Infowar resources

Opinion
Jun 17, 20084 mins

* If you happen to be researching information warfare...

I found some resources in infrastructure protection and information warfare that might interest some readers. This column will be a bit of a collage of neat infowar stuff that you may have overlooked but that bears attention and even rereading.

Recently I had to write a chapter for a textbook when the original author forgot to write it. While I was researching the topic, I used some resources in infrastructure protection and information warfare that might interest some readers. This column will be a bit of a collage of neat stuff that you may have overlooked but that bears attention and even rereading.

The famous Marsh Report (“Critical Foundations: Protecting America’s Infrastructures”) is the Report of the President’s Commission on Critical Infrastructure Protection which met through part of 1996 and 1997 and led to Presidential Decision Directive 63 (PDD-63) on Critical Infrastructure Protection. 

The 1999 RAND Corp. report entitled “Countering the New Terrorism” by Ian O. Lesser, Bruce Hoffman, John Arquilla, David Ronfeldt and Michele Zanini is a fascinating short (174-page) review of asymmetric warfare (the application of inexpensive, relatively easy tools and methods against sophisticated targets). Chapter Three on “Networks, Netwar, and Information-Age Terrorism” will be particularly interesting to readers of this column.

That same year, the General Accounting Office (now called the Government Accountability Office) issued its report GAO/T-AIMD-00-7, “Critical Infrastructure Protection: Fundamental Improvements Needed to Assure Security of Federal Operations”. This was the statement of Jack L. Brock, Jr., the Director of Governmentwide and Defense Information Systems Accounting and Information Management Division. He was testifying before the Subcommittee on Technology, Terrorism and Government Information of the Committee on the Judiciary of the U.S. Senate. His testimony began:

“GAO and IG reports issued over the last 5 years describe persistent computer security weaknesses that place federal operations such as national defense, law enforcement, air traffic control, and benefit payments at risk of disruption as well as fraud and inappropriate disclosures. Our most recent analysis, of reports issued during fiscal year 1999, identified significant computer security weaknesses in 22 of the largest federal agencies. These included weaknesses in (1) controls over access to sensitive systems and data, (2) controls over software development and changes, and (3) continuity of service plans. These types of weaknesses increase the risk that intruders or authorized users with malicious intentions could read, modify, delete, or otherwise damage information or disrupt operations for purposes, such as fraud, sabotage, or espionage. This body of audit evidence led us, in February 1997 and again in January 1999, to designate information security as a governmentwide high-risk area in reports to the Congress.”

In 2000, the White House issued “Defending America’s Cyberspace: National Plan for Information Systems Protection Version 1.0 – An Invitation to a Dialogue”. The document has useful text that can be used when convincing management of the importance – both for the private sector and for government – of information assurance.

Another document from 2000, “The Electronic Intrusion Threat to National Security and Emergency Preparedness (NS/EP) Internet Communications: An Awareness Document” was published by the Office of the Manager, National Communication System. The report includes a short summary of tools and techniques of computer crime and information warfare as well as a catalog of threats, a useful list of acronyms and a short glossary.

In March 2001, the Defense Science Board Task Force on Defensive Information Operations of Office of the Undersecretary of Defense for Acquisition, Technology and Logistics issued its report, “Protecting the Homeland: 2000 Summer Study – Volume II”. Key sections are:

• Building an effective security architecture

• Technology

• Readiness

• Policy and legal

• Findings and recommendations

The February 2003 “National Strategy to Secure Cyberspace” issued by the White House discusses measures related to national cyberspace security:

• A response system

• A threat and vulnerability reduction program

• A security awareness and training program

• Securing governments’ cyberspace and

• National security and international cyberspace security cooperation

A short-lived project from around 2005 and 2006 with the delightful title, “DIRT: Damage Information Reporting Tool” was put together by a group called the Common Ground Alliance. It summarizes some preliminary research – definitely not definitive findings – about damage to underground infrastructure in the United States such as telecommunications lines, gas pipelines and electrical conduits.

A recent paper from February 2008 is “Trojan Dragon: China’s Cyber Threat” by John J. Tkacik, Jr. This 14-page article discusses a widely held view (especially among neo-conservative policy pundits) that Chinese government and military circles are placing a systematic emphasis on information warfare in their foreign policy planning. Despite my credentials as a dyed-in-the-wool, left-wing, knee-jerk liberal radical (something a few readers have graphically pointed out in colorful correspondence after some of my columns), I find myself agreeing vigorously with the author’s analysis.

I hope you enjoy the reading.