Login

Forgotten your details?

« Back to previous page

US must focus on cyber attacks against its critical networks

26 October 2009

A new Rand Corporation study urges the US to focus on defending critical civilian and military computer networks from cyber attacks

Because it will be difficult to prevent cyber attacks on critical civilian and military computer networks by threatening to punish attackers, the United States must focus its efforts on defending these networks from cyber attack, according to a new RAND Corporation study.

The study finds that the United States and other nations that rely on externally accessible computer networks—such as ones used for electric power, telephone service, banking, and military command and control—as a foundation for their military and economic power are subject to cyber attack.

"Adversaries in future wars are likely to go after each other's information systems using computer hacking," said Martin C. Libicki, the report's lead author and senior management scientist at RAND, a nonprofit research organization. "The lessons from traditional warfare cannot be adapted to apply to attacks on computer networks. Cyberspace must be addressed in its own terms."

Working against connected but weakly protected computer systems, hackers can steal information, make the systems malfunction by sending them false commands and corrupt the systems with bogus information.

In most instances, the damage from cyber attacks is temporary and repeated attacks lead the victim to develop systems that are more difficult to penetrate. The RAND study finds that military cyber attacks are most effective when part of a specific combat operation—such as silencing a surface-to-air missile system protecting an important target—rather than as part of a core element in a long, drawn out military or strategic campaign.

Libicki says it is difficult to determine how destructive a cyber attack would be. Damage estimates from recent cyber attacks within the United States range from a few billion dollars to hundreds of billions of dollars a year.

The study indicates that cyber warfare is ambiguous, and that it is rarely clear what attacks can damage deliberately or collaterally, or even determine afterward what damage was done. The identity of the attacker may be little more than guesswork, which makes it hard to know when someone has stopped attacking. The cyber attacker's motivation, especially outside physical combat, may be equally unclear.
The weapons of cyber war are amorphous, which eliminates using traditional approaches to arms control. Because military networks mostly use the same hardware and software as civilian networks, they have similar vulnerabilities.

"This is not an enterprise where means and ends can be calibrated to one another," Libicki said. "As a result, it is ill-suited for strategic warfare."
Because offensive cyber warfare is more useful in bothering, but not disarming, an adversary, Libicki does not recommend the United States make strategic cyber warfare a priority investment. He says similar caution is needed for deterring cyber warfare attacks, as it is difficult to attribute a given attack to a specific adversary, and the lack of an ability to counterattack is a significant barrier.

Instead, Libicki says the United States may first want to pursue diplomatic, economic and prosecutorial efforts against cyber attackers.

The study, "Cyberdeterrence and Cyberwar," was prepared by RAND Project AIR FORCE, a federally funded research and development center for studies and analysis aimed at providing independent policy alternatives for the U.S. Air Force.

Latest News

New US Navy intel tool checks Philippines terroris… More…
09 February 2012

UK cyber security skills inadequate… More…
08 February 2012

Utilities warned again about IT vulnerability… More…
08 February 2012

Food and beverage industry top target for cyber cr… More…
07 February 2012

RSS Feed symbol | What is RSS?
View all news items…

Latest Events

13-14 February, 2012
Business Continuity and Emerge…
Location: Abu Dhabi, UAE

14-17 February, 2012
Security and Safety Technologi…
Location: Moscow, Russia

19-21 February, 2012
ASIS International 3rd Middle …
Location: Dubai, UAE

View all events…

Key Articles

The role of accurate mapping in disaster managemen… More…
07 February 2012

What's in your bin… More…
06 February 2012

Shropshire Council enhances CCTV for environmental… More…
06 February 2012

How to spot the cloud's pitfalls… More…
06 February 2012

RSS Feed symbol | What is RSS?
View all articles…


Design: Burnthebook