-440-million- new-hackable-smart-grid-points.
2011 / Can It Really Work? 30
with a large number of small providers, including individual households, contributing energy to the grid. These “last mile” networks are an important part of the cyber security problem facing the power grid, but they are hard to protect without a large-scale deployment of security infrastructure. At the same time, the grid involves many independent (sometimes competing) parties with complex trust relationships. The grid is, at best, a loosely coupled federation,72 making it difficult to consolidate into a small number of network attachment points as the U.S. federal government is achieving through TIC. Even if consolidation were possible, the requirements for real-time data and high reliability make it undesirable to circuitously direct data through few consolidated access points. Yet any practical deployment of EINSTEIN 3 would have to occur at locations where these small, heterogeneous networks aggregate. For example, a provider could place an EINSTEIN 3 device at a site that aggregates the connectivity to all of its customers, or at “peering” locations that connect the provider to other parts of the grid. As such, any deployment of EINSTEIN 3 in the power grid would likely involve a large number of locations, which may be logistically and financially unwieldy and make any ability to do correlation of anomalous behavior much less likely. The second major problem is function mismatch. The IDS/IPS solutions useful for protecting U.S. federal government computer networks may not be a fit for the power grid and may in fact have to be completely redesigned for use in the power grid. Just as in the telecommunications sector, many parties in the energy grid already have their own IDS/IPS and firewall solutions from a variety of vendors, making the EINSTEIN 3 equipment at least partially redundant. A more complex issue is reporting. Energy providers must generate Supervisory Control and Data Acquisition (SCADA)73 reports as part of Critical Infrastructure Protection (CIP) requirements for the North American and Federal Energy Regulatory Commission (NERC/FERC).74 Existing IDS/IPS solutions are often integrated with other important functionality such as quality-of-service, 72 Larry Karisny, Smart Grid Security: Ground Zero for Cyber Security, MUNIEWIRELESS BLOG (June 2, 2010, 12:51 PM), http://www.muniwireless.com/2010/06/02/smart-grid- security-ground-zero-for-cyber-security/. 73 SCADA (Supervisory Control And Data Acquisition) systems are used to monitor and control industrial processes. 74 JUNIPER NETWORKS, SMART GRID SECURITY SOLUTION: COMPREHENSIVE NETWORK-BASED SECURITY FOR SMART GRID 4 (2010), available at www.juniper.net/us/en/local/pdf/solutionbriefs/3510346-en.pdf.
31 Harvard National Security Journal / Vol. 3
compression, SCADA-specific reporting, and integration with existing management tools that are not naturally part of EINSTEIN 3-type devices. SCADA presents a particular problem. SCADA systems are typically not used in Internet applications, and thus parsing the messages sent and received by these protocols would require custom extensions to EINSTEIN 3. Perhaps more importantly, these systems have vulnerabilities subject to unique attacks, such as the Stuxnet worm that attacked Siemens SCADA systems in several countries in the summer of 2010. The EINSTEIN 3 system in the power grid would need to create and continually extend a library of signatures for these SCADA systems, increasing the cost and effort in running the EINSTEIN 3 program. These requirements mean that EINSTEIN 3 equipment cannot be extended to subsume all of this functionality without a major redesign—at great expense and uncertain outcome. Future trends further complicate the problem. Certain grid communications, particularly in the back-end systems that control electricity generation and distribution, are highly sensitive to delay, which forcing traffic through a small number of EINSTEIN 3 locations would only increase. At this time, the grid does not have hard requirements on communication delay, but this could easily change with a move toward finer-grain control of electricity generation and distribution. Meanwhile fundamental to any security solution for power grid communication is encryption.75 Systems like EINSTEIN 3 can, at best, detect attacks while they are happening. Encryption of the critical communication in the grid can help prevent many of these attacks in the first place. Supporting encryption is challenging, as it requires support from the many customer meters and smart devices, as well as having secure ways to exchange keys between customers and the utilities. We discuss encryption in the next section, but note that whatever encryption solutions are chosen will have a significant influence on whether and how systems like EINSTEIN 3 should be deployed. This strongly implies that the basic security architecture for the grid should be resolved before significant effort is made to deploy EINSTEIN 3 within the power grid.
