Ends and Means in War

We finally get to move on from Chapter 1!! Fortunately, the chapters are much more manageable in size.

In Book 1, Chapter 2, we move on from the nature of war and shift to what influence this has on the means and end in war. Or, why are we doing this war thing anyway? For those of you following along in the Modern Library edition, we begin on page 283.

“If, first of all, we ask what is the aim to which the whole war must be directed so as to be the proper means for attaining the political object…” This is definitely where one needs to start, not just with warfare, but with any goal: what is your goal and why do you want to accomplish it anyway? In military terms, how does your goal fit into the overall political and Combatant Commander’s priorities?

If you are going to be breaking into someone else’s computer systems, what does that get you? Do you have reasonable suspicion that system contains actionable intelligence that is worth collecting? Would rendering that system inoperable do more than just annoy the owner of the system? Or would that force the user of the system to choose a different means of communicating that is easier to intercept? (Thank you recent news about how El Chapo was caught for an example)

“keeping once more to pure theory…the political object of war really lies outside of war’s province” War isn’t fought for the sake of war. War is fought to change some behavior, so consider carefully what behavior you want to change. In the case of Stuxnet (drink!) the desired effect was pretty clear. Most ransomware also has a pretty clear behavior that is intended (pay money). SONY? Still up for debate. DNC? Yet to be determined, as there was a lot going on there, and I’m not sure that we’ve identified all the players.

Did those last two examples result in behavior change? Absolutely! SONY didn’t release a film, and the DNC… well.. umm… Were the behaviors that happened the ones that the attackers intended? Don’t know. I haven’t had the opportunity to interview the attackers.

Behavior change is an important point to remember not just in view of warfare, but in the day-to-day jobs of most Infosec professionals, as we don’t do this job to secure the network; we do this to allow the people who use the network to do their jobs safely. We want to shape people’s behavior so that they make good choices, but to do that we have to make the right choice the easy choice, and understand what they’re trying to do in the first place, and support them in that action (we support political aims, we aren’t the political aims).

“the military forces, the country, and the will of the enemy” are the three general categories we’ll be dealing with. While not inaccurate, this may need some broadening or some additions in order to be relevant today. For example, third-party researchers may not be acting on behalf of a military or country, and may not be trying to be adversarial, but they are definitely something you need to watch out for. Similarly, it isn’t just military/governments on the receiving end of “combat” (see again: SONY). This targeting of the civilian population, and non-defense industry is a big no-no in warfare, but is just another day in Infosecland.

It may be that Infosec/cyber warfare is more akin to guerilla warfare, where it is very difficult to tell who is a combatant, and (depending on who you ask) nearly anything that supports the enemy is considered fair game. Given that I honestly haven’t read ahead, I wonder if Carl will be covering unconventional warfare, given that these concepts have been around for a couple thousand years. Anywho..

“the war… cannot be regarded as ended so long as the will of the enemy is not subdued also”. This is the sticking point, isn’t it? Given that offensive cyberspace operations (OCO) are rarely overt, how do you know you’re really “at war” in the first place? Further, if you’re being clandestine, are you really changing behavior at all? If I don’t see what you’re doing to me, what are the odds that I’ll change my behavior?

Then, if you do do something that the target notices (say, turn out the lights) and the target wants to surrender… who do they surrender to? Not that attribution is impossible, but it is nontrivial. So, let’s say you have your target surrender to you, now you need to protect them lest they be conquered by someone else (because if you can get in, so can some other attacker). As the victim, would you want to accept your conqueror’s protection, or leave your self open to re-attack as a means of getting back at your first conqueror? Heck, what does it even mean to surrender anymore? (there’s probably an entire thesis hiding in that question)

“The enemy forces, even before they have been noticeably weakened, may retreat to the opposite side of the country, even right into foreign territory. In this case the greater part of the country, or even the whole, is therefore conquered.” This is some serious “chicken or the egg” stuff. Do you conquer the military to conquer the country, vice versa, or are they completely unrelated?

