What is War? pt 2

When last we met, our intrepid author was valiantly struggling to define war. Which, when writing massive tome titled “On War”, defining war would be pretty important, yes. He had just laid down the fact that theory and practice are two very different things (pg. 268).

Section 7: War is Never an Isolated Act. There is so much truth just in that section heading. Well, definitely when it comes to kinetic warfare – generally speaking, a country doesn’t blow up a different country’s facilities without a darn good reason (good to the aggressor, at least). Things get much messier when it comes to non-kinetic warfare.

A good chunk of this is due to the before-mentioned problem of “what is a weapon?” when it comes to cyber warfare. Generally speaking, civilians don’t own F-16 fighter jets, so I don’t have to worry about the neighborhood kids taking said jet for a joyride, blowing the neighboring country to bits on a lark, and sparking full-on war. I’ve had to worry about kids setting my trees on fire by ill-considered use of bottle rockets, but that doesn’t come anywhere close to the threshold of warfare.

When it comes to cyber warfare, because any computer is potentially a weapon, and anyone that knows where to look can find some pretty dangerous code, it is completely plausible that the neighborhood kids shut down a foreign government’s email service for the lulz. Is that an act of warfare? When the effects are the same, does it matter who did it and what their intent was?

If intent (and whodunit) is important, then attribution becomes key to determining if an act meets the threshold for warfare. Given the difficulty when it comes to accurate attribution, this is a not insignificant hurdle. When attribution goes well, the results can be weirder than you could ever imagine. For example, the Mirai Botnet, which crippled large swathes of the Internet in 2016, was a scheme related to Minecraft.

All of this to say: when you’re talking ones and zeroes, what looks like warfare and smells like warfare might be some script kiddies screwing around. The joys of working with protocols that assumed altruistic academics were the only people on the Internet.

“neither of the two opponents is for the other an abstract person” is a really great concept when you’re physical troops lined up on opposite sides of the battlefield, but doesn’t hold up so well when online personas are nothing but smoke and mirrors. We frequently talk about threat modeling in Infosec, and it is really hard to convey to people that the largest threat to them may be something that they don’t even know exists, much less can conceive of in an abstract fashion. How do you explain that they need to worry about someone apparating into their living room and running a money laundering scheme out of their homes without them noticing? But that is exactly what cryptominers do, and they’re a real problem.

The things that you can’t see or touch being threats to you are a lot of what makes risks assessment math really interesting to me – how do you quantify unknowns? What really is the percent chance of someone getting ransomware on my critical file server?

I suspect the fact that even the best of us acknowledge that risk assessments are super-fuzzy math on the best of days is what leads to a good bit of the distrust and oversight when it comes to non-kinetic operations. We trust a barely-trained fighter pilot to make decisions whether or not to fire missiles beyond line-of-sight because there’s some pretty basic physics at work that we all understand – there is a maximum amount of damage that missile can possibly do, unless it has the extreme misfortune to set off a statistically improbable set of chain reactions. In the non-kinetic world approvals are held at crazy-high levels. We don’t feel comfortable delegating what we don’t understand ourselves, because how do I teach my subordinates what right looks like when I don’t know the answer myself?

Section 8: War Does Not Consist of One Blow Without Duration. As much as we may want it to, “one shot, one kill” doesn’t work at the scale of war. It is generally frowned upon that we use one bomb to destroy an entire country, particularly as an opening move. There are a whole lot of things that we have to do to fight a war, and lots of things have to go right for us to win the wars we fight.

“The very nature of these resources and of their employment makes it impossible to put them all into operation at one and the same moment.” Our efforts necessarily have to be scattered – we can’t literally focus all of our efforts on a single spear point. There may be multiple offensives going at once. There’s also all of the “just keeping the lights on” tasks that need to be done. Logistics is an important part of any fight – we have to get the resources to the warfighter that they need to be that pointy tip of the spear. We also need defenders and administrators for our own networks, to make sure that our adversaries are not doing unto us what we are trying to do unto them. Heck, not everybody has the skills to be an offensive operator, so why try to use them that way? Employ your people where they best serve you, and you’ll probably get more out of them.

