3

 

 

 

Written submission by Dr Tara McCormack, Lecturer in International Politics, University of Leicester, for the Joint Select Committee on National Security Strategy inquiry into Cyber Security.

 

Summary

 

It is no longer science fiction but science fact that states can cause the critical infrastructure of another state to stop functioning, with all the attendant catastrophic consequences which this would entail, through computer viruses or ‘malware’. We can without hyperbole term these capabilities equivalent to weapons.

 

As a consequence of these developments, NATO (and other states) have designated cyber space as a military operational domain.

 

• British cyber security/defence remains within the remit of the secret services and the opening of the new National Cyber Security Centre within GCHQ suggests that this is the long term plan of the British government.

 

• Cyber security/defence capabilities, which can be understood as equivalent to weapons, should be brought out of the covert realm and into the public realm of democratic debate and ultimately democratic authorisation under the new Parliamentary Convention on authorising war.

 

1. Introduction - What is at stake in the cyber security debate?

 

1.1 Cyber security is a new field of study and of policy.  Capacities have developed extremely rapidly over the last ten years or so. Using digital technologies such as ‘malware’ or computer viruses or computer worms we now have the capacity to inflict damage that is equivalent to a military attack on another state. Other states have the capacity to do the same to us. We can without hyperbole understand these digital tools as cyber weapons.  Public understanding and knowledge lags woefully behind. This is not entirely accidental however, as cyber security remains under the control of the secret services in Britain, America, Russia, Israel and other countries.

 

1.2 This new and developing capacity of cyber weapons is reflected in a recent decision by NATO, and other states, to classify cyber space as a military operational domain. This means that NATO, for example, will potentially treat cyber attacks as equivalent to a conventional attack.

 

1.3 Given recent developments in cyber security and defence capacities and policies, there is no logical rationale for not bringing cyber security/defence into the public realm anymore than there would be for keeping chemical and nuclear capacities out of the realm of public debate and controlCyber security and defence needs to be come in from the cold of the covert realm and into the democratic realm.

 

2. Cyber security: from monitoring radio signals to taking control of the radio network

 

2.1 One of the problems with any discussion of cyber security is that the term is very lose and covers a wide range of things from on-line crime, industrial espionage, hacking, espionage, cyber sabotage and what can be termed cyber weapons. This written evidence is concerned principally with what may be termed cyber weapons, digital viruses or worms that have the capacity to create such devastation and chaos in a target state that they are equivalent to conventional weaponry. An important part of this debate is also the question about where to draw the between cyber sabotage/espionage and cyber-weaponry.

 

2.2 The initial debate about cyber attacks used in conflict situations was a question of whether cyber attacks should be considered acts of sabotage or more akin to acts of war. For example, in the 2008 Georgia/Russia conflict both sides engaged in acts that can be called cyber sabotage; denial of service attacks, hacking into news sites and government websites on both sides and so on. When we discuss acts of sabotage or denial of service attacks there is a reasonable debate to be had about whether such acts should be considered acts of war.

 

2.3 This however is a debate that is less relevant every day. Whilst espionage and sabotage are certainly used by many governments including our own, there is a very significant development in what can be called cyber weaponry. We know for a fact that America and Israel have developed cyber viruses/worms of such power and complexity that a targeted state may be in effect shut down. For example the electricity may be shut off and other critical infrastructure disrupted so that the state can no longer function. To give a hypothetical example (based on a real scenario that we will consider below) if Iran’s critical infrastructure were to be shut down in this way, including electricity, gas, sewage, water, communications, the immediate chaos and humanitarian consequences would be similar to those resulting from military strikes.

 

2.4 It is certain that Britain, Russia, China, Iran and some other European nations also now have similar capabilities. This takes us into a new realm of potential warfare, a far cry from disrupting news channels or hacking into accounts. Peter W Singer the American academic who writes on new technologies and war has a very evocative phrase to explain why cyber weapons take us into a new era, “It’s the difference between reading the enemy’s radio signals and being able to seize control of the radio itself”[1].

 

3. Operation Olympic Games/Stuxnet

 

3.1 We have an example of ‘seizing control of the radio’ in reality; the Stuxnet worm or Operation Olympic Games. Much of what is known has been set out in director Alex Gibney’s documentary film on Stuxnet featuring interviews with those involved such as former director of the CIA Michael Hayden and former Israeli Defence Forces high ranking personnel.  In 2010 cyber security companies noticed a computer virus unlike anything discovered before, infecting computers globally. For months it was unclear at what or where the virus was aimed at. It was aimed, as gradually leaked out, at disrupting Iranian nuclear facilities, in particular at the Natanz facility.

