Cyber Warfare Takes A New Turn

The recent ransomware events have created headaches and headlines, but also masked a greater cyber-issue: chaos and disruption on the Internet as the new normal. Earlier this week, in fact, the Alliance for Securing Democracy, a new effort headed by former US national security officials, formed as a separate, nongovernmental program to investigate Russian cyber-meddling.

Previous cyber-incidents focused on information acquisition, network infiltration or precision strikes to sabotage the opposition. What are we seeing now are disruptive cyber-actions, with the apparent goals of signaling capability, disrupting normal systems and demonstrating the instability of Western democratic models.

Ransom is not the issue

A number of analysts described the Petya/NotPetya incident of June and the WannaCry event in May as ransom attacks, aimed at gaining as much bitcoin as possible. But our analysis of cyber-coercion highlights how ransomware events such as the Petya are often strategically motivated and less about gaining funds than they are about sending a signal. The primary goal instead appears to be limited destruction through malware wiping systems.

These events can be classified as cyber-disruptions: the use of malware and website defacements between rivals as a form of coercive bargaining. Rival states use cyber-operations to signal one another. Cyber-operations are a 21st-century form of political warfare.

North Korea and Russia are the likely originators of these attacks. What’s the motivation, beyond simply the chaos factor? For Russia, the Petya attack could be a means of encouraging the perception of Ukraine as a failed state, a view that aligns with Russian interests.

Cyber-operations amplify larger psychological warfare efforts. North Korea’s goal, most likely, could be to cause general chaos in Western systems, as a means of signaling strength, and its capacity to escalate in any future crisis.

This is a new era of cyber-conflict

This wave of cyber-disruptions highlights an evolving strategic logic. Competitive interactions in the digital domain evolved from an early period of cyber-probing and testing (1980-2001) to a more stable recent period of cyber-restraint (2001-2016). With Russia’s brazen attempts to undermine American electoral infrastructure and amplify conspiratorial themes through US media outlets, we entered a new era.

The strategic logic of cyber has now shifted from restraint to one of disruption and constant harassment designed to signal capability and the threat of escalation. Russian hackers targeted US institutions, most likely hoping to gain leverage before entering complex negotiations around sanctions, Ukraine and Syria.

While we have yet to witness the extremes of cyberwar, the more subtle danger since 2016 is the way states like Russia and North Korea use cyber-strategies as a form of political warfare. These attacks create chaos, which challenges the prevailing international order and major institutions, from commerce to hospitals to elections, that represent the foundations of Western societies.

Why cyber-warfare works

States have learned that cyber-operations offer a 21st-century vehicle to conduct old-fashioned covert action and psychological warfare without significant fear of rebuke. Russian cyber-meddling over the past two years went largely unpunished in public. Instead, the United States relied on covert coercion to prevent escalation.

Cyber-strategies have now become indirect forms of coercion designed to weaken adversary resolve and create uncertainty, as well as undermine alliances or create political wedges. A growing number of states are using cyber-intrusions to wage psychological warfare and leak information with propaganda value.

In addition to propaganda, states use cyber-operations to influence elections and conduct disruption operations. Russian interference in the elections of Western states has become so common it is now expected. But instead of just disrupting elections, Russia now seems to be leveraging cyberespionage and propaganda to generate larger crises.

Rival states are using cyberspace to wage political warfare campaigns. Here are recent examples:

1) A new group called Global Leaks, an offshoot of the Russian military-attributed group DC Leaks, released the emails of the United Arab Emirates ambassador to the United States in June, causing tensions among Persian Gulf allies by suggesting an alignment between UAE and Israel.

2) In May, Vietnam covertly released transcripts of Donald Trump’s discussions with Philippines President Rodrigo Duterte to disrupt the relationship. Closer ties among China, the Philippines and the United States are problematic for other members of the Association of Southeast Asian Countries hoping to operate by consensus and ward off encroachments by China. Cyber-operations thus became a useful tool to disrupt that developing relationship.

3) In the Middle East, cyber-operations undermine alliances and isolate actors. In June, a Russian hack on Qatar’s state news agency and fake information incorrectly attributing positive statements about Hamas and Iran to the Emir of Qatar may have provoked the first online international crisis. The moves re-sparked a long-standing dispute in the Middle East.

