Showing posts with label Cyber Security Strategy. Show all posts
Showing posts with label Cyber Security Strategy. Show all posts

Friday, June 01, 2018

Australia Declares Cyberwar

The Australian Strategic Policy Institute (ASPI) and Australian Computer Society (ACS) today released a national cyberwarfare deterrence policy paper (Painter, 2018). The policy advocates unilateral reciprocity for cyber-attacks on Australia.

The report quotes Australia’s International Cyber Engagement Strategy:
"[h]aving established a firm foundation of international law and norms, the international community must now ensure there are effective consequences for those who act contrary to this consensus."
However, the Painter doctrine is more in line with the US strategy of promising "swift and costly consequences", saying:
"... every country has the right to act to defend itself, but, if possible, acting together, with each country leveraging its capabilities as appropriate, is better. Collective action doesn’t require any particular organised group ...". 
The Australian Public Service Commission (APSC) has issued a draft learning design standard, detailing the knowledge required for government cyber security specialists. Civilian specialists working for government may well find themselves involved in offensive operations. The ANU offers a course in Cyber Offensive Security Operations as part of a Master of Cyber Security, Strategy and Risk Management. To address the ethical issues with being involved in such operations I have run students through a hypothetical on Cyberwar over the South China Sea.

Reference


Deterrence in cyberspace - Spare the costs, spoil the bad state actor: Deterrence in cyberspace requires consequences, Chris Painter, Australian Strategic Policy Institute Limited, 1 June 2018.

Friday, August 18, 2017

Australian Joint Cyber Reserve Force


Tom Worthington aboard USS Blue Ridge
Tom Worthington
on USS Blue Ridge
Cyber commandos for defence reserve" 16 August 2017). The UK Joint Cyber Reserve Force. was stood up in May 2013 and I suggested Australia do some thing similar in August 2013.

These reservists would be similar to medical specialists who can apply their civilian skills in the military. This allows the military to use personnel who they could not afford to train and retain full time. It also provides a link between those running critical national infrastructure in the civilian sector and the government organizations tasked to protect it.

As I see it, members of the Cyber Reserve Force should be issued with secure communications equipment which they keep with them during their civilian job. The members would be in constant contact about threats and ready to act on them within minutes. This contrasts with a conventional reserve, where it takes days, weeks, or months for activation.

Saturday, July 01, 2017

Australian Defence Force Information Warfare Division


Head Military Strategic Commitments Division Major General PW 'GUS' GilmoreAn Information Warfare Division (IWD), has just been formed in Australian Defence Force Headquarters (July 2017). There are four branches: Information Warfare Capability, C4 and Battle Management Capability, Capability Support Directorate and the Joint Cyber Unit. The division is headed by MAJGEN Marcus Thompson as Deputy Chief Information Warfare. MAJGEN Thompson has a PhD in Cyber Security from the University of New South Wales. He is the author of "The cyber threat to Australia" . (Australian Defence Force Journal, 2012) and other papers on cyber security.

RAAF P-3 Orion Aircraft, photo by 'Timothy' CC BY 2.0, via Wikimedia CommonsThe ABC has speculated that one target for the new unit will be the Chinese South Sea Fleet, in the South China Sea.

It happens I have been teaching Australian National University IT students using a scenario about cyber-warfare over the South China Sea. In this hypothetical, students are asked to consider the use of information warfare as an alternative to conventional military action.

 As the ABC report notes, one of the problems with a cyber-warfare unit will be attracting, retaining and paying highly skilled personnel in competition with the private sector. An option I proposed in 2013 was the use of civilian computer professionals who are military reserve officers. After brief military training these personnel would return to their day jobs, but be ready to be instantly mobilized.

Wednesday, November 23, 2016

Warning of Cyber Storm from Australian Cyber Security Minister

Greetings from the National Press Club in Canberra, where Dan Tehan MP, Minister Assisting the Prime Minister for Cyber Security is describing a 'A Cyber Storm'. He is outlining a scenario where a virus introduced to critical systems shuts down the electricity grid, causing widespread deaths and injury. He described this as a "real and present threat". The minister suggested that government, industry and the public can address this threat together. The minister went on to mention that ASD had carried out cyber attacks on ISIS.

