Showing posts with label CYBER OPERATIONS. Show all posts
Showing posts with label CYBER OPERATIONS. Show all posts

Thursday, May 19, 2016

Cyber Conflicts: Quiz 3 - Cyberwarfare and International Conflicts

This week quiz is also very simple and easy to comprehend and answer. However, if you require any suggestion or help about how to answer do mention in the comment and I will help with that.


1. Since 1999 cyber attacks have caused large-scale injury, loss of life and destruction of property.
  • True
  • False
2. Identify the item which has NOT been recognized as a mode of cyberwarfare attack and activity.
  • Information gathering and espionage
  • Disruption of services
  • Physical system attacks
  • Social media and propaganda
  • None of the above
3. The countries who conduct powerful cyber attacks are:
  • Russia and China
  • China and U.S.
  • U.S. and Russia
  • All of the above


4. What's the current level of threat of cyber attack of terrorist activity, aka cyber terrorism?
  • Cyber terrorism threat has been largely unfounded
  • Cyber terrorism threat is somewhat likely
  • Cyber terrorism threat is extremely likely and dangerous
  • Cyber terrorism often happened in the past but no longer a big issue
5. What's an example of a real event for an activity of non-state actors?
  • Citizens in Russia working to attack computers in Estonia
  • Bank personel in China using computers to attack Australia
  • Groups of thugs in Egypt using cyber attacks on Tunisia
  • None of the above
6. There are a defined set of cyber attack characteristics that can clearly identify the different types of actor motivations.
  • False
  • True
7. A 2009 attack on more than 30 companies including Google and Yahoo stealing intellectual property was attributed to Taiwan. Where were the hackers traced back to?
  • Taiwan
  • China
  • U.S.
  • Russia
  • Iran


8. ___________ of infrastructure means a failure in one element could cause cascading failures on multiple _____________ infrastructure components.

Choose the BEST set of terms to complete the phrase above:
  • interdependence; critical
  • association; cyber
  • criticality; complex
  • internet; cyber
  • comparability; internet
9. Techniques for censoring information include the following, except:
  • IT blocking
  • URL and packet filtering
  • Web feed blocking
  • DNS filtering
10. __________ are machines connected to the Internet who have been infected by a virus or spyware and may be used by others to cause damage to any computer or networks, including by "denial of service attacks" where multiple __________ can suck up the resources of certain critical computers connected to the Internet.
  • Modems, IPs
  • Bot nets; bots
  • Trojans; viruses
  • Computers; spams

Cyber Conflicts: Internet Censorship

Another looming battle that we see is of internet censorship.

When the governments try to control the public internet, a struggle over information content has caused international discord. Some governments are apprehensive about exposing their citizens to offensive material that might be morally, culturally, or politically deleterious. While other government and citizens' groups vociferously advocate free speech. Effective censorship requires multi layered access control, including laws and regulations, technical filtering, physical restrictions, surveillance, and monitoring, warnings as the last, arrests. Laws and regulations include penal codes, anti-terrorism laws, visual media laws, and legislation allowing government access to ISP and telecommunication company information. For instance, the Chinese government deploys firewalls and gateways to prevent access to certain IP addresses. It also performs DNS poisoning of specific websites and imposes harsh penalties on ISPs and organizations that carry content not permitted by Chinese law.

Many other countries also engage in online censorship including Bahrain, Burma, Cuba, Iran, Jordan, Kuwait, Saudi Arabia, the list goes on.

And even Germany and Switzerland censors specific web sites for content. Techniques for censoring information include IP blocking, DNS filtering, routing, url and packet filtering, as well as blocking the web feed. Internet content is also monitored through automated tools and manual inspection to block objectionable pages and ISP cooperation.

Censorship can, however, be circumventing through use of proxy servers, allowing anonymous access to censored material. These servers can be blocked and their use discouraged by government threats to shut down websites.

So there's a fight on the censorship fronts. The large companies sometimes fight back. For example, in 2010 Google threatened to remove its Google dot China search engine and website unless China allowed its search engine to access uncensored information.

Remove its offices from China, cancel media events and delay release of phones with Android operating system. These declarations were in response to a chain of hacker attacks on Google's servers.

Top Courses in IT & Software 728x90 And brought out the long growing battle of internet censorship into the open.

Concerning the economic consequences of such actions companies cooperating with governments receive preferential access to rights and contracts, while non cooperating companies can lead to potential harassment and litigation. Google was among the first in around 2006 to willfully abide by the Chinese internet censorship regulation. Despite public disapproval in the US, Google's decision, 2010, to suspend censorship rules in China in response to the attacks and is not only financial based but as retaliation for the espionage. The threat of Google alone may not warrant concern, but combined with other large companies such as Microsoft and Yahoo could pose a greater threat to China's situation than any government action.
Top Courses in Network & Security 728x90
Scholastic Teacher Store Spring Special ends 5/31/16
The leverage of companies against governments and the influence of individual governments have helped in

in multinationals is generally defined by local circumstances.

The complexity of the issue of government control of information is evident from both the public battle, and it is part communication company in motion and it would to mid 2011. When it had to engage with several countries, including China, India, Russia, Saudi Arabia, and UAE so that they could monitor Blackberry communication, ostensibly for fighting terrorism.
April2516-25off-sitewide468x60
Being a cross border network makes it difficult for RIM, or Research In Motion, the company that makes Blackberry, to comply with conflicting laws in different countries. For example, dealing with a call between US and somebody outside, let's say in China, can become very tricky, where US citizens are protected by US laws. China emphasizes the rights of the government to be able to intercept and monitor communication.

So there are a lot of such contentious issues that we are facing. And we need to face all of these issues as we go forward in the cyber warfare arena. There are several actors which have all independent motivation. There are several attacks that can be launched. But one thing is clear, the strategies of national governments are very strong in developing these cyber arsenals. And there's a cyber going on, and we need to discuss it and debate it and make sure this does not derail the free internet and all that we have come to expect of it. Thank you very much.

Cyber Conflicts: Future Battles - Threats to Critical Infrastructure

The cyber warfare incidents to date have not generated mass panic, and are driven more by citizen groups, rather than the overt government sponsored national campaigns. These past attacks were meant to send a political message. However, future attacks could have serious consequences, pitting nation against nation and requiring political as well as military intervention. One concern shared by all governments is that threat to critical infrastructure through electronic control systems.
Testive
The critical infrastructure is an easy target for enemy countries and rogue transnational since groups it is widely distributed geographically and left largely unprotected. The systems and manage water supply, power, oil and transport are all a part of the national critical infrastructure. Each represents different threat levels. The significant interdependencies can lead to unintended consequences during an attack.

The critical infrastructure is also increasingly under the control of SCADA systems. A supervisory control and data acquisition system. Probably through ease of remote monitoring and management. However, increased accessibility correlates with increased vulnerability to breach security. And as SCADA has become more and more homogeneous. The potential of breaches is further exacerbated since a single exploit could be used to attack multiple systems. They draw graphic distribution of critical infrastructure, the government recognizes as inability to protect everything. A key concern is that interdependence of infrastructure elements could mean a failure in a single element could cause devastating widespread damage in multiple critical infrastructure elements. The power grid is one of the most vulnerable including transmission lines, transformers, power stations and suppliers.
April2516-25off-sitewide468x60
In 2009 actually authorities found that many segments of the U.S. power Ggid had experienced and suspected hacker infiltration. Software tools are to be used to disable infrastructure while identified on the machines. Interdependencies in the power grid alone were evident from the blackouts throughout the Northeast US and Canada in August 2003. A failure of a single Ohio power plant led to complete blackout of the Northeast US, along with nearby connected portions of Canadian National Power System.

Given some fragility in the system, we need to be very careful in protecting our critical infrastructure from cyber attacks. In 2008, the US power grid in multiple regions was disrupted purportedly for the purpose of extorting money.

The water supply is another critical infrastructure.

Encompassing both fresh water supply and wastewater collection. The US has more than a 170,000 public water systems, including weather wise dams, wells, aquifers, treatment facilities, pumping stations, aqueducts, and transmission pipelines. Waste collection includes 19,500 sanitary systems and 800,000 miles of sewer lines. In October 2006, an unknown hacker gained control of water filtering plant in Harrisburg, installing software that affect the plant operations. Though the US water supply is well distributed for the country, presenting multiple soft targets.

Interdependencies are weak and the effect of any single attack would be localized affecting at most a few hundred people.

A fail bomb is easily repaired or restarted leading to quick recovery without any serious long term devastating consequences but again the potential is here.

The financial of, the failure of financial institution infrastructure is however, more serious. It could undermine public confidence in financial institutions, as well as the government.

Less clear is how to compare these financial losses to the loss of life or to injury. Not all infrastructure attacks are perceived as equally devastating.

The risk and interdependency analysis are needed to accurately determine the risks. There's a lot of work that needs to be done.

