Showing posts with label Cyber Conflicts. Show all posts
Showing posts with label Cyber Conflicts. Show all posts

Thursday, May 19, 2016

Cyber Conflicts: Trust between Nations and Prisonner's Dilemma

Welcome back to this section on international issues in information security.

In this lecture, we will address the growing problem of mistrust between states regarding the use of cyberspace. The tensions and anxieties that exists between nations related to the nature and origin of cyber-attacks and espionage have the potential to escalate quickly into major cyber conflict and cyber warfare. The key to stopping the escalation of conflict to warfare is mutual trust.

My previous lecture identified key elements of interpersonal trust. In this lecture, we will shift our focus to trust between nations and ask the questions, how can nations trust each other and cooperate in order to prevent cyber attacks? We will examine the aspects of interpersonal trusts that are relevant to this discussion and what needs to be added to our analysis to ensure international cooperation in the cyber arena. If you remember from last lecture, we saw that humans are remarkably able to limit their self-interests, even in interactions with strangers, particularly because of the strength of reciprocity and fairness norms. We also saw that norms are particularly effective when there are repeated interactions between individuals that have long-term implications and when sanctions for non-cooperative behavior exist. We also saw the attributions of self-interest and low-expectations for reciprocity underminded trust.

These same principles are relevant when examining trust between nations.

In addition, we identified two important cognitive processes in trust relevant situations. First, feelings of vulnerability. And second, expectations of how the other party is likely to behave across time.

People will lack trust with others when they feel vulnerable and they do not feel confident in how the other individuals will behave.

These same cognitions apply, whether we are discussing trust between two people, or between nation states. In the case of two people entering a marriage or long-term relationships, partners feel vulnerable. They are committing their lives to the other person and they expect the other person to do the same. Over time, they can observe each other's behavior for signs of commitment and fidelity. They can't observe all that other person's behavior, obviously, but they can form expectations on what they do observe.

Now think of the same cognitive processes occurring between nation-states in the realm of cyberspace.

First, nations certainly feel very vulnerable when it comes to cyberspace. We live in a highly connected society, and any disruption of services can cause economic and financial damage. There is even significant psychological damage on nations from attacks, such as the 2004 hacks into Sony's studios. Think of the effect that that had on the psyche of Americans.

There are also new forms of espionage emerging constantly and increased sophistication of cyber attacks and probes. Third, nations have grave concerns about attacks on their country's infrastructure. An attack on a nation's power grid, for example, would have devastating consequences.

In addition, most nations perceive, quite accurately, that their defensive capabilities are not as strong as their offensive capabilities in cyberspace. Right now, offense has tremendous advantage over defense in cyber conflicts. Now, let's face it, the internet was built for convenience rather than security. And so, nations are always scrambling when it comes to defending their information.

Finally, the anonymity of attacks elevates feelings of vulnerability. Not knowing where attacks come from makes you suspicious of everyone.

So for these many reasons, nations feel very vulnerable to attacks from their adversaries.

Let's move to the second important cognition in trust relevant situations. Expectations for the behaviors of others.

The unique aspects of cyberspace make it difficult for nations to form clear and confident expectations about how their partners will behave.

The anonymity of the internet makes it difficult to determine who is responsible for malicious actions. An attack on a nation's institutions could be from the state actors, such as intelligence or defense agencies, or from non-state actors, criminal or a terrorist. It is difficult to tell, and thus nations often have plausible deniability, even if they were behind an attack.

It's also difficult to judge the intent of suspicious actions or attacks. For example, is an attack on a nation's financial institutions an attempt to steal money, or is it an act of espionage?

Another key point is that the barriers of entry are low when it comes to cyber-conflict. Small states and non-state actors can enter into the fray for relatively minimal costs. So the number of actors is much larger than in traditional conflicts. As is the number of possible strategic alliances.

Thus, the state of affairs in cyberspace seems slanted towards mistrust. Nations feel highly vulnerable and do not have confident expectations about the behavior of other nations, particularly their adversaries.

However, it is absolutely critical to establish trust between nations. Societies and economies depend on network communications provided by the internet. We are so interconnected that, if these networks are disrupted, the consequences would be disastrous. With low barriers to entry and ability to attack anyone from any place in the world, tracking down criminals and terrorists will take a coordinated effort between nations, which is only possible if mutual trust exists. So the problem, then, is how do we increase trust between nations when it comes to the use of cyberspace?

To start, let's return to our previous discussions of interpersonal trust. We saw that trust is likely to be higher in a relationship when each member's self-interested outcomes match those of their partner. In other words, what is best for me is also best for you.

And when both partners expect that the actions of the others

will be in terms of what is best for both people, for the relationship, rather than for personal self-interest. This is the ideal state we should strive for. Nations recognize the same end-goals, and expect that each other will act to obtain what is best for both parties, rather than what may be immediate best for one party.

Well, how is this done? Well, with individuals we saw that this is done through the process of positive reciprocity. Partners are exposed, themselves, to small amounts of risks, and observe how the other person responds. If the other person gives up something in order to reciprocate the partners initial trust, then there is mutual gain and heightened trust occurs. The importance of initial experiences and incremental steps cannot be overstated. Repeated experiences of mutually beneficial outcomes leads partners to perceive situations as positive sum, as opposed to zero sum situations.

These repeated outcomes may encourage the partner to engage in further relationship building and relationship sustaining acts.

Let's return briefly to the Prisoner's Dilemma game. What you saw is part of a exercise for the previous module.

The Prisoner's Dilemma sets up a situation where partners decide whether to cooperate or compete with each other. It establishes a positive-sum scenario. But to achieve that, outcome partners have to trust each other and overcome the tendency to see situations as competitive or zero-sum scenarios.

A zero-sum scenario is one in which one party's gains are balanced by another party's losses. It's a win-lose situation. One person wins, the other person loses. A positive-sum situation is one where all parties may gain or lose together. It potentially is a win-win situation.

The Prisoners Dilemma's payoff grid shows that both parties gain from a cooperative response.

However, if one party chooses a non-cooperative or competitive response, a defect response in this diagram, they stand the chance to gain more points and the partner comes away with nothing. That's the competitive win-lose response. So, parties may feel the urge to maximize their self-interests, at any single trial of the Prisoners Dilemma game. But if interactions occur over time, which is the case with nation-states, then an initial competitive response by one actor is going to elicit a competitive response in the other. And as a result, mutual gains are eroded. If one actor takes a risk and offers cooperation, and the partner responds by competing, the defect response here, then the chances of future cooperation are diminished. However, if an initial cooperative act is responded to in-kind, then mutually beneficial outcomes are experienced and trust builds. So the goal is to build positive-sum situations related to cyber security and conflict.

There have been several attempts to do this, primarily in the area of what are called confidence building measures.

Cyber Conflicts: International Treaties

So where do the world will go from here? So far I've talked about everything that is bleak, intransigent and undoable. But all is not that bad. Countries are working hard. They have started to recognize the importance of working on cyber-warfare treaties and other measures to basically improve the application of cyber laws. And there's a great desire within the international community to find a common ground and negotiate a cyber warfare treaty that will limit the use and development of cyber warfare capabilities. Very good, verifiable and effective.

It is not feasible, however, given the current political environment of states who continue to build cyber arsenals and continue to blame each other for attacks.

While international legislations who address cyber crime have made some progress in producing a treaty, others should negotiate treaties to stop Initiation of cyber war, constrained states can conduct a cyber war, once it has begun, our limit cyber war capabilities have not been successful.