Earlier in the year I ran the IT students at the Australian National University through a Hypothetical on Cyberwarfare over the South China Sea. Unfortunately this invented scenario is becoming more likely by the day.

There is a new Australian Cyber Security Innovation Centre being built just outside my office window at ANU. However, as the minister pointed out, this is not just something for IT professionals and federal government. State governments, business and the public have a role.

One of the press questions to the Minister asked if enough defense funding goes to Cyberwarfare. The Minister claimed that "new money" was being put into the military for cyber security and warfare. However, the amounts mentioned were tiny, compared to the amount spent on conventional military systems. One approach I have suggested is a CyberWarfare Battalion, made up of reservist military officers who are IT professionals. 

Thursday, October 13, 2016

Australian Cybersecurity for Energy

Greetings from the National Gallery of Australia where Michelle Price, Department of Prime Minister & Cabinet (currently at the ANU National Security College) is speaking on "Cyber security in relation to Australia’s energy security". This is part of an Energy Security Forum.

Dr. Price suggested talking about "critical services", rather than critical infrastructure. This is to focus on what people need, rather than poles and wires. For the first week of a disaster she suggested the Internet and electricity are all that are needed. I found this surprising, as I had assumed the HF radio systems Australian governments maintain would be sufficient for essential services. In 2015 the Australian Defence Force tested transmitting digital video via an Internet Protocol (IP) data link over Wideband High Frequency (WBHF) radio between Canberra, Townsville, Wagga, and an aircraft on the ground in South Australia.

Monday, August 15, 2016

Australian Government Needs a Planned Response to Cyber Attack

The security of government information systems is the responsibility of government ministers, not IBM or the ABS. What should be of concern is not just that there was a successful denial of service attack on the Australian Census, but the apparent lack of a planned and practiced response from the relevant government ministers and their staff. Had this been a more serious attack, such as one on critical infrastructure threating lives, the poor performance by ministerial level of government could have been disastrous.

At the senior levels of government there need to be plans in place for who says what and when. These plans need to be tested in exercises, just as is done for natural disaster planning, which Australian state and local governments do well. Internet Australia (IA) members are discussing what form of submission to make to the likely Parliamentary inquiries into this matter. I suggest the Australian Computer Society (ACS) join with IA on this and try to widen the discussion to cover Internet security more generally. ACS and IA need not agree on every aspect, buy could loosely coordinate, as was done for the Internet regulation inquiries of the 1990s, as  described by Chen (2000, p. 161).

Reference

Chen, P. J. (2000). Australia's online censorship regime: the Advocacy Coalition Framework and governance compared. Retrieved from
https://minerva-access.unimelb.edu.au/bitstream/handle/11343/38780/65881_00000240_01_AOCR.pdf?sequence=1#page=162

Monday, July 11, 2016

Cyber Threats and Nuclear Weapons

Dr Andrew Futter, University of Leicester,is  speaking on "Cyber Threats and Nuclear Weapons: New Questions for Command and Control, Security and Strategy" at the Australian National University in Canberra. Dr Futter argues that the Internet amplifies the risks with nuclear weapons. The scenario in the film "War Games" is more possible. He commented that the 2012 Glogal Zero US Nuclear Policy Commission Report raised more questions than it answered.
Dr Futter pointed out that nuclear weapons are inherently vulnerable, as they must be ready for use at any time, while also being under central control. One example was a training tape loaded into a US system which made the operators believe there was a real alert. Dr Futter commented that with a more on-line system it will be harder to detect such errors.

Dr Futter suggested that non-state actors were more likely to mount a cyber-attack to cause an un-commanded launch of a nuclear attack, a state actor was more likely to try to disable an opponents weapons. It seems to me that the risk with a state sponsored attack would be so high that this is unlikely to be attempted, expect by a "rogue" state. A more likely scenario is an attack on conventional command and control systems would disable nuclear weapons as a side-effect.

Dr Futter also included hacking of an Israel Defense Force Twitter account to spread false information about a nuclear accident. He also pointed out that an attack does not need to be on the weapons system: disabling the sewage system on a submarine will disable it as a weapon.

