Risk
7/30/2010
02:54 PM
50%
50%

Former NSA, CIA Director Says Intelligence-Gathering Isn't Cyberwar

Efforts to crack U.S. cyberdefenses are standard operating procedure, Hayden tells Black Hat audience

LAS VEGAS, NEVADA -- Black Hat USA 2010 -- There's a difference between the gathering of foreign intelligence -- the spy game -- and outright cyberwarfare, a former CIA director told an audience here yesterday.

Click here for more of Dark Reading's Black Hat articles.

Gen. Michael Hayden, who has served as the director of the National Security Agency and the Central Intelligence Agency, offered some insight into the government's views on cyberwarfare in a keynote address at Black Hat. His comments ran contrary to some current and former government officials, who have stated that the U.S. is already engaged in cyberwar.

"When it comes to the question of what is cyberwar, we've been thinking a lot about it, but not very clearly," Hayden said. "I think we've gotten a little sloppy with the language."

Hayden, who is also a former Air Force general, offered some perspective on how military and intelligence leaders view the parameters of cyberwar.

"Cyber is a domain, just as land, sea, air, and space are domains," Hayden said. "God made those four domains; you made the fifth one. God did a better job."

Just as campaigns in the natural domains are conducted by the Army, Navy, and Air Force, the new U.S. Cyber Command will conduct campaigns in cyberspace, Hayden said. But all conflict between nation-states in cyberspace is not warfare, he suggested.

Hayden described "cyber network operations" as a triangle with defense on one corner, attack on another corner, and "exploitation" on a third corner. Exploitation, as he defined it, is the use of cybersecurity technology to extract information from foreign powers.

"In the intelligence community, we don't call that cyberwar," Hayden said. "That's espionage. States do that all the time, and they are not at war." In fact, Hayden praised the efforts of the Chinese government to apply cyber tactics to intelligence gathering. "I stand in awe of the Chinese cyber effort," he said. "It is magnificent."

In the physical world, intelligence-gathering is easier than attack, Hayden said. But in the cyberworld, intelligence gathering is the hard part. "An attack is sudden and easily detected," he observed. "The difficult part in cyber is establishing ways of collecting data silently, without being detected, for a long period of time."

Most of the rules regarding cyberdefense and online intelligence-gathering "are fairly well-established," Hayden said. "But with attack, we're still figuring out the rules. In fact, today about 90 percent of what we're thinking about is attack. But about 90 percent of what we're doing is defense."

One of the biggest questions in cyberspace is who will set the rules of war, Hayden suggested. While the U.S. has its own domestic rules for what can and can't be done online, other countries have their own rules, and there isn't yet an international body whose authority is recognized to govern the use of cyber methods in intelligence or warfare.

The world's most advanced nations should get together and set some rules of engagement that would help prevent the misuse of cyber tactics between nation-states, Hayden said.

"We could set rules that say denial-of-service attacks will never be allowed or excused," he said. "We should agree that some domains are off limits -- such as the power grid or the financial system -- just as we've agreed not to use chemical weapons."

Hayden recognized that such agreements wouldn't prevent terrorists or other states from using such cyberwar tactics, "but if you could get the leading states to limit what they do, the truly malevolent activity would be easier to detect and deal with."

Governments must be careful to evaluate the potential impact of cyberwarfare, just as they are with nuclear weapons, Hayden said.

"Collateral damage is always a consideration," he said. "You have to ask, if you do this, are the lights still going to be on on the Eastern Seaboard?" While cyberwarfare may seem less life-threatening than conventional warfare, Hayden said, "we need to be careful that cyber weapons don't become the special weapons of the 21st century."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7441
Published: 2015-05-29
The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

CVE-2014-9727
Published: 2015-05-29
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

CVE-2015-0200
Published: 2015-05-29
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.

CVE-2015-0751
Published: 2015-05-29
Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800.

CVE-2015-0752
Published: 2015-05-29
Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.

Dark Reading Radio
Archived Dark Reading Radio
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?