75 Currently encryption is not required. When it is implemented, the implementation is often very poorly done. See Joshua Pennell, Securing the Smart Grid: The Road Ahead, NETWORK SECURITY EDGE (Feb. 5, 2010), http://www.networksecurityedge.com/content/securing-smart-grid-road-ahead?page=2.
2011 / Can It Really Work? 32
It is now time to turn to security solutions. D. Approaches to Securing the Cyber Networks of Telecommunications and the
Power Grid We have argued that EINSTEIN 3 protections are inappropriate and infeasible for the commercial telecommunications infrastructure and the power grid. What might be done as a practical alternative? Beginning with telecommunications infrastructure, it is instructive to consider how such infrastructure was protected when AT&T was essentially the sole provider of telecommunications services in the United States. At the time the company owned and operated the vast majority of the country’s long-haul transmission systems (AT&T Long Lines). It operated two basic types of services over these: retail switched long-distance service, and the long-term lease of “private lines” to both private companies (e.g., the New York Stock Exchange) and governmental organizations (e.g., the U.S. Department of Defense). The combination of legal requirements and good engineering practice led the design of a network that was secured from a large variety of threats by three basic methods:
• Physical security: The carriage of U.S. government traffic on the AT&T network led to the requirement of physically securing and monitoring all AT&T transmission and switching facilities.
• Transmission security: At least to a reasonable degree, the signals carried over AT&T’s transmission facilities were protected from intercept. While only a few signals were encrypted, all were carried by means physically or technologically resistant to interception (e.g., on buried coaxial cable, or on multiplexed microwave signals).
• Separation of control and content: For a variety of reasons, AT&T embarked in the middle 1970s on an aggressive effort to separate the control information used to set up phone calls, and control the
33 Harvard National Security Journal / Vol. 3
network in general, from the circuits used to actually carry the call.76 This approach, termed “out-of-band signaling,” and today referred to as Signaling System #7, is now the rule in telephone systems (but not in data networks like the Internet). With the “signaling” separated from the content it was possible to make the network more robust in many ways, to improve its operating efficiency, to introduce new services such as 800 calls, and, of importance here, to dramatically reduce an adversary’s ability to intercept calls or to manipulate the telephone network itself.
There are two obvious differences between the modern telecommunications infrastructure in the present compared to that of the U.S. of thirty years ago: (1) AT&T is not the only long-distance provider any more; and (2) much more data is being transmitted than voice. A more nuanced comparison reveals the following differences, leading to the conclusion that the telecommunications infrastructure had more security than it does in the present day:
• Physical security: For a variety of reasons, but mostly owing to the financial cost involved, the plethora of modern North American telecommunications providers, many of them small and undercapitalized, provide little practical physical security for their transmission and routing equipment.
• Transmission security: Even though the wholesale conversion to digital transmission from the old analog methods would appear to equally permit wholesale use of encryption-based transmission security, it is still rarely used.
• Separation of the control and content “planes”: Originally because of different architectural design principles and future research plans in the ARPANET, and now locked into decades of legacy practice, the Internet operates on the principle of passing both the control and content information for an application over the same “pipe.” It is much harder to tamper with traffic or traffic routing, or to eavesdrop
76 A. E. Ritchie, Common Channel Interoffice Signaling, 57 BELL SYS. TECHNICAL J. 361 (1978).
2011 / Can It Really Work? 34
on content if control and content message are in different communications channels (the Signaling System #7 solution) than if the control and content are in the same communications channel. The practice of combining control and content permits a wide variety of attacks on both the users of the network and the network itself.
