In 2012 - Future of Cyber Warfare

Topic: Future of Cyber Warfare
Country: United States
Delegate Name: Cody Hoeffel
School: Royal Oak High School

Topic page: background guide and all position papers All United States position papers GLIMUN 2012 committees

It is evident that cyber space is the next addition to the warzone. As such every nation must prepare for the new attacks and rules to follow this new front. Hackers take on the forms of states, individuals, terrorists, conveyors of industrial espionage, and activists. The result, as of present is a litany of problems plaguing the present system.

The first of these issues is the definition of the attacker, how can one tell the origin and purpose of the attack? In this case, there are clues to consider for each attack, clearly, for example is multiple pieces of infrastructure were to be simultaneously attacked, the origin must be a state or state backed organization as the resources needed to coordinate and execute such an attack are massive, in addition to this, it most likely that an attack that is meant to truly hamper a nation would be repeated in rapid succession to ensure success, this is something that once again only state based and state-backed organizations are capable of performing. Telling too is the target itself, infrastructure is the most likely target for state and terrorist attacks as they can cause the most damage. Attacks on a specific website, such as an embassy or public corporation, are likely the targets of activists and individuals seeking to send a message.

The next issue is what is at what point is a response in kind justified, this is where a page from the Geneva Conventions must be taken. Websites must have tags as to what they are, similar to the required uniforms of any legal conflict, or the clear identifications of NGOs, for the web this may be denoted by the url, ending with .org, .gov,.state, etc. However, additional markers should be provided by the servers themselves, showing that one may be solely hosting humanitarian information, and therefore should not, and legally cannot, be targeted by any party. The identification process also allows for the determination of the response to attacks as clearly, an attack on a public hospital is much more provocative than an attack on a company or website providing government information.

The next issue is the prevention of such attacks, this is easiest for developing nations, in that to prevent most cyber attacks the infrastructure needs to be wired into as many functional units as possible, this way there are far fewer tempting targets and any successful attack may only do the same damage as a power outage. For example, in the United States there are over 3000 separate power suppliers, as such any attack on the power system simply leads to a power outage in a small area which is simple enough to respond to. This is the other point to consider for the preparation in case of many infrastructure based cyber attacks, the result is the same as a semi-common failure in the system, rarely is it catastrophic. Regardless the lesson for developing nations is to not centralize their system, but to have their systems broken up into smaller networks, with non-networked backup systems.

Of greater concern is the economic system that has developed around the Internet, this system, without the proper safeguards and backups is extremely susceptible to attack and for the sake of the international community must be considered in addition to attacks on nations.