Login

Forgotten your details?

« Back to previous page

US must focus on cyber attacks against its critical networks

26 October 2009

A new Rand Corporation study urges the US to focus on defending critical civilian and military computer networks from cyber attacks

Because it will be difficult to prevent cyber attacks on critical civilian and military computer networks by threatening to punish attackers, the United States must focus its efforts on defending these networks from cyber attack, according to a new RAND Corporation study.

The study finds that the United States and other nations that rely on externally accessible computer networks—such as ones used for electric power, telephone service, banking, and military command and control—as a foundation for their military and economic power are subject to cyber attack.

"Adversaries in future wars are likely to go after each other's information systems using computer hacking," said Martin C. Libicki, the report's lead author and senior management scientist at RAND, a nonprofit research organization. "The lessons from traditional warfare cannot be adapted to apply to attacks on computer networks. Cyberspace must be addressed in its own terms."

Working against connected but weakly protected computer systems, hackers can steal information, make the systems malfunction by sending them false commands and corrupt the systems with bogus information.

In most instances, the damage from cyber attacks is temporary and repeated attacks lead the victim to develop systems that are more difficult to penetrate. The RAND study finds that military cyber attacks are most effective when part of a specific combat operation—such as silencing a surface-to-air missile system protecting an important target—rather than as part of a core element in a long, drawn out military or strategic campaign.

Libicki says it is difficult to determine how destructive a cyber attack would be. Damage estimates from recent cyber attacks within the United States range from a few billion dollars to hundreds of billions of dollars a year.

The study indicates that cyber warfare is ambiguous, and that it is rarely clear what attacks can damage deliberately or collaterally, or even determine afterward what damage was done. The identity of the attacker may be little more than guesswork, which makes it hard to know when someone has stopped attacking. The cyber attacker's motivation, especially outside physical combat, may be equally unclear.
The weapons of cyber war are amorphous, which eliminates using traditional approaches to arms control. Because military networks mostly use the same hardware and software as civilian networks, they have similar vulnerabilities.

"This is not an enterprise where means and ends can be calibrated to one another," Libicki said. "As a result, it is ill-suited for strategic warfare."
Because offensive cyber warfare is more useful in bothering, but not disarming, an adversary, Libicki does not recommend the United States make strategic cyber warfare a priority investment. He says similar caution is needed for deterring cyber warfare attacks, as it is difficult to attribute a given attack to a specific adversary, and the lack of an ability to counterattack is a significant barrier.

Instead, Libicki says the United States may first want to pursue diplomatic, economic and prosecutorial efforts against cyber attackers.

The study, "Cyberdeterrence and Cyberwar," was prepared by RAND Project AIR FORCE, a federally funded research and development center for studies and analysis aimed at providing independent policy alternatives for the U.S. Air Force.

Latest News

CloudStorm in Association with Cloud Live 2010 … More…
09 September 2010

Latest Joint Theater level Simulation version rele… More…
08 September 2010

TDM selects The Bunker to host AlarmLink… More…
07 September 2010

MPs to mount inquiry into flood legislation… More…
07 September 2010

RSS Feed symbol | What is RSS?
View all news items…

Latest Events

13-16 September, 2010
Identity Management for Govern…
Location: Washington, DC

13 - 15 September. Clare College, Cambridge, U.K., 2010
BAE Systems GXP -Regional User…
Location: Clare College, Cambridge, U.K.

14-15 September, 2010
Transport Security Expo & Conf…
Location: Olympia, London

View all events…

Key Articles

Invest in UK national security and resilience ind… More…
30 August 2010

Your Cloud won't be covered without disaster recov… More…
30 August 2010

Crisis contingency planning… More…
23 July 2010

Avoiding lock-in is a game of pick and choose… More…
23 July 2010

RSS Feed symbol | What is RSS?
View all articles…


Design: Burnthebook