SECURING CYBERSPACE a New Domain for National Security
Total Page:16
File Type:pdf, Size:1020Kb
SECURING CYBERSPACE A New Domain for National Security FOREWORD BY JOSEPH S. NYE & BRENT SCOWCROFT EDITED BY NICHOLAS BURNS & JONATHON PRICE Copyright © 2012 by The Aspen Institute The Aspen Institute One Dupont Circle, N.W. Suite 700 Washington, DC 20036 Published in the United States of America in 2012 by The Aspen Institute All rights reserved Printed in the United States of America ISBN: 0-89843-562-5 Wye Publication Number: 12/001 Cover Design by: Steve Johnson Interior Layout by: Sogand Sepassi aspen strategy group CO-CHAIRMEN Graham Allison Director, Belfer Center Joseph S. Nye, Jr. John F. Kennedy School of Government University Distinguished Service Professor Harvard University John F. Kennedy School of Government Harvard University Zoë Baird Budinger President Brent Scowcroft Markle Foundation President The Scowcroft Group, Inc. Samuel R. Berger Chair Albright Stonebridge Group DIRECTOR Stephen E. Biegun Nicholas Burns Vice President Professor of the Practice of Diplomacy Ford Motor Company and International Politics John F. Kennedy School of Government Robert D. Blackwill Harvard University Henry A. Kissinger Senior Fellow for U.S. Foreign Policy Council on Foreign Relations DEPUTY DIRECTOR Eliot Cohen Jonathon Price Professor Deputy Director Johns Hopkins SAIS Aspen Strategy Group Susan Collins Senator ASSOCIATE DIRECTOR United States Senate Jennifer Jun Richard Cooper Associate Director Professor Aspen Strategy Group Harvard University Richard Danzig Chairman MEMBERS Center for a New American Security Madeleine Albright John Deutch Chair Institute Professor Albright Stonebridge Group Massachusetts Institute of Technology Richard Falkenrath Richard G. Lugar Principal Senator The Chertoff Group United States Senate Peter Feaver Leo Mackay Professor Vice President Duke University Ethics & Business Conduct Lockheed Martin Corporation Dianne Feinstein Senator Jessica T. Mathews United States Senate President Carnegie Endowment for International Peace Stephen Friedman Chairman Sylvia Mathews Burwell Stone Point Capital President The Walmart Foundation Michael Green Senior Adviser and Japan Chair Sam Nunn Center for Strategic and International Studies Co-Chairman & CEO Associate Professor Nuclear Threat Initiative Georgetown University Meghan O’Sullivan Richard N. Haass Kirkpatrick Professor of the Practice President of International Affairs Council on Foreign Relations John F. Kennedy School of Government Harvard University Chuck Hagel Chairman William J. Perry Atlantic Council Professor Stanford University John Hamre President and CEO John Podesta Center for Strategic and International Studies Chair Center for American Progress Jane Harman Director, President, and CEO Tom Pritzker Woodrow Wilson International Center Chairman and CEO for Scholars The Pritzker Organization LLC David Ignatius Jack Reed Columnist and Associate Editor Senator The Washington Post United States Senate Nicholas Kristof Mitchell Reiss Columnist President The New York Times Washington College Condoleezza Rice Fareed Zakaria Professor of Political Economy Editor-at-Large Stanford University TIME Magazine Carla Anne Robbins Dov S. Zakheim Deputy Editorial Page Editor Senior Fellow The New York Times CNA Corporation David Sanger Philip Zelikow Chief Washington Correspondent Dean, Graduate School of Arts and Sciences The New York Times Professor of History University of Virginia Susan C. Schwab Professor Robert Zoellick University of Maryland President The World Bank Smita Singh Strobe Talbott President The Brookings Institution Acknowledgements Nicholas Burns Jonathon Price Director, Aspen Strategy Group Deputy Director, Aspen Strategy Group n early August 2011, the Aspen Strategy Group convened for a week in Aspen, IColorado to examine a novel and formidable national security challenge: cybersecurity. The diverse group of ASG members and invited guests – comprising government officials, policymakers, academics, journalists, corporate leaders, and foreign policy experts – ensured a wide range of perspectives and a bipartisan dialogue about the complex challenges interwoven in cyberspace. This publication presents the policy papers that established the foundation for our discussions throughout the week in Aspen. It also includes the third annual Ernest May lecture delivered by ASG co-chair, Joseph Nye. As always, the Aspen Strategy Group would like to express our sincerest gratitude to a number of organizations and individuals whose dedication, generosity, and support make the summer workshop possible. Our supporters for this year’s workshop include Mr. Howard Cox, the Bill & Melinda Gates Foundation, the Markle Foundation, McKinsey & Company, Mr. Simon Pinniger, the Margot & Thomas Pritzker