 

3.2 Several years after the virus was first noticed information has emerged about what was going on. America and Israel (with help from British secret services) devised a highly complex computer worm which damaged centrifuges in the Iranian nuclear facility of Natanz. This was a computer virus of such complexity that it had spread across the globe and took cyber security experts months to even begin to identify. It was part of a broader operation called Operation Nitro Zeus, authorised by President Obama, which would take control of and shut down Iran’s critical infrastructure in the event of the failure of the nuclear talks[2] . It is no longer science fiction but science fact that states now have the capacity to use digital technology to inflict damage equivalent to a conventional military attack on another state.

 

4. The problems of attribution, designation and proportionality

 

4.1 There are three serious and unresolved issues to do with cyber attacks; attribution, designation and proportionality. The first very serious issue is that of attribution. It took several years for the Stuxnet story to gradually leak out. At the time it was happening, no one knew where the virus had come from. By way of contrast, every aspect of NATO’s new deployment to Eastern Europe; Russia’s military exercises; Russian deployment of Iskander missiles to Kaliningrad is known and analysed at length. Every missile tested by North Korea is known. Nuclear weapons are heavily monitored, we know how many and what each official nuclear state has. We know this even of the non-official nuclear states, Israel, India and Pakistan. There are decades of treaties limiting numbers of weapons, testing and so on. States have established positions on questions of first use and so on. Unlike with standard military hardware from tanks to nuclear weapons, we simply do not know who has what and who is doing what to whom in cyber space. All that we do know for a fact is that several major states are engaging in cyber activities ranging from cyber espionage to cyber attacks.

 

4.2 What in any case is a legitimate proportionate reponse? Does Iran have the right to attack, for example, an Israeli military facility? Or an American ship? Certainly if British or American or Israeli nuclear facilities were being targeted in that way there would be a fair chance that we would consider it an act of war and respond with a conventional attack. Operation Nitro Zeus can in reason be described as (planned) major assault on a state.

 

4.3 The current hacking scandal in America also raises a key question of how do we designate such things, what is the line between a cyber weapon such as the Stuxnet virus and cyber espionage/hacking. What was the phishing operation against John Podesta and the leaking of the emails to Wikileaks? Was that an act of war? There are Democratic Senators who have called it so. What for example would be the appropriate response if it is proven that the Russian government had directed the phishing operation that John Podesta fell victim to? The balance of military forces, both conventional and nuclear, has taken decades of inter-governmental negotiations and treaties to establish limits and agreements on testing (for example), deployments and so on. We do not have any of that with cyber security.

 

4.4 There is a question of attribution even with the case of the alleged Russian government linked hackers phishing scam that targeted John Podesta’s gmail account, leading to emails being leaked to Wikileaks. It is easy to attribute blame and we have to have absolute confidence in the secret services, and the media, in particular in febrile highly politicised contexts. Intelligence services and media collusion over Saddam Hussein’s non-existent weapons of mass destruction suggests that caution should be the first principle here. Moreover, given that the FBI has been investigating this matter since three months before the American election but failed to offer any proof, we should be doubly cautious. An interesting case study occurred last December when the Vermont power grid appeared to be under some kind of cyber attack. There were immediate headlines in the Washington Post claiming Russian culpability. A day or two later articles appeared retracting this.[3] Given the most recent revelations about the CIA’s hacking and espionage capacities including that the CIA uses Russian malware, we are all well advised to be cautious before attributing blame.

 

4.5 The reason for asking these questions is not in order to play rhetorical or philosophical games but to illustrate that these are as yet crucial and unanswered questions that need to be addressed politically and publically. These are all issues that are discussed in any serious scholarly writing on the topic of cyber security, but are almost entirely absent from media and political discussions. These are profoundly serious questions that need to be discussed.

 

5. Cyber security as a military operational domain

 

5.1 A very significant shift in cyber security policy is occurring. Despite the key problems of attribution, designation and proportionality, states and international organisations are now designating cyber space as a military operational domain. NATO made this very underreported policy decision at the Warsaw summit in 2016[4]. This means that in principle cyber attacks may be treated as conventional attacks.

 

6. Declaring war: from the Royal Prerogative to the new Parliamentary Convention on authorising war

 

6.1 In Britain it is now Parliament that has the authority to take the state to war. Over the last decade British war powers (ie with what constitutional institution does the authority to take the state to war lie) have undergone a major constitutional shift. From the Prime Minister (part of the set of not fully defined) powers known as Royal Prerogative [RP] powers) to Parliament. The reason for this is that the power to take the country to war has been seen as particularly problematic for a number of reasons to do with a decline in trust in government and broader problems of legitimacy. The votes over military action in Syria demonstrated that the new Parliamentary Convention is now established [5].

