[00:02.000 --> 00:08.700] And our subject for discussion is Strategic Thought in Virtual Deterrence and Real Offense, and we're examining the computer's role. [00:11.000 --> 00:17.160] Our first section of this presentation is discussing an introduction or the basics. [00:18.640 --> 00:20.740] What are the fundamental subjects that apply? [00:21.220 --> 00:24.760] And as we discuss the subject, we're going to bring up a number of issues. [00:25.760 --> 00:28.800] And at the end, we're going to hope to discuss them and what they mean to you. [00:28.800 --> 00:38.020] The sections in this presentation are an introduction, the subject of virtual defense, virtual deterrence, what real offense means, and the conclusions. [00:40.700 --> 00:47.580] Okay, regarding strategy, warfare is not a simple conflict necessarily between fighting forces. [00:47.900 --> 00:54.780] There are different ways of approaching and understanding war, which started as early as the Chinese warrior philosophers in a meaningful way. [00:54.780 --> 01:15.700] During the Cold War, we have methods and notions developed regarding things such as the prisoner's dilemma problem and issues regarding mutually assured destruction, which relate to what do two parties with animosity do when they can either destroy each other and themselves potentially in the process, [01:16.300 --> 01:19.940] and how can they gain advantage if they have a potential to sink their adversaries. [01:20.500 --> 01:22.740] And this has been examined through math of game theory. [01:23.260 --> 01:29.560] Presently, we're looking at issues which are coming up now regarding notions associated with asymmetric warfare. [01:29.960 --> 01:33.720] What do you do with... Actually, I'll be discussing that in more detail shortly. [01:34.560 --> 01:36.340] Network-centric operations. [01:36.340 --> 01:46.560] To start with, I will take a quote from the Signal magazine of this month, which says, The Army's land warrior program will turn even the muddiest boot soldier into a network node. [01:47.040 --> 01:51.880] Military nowadays depend on computers and networks to conduct operations successfully. [01:52.300 --> 02:01.880] Network-centric operations enhance the information flow and reduce the time span between detection of a target and a kill. [02:01.880 --> 02:09.420] NCO also enables joint operation, which is cooperation between different branches of the armed forces. [02:10.240 --> 02:10.880] Next slide. [02:12.620 --> 02:13.800] Information superiority. [02:14.420 --> 02:26.960] Information superiority is defined as the capability to collect, process and disseminate an uninterrupted flow of information, while exploiting or denying an adversary's ability to do the same. [02:27.880 --> 02:35.940] Information superiority is vital for the military, as it enables them to remove the fog of war being uncertainty during a conflict. [02:36.220 --> 02:43.120] And already nearly ten years ago, General Sullivan said, Information is the currency of victory on the battlefield. [02:43.600 --> 02:47.700] But we have to keep in mind, information superiority alone is useless. [02:48.100 --> 02:49.780] We need to have decision superiority. [02:49.780 --> 02:54.960] And that's achieved if we translate superior knowledge and decision. [02:54.960 --> 02:56.360] Next slide. [02:56.840 --> 02:56.980] Okay. [02:57.760 --> 03:02.160] Information operations are not conducted alone, and they're not simple matters. [03:02.300 --> 03:10.000] They're not just an individual, regardless of the tool set, issuing commands or playing a game, so to speak. [03:10.000 --> 03:17.580] You have operations leveraged to gain, ideally, if waged properly, information superiority. [03:19.840 --> 03:23.060] What it does involve, though, are a number of factors and organizations. [03:23.400 --> 03:28.860] You have support in attack and defense roles, offensive and defensive organizations. [03:28.860 --> 03:42.200] With that comes information assurance, psychological operations, electronics warfare, counterintelligence, counter-psychological operations, deceptions and counter-deceptions, and additional methods, even including electronics warfare. [03:44.140 --> 03:49.540] It's not necessarily a simple or low-budget activity, and it can be rather intricate and has to be organized. [03:53.780 --> 03:57.260] Information operations can be viewed along a timeline. [03:58.040 --> 04:00.280] Now, peace, of course, is a relative term. [04:00.620 --> 04:02.900] There's typically not considered a true state of peace. [04:03.540 --> 04:09.100] Social Fortune magazine will explain that very nicely, that even when things appear quiet, there are conflicts all over. [04:09.380 --> 04:15.720] But this is a way from the bottom up to look at, perhaps, how and when different methods are employed. [04:15.720 --> 04:26.240] For example, navigation, weather analysis, are always conducted regardless of whether a peace, crisis, conflict, post-conflict, or a restoration of peace. [04:27.460 --> 04:37.320] Assurance matters, information security, computer security, communication security, and mission security, are always observed by government as best they generally can. [04:38.480 --> 04:45.700] Intelligence, surveillance, and reconnaissance missions are conducted routinely in all phases of life in existence for government. [04:45.720 --> 04:51.640] Now, command, communications, control, and computers, again, occur in all phases. [04:52.000 --> 05:03.900] What's interesting is that pre-crisis and up to post-restoration, or just about restoration, you get into deception operations, psychological ops, and electronics warfare. [05:04.780 --> 05:12.160] Now, slightly overlapping this, pre-crisis to post-restoration, you also find physical attacks occurring and information attacks. [05:16.870 --> 05:18.290] Just war theory. [05:18.550 --> 05:18.770] Just war theory. [05:18.770 --> 05:23.370] The just war theory is devoted to the justification of how and why wars are fought. [05:23.710 --> 05:26.990] The justification can either be theoretical or historical. [05:27.470 --> 05:37.430] The theoretical aspects look at how to ethically justify war and forms of warfare, whilst the historical aspect looks at international treaties, rules, and agreements. [05:37.430 --> 