2012 4Th International Conference on Cyber Conflict (Cycon 2012)
Total Page:16
File Type:pdf, Size:1020Kb
2012 4th International Conference on Cyber Confl ict PROCEEDINGS C. Czosseck, R. Ottis, K. Ziolkowski (Eds.) 5-8 JUNE, 2012 TALLINN, ESTONIA 2012 4TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT (CYCON 2012) Copyright © 2012 by NATO CCD COE Publications. All rights reserved. IEEE Catalog Number: CFP1226N-PRT ISBN 13 (print): 978-9949-9040-8-2 ISBN 13 (pdf): 978-9949-9040-9-9 ISBN 13 (epub): 978-9949-9211-0-2 COPYRIGHT AND REPRINT PERMISSIONS No part of this publication may be reprinted, reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording or otherwise, without the prior written permission of the NATO Cooperative Cyber Defence Centre of Excellence ([email protected]). This restriction does not apply to making digital or hard copies of this publication for internal use within NATO, and for personal or educational use when for non-profi t or non-commercial purposes, providing that copies bear this notice and a full citation on the first page as follows: [Article author(s)], [full article title] 2012 4th International Conference on Cyber Confl ict C. Czosseck, R. Ottis, K. Ziolkowski (Eds.) 2012 © NATO CCD COE Publications PRINTED COPIES OF THIS PUBLICATION ARE AVAILABLE FROM: NATO CCD COE Publications Filtri tee 12, 10132 Tallinn, Estonia Phone: +372 717 6800 Fax: +372 717 6308 E-mail: [email protected] Web: www.ccdcoe.org LEGAL NOTICE: This publication contains opinions of the respective authors only. They do not necessarily refl ect the policy or the opinion of NATO CCD COE, NATO, or any agency or any government. NATO CCD COE may not be held responsible for any loss or harm arising from the use of information contained in this book and is not responsible for the content of the external sources, including external websites referenced in this publication. 4TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT SPONSORS The NATO CCD COE and the conference organisers want to thank the following sponsors for their support of this year’s conference: ABOUT THE NATO CCD COE The NATO Cooperative Cyber Defence Centre of Excellence (NATO CCD COE) is an international military organisation accredited in 2008 by NATO’s North Atlantic Council as a “Centre of Excellence”. Located in Tallinn, Estonia, the Centre is currently supported by Estonia, Germany, Hungary, Italy, Latvia, Lithuania, the Netherlands, Poland, Slovakia, Spain, and the USA as Sponsoring Nations. The Centre is not part of NATO’s command or force structure, nor is it funded by NATO. However, it is part of a wider framework supporting NATO Command Arrangements. The NATO CCD COE’s mission is to enhance capability, cooperation and information- sharing between NATO, NATO member States and NATO’s partner countries in the area of cyber defence by virtue of research, education and consultation. The Centre has taken a NATO-orientated, interdisciplinary approach to its key activities, including academic research on selected topics relevant to the cyber domain from legal, policy, strategic, doctrinal and/or technical perspectives, providing education and training, organising conferences, workshops and cyber defence exercises and offering consultations upon request. For more information on the NATO CCD COE, please visit the Centre’s website at http://www.ccdcoe.org. For information on Centres of Excellence, visit NATO’s website “Centres of Excellence” at http://www.nato.int/cps/en/natolive/topics_68372.htm. FOREWORD Protecting critical information assets, enabling safe communications, and conducting effective military operations in cyberspace have become critical national security priorities for many nations. They are priorities driven not only by dramatic advances in cyber attack tools and technology, but also by the dangerous reality that such capabilities are in the hands of governments, criminal organizations, terrorist groups, and individual hackers. Once isolated and relatively ineffective, cyber attacks today are highly effective and well-coordinated operations that often consist of sequenced tit-for-tat attacks and counter-attacks. Such attacks have the theoretical potential to paralize national economies, cripple governmental functions, and endanger the physical well-being of populations. The inevitable result of these developments could well be local or even global cyber confl agrations, with consequences rising to the level of those occurring during traditional physical military confrontations. Academic institutions, industrial fora, and governmental organizations have been conducting research, performing case studies, and modeling cyber operations for a number of years. In this active cyber security “ecosystem”, the International Conference on Cyber Confl ict (CyCon) conducted