Sunday, September 6, 2015

Cyber101x Cyberwar, Surveillance and Security - Week 5 - Cyber Operations

CYBER OPERATIONS THAT CONSTITUTE AN ARMED CONFLICT




 
DALE  TEPHEN : It i  intere ting that Profe  or  chmitt acknowledge  that the red line of where a cyber operation con titute  a violation of Article 2(4) wa  not deci ively  olved in the Tallinn Manual. Thi  i  a matter of ongoing  tate practice to reveal more concretely though the Manual doe  outline factor  that may be taken into account when coming to thi  determination. A more fundamental que tion i  when doe  a cyber operation amount to an armed attack for the purpo e  of invoking a right of  elf defence under Article 51 of the charter. Again, the Nicaragua ca e i  in tructive in thi  area, in that it hold  that  uch an armed attack mu t be of a  ufficient gravity. Equally, it mu t be borne in mind that a cyber operation that con titute  a violation of Article 2(4) on the threat or u e of force, may not actually ri e to the level of an 'armed attack', giving ri e to a right to re pond in  elf defence through either cyber mean , or through kinetic force. Let'  li ten to how the Tallinn Manual applie  the e factor  in the context of cyber operation . MIKE  CHMITT: 2(4) i  only about whether or not a  tate ha  violated international law with it  cyber operation. The re pon e come  in Article 51. When can I re pond? You can re pond when the u e of force directed again t you i  of a particularly egregiou  u e of force known a  an armed attack. We believed -- that i , not the po ition of the United  tate  -- but all the expert  concurred, that we believe the e are two different  tandard . That the charter wa  meant to allow people to trip over the u e of force pretty ea ily, but that before a  tate could re ort to force in re pon e, it had to be a pretty bad u e of force.  o here, we were much more comfortable  aying the thre hold i  armed attack -- I'm  orry, i  phy ical de truction injury. And  ignificant. Not the phy ical de truction of my laptop, but rather  ignificant phy ical damage or injury. It'  at that point that the right of  elf defence mature . Now we were very quick -- and I happen to be one of the e people, who  aid, that we believe thi  norm will evolve. And it'  becau e international law i  meant to track the value  of a  ociety. And,  o if  uddenly, we  ee particular a pect  of  ociety'  activitie   ubject to new threat , we can expect the interpretation of exi ting law to, through  tate practice, move very quickly to meet thi  new threat. We  aw thi  example with re pect to tran national terrori m. I could go on and on about that. But I expect to  ee the  ame thing in cyber.  o, for example, I've ju t explained that you probably need phy ical damage. What if  omeone conducted a ma  ive cyber attack again t the Au tralian economy? Which could be done. And you're  tarting to collap e a pect  of the Au tralian economy. That'  not phy ically de tructive. It may manife t in phy ical con equence   uch a  hunger down the road. But it'  not phy ically de tructive. Neverthele  , I'm not quite certain that the Au tralian government would not re ort to force, either cyber force or kinetic force, in order to re pond to  omething that deva tating.  o we will  ee that norm evolve pretty quickly, and we're  tarting to  ee  ome movement on the part of  tate , particularly the Dutch, in thi  direction.

CYBER OPERATIONS THAT FALL SHORT OF AN ARMED ATTACK

  DALE  TEPHEN : Well, the ri e of cyber a  a mean  and method of warfare i  now a real po  ibility. It only activate  the law of armed conflict when it con titute  an attack in the cour e of that armed conflict. Thi  will be dealt with in the next module. What we are dealing with in thi  module i  the international law applicable to cyber operation  mounted by  tate  or non- tate actor  that do not amount to a cyber attack, but nonethele   can re ult in genuine negative con equence . One  uch example wa  the attack on  ony in the U  late in 2014. The incident I'll refer to a  the  ony Hack began on November 22, 2014, when it became apparent that  ony Picture ' computer  y tem had been compromi ed. The BBC reported that  kull  appeared on employee  creen  with a me  age which threatened to expo e  ecret  from data obtained in hacking. Large quantitie  of confidential information and company a  et  were  tolen. Multiple film  were then illegally uploaded to file  haring  ite . Confidential employee information wa  leaked, and private email  were made public. A group identifying them elve  a  the Guardian  of Peace, who had been linked to the North Korean  tate-run Bureau 121, claimed re pon ibility for the hack. The group al o made threat  again t theatre   et to conduct  howing  of  ony Picture ' controver ial  atire, The Interview, a film that had been critici ed by the North Korean foreign mini try. Another example i  the interference with the cyber infra tructure of E tonia in 2007 following the removal of the  oviet war memorial from the centre of the city that we've already covered in the fir t module. In that in tance, there were numerou  denial of  ervice attack  on government web ite , defacement on many web ite , botnet attack  and di tributed denial of  ervice attack  undertaken. The origin  of the attack  were tracked to over 150 other countrie , although a number were al o tracked to a number of Ru  ian government in titution . What doe  international law  ay about  uch interference? In e  ence, international law provide  a number of prohibition  of increa ing  ignificance relating to external interference. The varying  ignificance of the gravity of the interference  peak  to the type of re pon e  that are permitted under international law. A number of the e ground  were articulated by the International Court of Ju tice in the 1986 Nicaragua ca e; although that ca e wa  concerned with phy ical activity, not cyber, it  till provide  a u eful foundation. At it  mo t ba ic, interference with another  tate'   overeignty can amount to a violation of international law. Hence overflying national air pace without permi  ion, or non-innocent pa  age within the territorial  ea of a coa tal  tate, con titute example  of a violation of  overeignty, and hence a violation of international law. In the context of cyber operation , it matter  greatly what the  tate undertaking the violation i  doing. Li ten to Profe  or  chmitt a  he detail  three example  of apparent cyber interference that do, or in hi  opinion, do not, amount to a violation of  overeignty. MIKE  CHMITT: When do you violate the  overeignty of another  tate? We're looking at that in a proce   called the Tallinn 2.0, it'  an update to the Tallinn Manual, and, in fact, I ju t came back la t week from looking at that. And we believe there are three  ituation . The fir t  ituation i  where one  tate, and we're only talking  tate  here, not non- tate actor , where one  tate conduct  a cyber operation in a  econd  tate, and that cyber operation cau e   ome  ort of damage.  omething break ,  omeone i  injured. The computer doe n't work anymore, the computer doe n't function. I believe mo t international law expert  would concur, there'  ab olutely no que tion that that operation violated the  overeignty of the target  tate, even though the operation wa  launched from out ide the territory of that  tate. Now if we move down the continuum a little bit, we get to a  ituation where an operation i  launched by a  tate from out ide the territory of the target  tate, and in tead of breaking  omething, phy ically  omething doe n't work and no longer function , the fir t  tate i  manipulating one  and zeroe , i  changing data, i  de troying data, i  doing  omething in ide the  y tem of the territorial  tate. Now, here all international lawyer  do not agree that thi  i  a violation. But I do. I believe that'  the functional equivalent of your agent being in the other  tate, doing  omething that the other  tate would not have that agent do.  o in my view, that'  a violation of  overeignty. And then there'  the third  ituation, where you're in ide another  tate'   y tem, but you're not manipulating data, altering data, changing data, in any way that'  nece  arily adver e to the target  tate. For example, you put malware in ide the  y tem where you  imply track the activitie  of that  y tem. When doe  the  y tem come on, when doe  it come off, to whom doe  it communicate, et cetera, et cetera, et cetera. Here we have the  malle t group of international lawyer  that would  ay thi  i  a violation of  overeignty. I'm not one of tho e that would  ay that'  a violation. And the rea on I don't accept that a  a violation i  that, to me,  mack  of e pionage, and we've never  aid that e pionage i  a violation of international law. The act  that underlie e pionage may be a violation, but not e pionage per  e.  o tho e are the two below the thre hold likely violation  of international -- there are many more that I could come up with. For example, we're  itting here in Newport, Rhode I land, where we  ee the  ea out here. That'  the American territorial  ea. If a war hip from another  tate come  into our territorial  ea and conduct  cyber operation  again t the War College, then, in that ca e, that would violate our  overeignty, our territoriality, becau e it would not be what i  known a  innocent pa  age. It would be pa  age through our  ea adver e to our intere t .  o there are many other violation  I could give you, but the two big one  are intervention and a violation of  overeignty.

