In 2016 I presented a hypothetical for IT Ethics at ANU. This was a fictional incident involving a maritime surveillance aircraft. The question for the students was what, as an IT professional, what military response they could participate in. This scenario became real last week when an Australian P-8A Poseidon aircraft reported being targeted by a laser from a Chinese warship, just north of Australia. Fortunately the real situation did not escalate, unlike the hypothetical:
The real report:
"On 17 February 2022, an Australian Maritime Patrol Aircraft P-8A Poseidon detected a laser illuminating the aircraft while it was conducting a routine surveillance flight over Australia’s northern approaches.
The laser was detected as emanating from a People’s Liberation Army – Navy (PLA-N) vessel. Illumination of the aircraft by the Chinese vessel is a serious safety incident. ... sonobuoys were used after the incident ... ahead of the PLA-N vessel. ..."
"At 02:20 Zulu, 1 April 2017, one of our maritime surveillance aircraft was reported missing. The aircraft was conducting a freedom of navigation flyover ... signals from a fire control radar ... aircraft's flares and electronic countermeasures were activated ... "
The authors suggest mitigation strategies can be used, with authorities being ready to broadcast warnings. However, I suggest that if the warnings go out on "old" media, such as local TV stations, many may not see them. Also the attacker could reduce the effectiveness of the official announcements, by sending out fake official denials on social media saying the warnings were not real.
ANU energy researcher and entrepreneur, Dr Backhall, in 2019 described the current Australian electricity grid as being "duct-taped together". His work on smart renewable energy would allow for a more robust grid, which could switch off loads and switch on battery supplies at peak times. However, this equipment would need to be secure, as it offers a new target for hackers.
Reference
Raman, G., AlShebli, B., Waniek, M., Rahwan, T., & Peng, J. C. H.
(2020). How weaponizing disinformation can bring down a city’s power
grid. PloS one, 15(8), e0236517. URL https://doi.org/10.1371/journal.pone.0236517
UNSW Canberra has invited papers for “Cyber Storm”, 18-20 February 2019. The conference will focus on training for cyber warfare.
"Australia’s former Minister of Cyber
Security, Hon. Dan Tehan, warned in November 2016, of the need for the
country to prepare for a cyber storm, even if it was an unlikely
contingency. One view of the Cyber Storm sees it as the contingencies
arising from protracted and complex, multi-vector, multi-wave,
multi-theatre attacks against cyber assets. Such assets can include
critical civil infrastructure, military C4ISTAR, computerised systems in
weapons platforms, and even other civilian targets of military or
national security significance.
This conference will concentrate on the
role universities and professional education institutions, such as
military colleges, can play to address the unique challenges of
workforce formation for the Cyber Storm.
For middle powers like Australia, immense challenges exist in framing
education and training solutions for these contingencies, as the
research foundations on which these policy responses depend, are very
weakly developed, or even non-existent. This is especially case in the
sub-field of simulations. The conventional wisdom, or at least the
dominant practice, has been that the knowledge, skills and abilities
needed would be acquired “on the job” in highly classified environments.
There has been little space for open-source research and therefore
minimal open-source education and teaching. This scholarly conference
will discuss research papers on these subjects by leading specialists
from universities, professional colleges, think tanks, government, and
industry. The academic portion of the conference will not have any
special national focus, but papers that can address the U.S. experience
or that of middle powers like Australia will be highly regarded. The
academic portion will be followed by a one-day invitation-only policy
workshop to give strategic planners in government, the armed forces and
business the opportunity to reflect on practical recommendations arising
from the scholarly research."
Greetings from the National Pres Club In Canberra, where Dr Asif Gill is speaking on "Secure information architecture: security by design". Dr Gill is describing the strategy and architecture needed to get from the current insecure state of an IT system to the desired more secure state.
Dr Gill is describing a defensive strategy however, it occurs to me that the same approach could be used for thinking about offensive operations, where the desired state is less secure for your opponent.
The Australian National University (ANU) is looking for a CEO for its new ANU Cyber Institute. This is an initiative of the ANU's College of Engineering
and Computer Science (CECS) and the National Security College (NSC).
"The
ANU has recently announced the establishment of Australia’s first
interdisciplinary Cyber Institute, bringing together expertise across a
range of areas to deal with the increasingly complex issues in the cyber
domain.
The Institute will present exciting new opportunities for research, innovation and education.
The Chief Executive Officer (CEO) is the Institute’s Head, operating under the broad direction of the Institute Advisory Board.