05:39.050] There are usually two types. [05:39.670 --> 05:47.370] Use at bellum, the justice of war, how to justify engaging into a war, and use in bellum, just and fair conducts of war. [05:47.630 --> 05:49.490] And now we see the criteria's up there. [05:49.710 --> 05:52.810] And we see, like, just cause, competent authority, and so on. [05:53.010 --> 05:56.450] But at the back, at the bottom, we see reasonable hope of success and proportionality. [05:57.190 --> 06:05.530] And we have to ask ourselves, whether with information operations, whether we have a reasonable hope of success, and whether it's proportional to... [06:05.530 --> 06:06.270] Next slide. [06:07.450 --> 06:13.890] On the next slide, we see one of the leadership's responsibilities, like to accomplish the mission, fight and win. [06:14.230 --> 06:20.950] But even if we don't even have a doctrine for information operations, we don't really know how to fight, nor do we know how to win. [06:20.950 --> 06:26.970] And at the bottom, you'll see from the just war tradition, we need to limit civilian casualties. [06:27.210 --> 06:36.170] But how are we going to limit civilian casualties if we might have weapon systems, which can't discriminate between combatants and non-combatants? [06:38.190 --> 06:38.670] Okay. [06:38.670 --> 06:40.590] Some of the issues for this section... [06:40.590 --> 06:46.430] And again, we'd like to know your thoughts on these, and we'll discuss them in some length after the presentation. [06:46.430 --> 06:54.170] But for this section, we have issues of, are traditional or contemporary notions of strategy sufficient to understand information operations and warfare? [06:54.510 --> 06:58.310] And how do you analyze, in strategic terms, the asymmetric threats? [06:58.570 --> 07:05.750] The notion of the lone individual or rogue organization or self, for example, being disproportionately powerful should it choose to act. [07:06.370 --> 07:08.750] The next section is virtual deterrence. [07:08.910 --> 07:14.250] And we'll start by an examination of just what is virtual deterrence and how is it different from defense? [07:14.970 --> 07:21.450] Well, the notion of virtual deterrence does not refer purely to defensive measures such as firewalls. [07:21.610 --> 07:29.750] What it really regards and relates to is instilling a fear factor in potential adversaries onerous enough that they will not wish to attack you or engage you. [07:31.330 --> 07:32.270] Alertness fatigue. [07:32.630 --> 07:41.550] People responsible for defending networks are flooded with alerts, threat vulnerabilities, and so on, and also false positives from IDSs. [07:41.550 --> 07:50.950] So, we have to ask ourselves, how can they maintain village vigilance in such an environment if they are flooded with mostly meaningless alert? [07:51.510 --> 07:54.730] And also ask ourselves, how can the military and the government do the same? [07:55.410 --> 07:55.810] Next one. [07:59.530 --> 08:00.170] Retaliation. [08:00.570 --> 08:08.310] If the nation state is attacked by cyber attacks, it doesn't need to only respond with virtual counterattacks. [08:08.490 --> 08:17.310] It has different means, being conventional means, being non-conventional, which can be weapons of mass destruction or weapons of mass destruction. [08:17.310 --> 08:19.210] Also, there's another problem. [08:19.490 --> 08:23.170] Usually, how are you going to spot the origin of the attack? [08:23.330 --> 08:27.510] Because sometimes he can't, and you don't want to hit back at the wrong nation. [08:28.390 --> 08:34.210] Also, there are other issues that a response may be economic or military or by way of another information operation. [08:34.610 --> 08:46.030] But if you publish under what circumstances you will engage in information operations, then your adversaries will be aware of this and fly under that radar and come just short of performing those provocations. [08:50.270 --> 08:52.050] Okay, some general background issues. [08:52.330 --> 08:55.350] The first is dual-use technologies do come into play here. [08:55.810 --> 09:00.570] It's generally cheaper, if done properly, it's cheaper to encrypt data than to crack data. [09:01.290 --> 09:07.270] This gives an advantage to lesser-funded organizations in regards to cryptography, if done properly. [09:07.790 --> 09:09.710] There's the asymmetric warfare threat. [09:10.830 --> 09:19.910] If two major governments or organizations wish to make agreements, not to attack each other using certain technological methods, they may do those. [09:20.010 --> 09:22.090] There's some history of doing that in their protocols in place. [09:22.270 --> 09:26.770] How do you make such agreements with rogue or individuals or cells or smaller groups? [09:26.930 --> 09:28.270] And it may not be practical. [09:29.250 --> 09:50.670] Also, we have the Dr. Strangelove scenario and the question of whether information operation tactics, strategies, and methods may grow in the dangers they present, and whether at some point cyber warfare disarmament or at least arms reduction or control treaties may become a serious concern or issue to be addressed. [09:51.450 --> 10:03.230] The issues for this section that we see as perhaps being something to consider and discuss include whether anyone would be so scared of retaliation that computer-based information attacks won't work. [10:03.230 --> 10:07.050] Really, is virtual deterrence, deterrence, true deterrence. [10:07.630 --> 10:11.370] Also, what about attacks intended to subtly damage the integrity of key systems? [10:11.910 --> 10:16.530] Here, a premise might be that the origin of a successful attack, the attacker, might never be discovered. [10:16.770 --> 10:21.610] If you feel that you can wage an attack and not be discovered, what's going to keep you from doing this? [10:21.610 --> 10:24.610] And to what extent can networks truly be protected? [10:25.310 --> 10:32.010] And to what extent is it worth trying to protect networks if you're not basing them on the most rigorous methods of development actually possible? [10:32.450 --> 10:35.710] And that most critical infrastructure is not controlled by the government. [10:35.950 --> 10:46.150] According to Howard Schmidt, with TCP/IP, perhaps 85% of infrastructure, critical infrastructure, is