Meeting the Cyber Security Challenge
Total Page:16
File Type:pdf, Size:1020Kb
Research Series 01.2012 - Newidea 7 - 2012 GCSP avenue de la Paix 7bis Meeting the P. O. Box 1295 CH - 1211 Geneva 1 T + 41 22 906 16 00 Cyber Security Challenge F + 41 22 906 16 49 [email protected] www.gcsp.ch Gustav Lindstrom Impartial, Inclusive, Influential The opinions and views expressed in this document do not necessarily reflect the position of the Swiss authorities or the Geneva Centre for Security Policy. Copyright © Geneva Centre for Security Policy, 2012 Meeting the Cyber Security Challenge Gustav Lindstrom GCSP Geneva Papers — Research Series n° 7, June 2012 The Geneva Centre for Security Policy The Geneva Centre for Security Policy (GCSP) is an international training centre for security policy based in Geneva. An international foundation with over forty member states, it offers courses for civil servants, diplomats and military officers from all over the world. Through research, workshops and conferences it pro- vides an internationally recognized forum for dialogue on timely issues relating to security and peace. The Geneva Papers and l’Esprit de Genève With its vocation for peace, Geneva is the city where international organizations, NGOs, and the academic community, working together, have the possibility of creating the essential conditions for debate and concrete action. The Geneva Pa- pers intend to serve the same goal by promoting a platform for constructive and substantive dialogue. Geneva Papers – Research Series The Geneva Papers – Research Series is a new set of publications offered by the GCSP. It complements the Geneva Papers – Conference Series that was launched in 2008, whose purpose is to reflect on the main issues and debates of an event organized by the GCSP. The Geneva Papers – Research Series seeks to analyse international security issues through an approach that combines policy analysis and academic rigor. It encour- ages reflection on new and traditional security issues that are relevant to GCSP training, such as the globalization of security, new threats to international secu- rity, conflict trends and conflict management, transatlantic and European security, the role of international institutions in security governance, and human security. The Research Series offers innovative analyses, case studies, policy prescriptions, and critiques, to encourage discussion in International Geneva and beyond. Drafts are peer-reviewed by the GCSP Review Committee. All Geneva Papers are available online, at www.gcsp.ch/Resources-Publica- tions/Publications For further information, please contact : Anne-Caroline Pissis, External Relations Manager : [email protected] Series Editor : Thierry Tardy Copyright © Geneva Centre for Security Policy, 2012 Table of Contents About the Author .................................................................................................4 List of Acronyms ..................................................................................................5 Executive Summary .............................................................................................6 Introduction..........................................................................................................8 Why Should We Care About Cyber Security?......................................................10 What Are the Principal Cyber Security Challenges? ...........................................15 Cyber security challenges primarily impacting the individual user .......15 Cyber security challenges primarily impacting national security ...........19 What Is Being Done to Address Cyber Security Challenges? ..................................23 Preventive measures ...............................................................................23 Consequence management measures .....................................................26 What Are the Outstanding Issues?.....................................................................28 Reaching balance between defensive and offensive cyber capabilities.........28 Clarifying the legal landscape and the application of international law....30 Making progress on a governance model ..............................................32 Conclusion..........................................................................................................35 Annex A: Glossary of Technical Terms .................................................................36 Geneva Papers – Research Series.........................................................................39 GCSP Geneva Papers — Research Series n°7 3 About the Author Dr Gustav Lindstrom is Head of the Euro-Atlantic Security Programme and Course Director of the European Training Course in Security Policy (ETC) at the Geneva Centre for Security Policy (GCSP). He received his doctorate in Policy Analysis from the RAND Graduate School and M.A. in International Policy Studies from Stanford University. Prior to his tenure at the GCSP, Dr Lindstrom served as a Senior Research Fellow at the EU Institute for Security Studies (EUISS) in Paris. His areas of expertise include transatlantic relations, the EU’s Common Security and Defence Policy (CSDP), terrorism, non-proliferation, and cyber security. 4 GCSP Geneva Papers — Research Series n° 7 List of Acronyms ATM Automated Teller Machine CERT Computer Emergency Response Team CoE Council of Europe CSIRT Computer Security Incident Response Team CSIS Center for Strategic and International Studies DARPA Defense Advanced Research Projects Agency DCS Distributed Control System DDoS Distributed Denial of Service DNSSEC Domain Name System Security Extensions EMP Electromagnetic Pulse ENISA European Network and Information Security Agency EU European Union GGE Group of Governmental Experts GSM Groupe Spécial Mobile (Global System for Mobile Communications) ICANN International Corporation for Assigned Names and Numbers ICS Industrial Control System IHL International Humanitarian Law IPv6 Internet Protocol Version 6 IT Information Technology ITU International Telecommunication Union LoAC Law of Armed Conflict NATO North Atlantic Treaty Organization OECD Organization for Economic Cooperation and Development Malware Malicious Software RFID Radio Frequency Identification Device SCADA Supervisory Control and Data Acquisition System SIM Subscriber Identity Module GCSP Geneva Papers — Research Series n°7 5 Executive Summary While most policymakers agree that there are substantial risks in cyber space, there is disagreement on whether or not it poses a threat to national security. The divergence in opinions is most obvious when references are made to terms such as cyber war and cyber warfare. In spite of these differences, there are many reasons why policymakers should care about developments in cyber space. With society’s growing reliance on cyber space, a disruption can have wide ranging implications and cascading effects. At the level of national security, there are also indications that government systems are routinely probed for weaknesses. It comes as no surprise that the losses from sabotage, the theft of intellectual property, and cyber crime are counted in the billions of Euros. While the prospects of cyber war are unlikely, it is increasingly evident that a cyber dimension is likely to be part of future conflicts. According to a preliminary assessment carried out by the Center for Strategic and International Studies (CSIS) in Washington, DC, 33 countries presently include cyber warfare in their military planning and organization. These might include “cyber capabilities for reconnaissance, information operations, the disruption of critical networks, for ‘cyber-attacks’, and as a complement to electronic warfare and information operations.”1 In response, there are a number of measures being undertaken to address dif- ferent types of cyber security challenges. These include both technical and insti- tutional means that can be applied in a preventive and consequence management situation. Key among these measures are raising awareness of cyber risks and promoting international cooperation. Looking ahead, policymakers in national security will have to give careful consideration to three key issues: 1 J. Lewis and K. Timlin, “Cybersecurity and Cyberwarfare: Preliminary Assessment of National Doctrine and Organization”, Center for Strategic and International Studies, Washington, DC, 2011, p.3. Ac- cessed on 7/05/2012 at http://www.unidir.org/pdf/ouvrages/pdf-1-92-9045-011-J-en.pdf 6 GCSP Geneva Papers — Research Series n° 7 • Finding a balance between defensive and offensive cyber capabilities – What are the implications of a shift to more offensive cyber capabilities? For exam- ple, could it lead to a cyber arms race? How might it affect the future conduct of warfare? • Clarifying the legal landscape and the application of international law – A key question is whether a cyber operation can be equated to an armed attack or a wrongful threat or use of force. • Examining the prospects for or against an Internet governance model – Spe- cifically, is there need for a more formal government role to manage the Internet? Regardless of the paths taken, the choices will have longstanding implications for cyber security and how cyber space is used in the future. GCSP Geneva Papers — Research Series n°7 7 INTRODUCTION Introduction2 The link between cyber security and national security is a recent phenomenon.3 As of 2000, an increasing number of national security strategies and white papers link cyber security to one of three aspects associated with national security: the need to protect critical