 DALE  TEPHEN : It i  in tructive from Profe  or  chmitt'  commentary, that a forming con en u  accept  that pa  ive ob ervation of communication  through cyber mean  doe  not, in it elf, con titute a violation of  overeignty. Thi  wa  a point that I made back in week three about international  urveillance activity. Whether regional human right  law  and practice  will cry talli e in the future into  ome more general international human right  principle to prohibit  uch activity remain  to be  een. But for now, it would appear to be not  ubject to  uch a conclu ion. In any event, it would  eem unlikely that even a broadly ba ed prohibition would not  till allow  ome kind of national  ecurity exemption. It  eem  very unlikely that  tate  would not include  uch a qualification. What i  caught for certain i  any activity that cau e  phy ical damage, po  ibly including to the data it elf. Whether changing data within a  y tem through intervention con titute  a violation of  overeignty i   omething that ha  divided opinion. A more  ignificant breach of international law occur  where a  tate violate  the principle of non-intervention. Thi  principle exi t  in cu tomary international law. In the Nicaragua ca e, the ICJ examined U  funding of rebel group  in Nicaragua, and determined that thi  did amount to a violation of the principle of non-intervention. The principle of non-intervention wa  expre  ed by the court to be ba ed on the concept of coercion. The court then ventured an ob ervation that the principle i  violated, not only in re pect of the u e of direct force, but al o by the application of indirect force, including, for example, monetary  upport for  ubver ive or terrori t activitie . How doe  thi  type of te t manife t in the cyber domain? Thi  may be manife ted when  tate A manipulate  the election return  of  tate B, thu  re ulting in the election of a candidate that may be more  ympathetic to  tate A'  need  or de ire . It may  imilarly be manife ted in any kind of manipulation that indirectly, but cau ally, a  i t  in any rebel group gaining a  pecific military advantage through the direct manipulation of data within the target  tate. The breache  de cribed above all fall below the actual armed attack criteria that the ICJ ha  con i tently held in the Nicaragua and  ub equent Oil Platform  ca e a  having a high thre hold. For example, that then give  ri e to a right of kinetic or cyber  elf defence under Article 51 of the charter.  o what then i  available to  tate   ubject to  uch violation  that don't meet the armed attack thre hold? In thi  in tance, general international law doe  provide  ome guidance. The 'Article  on Re pon ibility of  tate  for Internationally Wrongful Act ' are a product of the International Law Commi  ion, and reflect many year  of work. They are regarded a  an authoritative reading of the right  and obligation  in thi  field. Let'  li ten to Profe  or  chmitt'  outline of the right  that a victim  tate may have under principle  of international law, and largely reflected in the  tate Re pon ibility regime. The e cover retor ion, countermea ure , and nece  ity. MIKE  CHMITT:  o if we're talking about the remedy of  tate  below the thre hold -- again, I want to empha i e thi  i   omething which in the ca e of remedie , doe  not ri e to the level of an 'armed attack' under Article 51 of the UN charter, becau e that'  the point at which you may u e force in  elf defence. If we're not talking about tho e  ituation , mo t of the re pon e  appear in the law of  tate Re pon ibility. The International Law Commi  ion ha  produced draft article  on the law of  tate Re pon ibility which mo t  eriou   cholar  believe fairly accurately repre ent cu tomary law. And we are, in fact, in the Tallinn proce  , u ing the article .  o there are actually three remedie  that are critical. At the lowe t level, a  tate may alway  engage in what'  called retor ion. Retor ion i  an unfriendly but lawful re pon e.  o, for example, if you conduct, if your  tate,  tate A conduct  a cyber operation again t my  tate,  tate B, I could choo e to  hut off, ab ent any applicable treaty regime,  hut off your acce   to  erver  in my country. They're in my country, I have  overeignty over tho e  erver , territorial  overeignty over the  erver . Unle   there'  a treaty regime to the contrary, I have the authority to  ay you can't,  tate A can't come into my  tate,  tate B. That would be an act of retor ion. It'  not friendly, it'  unfriendly, but it'  lawful. And that would be de igned to induce you back into compliance with international law. Now, if your act i  an internationally wrongful act, it'  a legal term that mean  if you violated international law, in particular, an obligation you owe me, your  tate owe  my  tate, then I might engage in what are called countermea ure . Now a countermea ure i  a  tep up from contor ion. What a countermea ure i , i  a countermea ure i  an act that would otherwi e be unlawful but for your initial act.  o you,  tate A, intrude into my  y tem, violating my  overeignty. I may do thing  in cyber pace, or not in cyber pace, I may do thing  that otherwi e would violate my obligation  owed to you, in order to compel you back into compliance with the law. And the logical thing in cyber pace would be -- you hack into my  y tem , you manipulate my one  and zero , and  o I re pond in kind. I hack back. I normally would not be able to do  o, becau e I would be violating your  overeignty. But becau e of your unlawful act, the veil of  overeignty ha  been pierced. And I can re pond. And then, the next level up i  found in Article 25 of the article  of  tate Re pon ibility, and it'  called the plea of nece  ity. Now, the plea of nece  ity i  an act taken when your  tate i   uffering  omething that affect  it  e  ential intere t in a grave and imminent way. The e are term  drawn from the law.  o it mu t be an e  ential intere t, very, very important, and in the cyber context, we in tantly think of critical infra tructure, e  ential intere t i  affected, and in a way that'  grave, in other word , very, very  eriou , and imminent. It'  happening now, or it'  about to happen. If your country find  it elf in thi   ituation, then it may re pond with action  that would otherwi e violate international law obligation  owed to other  tate .  o I could hack back at whoever'  hacking. Now, why i  the plea of nece  ity important? The plea of nece  ity i  important for two rea on . Fir t, there'  no requirement that there be a violation of law, of international law, a  a condition precedent. All you know i   omething really bad i  happening to u , and I need to re pond right now. And the  econd important thing i , i  wherea  countermea ure  are limited to wrongful act  by  tate , when we're talking about the plea of nece  ity, you can be re ponding to an act conducted by non- tate actor  like cyber terrori t , or you can be re ponding to an act where you don't even know who'  conducting the act. You don't know if it'  a  tate, you don't know if it'  attributable to a  tate, you don't know if it'  a non- tate. All you know i  it'  really bad and I've got to do  omething. Hack back or whatever. What thi  doe  i  it give  you, if you will, from the American game Monopoly, a get out of gaol free card. Your wrongful act i  no longer wrongful, even if it affect  the intere t of other  tate ,  o long a  the intere t of the other  tate  you're affecting i n't e  ential to them.  o in order to defend your cyber infra tructure, you can't hack back into their critical cyber infra tructure and  hut that down. Becau e that would be their e  ential intere t.  o you  ee a balancing happening here. And then the fourth  tep along the journey, i  the law of  elf defence under Article 51. 

 DALE  TEPHEN : In re pect of countermea ure  that you've ju t heard Profe  or  chmitt refer to in the Article  of  tate Re pon ibility, they provide in Article  51 and 52 that  uch countermea ure  mu t be proportionate, and that notice mu t be given prior to any invocation of  uch countermea ure .  uch a requirement for proportionality may be manife ted in relation to a 'hack back', a reciprocal re pon e through  imilar mechani m . But thi  i  not without it  ambiguity. The que tion of notice i  equally potentially problematic in under tanding what i  required in giving  uch notice. What i  a rea onable notice to provide in  uch circum tance  where action  are taken in tantaneou ly? What do the Article  on  tate Re pon ibility provide for in thi  in tance? Can urgency, for example, be an excu e not to provide  uch notice? The an wer to that que tion i  actually Ye . Article 52(2) of the Article  provide  that an injured  tate my take urgent countermea ure  a  are nece  ary to pre erve it  right . Thi  rai e  the i  ue of attribution. In undertaking a re pon e,  tate  need to be clear a  to the origin of the cyber operation, and al o the connection of the target and the  tate.  ignificantly, the que tion of attribution i  one that come  up frequently in thi  field. But it i  al o one that can be often over tated a  being problematic. Li ten next to what Emma Lovett, a cyber expert, ha  to  ay on thi  i  ue. There are a number of way  that attribution can be verified in practice. In the next clip, you'll hear her  peak about the rea oning proce   that goe  into triangulating the origin of an attack, and the identifying  ignature  that code can reveal in e tabli hing attribution. EMMA LOVETT: A  we know, the internet take  package  of information, and di per e  them, and then a  emble  them again at the other end where you want them to arrive. Being able to  ay with certainty what bit  of the world they went through, and who wa  making them go through there, i  the attribution part.  o, it'  not  o much about determining exactly where the e little bit  and byte  were at a particular time. It'  being able to  ay, we think country alpha wa  attacked by country yankee, becau e we know there were, for example,  ix  erver  that it went through. We know that two of them were in country tango, country uniform. But before we get to country yankee, we lo e a couple of  erver . We don't get the whole trail.  o how do you come to a point where I can be certain with very high confidence in my attribution? And I want a high confidence. If I'm  aying that country yankee ha  done  omething contrary to my  tate  ufficient to be equivalent to an armed attack contrary to my intere t , and I want to re pond with force, whether it'  cyber or not. And may I ju t add, You're not going to get kinetic attack  without cyber in thi  world. Ju t  aying.  o how do I get from here to here when I've got a gap? I'm al o going to be looking at the character of the attack. Becau e the nice thing about being attacked i  you get to have the time, the luxury to pull apart the code, the programming, and you get a feel for where it come  from. There are identitie  that become apparent.  o you can  ay, well, thi  i  the  ort of work that come  from thi  region of the world. Why? Becau e they  peak a certain language and that'  the way their brain  work. Even though computer language i  it  own thing, we  till have our own ethnic tendencie . And that'  the  ort of thing that we think come  from there. Then you add the political overlay of why it would be that country. And if thi  were an intelligence analy i , you add one, two, three, and four, and the character -- attribution. More likely than not.