 

7. Cyber security and warfare by remote control

 

7.1 Cyber weaponry is one of a range of new military weapons the use of which Paul Rogers has termed ‘security by remote control’, for example the use of drones, special forces and cyber security [6]. These methods are not subject to formal declarations of war but tend to be authorised and conducted out of the public eye. In Britain, these are not measures that are subject to the new Parliamentary Convention. These weapons are ‘remote control’ because they avoid ‘boots on the ground’.  They are methods that are therefore seen as cheap and easy, a form of military intervention that avoids the costs both at home and abroad – political, financial, moral and physical - of traditional forms of intervention [7].

 

7.2 However, the reality is that once a certain level of impact is reached, cyber weapons can no longer be considered a ‘cost-lite’ form of military intervention. Furthermore, cyber space is becoming a military operational domain, thus being treated as conventional military domain. Cyber weapons should be treated as conventional weaponry and subject to the new Parliamentary Convention on authorising war.

 

8. Conclusion; British cyber security and defence must be democratically debated, controlled and authorised

 

8.1 British cyber security and defence is within the remit of the secret services and this does not look set to change. The new National Cyber Security Centre is a part of GCHQ. However, there are a number of converging factors that mean that cyber security and defence must come into the public realm of debate, understanding and ultimately democratic control and authorisation.

 

8.2 Firstly, cyber security is no longer a question of espionage and sabotage. States now have the capacity to use cyber measures to inflict damage on another state that is equivalent to a conventional or nuclear attack. Yet the public in all ‘cyber armed’ states and also many politicians have little knowledge of cyber capacities nor of the profoundly serious problems around attribution, designation and proportionality. Secondly, cyber space is becoming a military operational domain. There is no rational for keeping cyber weapons within the remit of the secret services in fact it is a matter of some urgency that this area of security and defence is brought into the public realm. We may find ourselves in a war without any public debate or authorisation.

 

8.3 The counter argument will be made that these things need to remain secret for effectiveness. However, whilst that argument may be relevant when thinking about espionage and counter-espionage, it is an argument that is no longer relevant given the cyber capacity that we and other states have. We and other states have cyber weapons that can shut down a state. We are in different league from cracking the enigma codes. It is the case that all states with cyber capacities are keeping them hidden and with the covert realm. The only way this can begin to change is with individual states beginning to change their policy. This is not something that can happen over night. It has taken decades for nuclear weapons to be regulated. This is a critical time in the development of cyber security/defence policies one that is analogous to the early days of the Cold War and the development of nuclear weapons. Britain should take a lead in this developing area of security and defence and begin to establish democratic control over cyber security.

 

 

 

 

 


[1] Peter W Singer (2014), Cybersecurity and Cyberwar (Oxford: OUP), p 128.

[2] Zero Days (2016), documentary, Director Alex Gibney, USA.

David E Sanger and Mark Mazzetti (2016), US Had Cyberattack Plan if Iran Nuclear Dispute Led to Conflict, The New York Times, Feb 16th. https://www.nytimes.com/2016/02/17/world/middleeast/us-had-cyberattack-planned-if-iran-nuclear-negotiations-failed.html?_r=0

 

[3] Leetaru, Kalev (2017), Fake News and How the Washington Post Rewrote Its Story on Russian Hacking of the Power Grid, Forbes, https://www.forbes.com/sites/kalevleetaru/2017/01/01/fake-news-and-how-the-washington-post-rewrote-its-story-on-russian-hacking-of-the-power-grid/ - 42de784c7ad5

[4] Stoltenberg, Jens (2016), NATO press conference, 14 June, http://www.nato.int/cps/en/natohq/opinions_132349.htm?selectedLocale=en

[5] Strong, James (2015), Why Parliament Now Decides on War: Tracing the Growth of the Parliamentary Prerogative through Syria, Libya and Iraq, British Journal of Politics and International Relations, Vol. 17, No. 4, pp. 604–22.

[6] Rogers, Roger (2013), Security by “Remote Control: Can It Work?, The RUSI Journal, MAY/JUNE VOL.158 NO 3 pp. 14–20.

[7] McCormack, Tara (2016), The Emerging Parliamentary Convention on British

Military Action and Warfare by Remote Control, The RUSI Journal, APRIL/MAY  VOL. 161 NO. 2 pp. 22–29.