Developing universal rules, or laws governing conduct of cyberspace, presents a very challenging problem for the world states. That is rooted in the core definition of sovereignty, defenses, and legal systems as there are differences in societal norms.

Each state has a different legal system with diverse laws, different definitions of crime, and different penalties for the same crime.

Each state's laws are based on societal values, political institutions, social norms which has been developed, as I mentioned, through centuries of history.

And instead of facing the reality of globalization, the politicians continue to maintain their hold, their control on their own countries rather than trying to address international problem. Because their local domestic politics is way more important then it is for them to deal with their international problems. However, there will be a time when we will have a catastrophic incidents or incident that will move the world community into establishing the laws. The 2001 Council of Europe Convention on Cybercrime entered into force in 2004.

However, ten years after that, it has not been signed and ratified by several key CEO member states such as Russia and Turkey. Although the conventions are open to non-Council of Europe member states, and several have ratified it, including Australia, Japan, and the United States. A total of only 42 of the 193 members states of the United Nations are acceded to this convention.

The main point of contention is jurisdictional access. The internet has no borders. However, in order for law enforcement authorities to successfully apprehend, prosecute, and punish perpetrators of transnational cyber crimes, authorities must get access to track criminal activities across the entire Internet which is unfettered by states and jurisdictional boundaries.

The justification for unfettered access to the data is the volatility of data and delays in handing over investigations to law enforcement authorities of other countries.

Opponents of unfettered data access argue that it is a violation of sovereignty. Distrust among states built with centuries of conflict and by diversity and societal norms, is hard to bridge in a short time.

Lacking provisions for unfettered access to singular members jurisdictions, the Budapest treaty is becoming obsolete and increasingly irrelevant. In 2011, Russia put forward the Yekaterinburg Treaty that focuses on cyber warfare. Although it addresses the issues of cyber warfare and brings up issue of confident building, it does not have the potential to become universally acceptable either.

Some regional efforts have seen more traction, such as those of the Shanghai Cooperative Organization, through which countries like Russia and China have built some consensus on governing principles of behavior in cyberspace. However, there's still a large gap between countries, in terms of their position.

There are two main points to note here. One, would a country like to be handicapped by agreeing to a treaty to not be able to deliver cyber weapons?

Second, a cynical view would be to go ask for us to state that the laws are for the weak countries, they don't apply to the strong.

Would the militarily stronger countries use these weapons and deny culpability while prosecuting the weaker countries base on ambiguity in attribution? So again, we really need to look at the equity here in terms of what different countries are able to do.

Initially the thought was, that the cyber spaces are big equalizer. When every country can have the same weapons, the same level of techniques, however this is again becoming a question of haves and have-nots. The countries which have resources are basically, have large armies of people working on cyber-weapons. While the countries which can't afford it are still basically scouting around for simple tools and weapons from the internet. So again, there's a huge disparity that is starting to emerge even in cyberspace, as is conventional weapons.

Cyber Conflicts: Ambiguity and Attribution

So, first there has to be a common,unambiguous definition of the terms across the nation as we start harmonizing law. We need to understand what we are talking about. For instance, there has been a debate on the distinction between cyber crime, cyber warfare and cyber terrorism. We can add one more term to this, cyber activism.

The tools and techniques are common across all of these. The difference lies in the actors and motivations behind these attacks. Cyber warfare is appropriate when state actors are involved and the motivation is to achieve political objectives.

Cyber warfare then becomes another in the off countries that can be used in conflicts, or political conflicts. For this have been used excessively giving recent tax. Mainly for physiological impact and propaganda. Set out to attempting to influence what a little change it is to invest. Cyber terrorism such as Al Qaeda attempting to influence young Muslims in the United States to join the Jihad. And some are active as a mockers when the, when social groups launch attacks in order to bring attention to social and political issues. Both within a country and across multiple countries. For instance, activists in Middle East countries campaigning on social media for political change, or hacking groups attacking organizations that supported the persecution of Julian Assange.

And so all of those are examples of social activism. Now the tools and techniques aren't the same. However, the impact can be very similar. All of these attacks can lead to billions of dollars in damages. And harmful to average citizens who are trying to use the services that are being offered.

The fundamental problem in such definitions is in the differing perceptions. First, the distinction between state and non-state actors is often blurred.

The non-state actors have tacit and financial support as well as patronage of government. Organizations in a lot of the cases. So should the governments be held responsible, or the non-state actors? The non-governmental groups have been linked to governments in Iran, Russia, and China. It is very difficult to prove this nexus conclusively, hence this ambiguity. Second, the definition of terrorism differs based on perception. A social activist for one country could be a terrorist for another country, making the distinction even fuzzier.

One could be a criminal in one country, and it could be a hero in another country. So again, we need to make sure that we understand and clearly define these rules and laws.

Now, let's look at the motive.

Are the intelligence agencies and military of states are increasingly engaging.

In espionage and some works of activities against other nation in cyber space. Distinction between cyber, cyber crime and cyber warfare is blurring. Given that it is difficult for leadership or one state to distinguish for their attacks, on the website, our online type of data are actions of individual demand of street. Motivated by financial gain, political or religious ideology or actions taken by this that stays intelligence agency of military. It is very difficult to differentiate between potential acts of cyber war, of cyber crime from cyber activism. Hence, the motive is unclear.

Now, let's look at the attribution.

That is one of the biggest challenges in enforcement of cyber warfare rules

when it applies to cyber laws.

Can we unambiguously identify the perpetrators of cyber crime to be able to apply an international law? There are three categories of attribution problems. The first deal with attacks through the internet, which are the most notorious for lack of attribution.

These attacks can be camouflaged due to the underlying architecture of the internet that allow the attackers to act remotely by exploiting lack of security in many hosts. Which allowed them to use machines in a third country for launching attacks.

Without proper cooperation across borders, or surveillance across borders, it is hard to have high confidence in attribution. The second problem deals with delivering attacks on secure systems through other media, such as thumb drives, CDs, and DVDs.

For instance, Stuxnet worm was introduced into Iranian nuclear facilities through thumb drive. For these secure systems, forensics intelligence should identify the source of the weapon.

But the forensics procedures are not developed, and they face the same problem of the weakness of the Internet. And the lack of the data that is available.

The third attribution issue is the malware in the hardware that is embedded now and the software that is preloaded onto the computers. It is very hard to find out at what stage the malware was tainted when the trojans are inserted, and when a lot of the cases were very difficult to find out even if a trojan was created.

Cyber Conflicts: Law of Neutrality and Humanitarian Law

http://plato.stanford.edu/entries/war/

The law asserts that neutral countries should not allow their resources to be used by one country to attack another country.

The fundamental problem with this is the weakness of sovereign infrastructure of countries. Computers can be infiltrated without cognizance of the neutral country to launch attack. Can we hold these countries responsible for the attacks launched by other countries, or elements that they don't control?

Especially if the country does not have technical ability or resources to secure the network to protect from such activities.

Can they be responsible, or can they be held responsible? Take the case of attack on Sony, multiple countries were attributed to the attacks by different people. But the attribution was never clear. So whom can we blame for the attack?

And so neutrality can be maintained only when there is equality. Only when there is enough technical ability among the countries to be able to manage the attacks.

And enough technical ability to be able to monitor their own networks. Given that you don't have total control of cyberspace in all the countries, this whole idea of neutrality and the law of neutrality is very difficult to apply.

Third, look at the humanitarian law.