 DALE  TEPHEN : In re pect to the plea of nece  ity that you've heard Profe  or  chmitt refer to, you may recall that he mentioned that thi  right of re pon e turned on a grave and imminent threat to an e  ential  tate intere t. Moreover, that  uch a right could be exerci ed again t both  tate and non- tate actor . Key to thi  authority i  that an e  ential  tate intere t ha  been affected. While power  ource  and other infra tructure that  ignificantly underpin  normal daily life would be covered, it i  le   clear what el e may be included. A  a criteria nece  ary to be e tabli hed before any re pon e may be legitimately undertaken, it i  important to under tand the boundarie  of e  ential  tate intere t in thi  context. The matter i  one that i   ubject to ongoing con ideration by both expert  and  tate  in thi  dynamic area. The final i  ue to be canva  ed in thi  outline of right  and obligation  i  when a cyber operation amount  to a violation of Article 2(4) of the charter. Namely, a threat or u e of force. The Nicaragua ca e previou ly mentioned had determined that the  upply of arm  and training to rebel group  within a  overeign  tate can con titute a violation of Article 2(4), thu  giving ri e to a right of countermea ure , or potentially, even a plea of nece  ity in re pon e. How doe  thi  manife t in the cyber phere? When would a cyber operation amount to a breach of Article 2(4)? Let'  li ten to what Profe  or  chmitt  ay  on the i  ue. MIKE  CHMITT: With regard to Ju  ad Bellum, and Ju  ad Bello, there were a number of problem . With regard to, let'   tart with the Ju  ad Bellum. There were two. They are the cla  ic que tion . What i  the 'u e of force' pur uant to Article 2(4) of the UN charter? Becau e there'  a prohibition on the u e of force unle   there'  one of two exception . The  ecurity Council approve  the u e of force, or alternatively, the u e of force i  an act of  elf defence.  o when i  a cyber operation by one  tate again t another  tate a u e of force? We agreed that any time a  tate u e  a cyber operation that cau e  phy ical damage or injury, that wa  a u e of force. And it could only be ju tified by one of the two exception . However, in the very famou  Nicaragua ca e, the ICJ ca e in 1986 ca e, the ICJ held that you don't nece  arily have to have forceful action  to trip over thi  wire. For example, if you arm and train guerilla , that could be a u e of -- you arm guerilla  and then train them to u e weapon  -- that could be a u e of force. And we  aid, well golly, that mu t apply in the cyber context a  well. If I give guerilla  in another  tate malware and then train them how to u e the malware, how i  thi  different than arming and training guerilla ?  o one of the problem  we had in the tran lation of the norm wa , when doe  a cyber operation trip over the u e of force line,  uch that it could only be ju tified by either a  ecurity Council re olution or  elf defence? We never  olved that problem. Thi  i  -- we looked in there, in fact, it'  from  ome earlier wording, it'  called the  chmitt analy i . What we  aid i , we don't know where -- until we  ee  tate practice -- we don't know where that red line i . Where i  that thre hold?

