The Macrosite for News, Analysis and Opinion about the Future of the Internet
Kenneth Geers

Arms Control in Cyberspace: A Proposal

Written by Kenneth Geers
12/13/2010 18 comments
no ratings
1 saves
DISCUSS     Email This

World leaders fear that cyber-terrorism and cyber-warfare may pose a real threat to national security. In the future, unknown hackers might target everything from electricity to elections.

Therefore, national security planners may look beyond reactive cyber-defense tactics to proactive, cyber-defense strategies.

Cyber-arms control is one possibility. The Russian government has suggested that the 1997 Chemical Weapons Convention (CWC) could serve as a model.

On the surface, the arms control analogy appears difficult to make. Chemical warfare is designed to kill humans, cyber-warfare is designed to kill machines (or their functionality). But let's see where the comparison could be helpful -- and where cyber-weapons may be unique.

Chemical weapons employ the toxic properties of chemicals to kill or injure human beings and animals. Archeologists have found poison-covered arrowheads dating to 10,000 BC. In WWI, chemical weapons may have caused one-third of the estimated 5 million casualties.

First, the most important reason for the success of CWC was political will. In 1997, Bill Clinton and Boris Yeltsin declared that we should "banish poison gas from the Earth." Political leaders today are beginning to describe the cyber-attack threat in similar terms: Chinese Minister Lou Qinjian has complained of "massive and shocking" damage caused by hacking, and President Obama announced that unknown hackers had "plunged entire cities into darkness."

Second, there is a universal nature to the threat posed by both chemical and cyber-weapons. For CWC, signatories feared not only nation-state use; they also worried that chemical weapons may be used by terrorists. CWC's goal is thus worldwide participation and the elimination of an entire class of weapons of mass destruction (WMD). Currently, CWC has 188 signatories, encompassing 98 percent of governments and 95 percent of the Earth's population. The ubiquity of cyberspace and the fact that hackers are able to anonymize their attacks may put a fear of cyber-weapons into the same universal category.

Third, CWC helps its members to fulfill treaty requirements and provides advocacy in the event that a member is threatened by chemical weapons. The persistence of cyber-vulnerabilities and the challenge of implementing best practices in computer security suggest that a Cyber Weapons Convention could create an international institution to provide technical, legal, and policy guidance to its members. One significant but politically and technically difficult step might be the joint observation of Internet traffic flows.

At this point, however, the helpful analogy between chemical and cyber-weapons breaks down. Arms control in CWC relies on the principles of prohibition and inspection. Both are currently very hard to imagine implementing in cyberspace.

Since 1997, CWC has overseen the destruction of over 60 percent of the world's declared chemical agent stockpiles and almost 50 percent of chemical munitions. However, it is difficult to prohibit something that is hard to define, and cyber-weapons present just such a challenge. In the single month of May 2009, Kaspersky Lab counted 42,520 "unique malicious, advertising, and potentially unwanted" programs on its clients' computers.

Another key to the success of CWC is its inspection regime. Since 1997, there have been over 4,000 CWC inspections in 81 countries, and almost 5,000 industrial facilities are subject to inspection at any time. This is a large but manageable number. Compare it to one 256-Gbyte USB Flash drive, which holds over 2 trillion bits of data. Or the number of Internet-connected computers in the US, 400 million.

Some regular inspections probably already take place at the ISP level -- perhaps as part of China's Golden Shield Project, the European Convention on Cybercrime, Russia's SORM, and the USA PATRIOT Act -- but all such initiatives will face the same problem of overwhelming traffic volume.

In spite of these challenges, cyber-arms control may be a part of our future. CWC is an imperfect analogy, but it still offers national security planners with a few helpful ideas and some inspiration. In the future, if enough political will is generated to sign an international cyber-arms control treaty -- perhaps in the wake of a surprisingly powerful cyber-attack -- political leaders may give scientists the funding they need to attack the technical challenges of prohibition and inspection.

— Kenneth Geers, US Representative to the Cyber Center of Excellence in Tallinn, Estonia

Channel: Security, Terrorism
Tags: Government
DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 2   Next >
Paul Whyte
Researcher
Tuesday January 18, 2011 8:51:17 AM
no ratings
"The risk of cyber attacks is massively overstated, because very few attacks can cause global meltdown, an OECD report claims.
 
Headline-grabbing events including malware, distributed denial of service attacks, criminal activities and espionage can, at best, cause only local disruption, and it would take a concentrated attack on the technology protocols underpinning the Internet to cause a catastrophic meltdown in global communications, the report states."


Cyber attack risk overhyped


So please Congress no rush to give the president unlimited powers to shut down the internet.

