The "Korean" Cyber Attacks and Their Implications for Cyber Conflict
It has been several months since the basic "denial of service" attacks against networks in the United States and South Korea in early July. No one has yet taken credit, nor have others been able to determine the attackers' identity. As with many other cyber incidents, there is no conclusive evidence as to who was responsible. Cyberspace enables anonymous attacks. Identities are easily concealed or fabricated in cyberspace, and an astute opponent will of course make it look as if another was responsible for an attack. The use of botnets complicates attribution - the source of an attack, at the first iteration, will be innocent and unknowing third parties. Forensic work may eventually reveal the source of an attack, but a sophisticated opponent will be able to operate clandestinely and with a high degree of deniability. The "Confickr" worm is a good example of this difficulty. Confickr was a global malware that infected millions of computers. Many companies and governments made a coordinated effort to fend it off, but we still have no idea who launched Confickr, what their intent was, or even whether it has been removed from all infected systems. This failure of attribution leads to several conclusions on state of cyber conflict. Cyber conflict is a new and complicated strategic problem. There is neither an adequate policy framework to manage conflict in cyberspace nor a satisfactory lexicon to describe it. Uncertainty is the most prominent aspect of cyber conflict - in attribution of the attackers identity, the scope of collateral damage, and the potential effect on the intended target from cyber attack. Many concepts - deterrence, preemption, proportional response - must be adjusted or replaced for the uncertain cyber environment.
The "Korean" Cyber Attacks and Their Implications for Cyber Conflict