There has been a particular emphasis on application of this international humanitarian law to cyber conflict.

This law defines a set of rules that limit the effects of armed conflict while protecting individuals who are not, or are no longer participating in the hostilities and restricts the means and methods of warfare.

While one may agree that the arguments being made, once you recognize the unique difference between the sovereign and physical domain. In several instances citizens of a country are themselves involved in launching attacks. For instance, if you look at the US-Russia conflict, the citizens of Russia were launching attacks on the computers that were installed in Estonia and Georgia in two different attacks. Now, can the citizens of a country be held responsible, especially if they were instigated by non-governmental bodies? Who is responsible? Or, if the entire population of a country were responsible for an attack. So again, this is a very difficult thing to gauge.

It is also important to note that laws are subject interpretation, based on one's own point of view.

They can be applied erroneously, misused for parochial reasons, or flouted by reasons of reciprocity on flimsy grounds. The laws need to be made such that are unambiguous and enforceable.

The attackers can use the cloak of anonymity that the Internet provides to camouflage their true identities. And therein lies the difficulty in enforcing the rules. There are several explicit factors that make enforceability very hard, and one of them is ambiguity. Which is very hard to overcome.


International Humanitarian law does not strictly prohibit countries from entering a war  but declares certain actions in a war to be legal or not.

Cyber Conflicts: Principles of Just War

In this unit we are going to discuss the laws of foreign conflict, or the laws of war. The reason we need to understand is we need to see how they translate when we start talking about cyber warfare. Or how cyber warfare relates to these laws, so that we can start to understand how we can resolve the conflicts which are happening on the internet. There are two distinct domains in which the rights and laws of armed conflict apply in the actions of going to war. In the actions in a war, the principles that govern the right to go to war are also know as jus ad bellum, and the principles that govern the action of war are also known as jus in bello. Laws regarding war conduct are laid out in international law, mostly through what is known as international humanitarian law. International humanitarian law is reference to jus in bello, or acts within a war. International humanitarian law limit the effects of armed conflict and is made up of different laws which makes up a treaty that many of countries have signed. And the most important of which are probably the Geneva Convention Center additional protocols.

International Humanitarian Law is just a set of international agreements, many of which the US is a signatory to. In the US, according to Article 6 of the Constitution, international treaties and laws are part of US laws and therefore should be followed as such. The principle of jus ad bellum, on the other hand, fall under what is known as just war theory and are not necessarily explicitly laid out in international laws. Some jus ad bellum principles present in the Charter of the United Nations. For example, Article 2 states all members shall refrain in their international relations from the threat or the use of force against the territorial integrity or political independence of any state, or in any other manner inconsistent with the purposes of the United Nations. And article 51 states, nothing in the present Charter shall impair the inherent right of individual or collective self defense if an armed attack occurs against a Member of the United Nations.

There are generally five recognized principals of jus ad bellum, we will cover them here and raise questions about how we may think about these principals in the context of cyber warfare. One reference to the notion that war should be waged by a proper and legitimate authority, following proper processes.

Now in the context of cyber warfare you may ask what is the legitimate authorities of cyber warfare? Cyber warfare is a covert warfare typically conducted by proxies of countries. Are the proxies of nation states legitimate? Would nation states ever agree that the entities committing their tax are the proxies? What if the proxies are operating outside of the country? These are some of the questions which make it challenging to apply that.

The second indicates that war must be waged with right intentions, motivated by just cause. What is a just cause in cyber space? Can a preemptive strike for national interest be justified? Again, an unanswered question. The probability of success must be determined. Efforts that cannot address the situation must be avoided.

Given the complexity of the technologies through which cyber-attack occurs, it is often difficult to make accurate assessment of the probability of success. It will be unclear if a counterattack is effective in deterring a current attack. Therefore, again, hard to apply the principle. Another principle refers to the notion that benefits of war must be proportional or worth the costs encountered, principally casualties. The concept of proportionality is based on assessment of damage, which often takes a long time to do in cyber warfare. Due to the need of immediate reaction, it is difficult to assure proportionality. Also cyber attacks at least up until now, are not usually encountered direct casualties, so I don't know how well it applies. War should, again, be waged as a last resort, only when diplomatic options have been exhausted. With ambiguity and attribution, diplomatic wrangling can often be tedious and long drawn, while need for response has urgency to repose the attack and minimize collateral damage.

So again, it's very hard to manage this. So these are a lot of unanswered questions that we have on how we can apply the international humanitarian law to cyber warfare. And as we go through this course further, we are going to discuss it and try to understand what the nuances of this are and we will debate in different cases as we study along with this. How we can start to understand this problem, how international law can start to apply with the problem of cyber warfare. Thank you.

Cyber Conflicts: Cyber Warfare - Types of the Attacks

There are several reported cases of cyber warfare over the past five years that have involved reconnaissance and espionage between countries. And the cyberspace has increasingly become important in US military strategy and tactics, as it is in Russia and China.

April2516-25off-sitewide468x60 And so, we will look at what some of these motivations are for these countries.

And there are several reports attributed to Chinese military officials, specifically discusses the need for China to devise cyber-warfare techniques to target enemy financial network, civilian electricity grids, and telecommunication networks. While installing malware on systems, ahead of launching cyber attacks, in a 2009 investigation by researchers at the University of Cambridge and the University of Toronto, a massive espionage network was discovered originating from China, that it infiltrated at least 1,200 computers in 103 countries, including many embassies, foreign ministries, and government offices, as well as the Dalai Lama's Tibetan exile centers in India, Brussels, London, and New York. In 2009, Chinese hackers reportedly launched an attack that penetrated computers of more than 30 companies, including Google and Yahoo. These attacks were camouflaged by multiple levels of encryption, allowing hackers to operate undetected for long periods of time. Attack vectors including a generic explorer remote code execution exploit were downloaded by email or instant message links. The militia then infected websites, hackers stole intellectual property, gained access to the email messages of human rights activists, and monitored their behavior.

The attacks purportedly came from Taiwan, but were traced back to Mainland China. So assigning attribution is often a very serious challenge.

For instance, let us consider the recent attack where purported attacks from North Korean hackers was done on the Sony studio. The attribution of that was never clear, but it was being attributed by different people to different organizations, including North Korea, including some hacker groups, including Russia, but it's never clear. And there's another example that the Taiwanese hacker could've attacked and purported attacks through electronic media.

But someone in Mainland China was actually responsible for that. So this misattribution is becoming a huge challenge.

In traditional warfare this is different. Where there's warfare between countries, where the enemy's identity is more or less readily discernible, not all attacks aim to disable computing and network infrastructure. And equal devastation is caused by use of social media for propaganda, manipulation of public opinion, and incitement of violence, hatred, and national, nation-state public disharmony. And so, we look at what this propaganda and social warfare can do.

The internet has amplified terrorist effectiveness many fold by enabling distribution of shared ideologies to a much wider population. For example, social networks are employed to foster member kinship, fuel member zeal and to act by propagating ideas about martyrdom and revenge. Public internet allows loosely connected terrorist groups to aggregate, forming larger networks. They're distributed, layered, and more redundant, and consequently more resistant to leadership changes and disruption, and even detection.

The ability to recruit members from population centers for terrorist acts are to be committed, rather than transporting operatives globally, give the terrorists a strategic advantage. That's another consequence of cyber warfare and the internet.