The
CEO will be responsible for driving the strategic vision and
operational plan for the Institute, working closely with executives and
stakeholders across the University, industry and government, to create a
globally pre-eminent Institute focused on addressing Australian and
global cyber needs."
Dr Herb Lin, Senior Research Scholar,
Stanford University, is speaking on "Cyber-enabled information warfare and the end of the Enlightenment" at the Australian National University in Canberra. He argues that Information Warfare and Influence Operations (IWIO) is a hostile act, but not "warfare" under the UN Charter and laws of war. I agree that using the Internet to influence an enemy is just an extension of previous analog information techniques, but I am not sure those being targeted would not see it as warfare.
Dr Lin's characterizes IWIO operations as being effective, with the use of violence. However, the doctrine of the USA (and Australia) is to respond to cyber attacks based on the effect the attack has, not the nature of the weapons used:
"When warranted, the United States will respond to hostile acts in cyberspace as we would to any other threat to our country. ... We reserve the right to use all necessary means—diplomatic, informational, military, and economic—as appropriate and consistent with applicable international law, in order to defend our Nation, our allies, our partners, and our interests.”
I suggest that if IWIO has a damaging effect on a nation, that nation will respond accordingly. If the attacked nation has a IWIO capability, then they may use that to respond, but reciprocity doesn't require that.
Conventional military forces could be used to respond to IWIO, despite the problem that this may play into the information agenda of the attacker. For this reason a nation may use a covert kinetic military response to IWIO.
Dr Lin discussed ways to disarm a information warfare attack, by carefully identifying the attacker and their motives, as well as debunking false claims made. However, this task may be made more difficult, I suggest, by the nation's own politicians and organizations using the same IW techniques for political campaigning and marketing.
Dr Lin asserted cyber warfare is not a threat to civilization. I don't agree. Conventional and nuclear weapons can only kill people, but cyber war can kill an idea.
Dr Lin used the example of the Russian Government allegedly funding both "black lives matter" and "while lives matter" campaigns in social media in the USA, to spread discontent. These he characterized as chaos-producing operations. While such attacks existed before the Internet, they can now be carried out much easier on-line.
As an example, the technique of fuzzing with AI (Rajpal, Blum & Singh, 2017) might be applied to IW. With fuzzing is used to test the security of computer systems by generating a large number of sets of test data. AI can be used to see which sets are most effective for breaking into a system. The same could be (and may already be) applied to IW: the attacker would generate a large number of variations on a message, such as "black lives matter" and AI would be used to refine the versions of the message which are most effective at creating discontent. On-line marketers already use similar techniques to measure the effectiveness of advertising, by sending slightly different advertisements to individual consumers. However the use of AI could speed up the process. It may that social media is itself is a form of inadvertent IW attack, with a reports linking social media use and depression in teenagers.
One one the more amusing parts of Dr Lin'sentertaining presentation was a clip from Star Trek Deep Space Nine:
"The truth is usually just an
excuse for lack of imagination ...".
From "The Wire", script by Robert Hewitt Wolfe, Episode 2x22, Production number: 40512-442, First aired: 8 May 1994).
Start Trek presented an idealized image of a united world where a western (mostly US) world view had prevailed. This form of soft-power perhaps should not be underestimated.
"The West has no peer competitors in
conventional military power. But its adversaries are increasingly
turning to asymmetric methods for engaging in conflict. In this public
seminar, Dr Herb Lin will address cyber-enabled information warfare
(CEIW) as a form of conflict or confrontation to which the Western
democracies are particularly vulnerable.
CEIW applies the features of modern
information and communications technology to age-old techniques of
propaganda, deception, and chaos production to confuse, mislead, and
perhaps to influence the choices and decisions that the adversary makes.
A recent example of CEIW can be seen in the Russian hacks on the US
presidential election in 2016. CEIW is a hostile activity, or at least
an activity that is conducted between two parties whose interests are
not well-aligned, but it does not constitute warfare in the sense that
international law or domestic institutions construe it. Some approaches
to counter CEIW show some promise of having some modest but valuable
defensive effect. If better solutions for countering CEIW waged against
free and democratic societies are not forthcoming, societal discourse
will no longer be grounded in reason and objective reality – an outcome
that can fairly be called the end of the Enlightenment."