How would “deploying” forces to completely wrong missions/areas affect this? Forces don’t necessarily need to run, they just need to be in the wrong place at the wrong time and leave something critical undefended as it is being attacked. When the terrain is a network, who are the combatants? Users? Cyber Protection Teams (CPTs)? System Administrators? All of the above? Given that the deployment of CPTs is still very much a thing that is being worked on, does their being tasked somewhere else mean a section of the network is undefended, or does it mean the System Administrators are the primary defenders? (there’s a whole other rant I have prepared on how we need to make admins better defenders, but that will be another day)

“If, therefore, we have seen wars take place between states of unequal power that is because war in reality is often very far removed from our original theoretical conception of it.” No, really?

“A war need not, therefore, always be fought out until one of the parties is overthrown…” Wouldn’t have guessed this one, either.

Snark aside, the point that you don’t necessarily need to trample your enemy, but you do need to convince them that you could still stands. To borrow a favored saying of Teddy Roosevelt: speak softly and carry a big stick. A significant portion of the point of the modern US military is to be so big and scary that no one wants to attack in the first place, which we’ve generally done a pretty good job at… on the conventional warfare side of the house. On the unconventional side… *waves vaguely at Afghanistan*

Also, as much as it pains me to say this, I’m not sure how seriously most of the world takes USCYBERCOM. Granted, most things they do won’t be public any time soon because classification, but I’m not sure “we see you and we’d like you to stop” is what I’d call effective at changing behavior. If reports can be trusted there’s work being done to give USCYBERCOM more teeth (namely the replacement of PPD-20) but there’s still a long way to go to get USCYBERCOM staff to a level of maturity where they’re able to plan and execute effective operations – this will probably take a generation.

Tangentially, I’m reminded of the episode of Dr. Who (The God Complex) with the race that always surrendered. They basically subjugated themselves in order to ensure that they never got wiped out in battle – they ensured their survival. Sometimes there’s a weird sort of strength in not resisting.

“…or whether we mean to content ourselves with one victory in order to shatter the enemy’s feeling of security, to give him a feeling of our superiority, and so to instill into him apprehensions about the future.” I definitely feel like “show of force” is something that some OCO is trying to do (see earlier link on the messaging operation) – make your targets nervous. But, what is the point of making them nervous? What is the political aim? What behavior are you trying to change?

“The second question is how to influence the enemy’s expenditure of strength, that is to say, how to raise for him the price of success.” I definitely aim to “raise the attacker’s cost” as a defender. Depending on the persistence of the attacker, I can encourage them to move on to a softer target. If they’re really not persistent, an attacker may not bother targeting me in the first place, if they’ve done good recon. Granted, this doesn’t work for the more persistent attackers, but if you’ll be patient with me, we’ll get there…

“The enemy’s expenditure of strength lies in the wastage of his forces, consequently in the destruction of them on our part, and in the loss of provinces, consequently the conquest of them by us.” This is going to take a bit to deconstruct.

  • “wastage of forces” are expenditure of the attacker’s resources. This is their time, their money, their infrastructure. Time and money get taken up in researching new exploits (even when they’re publicly available, you have to train your team in how to use them) so being different wastes the attacker’s resources.
  • “loss of provinces” is when things get “burned” – their tools get released and signatures become available, their infrastructure gets mapped out so that has to be destroyed and rebuilt, or (even worse) a TTP becomes associated with that actor and they have to essentially start over from scratch to avoid attribution/being blocked (the top of the Pyramid of Pain is a bad place to have a leak).
  • Granted, this isn’t a perfect one-to-one mapping, but you get the general idea.

“There are three other special ways of directly increasing the enemy’s expenditure of force. The first is invasion, that is, the occupation of the enemy’s territory, not with a view to keeping it, but in order to… devastate it. … The immediate object here is to… do him damage in a general way.” This may be where hacking is most effective. As long as people rely on computers for communications (even “old school” communications methods have a computer under the hood somewhere) other people can disrupt those communications from around the world. Ditto messing with data. Ransomware and other destructive attacks are, well, destructive. Even if you’re not directly destroying data, you can manipulate it – integrity attacks are what scare me, personally. It is very possible to make life generally suck for your adversary, to wreak havoc and harass them via network attacks.

