At long last, the much-awaited conclusion to Book 1, Chapter 1 of On War. When last we spoke Carl had just hit on the importance of feelings. But now we need to talk about the end. Specifically, how wars end. If you’re following along in the Modern Library War Series edition, we’re on page 273.
“A complete equilibrium of forces can never produce a suspension of action.” Given the concept of a truce, this seems really counter-intuitive, but keep reading. Any such truce is likely just delaying things until someone can actually win. I present as evidence the armistice on the Korean Peninsula that has lasted multiple decades – there’s not illusion that things are actually calm there.
Bringing this back to cyberspace, given that we all have essentially the same capabilities (computers) there is a certain level of logic that suggests we have an equilibrium of forces. But we don’t. Not by a long shot. Different people have different strengths (and amount of money to throw at development efforts). Political wills (and the will to conscript) vary wildly between states. Given exactly the same set of chess pieces, there are a multitude of different things that people will do with them.
Also, exactly how does one surrender? It isn’t as neat as when a country hands over all its rifles and accepts occupation by a foreign force. It is very nearly physically impossible for someone to actually take their networks offline in defeat. And even if one did, there are still ways of attacking them that have nothing to do with what that individual does, as their information is often held by third parties (thank you OPM and Experian for offering excellent case studies on how an individual can do everything right and still be screwed).
“In all of this, it is, of course, assumed that each side has a complete knowledge of the circumstances.” Assumptions are fun. Not. I’m guessing that Carl is referring to Intelligence for feeding these assumptions? In any case, knowledge is never complete. Even knowledge of one’s own situation, as we’ll see here shortly.
“16. Attack and defense are things different in kind and of unequal force. Polarity therefore is not applicable to them.” I am very much looking forward to further analysis on this, and how it relates to cliches such as “offense must only win once”, to which the defensive cliché is “the attacker only has to trip over one of the tripwires”. There’s also some really good Twitter threads out there comparing defense to sprinkling LEGO bricks over the floor of a dark room, and waiting for someone to scream as they step on one (I happen to really like that one).
There’s some discussion here on timing. This is a concept that bears further discussion (and I really hope Carl goes into more detail later) as other than when attackers take action when admins are least likely to be paying attention, I’m not quite sure how to manipulate timing to one’s advantage in computer networks. ….yet.
“If the form of defense as we shall hereafter show, is stronger than that of attack…” Given the standard cliché (mentioned above), I’m interested to see of the means by which he came to this conclusion stand up to a rather different domain of warfare.
“No commander has accurate personal knowledge of any position but his own.” Depending on the level of command, the personal knowledge arguably gets less and less. It is much easier to keep track of every person in a company than it is to keep track of every person in a division. Yes, the Division Commander should have general awareness of more total personnel, but the amount of certainty should be inversely proportional to the number of personnel.
This is precisely why CIS Controls 1 and 2 are so important. Asset/software inventory may be relatively simple in a small office/home office (SOHO) environment, but they get way more challenging in a full-blown enterprise. Scale up to a multinational corporation and you see why people tend to snicker at those two controls – it isn’t that they’re not important, but they start approaching impossible. Similarly, how many commanders truly have an accurate picture of where all of their subordinates/subordinate units are at any given moment? At best, they have high probability that most of a unit is in a given location.
Perhaps this is a large part of why defenders feel they are at a disadvantage on computer networks, while we think of defense as having an advantage in other domains? Or, perhaps we fail to understand just how hard defense is in the land domain, and we fail to apply those lessons to the information domain?
“There is no human activity that stands in such constant and universal contact with chance as does war. Thus together with chance, the accidental and, with it, good luck play a great part in war.” I’ve been accused of crimes against commas, but there’s some seriously egregious behavior going on here. I wonder how much of the choice is Carl’s versus the translator’s when it comes to style.
Anyway, back to luck: Yes. Very much yes. Not only is there normal sheer dumb luck, but supposedly deterministic systems don’t always behave in a deterministic manner. At the extremely low level, bit flips are a thing. Stable exploits end up crashing the box. I blame things on computer gremlins all the time. That admin is never around during this time of day…
“From the outset there is a play of possibilities and probabilities, of great and bad luck, which permeates every thread, great or small, of its web and makes war, of all branches of human activity, the most like a game of cards.” Firstly, I just find this to be a really beautiful sentence.
Secondly, I can’t help but be struck by the crossover between Infosec and poker. Particularly, this thread by the always amazing @tarah. Yes, there’s luck, but there’s also head games, there’s ruthlessness, there’s quite a few of the components of warfare, especially when you’re a leader trusted with making decisions – you may have an idea about what cards the other players hold, but you don’t *know*, and you also don’t know how they will play them even if you did know what cards they held. See also: why people get frustrated with the intelligence community.