not belonging to the government or under their direct control. [10:48.310 --> 10:50.830] We're moving now to the section on real offense. [10:53.150 --> 10:53.690] Klausewitz. [10:54.010 --> 10:57.830] Klausewitz was a Prussian soldier who fought against Napoleon's army. [10:58.090 --> 11:04.170] He had extensive combat experience and he already fought for the first time at the age of 13. [11:04.170 --> 11:18.210] This led to him writing an important book on strategy called Vom Kriege on War, which is a classic masterpiece of Western strategic thought, which looks at the human on human strategic problems and hence it's very timeless. [11:18.930 --> 11:26.750] One of the aspects Klausewitz mentioned was the center of gravity, the focal point of a country's power during war at a strategic level. [11:26.750 --> 11:32.170] This needed to be defined because to have the correct military objectives. [11:32.570 --> 11:38.930] Nowadays, if we look at virtual and real center of gravity, we have like more targets, more possible targets. [11:39.050 --> 11:47.310] And we have to ask ourselves what we're going to target at, whether it be the military, whether it be the economic system, whether it be the political system and so on. [11:49.730 --> 11:57.330] Also, I'll note that the notion and concept of virtual center of gravity works in that when you have a virtual center of gravity, you actually have a real center of gravity. [11:57.490 --> 12:02.150] It's tangible, and if it's destroyed, it promotes the collapse of your adversary's force. [12:03.690 --> 12:07.330] There's a notion called an OODA loop that comes into strategic play. [12:07.770 --> 12:09.070] It's based on the notions. [12:09.250 --> 12:12.410] It's an acronym to observe, orient, decide, and act. [12:12.410 --> 12:17.170] But in conflict, what it does is it creates a certain situation. [12:17.690 --> 12:31.570] Basically, by performing these steps, the concept is that you can act and act with determination fast enough and efficiently enough to get inside or within the constraints of your adversary's decision cycle. [12:31.950 --> 12:36.870] You act and operate efficiently and accurately, more efficiently than they can respond. [12:37.110 --> 12:40.210] If you do this and can maintain it, it creates what's referred to as a tempo. [12:41.010 --> 12:44.270] And if the enemy cannot resist this tempo, it will be destroyed. [12:45.150 --> 12:48.950] You act and you're unable to act responsibly. [12:49.790 --> 12:53.630] Computer network operations are a subset of information operations. [12:53.970 --> 12:55.450] You've got three parts of it. [12:55.650 --> 13:00.250] One being computer network exploitations, where one looks at vulnerability and exploits. [13:00.450 --> 13:02.610] And this enables you to do two things. [13:02.790 --> 13:11.970] One being computer network attacks, where you attack an enemy's computer system and try to interrupt his information flow, corrupt his data, and so on. [13:12.150 --> 13:19.970] Whilst at the same time, you will be conducting computer network defense, where you try to defend your own networks from enemy attacks. [13:23.510 --> 13:28.430] Air strategy, air supremacy versus information supremacy. [13:28.890 --> 13:30.590] Both are actually quite equal. [13:30.910 --> 13:35.530] Because what we see nowadays, there's always a gap between technology and doctrine. [13:36.010 --> 13:39.110] In other words, doctrine tries to catch up with technology. [13:39.110 --> 13:41.370] For example, looking at air strategy. [13:41.710 --> 13:44.810] During the First World War, planes were slowly used. [13:44.910 --> 13:49.170] But people didn't really know how to use them efficiently, in a military way. [13:49.850 --> 13:55.670] And then we had strategies like Duet, Trenchard, who started developing air doctrine and so on. [13:55.830 --> 13:59.030] Which led to the strategic bombing campaign in the Second World War. [13:59.030 --> 14:02.550] But then, afterwards, we sent a man to the moon. [14:02.790 --> 14:06.090] But it took us longer than that to achieve air supremacy. [14:06.350 --> 14:10.550] A concept developed by Warden, which was successfully used during the Gulf War. [14:10.850 --> 14:16.730] So in other words, it will take time to develop an IO doctrine, as we are still at the early beginning. [14:19.190 --> 14:39.110] Special information operation is defined as special information operations are information operations that, by their sensitive nature and due to the potential effects or impact, security requirements or risk to the national security of the U.S., require a special review and approval process. [14:39.430 --> 14:42.450] They can be converted and perhaps dirty sometimes. [14:42.770 --> 14:48.630] And what's going to distinguish these SIOs from other operations, I believe it's going to be their gravity. [14:50.910 --> 14:57.990] We're not looking at, in terms of conducting a financial SIO, at moving from one politician's bank account to another $10 or $20. [14:58.510 --> 15:00.850] We're not talking about setting up small slush funds. [15:01.010 --> 15:10.330] We're talking about actions made, for example, through computer or other methods at destabilizing the financial structure of, say, a government or a country or its industrial base. [15:10.830 --> 15:18.730] In terms of a military example of what might be an SIO, and, again, if you ask what is an SIO, I don't think it's going to be publicized. [15:18.870 --> 15:29.930] So there are some speculations involved, but something that would seem reasonable would be an example of infiltrating an adversary's military command and control networks, so that when the commands are issued, they don't destroy their adversary's forces, [15:30.210 --> 15:32.550] they inflict friendly fire casualties on their own troops. [15:32.550 --> 15:37.250] Now, we'll discuss later some of the consequences of someone attempting to use an SIO. [15:37.490 --> 15:40.050] These can be very risky and do come with some uncertainty. [15:40.970 --> 15:44.150] These deal with things that could affect matters of stability of states. [15:47.110 --> 15:59.330] Regarding the nature of targeting and precision, it's very important to governments, especially as we're fighting in more and more modern eras, to