12.07.2015 Views

2011 report to congress - U.S.-China Economic and Security Review ...

2011 report to congress - U.S.-China Economic and Security Review ...

2011 report to congress - U.S.-China Economic and Security Review ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

dkrause on DSKHT7XVN1PROD with $$_JOB178incident suggested that the attack shown was rudimentary, apparentlyon the basis of the program’s graphical user interface <strong>and</strong> theattack method itself. However, the scope <strong>and</strong> implications of the attackcannot be determined from the footage.* Initially posted onthe broadcaster’s website, the documentary episode was promptlyremoved by CCTV when international media started <strong>to</strong> <strong>report</strong> thes<strong>to</strong>ry. This measure, along with the offh<strong>and</strong>ed manner by whichthe show presented the material, led most <strong>report</strong>s <strong>to</strong> characterizethe footage as an accidental disclosure. 144Military strategiesLike the United States <strong>and</strong> other nations with modern militaries,<strong>China</strong> seeks <strong>to</strong> leverage cyber capabilities <strong>to</strong> achieve or helpachieve military objectives. As the Department of Defense’s <strong>2011</strong>annual <strong>report</strong> <strong>to</strong> Congress on Military <strong>and</strong> <strong>Security</strong> DevelopmentsInvolving the People’s Republic of <strong>China</strong> states, <strong>China</strong>’s militarycould use cyber warfare ‘‘<strong>to</strong> constrain an adversary’s actions or slowresponse time by targeting network-based logistics, communications,<strong>and</strong> commercial activities.’’ 145 Expert testimony <strong>to</strong> the Commissionin <strong>2011</strong> provided details about how <strong>China</strong> would seek <strong>to</strong>employ such techniques. David A. Deptula, a retired U.S. Air Forcelieutenant general, testified that <strong>China</strong> has ‘‘identified the U.S.military’s reliance on information systems as a significant vulnerabilitythat, if successfully exploited, could paralyze or degradeU.S. forces <strong>to</strong> such an extent that vic<strong>to</strong>ry could be achieved.’’ 146Specifically, General Deptula categorized cyber attacks on U.S.C4ISR [comm<strong>and</strong>, control, communications, computers, intelligence,surveillance, <strong>and</strong> reconnaissance] assets as a key action that <strong>China</strong>’smilitary would take ‘‘<strong>to</strong> impede U.S. military access <strong>to</strong> theAsian theater in the event of a U.S.- <strong>China</strong> conflict.’’ 147Martin C. Libicki, senior management scientist at the RANDCorporation, testified that operational cyber attacks, such as thosethat would degrade U.S. logistics systems, present a serious challenge<strong>to</strong> U.S. military forces. As such, the ‘‘[U.S] Department of Defenseneeds <strong>to</strong> take the prospect of operational cyberwar seriouslyenough <strong>to</strong> underst<strong>and</strong> imaginatively <strong>and</strong> in great detail how itwould carry out its missions in the face of a full-fledged attack’’(emphasis in original). 148 He characterized strategic cyberwar, suchas ‘‘a cyberattack on the U.S. power grid, throwing the Midwestin<strong>to</strong> the dark,’’ as less likely in the context of a Taiwan contingency,a conceivable backdrop <strong>to</strong> hostilities between the UnitedStates <strong>and</strong> <strong>China</strong>. Because <strong>China</strong>’s leadership would likely seek <strong>to</strong>keep the United States out of such a contingency, a strategic cyberattack on the United States might have the opposite effect <strong>and</strong>could therefore serve as a ‘‘very poor coercive <strong>to</strong>ol.’’ 149 However,this assessment may not hold for other types of contingencies.* A graphical user interface could easily be mated with a controller capable of launching asignification distributed denial of service attack. A military organization would likely use suchan interface in order <strong>to</strong> make its computer network operations <strong>to</strong>ol more accessible <strong>to</strong> its force.With respect <strong>to</strong> the method of attack itself, computer security experts generally regard distributeddenial of service attacks as one of the more manageable threats. However, certain techniquesare sophisticated <strong>and</strong> difficult <strong>to</strong> mitigate. For a brief discussion of what constitutes asignificant distributed denial of service attack, see Craig Labovitz, ‘‘The Internet Goes <strong>to</strong> War’’(Chelmsford, MA: Arbor Networks, December 14, 2010). http://asert.arbornetworks.com/2010/12/the-internet-goes-<strong>to</strong>-war/.VerDate Nov 24 2008 13:46 Nov 10, <strong>2011</strong> Jkt 067464 PO 00000 Frm 00190 Fmt 6601 Sfmt 6601 G:\GSDD\USCC\<strong>2011</strong>\067464.XXX 067464

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!