“The country with its superficial extent and its population… is also in itself an integral part of the factors operative in war.” This is true for several reasons. The first is that the populace of your country is where your Soldiers come from. Your military will have attributes of your populace. You may have the option of scraping your civilian population for people with certain skills in time of great crisis. I don’t recommend this because there is a huge difference between people that volunteered and people that have been pressed into service. Even if they are “critical shortage” skills like people with “cyber smarts”. Yes, that has been proposed. No, I don’t agree with that tactic.

The country is also so integral to the war because it is the battlefield. Given that it has been several generations since there were actual battles fought on continental American soil, we’re prone to forgetting that the battles are happening in someone’s backyard. The notion of cyber war brings warfare back to American soil. Not only are the battlegrounds the social networking services that many people use every day, and American corporation, but American system administrators and SOC analysts are as much on the front lines as any member of a military Cyber Protection Team. It isn’t just the defense industry that gets targeted by state-spectrum actors, but companies like SONY Pictures (mentioned earlier). And that’s without getting into the influence campaigns happening on multiple social media platforms.

Section 9: The Result of a War is Never Absolute. All I have to add to this are some @SwiftOnSecurity memes:

Only the dead have seen the end of cyberwar. Cyberwar does not determine who is right. Only who is left.

Section 10: The Probabilities of Real Life Take the Place of the Extreme and Absolute Demanded by Theory. This looks like some more risk assessment math. Speaking of which, there are many people I know that are interested to see what actuaries come up with regarding information security. Actually being able to put dollar values on particular configurations will certainly change things for businesses if they want insurance. However, at the end of the day we return to the fact that humans are messy and illogical, so have fun applying math to human behavior.

We return to “the political object of the war”, or why are fighting in the first place? Setting aside the problems with attribution for a few moments, knowing who is likely to come after and knowing what they are likely to come after is what we generally refer to as threat modeling, and it is a very important step to choosing the most effective defenses for your situation. For example, if I know that my adversary is a competitor who wants my trade secrets, then they are where I will spend most of my money on mitigations. On the other hand, if my adversary is a scammer who just wants lists of good contact information, I’m going to spend more protecting my HR database.

The obvious flaw being: there’s no reason it can’t be both. When you’re not geographically constrained, the entire planet is potentially your adversary. When their “weapon” is a common computer, they are truly capable of attacking you. So, you play probabilities, follow trends, to figure out what to focus on in your threat model.

“the smaller the sacrifice we demand from our adversary, the slighter we may expect his efforts to be to refuse it to us.” If what I’m attacking is of little value (like, bordering on public knowledge), my adversary probably isn’t defending it very well because, well, why spend money on something that isn’t worth much to you? In that case I’m not going to both using my custom super-l33t tools, I’ll just metasploit awtopwn and move on.

The other part to remember is that sometimes valuable things wander into less protected areas. A human target, no matter how well-defended, will expose themselves to sniper fire at some point; the attacker need only be patient. Similarly, there’s usually better ways of obtaining data than going after the protected database. Employees take work home with them, or there’s a subcontractor with access to the data whose network isn’t as well protected…

Where this gets particularly interesting in the non-kinetic realm is, because the entire world can attack you, that also means those attackers can attack the entire world. If your attacker isn’t specifically targeting you but just looking for someone who has useful goodies, you don’t have to be impenetrable: you just have to be better than the other people who who have similar goodies. Or, to quote this shirt from ThinkGeek:

When you find yourself in the company of a halfling and an ill-tempered Dragon, remember, you don't have to outrun the Dragon...

“One and the same political object can in different nations, and even in one and the same nation at different times, produce different reactions.” Again, attribution sometimes helps. One adversary may not care about your latest tech, while another will stop at nothing to obtain it.

“In two nations and states such tensions, and such a mass of hostile feelings, may exist that a motive for war, very trifling in itself, still can produce a wholly disproportionate effect.” People are messy, emotional, and illogical. It is entirely possible that pleasing the masses, even if things are ultimately not going to turn out well for the masses, can be a political aim in itself. The supposed will of the people has driven some “interesting” decisions (see: Brexit).

We also have a hard time with differentiating “cyber effects” from “things that happened in cyberspace”, or “information operations delivered via social media which happens to live in the cyberz.” And this is an interesting legal authorities distinction, that I’m not sure is appropriate for the threats faced at this time.

Giving it another pause here. I should be able to wrap up Chapter 1 in one more post. I swear the next few chapters aren’t quite this beastly.

Leave a Reply

Your email address will not be published. Required fields are marked *