Biden vows to wield ‘all instruments’ in fighting cyberthreats拜登誓言将动用“一切手段”打击网络威胁
The strategy calls out China, Russia, Iran, North Korea and others for “reckless disregard for the rule of law and human rights in cyberspace."

WASHINGTON — The Biden administration in its highly anticipated cyber strategy pledged to use “all instruments of national power” to disrupt and dismantle malicious cyber actors near and far, while also promising to invigorate international relationships, including with nations previously untapped.
The strategy, rolled out March 2 after much buzz and speculation within the cybersecurity community, describes the digital domain the world has become reliant upon as a reflection of its users and its architects — and one that needs protecting, even if it means upheaval in the short-term.
“We must make fundamental changes to the underlying dynamics of the digital ecosystem, shifting the advantage to its defenders and perpetually frustrating the forces that would threaten it,” it reads. “Our goal is a defensible, resilient digital ecosystem where it is costlier to attack systems than defend them, where sensitive or private information is secure and protected, and where neither incidents nor errors cascade into catastrophic, systemic consequences.”
The document, more than two-dozen pages and spanning five “pillars,” is colored by Russia’s latest invasion of Ukraine , which days ago ground past its bloody one-year anniversary. It specifically calls out China, Russia, Iran, North Korea and other autocratic states for alleged “reckless disregard for the rule of law and human rights in cyberspace.”
The Russia-Ukraine war, so far killing more than 8,000 civilians and hundreds of thousands of troops, according to the U.N. human rights office, has been punctuated by cyber paroxysms, including an early-days assault on Viasat, a California-based satellite specialist and defense contractor, meant to cripple command and control.
“Looking back at the last 24 months of the Biden-Harris administration, and especially over the last year, as we recently hit the one-year mark of the war in Ukraine, we’ve seen the cyberthreat be at the forefront of geopolitical crises,” Anne Neuberger , deputy national security adviser for cyber and emerging technology, told reporters this week. “And as we know, the threat is not only Russia. We’ve seen disruptive cyber and ransomware attacks executed by cybercriminals and other countries across the globe.”
The U.S. dispatched cyber experts to Ukraine in late 2021, as tensions in Eastern Europe boiled and lawmakers pressed the White House to slap Russian President Vladimir Putin with sanctions.
The so-called hunt-forward operation — a defensive and cooperative measure, undertaken at the invitation of a foreign government — was designed to root out malign activity, identify network weaknesses and glean information about the tools hackers use .
Spearheaded by Cyber Command, the operation has since been credited with blunting Russia’s cyber efficacy.
Such endeavors are part of CYBERCOM’s persistent engagement strategy: a means of being in constant contact with adversaries and ensuring proactive, not reactive, moves are made. The command, tasked with guarding Department of Defense information networks and coordinating cyberspace operations, has conducted dozens of similar missions across many countries.
“Cyberthreats are fundamentally transnational threats,” Neuberger said. “They cross borders.”
The Biden administration’s strategy “will definitely expand on partnership,” Col. Candice Frost , commander of the Joint Intelligence Operations Center at CYBERCOM, said ahead of its release. “That’s been because of what’s going on with Russia and Ukraine, in the work that we’ve done with them.”
“I think it was very unique when we look at Russia and Ukraine,” she said Feb. 28 at an event hosted by Billington Cybersecurity. “In the military, we have a supporting and supported kind of relationship. Cyber Command at one point was the supported command.”
Cyber specialists were previously sent to Croatia, Estonia, Lithuania, Montenegro and North Macedonia.
Col. Candice Frost, commander of the Joint Intelligence Operations Center at U.S. Cyber Command, gestures as she speaks Feb. 28, 2023, at an event hosted by Billington Cybersecurity. (Colin Demarest/C4ISRNET)
While some deployments were tied to stateside elections, efforts in Lithuania, specfically, were related to the perceived Russian threat. The work there lasted three months and marked the first shared operation between Lithuania’s cyber forces and U.S. experts overseas.
“We’re leaning forward in looking at partner nations that just typically haven’t been as close with us in the past,” Frost said. “It’s been really exciting to see that form.”
Exactly how the U.S. plans to bear down on and punish malicious cyber actors, senior officials would not say. Military operations in cyberspace are often clandestine; details rarely emerge, let alone in a timely fashion.
Generally speaking, though, the idea is to combine intelligence and military might , both kinetic and non-kinetic, with diplomatic, financial and legal options to suffocate malfeasance, according to the strategy. The aggressiveness can be seen as a continuation from the Trump administration, which empowered CYBERCOM and took digital action against Russia and Iran.
“We want to shrink the surface of the Earth that people can conduct malicious cyber activity on with impunity, and put pressure on them and make their lives a little bit less pleasurable,” one senior U.S. official said, speaking on condition of anonymity. “And if a criminal is restricted to living in Russia and can’t leave the borders, then, perhaps, that might create a bit of a deterrent effect.”
Cooperative crackdown
Stamping out cyber misconduct, a lofty goal, will require the cooperation of many governments , the coordination of many moving parts and the corralling of many influential thinkers.
The strategy anticipates this. The Biden administration intends to lean on like-minded nations “to counter threats,” enforce online norms and develop “new collaborative law enforcement machanisms for the digital age.”
Disruptive ransomware attacks, as seen with Colonial Pipeline and JBS Foods in 2021, are increasingly common, and are often traced to sources outside the U.S. The blueprint cites successes of the European Cybercrime Centre, set up by Europol in 2013, and vows to support the model in other regions.
The document, said Matt Hayden, vice president of cyber client engagement at General Dynamics Information Technology, transcends traditional “protection of U.S. domestic critical infrastructure by amplifying the effort to impose costs on bad actors internationally in partnership with our allies.”