try to minimize and reduce collateral damage. [15:59.710 --> 16:05.190] And you really have to identify and respect the issue of who are and what are combatants versus non-combatants. [16:05.770 --> 16:10.630] Towards this end, they're actually very large and complex infrastructures for intelligence gathering and targeting. [16:12.290 --> 16:15.430] And these are done for, I'd say, two key reasons. [16:15.570 --> 16:27.190] Besides the one that there's no intention to harm people who are not threats, there's another issue in that the indiscriminate use of your own munitions impedes your ability to conduct more. [16:29.610 --> 16:30.430] Pandora's Box. [16:30.810 --> 16:40.690] A few days ago, I attended a presentation by someone from a military force, and he said, Well, information operations are really great because they're cheap. [16:41.310 --> 16:46.390] Instead of investing into missiles when we fire them once, we have to buy new ones. [16:46.570 --> 16:51.230] But with information operations, we can just use them over and over again, and it's really cheap. [16:51.410 --> 16:56.190] But that's not true, as we face two problems when Ion is let out of the box. [16:56.470 --> 17:01.970] First of all, we lose the element of surprise as the enemy is able to analyze our attack. [17:01.970 --> 17:08.390] Furthermore, he might even be able to make more advanced attack based on our attack onto our system. [17:08.650 --> 17:12.190] In addition to that, we lose the element of counterintelligence. [17:12.370 --> 17:18.190] The second point, which was mentioned already in a just war theory, is how do we limit I.O. [17:18.370 --> 17:19.350] Because I.O. might not be able to distinguish between combatants and non-combatants. [17:23.510 --> 17:27.950] And nowadays, we do not want to have civilian casualties at all, if possible. [17:27.950 --> 17:30.370] Okay, there's a fundamental notion in the U.N. [17:30.370 --> 17:31.710] Charter that war is unlawful. [17:32.930 --> 17:35.710] And there is an intrinsic reluctance to declare war. [17:36.170 --> 17:41.170] Now, an interesting thought is that if a nation has an I.O. [17:41.170 --> 17:51.070] Supreme or a significant capability, it may not wish to use it very lightly, especially not towards promoting conflict. [17:51.070 --> 18:00.710] Because there's potential, besides bad press, that you can have what happened between, let's say, NATO and Warsaw Pact nations politically, regarding political alliances. [18:01.010 --> 18:04.790] That if you form or establish an I.O. [18:04.790 --> 18:08.430] base of power, or you and certain allies do, I.O. [18:08.510 --> 18:13.190] coalitions could develop as a force to counter the virtual deterrence threat you created. [18:13.190 --> 18:21.410] In other words, one organization might not take you on, but a collection of them very well might be willing to using similar methods. [18:24.150 --> 18:36.590] A product of the Joint Chiefs of Staff is something called Joint Vision 2020, which deals with how the future of combat is being perceived and developed, and how to fight for the future. [18:37.170 --> 18:42.990] And a lot of people will criticize various militaries as always using the mindsets and philosophies of the last war. [18:44.070 --> 18:47.650] And this is a great example of how that's not always accurate. [18:48.850 --> 18:54.790] One notion, and this is a very key notion, is that information superiority by itself may not have any meaning or relevance. [18:54.910 --> 18:56.310] You need to link that to innovation. [18:56.630 --> 19:01.750] If you don't need to move forward and innovate as necessary, you will lose your advantages. [19:02.230 --> 19:09.050] Now, if you take focused logistics, the ability to put all your forces, troops, and knowledge where it needs to be. [19:09.630 --> 19:11.190] Combine that with precision engagements. [19:11.370 --> 19:12.350] You don't target cities. [19:12.490 --> 19:17.450] You don't target large complexes in order to destroy one single building. [19:17.610 --> 19:20.630] You deliver the steel you need on target where it's needed. [19:20.990 --> 19:29.290] Combine that with a full-dimensional protection capability, the ability to protect your soldiers, your forces, your information, and all their spaces in which they appear. [19:29.290 --> 19:37.570] And if you can commit dominant maneuvers, you can operate in manners that your enemy cannot, or adversary cannot resist, control, or mitigate. [19:37.950 --> 19:40.650] You achieve something referred to as a full-spectrum dominance. [19:41.430 --> 19:43.170] It's an overwhelming advantage. [19:43.170 --> 19:50.310] And the notion is, if you achieve this, you can be persuasive in peace, decisive in war, and preeminent in any form of conflict. [19:50.490 --> 19:53.890] And it makes it less appetizing for people to engage you in conflict. [19:55.310 --> 20:04.210] Some issues we see of interesting moments in this section are whether information supremacy is a smaller component of a grander vision of perhaps electronics warfare. [20:04.650 --> 20:10.390] And the question is really, can information supremacy be achieved without bombs, electronics warfare, and air assaults? [20:12.510 --> 20:12.990] Okay. [20:13.430 --> 20:15.930] And now we're going to introduce some of our conclusions. [20:15.930 --> 20:17.290] We have a few of them, actually. [20:21.270 --> 20:21.510] Okay. [20:22.660 --> 20:29.920] Nation states, even if they don't want to wage offensive I.O., they will have to consider it and look at it, because the enemy will do it. [20:30.060 --> 20:32.560] And you need to know what the enemy is going to do. [20:33.200 --> 20:37.210] Also, any government which would not look at it would not be very wise. [20:37.210 --> 20:42.660] In addition to that, we have to look, doctrine at the moment is not fully understood nor realized. [20:43.060 --> 20:47.620] Like we looked, like before, looking at the air campaign strategy and so on. [20:47.770 --> 20:52.660] We have to look at the history of air doctrine and develop a doctrine for information operations. [20:53.140 --> 20:56.010] We also have an online message center for this subject. [20:56.360 --> 20:57.230] The URL is there. [20:57.580 --> 20:58.990] We'll set up a mailing list. [20:58.990 --> 