Contributor

Stop the rush to arm cyber space

Opinion
Apr 3, 20083 mins

If you really want to set me off just point me to an interview with some old military guy who uses “cyber” as a noun and uses euphemisms for everything. This article for instance. Apparently there was a conference on Cyber Warfare in London this week and an Air Force base commander was spouting off about counter-measures in cyberspace. Let me re-iterate a few things I have mentioned in previous postings.

Take this from the article:

Air Force Cyber Command (AFCYBER), a US military unit set up in September 2007 to fight in cyberspace, is due to become fully operational in the autumn under the aegis of the US Eighth Air Force.

It makes you think that the Air Force is taking the lead in cyber defense, no? In reality this new “unit” is just the IT department of the US Air Force. You see, “cyber” means “computers” ,and anything to do with them, in the military. The Air Force is not really dedicating 10,000 personnel to defending their cyber assets.

What really concerns me is the talk about taking the offensive. Here you have a branch of the military that has repeatedly demonstrated that it cannot secure its own house contemplating bringing out the big cyber guns and retaliating. I don’t feel comfortable with that. While I would not argue that the US government should not be involved in cyber espionage I would argue that developing new attack tools on the one hand is easy and on the other dangerous. Attacks are simple because most targets are unprepared, as the Air Force has discovered from internal experience. But you better not start lobbing cyber bombs until you have hardened your own defenses.

Try to decipher this statement quoted in the article:

“We’re trying to move away from clandestine operations. We’re looking for real physics – a bigger bang resulting in collateral damage.”

You know what that means. Collateral damage means that infrastructure, enterprises, and commerce could suffer from this “bigger bang” concept.

Someone with a clue has to step in to the US military. One, to stop this kind of silly talk and two, to make sure that IT systems are being hardened in advance of these cyber wars they seem so anxious to engage in.

In the mean time the diplomatic corp should start working on a Pax Internetica. It is my belief that in cyber warfare a good offense is not a good defense. The only result from escalating offensive capability will be disaster. In cyber warfare a good defense is a good defense.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author