There is evidence that terrorists' reach is widening. And this can be seen from attacks across the globe, in Egypt, India, Indonesia, Pakistan, Russia, Spain, UK and the US. An important element in terrorist fight strategy is mobilizing public opinion. To sustain themselves, terrorist organization need sympathizers to willingly provide resources and logistic support, as well as to perpetrate their crimes.

Terrorist groups are able to launch effective propaganda using the internet, gaining influence over international affairs, including the flow of information, public opinion, and politics. And efforts intended to locate and share terrorist websites have been largely unsuccessful over the last ten years. The websites are able to crop up elsewhere. Counter-narratives are being used extensively to negate terrorist messages but with limited success.

Another source of threats come from sociopolitical groups operating independently or under direct patronage from national governments, which are very large threats. They have large social following and they're used for both propaganda and attacks. For instance, during Israel's great Gaza offensive in the Winter of 2009, a Moroccan based Islamic group hacked into a Israeli registration server and poisoned the routing table of popular domains to reel out users to a page featuring hacker-created anti-Israel messages, rather than launch a typical dos attack. Likewise, following the November 2008 attacks in Mumbai, hackers in India and Pakistan defaced government-sponsored web sites in Pakistan and Indian web sites respectively, throughout one another's national networks. Most such attacks can be categorized in news sensors drawing minimal attention to their respective causes. And affecting only specific government websites that are often quickly resolved.

However, deliberate attacks to disable a critical portion of national government web presence can affect communication between government and the citizens, demoralizing the citizens and destabilizing governments. These attacks reflect an even more disturbing trend with long-term ramification, especially as they links to political conflicts in nations. Within hours of the start of the Russia-Georgia war in 2008, Russian based cyber attackers disabled and defaced Georgian government web sites. The attacks were encouraged and facilitated by a Russian patriotic hacker group called Nashi and launched by seemingly ordinary citizens who could not be probably employed by the Russian government or military. While there is evidence that Russia was the source of the attack, no conclusive proof confirms Russian government involvement.

What was clear is that ordinary Russian citizens participated in the attacks. The hacker groups provided the resources and information to perform the attacks. And a large number of Russian citizens and expats launched them.

A similar attack in May 2007 was launched by Russian hackers against Estonian government websites was response to uprooting of a World War II memorial bronze statue, which was commemorating Russian military losses in the campaign to drive the Germans from the region in World War II. Numbers of attack participants can play an important role in such attacks.

Now, this raises an important question. As the disparity in internet availability is breached between developed and developing countries, countries with larger populations can expect to have a future strategic advantage. China and India, with populations of more than a billion each, will be powerful forces in citizen-led attacks. Ironically, botnets, which are blamed for many recent attacks, will be critical in shifting the strategic cyber warfare balance, as nations attempt to create botnets using resources from other countries to bridge this disparity. As a disparity in internet availability is bridged between developed and developing countries, countries with larger populations can expect to have a future strategic advantage.

The key question that we face, however, is how do we classify these attacks by ordinary citizens participating in these political conflicts? Are they criminals? Are they warriors? Are they patriots? The answer is neither obvious nor easy, but I see this implication in terms of law enforcement and international justice.

And that's something we need to ponder over. And these are the attacks that we have seen, but there's future battle that we need to worry about.

So let's look at some of these.

Cyber Conflicts: Cyber Warfare - Types of the Attacks

There are several reported cases of cyber warfare over the past five years that have involved reconnaissance and espionage between countries. And the cyberspace has increasingly become important in US military strategy and tactics, as it is in Russia and China.
Testive
And so, we will look at what some of these motivations are for these countries.

And there are several reports attributed to Chinese military officials, specifically discusses the need for China to devise cyber-warfare techniques to target enemy financial network, civilian electricity grids, and telecommunication networks. While installing malware on systems, ahead of launching cyber attacks, in a 2009 investigation by researchers at the University of Cambridge and the University of Toronto, a massive espionage network was discovered originating from China, that it infiltrated at least 1,200 computers in 103 countries, including many embassies, foreign ministries, and government offices, as well as the Dalai Lama's Tibetan exile centers in India, Brussels, London, and New York. In 2009, Chinese hackers reportedly launched an attack that penetrated computers of more than 30 companies, including Google and Yahoo. These attacks were camouflaged by multiple levels of encryption, allowing hackers to operate undetected for long periods of time. Attack vectors including a generic explorer remote code execution exploit were downloaded by email or instant message links. The militia then infected websites, hackers stole intellectual property, gained access to the email messages of human rights activists, and monitored their behavior.

The attacks purportedly came from Taiwan, but were traced back to Mainland China. So assigning attribution is often a very serious challenge.

For instance, let us consider the recent attack where purported attacks from North Korean hackers was done on the Sony studio. The attribution of that was never clear, but it was being attributed by different people to different organizations, including North Korea, including some hacker groups, including Russia, but it's never clear. And there's another example that the Taiwanese hacker could've attacked and purported attacks through electronic media.

But someone in Mainland China was actually responsible for that. So this misattribution is becoming a huge challenge.

In traditional warfare this is different. Where there's warfare between countries, where the enemy's identity is more or less readily discernible, not all attacks aim to disable computing and network infrastructure. And equal devastation is caused by use of social media for propaganda, manipulation of public opinion, and incitement of violence, hatred, and national, nation-state public disharmony. And so, we look at what this propaganda and social warfare can do.

The internet has amplified terrorist effectiveness many fold by enabling distribution of shared ideologies to a much wider population. For example, social networks are employed to foster member kinship, fuel member zeal and to act by propagating ideas about martyrdom and revenge. Public internet allows loosely connected terrorist groups to aggregate, forming larger networks. They're distributed, layered, and more redundant, and consequently more resistant to leadership changes and disruption, and even detection.

The ability to recruit members from population centers for terrorist acts are to be committed, rather than transporting operatives globally, give the terrorists a strategic advantage. That's another consequence of cyber warfare and the internet.

There is evidence that terrorists' reach is widening. And this can be seen from attacks across the globe, in Egypt, India, Indonesia, Pakistan, Russia, Spain, UK and the US. An important element in terrorist fight strategy is mobilizing public opinion. To sustain themselves, terrorist organization need sympathizers to willingly provide resources and logistic support, as well as to perpetrate their crimes.

Terrorist groups are able to launch effective propaganda using the internet, gaining influence over international affairs, including the flow of information, public opinion, and politics. And efforts intended to locate and share terrorist websites have been largely unsuccessful over the last ten years. The websites are able to crop up elsewhere. Counter-narratives are being used extensively to negate terrorist messages but with limited success.

Another source of threats come from sociopolitical groups operating independently or under direct patronage from national governments, which are very large threats. They have large social following and they're used for both propaganda and attacks. For instance, during Israel's great Gaza offensive in the Winter of 2009, a Moroccan based Islamic group hacked into a Israeli registration server and poisoned the routing table of popular domains to reel out users to a page featuring hacker-created anti-Israel messages, rather than launch a typical dos attack. Likewise, following the November 2008 attacks in Mumbai, hackers in India and Pakistan defaced government-sponsored web sites in Pakistan and Indian web sites respectively, throughout one another's national networks. Most such attacks can be categorized in news sensors drawing minimal attention to their respective causes. And affecting only specific government websites that are often quickly resolved.

However, deliberate attacks to disable a critical portion of national government web presence can affect communication between government and the citizens, demoralizing the citizens and destabilizing governments. These attacks reflect an even more disturbing trend with long-term ramification, especially as they links to political conflicts in nations. Within hours of the start of the Russia-Georgia war in 2008, Russian based cyber attackers disabled and defaced Georgian government web sites. The attacks were encouraged and facilitated by a Russian patriotic hacker group called Nashi and launched by seemingly ordinary citizens who could not be probably employed by the Russian government or military. While there is evidence that Russia was the source of the attack, no conclusive proof confirms Russian government involvement.