21:01.640] If anyone is interested in, like, discussing, feel free. [21:01.990 --> 21:07.440] And at the bottom you see, any form of warfare must be underpinned by a real understanding of the enemy. [21:07.680 --> 21:16.710] Which brings us back to, even if you don't want to wage offensive I.O., you will have to look at it just in order to protect your nation state. [21:16.990 --> 21:17.420] Next slide. [21:18.820 --> 21:19.770] Reality check. [21:20.440 --> 21:25.680] Lots of people or scaremongers say, Cybergeddon looms around the corner. [21:25.900 --> 21:27.340] But this is not really true. [21:27.340 --> 21:31.160] Physical attacks are still more powerful than any cyber attacks. [21:32.840 --> 21:37.700] So we're going to address what we can do to at least make this balance not change. [21:37.860 --> 21:49.160] We do not see necessarily a destabilization caused by information operation attacks against, let's say, government friendly or ourselves to be desirable. [21:49.400 --> 21:52.920] What can we do to make systems safer is another way of looking at this. [21:52.920 --> 21:59.380] One thing is to separate life critical, mission critical, and infrastructural critical components from less critical systems. [21:59.600 --> 22:08.580] We do not want an internet capable soda machine linked to a military command control or intelligence sharing system, for example. [22:11.020 --> 22:15.620] In regard to software development and ethics, it's very important to build systems well and carefully. [22:16.100 --> 22:20.000] As a quote that I've been presented with is, with great powers and great responsibilities. [22:22.000 --> 22:26.220] I've published a few papers and presented some papers regarding two different subjects. [22:26.220 --> 22:32.240] One is how to improve the security and securely build defense weapons platforms. [22:32.580 --> 22:37.700] And there are a number of steps and measures that are taken early on that can help make them relatively secure. [22:38.680 --> 22:42.320] But if you don't try very hard, it's very easy to make systems that are not very secure. [22:42.320 --> 22:45.440] Also, the ethics component is very significant. [22:45.700 --> 22:54.500] People have to want to build machines and operating systems and platforms and communications grids that will be secure. [22:54.840 --> 23:00.040] They actually should appreciate and understand what the consequences would be if this is not the case. [23:00.040 --> 23:03.280] We feel that information assurance education is very critical. [23:03.500 --> 23:04.520] Not just the developers. [23:04.700 --> 23:12.260] The users have to have some understanding and be taught what the information security issues are and what are and are not real threats. [23:13.080 --> 23:21.460] And I'm going to return to the notion presented earlier regarding just war theory that you don't want to cause unnecessary harming conflicts. [23:21.460 --> 23:23.880] And that refers to militaries. [23:23.980 --> 23:31.500] And it also refers, I'd like to see it referred to, hostile groups who might just be upset about specific issues or causes. [23:33.400 --> 23:43.500] If they're going to seek out organizations to hurt them through information operation type attacks or mechanisms. [23:43.500 --> 23:45.720] Asi intervention warfare, theories, etc. applications. [23:49.180 --> 23:51.160] This is a nice little cartoon Vanya happened to like. [23:51.440 --> 23:56.480] But we're going to have more information on the subject and we're hoping to encourage discussion on the system. [23:56.760 --> 23:58.280] A quick remark to the slides. [23:58.600 --> 24:01.660] On the website currently, we only have an old version of it. [24:01.980 --> 24:04.760] The new version should be up on Monday if you want to download it. [24:04.880 --> 24:08.840] And just while the cartoon is up, I would like to make an invention that I was supposed to make earlier. [24:08.980 --> 24:10.880] I do want to mention that these are our theories. [24:10.880 --> 24:15.140] These are not backed or financed or linked to any organizations that we have or have not worked for. [24:15.320 --> 24:16.720] Nor are they influenced by them directly. [24:17.500 --> 24:19.000] Just, I had to get that in there somewhere. [24:19.180 --> 24:20.340] It's actually rather essential. [24:22.040 --> 24:23.760] And that's our basic presentation. [24:24.000 --> 24:25.000] And we would like to thank you. [24:25.140 --> 24:27.940] And we do intend to have some real discussion on this. [24:28.060 --> 24:28.880] I'd like to hear your thoughts. [24:32.220 --> 24:41.280] It means these are not official viewpoints of any of the government's, contractors organizations we've ever sat down and had lunch with, broken bread, and you don't... [24:42.060 --> 24:42.360] Oh. [24:43.240 --> 24:43.620] Sorry. [24:44.620 --> 24:46.540] We can be paranoid too sometimes. [24:48.740 --> 24:49.500] So I'm sorry. [24:49.640 --> 24:51.900] But I've actually had one or two issues come up. [24:52.000 --> 24:53.280] And I just have to... [24:55.620 --> 24:56.080] Okay. [24:56.640 --> 24:57.160] Um... [24:57.160 --> 24:57.640] Yes. [24:57.940 --> 24:58.000] Please. [24:58.400 --> 25:00.000] I'm from Pollywood University. [25:00.360 --> 25:00.880] Yeah. [25:01.160 --> 25:01.940] Actually, can we... [25:01.940 --> 25:03.580] Can we have a microphone over there? [25:03.760 --> 25:05.420] If you could talk to Mike, please. [25:05.740 --> 25:05.960] Thanks. [25:06.300 --> 25:08.160] I am from Pollywood University in Brooklyn. [25:08.300 --> 25:12.920] I teach in their NSA-approved information assurance thingy there. [25:13.900 --> 25:19.200] And we've been starting engagements on relations with the military academy and so on. [25:20.640 --> 25:21.880] We're working on it for war. [25:22.360 --> 25:23.340] And I'd like to ask you a question. [25:23.840 --> 25:28.100] Is low-intensity information warfare between China and Taiwan existing right now? [25:28.440 --> 25:33.020] Are those two factories, for all intents purposes, that information war or cyber war? [25:33.180 --> 25:34.060] Can you address this one? [25:34.550 --> 25:36.700] Well, first of all, I wouldn't... [25:36.700 --> 25:40.500] Well, there's a difference between the term information warfare and information