
Patricia Muoio
I have to admit I was ecstatic when I read about the establishment of the volunteer cyber army in the Ukraine. The story had an appealing “can do” attitude and echoed the tales of the triumph of the little guy and the have-nots in much loved stories of David and Goliath and Robin Hood Cleverness and agility triumph over stodgy might. However, the notion of a cyber militia shines a light that reveals some troubling aspects of the state of cybersecurity.
Cyber Weapons Are Way Too Easy to Deploy
One can arm a cyber militia instantaneously at extremely low cost. Set up a website with some tools and instructional videos and you are good to go. No supply chain issues, no limit on availability quantities, no fuss about delivery delays. The technical barriers to join the ranks of the hackers are extremely low. Any moderately savvy internet user can come up to speed quite quickly. There are some brakes on the activity of a newly minted hacker. Skill is needed to determine which attacks will work on which systems and some attacks, such as DDoS attacks, require concerted effort. However, a hacker once armed can turn his attention to other objectives. Given the ease with which cyber weapons can be deployed and replicated, should we have a different standard of care for letting them loose in the wild?
"We must come to understand and address the underlying properties that are common to attacks and not get caught up in their accidental differences"
We Have Profound Understanding of Cyber Attacks, Why Can’t We Defend Against Them
The ease with which we can make cyber attack methods available to the masses demonstrates the robustness of our understanding of cyber attacks. We can essentially shrink wrap our exploits and ship them wherever we would like to use them. Given this depth of knowledge, why can’t we defend against them? The standard line in cyber discussions is “you only need to exploit one vulnerability, you need to defend against them all,” and this asymmetry is used to explain our ineffectiveness in thwarting cyber attacks. The flaw with this reasoning is the assumption that you guard against each vulnerability uniquely rather than seek general defenses that have broad-based effectiveness. Much of our cyber security industry is made up of point solutions targeting individual threats dooming us to a losing game of cyber whack-a-mole. We need to use our understanding of cyber attack methodology to reason about what is essential to all (or at least many) attacks and develop solutions that address these essential features. We need to stop cataloging threats and vulnerabilities, and concentrate on which flaws matter and why. We must come to understand and address the underlying properties that are common to attacks and not get caught up in their accidental differences. Paradoxically, this kind of understanding underpins the commoditization and democratization of cyber attacks for general use. It would be quite powerful to use it in the development of our cyber defenses.
Should Cyber War Have Different Rules Than Kinetic War
We mentioned the low technical barriers to cyber weapon proliferation above. It is worth considering other aspects of cyber warfare that increase the risk of rapid proliferation. Cyber weapons are bloodless and targeted against abstract enemies. Cyber weapons are cool, brainy, and frequently glorified in TV, movies, and media. The attacker can keep his hands clean, and even boast of his exploits, with little risk of recoil. Cyber attackers are perceived as heroes more than villains. This lack of broad-based moral objection to cyber attack further accelerates the proliferation of cyber warfare. Further, the impacts of cyber attack are often diffuse and even carefully targeted efforts can cause harm to connected organizations. Attackers rarely look beyond first order effects and the penumbra of harm is ill understood. Given these realities, should we exercise greater caution in calling for volunteers to the cyber army? Can we really expect to control the use of cyber weapons made broadly available? Should we just admit broad based attacks as a reality and redouble our efforts to find systemic, attack-agnostic cyber solutions that make sense in this new reality? It may be too late for meaningful discussion on these issues, and this move to systemic solutions is our only viable response.