Dr Futter then discussed the different nature of cyber and nuclear weapons and the feasibility of responding to a cyber attack with a nuclear weapon. It occurs to me that cyber weapons are more like biological and chemical weapons: they are unpredictable in their effectiveness, may harm the attacker more than the attacked. On the one hand a cyber attack is deniable, on the other its source may be detected but then have little effect, resulting in a large political damage for no military value.

Dr Futter commented that he hoped Nuclear Weapons Officers did not freely discuss their jobs on-line. This got a laugh from the audience, but a search of Facebook for "Nuclear Weapons Officer" resulted in several hits and more than one hundred listed on LinkedIn.

Dr Futter recommended Ghost fleet : a novel of the next world war by P.W. Singer and August Cole, as a fictional but perhaps prescient view of the future, where the only military equipment working is pre-Internet-of-Things. Also one of the audience members, Adam Henschke, mentioned his book (edited with Fritz Allhoff) "Binary bullets : the ethics of cyberwarfare" (I ran the ANU IT students through a hypothetical on the ethics of cyberwarfare over the South China Sea last semester).

Tuesday, July 05, 2016

Cyber Threats to Nuclear Weapons

Dr Andrew Futter, University of Leicester, will speak on "Cyber Threats and Nuclear Weapons: New Questions for Command and Control, Security and Strategy" at the Australian National University in Canberra, 3pm 11 July 2016. 
"The development and spread of cyber ‘weapons’, information-warfare capabilities and the new dynamics of the ‘cyber age’ are providing a considerable – albeit nuanced – challenge to the management, thinking and strategy that underpins nuclear weapons. Although, in the near future at least, cyber-attacks will not supersede nuclear weapons as the ultimate guarantor of national security, the tools and capabilities associated with cyber present new problems that affect the nuclear weapons enterprise in numerous ways."
See also:

Thursday, April 21, 2016

Australia’s Cyber Security Strategy

Prime Minister, Malcolm Turnbull, today released a 67 page document entitled "Australia’s Cyber Security Strategy: Enabling innovation, growth & prosperity". The government will create a new position of Special Adviser on Cyber Security. The report says that cyber security governance will be streamlined and "clearly identify lead responsibilities", but unfortunately does not state these, clearly or otherwise. Also the Australian Cyber Security Centre will be moved from the ASIO building to a location most likely elsewhere in Canberra. There is also mention of research being commissioned on cyber security, but no funding.

The document provides a good overview of the problem of cyber-security and shows the authors had an understanding of the issues, but does not provide any actionable solutions. The report ends with what is titled an "Action Plan", but this does not have any firm deadlines nor resource allocation, so it is not really an action plan.

ps: As an example of one challenge see "Cyberwar over the South China Sea".

Friday, February 19, 2016

Australia to Lead Next step in Securing Cyberspace

Fred CateGreetings from the last public session of  "Securing our Future in Cyberspace" at the Australian National University. Professor Fred Cate from Indiana University has proposed Australia should act as a bridge between western nations security academics and officials and those in China. 

Thursday, February 18, 2016

Role of Cybersecurity in Chinese Foreign Policy

Greetings from the Australian National University in Canberra, where Professor Jon Lindsay from University of Toronto is speaking on "The role of cybersecurity in Chinese foreign policy". Professor Lindsay, has written several papers and is editor of the book "China and Cybersecurity: Espionage, Strategy, and Politics in the Digital Domain" (2015). He pointed out that the US Government makes a distinction between industrial and security espionage, which China does not necessarily follow. Somewhat more controversially he suggested the term "Advanced Persistent Treat" could be applied to USA's NSA, as well as its Chinese equivalent.

Professor Lindsay contrasted NSA's covert attempts to obtain information on-line with overt moves by China to ensure the Internet is not used internally for anti-state political activities. He pointed out that Chinese law imposes severe limits on what the Internet can be used for.

Professor Lindsay characterized Internet regulation as fragmented. The central state regulation body is under the propaganda ministry, concerned with the content. He commented that as a result cyber-crime, provided it is for economic gain, is less of a priority for government.

Professor Lindsay quipped that there are two sorts of organizations in the USA: those who have been hacked by China and those who do not realize they have. Admitting attributing attacks is difficult, he pointed out that phishing attacks align with the Shanghai working day (where PLA Unit 61398 is based), suggesting this is an industrial scale activity.

Professor Lindsay pointed out that a sophisticated system was needed to handle large amounts of information obtained through industrial espionage. He said that information on how this is done in China is obviously not freely available. However, information on collecting and processing overseas open access information. He made the point that China has been greatly increasing expenditure on the absorption of information, rather than just collection.

Professor Lindsay pointed to a PLA documentary on cyberwar "The Cyber storm has arrived" (2011), which features a fictitious attack on a Falun Gong group in the USA. The point being that a religious group is seen as a threat to the state. His implication was that this is different to western military doctrine. However, this reminds me that one of the US presidential candidates has proposed banning immigrants based on religion, on the assumption they are a threat to the state.

Professor Lindsay pointed out cyberwar increases the "fog of war". Even well resourced nation states will have difficulty conducting such a war. He suggested China had less experience at this than the USA. However, China has very expert IT professionals (I train some of them at ANU in Canberra). It has to be assumed the Chinese military train their IT professionals well. Also China has a military doctrine which is more accommodating of cyber-warfare.



This seminar is part of this week's conference "Securing our Future in Cyberspace", which ends Friday with "Securing our future in cyberspace - next steps".

Friday, December 26, 2014

Australian Information Security Certification

In "Could the Government's cybercrime focus be a catalyst for change?" Tony Campbell (IT News, ) suggests the Australian Computer Society could "act as the certification authority for information security exams". This would follow the practice of the British Computer Society (BCS) for the UK.

The UK Cyber Security Strategy: Protecting and promoting the UK in a digital world, was released 25 November 2011. A GCHQ Joint Cyber Unit has the central role. Also the UK expanded its Centre for Protection of the National Infrastructure.

As Campbell points out, a review of Australia’s cyber security strategy was announced in November. The ACS assisted with public consultationson cyber-security around  Australia in October 2011. As a member of the ACS Cyber Task Force I assisted in preparing the ACS Submission for the Australian Cyber Policy White Paper and "Response to The Department of the Prime Minister and Cabinet's Discussion Paper". PM&C was planning to issue a "CyberWhitePaper" in early 2012, but this did not occur.

The ACS Virtual College already includes Information Security as an elective. It could be expanded to cover the  Australian National Plan to Combat Cybercrime, and working with the Australian Cybercrime Online Reporting Network (ACORN).

Thursday, September 25, 2014

Cyber Security Training for All New Australian Defence Force Students

Greetings from the the University of NSW Canberra, where I am attending the ICT for Development Symposium. In his welcome, the UNSWC Deputy Rector, Professor John Arnold, pointed out that all undergraduates would be trained in cyber security, commencing 2015. This is very significant for national security as UNSW Canberra is the location of the Australian Defence Force Academy (ADFA) and trains Army, Navy and Air Force personnel. Northrop Grumman installed a "Cyber Range", which could be used as part of the training. However, while it will be very useful for all ADF personnel to have some knowledge of the topic Australia also needs a specialist CyberWarfare Battalion.

