Section I

Workshop Background

Introduction and Background: About one year ago, the Cyber Conflict Studies Association (CCSA) was formed by a group of senior cyber defense colleagues representing industry, government, and academia. The driving force behind the CCSA was recognition that the shared military/civilian infrastructure, by virtue of its complexity, interconnectivity, and reliance on information technology (IT), is becoming increasingly vulnerable to large-scale cyber attacks. Cyber tools capable of disrupting networks are not difficult to obtain, and most experts recognize that cyber conflict is the work not only of script kiddies, hackers, and hostile nation-states, but also of non-state/transnational actors, who may operate in conjunction with other forces such as organized crime. The objectives of these new threat agents may not only be web defacements, embarrassment, fraud, and business related espionage, but also political disinformation, economic and communication chaos, and disruption of military and homeland defense operations.

The impact of cyber conflicts on our complex infrastructure is unpredictable, in part because of a lack of good analytical tools and models. Enterprise designs, highly interactive mobile code, and critical reliance on network centric communications are relatively new phenomena, and their development objectives are innovation, performance, and profit, not cyber security. The nation’s approach to infrastructure and information protection has focused on the physical protection of resources. Security is usually limited to redundancy of systems, backup of data drives, or some other hardware-specific solution. The cost of protecting human life and the value of structures and equipment are linked to well-established processes; risk analysis, insurance values, and manufacturing techniques that managers, engineers, financiers, and policy makers know and understand. Quantifying the costs of loss, disruption, and changes to information carried by the infrastructure is a much more abstract activity. Government efforts to foster a better understanding of cyber networks that are owned mostly by private entities were pushed into the background as a result of the September 11th attacks on the World Trade Center and the Pentagon. Since then, the emphasis has been on protecting and screening physical assets or personnel, and cyber policy has reverted to concentrating on intelligence collection, attack identification, and protecting against known vulnerabilities. In an environment where the nation’s military, government, and private sector openly tout their dependence on network centric enterprises, the risks of cyber warfare must be addressed from a futuristic perspective.

To fill this apparent void, the CCSA determined that a cyber conflict framework must be established that defines and bounds the problem and assesses how serious cyber conflict could be as a coercive factor. The CCSA proposes creation of a workspace for a social-technical dialogue that addresses, at a minimum, the following questions:

• How do we define cyber conflict, and do its descriptive boundaries change situationally, depending on the adversary?
• Does cyber conflict constitute a significant form of coercive power?
• What large-scale effects can be achieved through cyber attacks?
• What factors (policies, technologies, etc.) will govern the capacity of a state or organization to deter cyber attacks?
• What thresholds for response to or use of cyber attacks might be established?
• How can states and organizations establish the most effective defenses, and how will these defenses interact with other coercive means, particularly economic and military power?
• How will establishing cyber conflict defense postures impact privacy and civil liberties?
• How should national policy and military doctrine be changed to reflect cyber conflict concerns?
• What international agreements are needed to ensure protection against interdiction and punishment of cyber attacks, while respecting the sovereignty of nation-states?

Addressing cyber conflict issues is a formidable task. It is unclear whether traditional, linear problem solving and domain-centered techniques can adequately address these complex and interconnected issues. An interdisciplinary approach is needed to understand the likely technical, operational, economic, and social impact of a cyber attack on critical, shared infrastructures. One CCSA goal is to understand and foster the establishment of effective teams and their methodologies. This requires education of leaders in the field of cyber conflict and development of metrics of the effectiveness of cyber studies. These metrics will provide the analytic data necessary to influence policy and research and product development.

The concept for the complexity workshop series was formed jointly by the CCSA and CTNSP. CTNSP has been addressing issues of information assurance as they relate to military transformation and homeland infrastructure protection and saw workshops on cyber conflict as a means to improve understanding and establish a dialogue on cyber security. The workshop leads were Col (S) Gregory Rattray, Ph.D., a founding member of the CCSA, and Marie Stella, a CCSA member and Federal Aviation Administration employee on detail to CTNSP to address cyber security issues. Mr. Michael Schrage, co-director of the MIT Media Lab's E€Markets initiative, also volunteered his time to help plan and moderate the workshops. Schrage has written and consulted extensively on the design and diffusion of digital technology and its effects on business relationships. His expertise in developing collaborative workspace and his ongoing work on the role of prototypes, simulations, and games as media for innovation, were critical to the success of the workshop effort to date.

Workshop Series Objectives: A series of workshops covering the following topics is envisaged:

I—Begin the Dialogue: to bring diverse communities together and introduce concepts and challenges of complexity and its impact on emergent issues and infrastructure vulnerabilities

II – Engage: to deepen the understanding and dialogue between the cyber defense community and developers of cyber defense applications to improve understanding of how to conduct cyber defense in complex, unpredictable environments and gain an understanding of policy needs in this area

III – Visualize: to examine approaches to visualizing complex systems, interactions of constituent parts, and how systems change with an eye to utilizing these methods within the cyber defense community. This work will add to the dialogue on technology, organizational design, and policy in the area of cyber defense

IV—Design: to examine design concepts for organizations and applications to manage missions involving complex systems and their applicability to cyber defense

V—Formulate: to review current policy constructs for cyber defense and make recommendation on national cyber defense policy

Table of Contents Preface Section II