What was clear is that ordinary Russian citizens participated in the attacks. The hacker groups provided the resources and information to perform the attacks. And a large number of Russian citizens and expats launched them.

A similar attack in May 2007 was launched by Russian hackers against Estonian government websites was response to uprooting of a World War II memorial bronze statue, which was commemorating Russian military losses in the campaign to drive the Germans from the region in World War II. Numbers of attack participants can play an important role in such attacks.

Now, this raises an important question. As the disparity in internet availability is breached between developed and developing countries, countries with larger populations can expect to have a future strategic advantage. China and India, with populations of more than a billion each, will be powerful forces in citizen-led attacks. Ironically, botnets, which are blamed for many recent attacks, will be critical in shifting the strategic cyber warfare balance, as nations attempt to create botnets using resources from other countries to bridge this disparity. As a disparity in internet availability is bridged between developed and developing countries, countries with larger populations can expect to have a future strategic advantage.

The key question that we face, however, is how do we classify these attacks by ordinary citizens participating in these political conflicts? Are they criminals? Are they warriors? Are they patriots? The answer is neither obvious nor easy, but I see this implication in terms of law enforcement and international justice.

And that's something we need to ponder over. And these are the attacks that we have seen, but there's future battle that we need to worry about.

So let's look at some of these.

Cyber Conflicts: Cyber Warfare - Actors of Cyberwarfare

Cyberwar acts are continually morphing as a variety of actors are strengthening their skills and devise new ways to bolster their cyber arsenals that are growing both in sophistication and scale.

In order to be able to predict and envision how cyber warfare may evolve over time, we turn to examining the current actors and their motivations. So let's look at who these actors are.

The cyber warfare involves several actors including nation states, terrorists, sociopolitical groups. And they all differ in their primary intent and targets.

April2516-25off-sitewide468x60
Nation states aim to weaken the enemy nation to give the attacker wartime advantage. The terrorists generally inflict damage as a revenge, or as a show of strength leveraging it to solicit sponsors and recruits.

And sociopolitical groups create and relevance in political negotiations and policy formulation.

In some cases the distinction between terrorists and social political groups has blurred with groups defined by overlapping motivations.

Social political groups may have the tacit support of government organizations when their objectives align. In addition, secondary players work symbiotically or parasitically with major actors towards their own goals, with political or financial. Engaging in espionage or reconnaissance attacks on the internet infrastructure and the raw cyber vandalism.

The primary actors in the cyber warfare arena are states, non-state actors and international organizations. Arguably, anybody who uses the internet can become an actor in this arena.

Groups of state citizens targeting either their own government or other states, in this case, patriotic hacking, have influenced the course of domestic and international politics, which is a game changer.

In the past, states mostly watched on the sidelines as noisy hackers demonstrated their hacking skills by hacking each other's websites, often for bravado with little real impact.

Over the last few years, however, states have become the most active players in the cyber arena. Governments, military, and intelligence agencies have recognized the potential harm that cyber attacks could inflict on their countries information and communication infrastructure.

It's physical infrastructure, economy, as well as potential benefits of a cyber arsenal for counter attack and first strike capabilities.

So far, states have primarily focused on identifying vulnerabilities in enemy infrastructure, espionage, and intelligence gathering, but their stats are increasing acquiring hacker assets to be able to stay ahead of their adversaries in developing strategic cyber warfare capabilities. Several countries, including the United States, Russia, China, and Israel have gathered formidable arsenals of cyber weapons. However, they remain weak in defending against sophisticated cyber attacks. The point to note here is that, as we are collecting all of these cyber arsenals, the basic premise that the cyber ward is a stabilizer and equalizer against discrepancies. And the current expanse of countries is changing.

More money, more resources are giving more leverage to countries with more resources to have a better cyber arsenal. For the strategic advantage which some of the foreign countries have in being able to launch cheap and dirty attacks is changing. And the attacks are getting much more sophisticated. And there's a huge asymmetry in defense and offence, there are multiple targets to defend, when only a few vulnerabilities could be exploited for a successful attack. Therefore, most countries are fairly weak at defending against cyber attacks.

A major fear has been cyber attacks launched by Islamic terrorists, some of whom had demonstrated some initial hacking promise.

However, the fear of attacks by terrorists on critical infrastructure have not been realized.

And the threat of extreme harm posed by non-state actors has thus far proved unfounded.

Most of the attacks from such non-state actors are focused on propaganda and publicity to mobilize people to join their cause and join their fights.

But such cyber attacks have not directly caused much substantive damage. Sophisticated cyber attacks are no longer a matter of a viskit program, or executing a spectacular attack, but rather rigorous processes that require large investments in manpower, training, computing, equipment, and intelligence.

Most non set actors are unable to compete with the resources of large states. They, however, continue to effectively use social media and other web resources for fundraising, propaganda, and member recruitment.

The arena of cyber warfare has expanded steadily as internet connectivity and the number of individuals willing to use internet for political objectives grows. For instance, some attacks launched during the Russian conflict with Georgia, Estonia and involved Russian citizens, who prompted by nationalistic zeal work in mass to launch attacks against government and business websites in Estonia and Georgia. This has raised a spectrum of different form of war field, a cyber war that is conducted by civilians of one country against government institutions and civilians in another country but may or may not be state sanctioned or even controlled by the military of the state. Citizens are also involved actively in fomenting unrest against national governments in response to propaganda, information warfare of other countries. The Arab Spring triggered fear among many authoritative leaders of similar social, social media field revolutions. Which are in turn prompted them to constantly scour the network for activity that may catalyze into an uprising similar to the Arab Spring.
Testive
Ironically, even those days may store public outrage and basically support several attacks against adversaries. The same important citizens can strike back at the state to bring political change in their own countries. In addition to states, non-state actors and civilians, international organizations such as the United Nations, the Organization for Security and Cooperation in Europe, NATO and the Shanghai Cooperation Organization have become key players in fostering International cooperation aimed at reducing the threats to international peace, peace, and security posed by a possibility of full scale cyber warfare. The activities of each of these international organizations have, however, often reflect the narrow strategic interests of key state members. And despite strong rhetoric about cyber cooperation, and limiting the potential of conflicts, negotiations toward agreements and treaties often exhibit crucial differences among these key states and of the international organizations compose of these states.

An absence of this consensus is also influenced by insufficient credibility of international organizations to provide guarantee of compliance. With any cyber arms control or cyber peace treaties signed by member states.

Fundamental problems in actor definition lie in actors serving as proxys for others and in differing perception of actors. First, the distinction between state and non-state actors is often blurred because these non-state actors often have tacit and financial support as at the patronage of government organizations, such as Hezbollah being a proxy for Iran, the Russian Business Network being a proxy for Russian government and the Hidden Lynx hacking group being a proxy for the Chinese government. All of this are basically attributions to different organizations without concrete proof.

It is very difficult to prove the nexus conclusively, hence this ambiguity.

Second, the definition of terrorism differs based on perception. A social activist for some could be a terrorist for others. They have been making the distinction even fuzzier. For example, the cyber terrorism has been used to describe Al Qaeda's use of we to influence Young Muslim United States and Europe to join jihadis aimed at achieving Islamist objectives. Of course, some of the same protesters that have been initially categorized as cyber activists by using social media in protests against the Kadafi regime in Libya and the Assad regime in Syria, are now categorized as cyber terrorists because they also support implementation of sharia and establishment of Islamic states. And politically, in the case of Syria, use the internet to call upon Muslims in Europe and the United States to come join in the jihad against Assad's regime.