In an interesting case of “back to the future,” rather than proposing EINSTEIN 3 protections for telecommunications infrastructure, perhaps we should consider reintroducing telecommunications design principles that were in place three decades ago and applying these principles to cyber networks. While requiring these of all network operators might be neither desirable nor practical, it would not be unreasonable to consider that only “certified” network operators be considered when procuring communication services supporting critical civil or military activities. This certification should include, in order: (1) physical security; (2) transmission security via encryption or arguably equivalent protection; and (3) the use of techniques that isolate the control of the network itself from the content it carries. Such a separation would secure that which needed securing without the disruption provided by an IDS/IPS that would prevent the innovative telecommunications services the dynamic information and communications technologies sector keeps providing. The cyber infrastructures of the power grid, although vulnerable to cyberattacks, present a very different case. While critical infrastructure could (and perhaps should) not be accessible via the Internet, the system should be able to prevent malicious behavior—whether the attack is launched remotely or not. The controlling computer, aware of the generator's limitations, should refuse to initiate commands that would damage the equipment. Still, this solution merely introduces another problem—ensuring the controller software itself is reliable. But in this problem lies the key to protecting power grid infrastructure. Unlike telecommunications, the cyber networks of the power grid do not provide, or need to use, hot-from-the-developers communication technologies. This, and the fact that changes in power grid technology happen slowly—at least when measured by Internet years—greatly simplify the problem of protecting the cyber infrastructure of the power grid. Compared to operations that control the generator, software changes in
35 Harvard National Security Journal / Vol. 3
power grid cyber infrastructure occur relatively infrequently. Software updates could be delivered via a trusted courier instead of over the network. The broader solution to many of the security problems facing the power grid is cryptographic. No instruction to change behavior and or replace software should be accepted unless it is digitally signed. Once appropriate cryptographic measures are in place, the physical origins of the commands are no longer a concern; these commands can come in person, by telephone, the Internet, or satellite radio. The essential mechanism is guaranteeing that the agent with the authority to give a command possesses the correct authorizing key and is the only possessor of that key. The scale and diversity of authority can raise challenges in distributing and managing keys. Fortunately, the power grid consists of just a few thousand power companies in the United States, and not all of these companies run generators. This is not a particularly large number of users for a key- management system. Cryptography also offers a way of controlling smart devices and providing data about electricity usage. For example, encrypting communication from the electricity meter to the power company prevents rogue parties from passively snooping on the transmissions. Authenticating the messages from the power company to smart devices prevents unauthorized parties from remotely controlling these devices. Ensuring that electricity meters and smart devices have keys and the necessary cryptographic machinery is no trivial matter. Yet grappling with these issues is crucial to ensuring the security of the power grid, whether or not a system like EINSTEIN 3 is ever deployed.
V. Making Sense of Virtual Fences In 2005 Governor of Arizona Janet Napolitano said, “You show me a 50-foot wall and I’ll show you a 51-foot ladder.”77 She was discussing the physical fence being built between Mexico and the United States. Over time, the wall became a virtual one, in which electronic sensors, radar, and cameras were used to alert border guards about illegal crossings. In 2011, as Secretary of the Department of Homeland Security, Napolitano canceled
77 Linda Greenhouse, Op-Ed, Legacy of a Fence, OPINIONATOR N.Y. TIMES BLOG (Jan. 22, 2011, 5:07 PM), http://opinionator.blogs.nytimes.com/2011/01/22/legacy-of-a-fence/.
2011 / Can It Really Work? 36
the project,78 which had cost one billion dollars over its five-year effort. The secretary concluded the project was not viable. It would have been better, of course, to have realized this earlier.79 Had the “virtual fence” been evaluated for effectiveness from the start, it might never have gotten off the ground. The savings in time would have been quite valuable; even more important were the lost opportunities to pursue alternative solutions, opportunities lost because of diverted resources. Effectiveness matters, and should be measured at all points along the development cycle of a project.
EINSTEIN 3 is an electronic fence. The arguments in Section IV do not mean EINSTEIN-type solutions have no value. Rather, they mean that the effectiveness of such solutions should be weighed against alternatives before they are developed, and development should proceed with the technologies most likely to provide the needed security. There are a number of problems to be solved in order for EINSTEIN-type solutions to succeed. For example, within telecommunications, the issue of de-identified data sharing is one worth exploring. Recent research on “privacy-preserving” algorithms identifies ways to compute answers to data-analysis questions without revealing the raw input data. The classic example is the "millionaire problem," where two people want to know who is richer without revealing the precise amount of their wealth to each other.80 In the context of IDS/IPS systems, multiple sites, each run by different companies, may want to identify malicious users that send excessive traffic, while neither divulging the total traffic received at each site nor revealing the access patterns of the well-behaved users.81 Promising solutions already exist for many of these kinds of data-analysis tasks. Further innovations in this area could lower the barrier for collaborative security solutions to protect critical infrastructure. Another direction to pursue is opening up the EINSTEIN 78 Julia Preston, Homeland Security Cancels ‘Virtual Fence’ After $1 Billion is Spent, N.Y. TIMES (Jan. 14, 2011), http://www.nytimes.com/2011/01/15/us/politics/15fence.html?. 79 This is not a comment on Secretary Napolitano, who had inherited the program. 80 Andrew Yao, Protocols for Secure Computations, in PROCEEDINGS IEEE SYMPOSIUM ON FOUNDATIONS OF COMPUTER SCIENCE 160–64 (1982). 81 Benny Applebaum, Matthew Caesar, Michael Freedman, Jennifer Rexford & Haakon Ringberg, Collaborative, Privacy-Preserving Data Aggregation at Scale, PROCEEDINGS PRIVACY ENHANCING TECHNOLOGIES SYMPOSIUM (July 2010).
37 Harvard National Security Journal / Vol. 3
architecture to public view. While using classified signatures on a private- sector IDS/IPS creates a complicated control mechanism, the decision to have some signatures classified may not itself be unreasonable. That is in contrast to the decision to classify the architecture, which is not a sensible choice. A fundamental principle in cryptography, Kerchoffs’ Law, is that a cryptosystem’s security should depend not on the secrecy of the algorithm but solely on the secrecy of the key.82 Similarly, an IDS/IPS security solution should depend solely on the secrecy of the signatures being used. Public examination of the architecture allows a full appraisal and will establish greater confidence and trust in the system. The lack of a public vetting of the EINSTEIN 3 architecture being used in protecting federal civilian agencies means that there has been virtually no informed public discussion on the efficacy of using EINSTEIN-type technologies in protecting critical infrastructure. Consider the virtual fence at the border, the project that Secretary Napolitano canceled. “The problem with the [virtual fence] was that it is the wrong kind of technology to be deployed across the entire U.S.-Mexico border,” Napolitano said. “It was too expensive, it was too elaborate and it was not flexible enough to meet the fact that immigration patterns change.”83 In the absence of a public vetting of EINSTEIN 3 technology, it too is likely to be too expensive, too elaborate and not sufficiently flexible as attacks vectors change. In order to consider such a heavyweight security solution, the architecture should be made public. This should happen early in the life of the program. The publicly available documentation on EINSTEIN does little to clarify the technology’s limitations. While experts understand that signature- based schemes can only protect against known attacks, the publicly available documentation on the EINSTEIN technology does not state this. U.S. Deputy Secretary of Defense William Lynn has characterized the cyberexploitations of U.S. business and government sites as what “may be the most significant cyber threat that the United States will face over the long term.”84 The technically unsophisticated reader would have no idea from reading the EINSTEIN documentation that the technology provides
82 David Kahn, THE CODEBREAKERS: THE STORY OF SECRET WRITING 235 (1996). 83 Lauren Gambino, Failed Virtual Border Fence has Politicians Pointing to Success in Yuma Area, CRONKITE NEWS (Jan. 31, 2010), http://cronkitenewsonline.com/2011/01/failure-of- border-fence-has-politicians-pointing-to-success-around-yuma/. 84 William Lynn III, Defending a New Domain, 89 FOREIGN AFFAIRS 97, 100 (2010).
2011 / Can It Really Work? 38
essentially no protection against such attacks.85 This should be made clear to policymakers. The inflated implications of what EINSTEIN can handle—phishing,86 IP spoofing, man-in-the-middle attacks87—noted in Section II are likely to lead to unrealistic expectations regarding the problems EINSTEIN-type solutions can solve, and are not unlike the claims made for the virtual border fence.