operations. [25:41.180 --> 25:44.100] Information warfare is like more computer warfare. [25:44.340 --> 25:47.060] But for me, personally, I think that's just scaremongering. [25:47.060 --> 25:51.940] You have, like, some script kiddies or whatever, some teenagers playing around and poking around. [25:52.100 --> 25:54.740] But I don't consider it to be an information war. [25:56.600 --> 25:57.980] There's probably one thing. [26:00.180 --> 26:05.600] The People's Liberation Army has a battalion for cyber warfare. [26:05.640 --> 26:10.540] And the Taiwanese have about a thousand men in their army for hacking. [26:11.220 --> 26:13.220] Certainly, they have their developing capabilities. [26:13.880 --> 26:14.900] The Chinese are well-known. [26:14.900 --> 26:17.060] They have, like, lots of strategists and everything. [26:17.320 --> 26:21.700] But the thing we read in the media about is mostly teenagers having fun. [26:22.720 --> 26:24.820] Maybe... that's a maybe, I don't know. [26:25.200 --> 26:33.120] Maybe the Chinese or Taiwanese using those teenage pranks to conduct reconnaissance or whatever. [26:33.540 --> 26:35.520] But that's just an assumption I don't have. [26:35.520 --> 26:40.600] I'd also expect more governments to come up with funding to start investigations. [26:41.520 --> 26:45.100] I mean, for no other reason, you're going to have what you had in the 60s of Project Blue Book. [26:45.200 --> 26:50.220] You know, as soon as one government starts looking into UFOs or any other unusual subject, others are going to have to do the same. [26:50.440 --> 26:55.920] But I see, really, that more governments, especially with the perceived bang for the buck, are going to have to start to look into this. [26:55.920 --> 26:58.040] So I expect it to expand quite a bit. [27:01.070 --> 27:02.450] I've got two questions. [27:02.690 --> 27:18.390] The first one is, could you comment on the role of, let's say, information warfare against your own people in your own country to actually justify the war in terms of making it such that certain victims are not innocent victims but are actually guilty. [27:19.090 --> 27:32.770] And then also to comment on the role of the, let's say, the paranoia about commenting about things and stopping people from publishing things because they may encourage other people to act. [27:33.090 --> 27:42.190] One of the great fears that I have is ever getting onto an aeroplane and seeing something suspicious and even commenting because you hear so much about people being thrown out of aeroplanes for commenting on things. [27:42.890 --> 27:44.810] And therefore, what if you do see something? [27:44.970 --> 27:45.890] Do you comment or not? [27:51.370 --> 27:57.190] Well, regarding information, warfare and... [28:12.190 --> 28:14.190] Do you want to say something? [28:15.730 --> 28:17.070] Veteran from Hull, I think. [28:19.150 --> 28:28.650] An interesting thing that I've been thinking about for a while is, you were talking about asymmetric conflicts and how you were going to come back to that, which is very interesting to me. [28:28.650 --> 28:39.890] And that is, if you look at NATO, if you look at the U.S. and the type of military might that is displayed, that is available, that forces asymmetric warfare. [28:40.150 --> 28:45.490] There is no adversary that has that type of defense spending that advance a defense industry. [28:45.690 --> 28:52.730] So you're basically forcing an adversary to perform terror attacks to make any kind of impression. [28:55.130 --> 29:03.050] So, I'd like your thoughts on that and what that means in terms of information warfare, what that means in terms of conflict in the future. [29:03.050 --> 29:16.010] Well, one thing, Vine may know the name, I believe it was a Chinese colonel who wrote a book discussing some of this, but the Chinese have basically said, on different levels, and other people acknowledge that, if you're going to do a fight with the nation, [29:16.130 --> 29:19.250] let's say for the United States, you'd be crazy to go head on. [29:20.210 --> 29:24.090] That's not how you win, that's not how you build your government to be strong. [29:27.450 --> 29:32.750] Organizations that will... large governments are not interested in attacking each other directly in a number of cases. [29:33.030 --> 29:35.030] They're not always interested in doing that, actually. [29:37.030 --> 29:43.110] Now, smaller organizations may see asymmetric warfare as a means where you leverage what strength you have. [29:43.270 --> 29:49.970] If you can find a technological strength which will undermine another nation's large defensive capability, that's what you go with. [29:50.190 --> 29:55.110] And asymmetric warfare, I think, directly addresses that, almost in its definition. [29:55.330 --> 29:59.310] That this is how a small force can hope to overcome a larger, more powerful one. [29:59.730 --> 30:01.570] It's quote-unquote less powerful. [30:03.610 --> 30:14.650] I did a paper on the nature of information of computers in warfare, and I kind of broke up groups into two types, the fat cats and the underdogs. [30:15.190 --> 30:21.850] And the underdogs are going to use cryptography if they can have their advantage, whatever means are to their advantage, and the fat cats have to play defense a bit more. [30:30.160 --> 30:34.140] From a theoretical point of view, but from the point of view of... [30:34.140 --> 30:43.040] I'm thinking more of attacks on civilians rather than purely military targets. [30:43.040 --> 30:51.820] Are there any concrete examples of this sort of information warfare that you can cite that have been used? [30:52.000 --> 30:55.080] Other than like script kiddies in China, hacking out... [30:55.080 --> 30:55.560] Well, an air strategy... [30:55.560 --> 30:56.960] Is it an Australian... [30:56.960 --> 30:58.360] It would be an air strategy? [30:58.880 --> 30:59.240] Well... [30:59.240 --> 31:02.140] I'm thinking, for example, I'm thinking of an Australian thing within the... [31:02.140 --> 31:04.260] There's only a couple of million gallons... [31:04.260 --> 31:05.600] Yeah, but it's nothing, and it has no impact. [31:05.660 --> 31:07.280] If it would be bigger, it could be something. [31:07.280 --> 31:14.880] The thing is, as I said, like looking at air strategy