So this is a complex scenario.

Wednesday, May 18, 2016

Cyber Conflicts: Introduction to Cyberwarfare

Top Courses in Network & Security 728x90 Good afternoon. Welcome to the International Cyber Conflicts class. Today we are going to talk about an important topic, the cyber warfare. We have spent the last two decades worrying about cyber crime, how people are coming in and stealing information and stealing financial resources. However, cyber crime has morphed into something much more insidious and potent that we need to pay attention to that is cyber warfare. Instead of individuals launching attacks on the internet for financial gain, countries are launching attacks on each other, or at least planning to launch attacks on each other, or preparing their strategies to launch attacks on each other for political gains and strategic leverage over one another.

So after land, sea, air, and space, cyber is becoming the next frontier of conflict among countries.

The term cyberwar has been used to describe the nation states attacking each other via the internet. This is an important weapon in political conflicts, espionage and propaganda. It's very difficult to detect a priori and is often recognized only after significant damage has already been done.
Top Courses in IT & Software 728x90
Gaining offensive capability on the cyber battlefield figures prominently in the national strategies of many countries and is explicitly stated In the doctrines of several of them including China, Russia and the United States.

It is generally understood that they are laying the groundwork for potential cyber conflicts by hacking networks of adversaries and allies alike.

The cyber warfare incidents are increasing, not only among nation states but among terrorists, political and social organizations and cyber transnational groups nobody has control of. One early example of cyber warfare was the 1999 targeting of US government websites by suspected Chinese hackers in the aftermath of the accidental US bombing of the Chinese embassy in Belgrade. Cyber warfare, since then has advanced further. It has morphed. As of mid-2011, there have been several large nuisance attacks, but mainly nuisance attacks, such as website defacements and denial of service, or service disruptions with only occasional incidents of espionage and infrastructure probes. In rare cases, these attacks have caused large scale failures of public Internet. However they have not resulted in large scale injury, loss of life or destruction of property.
Alibris: Books, Music, & Movies
Future attacks would involve destruction of information and communication systems, the critical infrastructure and also enhance psychological operations or psycops or psyops as they are called.

Example
The cyber attacks on Estonia in 2007 and Georgia in 2008 are the part of conflict with Russia., hinted at the potential of cyber warfare.

The prospective crippling impact to the critical national infrastructure has established the role of cyber warfare in modern conflicts. Not only Is information flow disrupted, but we can also disable critical infrastructure like power, finance, and water supply.
 Become a Web Developer in 2016 with Coursera
Tools and Motivation
If you compare different modes of attacks on the internet, the tools and techniques for launching attacks in cyber warfare, are the same as in cyber war, cyber crime, or cyber terrorism or hacktivism. However, the motivation differs from more political objectives of cyber warfare to the significant financial incentives of today's cyber crime. In addition, the scale, intention, and consequences can be much more severe for cyberwarfare, because these attacks are much more planned. With many more resources, the nations are attacking each other.

One big fear is that in one of these national attacks it could result in a critical attack by the other country either deservedly or accidentally. The cyberwar landscape is complicated. There's several challenges involved. In data collection, analysis and attribution and in our understanding cyberwarfare incidents.

Top Courses in IT & Software 300x250  
Analyzing Cyber Attacks

Analyzing cyber attacks follows several discrete steps, including attack detection, relevant data collection, chronology determination, damage assessment, identification and remediation of vulnerabilities, and attribution assignment. And each of these steps poses a special challenge. There are disparate sources of data. The privacy laws that make data acquisition difficult, the lack of cross-border treaties for data sharing, use of cloaking techniques to hide identity, and volatile data that can be erased if not gathered promptly. All of that makes tackling cyberwarfare extremely hard.

Cyber Conflicts: Quiz 2 - Internet Governance

These week question were very easy and I think this doesn't require my answers. However if you think you want an answer to certain bullets do mention in the comment and I will help you accordingly.

1.

What does IP stand for?

  • Internal Packets
  • Interest Protocol
  • Internet Packets
  • Internet Protocol
2.

The packet-switching mechanism involves
  • The separation of data into packets
  • The sending of packets of data across multiple nodes
  • Each packet of data has address and sender information
  • None of the above
Top Courses in IT & Software 728x90 3.

A single IP address can refer to how many domain names?
  • Three
  • One
  • Multiple
  • Two
Top Courses in Network & Security 728x90 4.

Who manages the Domain Name Server?
  • Internet Service Provider
  • Your own organization
  • Government offices
  • All of the above
5.

What organization manages the Domain Name System?
  • IP
  • IFAN
  • Domain Name Registrar
  • ICANN
  • TCP/IP
April2516-25off-sitewide300X250

6.

What event triggered a global debate about who controls Internet policy?

  • The 2007 cyber attacks between Russia and Estonia
  • Death of John Postel and the emerging rights of ICANN to govern
  • The 2006 conferences of global leaders and ICANN
  • Edward Snowden's revelation about NSA spying in 2013
7.

What are the main competing interests groups in internet governance

  • The U.S., West Europe and the East
  • Governments, nations and private groups
  • Nation states, governments and non-profits
  • Private sector, civil society and nation states
  • The U.S., Russia and China

8.

The main source of criticism towards ICANN stems from:


  • Proliferation of an arms race to combat the cyber warfare and the proliferation of splinter groups
  • Feeling of insecurity for lack of control of Internet policy and issues regards proper rights implementation
  • Issues regarding managerial performance of ICANN and unfair legacy control by the U.S. over ICANN and the DNS
  • Its poor peformance in matters of cyber warfare and its support for policies that proliferate cyber crime


9.

The World Trade Organization implements the TRIPS aggreement, which establishes a number of common rules that members must respect in the domain of intellectual property rights. However, the Internet has allowed people to violate property rights to an enormous extent.

  • False
  • True

Scholastic Teacher Store
10.

What does "Internet Balkanization" mean?
  • The attempt of countries to create their own Internet
  • The move of Internet governance to the Balkans
  • The division of the Internet governance amoung multiple stakeholders
  • Split of the Internet protocol into several pieces

Cyber Conflicts: Current Issues in Internet Governance

And one of the issues in cyber warfare is that the Internet has been designed to support the hackers and not the protectors. And it has anonymity, and it has the power of misdirection, so the attribution of attacks becomes very challenging.



And the second issue that we have is, what are the rules that govern warfare? Do the existing international laws apply to it? For instance, we have the international humanitarian law which is used in terms of armed conflict. Now does that apply to the Internet? And if it does, what does it mean?
Testive
And if an attack is coming from China, is it really the Chinese sitting in China launching the attack or somebody else, or is somebody else misdirecting the attack? And there's the question of spillover of cyber attacks. What is a spillover of cyber attack? A spillover is that in case an attack is launched and somebody else launches a retaliatory attack without really knowing where the origin was, that can cause a problem. Let's take the instance of the North Korean attack, where the perception is that North Korea attacked or did the Sony hack. Now nobody knows for sure. We don't have credible evidence which is public yet. So that's the issue I'm talking about in attribution of the attacks. Now people can launch attacks, misdirect attacks, and the attribution is not clear. There was a report which came out recently that someone had done linguistic analysis which points to the attacks being launched by Russia. But again, there is no convincing evidence of that. So given this difficulty, it is very, very hard to really understand where the attacks are coming from, what laws apply to it, and there is no evidence in case of whether we want to retaliatory attack. And there are other issues associated with cyber attacks. The one is the issue of intellectual property.