annually in Tallinn by the NATO Cooperative Cyber Defence Centre of Excellence has emerged as especially infl uential, for they offer a unique perspective. This distinctiveness is marked by an innovative synergistic approach to the conceptual framework, architectures, processes and systems of cyber security and confl ict. It holistically examines strategic and policy matters, social and economic concerns, law, computer science and Information technologies, military doctrine, and human behavioral modeling with respect to cyber space. No less important is the open and interactive forum it offers to world-class researchers, legal/ policy/military experts, and IT practitioners. The Proceedings of CyCon 2012, conducted with the technical support of the IEEE Communications Society, are collected in this volume. The twenty-nine papers were selected by the conference Programme Committee following a rigorous peer review process conducted by distinguished experts. The works are sprinkled across the legal, policy, strategic, and technical spectra of cyber confl ict; they include sophisticated analyses of topics like offensive and defensive cyber activities, the concept of the cyber space, its legal and technical boundaries, and the fundamental notions of cyber attacks, cyber attackers, cyber confl ict, and cyber warfare. We hope readers will agree that they comprise erudite and useful examinations of the key questions with which scholars and practitioners continue to struggle. This volume is arranged into six chapters. The fi rst, Cyberspace – The Role of States in the Global Structure, includes articles that consider the role of governments in cyber space policy- making. The second chapter, Cyber Policy & Strategic Options builds on the fi rst with papers that turn to the policies and strategies that States are adopting on such matters as cyber space protection, militarization of the cyber space and cyber warfare. Articles in the third chapter, Cyber Confl ict – Theory & Principles, examine theoretical issues and the historical and operational context in which they are at play. The fourth chapter, Cyber Confl ict – Actors, is a collection of papers that identifi es the various human and software actors involved in cyber ii confl ict and examines their roles and objectives, as well as the ramifi cations of their activities. Chapter Five, “Cyber-Attacks” – Trends, Methods & Legal Classifi cation, deals with the activities of those cyber actors. It includes articles on computer network attack, methods of commanding and controlling cyber attacks, and cyber attacks in the context of international law. The volume concludes with a chapter, Cyber Defence – Methods & Tools, providing a series of technical pieces on cyber security information sensing, decision support and tools supporting the tasks of cyber defense. We would like to thank the distinguished members of the CyCon 2012 Programme Committee for their tireless work in identifying papers for presentation at the conference and publication in this book. Most importantly, though, we are delighted to congratulate this volume’s editors – Dr Katharina Ziolkowski, CPT Christian Czosseck, and Dr Rain Ottis of the NATO Cooperative Cyber Defence Centre of Excellence. Without their technical expertise, professional attitude, personal dedication, and boundless enthusiasm this impressive work would not have been possible. The CyCon 2012 Programme Committee Co-Chairs Dr Gabriel Jakobson Chief Scientist, Altusys Corp Brookline, MA Professor Michael N. Schmitt United States Naval War College Newport, Rhode Island iii TABLE OF CONTENTS Introduction 1 Chapter 1: Cyberspace – The Role of States in the Global Structure 5 Legal Implications of Territorial Sovereignty in Cyberspace 7 Wolff Heintschel von Heinegg When “Not My Problem” Isn’t Enough: Political Neutrality and 21 National Responsibility in Cyber Confl ict Jason Healey Neutrality in Cyberspace 35 Wolff Heintschel von Heinegg Impact of Cyberspace on Human Rights and Democracy 49 Vittorio Fanchiotti / Jean Paul Pierini Chapter 2: Cyber Policy & Strategic Options 61 Russia’s Public Stance on Cyber/Information Warfare 63 Keir Giles French Cyberdefense Policy 77 Patrice Tromparent A Treaty for Governing Cyber-Weapons: 91 Potential Benefi ts and Practical Limitations Louise Arimatsu Internet as a Critical Infrastructure – A Framework for the Measurement 111 of Maturity and Awareness in the Cyber Sphere Assaf Y. Keren, Keren Elazari The Signifi cance of Attribution to Cyberspace Coercion: A Political Perspective 125 Forrest Hare The Militarisation of Cyberspace: Why Less May Be Better 141 Myriam Dunn Cavelty iv Chapter 3: Cyber Confl ict – Theory & Principles 155 Beyond Domains, Beyond Commons: 157 The Context and Theory of Confl ict in Cyberspace Jeffrey L. Caton Applying