before, in the early time, we don't really have a doctrine to develop the weapons. [31:15.080 --> 31:17.540] And I'll give you an information security example. [31:17.840 --> 31:24.640] If you have firewalls, IDSS and so on, but you have no information security policy, you can't do anything with it. [31:24.700 --> 31:26.420] It's useless in a way. [31:26.420 --> 31:28.220] And first of all, we need to... [31:28.220 --> 31:30.880] The militaries need to develop a doctrine. [31:32.280 --> 31:32.800] And... [31:32.800 --> 31:33.400] Do you want to add something? [31:34.980 --> 31:39.020] Well, what we're saying really is not that there's been a lot that's been tangible and done immediately. [31:39.320 --> 31:55.400] We used the analogy really amongst ourselves that at the dawn of heavier than air flight, the notion of air combat was taking a biplane up and throwing a grenade out the side, you know, just throwing one overboard. [31:56.820 --> 32:04.180] And it's taken a good many decades to advance from there to the concept of air supremacy. [32:04.940 --> 32:10.500] We're not saying that information operations are futile or worthless, nor are we saying that they're going to cause the fall of mankind. [32:10.520 --> 32:23.700] What we are saying is that it may take a matter of time or decades and enormous amounts of money for this to realize its potential or for anyone to understand how to really use it effectively, either from a small organizational perspective or by government. [32:24.440 --> 32:32.420] I guess my question is, can you think of any real examples of when it's actually been used that you can cite? [32:32.600 --> 32:34.740] I mean, other than from a theoretical point of view? [32:37.780 --> 32:45.180] I can't really, to be honest, because anything I read in the media or so, I don't consider the information operations, to be honest. [32:45.180 --> 32:48.100] But that's my view, my view of point. [32:48.300 --> 32:49.060] I mean... [32:52.060 --> 32:52.620] Strategy. [32:52.620 --> 32:53.940] It's strategic discussion. [32:55.940 --> 32:56.500] Yes? [33:09.900 --> 33:22.380] One thing I feel like I've been hearing in the wake of September 11th and I've sort of been hearing beforehand is that maybe strategy based on models of nation states is, if not obsolete, heading into obsolescence. [33:22.380 --> 33:33.000] And I'm wondering if you can comment on how what you've said so far and the topics you're talking about address this, the fact of the matter that nation states are not necessarily the primary bodies in any given conflict nowadays. [33:33.000 --> 33:50.580] Well, he got the theory of, what's his name, von Krefeld on future war or something, who said that in the future nation states will disappear and small armed groups, what entities there be, will engage in conflict using high-tech weapons, using low-tech weapons. [33:51.300 --> 33:52.560] Yeah, I'll agree with that. [33:52.800 --> 33:55.480] Actually, I may refer back to an earlier slide. [34:12.190 --> 34:18.450] We don't, we don't see really that you're going to consider or accept that your adversary has to be government. [34:18.590 --> 34:28.610] The whole point of the problem from asymmetric warfare is that powers or organizations, as I said, even renegade groups or cells or individuals could become a potential threat. [34:28.610 --> 34:31.490] And that's what makes this very difficult to deal with. [34:31.630 --> 34:33.730] There's not necessarily anyone to negotiate with. [34:34.650 --> 34:37.610] Potential threat to nation states or potential threat to... [34:43.470 --> 34:46.650] Major nations present, it's pretty hard to destabilize. [34:47.430 --> 34:53.590] The less technologically advanced nation is in general, the harder it is to, I think, leverage effective information operations against them. [34:54.190 --> 34:57.870] The bigger governments, the sound roads are pretty hard to destabilize. [34:58.190 --> 35:03.410] But I believe that with information operations being so young, there's time for them to mature. [35:03.870 --> 35:17.610] And depending on where technology goes, what systems are linked to each other, and how a doctrine develops, not just by government, but by these organizations who choose to attack governments, I think that there might be some real consequences. [35:17.610 --> 35:21.530] But it has to really be watched to determine where this is going to run. [35:22.010 --> 35:24.330] But it's not going to be this week or next week. [35:25.270 --> 35:27.670] But this could take years or decades. [35:31.200 --> 35:32.040] Good afternoon. [35:32.220 --> 35:45.040] Do you see as we develop an IO doctrine that, in effect, we're actually making ourselves more susceptible to IO attack because we're more reliant on certain backbones that make other systems work? [35:45.040 --> 35:51.860] The thing is, we nowadays live in the information economy, so we get more and more reliable on information. [35:52.400 --> 35:52.680] Reliant? [35:53.540 --> 35:55.200] Reliant on information. [35:55.520 --> 35:59.340] And some people even talk about the information has and the information have not. [35:59.880 --> 36:04.460] So, even if we don't develop it, we're still reliant on it. [36:04.780 --> 36:11.460] I think that a lot of the communications linkages that are in place might be a little haphazard. [36:11.460 --> 36:17.400] Not every network or even high capability trunks. [36:17.940 --> 36:21.200] Certain people could be doing things a little more precisely. [36:21.560 --> 36:23.700] Not every networking facility is perfect. [36:24.320 --> 36:29.180] And there are opportunities that small things that go wrong could have big consequences. [36:29.860 --> 36:32.900] And if someone can identify what those things are, they can cause some real harm. [36:33.140 --> 36:35.240] So, I'd say that there's a potential for truth in what you're saying. [36:35.240 --> 36:35.520] Yes. [36:36.760 --> 36:38.620] But, you know, again, I'm not saying it's going to happen today or tomorrow. [36:38.800 --> 36:39.260] But, yes. [36:39.560 --> 36:45.940] The more you rely on information, the more it spreads, the more you depend on having it immediately, that can also become a liability. [36:47.260 --> 36:47.860] Hi. [36:48.760 --> 37:00.540] In addition to