And if you look at the intellectual property, the Internet has allowed media to be distributed across the globe. There are websites world over which basically contain information or media content, and the question is which jurisdiction do they lie on?
Scholastic Teacher Store Spring Special ends 5/31/16
The World Trade Organization TRIPS, the Trade-Related Aspects of Intellectual Property Rights, defined a common set of international rules for members to respect intellectual property rights amongst members. In the modern era, the Internet has allowed for these rights of intellectual property holders to be violated at quite literally the speed of light. Piracy of software and other intellectual works has existed on the Internet since the early days of the Usenet, a series of news groups that can considered the modern precursor to the modern web forums.
 

ICANN and other multi-stakeholder entities have resisted, in the large part, the demands of state actors to grant greater control over Internet infrastructure for the purposes of mitigating intellectual property violations.

But this has not stopped state actors from passing a variety of laws. These can vary from country to country to combat the theft and sharing of intellectual properties such as music, movies, books, and software.

And there's a patchwork of laws relating to intellectual property that have led to several things.

April2516-25off-sitewide125X125
The first is balkanization. One of the main issues in balkanization is that countries are trying to create their own Internet to protect their own national interests. For instance, a lot of countries feel that the openness of the Internet is not conducive to the societal values or to the norms in the society. If you look at what is happening in China, China has basically created a censorship regime on the Internet.

And by using technical means and laws, they're basically able to control content on their own Internet. Several other countries want to do exactly the same thing. And there are countries which want access to all of the communication that is going on the Internet to be able to fight terrorism better. So given that there is a lot of discord on how the Internet should be run, how much freedom there should be on the Internet, there's a great fear of balkanization where everybody creates their own personal Internet and the global Internet breaks up. That's from the basic challenges we face.

Especially in the light of the Edward Snowden revelation regarding mass surveillance of the Internet by the NSA, several countries, notably Brazil and Germany, they are proposing creating nationalized services as alternative to multinational products such as electronic mail. That would be routed only through their countries instead of going through the global Internet. And obviously China has had this long-standing weird firewall that is monitored by the Chinese government in order to restrict access to information on issues and historical events such as the Tiananmen Square massacre.

Top Courses in Network & Security 728x90 Many G-77 nations, the Group of 77 nations, tend to desire greater control over the Internet in their country, either as a reaction to the so-called social media revolutions like the Arab Spring, which are probably be seen as having used online social networks to organize, or due to protectionist tendencies with the state-run or public-sector telecommunications networks. There are legal and jurisdictional issues, and one of the most important emerging issues in Internet governance is the application of law to actions carried out on the Internet. Which is the governing authority? Can we bring them to international court? Given the competing patchwork of jurisdiction and legal authority, and the vast geographical distances, along with evidence which can rapidly evaporate, it is very hard to question people on the Internet. Who should prosecute the crimes on the Internet and differing national standards for speech are raised here. Consider the issue of an American citizen in the US posting comments on a British website about a public figure. US and UK law have very different levels of protection for certain types of speech, and China has even more different values. Whose law has supremacy in this situation? Consider, for example, where a criminal enterprise involving a small conspiracy of individuals in Russia uses malicious software to attack computers in the US and make them send spam email around the world. So cooperation is required between US and Russian authorities to prosecute this individual, but often the officials are corrupt and police block any sort of joint venture. And these processes have typically been very slow due to mutual distrust through years and years of Cold War. So the future of the Internet and the globalization of the ICANN and the resolve of the state actors to have more control, that has put ICANN in a difficult situation. ICANN is linked to the desires of the US government and in the wake of the Snowden revelations, ICANN issued a Montevideo statement that outlines four major points. The important global coherence in Internet operations, effort to address Internet governance challenges, globalizing ICANN and functions, and the transition to IPv6. It remains to be seen what model a truly globalized ICANN will follow. Will it be beholden to state actors in a multilateral top-down model where ICANN is ultimately accountable to the states? Or will it be a bottom-up transformation where the institution answers to Internet users and suppliers through direct accountability? So the challenges are great. We have a long road ahead of us.

Top Courses in IT & Software 728x90 The Internet has become a major economic hub. And the more important it becomes, the more concerned that countries get and the more they're striving to get control. Cyber warfare is a reality today. We have seen what happened in the Russia-Georgia conflict, the Russia-Estonia conflict. We have seen what happened with the Stuxnet and Flame viruses, when cyber physical systems were attacked. This is just the beginning, and there are more and more conflicts to come on the Internet. And Internet governance can go a long way in building trust. We just need to find the right model. Thank you.

Cyber Conflicts: Importance of Internet Governance

So why is Internet governance so important? And that the Internet governance has kept growing in importance as the stakes have risen.

And the internet is growing at a very, very rapid pace. And this rapid expansion and the growth of the internet is causing major concerns about internet governance, because countries want more control of that, they don't want somebody else to take the lead on that. All right, now let's try to see why there is so much interest in internet governance and what is at stake. So the most important thing is that people don't want other countries controlling their internet, because they fear that in the case of a conflict, somebody else can basically control their internet. And some of the recent conflicts have actually demonstrated how Internet can be used, or can be disrupted in other countries in addition to the kinetic warfare.


So several attacks happened on the Internet, which were pretty high profile, between the US, between the conflict between Russia and Estonia and then Russia and Georgia. In the Middle East, there was conflicts been the Palestinians and the Hamas folks, and the Israelis. So all of that have happened.

But in 2013, the game changed quite a bit. And that followed Edward Snowden's revelation about widespread and pervasive monitoring of internet traffic by the US National Security Agency. And this touched off a global response that continues to reshape the debate over who should control the internet policy.

And since 2003 there have been roughly three major groupings of actors with stakes in Internet governance and politics.


These groups are the national sovereignty group, a civil society group, and a private sector group.

A national sovereignty group oriented approach favored by both developing countries, and the BRIC, which is Brazil, Russia, India, and China group minus India. These actors are generally members of the group of 77, whose roots spring from the non aligned political actors in the Cold War. They are generally critical of the US global hegemony and believe that the current institutions are US government puppets. And this group would rather prefer that Internet governance be under the purview of intergovernmental agencies, such as the United Nations.
Testive
They feel that putting it under the United Nations will give more control, or at least more security to these organizations. And some are heavily authoritarian, and favor restriction on Internet usage. A lot of countries, for instance, don't want a free Internet. They want to censor Internet.

And many of them are also characterized by a strong state run telecom monopolies who would like more control than a multi stakeholder model approach. Which is the current model of Internet governance, is favored by the civil society and private sectors in general. The private sector group contains the current affairs governance institutions, and multinational Internet and telecommunication companies, such as Google and AT&T. Some governments are also on board with these private sector companies, such as the US, Japan, and most of the European countries.

The civil society group includes organizations that promote Internet freedom, privacy, and users' rights. And this can also include ideologically motivated technical groups inside the nations that might otherwise make a national sovereignty approach.

These people appeal to their nation for a more liberal outlook on Internet governance issues.