The embargo and ejection of Qatar from the Gulf Cooperation Council (GCC) demonstrates how cyber-operations can have heavy diplomatic ramifications. Russia manipulated the entire Gulf region to turn its back on Qatar by planting stories to be picked up by Saudi news agencies. This led to a cascading diplomatic crisis. Saudi Arabia severed relations with Qatar. Bahrain, Egypt, Jordan and the UAE quickly followed suit.

All of these examples suggest a different character of cyber-conflict, and any new efforts to monitor and curtail these efforts will face no shortage of challenges. To date, cyber-exchanges operated largely under relatively stable international norms, as suggested by Joseph Nye. Yes, China stole intellectual property and rivals probed each other’s networks, but these events didn’t create dangerous crises or seek to undermine faith in Western institutions.

Russia now appears to be using Ukraine as more than a testing ground for cyberwar, it is demonstrating its ability to disrupt faith in public institutions. While the resulting crises after a cyber-event risk inadvertent escalation, the real danger is the erosion of cyber norms. With each new cyber-disruption, the shock decreases, and we grow to expect disorder.

The resulting uncertainty and chaos undermines our trust in the open Internet architecture and risks upsetting stability inherent in cyber-exchanges to date.

Ein News

You Might Also Read: 

Cyberwar: A New Front For US Military:

NATO Could Go To War In Response To A Cyber Attack:

 

« The Impact Of AI On Employment Demands New Thinking
Dark Web Marketplaces Shut Down »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Infinigate UK

Infinigate UK

Infinigate is a value-added distributor of IT security solutions to protect and defend IT networks, servers, devices, data, applications, as well as the cloud.

IP Performance

IP Performance

IP Performance Limited is a leading supplier of customised network infrastructure and security solutions.

Actiphy

Actiphy

Actiphy provides a tried and proven backup and disaster recovery software solution to ensure business continuity at all times.

Conix

Conix

Conix offerings include Governance and Risk Management, Auditing and Penetration Testing, Digital Forensics, Managed Security Operations Centre (SOC).

SIGA

SIGA

SIGA provides cyber security solutions for Industrial Control Systems SCADA systems used in critical infrastructures and industrial processes.

Tecnalia Research & Innovation

Tecnalia Research & Innovation

Tecnalia is the largest center of applied research and technological development in Spain, a benchmark in Europe and a member of the Basque Research and Technology Alliance.

Austrian Institute of Technology (AIT)

Austrian Institute of Technology (AIT)

AIT is Austria's largest research and technology organisation and a specialist in the key infrastructure issues of the future including data science and cybersecurity.

HackControl

HackControl

HackControl services include penetration tests, security audits, block chain audits and brand and anti-phishing protection.

SecureStack

SecureStack

SecureStack helps software developers find security & scalability gaps in their web applications and offers ways to fix those gaps without forcing those developers to become security experts.

Secuvant

Secuvant

Secuvant is an independent IT Security firm providing enterprise-grade IT security services to mid-market organizations.

Two Six Technologies

Two Six Technologies

Two Six Technologies delivers R&D, innovation, productization and implementation expertise in cyber, data science, mobile, microelectronics and information operations.

3i Infotech

3i Infotech

3i Infotech offers consulting & professional services to assess, design and build next gen IT infrastructure, and managed services to operate, optimize and continuously improve.

Dig Security

Dig Security

Dig Security offers the first data detection and response (DDR) solution, providing real-time visibility, control and protection of your data assets across any cloud.

Global Market Innovators (GMI)

Global Market Innovators (GMI)

Global Market Innovators (GMI) delivers secure technology solutions to organizations in need.

Supra ITS

Supra ITS

Supra ITS is a leading full-service technology partner offering IT Consulting, Cloud Services, 24x7 Managed IT & Cybersecurity Services, and IT Project Support.

Defence Innovation Accelerator for the North Atlantic (DIANA)

Defence Innovation Accelerator for the North Atlantic (DIANA)

The NATO DIANA accelerator programme is designed to equip businesses with the skills and knowledge to navigate the world of deep tech, dual-use innovation.