The Politics of Internet Security Private Industry and the Future of the Web
Total Page:16
File Type:pdf, Size:1020Kb
CYBER STATECRAFT INITIATIVE THE POLITICS OF INTERNET SECURITY PRIVATE INDUSTRY AND THE FUTURE OF THE WEB Justin Sherman Scowcroft Center for Strategy and Security The Scowcroft Center for Strategy and Security works to develop sustainable, nonpartisan strategies to address the most important security challenges facing the United States and the world. The Center honors General Brent Scowcroft’s legacy of service and embodies his ethos of nonpartisan commitment to the cause of security, support for US leadership in cooperation with allies and partners, and dedication to the mentorship of the next generation of leaders. Cyber Statecraft Initiative The Cyber Statecraft Initiative works at the nexus of geopolitics and cybersecurity to craft strategies to help shape the conduct of statecraft and to better inform and secure users of technology. This work extends through the competition of state and non-state actors, the security of the internet and computing systems, the safety of operational technology and physical systems, and the communities of cyberspace. The Initiative convenes a diverse network of passionate and knowledgeable contributors, bridging the gap among technical, policy, and user communities. Atlantic Council CYBER STATECRAFT SCOWCROFT CENTER INITIATIVE FOR STRATEGY AND SECURITY THE POLITICS OF INTERNET SECURITY PRIVATE INDUSTRY AND THE FUTURE OF THE WEB Justin Sherman ISBN-13: 978-1-61977-125-3 © Justin Sherman Cover: Concept image of cables and connections for data transfer in the digital world. Credit: iStock. This report is written and published in accordance with the Atlantic Council Policy on Intellectual Independence. The author is solely responsible for its analysis and recommendations. The Atlantic Council and its donors do not determine, nor do they necessarily endorse or advocate for, any of this report’s conclusions. October 2020 #ACcyber THE POLITICS OF INTERNET SECURITY: PRIVATE INDUSTRY AND THE FUTURE OF THE WEB TABLE OF CONTENTS Executive Summary �������������������������������������������������������������������������������������������������������������������������������������������� 1 1: Introduction ...................................................................................................................................................... 2 2: Mapping Private Sector Influence on the Internet: Starting with Internet Protocols ������������4 3: Routing and the Border Gateway Protocol .......................................................................................... 8 3.1 How the BGP Works .............................................................................................................................. 8 3.2 How the BGP Malfunctions and Gets Exploited ........................................................................ 9 3.3 Influencing the BGP’s Security. .......................................................................................................13 4: Addressing and the Domain Name System .......................................................................................16 4.1 How the DNS Works.............................................................................................................................16 4.2 How the DNS Gets Exploited ..........................................................................................................16 4.3 Influencing the DNS’s Security .......................................................................................................18 Recommendations and Conclusion...........................................................................................................22 About the Author ..............................................................................................................................................24 Acknowledgments ...........................................................................................................................................24 IV ATLANTIC COUNCIL #ACcyber THE POLITICS OF INTERNET SECURITY: PRIVATE INDUSTRY AND THE FUTURE OF THE WEB EXECUTIVE SUMMARY he private sector’s influence on the Internet’s that US policymakers better understand this private sector shape and behavior—and, therefore, its security— influence on the Internet so it can help shape incentives for is enormous yet understudied. This infrastructural security. influence, spanning companies like Internet Tservice providers and cloud services providers, is also This report examines two protocols as examples of private underappreciated in US policy. The US government was the sector influence over presently vulnerable systems key to the exclusive driver of Internet development for its first twenty- Internet’s function: the Border Gateway Protocol (BGP), used four years, and states continue to shape the Internet today to route Internet traffic, and the Domain Name System (DNS), through regulation, capacity-building, and direct participation used to address Internet traffic. These two case studies detail in Internet processes. But Internet governance is now largely how the protocols work, why they are vulnerable or error- privatized. This report argues that the US private sector’s prone, and what the private sector can do about it. This report unique influence on global Internet infrastructure gives it an uses empirical data on attacks and current protections. opportunity and responsibility to improve Internet security, and that the US government should better collaborate with This report concludes with a set of actionable recommendations those actors and leverage that influence. for US policymakers. The US government should add Internet protocol security best practices to federal procurement rules, This argument matters because Internet insecurity is a targeting major players with outsized influence on Internet national security issue for the United States and every infrastructure. The US government should also leverage other nation. Internet insecurity is also a selling point for the its public-private partnerships to convene forward-looking several authoritarian countries seeking to undermine trust discussions about the next set of Internet protocol security in the free and open Internet model and replace it with a challenges. This report recommends that the US government state-controlled, “sovereign” version. The US private sector, require Internet protocol protections for federal agencies. It through its influence on the Internet’s technology, protocols, recommends private sector dialogues on threat data sharing standards, and operational practices, has an opportunity for Internet protocol attacks. And it recommends a concerted and responsibility to address these problems by reshaping US reinvestment in cyber diplomacy at the State Department the Internet to make it more secure—but many firms are not to help establish state norms of nonaggression against key maximally using their influence to do so. It is critically important parts of the Internet’s infrastructure. ATLANTIC COUNCIL 1 #ACcyber THE POLITICS OF INTERNET SECURITY: PRIVATE INDUSTRY AND THE FUTURE OF THE WEB 1: INTRODUCTION he private sector plays a crucial role in defining the space is enormous yet incompletely studied and could be changing shape of the Internet, especially its security. better leveraged in US government policy. Any renewed US strategy to secure cyberspace must recognize and leverage this private sector influence, As some elements of the US government2 work to increase the Twhich spans everything from undersea fiber optic cables and security of the Internet and its users—journalists, diplomats, the management of Internet exchange points to the definition businesses, citizens—they must address the influence of Internet standards and the management of cryptographic of the private sector on global Internet security. Internet keys. Internet protocols for packet addressing and routing insecurity is a national security issue for the United States are a useful way to examine how the private sector and the and every other nation. It has become even more important US government can collaborate to improve global Internet during the COVID-19 pandemic as citizens, businesses, and security. Where the private sector may not maximally use its governments massively increase online activity that must influence to shape these digital behaviors for security, the US be secured. Internet insecurity is also a selling point for government can incentivize firms to do so. many authoritarian countries which seek to promote a state- controlled replacement for the current Internet. Many private Governments influence the shape of the global Internet today companies have influence over Internet infrastructure, and by diverse means: laws around online content takedowns, thus the power to improve Internet security, but are not commercial encryption, and data localization; interactions with maximally using it—which is where the US government can standard-setting bodies like the Internet Engineering Task provide better incentives. Force (IETF) and norm-setting bodies like the United Nations Group of Government Experts (UN GGE); and, more directly, Internet protocols for packet addressing and routing are a via the procurement and construction of public infrastructure. prime point of this influence. They are defined by the Internet Through regulation, standard-setting, diplomatic negotiations, Engineering Task Force (IETF), a multistakeholder body overseas capacity-building and investment, trade agreements, composed of many