Family Foundation, the Resnick Family Foundation, Ms. Carolyne Roehm, the Stanton Foundation, and Mrs. Leah and Mr. Ralph Wanger. We would also like to thank our Associate Director Jennifer Jun and our Brent Scowcroft Award Fellows Allie Kirchner and Annie Moulton for their important contributions to this initiative. We look forward to following their careers as the next generation of foreign policy leaders and experts. Rebecca Yael Weissburg provided her invaluable proofreading and editing skills, and we are deeply grateful. Finally, our highest regards go to our co-chairmen, Joseph Nye and Brent Scowcroft, whose vision and expertise provide the founding merits of the Aspen Strategy Group. Only through their leadership has the ASG been able to build a legacy as a forum of innovative strategic thinking on the most complex national security issues of the day. Contents Foreword by ASG Co-Chairmen .............................................11 Joseph S. Nye, Jr. & Brent Scowcroft Preface by ASG Director ....................................................15 Nicholas Burns Part 1 CYBERWARS & CYBERTERROR: UNDERSTANDING CYBERSPACE AS A NEW BATTLEGROUND The Third Annual Ernest May Memorial Lecture .........................21 Nuclear Lessons for Cybersecurity? Joseph S. Nye, Jr. CHAPTER 1 U.S. Cybersecurity: The Current Threat and Future Challenges ..........43 Eric Rosenbach and Robert Belk CHAPTER 2 Resilience, Disruption, and a “Cyber Westphalia”: Options for National Security in a Cybered Conflict World ...............59 Chris Demchak Part 2 CYBER POLICY: REGULATING CYBERSPACE CHAPTER 3 Eight Questions and Answers on U.S. Cyber Statecraft ...................97 Jason Healey CHAPTER 4 Harnessing Leviathan: Internet Governance and Cybersecurity .................................113 James A. Lewis Part 3 CYBERCRIME: IMPLICATIONS FOR BUSINESS AND THE ECONOMY CHAPTER 5 The Cybersecurity Threat to U.S. Growth and Prosperity . .129 John Dowdy CHAPTER 6 Falling Prey to Cybercrime: Implications for Business and the Economy .............................145 Melissa E. Hathaway Part 4 CYBERSECURITY AND ITS TENSIONS WITH INTERNET FREEDOM CHAPTER 7 Internet Freedom and its Tensions with Cybersecurity ..................161 Richard A. Falkenrath CHAPTER 8 Internet Freedom and Political Change ..................................175 Richard Fontaine Part 5 CYBERSPACE: NEW POLICIES AND A NEW STRATEGY CHAPTER 9 A Path Forward for Cyber Defense and Security .........................193 Michael Chertoff and John Michael McConnell Foreword 11 Foreword by ASG Co-Chairmen Joseph S. Nye, Jr. Brent Scowcroft ASG Co-Chairman ASG Co-Chairman ast March, the U.S. Department of Defense reported that in one of the largest Lcyberattacks in U.S. history, unidentified hackers targeted the Pentagon, stealing approximately 24,000 files, some of which contained highly sensitive information on aircraft avionics, surveillance technologies, satellite communications systems, and network security protocols. Although the scope and success of the attack garnered a great deal of public attention, it is simply one of the countless attacks targeting the government, corporations, and private citizens that rely on cyber technology to meet their daily and perennial needs in areas of communication, business and finance, infrastructure, transportation, and much more. The indispensable role that cyber has come to play in virtually all areas of life renders us all the more vulnerable to the consequences of an insecure cyber environment. Cyberspace today is marred by new and difficult challenges that we have not yet experienced in other traditional domains such as land, sea, air, and space. In the physical realm, countries are marked by borders, and individuals can be traced by addresses, phone numbers, and identification cards. In cyberspace, national borders and individual identities are more ambiguous, making it difficult to attribute a cyberattack to a specific actor. Another perplexing challenge is the inadequate understanding of the full dangers associated with cyberattacks. The private sector’s natural sensitivity to investor confidence proves a major disincentive for companies to reveal any information about their vulnerability and experiences of attack. Meanwhile, governments are unlikely—and rightly so—to publicize information that may compromise national security, including past cases of attacks orchestrated by foreign entities. As for private citizens, many are victims or even abettors of widespread attacks, all without their knowledge. As a group of national security experts that seek to apply our collective acumen to tackle the most important challenges to the United States and the wider world, we 12 Securing Cyberspace: A New Domain for National Security chose to convene our annual Summer Workshop around