“But war is no pastime, no mere passion for daring and winning, no work of a free enthusiasm; it is a serious means to a serious end.” This is a really interesting counter-argument for those seeking passion in their employees. However, one could argue that the equivalent to those that reverse engineer malware in their spare time is more like those that take up marksmanship than those that take up warfare. I suspect one could spend a good deal of time relating Infosec to firearms, if one were so motivated.
“…just as a mine, when it is going off, can no longer be guided into any other direction than that given it by previous adjustments.” Even the smallest “cyber attack” shares this with warfare: it is not a simple matter of physics. Cause and effect are often asymmetric, and the effects can be cascading and extremely weird, as well as very long-lasting. The fact that Conficker is still bouncing around the Internet is a very good example of just how long-lasting some of these things can be.
The involvement of non-traditional actors probably makes this even worse, as they may not care as much about fine-tuning things to have precise effects (I once again bring up Mirai as an example of non-professionals letting things get way out of hand). On the other hand, there are multiple examples of criminal organizations providing better technical support for their ransomware than many legitimate software companies. So, professionalism varies wildly, and who is more professional may surprise you.
Finally, at long last, it is time for the quote you all have been waiting for! If you know one thing said by Clausewitz, it is probably this. This one has enough depth to it that it is worth pulling out both the picture of the paragraph and the blockquote:
24. WAR IS A MERE CONTINUATION OF POLICY BY OTHER MEANS
We see, therefore, that war is not merely a political act but a real political instrument, a continuation of political intercourse, a carrying out of the same by other means. What now still remains peculiar to war relates merely to the peculiar character of the means it uses. The art of war in general and the commander in each particular case can demand that the tendencies and designs of policy shall be not incompatible with these means, and the claim is certainly no trifling one. But however powerfully it may react on political designs in particular cases, still it must always be regarded as only a modification of them; for the political design is the object, while war is the means, and the means can never be thought of apart from the object.

You’ll see that the phrase that everyone knows is the section heading, whereas the real quote is much more nuanced.
There’s a concept referred to as the Instruments of National Power: Diplomacy, Information, Military, Economics (DIME). These are the things that states have at their disposal to exercise their will. The military, and, thus, warfare, is but one of those instruments. It is one of the tools in the toolbox of the state to get its way. The right tool depends very much on the situation – they are not all equally effective in all situations, so the smart leader must choose. It isn’t as simple as “politics or war”, but war is part of politics. So is diplomacy. So is the economy.
That last sentence is a doozy: “for the political design is the object, while war is the means, and the means can never be thought of apart from the object.” We should not go to war for the sake of going to war; there should always be a political aim that war helps to achieve. Similarly, any “cyber war” should support a political aim. It needs to be in support of Combatant Commanders’ priorities. “Shut up and gimme cyber” is not really an effective strategy, no matter how awesome your cybers are. Firing the biggest, baddest ammunition in the wrong direction will not win a war any more than exploiting a target that doesn’t actually help you out will.
Another interesting thing is that cyber has the ability to cross all 4 areas of DIME. Modern diplomacy relies as much on email as snail mail, and disrupting communications is a great way to kick off an incident. Most information touches information networks in one way or another – even paper books likely existed as digital files for printing. The military is certainly involved in both offensive and defensive cyberspace operations. The financial system is pretty much inextricably tied to networks at this point (a fact which has been repeatedly exploited, as often those networks are less secure than the financial institutions themselves). Also, pretty much every business has some sort of online presence, even if it is just a listing with store hours.
“Now the first, the greatest and the most decisive act of the judgment which a statesman and commander performs is that of correctly recognizing in this respect the kind of war he is undertaking, of not taking it for, or wishing to make it, something by which the nature of the circumstances it cannot be.”
Regardless of your field, this is a really powerful sentence. We can’t always choose our circumstances, but we can ensure that our reaction to them is the most appropriate for the situation. In order to do this, we first have to define the problem. Given that Infosec is an industry that really tries to push blinkenboxen, we have to be careful about jumping straight to “solutions”. Be sure to work through all the problem-solving steps, develop courses of action… then pursue the appropriate solution. Which may be a blinkenbox, but at least do the staff work to determine if that is the case, first.
Cyber isn’t always the correct action to take. Even when it a correct action, it is rarely the correct action – it should probably be used in support of other stuff going on. We live in a multi-domain world, and cyber is one of those domains, so it can be used to good effect in a well-developed multi-domain battle plan. Similarly, it is rarely a good idea to turn an entire country into a smoking crater, even if that is an effective end to the current conflict. Use the right (combination of) tool(s) for the job.
With that, we finally end Book 1, Chapter 1. Whew!
From here on out the chapters are much more bite-sized, but there’s a loooooot of them. The ride is just beginning!
