Risk
2/17/2011
07:44 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Cyberwar: Experts Have Hard Time Defining It, Let Alone Defending Against It

Rather than wait for a catastrophic event, government and private industry should develop a framework for dealing with state sponsored attacks aimed at the critical infrastructure.

Rather than wait for a catastrophic event, government and private industry should develop a framework for dealing with state sponsored attacks aimed at the critical infrastructure.Although, after watching the panel, one wasn't left with any level of confidence that such a plan would be put into place.

The panel, Cyberwar, Cybersecurity, and the Challenges Ahead, moderated by James Lewis, director and senior fellow at the Center for Strategic and International Studies included Michael Chertoff, former Secretary of Homeland Security; Bruce Schneier, chief technology security officer at BT; and McConnell, former director of national intelligence and former director of the NSA.

To kick things off, James Lewis asks the audience if Stuxnet, operation Aurora, and other similar attacks are, indeed, acts of cyberwar. Some hands went up in agreement that those types of events are acts of war, more attendees however didn't think so.

The panel seemed no more capable of hanging a definition to the term, either. But they did agree, generally, that there is a lot of nastiness that needs to be better controlled. As CSIS' Lewis put it: "We are not in a state of cyberwar, but we are in something that is dangerous."

What do we do about it? Chances are the nation will wait for some catastrophic event argued former intelligence chief Mike McConnell. McConnell expressed doubt that the nation would come together to put into place the policies and public/private partnerships necessary to defend state-sponsored advanced attacks against the critical infrastructure.

McConnell and Chertoff also agreed that vanilla digital espionage and information theft don't rise to Cyberwar. And any such designiation would depend on the scale and the amount of data destroyed in an attack. "I tend to look at security as a spectrum of challenges, and I draw a bright line between theft and espionage and then the destruction of systems," Certoff said. "It depends upon the scale [of the destruction] and its genesis as to whether it is war," he said.

To crystallize his point, Certoff said that as a nation we tolerated state-level spying and the stealing of national secrets without labeling it an act of war, but added that "stealing and espionage are much different things that a sustained attack on the power grid."

Schneier, however, made a case that Cyberwar is a sexy term and a term that sells and opens government budget coffers. "There's a lot of push for budget and power and overstating the threat is a good way to get people scared."

Regardless, it's a dangerous Internet and likely to stay that way for some time. As for potential solutions, the panel put forth little more than increasing regulatory demands on companies to secure their networks and increasing the liability responsibilities for those that fail to protect their systems.

So, as we've dealt with viruses, e-mail based attacks, worms, network breaches, and most every other type of attack - so too will we probably deal with state-backed cyber attacks. And that's to deal with it after the fact, just as McConnell predicts.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: No, no, no! Have a Unix CRON do the pop-up reminders!
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The Impact of a Security Breach 2017
The Impact of a Security Breach 2017
Despite the escalation of cybersecurity staffing and technology, enterprises continue to suffer data breaches and compromises at an alarming rate. How do these breaches occur? How are enterprises responding, and what is the impact of these compromises on the business? This report offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.