After examining the complications of applying EINSTEIN 3-type solutions to telecommunications and the power grid, it should be clear that the current architecture of EINSTEIN 3—concentrated Internet access points cooperating to perform intrusion detection/prevention—does not provide a viable model for protecting the cyber networks of critical infrastructure. EINSTEIN 3 is a virtual fence that has the potential to work when you can funnel all comers through your gates—that is EINSTEIN 3 applied to the federal civilian agency sector—but not when architecture and control are highly distributed. Private infrastructure is likely to remain inherently more distributed and less trusting of partners than U.S. federal government services. To be viable, what is needed for protecting critical infrastructure’s cyber networks are new IDS/IPS solutions that scale to a large number of vantage points and analyze traffic without divulging private user data or proprietary business data. That should be the direction pursued in protecting these networks, not that of molding them into centralized systems more akin to the public switched telephone network. Sometimes hammers are just not appropriate solutions. So it is in this case.
85 We say “essentially,” since by eliminating some malware, the exploitations launched by the highly targeted attacks may stand out more. That is, however, a second-order effect, and one that cannot be counted upon. 86 EINSTEIN should be able to prevent phishing and spear phishing attacks that use known malware. Highly-targeted spear phishing exploitations using zero-day attacks are unlikely to be stopped. 87 INITIATIVE THREE EXERCISE, supra note 24.
Assignement2/Written Assignment.docx
Written Assignment
Submit as single MS Word document.
Title each Part below. The minimum approximate length for both Parts should be 1500 words
Part 1
o Evaluate arguments and theses by
1. Clemente (2013) https://www.chathamhouse.org/publications/papers/view/189645#
2. Bellovin, Bradner, Diffie, Landau & Rexford (2011) **See Attachment**
3. Saadawi & Jordan (2011) *** See Attachment**
4. FEMA (2013) https://www.dhs.gov/national-infrastructure-protection-plan
Specifically, respond to the following questions:
1. What do they in common?
2. What are the differences is their assessment of cybersecurity and critical infrastructure protection?
3. How does FEMA's Critical Infrastructure Protection Plan address key requirements set for by Clemente (2011)?
Conclude with a research or policy question for further research.
You must utilize literature and cite and reference your work using APA style.
Part 2
Evaluate
1. Findings and Lessons Learned in Xia, Becerra-Fernandez, Gudi, & Rocha-Mier (2011) ***See Attachment***
2. Information Fusion in Hennessy, Patterson & Lin (Eds.) (2003). **See Attachment***
3. Can these findings be utilized in your city, county, state EOC. Why? Why not?
4. Conclude with a research or policy question for further research
You must utilize literature and cite properly.
o Use APA style. Submit as Microsoft Word document.
Readings:
Part 1:
· Clemente, D. (2013). Cyber security and global interdependence: What is critical? Programme Report. February 2013. Chattam House.
· Bellovin, S. M., Bradner, S. O., Diffie, W, Landau, S. & Rexford, J. (2011). Can It Really Work? Problems with Extending EINSTEIN 3 to Critical Infrastructure . Harvard National Security Journal. 3.1, pp. 1-38.
· Saadawi, T & Jordan, J. Jr., (2011). eds. Cyber Infrastructure Protection . Carlisle Barracks: U.S. Army War College, Strategic Studies Institute.
· FEMA (2013). National Infrastructure Protection Plan .
Part 2:
· Xia, W., Becerra-Fernandez, I., Gudi, A., & Rocha-Mier, J. (2011). Emergency Management Task Complexity and Knowledge-Sharing Strategies . Cutter IT Journal, 24(1), pp. 20-25.
· Hennessy, Patterson & Lin (Eds.) (2003), Information Technology for Counterterrorism: Immediate Actions and Future Possibilities, Section 2 (Types of threats associated with information technology infrastructure), Section 3.2 Systems for Emergency Response and Section 4 . National Academies Press.