Nominee for Cyber Command post takes shoot first, ask questions later stance
endif; ?>A nominee to head the United States’ Cyber Command is expected to tell a Senate committee Thursday that the U.S. should retaliate against cyber attacks even when the identity of the attackers is unknown.
U.S. Army Lt. General Keith Alexander’s position was revealed in his answers to a questionnaire from senators on the Armed Services Committee who will vote on his nomination by President Obama to add the Cyber Command duties to his current job as director of the National Security Agency. The questionnaire was obtained by the Associated Press.
I’ve followed with interest the issue of cyber warfare on this blog in the past, most recently when the subject came up during the RSA Conference 2010 in San Francisco in March. Of course, since so many of the world’s computers run Microsoft Windows, those machines are common targets of cyber attacks.
“Alexander’s answers reflect the murky nature of the Internet and the escalating threat of cyber terrorism, which defies borders, operates at the speed of light and can provide deep cover for assailants who can launch disruptive attacks from continents away, using networks of innocent computers,” the AP noted.
Although it is difficult to effectively retaliate or prevent an attack if the attackers’ identity isn’t known, we have a clear right to self-defense, Alexander asserted. “[While] this right has not been specifically established by legal precedent to apply to attacks in cyberspace, it is reasonable to assume that returning fire in cyberspace, as long as it complied with law of war principles … would be lawful.”
As the senators noted in their questions, the police don’t have to know the identity of a shooter before they can shoot back.
U.S. computer networks are under constant attack and while cyber sleuths have sometimes been able to trace attacks to certain countries, it can’t always be determined if the attackers are criminals or state-sponsored cyber terrorists. On the RSA cyber security panel I listened to, security consultant Richard Clarke and former Department of Homeland Security Secretary Michael Chertoff said effective defenses against cyber attacks are complicated by the lack of attribution of attacks to a person or persons.
Alexander, though, is saying that doesn’t matter. To him the cyber security threat is too real and the consequences too great to have to identify the attackers before retaliating. He said a cyber counter-attack must be authorized by the president and, just as in a military counter-attack, the cyber counter-attack must conform to international law and be proportional to the size and scope of the original attack.
My original post about the RSA panel prompted a reaction from some readers who felt Clarke and Chertoff were hyping the threat to sell their consulting services. But from what I’ve learned about cyber attacks, it’s a threat to be taken seriously. Because hackers launch their attacks with such stealth, it can be hard to know when they may strike or from where. And because we don’t know if cyber attackers have yet done their worst, the potential damage they could do to computer networks, our security and the economy is incalculable.