CYBER OPERATIONS

 DR DALE STEPHENS: So, in summary, we have been able to map out a reasonably robust international framework that applies when faced with cyber operations that interfere with a target state's activities. Hence a cyber operation that causes some kind of damage within the infrastructure of a victim state commits a violation of the principle of sovereignty. There may be room to include the destruction of data in this formulation. But what is not a violation of sovereignty, it would seem, is the passive tracking of communications itself. A step up from this principle of sovereignty in terms of severity, is the violation of the principle against intervention. The test turns on the issue of coercion. Further up the line was a violation of Article 2(4) of the Charter that prohibits the threat or use of force. This may be manifested when malware is supplied to rebel groups and cyber training for the manipulation of target states' cyber capacities. Finally, at the extreme end of the scale, a cyber attack could also amount to an 'armed attack' for the purposes of Article 51 of the UN Charter whenever there was a cyber attack that resulted in physical damage of sufficient gravity, such as the taking down of a power network. In terms of response, for actions that come below the 'armed attack' threshold, rights of retorsion, countermeasures, and necessity could be activated to at least permit a cyber response. The question of attribution obviously is important in these contexts and as we have heard Emma Lovett outline, this can be a slightly overstated problem in practice for which there are well rehearsed mechanisms for establishing attribution. Finally, for cyber operations that do meet the 'armed attack' threshold, then both cyber and kinetic means are available to mount a lawful action in self defence. This framework is one that applies in peacetime. Let's now turn to the next module where I'll discuss some issues relating to cyber in the context of armed conflict and the application of international humanitarian law to such activities.

Cyber101x Cyberwar, Surveillance and Security - Week 5 - Cyber Security and Cyber Warfare