“The second way is to direct our enterprises preferably to the points at which we can do the enemy most harm.” I’m not sure that I have a very good analogue for this. Letting your enemy know you’re researching <insert critical system here> for vulnerabilities is about as close as I can get, and even then, messaging is a thing that needs to be done very carefully to be effective.

“The third way, by far the most important from the number of cases to which it applies, is the wearing out of the enemy. …a gradual exhaustion of the physical powers and the will by the long continuance of action.” As a defender, I love nothing more than making the attacker give up and move on. As an attacker, I love the defenders who think there’s nothing they can do and just give up.

“…the smallest object that we can propose to ourselves is pure resistance” I think I’m going to need some more discussion on the nature of defense before this entirely makes sense. Carl clearly wouldn’t consider “active defense” measures as pure resistance, but what would? Would that be just secure configurations? Fail2ban? Pretty much anything automateable, or are normal defensive activities pure resistance for him?

(paraphrase) resistance/defense has ‘negative character’. Negative acts in same direction as positive would be less effective, but they’re not in same direction, usually, so they tend to be more effective. Specifically… “with the duration of the struggle, and thus this negative intention, which constitutes the essence of pure resistance, is also the natural means for outlasting the enemy in the duration of the struggle, that is to say, for tiring him out.” Here we begin to see how defense has the advantage in conventional warfare. I think I’m starting to see how defense can have an advantage in cyber warfare as well.

Offense doesn’t really have to win only once. A whole ton of things have to go right, particularly if the target has reasonable defenses. While the attacker is trying to get around those defenses, unless they have amazing intelligence and know all the defenses up front and can bypass all of them on the first try, there’s going to be failure. All of that failure is going take time, and make noise. That noise (and time) works to the target’s advantage as that gives them an opportunity to see what’s up, and add some new defenses. Thus, the attacker lives in constant fear of getting burned. It is possible for them to achieve that mission’s objectives, but get burned, putting all other operations that use similar TTPs at risk.

Also, particularly when it comes to businesses, how often have attacks really hurt the bottom line (*cough*Target*cough*)?

“Every military activity, therefore, necessarily relates to the engagement, either directly or indirectly. The soldier is levied, clothed, armed, trained, sleeps, eats, drinks, and marches merely to fight at the right place and the right time.” In an all-volunteer force, whose motivations for joining the service include college, dental coverage, a paycheck… this is an important thing to be reminded of. Regardless of what one’s role is, everyone is either fighting, or supporting those fighting in some capacity. Even us cyber geeks.

Which brings up the question: when Soldiers don’t set foot on a battlefield, are they still truly Soldiers? Pilots still put their lives in danger by being a thing that enemies can attack, but what about UAV operators? What about cyber operators? Does it need to be uniformed personnel performing this work? How does being uniformed affect how seriously you take these duties? Or are the cyber forces the equivalent of camp followers – necessary logistical support, but these roles could absolutely be done by civilians? Does it depend on the specific role you’re asking those people to fill? This has important implications for how you recruit, train, and retain those forces.

“All action, therefore, takes place on the assumption that if the decision by force of arms which lies at its foundation should actually take place, it would be a favorable one.” While completely valid for conventional warfare, I’m not convinced this holds as well for irregular warfare. Not only is this a space where a very small A team can run circles around a much larger B team (so numbers aren’t as much of a deciding factor), but there’s a significant lack of negative consequences. A low-skilled individual can spray the entire planet with nastiness, and unless they’re in the wrong country the odds of them facing any penalties are very low, so why not take the action? It is better said that the assumption should be that the result would not be unfavorable (yes, double negative, but more accurate).

That, my friends, is my read of Book 1, Chapter 2. I will note that all italics are as presented in my edition – I have not added any formatting to quotations.

Leave a Reply

Your email address will not be published. Required fields are marked *