Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

The U.S. Department of FUD?

By Winn Schwartau , Network World , 12/15/2006
Schwartau
  • Share/Email
  • Tweet This
  • Comment
  • Print

The U.S. government recently warned financial firms and services of an al-Qaida call for a cyberattack against online stock trading and banking Web sites. The Islamic militant group wants to "penetrate and destroy the databases of the U.S. financial sites," Reuters reported.

Should you care? Not if you have been doing your job.

The United States has been handling information warfare attacks for more than a decade, with varying degrees of success. Our biggest national failure has been defending against Class I information warfare, which targets personal information and is the backbone of identity theft, phishing and similar profit-oriented criminal endeavors.

Business has done better against Class II information warfare: company-to-company information conflicts and industrial espionage. In many ways it can be argued that American industry essentially has chosen to permit the continued theft of intellectual property, rather than institute appropriate (and perhaps politically incorrect) security policies and procedures.

The alleged al-Qaida threat is Class III information warfare. Nation-states, terrorists or other political and/or religious nongovernment organizations target their adversaries for nonprofit motivations, such as denial of service and systemic disruption, including psychological operations (PsyOps). Targeting the private critical infrastructures of perceived adversaries is called unrestricted warfare, as declared by the Chinese against the U.S. private sector in 1998.

Could the United States be promoting or exaggerating the al-Qaida cyberterrorism threat as a means to garner support for current U.S. policies? FUD - fear, uncertainty and doubt - is a powerful weapon that cannot be dismissed out of hand. Or is this al-Qaida using PsyOps, their own form of FUD? This form of FUD-based PsyOps, be it a videotaped beheading or the threat of economic meltdown, is a proven Class III weapon. A few years ago the Irish Republican Army effectively shut down London with a few well-placed threats. No bombs, no boom, but London was brought to a halt.

Let's say that al-Qaida has hired the best hackers and intrusion experts from the United States, China, Israel, Russia. Mass hiring on this scale is highly unlikely, but in examining risk, I like to turn up the dial full tilt to get a view of possibilities. Al-Qaida certainly has more than one guy on an oasis, but they do not have the power of DefCon. They do not have a magic switch to say, "Goodbye, New York Stock Exchange" or "Good riddance, Schwab!"

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed