Overblog Tous les blogs Top blogs Entreprises & Marques Tous les blogs Entreprises & Marques
Editer l'article Suivre ce blog Administration + Créer mon blog
MENU
25 avril 2012 3 25 /04 /avril /2012 07:40

Cyber-1964_tn.jpg

 

April 24, 2012 Written by: Ms. Naomi Joseph, Canadian International Council.  www.opencanada.org

 

The NATO Policy on Cyber Defence, adopted June 2011, lays the groundwork for a response to cyber-attack under Article V of the Washington Treaty, wherein an attack on one NATO Ally is treated as an attack on all. NATO’s Policy on Cyber Defence ensures that “NATO will provide coordinated assistance if an Ally or Allies are victims of a cyber-attack.” In the lead-up to the policy’s approval by NATO Defence Ministers, General Stéphane Abrial, Supreme Allied Command Transformation, raised the question of an Article V response to cyber-attack in a New York Times op-ed. Though he would not detail hypothetical, he wrote that “assuredly, the Alliance would respond deliberately to any significant attack, adapting its reaction to the extent of the damage, the degree of certainty in attribution, the identity of the attackers and their perceived intentions.” These assurances elide important facts about both Article V and cyber-attacks as we know them.

 

First, Article V can be invoked only when it is determined that an attack on a NATO Ally was directed from abroad. A high degree of certainty of attribution is therefore essential to a defence response under Article V. But cyber-attack is anonymous by nature, denying any certainty in attribution. The three major international incidents of cyber-attack to date remain unattributed, despite their high profile. The distributed denial of service attacks on Estonia in 2007 and the combination of government site defacement, denial of service and malware attacks on Georgia in 2008 left no evidence for attribution. The highly sophisticated Stuxnet worm that wounded Iran’s nuclear enrichment program between 2009 and 2010 was likely introduced on-site by an individual with a USB key but has been untraceable. Unlike the terrorists whose attacks led to the first invocation of Article V on September 12, 2001, the perpetrators of these cyber-attacks leave their identities and intentions anyone’s guess.

 

Second, Article V applies exclusively to armed attacks. The Alliance would have to redefine “armed” to include cyber-weapons to justify an Article V response to a cyber-attack. Currently, that redefinition would be unconvincing, since no known cyber-attack has resulted in physical human injury or fatality. The most aggressive form of cyber-attack the world has seen is non-violent sabotage in Estonia, Georgia and Iran; in contrast to those incidents, most cyber “attacks” fall into one of three categories of non-violent activity – “hacktivism”, theft and espionage. Of those three, only the first seeks any form of attribution, usually to an ill-defined group such as Anonymous or LulzSec.

 

Take a recent incident involving NATO, for example: a phoney Facebook profile of NATO’s Supreme Allied Commander, Europe, Admiral James Stavridis was created by hackers unknown. Was it a hacktivist prank? Or were spies luring Admiral Stavridis’s colleagues into divulging information? Did it serve any purpose? We will probably never know, and that may be part of the point.

Partager cet article
Repost0

commentaires

Présentation

  • : RP Defense
  • : Web review defence industry - Revue du web industrie de défense - company information - news in France, Europe and elsewhere ...
  • Contact

Recherche

Articles Récents

Categories