TALLINN MANUAL ON CYBER OPERATIONS

 DR DALE STEPHENS: The conduct of military operations has traditionally occurred in the land, sea, and air environments. To these theatres may also be added the cyber sphere. In recent years, it is becoming clearer that cyber offers an ideal means to address asymmetric disadvantage and renders marginal the traditional geographic boundaries that countries like Australia and the US, among others, have relied on in their ocean-bounded and relatively physically remote positions. Cyber operations have been defined as, "the employment of cyber capabilities with the primary purpose of achieving objectives in or by the use of cyberspace." This definition comes from the Tallinn Manual on cyber operations. This manual, which is not a treaty or an official state-sponsored restatement of international law, nonetheless represents the views of a number of legal experts on the state of cyber operations and the applicable law that applies to the conduct or such operations. It is fast becoming an authoritative source of clarification about the application of law in this area. By way of background, in 2009, the NATO Cooperative Cyber Defence Centre of Excellence, an international military organisation based in Tallinn, Estonia, invited an independent international group of experts to produce a manual on the law governing cyber warfare. The manual drafting team was headed by Professor Michael Schmitt of the US Naval War College and was completed in 2013. It represents a statement of the law applicable up to that point relevant to the conduct of armed conflict, and also deals with issues concerning the Jus ad Bellum, the law relating to resort to the use of force in the cyber field. The increase of publicly acknowledged cyber operations relating to incidents occurring in Estonia in 2007, Georgia in 2008 during its war with Russia, the Stuxnet worm that infiltrated Iranian nuclear programs in 2010, and the Sony attacks in 2014, all demonstrate the growing capacities of cyber to impact state and private activities. They also reveal the potential vulnerabilities of states and their infrastructure, and speak to the need for clarification of rules that apply in such contexts. By way of background to the attacks in Estonia in 2007, and the initiation of work associated with the Tallinn Manual, let's turn to Professor Michael Schmitt who provides the relevant background to the material. MIKE SCHMITT: In 2008, I received a phone call from the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn, Estonia, asking me to lead a project to look at the applicability of international law to cyber affairs. The reason they wanted to look at this was because the previous year in 2007, there had been what was, without a doubt, the major watershed event in cyber history. The story's actually a very fascinating one. Let me give it to you in a very short, overly concise rendition. What happened was during World War II, Estonia was an independent state. But it was conquered first by the Germans, then by the Soviets. Eventually, the Soviet Union took over Estonia, incorporated it into the Soviet Union. And like every major city, in every Soviet city, every major city in the Soviet Union, there was a statue commemorating the great patriotic war -- socialist realism statue, the soldier looking skyward fighting for the cause. There was one in Tallinn. And it was right in the centre of the city. In fact, it was in front of the major library there. So everyone could see this statue. Well, it was the great patriotic war to the Soviets, but it wasn't the great patriotic war to the Estonians. To the Estonians, it was the occupation of their countries for a period measured in decades. So when they got their independence, when they see this statue called the bronze statue in the middle of the city, this reminds them that their country had been occupied for over half a century. So they decide to move the statue. It actually created problems. Because by this time, 23% of the population is now ethnic Russian. They all came to Estonia because the cost of living was low, the standard of living was high. It's a very beautiful country. So they had come there and it had become a problem after independence because pro-Soviet/anti-Estonian independence folks would go there and bring flowers and disrupt the orderliness. So the city decides, let's move that statue. And they moved it to a Soviet war cemetery outside the city. But when they did, this caused rioting, physical rioting in the streets with the ethnic Russian minority. And contemporaneously with the rioting, there were massive cyber attacks against the country. And really, they were devastating cyber attacks because Tallinn, and the country more broadly, had, with the assistance of the Swedes, become very wired. They were starting from scratch. So the Swedes, who have a historical tie to Estonia, came in, wired the entire country. They do everything from vote to pay their parking online. It shut the country down and drew attention to the possibility of massive countrywide cyber operations. And so NATO set up this centre. So the centre asked me to convene a group. And I convened a group of 20 scholars from around the world, some working for government, some in their private capacity. And we spent three years looking at the international law that applied to two areas, the Jus ad Bellum, which is the law governing the use of force between states or between non-state groups and states; and war, armed conflict, international humanitarian law. And so after three years, we produced this manual that governs that. DR DALE STEPHENS: Interestingly, a Tallinn Manual 2 has also been commissioned. And it will look at cyber operations that do not meet the armed attack model and the international legal framework that applies in that context, which the Tallinn Manual 1 did not address. Work is progressing on this manual and it is expected to be completed in 2016. Let's again hear from Professor Schmitt, who describes the Tallinn 2 Manual process and contrasts that with the work done in Tallinn 1. MIKE SCHMITT: That process, that part of the Tallinn process, dealt with the problem that was most severe. It's where you have a cyber attack that shuts countries down, that kills people, that affects your critical national infrastructure. But on a day-to-day basis, if you're in Canberra, Washington, Paris, or Tallinn, that's not what you're dealing with. You're dealing with the lower intensity, more frequent cases of attacks against your companies, attacks against the Naval War College network, attacks against government facilities, and so forth. Some malicious, some by terrorists, some by other states. So once we finished the Tallinn Manual, the centre wanted to keep going. And now we are involved in a process called Tallinn 2.0 that looks at the less severe but more frequent operations that occur on a day-to-day basis. So we're looking at sovereignty, jurisdiction, state responsibility, countermeasures, law of the sea, law of the air, space law, and human rights among other areas, all below the threshold operations. We will do that through 2016. And sometime in 2016, publish Tallinn 2.0, which will be an expanded version of Tallinn 1. DR DALE STEPHENS: Throughout the modules of this topic, we will discover aspects of both cyber operations that do amount to an armed attack and those that fall short of that, but nonetheless, implicate international law that guides actions and responses. We will be anticipating to some extent what will appear in the Tallinn 2.0 Manual process. But we'll do so on the basis of accepted principle and reasonable inferences that can be drawn from those principles. Finally, a word about the role of the Tallinn Manual. It represents the latest iteration of a process that is becoming frequent nowadays in respect of groups of experts coming together to articulate what the law is in relation to a particular contentious topic. We have seen this with previous manuals, such as the 1995 San Remo Manual on the Law of Naval Warfare, the 2009 Harvard Manual on International Law Applicable to Air and Missile Warfare. And now, the Tallinn Manual on International Law Applicable to Cyber Warfare. Such manuals do carry intellectual weight and do influence decision-making processes within states. They do this not because of their inherent authority. They have no formal authority. But rather as a representation of the persuasiveness and accuracy of their views. Such a phenomena may be a reflection of the vibrancy of international law, but is also an indictment on the capacity of states to undertake this heavy lifting process themselves. It does remain the case that it is still states and only states that make international law. And hence, progress of law in this field does still require active involvement and collaboration in articulating agreed positions between such central players. Understanding this, it is insightful to hear Professor Schmitt make reference to the goals and also to the nature of the Tallinn Manual drafting process. To a large extent, unlike its predeccesors, the Tallinn Manual does largely arrive at a consensus view on a number of key principles, but also is written for state legal advisors in disclosing competing views on a topic and allowing for the mature considerations by such advisors on the merits of majority and minority positions on these matters. Let's turn now to a consideration of the law applicable to intrusive cyber operations that occur in the context of peacetime and which can and do violate international law and registers of lawful response open to states subject to such activities.