Monday, July 14, 2014

Australian Army Considering Use of Cyber Weapons Against Terrorists

Operations Centre, CanberraThe "Future Land Warfare Report 2014" from the Australian Army's Directorate of Future Land Warfare Headquarters discusses the issue of boosting the Army's cyber capability. The most interesting point is "Military cyber operations can be as effective as precision-guided munitions against either a nation-state or a non-state actor", that is cyber-weapons can be used against terrorists. It is not quite the "Australian CyberWarfare Battalion" I proposed, but it is a step in the right direction:
Less sophisticated but highly lethal threats of the
future may seek to undermine the kinetic dominance of Western forces. To what degree is the Army prepared to rebalance its force structure into non-traditional capabilities and units (such as boosting the capability of the intelligence battalion or adding an Army cyber capability) in order to build greater capacity for intelligence-led targeting? Can the Army manage risk and reduce some traditional capabilities while relying on its ability to rapidly regrow these as required? ...
The land, sea and air domains will become further entwined with the cyber, electromagnetic and space domains. These domains will be the subject of constant competition, with land force operations increasingly enabled (or disabled) by access to digital networks. ... 
Global telecommunications networks coupled with omnipresent communications technology will continue to empower non-state and semi-state actors. The effect will be disproportionate to their size and stature and allow the formation of supra-national organisations within the cyber domain. ... 
Current cyber defence capabilities have not kept pace with technological change and the Army must develop an ability to defend critical networks against cyber attack, while also being prepared to operate in a degraded network environment. ...
Given the increasingly important role of cyber capability in conflict, land forces must constantly evaluate their professional military training to ensure that soldiers understand how to use digital systems and other emerging technologies. Military cyber operations can be as effective as precision-guided munitions against either a nation-state or a non-state actor. Legal and ethical employment of cyber capabilities requires an appreciation that friendly, adversary and civilian forces may rely on thttp://www.army.gov.au/~/media/Files/Our%20future/Publications/FLWR_Web_B5_Final.pdfhe same digital infrastructure. Understanding the second and third order consequences of preventing access to digital domains, particularly for civilians, is critical. 
28.     The trend towards inter-agency and joint operations will make the land force more integrated at lower levels. Thus the force will become increasingly enmeshed with external enabling capabilities and require much greater use of civilian infrastructure in the conduct of operations. If access to digital systems offers Australian forces a ‘competitive advantage’, interdependence will see the land force become increasingly vulnerable to disabling attacks on partner capabilities (in addition to direct attacks on military systems). 
29.     In addition to protecting its access to digital domains, the land force will also need to identify back-ups to digital technologies. To achieve this, land forces must retain skills and equipment that will provide redundancy when digital networks fail. Troops will require the ability to fight effectively without access to digital networks for limited periods of time. The Army will need to imbue its soldiers with the mindset to ‘fight for communications’. ... 
The land force may be required to develop more dispersed headquarters and decentralised logistics infrastructure in its future operating concepts to reduce exposure to long-range kinetic and cyber attacks.   ... 
The capacity of a variety of threats to collect, share and analyse data will improve the precision of attacks on our forces. These attacks will be cross-domain in nature, exploiting cyber means and traditional kinetic effects. ...
From:  "Future Land Warfare Report 2014", Directorate of Future Land Warfare Headquarters, Modernisation and Strategic Planning Division, Australian Army, April 2014

Wednesday, March 05, 2014

Future of Cyber Warfare

Greetings from the 2014 Digital Government Conference in Canberra, where Dr Suresh Hungenahally, Chief Information Security Officer, Department of Business and Innovation (Vic), is speaking on "The Future of Cyber Warfare". He showed a video from the Australian Signals Directorate (ASD) depicting a government official who has lost their laptop, so logs in from a cybercafe and has their password stolen as a result.

Dr Hungenahally pointed out that "hackers" are now not just teenager having fun, they are criminals out to steal corporate secrets. He related the Queensland case of a SCADA system being penetrated  the Maroochy Shire Council's sewage control system.
Dr Hungenahally then claimed that the Australian Air Traffic control system depended on US based computer systems, which seems unlikely.

ps: The Australian National University is launching its "Strategy and Statecraft in Cyberspace" research, later today.

Monday, February 17, 2014

European Internet Will Not Stop Eavesdropping

I was interviewed on ABC News Radio Monday morning, about reports of the German Chancellor's proposal for a European Internet to stop US eavesdropping

I said a European Internet would be more expensive and ineffective. Those who traditionally spy on the Germans are the French. ;-)

More seriously, I pointed out that Europe tended to have higher data charges, so US services are used by Europeans. I suggested that individuals could help by encrypting their own data (which will slow down, but not stop eavesdropping) and check where the organisations they do business with store their data.
Some relevant documents:
  1. Australian Government Cloud Computing Policy: Maximising the Value of Cloud, version 2.1, AGIMO, July 2013
  2. Outsourcing and offshoring - Specific considerations when using cloud computing services", Australian Prudential Regulation Authority (APRA), 15 November 2010
  3. Advice on managing the recordkeeping risks associated with cloud computing, Cassie Findlay, Australasian Digital Recordkeeping Initiative, Council of Australasian Archives and Records Authorities, 29 July 2010
 

Saturday, November 23, 2013

Cyber War Will Take Place

Thomas Rid's book "Cyber War Will Not Take Place" (Oxford University Press, 2013), is readable and well researched. It argues that on-line attacks on nation states will be at most an adjunct to the use of conventional military force. The limits to the effectiveness of an on-line attack are discussed, using documented cases. The conclusion is that cyber-war will not happen, because it is unreliable in its effect, cannot be well targeted and can't cause violence directly. Surprisingly, Queensland, Australia, features prominently as one place where a cyber-attack on infrastructure had a significant effect. In 2000 the Maroochy Shire SCADA system was commanded to dump millions of liters of raw sewage into waterways.

Rid soberly counters the hype around "cyber-war", but perhaps goes too far in dismissing it altogether. There are many weapons which have uncertain military value, but are nonetheless made ready for use. An example is Barnes Wallis' bouncing bomb, used to breech the Möhne and Edersee Dams in WW2. The bomb had a mostly indirect effect, by breeching the dam wall, cutting off hydroelectric power and flooding the land below. The bombs has some propaganda value, but were of limited military value.

It is unlikely there will be a pure cyberwar, but very likely that any future major conventional war will involve extensive use of on-line attacks. These will be intended to cause confusion and degrade the enemy infrastructure to make conventional kinetic attack more effective, rather than replace it.

Compared to conventional warfare, cyber-war takes little hardware. Office computers are cheap compared to missiles, submarines and supersonic aircraft. A country with a conscription army also has a ready supply of recruits, who can be screened for computing skills. Reserve personnel, who work in the ICT, can be used, with most of their technical training taken care of by their civilian employers (previously I proposed such a "Australian CyberWarfare Battalion").

Nations with less developed infrastructure may also see this as a useful form of asymmetric warfare. A less developed nation has little to fear in terms of retaliation when  disrupting the water, transport and power infrastructure of a developed nation.

Thursday, November 21, 2013

Security challenges in the Indian Ocean littoral and the US pivot to Asia

Greetings from the Australasian Council of Security Professionals and combined Associations’ Seminar at the Australian National University in Canberra, where  Peter Leahy, former Chief of the Australian Army and Director of the National Security Institute, is speaking on "Security challenges in the Indian Ocean littoral and the US pivot to Asia".

Professor Leahy pointed out that the Indian Ocean was surrounded by many unstable states and 50% of the world's shipping cargo crosses the region, with a number of vulnerable choke-points. The Australian warships were sunk in the Indian Ocean in WW2. HMAS Stirling is the main naval base for the west.

Professor Leahy referred to "Gateway to the Indo-Pacific: Australian Defense Strategy and the Future of the Australia-U.S. Alliance" (Jim Thomas, Zack Cooper, and Iskander Rehman, November 2013, Center for Strategic and Budgetary Assessments). He pointed out that despite the title, this publication, like much US strategic thinking is fixated on China. I did a quick check and found "India" occurs 10 times in the document, "China" 13 times. What worried me more was that "Cyber" occurs only twice and "Internet" and "World Wide Web" not at all. The RAAF's E-7A Wedgetail AEW&C aircraft are mentioned as providing early warning of approaching aircraft. An expansion of the JORN Over the Horizon Radar is suggested. While the P-8 Poseidon maritime patrol aircraft is mentioned once, but not the pod-mounted, active electronically scanned array (AESA) radar option.

Cyber Security Cooperative Research Centre

Greetings from the the Australasian Council of Security Professionals and combined Associations’ Seminar at the Australian National University in Canberra, where someone from Edith Cowan University (ECU) is talking about a bid for a Cyber Security Cooperative Research Centre (CRC). So far the bid has CSIRO, QUT, Deakin University, University of South Australia, University of Adelaide, Hannover University and Groningen University. There is a 2013 CyberCRC Prospectus available. ECU is also running a  Control Systems: Cyber Security Training Course on 9 December 2013.

Protective Security Policy Framework

Greetings from the the Australasian Council of Security Professionals and combined Associations’ Seminar at the Australian National University in Canberra, where someone from Attorney General's Department is talking about the "Protective Security Policy Framework". They made the point that rather than a rigid set of rules on what to do, the framework is designed help agencies identify their needs. Australian personnel vetting practices include a physiological profile of each individual, which can help identify future problems.

Staff of the Australian Cyber Security Center will move into the new ASIO building in Canberra, when it is ready.