relying on computers and information more, I'm concerned that we're relying on poorly planned defenses more. [37:00.920 --> 37:12.100] As Lucas Ganci said earlier in the earlier panel, being able to encrypt the stuff meant that the criminal put more stuff on his computer because he felt more secure about it. [37:12.100 --> 37:22.980] And I think that we're picking the wrong public policies and trying to... thinking that our defenses are good and therefore we can rely on them. [37:23.180 --> 37:34.280] Or trying to prevent the public from having access to computers and trying to restrict access, trying to restrict devices and so on. [37:34.720 --> 37:40.200] That this is going to give us security because they're predicting where the attacks are going to come from. [37:40.200 --> 37:41.220] Yeah. [37:42.100 --> 37:49.360] Could you comment on how we can change their opinion and what their opinion... or even just characterize their opinion in more detail? [37:49.600 --> 37:49.820] Sure. [37:50.080 --> 37:58.520] Well, actually, a lot of people in government would love to have well-qualified, well-trained, highly-expert mathematicians and computer scientists available to them. [37:58.560 --> 38:04.800] A lot of people would love to see a very technologically advanced public, which would also appreciate information and security issues and solutions. [38:05.440 --> 38:09.860] Not necessarily a public that would be seen as hostile, but one that would say we have certain interests. [38:10.180 --> 38:16.820] And by understanding the math, the computer security, the networking theory, or just being generally security aware, we can contribute to this. [38:18.320 --> 38:24.620] In the circles I'm in, you know, more people know about computer security and what to do in terms of good practice, the better. [38:27.560 --> 38:38.060] I'd say certain other nations are much more concerned about having the haves and have-nots in terms of information because it's to their own interest to try to restrict the flow of information. [38:38.060 --> 38:40.100] I don't personally believe this is such a country. [38:42.800 --> 38:44.300] Was there another business question? [38:45.300 --> 38:46.400] I think it was just a... [38:46.400 --> 38:49.340] General encryption, encryption controls. [38:49.840 --> 38:51.320] Yeah, encryption controls. [38:51.440 --> 38:54.520] Encryption is a tool, if you misuse it, it can backfire on you. [38:54.660 --> 38:58.260] There are people who have encrypted documents and, you know, it's done virtually nothing. [38:59.020 --> 39:01.020] There are people who have relied on Microsoft Word encryption. [39:01.880 --> 39:09.580] I was, for fun, I called Microsoft and asked how hard it was to get around the security of someone encrypted documents with Microsoft Word. [39:09.800 --> 39:11.880] What would it take to open it without the password? [39:11.980 --> 39:12.700] They said it couldn't be done. [39:13.160 --> 39:22.660] You know, that's not the level of expertise you want even in technology circles when you have a question to which you know what is or is not involved in penetrating their data. [39:23.920 --> 39:25.420] I don't know if I... Did that help? [39:26.620 --> 39:27.040] No. [39:27.580 --> 39:27.800] Sorry. [39:28.700 --> 39:29.600] I'll give it another shot. [39:29.840 --> 39:34.320] Obviously, your thought isn't along the same lines as mine, so there's no point in my... [39:34.320 --> 39:38.260] You know, if it were, I would have brought out the response, that's all. [39:38.800 --> 39:40.640] I wonder if you want to go ahead and response anyway. [39:41.140 --> 39:41.640] You're welcome to. [39:42.080 --> 39:42.880] No, that's all right. [39:43.060 --> 39:43.180] Okay. [39:43.320 --> 39:44.060] Okay, thank you. [39:44.140 --> 39:44.440] Thank you. [39:45.560 --> 39:45.720] Yeah. [39:47.460 --> 39:48.480] Okay, let's wrap up there. [39:48.820 --> 39:49.580] Okay, one more. [39:49.780 --> 39:50.060] One more. [39:50.300 --> 39:50.980] Okay, last one. [39:50.980 --> 39:51.680] One more question for you. [39:52.340 --> 40:09.160] Back in the Gulf War, there was a rumor that floated around about the, that the, the Iraqis had purchased a printer, had purchased a hardware from the U.S., computer hardware from the U.S., and that computer hardware was compromised by back doors that were, [40:09.280 --> 40:17.170] you know, that were already known by the hardware manufacturers, computer companies that already, and they inserted words to stabilize the infrastructure. [40:17.650 --> 40:18.870] Just wanted your thoughts on that. [40:18.990 --> 40:19.110] Okay. [40:19.210 --> 40:19.730] You hear my thing? [40:20.010 --> 40:20.850] Yeah, sure, sure. [40:21.510 --> 40:21.870] Okay. [40:22.250 --> 40:25.510] Now, even if I didn't know about a specific operation, I couldn't discuss that in detail. [40:25.710 --> 40:26.690] Here's what I can say. [40:26.850 --> 40:38.010] I think the best, probably the best paper ever written on computer security was Ken Thompson's paper on trusting trust, which says, basically, in short, that you can't trust any system not written by yourself. [40:38.470 --> 40:40.170] Now, there are means to mitigate that. [40:41.750 --> 40:45.670] And I'll say, conversely, I wouldn't be surprised if some number of software products in the U.S. [40:45.730 --> 40:47.150] have been intentionally subverted by people who've developed it. [40:47.550 --> 40:48.790] It can go both ways. [40:49.210 --> 40:49.570] It can go both ways. [40:49.570 --> 41:00.510] But if you know that there's control over code in development, you monitor it, you watch it, and you can do a lot to mitigate your security threats. [41:00.610 --> 41:04.070] But if you're taking untrusted code, you really don't know all the implications, and you can't. [41:04.770 --> 41:07.610] Actually, Ken Thompson takes this notion further, but I won't get into the intricacies. [41:07.790 --> 41:10.990] But I think it's a wonderful paper regarding what you can or cannot trust in software. [41:12.110 --> 41:14.010] And I think we'll call that our presentation. [41:14.010 --> 41:16.270] And we thank you very much for having to entertain us. [41:16.750 --> 41:17.210] Thank you. [41:17.430 --> 41:17.790] Thank you. [41:17.790 --> 41:18.150] Thank you.