References
Rajpal, M., Blum, W., & Singh, R. (2017). Not all bytes are equal: Neural byte sieve for fuzzing. arXiv preprint arXiv:1711.04596. URL https://arxiv.org/abs/1711.04596
Last week I attended a series of seminars as part of the Securing our Future in Cyberspace Conference hosted by the Australian National University. This gave me inspiration for new material to teach ICT Ethics at ANU. Here is a draft. Comments are welcome:
Unclassified. All Scenario Data is Notional and For Exercise Only
Cyberwar: Hypothetical Scenario for Teaching ICT Ethics
Briefing by Cyberspace Operations Wing at Headquarters Joint Operations Command (COW/HQJOC), 12:30 Zulu 1 April 2017:
Maritime Surveillance Aircraft
"At 02:20 Zulu, 1 April 2017, one of our maritime surveillance aircraft was reported missing. The aircraft was conducting a freedom of navigation flyover on one of the reefs, subject to claim by several nations. The last recorded radio transcripts are:
OPFOR: "Unidentified military aircraft, you are entering a restricted zone. Turn now to avoid unfortunate consequences.
OURFOR: We
are over international waters, in accordance with accepted law.
OPFOR: Unidentified military aircraft, turn back now. This is your last warning.
OURFOR: Mayday, Mayday, Mayday, this is Surveillance One Zero Five Charlie Delta, one zero zero kilometers South East of ... " [Transmission ends]
SIGINT Aircraft
Intercepts from our new signals intelligence (SIGINT) aircraft, which was on a test flight in the area, reported signals from a fire control radar, shortly before communication was lost.
SAM Fire Control Radar
The radar was in test mode, however, the older radar warning receiver in our maritime surveillance aircraft is not sophisticated enough to distinguish a test signal from a real attack.
Our aircraft's flares and electronic countermeasures were activated. This may have been mistaken for the launch of a cruse missile, which our aircraft can carry (but was not).
SAM Transporter Erector Launcher
A surface-to-air missile (SAM) was launched and our aircraft appears to have crashed while maneuvering to avoid the missile. The crew have been rescued by a civilian vessel, but have not yet been debriefed.
The media are reporting that one of our unarmed aircraft has been shot down and the Government has asked for military options to respond. The best kinetic solution is a precision air attack on the missile batteries, guided by special forces landed from a submarine, which is already on station. However, the government has also asked for a cyber option which would disrupt the opposing force's systems, show our national resolve, but avoid casualties.
It is proposed to target the opposing force's electronic control systems. This is expected to disable electrical systems and cause some local electrical fires. Our intelligence assets in the area will arrange for video of the damage to be posted to social media, for maximum news value. We will be working with civilian government personnel with special expertise, to prepare a human factor attack on their Internet of Things (IoT).
Unclassified. All Scenario Data is Notional and For Exercise Only
What Will You Do?
Suppose you are a Senior Incident Responder (SRI) in the Digital Protection Group (DPG) at the Digital Transformation Office (DTO) of the Government. Your job is protecting the whole of government website. Recently you detected a sophisticated attack and boasted "we could turn that attack back on them!". So you are now asked to do just that, despite being a civilian employee.
You are reasonably sure you can mount a cyber-attack which will have the desired political effect: it will disrupt systems of the opposing force enough to cause public embarrassment to their government, with minimum risk of casualties. But can you be sure its effects will be confined to government systems, or to that country? What if the attack shuts down hospital in their country, or across the world?
Is it ethical to be involved in planning such an attack? Would your answer be different, if you are a civilian contractor rather than a government employee, or if you were a military officer? Note that the hypothetical scenario does not say what country is planning the attack, or who they are attacking: does it make a difference to your answer who is attacking who?
Note that you are not asked to become an expert on the Geneva Conventions or the laws of war. However, as an professional you need to be aware of the ethical implications of what you choose to do, or not do, in your work.
The Australian Computer Society's Code of Professional Conduct and Professional Practice, incorporating a code of ethics which requires all members to act with professional responsibility and integrity. How does that code apply to cyberwar? In decreasing order of priority, the ACS Code of Ethics lists:
There will be a question on this topic in the examination.
Discussion
The hypothetical scenario presented is based on real events. In 2015 an Australian military aircraft was challenged by radio while on patrol (Wroe & Wen, 2015). In 2010 the "Stuxnet" computer worm was released, apparently designed to destroy a nuclear processing facility, but spread world wide (Langner, 2011). In 2014 five military officers were charged with hacking to obtain trade secrets (Wechsler, 2016).