These two approaches were contrasted during the initial formation of ICANN. Contextually in the mid 1990s, there was little legitimate policy making authority regarding the coordination of the Internet. When the U.S. government began to assert itself,

by virtue of its historical genesis of the internet through ARPANET, the Department of Commerce issued a white paper suggesting a private sector organization step forward to assume responsibilities for DNS.
Scholastic Teacher Store Spring Special ends 5/31/16
And participants in the process can mean global meetings in order to debate and design an institution that would meet this criteria. But it failed to achieve consensus and was supplanted by a private deal between Jon Postel, from Network Solutions, which is the operator of the authoritative root zone server, and the dotcom dome server, and the Department of Commerce.

And the early designs of ICANN excluded governments from serving or participating in decision making, to the chagrin of non US governments, because they wanted to be a part of the United States. In the early 2000s, the US and the ICANN were directly challenged by developing nations along with the European Union and the World Summit on Internet information society.

In contrast, civil society groups embraced the multi stake holder model, seeking an opportunity to advance their policy without constraints of governmental treaties and agendas.

While ICANN and the multi stake holder model merged into one piece from this conference, the voice of state actors became even louder in the organization.
April2516-25off-sitewide300X250
And generally the conflict between the state and non-state actors in ICANN, can be distilled to issue with these two groups having difficulty participating in the forum, where both have a relatively equal footing. The standards for accountability inclusion representation are very different between a state and non-state actor.

What that conference led to was the Internet Governance Forum, which is a multi task holder meeting which happens around the world, which discusses issues related to governance, and that are non binding in fashion.

The Internet governance forum, or the IGF, which has no power to implement changes based on discussion. It is merely an anchor for various groups who have interest in the current system and the preemption against other groups, which are claiming to represent the Internet and governance over the Internet.

And due to the lack of power in the IGF, many regional or state run organizations have created forums to discuss and implement Internet policy.
Top Courses in IT & Software 728x90
Intergovernmental agencies, such as the United Nations, failed to buy in to the IGF. Due to fear that it would erode their relevance in the international system.

Now, in 2010 these alternative forums have become more popular and spying even more alternative challenge. Such as freedom online, normative cyberspace, WCID, WSIS, and the ITU. Or state and non-state actors to discuss Internet governance.

The proliferation of these events points to an insecurity of state actors who feel that they lack control over Internet policy.

And this has been worsened since the revelations which came from Edward Snowden. The current issues of Internet governance are multi fold. First of all is cyber warfare. Now what's happening is a lot of the countries have cyber warfare as a strategic leverage in terms in armed conflict. And they have doctrines in their armed forces which are declaring cyber warfare to be a major element in their warfare. Apart from the land, sea, air, and space, cyber warfare comes next for them.

And what cyber warfare is, basically, ability of a country to attack another country.

And these attacks may be leveraged against physical infrastructure, like electricity, water, power, military or civil, are main structures. A typical goal of one country is to inflict how much damage as possible into another country. And in the case of cyber warfare, that is exactly the same as the idea. We have so much dependence on the Internet
Top Courses in Network & Security 728x90
that we will be able to inflict a lot of damage by disrupting supply. We can disrupt communication in air traffic control, governmental private institutions, or other targets in the military. Their attacks may not be carried out directly by a state, but affiliated proxy groups. And typically most of the states that don't directly attack, but they have cultivated these groups which are basically individual hacker groups which are doing a lot of this work.

Cyber Conflicts: Internet Infrastructure

button
Greetings, so let us first understand what the Internet infrastructure looks like. The reason you need to understand this is because a lot of the issues of the Internet today are based on its basic architecture. Things like security, cyber crime, anonymity, censorship. Once we understand the infrastructure better, it will help you understand the basic cause and the origin of a lot of the issues that we have on the Internet and a lot of conflicts that we have.

Business Analytics from the Wharton School So what is Internet? The Internet really is a network of networks. We had a lot of networks before and all of them got connected into a gigantic network through backbones. And that is called the Internet today. So it is basically a collection of thousands of interconnected devices which allow for communication among millions of devices and people around the world.
Pimsleur All Languages Blue 125x125button The Internet is thus a collection of networks and means of communication for individual machines to send and receive data amongst each other.  And communication over the Internet happens by a process called packet-switching. Which is in contrast to something we called circuit-switching, which has been used for many, many, many years in telecommunications, such as with the telephones.

So what is the difference?
Testive
In circuit-switching the communication is happening through a dedicated connection between two points. Again, it could be any medium. It could be a wire, it could be wireless. It could be any medium at all. However, whatever bandwidth you have is dedicated.
ed2go Online Education Generic Bannerbutton
So you may have been familiar with the image of telephone operators managing switchboards and phone plugs. This was necessary because the connection was made by creating a dedicated connection between two devices of the communication.
Now let's contrast this with packet-switching. What happens in this case? You take a large message, you break it down into small pieces or packets, and you basically release them on the Internet. They basically hop from place to place of the sender and only the listed destination of the receiver. They can take any of different paths that come on their way.

The packet has the smallest unit or the amount of data that can be interpreted. The smallest sequence of zeroes and one that the Internet communication will understand.

Pearson Education (InformIT)
If you're sending an email from one computer to somebody, received at the other computer, the email is broken down into several packets. Each packet has a piece of email. The packet travels through the network separately and then re-assembled at the other end and composed back into the email. So again, at the sender's side, they're broken into pieces and reassembled on the receiver's side.

And when the packets travel they don't have to go through any dedicated path. They go through different paths wherever they have the least resistance. Whatever the protocols tell them and they take a different journey and they may it to the same destination. And once they get to the final destination, then again they're the same message that appeared initially okay. The connection and communication through the Internet uses standard protocols.

Why does it use standard protocols? Because by standardizing the protocols they're able to manage the complexity.

And what is a protocol? It's just like a language, it establishes rules for the computers to understand and rules that device makers must follow for them to be compatible with the Internet.

So, as we strive to understand what these protocols mean, we need to make sure that we know that the standard protocols for the Internet is the TCP/IP. Which is basically implemented in all the devices that are connected to the Internet.

It can be any device, a desktop computer, a laptop, it could be a smartphone. And all of them have very similar processes and similar protocols which they are able to connect to the Internet.

Now, the connection to the Internet requires a particular kind of hardware that can support communication with the Internet Protocol. The Internet Protocol is a set of protocols suite called a TCP/IP suite. Which is again a set of instructions on how data is to be sent and interpreted by communicating devices in the Internet. And one of the main components of IPs in the addressing scheme.
The Heart of the Matter course
Why do we need the addressing scheme? Because each device that is connected to the Internet has a unique address for information to travel from one place to another. It goes from one address to another address, just like a postal address.

And if you're looking at the framework of the Internet, the format of each unique address is called the IP address. The IP address is simply a number, like a phone number and it is structured in a format which is called a dotted decimal notation which is like 169.226.221.9. Now again, this is a short form for a 32-bit binary number broken down into four 8-bit segments. Now since we are running out of addresses, a new version of hybrid addresses with a high number of possible addresses has been in deployment since 2006. It's called the IPv-6.

April2516-25off-sitewide468x60
Since IP addresses are difficult to remember, an alternate naming system, called the domain name system (DNS) has been developed. This system allows each device to have a unique mnemonic address such as amazon.com or dating.com instead of a number like 72.21.214.144. The domains name system allows for organizational computers to translate the dotted decimal number into the real domain name. So, the domain name system is essentially a database that stores the phone numbers, the IP address of each computer and the domain name and allows people to translate back and forth. For instance amazon.com is 72.21.214.144, the database also stores the hierarchy or how the levels of the naming system are organized. That makes it easy to navigate and easy to search and find.