 
Mike Acker
Rank: Cyborg
Thursday December 23, 2010 9:47:11 AM
no ratings

the lack of computer security -- or security generally for that matter is most likely mainly a behavior problem and not a technical one.

There was this from Dark Reading:

The stream of database exposures remained steady in the second half of 2010: We saw organizations face the consequences of inept database account provisioning, bad encryption policies, poor choice of third-party vendors, and an overall indifference to security -- all of which continued to keep consumers on the watch for blips in their credit reports.
According to the recent Computing Technology Industry Association's (CompTIA's) 8th Annual Global Security Trends Study, only about half of IT professionals view security as a major priority. It's no surprise, then, that the survey found 63 percent of their companies have experienced some kind of breach this year.

Consider the Bradley Manning/Wikileaks thing: it seems he wrote all those memos to a RW DVD and just walked out of the message center with all of it.

NOT JUST END USERS

The behavior issue isn't limited to end users but is pervasive through the process that builds and distributes software with little or no attention to the security question.  And this starts with the guy who assembles the compiler.

pjpugliese
IQ Crew
Friday December 17, 2010 11:09:47 PM
no ratings

Very valid point Michael. New code, virus and programs are written constantly. There would be no way to identify & include them all. 

DHagar
Thinkernetter
Tuesday December 14, 2010 12:55:32 PM
no ratings

David, what I was relating to was the overall structure of multilateral inspection that would set a broad standard that a multinational collaboration would be involved with, like his examples in chemical warfare, nuclear, etc.

Obviously, that in and of itself will not be a full detection.  That would that require our own national security process that would seek protection, or minimally detection of leaks. 

I do not know if it is technically possible to stop leaks, I was thinking that a better and more comprehensive monitoring and detection may be the best security at this stage.

DHagar

davidmanheim
IQ Crew
Tuesday December 14, 2010 12:46:10 PM
no ratings

DHagar,

I'm not sure quite what you mean. Ken did mention inspection, but mentioned the challenges of inspecting data. I'd amplify; there is not way to inspect packets that contain arbitrary malicious code, only scan for specific know attacks. This is effective ask long as there is no encryption of the data which is basically trivial and will be come universal for attackers if such a regime is implemented. (It's already not uncommon for botnets to encrypt most of their traffic.)

So what are we planning to inspect? My vote would be checking machines for required patches. If a machine facing the internet is found unpatched more than some fixed amount of time after the patch is released, there would be a flag. The rule could be, for instance, that if networks with more than some minimum number of flags would have different treatment; possibly restrict nonroutine traffic, or increase penalties for compromised machines within such networks. (if a network that has always stayed patched get compromised, the penalties should be significantly less.

Does anyone have any other ideas about what could be inspected?

jnieusma
Rank: Cave Painter
Tuesday December 14, 2010 12:09:03 PM
no ratings

Enforcing any sort of treaty will be largely determined by everyone’s definition of the key terms. International law enforcement is current slogging its way through legal channels to bring these definitions into agreement. This is why piracy and slavery are still rampant in some parts of the world.

No political entity is willing to share their slice of the pie in order to prevent crime somewhere else. It’s not so much a “not in my backyard” mentality as it is an “it’s my yard, it’s my rules.” We will continue to operate in a reactive fashion, chopping off the hands that reach into our jurisdictions until all parties involved agree on what constitutes a crime and how it should be stopped.

 

SteveGNYC
IQ Crew
Tuesday December 14, 2010 11:20:34 AM
no ratings

Kenneth - really nice post. Do you think that leaking data or holding data hostage is also a strong threat? I think so.

David - I agree with you and with DHagar. Extradition is a reactive solution, and hardly a proactive one. 

DHagar
Thinkernetter
Monday December 13, 2010 9:40:09 PM
no ratings

I agree, David, that the accountability and use of the existing tools would advance the controls of the cyberwarfare.

Kenneth has some interesting new thoughts as well on increased "inspection", along the lines of chemical warfare and nuclear inspections.  Maybe that would hold some promise.

DHagar

davidmanheim
IQ Crew
Monday December 13, 2010 9:02:21 PM
no ratings

Extradition isn't necessary to stop attacks; it's a poor security system where  the only thing preventing robberies is that the police might catch you afterwards. We need proactive approaches for cutting off attacks as they happen, as well as regimes to stop those who have acted badly, to reform or restrict them.

The best way to provide enforcement in these cases is to use the system they are abusing; if an ISP refuses to block an attack, the ISP would need to be blocked completely, in order to prevent the attack from occurring. That's all the impetus they should need.

