From: Foreign Policy

How Virtual Espionage Can Lead to Actual Destruction

Richard Bejtlich

It is easy to get lost in cyberspace. This world, created by engineers and populated by everyone, looks different to every person or group that interacts with it. For the U.S. military, cyberspace is a war-fighting domain; for a student, it is a place to interact with peers; for a business, it is a place to make money — and the list goes on.

Discussions of a related topic, cybersecurity, share the same characteristic. How to achieve security, or even define it, also depends on the participant. For most in the world of cybersecurity, digital espionage is a hot topic. Few news items have caused such a stir in this world as the report released in February by my firm, Mandiant, on Unit 61398, formally known as the Second Bureau of the People’s Liberation Army’s General Staff Department’s Third Department. The report revealed the seven-year history of digital espionage by Unit 61398 against at least 141 Western companies. Mandiant traced Chinese cyber- spying back to the doorstep of a 12-story office building outside Shanghai.

Espionage of any kind is serious, of course, but some do not understand how spying in the cyber world is different from spying in the physical world. Few realize that the same tools required to conduct digital espionage could allow intruders to go a step further and commit digital destruction. Once an adversary has entered a computer system, the amount of damage he does or does not inflict depends entirely on his intent. Whether such actions qualify as war is largely a political decision, but the ability to escalate from espionage to destruction is often ignored.

Critics are quick to assert that espionage is a step below a full-fledged digital attack — which could constitute an act of war. The writer Bruce Schneier, for example, responded to reports of Chinese cyberactivity by saying, “This is not cyberwar. This is not war of any kind. This is espionage, and the difference is important. Calling it war just feeds our fears and fuels the cyberwar arms race.”

A better general understanding of digital defense, spying, and war is clearly needed. Those with military backgrounds use three terms to explain cyberactivity: computer network defense (CND), computer network exploitation (CNE), and computer network attack (CNA). CND, protecting digital information from hackers, is universally considered to be a good thing. CNE and CNA are more problematic because they involve taking offensive actions against a target.

Security professionals in the West think of CNE as digital espionage and of CNA as altering, disrupting, or destroying computer systems, whether virtually or physically. Examples of CNE include penetrating computer networks to steal trade secrets or other sensitive data, monitoring individuals’ typing to steal their passwords, or capturing information as it passes through the Internet. Examples of virtual CNA include changing database records or deleting data, while examples of physical CNA include using computers to damage or destroy equipment or inflict other harm in the real world.

The term “cyberwar” usually refers to the use of a digital weapon to cause physical damage. Thus far, the only commonly accepted example of this was the Stuxnet attack against Iran’s nuclear facilities. Some employ “cyberwar” far too loosely, or consider many forms of digital action to be cyberwar so long as they are paired with real-world military operations, as when Russian hackers took down Georgian Web sites during the 2008 war between the two countries.

Any adversary that can spy can also harm — the only limitation is his intent. As a result, depending on the target, cyber-espionage could quickly escalate to cyberwar — in which digital weapons are used to inflict physical damage.

Consider the following attack pattern. First, an intruder performs reconnaissance against his target to survey its weaknesses and find ways to steal or manipulate data. Next, he delivers weaponized content (for example, a document with malicious code, or a link to a malicious Web site) via an e-mail message. The e-mail recipient opens the attachment or clicks on the link, resulting in his computer falling victim to the intruder. The attacker can now control the victim’s computer and is free to pursue his objectives.

Read Complete Article