Henschke (p. 17, 2014) points out that "the purpose of a cyberweapon is to attack an information system in order to perpetrate harm". Ford (p. 7, 2014) provide a diagram to help decide how to respond to a critical infrastructure/high impact attack. This chart could equally used to plan an attack for maximum impact.
Fictional day care centre (Page & Jean, 2013)
Cyber-warfare attacks do not necessarily need sophisticated computer code. Human factor attack, where someone within the organization being attacked is tricked into providing information or access. In 2013 invitations to apply to a supposed government endorsed child care center were sent to employees of an intelligence agency. An attached form was designed to collect personal information which could be used for later attacks (Page & Jean, 2013).
Department of Defence. (2014, March 18) Royal Australian Air Force AP-3C Orion maritime patrol aircraft. Department of Defence. Retrieved from https://video.defence.gov.au/play/3267#
This presentation contains images that were used under a Creative Commons License. Click here to see the full list of images and attributions: https://link.attribute.to/cc/1584914
Greetings from the Australian National University where a research symposium on "Towards a political ecology of cyberspace" is taking place as part of the conference "Securing our Future in Cyberspace". There is a public forum on "Quantum sovereignty: the Westphalian principle and the global governance of cyberspace" tomorrow, "Taming cyberspace: applying international law in a new domain" Wednesday, "The role of cybersecurity in Chinese foreign policy" Thursday and "Securing our future in cyberspace - next steps" on Friday.
The event has not started well, with the first speaker asking "What is Cyberspace?" and answering their own question with "Well it is really big.". This sounds like a line from the 1995 Steven Seagal film "Under Siege 2: Dark Territory": a US DoD technician searching for a orbital weapons platform says something like "It called 'space' because it is really big". ;-)
The first presentation on the ontology of cyberspace. The second presentation was on the ethics of cyberwarfare. An interesting aspect is the interaction of IT and military ethics. Perhaps the most insightful comment of the morning was describing cyber-warfare as "a game of rock, paper scissors".
The last session I attended was on Balkanization of the internet". This seemed to have missed the point that "The Internet" (with a capital "I") is an internet (small "i"): that is a network of networks. So the term "Balkanization of the Internet" is a tautology: the Internet is, by design balkanized and this is one of its strengths. The network of networks provides for security and Resistance of the Intent. Balkanization is not an emergent property of the Internet, it is an important part of the design.
The "Towards a political ecology of cyberspace" research symposium was disappointing. It presented some introductory material which would be suitable for a first year introduction lecture. Some of the material was technically incorrect. The work presented was of practical minimal pratical value and not high quality academic research.
Dr Leonie Simpson, from QUT, today detailed flaws in the encryption technology in commercial satellite phones. Simpson said that only an ordinary laptop computer would be needed to break the encryption of satphones and "All users of commercial satellite phones are at risk" also that only an ordinary . These phones are used by Australian government officials and the Australian Defence Force on overseas deployments. Simpson was speaking at the Australasian Information Security Conference (AISC 2016).
Vishesh Bhartiya and Leonie Simpson. Initialisation Flaws in the A5-GMR-1 Satphone Encryption Algorithm, Australasian Information Security Conference, February 2016
Greetings from the National Security College at the Australian National University in Canberra, whereMalcolm Turnbull, Minister for Communications, is speaking at the launch of "Strategy and Statecraft in Cyberspace" research. This research will use techniques of complex systems and natural ecology.
The researchers are asking for input from the community and will reach
out via blogs and other on-line forms.
Minister Turnbull started by saying the Internet is the single most powerful driver of innovation in human history (I would nominate the invention of language and writing as greater influences). He included ASD one agency which has a role in cyber security policy. Also he made a reference to "Mr. Snowdens's burglary". Minister Turnbull pointed out that governments had to protest publicly about being spied on by NSA, because the details were made public.
Minister Turnbull then turned to the digital economy. He emphasised that the Internet was built and is run by the private sector, not governments. I don't agree that this is so significant: most human activities are run by private individuals, non-profit and for-profit organisations (not government). I helped set up the structure used to run the Internet and it was not so different to the structures I help run for other civic activities. However, I agree with his assertion that maintaining a cyberspace not dominated by government is a goal.
Minister Turnbull asserted that the Internet is run by US based bodies, but not run by the US government. He characterises the way the Internet is governed as ad-hoc, but this is not the case. The Internet was set up with a governance structure carefully designed to prevent government control: this is no accident.
I will post a link, when the text of the speech is available.