08 Oct 2008
All U.S. agencies with counterterrorism programs that collect or "mine" personal data -- such as phone, medical, and travel records or Web sites visited -- should be required to systematically evaluate the programs' effectiveness, lawfulness, and impacts on privacy, says a new report from the National Research Council. Both classified and unclassified programs should be evaluated before they are set in motion and regularly thereafter for as long as they are in use, says the report. It offers a framework agencies can use to assess programs, including existing ones.
The report also says that Congress should re-examine existing law to assess how privacy can be protected in such programs, and should consider restricting how personal data are used. And it recommends that any individuals harmed by violations of privacy be given a meaningful form of redress.
"The danger of terror attacks on the U.S. is real and serious, and we should use the information technologies at our disposal to combat this threat," said William Perry, co-chair of the committee that wrote the report, former U.S. secretary of defense, and Michael and Barbara Berberian Professor at Stanford University. "However, the threat does not justify government activities that violate the law, or fundamental changes in the level of privacy protection to which Americans are entitled."
At the request of the U.S. Department of Homeland Security and the National Science Foundation, the report examines the technical effectiveness and privacy impacts of data-mining and behavioral surveillance techniques. Each time a person makes a telephone call, uses a credit card, pays taxes, or takes a trip, he or she leaves digital tracks, records that often end up in massive corporate or government databases. Through formal or informal agreements, government has access to much of the data owned by private-sector companies. Agencies use sophisticated techniques to mine some of these databases -- searching for information on particular suspects, and looking for unusual patterns of activity that may indicate a terrorist network.
The Reality of a Serious Terrorist Threat
The terrorist threat to the United States is all too real, the committee said. Terrorist acts are possible that could inflict enormous damage on the nation. Such acts could cause, and have caused, major casualties as well as severe economic and social disruption.
The most serious threat today comes from terrorist groups that are international in scope; these groups use the Internet to recruit, train, and plan operations and use public channels to communicate. Intercepting and analyzing these information streams might provide important clues about the nature of the threat they pose, the report says. Key clues might also be found in commercial and government databases that record a wide range of information about individuals, organizations, and their behavior. But successfully identifying signs of terrorist activity in these masses of data is extremely difficult, the committee said.
Pattern-Seeking Data-Mining Methods Are of Limited Usefulness
Routine forms of data mining can provide important assistance in the fight against terrorism by expanding and speeding traditional investigative work, the report says. For example, investigators can quickly search multiple databases to learn who has transferred money to or communicated with a suspect. More generally, if analysts have a historical basis for believing a certain pattern of activity is linked to terrorism, then mining for similar patterns may generate useful investigative leads.
Far more problematic are automated data-mining techniques that search databases for unusual patterns of activity not already known to be associated with terrorists, the report says. Although these methods have been useful in the private sector for spotting consumer fraud, they are less helpful for counterterrorism precisely because so little is known about what patterns indicate terrorist activity; as a result, they are likely to generate huge numbers of false leads. Such techniques might, however, have some value as secondary components of a counterterrorism system to assist human analysts. Actions such as arrest, search, or denial of rights should never be taken solely on the basis of an automated data-mining result, the report adds.
The committee also examined behavioral surveillance techniques, which try to identify terrorists by observing behavior or measuring physiological states. There is no scientific consensus on whether these techniques are ready for use at all in counterterrorism, the report says; at most they should be used for preliminary screening, to identify those who merit follow-up investigation. Further, they have enormous potential for privacy violations because they will inevitably force targeted individuals to explain and justify their mental and emotional states.
Oversight Needed to Protect Privacy, Prevent "Mission Creep"
Collecting and examining data to try to identify terrorists inevitably involves privacy violations, since even well-managed programs necessarily result in some "false positives" where innocent people are flagged as possible threats, and their personal information is examined. A mix of policy and technical safeguards could minimize these intrusions, the report says. Indeed, reducing the number of false positives also improves programs' effectiveness by focusing attention and resources on genuine threats.
Policymakers should consider establishing restrictions on the use of data, the committee said. Although some laws limit what types of data the government may collect, there are few legal limits on how agencies can use already-collected data, including those gathered by private companies. An agency could obtain and mine a database of financial records for counterterrorism purposes, for example, and then decide to use it for an entirely different purpose, such as uncovering tax evaders. Restrictions on use can help ensure that programs stay focused on the particular problems they were designed to address, and guard against unauthorized or unconsidered expansion of government surveillance power.
Poor-quality data are a major concern in protecting privacy because inaccuracies may cause data-mining algorithms to identify innocent people as threats, the report says. Linking data sources together tends to compound the problem; current literature suggests that a "mosaic" of data assembled from multiple databases is likely to be error-prone. Analysts and officials should be aware of this tendency toward errors and the consequent likelihood of false positives.
All information-based programs should be accompanied by robust, independent oversight to ensure that privacy safeguards are not bypassed in daily operations, the report says. Systems should log who accesses data, thus leaving a trail that can itself be mined to monitor for abuse.
The report notes that another area ripe for congressional action is legislation to clarify private-sector rights, responsibilities, and liability in turning over data to the government -- areas that are currently unclear. Although the committee did not recommend specific content for this legislation, it noted that private companies should not be held liable simply for complying with government requirements to turn over data.
A Framework to Assess Effectiveness, Privacy Impacts
The report offers two sets of criteria and questions to help agencies and policymakers evaluate data-based counterterrorism programs. One set is designed to determine whether a program is likely to be effective. For example, a system should be tested with a data set of adequate size to see if it will work when used on a large scale, and should be resistant to countermeasures. A second set of criteria assesses likely privacy impacts and helps ensure that, if implemented, the program protects privacy as much as possible. Each program should operate with the least amount of personal data consistent with its objective, for instance, and should have a process in place for the reporting and redress of privacy harms due to false positives.
These evaluations should involve independent experts, and the results should be made available to the broadest audience possible, the report says. Evaluations may result in a program being modified or even cancelled, it notes.
"We hope this framework will help agencies and policymakers determine whether new programs are likely to be effective and consistent with our nation's laws and values and continually improve programs in operation," said Charles Vest, committee co-chair and president of the National Academy of Engineering. "Decisions to use or continue programs need to be based on criteria more stringent than 'it's better than doing nothing.'"
The report was sponsored by the U.S. Department of Homeland Security and the National Science Foundation. The National Academy of Sciences, National Academy of Engineering, Institute of Medicine, and National Research Council make up the National Academies. They are private, nonprofit institutions that provide science, technology, and health policy advice under a congressional charter. The Research Council is the principal operating agency of the National Academy of Sciences and the National Academy of Engineering. A committee roster follows.
----------------------------
Article adapted by Medical News Today from original press release.
----------------------------
Copies of Protecting Individual Privacy in the Struggle Against Terrorists: A Framework for Program Assessment are available from the National Academies Press on the Internet at http://www.nap.edu/.
NATIONAL RESEARCH COUNCIL
Division of Behavioral and Social Sciences and Education Committee on Law and Justice Committee on National Statistics and
Division on Engineering and Physical Sciences Computer Science and Telecommunications Board
Committee on Technical and Privacy Dimensions of Information for Terrorism Prevention and Other National Goals
William J. Perry1 (co-chair)
Michael and Barbara Berberian Professor
Stanford University
Stanford, Calif.
Charles M. Vest1 (co-chair)
President
National Academy of Engineering
Washington, D.C.
W. Earl Boebert
Senior Scientist
Sandia National Laboratories (retired)
Albuquerque, N.M.
Michael L. Brodie
Chief Scientist
Verizon Services Operations
Verizon Communications
Waltham, Mass.
Duncan A. Brown
Director
Strategic Assessments Officev Applied Physics Laboratory
Johns Hopkins University
Laurel, Md.
Fred H. Cate
Distinguished Professor
School of Law, and
Adjunct Professor of Informatics, and
Director
Center for Applied Cybersecurity Research
Indiana University
Bloomington
Ruth A. David
President and Chief Executive Officer
ANSER (Analytic Services Inc.)
Arlington, Va.
Ruth M. Davis
President and Chief Executive Officer
Pymatuning Group Inc.
McLean, Va.
William H. DuMouchel
Vice President, Research, and Chief Statistical Scientist
Lincoln Technologies Inc.
Wellesley Hills, Mass.
Cynthia Dwork1
Principal Researcher
Microsoft
Mountain View, Calif.
Stephen E. Fienberg2
Maurice Falk University Professor of Statistics and Social Science
Department of Statistics
Carnegie Mellon University
Pittsburgh
Robert J. Hermann1
Senior Partner
Global Technology Partners LLC
Bloomfield, Conn.
R. Gil Kerlikowske
Chief of Police
Seattle Police Department
Seattle
Orin S. Kerr
Associate Professor of Law
School of Law
George Washington University
Washington, D.C.
Robert W. Levenson
Professor, and Director
Institute of Personality and Social Research
Department of Psychology
University of California
Berkeley
Tom M. Mitchell
Fredkin Professor of Computer Science
School of Computer Science
Carnegie Mellon University
Pittsburgh
Tara O'Toole
Chief Executive Officer and Director
Center for Biosecurity
University of Pittsburgh Medical Center
Baltimore
Daryl Pregibon
Research Scientist
Google Inc.
New York City
Louise Richardson
Executive Dean and Senior Administrative Officer
Radcliffe Institute for Advanced Study
Harvard University
Cambridge, Mass.
Ben A. Shneiderman
Professor
Department of Computer Science
University of Maryland
College Park, Md.
Danny J. Weitzner
Principal Research Scientist
Computer Science and Artificial Intelligence
Massachusetts Institute of Technology
Cambridge
RESEARCH COUNCIL STAFF
Betty ChemerS
Study Director
HERB LIN
Chief Scientist, Computer Science and Telecommunications Board
1 Member, National Academy of Engineering
2 Member, National Academy of Sciences
Source: Sara Frueh
National Academy of Sciences
Article URL: http://www.medicalnewstoday.com/articles/124717.php
Saturday, November 15, 2008
Friday, November 14, 2008
US Embassy in Ethiopia issues terror warning
Associated Press - November 14, 2008 2:43 PM ET
NAIROBI, Kenya (AP) - The U.S. Embassy in Ethiopia has warned American citizens against taking part in the Great Ethiopian Run because of the threat of terrorism.
Friday's message says embassy staff and their families should not to take part in the 10-kilometer (6.2-mile) race set for Nov. 23. The message followed an unspecified terror warning from the Ethiopian government about the race featuring tens of thousands of runners from Ethiopia and around the world. The race is led by distance great Haile Gebrselassie.
The message did not say if the event was named as a specific target but reminded U.S. citizens of deadly bombings this year in the capital, Addis Ababa.
Ethiopia is fighting insurgent groups and supporting the U.N.-backed government in Somalia.
NAIROBI, Kenya (AP) - The U.S. Embassy in Ethiopia has warned American citizens against taking part in the Great Ethiopian Run because of the threat of terrorism.
Friday's message says embassy staff and their families should not to take part in the 10-kilometer (6.2-mile) race set for Nov. 23. The message followed an unspecified terror warning from the Ethiopian government about the race featuring tens of thousands of runners from Ethiopia and around the world. The race is led by distance great Haile Gebrselassie.
The message did not say if the event was named as a specific target but reminded U.S. citizens of deadly bombings this year in the capital, Addis Ababa.
Ethiopia is fighting insurgent groups and supporting the U.N.-backed government in Somalia.
Al-Qaida in Yemen claims US Embassy attack
The Associated Press
Friday, November 14, 2008
CAIRO, Egypt: A group that monitors extremist Web sites says al-Qaida's branch in Yemen has claimed responsibility for a deadly suicide bombing outside the U.S. Embassy there in September.
Thirteen people died in the attack, including an 18-year-old American woman of Yemeni origin.
The SITE Intelligence Group said Friday the statement in an al-Qaida electronic magazine includes an account of how the car bomb attack was carried out.
It also gives the names of the seven men involved, including a spiritual leader and six of his students who carried out the attack.
The statement warns further strikes will deliver a "taste of horrors."
Yemeni security officials had said this month that the men who assaulted the embassy had links to al-Qaida.
Friday, November 14, 2008
CAIRO, Egypt: A group that monitors extremist Web sites says al-Qaida's branch in Yemen has claimed responsibility for a deadly suicide bombing outside the U.S. Embassy there in September.
Thirteen people died in the attack, including an 18-year-old American woman of Yemeni origin.
The SITE Intelligence Group said Friday the statement in an al-Qaida electronic magazine includes an account of how the car bomb attack was carried out.
It also gives the names of the seven men involved, including a spiritual leader and six of his students who carried out the attack.
The statement warns further strikes will deliver a "taste of horrors."
Yemeni security officials had said this month that the men who assaulted the embassy had links to al-Qaida.
'Ruggedised, weaponised' raygun modules now on sale
By Lewis Page
US killtech behemoth Northrop Grumman has has said that it is ready to take orders for the "world's first ruggedised, weaponised high energy solid state laser designed for battlefield applications". The raygun module is dubbed FIRESTRIKE™.
Northrop cutaway of the Firestrike™ laser chain module
Overkill, you might say, just for lighting campfires.
"This is a rugged electric laser with power levels, beam quality and runtime suitable for offensive and defensive military utility," said Northrop beam-cannon chief Dan Wildt.
"Combined with advanced electro optical and/or infrared sensors, the FIRESTRIKE™ laser can provide self-defense [or] precision strike capabilities."
Click here to find out more!
Northrop has long been working to produce weapons-grade solid state lasers with US military funding. To date, the only way to make a laser useful as a weapon in its own right - rather than a pointer for other systems, or a dazzler - has been to use chemically fuelled systems.
There are two combat lasers under development right now using chemical fuels. The biggest is the jumbo-jet mounted Airborne Laser (ABL), intended to blast enemy ICBMs above their launch bases. Then there's the Hercules transport-plane Advanced Tactical Laser (ATL) gunship model, intended perhaps as a silent, undetectable sky-sniper for the US special-ops community.
But chem lasers need big tanks of dangerous toxic fuel, and produce equally hazardous and corrosive exhaust products. Their logistics requirements are nightmarish, and realistically they are only for static use or mounting in large aircraft or ships.
Solid state lasers, powered by electricity, are much easier to deal with. Until now, however, they have had rather low power levels. As an example, Boeing's Humvee-mounted "Laser Avenger" has to be shone on an enemy munition for quite some time before it will explode.
Northrop reckon they've changed all that. A single FIRESTRIKE™ module weighs 400lb and delivers 15 kilowatts. FIRESTRIKE™s can be linked together to get a more powerful beam, apparently.
It would seem, then, that FIRESTRIKE™ is simply one of Northrop's previously-announced solid state laser "chain" units, ready for sale. The firm has said that at least eight of these can be linked up to get a proper 100 kilowatt beam, generally seen as the threshold for a true battlefield weapon. Beam quality, for the laser aficionados among those reading, is listed at "nominally 1.5 times the diffraction limit". Others may be pleased to note that FIRESTRIKE™s come with Ethernet interface as standard.
Energy efficiency for Northrop's chains is supposedly in the 20 per cent region. This suggests that a full-bore 100kW battle ray will weigh about 1.5 tonnes and require half a megawatt of power. That's pretty hefty, but it's within the ballpark for modern combat vehicles.
Portable blaster rifles or carbines aren't really on the cards yet, then. But a reasonably useful laser tank could well be a goer if Northrop can do what they say.
There was no word on possible waterproof versions, with handy attachments for mounting on the head of one's hollowed out volcano lair swimming-pool menagerie. ®
US killtech behemoth Northrop Grumman has has said that it is ready to take orders for the "world's first ruggedised, weaponised high energy solid state laser designed for battlefield applications". The raygun module is dubbed FIRESTRIKE™.
Northrop cutaway of the Firestrike™ laser chain module
Overkill, you might say, just for lighting campfires.
"This is a rugged electric laser with power levels, beam quality and runtime suitable for offensive and defensive military utility," said Northrop beam-cannon chief Dan Wildt.
"Combined with advanced electro optical and/or infrared sensors, the FIRESTRIKE™ laser can provide self-defense [or] precision strike capabilities."
Click here to find out more!
Northrop has long been working to produce weapons-grade solid state lasers with US military funding. To date, the only way to make a laser useful as a weapon in its own right - rather than a pointer for other systems, or a dazzler - has been to use chemically fuelled systems.
There are two combat lasers under development right now using chemical fuels. The biggest is the jumbo-jet mounted Airborne Laser (ABL), intended to blast enemy ICBMs above their launch bases. Then there's the Hercules transport-plane Advanced Tactical Laser (ATL) gunship model, intended perhaps as a silent, undetectable sky-sniper for the US special-ops community.
But chem lasers need big tanks of dangerous toxic fuel, and produce equally hazardous and corrosive exhaust products. Their logistics requirements are nightmarish, and realistically they are only for static use or mounting in large aircraft or ships.
Solid state lasers, powered by electricity, are much easier to deal with. Until now, however, they have had rather low power levels. As an example, Boeing's Humvee-mounted "Laser Avenger" has to be shone on an enemy munition for quite some time before it will explode.
Northrop reckon they've changed all that. A single FIRESTRIKE™ module weighs 400lb and delivers 15 kilowatts. FIRESTRIKE™s can be linked together to get a more powerful beam, apparently.
It would seem, then, that FIRESTRIKE™ is simply one of Northrop's previously-announced solid state laser "chain" units, ready for sale. The firm has said that at least eight of these can be linked up to get a proper 100 kilowatt beam, generally seen as the threshold for a true battlefield weapon. Beam quality, for the laser aficionados among those reading, is listed at "nominally 1.5 times the diffraction limit". Others may be pleased to note that FIRESTRIKE™s come with Ethernet interface as standard.
Energy efficiency for Northrop's chains is supposedly in the 20 per cent region. This suggests that a full-bore 100kW battle ray will weigh about 1.5 tonnes and require half a megawatt of power. That's pretty hefty, but it's within the ballpark for modern combat vehicles.
Portable blaster rifles or carbines aren't really on the cards yet, then. But a reasonably useful laser tank could well be a goer if Northrop can do what they say.
There was no word on possible waterproof versions, with handy attachments for mounting on the head of one's hollowed out volcano lair swimming-pool menagerie. ®
Air Force scales back cyberwar plans
Shaun Waterman UNITED PRESS INTERNATIONAL
The general in charge of the U.S. Air Force's cyberwarfare effort says plans for his unit have been scaled back because staff who would have been used to set up a cybercommand will be allocated to the service's new nuclear command instead.
Air Force Cyber Command was to be established as a major command alongside the service's space, air-combat and other commands -- last month. However, those plans were suspended over the summer after Defense Secretary Robert M. Gates fired the Air Force's civilian and military leaders because of lapses in the security of the nation's nuclear arsenal.
Last month, plans for a full-fledged major command for cyberwarfare were scrapped.
The Pentagon's Armed Forces News Service reported on Oct. 8 that a gathering of the service's leadership in Colorado was told that cyberoperations would be a numbered Air Force component -- one step down from a major command in organizational terms.
Maj. Gen. William T. Lord, commander of Air Force Cyber Command, told United Press International that the change helped solve the organizational challenge of creating a new nuclear command "with the manpower that was going to be allocated to make cybercommand a major air command allocated instead to fix the more pressing problem... [of] making sure that people are comfortable that we in fact have our eye on the ball of our nuclear enterprise."
Gen. Lord said the headquarters billets that were going to be allocated to cybercommand were used to create the Air Force's Global Strike Command.
The new command brings together all the Air Force's nuclear weaponry under one leadership and is one of a series of measures taken to restore confidence in the service's stewardship of the nation's atomic arsenal after some high-profile missteps.
An internal report released in early June was sharply critical of the Air Force, focusing on a mistaken shipment to Taiwan of four Air Force electrical fuses for ballistic missile warheads. In August 2007, a B-52 bomber was mistakenly armed with six nuclear warheads and flown across the nation without anyone realizing it.
As a numbered Air Force component, the cybercommand will be a force provider to the U.S. military, organized within Air Force Space Command - much as a bomber wing forms part of Air Combat Command, which provides air power to the joint combatant commands.
Gen. Lord said the new arrangement is "a good marriage between the expertise capabilities inside Air Force Space Command and the capabilities we're tying to bring on in the cyberbusiness."
Space Command is already the repository of the technical and engineering expertise required, he said. He dismissed suggestions that the Air Force was rebuffed after an overreaching power grab -- which is how some critics of the service saw its plans for a major cybercommand.
Amit Yoran, former National Cyber Security Division director within the Department of Homeland Security, said that whatever the reason behind the decision, it showed Air Force leaders were "still being open-minded to evolve their strategy based on feedback and input they got" from the civilian leadership and cybersecurity experts.
Dave Aland, a senior analyst for El Segundo, Calif.-based Wyle Laboratories Inc., which supports the Department of Defense and other clients, declined to comment directly about the Air Force decision but said that, in general, the military needs to address the issue of cyberwarfare "considerably more collaboratively."
He said that applies to interservice cooperation as well as relations between the military and other federal entities and allies.
"The spillover is very broad-based," he said of potential collateral damage from cyberattacks.
Mr. Aland said the nature of cyberconflict made it practically impossible to distinguish warfare from crime or terrorism.
"The only real difference is in the target set, which bleeds over dramatically from one [category] to the next - and the intent of the actors," which is all but impossible to determine, he said.
"It becomes impractical to work out who the actors are... and apply the relevant legal framework," Mr. Aland said, adding that there needs to be a "wholly new approach."
Gen. Lord agreed.
"When does a cyberattack on a bank change from being just a cybercriminal to being someone attacking the nation's banking system?" he asked.
"Some would argue it doesn't matter," he said, "and it may not matter if you are inside the bank, but it matters if you are following U.S. law in determining what action, what activity, you can take against -- if you can figure out who the attacker is."
He also said the laws that govern traditional conflicts apply to U.S. cyberwarfare efforts, much the same way targeting decisions for U.S. air power are bound by the restrictions of the Geneva Conventions.
"You still have to look at reciprocity, at collateral damage," he said. "We do consider cyber as a war-fighting domain, but one in which places like the Internet exist, and you have to de-conflict all that."
Those decisions lie with the combatant commanders and, specifically, with the commander of U.S. Strategic Command, which is also setting the requirements for the Air Force's cyberforces.
Gen. Lord said the top-priority requirement right now is training, "all the way down from the Air [Force] Institute of Technology to basic military training." He likened the basic training to "equipping airmen with cybersidearms... officers, enlisted and maybe even contractors, so that they know their responsibilities for behavior on the network today."
Gen. Lord said the numbered Air Force cybercomponent will also support U.S. Northern Command, which controls all U.S. military forces within the continental United States, whether it is needed in response to a cyberattack or as a result of a more conventional disaster, such as a hurricane.
"It's not just the attack-and-defense piece; there's consequence management, too," he said, "where military personnel and equipment could get broken networks up and running for the civilian population."
The general in charge of the U.S. Air Force's cyberwarfare effort says plans for his unit have been scaled back because staff who would have been used to set up a cybercommand will be allocated to the service's new nuclear command instead.
Air Force Cyber Command was to be established as a major command alongside the service's space, air-combat and other commands -- last month. However, those plans were suspended over the summer after Defense Secretary Robert M. Gates fired the Air Force's civilian and military leaders because of lapses in the security of the nation's nuclear arsenal.
Last month, plans for a full-fledged major command for cyberwarfare were scrapped.
The Pentagon's Armed Forces News Service reported on Oct. 8 that a gathering of the service's leadership in Colorado was told that cyberoperations would be a numbered Air Force component -- one step down from a major command in organizational terms.
Maj. Gen. William T. Lord, commander of Air Force Cyber Command, told United Press International that the change helped solve the organizational challenge of creating a new nuclear command "with the manpower that was going to be allocated to make cybercommand a major air command allocated instead to fix the more pressing problem... [of] making sure that people are comfortable that we in fact have our eye on the ball of our nuclear enterprise."
Gen. Lord said the headquarters billets that were going to be allocated to cybercommand were used to create the Air Force's Global Strike Command.
The new command brings together all the Air Force's nuclear weaponry under one leadership and is one of a series of measures taken to restore confidence in the service's stewardship of the nation's atomic arsenal after some high-profile missteps.
An internal report released in early June was sharply critical of the Air Force, focusing on a mistaken shipment to Taiwan of four Air Force electrical fuses for ballistic missile warheads. In August 2007, a B-52 bomber was mistakenly armed with six nuclear warheads and flown across the nation without anyone realizing it.
As a numbered Air Force component, the cybercommand will be a force provider to the U.S. military, organized within Air Force Space Command - much as a bomber wing forms part of Air Combat Command, which provides air power to the joint combatant commands.
Gen. Lord said the new arrangement is "a good marriage between the expertise capabilities inside Air Force Space Command and the capabilities we're tying to bring on in the cyberbusiness."
Space Command is already the repository of the technical and engineering expertise required, he said. He dismissed suggestions that the Air Force was rebuffed after an overreaching power grab -- which is how some critics of the service saw its plans for a major cybercommand.
Amit Yoran, former National Cyber Security Division director within the Department of Homeland Security, said that whatever the reason behind the decision, it showed Air Force leaders were "still being open-minded to evolve their strategy based on feedback and input they got" from the civilian leadership and cybersecurity experts.
Dave Aland, a senior analyst for El Segundo, Calif.-based Wyle Laboratories Inc., which supports the Department of Defense and other clients, declined to comment directly about the Air Force decision but said that, in general, the military needs to address the issue of cyberwarfare "considerably more collaboratively."
He said that applies to interservice cooperation as well as relations between the military and other federal entities and allies.
"The spillover is very broad-based," he said of potential collateral damage from cyberattacks.
Mr. Aland said the nature of cyberconflict made it practically impossible to distinguish warfare from crime or terrorism.
"The only real difference is in the target set, which bleeds over dramatically from one [category] to the next - and the intent of the actors," which is all but impossible to determine, he said.
"It becomes impractical to work out who the actors are... and apply the relevant legal framework," Mr. Aland said, adding that there needs to be a "wholly new approach."
Gen. Lord agreed.
"When does a cyberattack on a bank change from being just a cybercriminal to being someone attacking the nation's banking system?" he asked.
"Some would argue it doesn't matter," he said, "and it may not matter if you are inside the bank, but it matters if you are following U.S. law in determining what action, what activity, you can take against -- if you can figure out who the attacker is."
He also said the laws that govern traditional conflicts apply to U.S. cyberwarfare efforts, much the same way targeting decisions for U.S. air power are bound by the restrictions of the Geneva Conventions.
"You still have to look at reciprocity, at collateral damage," he said. "We do consider cyber as a war-fighting domain, but one in which places like the Internet exist, and you have to de-conflict all that."
Those decisions lie with the combatant commanders and, specifically, with the commander of U.S. Strategic Command, which is also setting the requirements for the Air Force's cyberforces.
Gen. Lord said the top-priority requirement right now is training, "all the way down from the Air [Force] Institute of Technology to basic military training." He likened the basic training to "equipping airmen with cybersidearms... officers, enlisted and maybe even contractors, so that they know their responsibilities for behavior on the network today."
Gen. Lord said the numbered Air Force cybercomponent will also support U.S. Northern Command, which controls all U.S. military forces within the continental United States, whether it is needed in response to a cyberattack or as a result of a more conventional disaster, such as a hurricane.
"It's not just the attack-and-defense piece; there's consequence management, too," he said, "where military personnel and equipment could get broken networks up and running for the civilian population."
Subscribe to:
Posts (Atom)