Kenneth Geers
Thinkernetter
Monday December 13, 2010 7:09:21 PM
no ratings

Sean,

Great point. The extradition of criminals is hard because it offends national pride, not just the principle of sovereignty over people and borders. "Like, I am sure that my kid did not hit your kid."

In the 2007 cyber attacks against Estonia, most of the original attacking computers were located in the U.S. As the traffic was blocked, the bots moved to Egypt, Vietnam and elsewhere.

The cyber treaty negotiators would have to come up with something, but it could be different in every case. With extradition, I think the treaties are mostly bilateral, which provides some flexibility.

For a universal treaty, part of the new power might be the ability to publicly name and shame those who flout the treaty. Just peer pressure, but better than nothing.

Best, Kenneth

 

Page 1 of 2   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Kenneth Geers
Kenneth Geers
Kenneth Geers   3/4/2013   31 comments
Cyberattacks are back in the news, but there is still legitimate skepticism regarding their true threat to national security.
Kenneth Geers
Kenneth Geers   8/15/2012   18 comments
National security thinkers are still debating whether a"“Digital Pearl Harbor" is possible. But in the ongoing revolution in Syria, the cyber battleground is already strewn with interesting proofs-of-concept.
Kenneth Geers
Kenneth Geers   5/9/2012   11 comments
My blog, The Art of Cyberwar, posted on Internet Evolution this past January, described 10 revolutionary aspects of conflict in cyberspace. Based on the feedback I received, I've decided to revisit each of the 10 aspects with a new view based on what I've learned from many comments. Here is my list:
Kenneth Geers
Kenneth Geers   1/24/2012   25 comments
The establishment of the US Cyber Command in 2010 confirmed that cyberspace is a new domain of warfare. The computer is not only a target but also a weapon. Therefore, national security thinkers must find a way to incorporate cyberattacks and defense into military doctrine as soon as possible.
5
of
Beau Brendler
Terrorism Expert Says US Gave Away Stuxnet Tech

4|4|12   |   3:29   |   9 comments


US counterterrorism expert Richard Clarke, who came to prominence with his prescient warnings before the 9/11 attacks, tells Smithsonian Magazine the US was responsible for the Stuxnet supersmart worm that attacked parts of nuclear reactors in Iran – and in the process, has given away one of the world's most sophisticated cyberweapons.
what.the.ferraro
CMAS Alert! Something's Wrong! Or Not!

11|2|11   |   03:18   |   27 comments


If you have a CMAS-enabled handset, be prepared to receive scary alerts from the government.
Wisdom of the Big Chair
Facial Recognition Looms on the Horizon

7|27|11   |     |   4 comments


Law enforcement agencies are poised to use iPhones as facial recognition systems in the coming months. The technical advance promises efficiency but has created a backlash among civil liberties proponents.
Full Nelson
The New Cyber War

10|8|09   |   3:06   |   4 comments


Cyber Warfare may be the next frontier for tactical hacking. It has already reared its head in Estonia, Russia, and Georgia, and some say it has been used by North Korea, China, and other world powers. The implications and the potential are both fascinating and scary.
Kim Davis
Aaron Swartz, RIP

1|14|13   |   2:36   |   6 comments


The Internet freedom activist, threatened with jail time, seems to have taken his own life last week.
Kim Davis
British Hacking Report Is 'Bonkers'

12|5|12   |   2:20   |   3 comments


Prime Minister David Cameron pledged to accept the hacking report’s recommendations unless they were “bonkers.” He’s rejecting the main one.
Mary E. Shacklett
Financial Services Policies Lag Tech Advances

12|4|12   |   2:18   |   6 comments


Regulations haven't kept up with advances in mobile devices and credit cards.
Wisdom of the Big Chair
FBI Turns Attention to Mobile Security

10|30|12   |   3:45   |   8 comments


The FBI recently issued a warning to smartphone users, highlighting two mobile malware applications: Loozfan, which steals personal information, and FinFisher, which is spyware that takes over a smartphone's functions.
Mitch Wagner
A Humbling Lesson From Libya on Why IT Matters

9|17|12   |   3:09   |   5 comments


Sean Smith, a US Foreign Service IT manager, gave his life in service of his country and the world. His life and death are a humbling example for all of us who work in IT.
Beau Brendler
Another Step Toward a Chinese Internet

7|2|12   |   1:44   |   3 comments


It wouldn't be the first time, but a group of Chinese engineers has proposed a means by which the Internet's root could be split, enabling secondary, independent networks that could be government-controlled. The Internet's root security committee is taking such proposals seriously.
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   4 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE