NATOSource is proudly sponsored by EADS North America

New Atlanticist
National Interests
- Afghanistan
- Albania
- Armenia
- Australia
- Austria
- Azerbaijan
- Belarus
- Belgium
- Bosnia-Herzegovina
- Brazil
- Britain
- Bulgaria
- Canada
- Chad
- China
- Congo (DRC)
- Croatia
- Cyprus
- Czech Republic
- Denmark
- Egypt
- Estonia
- Finland
- France
- Georgia
- Germany
- Greece
- Hungary
- Iceland
- India
- Indonesia
- Iran
- Iraq
- Ireland
- Israel
- Italy
- Japan
- Jordan
- Kazakhstan
- Kosovo
- Kyrgyzstan
- Latvia
- Lebanon
- Lithuania
- Luxembourg
- Libya
- Macedonia
- Malta
- Montenegro
- Morocco
- Netherlands
- North Korea
- Norway
- Pakistan
- Philippines
- Poland
- Portugal
- Qatar
- Romania
- Russia
- Saudi Arabia
- Serbia
- Slovakia
- Slovenia
- Somalia
- South Africa
- South Korea
- Spain
- Sudan
- Sweden
- Switzerland
- Syria
- Taiwan (ROC)
- Tajikistan
- Tunisia
- Turkey
- U.A.E.
- U.S.
- Ukraine
- Uzbekistan
- Yemen
Post-Stuxnet: The era of computer-mediated destruction has begun
Jorge Benitez | June 12, 2012From R. Scott Kemp, the Bulletin of the Atomic Scientists: While digital spying has taken place for decades, the era of computer-mediated destruction has only recently begun. Early this month The New York Times published an investigative feature that explored Olympic Games, a cyberweapons program designed to sabotage an element of another country's infrastructure. Started during the Bush administration, this is the first known program of its kind. In embarking on Olympic Games, the United States and Israel stepped boldly, but naively, into uncharted territory.
The first battle of Olympic Games reached the public eye in July 2010, when news broke of Stuxnet, a creative worm designed to cause Iran's uranium-enrichment centrifuges to explode by changing, with software, their operating parameters. On its heels were Duqu, Wiper, and Flame, a set of multipurpose tools that collected intelligence, identified vulnerabilities, and sabotaged information systems. . . .
[I]f the measure of Iran's progress toward a nuclear weapon is its inventory of enriched uranium, then Iran came out ahead. IAEA data indicates that Iran was able to boost output enough to reverse all Stuxnet-induced production losses by March 2010, about eight months after the attack first began to have an effect. After the successful eradication of Stuxnet in the summer of 2010, Iran sustained its heightened level of production, expanding its low-enriched uranium stockpile at rates exceeding the pre-Stuxnet trend. If, without Stuxnet, Iran would have expanded production according to its historical trajectory, then one would conclude that the cyberattack wound up enhancing Iran's ability to make nuclear weapons instead of setting the program back.
What went wrong? Stuxnet was designed to operate on an ongoing basis without being detected: a strategy of steady attrition in the pursuit of time. The worm was not supposed to leave Iran or be discovered -- but it soon spread beyond the confines of Iran's nuclear facilities until, ultimately, members of the computer-security community identified it. Stuxnet both failed to operate according to plan and failed to have a long-term benefit. Perhaps, then, the lesson for the authors of future cyberweapons is to recognize the short-lived and unpredictable nature of cyberattacks and aim for more acute, immediate destruction, rather than persistent manipulation of another nation's assets -- a worrisome conclusion suggesting that cyberweapons may be better suited for terror than for strategic affairs. . . .
In the world of armaments, cyber weapons may require the fewest national resources to build. That is not to say that highly developed nations are not without their advantages during early stages. Countries like Israel and the United States may have more money and more talented hackers. Their software engineers may be more skilled and exhibit more creativity and critical thinking owing to better training and education. However, each new cyberattack becomes a template for other nations -- or sub-national actors -- looking for ideas. Stuxnet revealed numerous clever solutions that are now part of a standard playbook. A Stuxnet-like attack can now be replicated by merely competent programmers, instead of requiring innovative hacker elites. It is as if with every bomb dropped, the blueprints for how to make it immediately follow. In time, the strategic advantage will slowly fade and once-esoteric cyber weapons will slowly become weapons of the weak.
Whatever the greater nature of cyberwarfare, it is clear that individual cyberweapons are inherently fragile. They work because they exploit previously unknown vulnerabilities. Stuxnet, for example, exploited four "zero day" vulnerabilities in the Windows operating system. As soon as Stuxnet made them public, they were patched and thus no longer available vectors for future attacks or intelligence gathering. Such vulnerabilities are also closed through routine software updates and patches. Powerful hacker entities like the US National Security Agency must continue to discover new weaknesses in an attempt to stay ahead, and probably maintain a sizable list of unpublished vulnerabilities for future exploitation -- but to what end? These security gaps apply to all computer systems of a specific type regardless of national borders. Every vulnerability kept secret for the purpose of enabling a future cyberattack is also a decision to let that vulnerability remain open in one's own national infrastructure, allowing it to be exploited by an enemy state or even a terrorist hacker. This raises a basic philosophical question about how states should approach the question of cyberwarfare: Should countries try to accrue offensive capabilities in what amounts to a secret arms race and, in doing so, hold their own publics at risk? Or should states take a different tack, releasing knowledge about vulnerabilities in a controlled way to create patches to shore up their own digital frontiers?
R. Scott Kemp is an associate research scholar with the Program on Science and Global Security at the Woodrow Wilson School for Public and International Affairs at Princeton University. (graphic: Matt Murphy/Economist)
NATOSource

The daily news of the world's most powerful alliance.
The views expressed in NATOSource are solely those of the authors and do not necessarily reflect the views of the Atlantic Council, its staff, or its supporters.
Follow on Twitter: @NATOSource
"I am an enormous fan of NATOSource. I use it virtually every day, because it provides a wide variety of views, a solid base of factual knowledge, and keeps me in touch with the world of NATO."
Admiral James Stavridis, (Ret,), former SACEUR

(Graphics: Deutsche Welle and Reuters)
Most Popular NATOSource Posts
Key Issues
- Alliance Unity
- Allied Command Operations
- Allied Command Transformation
- Article 5
- Burden Sharing
- Capabilities Gap
- Chicago Summit
- Congress
- CSTO
- Cyber Threats
- Defense Spending
- Energy Security
- EU
- High North
- Intelligence
- ISAF
- Missile Defense
- NATO Defense Ministerials
- NATO Exercises
- NATO Ministerials
- NATO Operations
- NATO Partnerships
- NATO Response Force
- Nuclear Weapons
- OSCE
- Piracy
- R2P
- SACEUR
- SACT
- Secretary General
- Smart Defense
- Special Forces
- Strategic Concept
- Terrorism
- Transatlantic Relations
- United Nations
- Weapon Systems
TransAtlantic Links
Media Links
- Associated Press
- Baltic Times
- Brussels blog
- Deutsche Welle
- Economist
- EU Observer
- European Voice
- Financial Times
- Guardian
- Hurriyet Daily News
- International Herald Tribune
- Kathimerini
- Kyiv Post
- Le Monde Diplomatique
- Moscow Times
- New York Times
- Newsweek
- Prague Daily Monitor
- Radio Free Europe
- Reuters
- Ria Novosti
- Russia Today
- Slovak Spectator
- Spiegel
- St. Petersburg Times
- Sur
- Telegraph
- Times (London)
- Today's Zaman
- Wall Street Journal
- Washington Post
- Xinhua
Research Centers
- American Enterprise Institute (AEI), United States
- Aspen Institute, United States
- Atlantic Council, United States
- Brookings Institution, United States
- Carnegie Endowment for International Peace, United States
- Cato Institute, United States
- Center for a New American Security (CNAS), United States
- Center for International Relations (CIR), Poland
- Center for Security Studies (CSS), Switzerland
- Center for Strategic and International Studies (CSIS), United States
- Center for Transatlantic Relations, United States
- Cicero Foundation, Netherlands
- Council on Foreign Relations, United States
- Danish Institute of International Studies (DIIS), Denmark
- EU Institute for Security Studies, France
- European Council on Foreign Relations, Bulgaria, France, Germany, Spain, UK
- European Institute, United States
- Fondation pour la Recherche Stratégique (FRS), France
- French Institute of International Relations (IFRI), France
- Fundacion para el Análisis y los Estudios Sociale (FAES), Spain
- German Council on Foreign Relations (DGAP), Germany
- German Marshall Fund of the United States, United States
- Grupo de Estudios Estratégicos (GEES), Spain
- Heritage Foundation, United States
- Hoover Institution, United States
- Institut de Relations Internationales et Stratégiques (IRIS), France
- Institute for Foreign Policy Analysis (IFPA), United States
- Institute for International and Security Affairs (SWP), Germany
- Instituto Affari Internazionali (IAI), Italy
- International Institute for Strategic Studies (IISS), United Kingdom
- Konrad Adenauer Stiftung, Germany
- Lemnitzer Center, United States
- Marshall Center, Germany
- Netherlands Institute of International Relations (Clingendael), Netherlands
- Norwegian Institute of International Affairs (NUPI), Norway
- RAND, United States
- Real Instituto Elcano, Spain
- Ridgway Center, United States
- Royal Institute of International Affairs (Chatham House), United Kingdom
- Royal United Services Institute (RUSI), United Kingdom
- Schuman Center (RSCAS), Italy
- Security & Defence Agenda (SDA), Belgium
- Strategy International (SI), Greece
- U.S. Institute of Peace, United States
- Woodrow Wilson International Center for Scholars, United States