“An example,” he said in a statement Wednesday, “is the partnership in Ukraine that involves sharing cyber threat intelligence, tools and training to thwart attacks and maintain resilient critical systems.”
Washington and Kyiv in July agreed to grow its cyber relationship with an agreement struck between the Cybersecurity and Infrastructure Security Agency and its Eastern European analogue, the State Service of Special Communications and Information Protection.
The arrangement is designed to expand cyber education , joint exercises and avenues for sharing best practices.
“We need to ensure that we are prepared for threats, for incursions against our critical infrastructure, whether it’s state supported actors, criminally aligned ransomware groups, or even the cascading attacks, with attacks in Ukraine that could bleed over to Russia or could bleed over to the U.S., as we saw with NotPetya in 2017,” CISA Director Jen Easterly, who has more than two decades of military intelligence and cyber experience, said last year.
NotPetya malware incapacitated vital systems the world over , resulting in massive financial loses. Russia was blamed for the devastation. Like Notpetya, the Biden Administration strategy states, Russia’s cyberattacks “in support of its 2022 brutal and unprovoked invasion of Ukraine have resulted in irresponsible spillover impacts onto civilian critical infrastructure in other European countries.”
The president’s fiscal 2023 budget request included $2.5 billion for CISA, approximately 18% more than what was sought in 2022. The budget request also included some $11.2 billion for Pentagon cyber, nearly 8% over the administration’s previous ask.
Biden’s latest request, for 2024, is expected to be unveiled later this month .
Colin Demarest was a reporter at C4ISRNET, where he covered military networks, cyber and IT. Colin had previously covered the Department of Energy and its National Nuclear Security Administration — namely Cold War cleanup and nuclear weapons development — for a daily newspaper in South Carolina. Colin is also an award-winning photographer.
华盛顿——拜登政府在其备受瞩目的网络战略中承诺,将动用“一切国家力量”来扰乱和瓦解近在咫尺和遥远的恶意网络行为者,同时承诺加强国际关系,包括与以前未曾接触过的国家建立联系。
该战略于 3 月 2 日推出,此前网络安全界对此进行了广泛的讨论和猜测。该战略将世界赖以生存的数字领域描述为用户及其架构者的反映——即使这意味着短期内的剧变,也需要对其进行保护。
“我们必须从根本上改变数字生态系统的底层动态,将优势转移到防御者手中,并持续挫败任何威胁它的力量,”声明中写道。“我们的目标是构建一个可防御、有韧性的数字生态系统,在这个生态系统中,攻击系统的成本高于防御成本,敏感或私人信息得到安全保护,任何事件或错误都不会引发灾难性的系统性后果。”
这份长达二十多页、涵盖五大“支柱”的文件,处处都笼罩着俄罗斯最新入侵乌克兰的阴影。几天前,这场战争刚刚过去了血腥的一周年纪念日。文件特别点名批评中国、俄罗斯、伊朗、朝鲜和其他专制国家,指责它们“肆意践踏网络空间的法治和人权”。
据联合国人权事务高级专员办事处称,迄今为止,俄乌战争已造成 8000 多名平民和数十万士兵丧生,期间还发生了一系列网络攻击事件,包括早期对总部位于加利福尼亚州的卫星专家和国防承包商 Viasat 发起的攻击,旨在瘫痪其指挥和控制系统。
“回顾拜登-哈里斯政府过去24个月的执政,尤其是在过去一年里,随着乌克兰战争爆发一周年,我们看到网络威胁已成为地缘政治危机的焦点,”负责网络和新兴技术的副国家安全顾问安妮·纽伯格本周对记者表示。“而且我们知道,威胁不仅仅来自俄罗斯。我们看到网络犯罪分子和其他国家在全球各地发动了破坏性的网络攻击和勒索软件攻击。”
2021 年底,随着东欧局势日益紧张,国会议员向白宫施压,要求对俄罗斯总统弗拉基米尔·普京实施制裁,美国向乌克兰派遣了网络专家。
所谓的“前线搜寻行动”——一项防御性和合作性的措施,是应外国政府的邀请而采取的——旨在根除恶意活动,识别网络弱点,并收集有关黑客使用的工具的信息。
此次行动由网络司令部牵头,被认为削弱了俄罗斯的网络作战能力。
此类行动是美国网络司令部持续接触战略的一部分:旨在与对手保持密切联系,确保采取主动而非被动的行动。该司令部负责保护国防部信息网络并协调网络空间行动,已在多个国家开展了数十次类似任务。
纽伯格说:“网络威胁本质上是跨国威胁,它们跨越国界。”
美国网络司令部联合情报行动中心指挥官坎迪斯·弗罗斯特上校在相关战略发布前表示,拜登政府的战略“肯定会扩大伙伴关系”。“这是因为俄罗斯和乌克兰目前的情况,以及我们与他们开展的合作。”
“我认为,当我们审视俄罗斯和乌克兰的关系时,会发现这种情况非常特殊,”她在2月28日由比灵顿网络安全公司主办的活动上说道。“在军队中,我们之间存在着一种支持与被支持的关系。网络司令部一度是被支持的司令部。”
此前,网络安全专家曾被派往克罗地亚、爱沙尼亚、立陶宛、黑山和北马其顿。
2023年2月28日,美国网络司令部联合情报行动中心指挥官坎迪斯·弗罗斯特上校在比灵顿网络安全公司主办的活动上发表讲话时做手势。(科林·德马雷斯特/C4ISRNET)
虽然部分部署与美国国内选举有关,但在立陶宛的行动则专门针对当时被认为存在的俄罗斯威胁。此次行动持续了三个月,标志着立陶宛网络部队与美国海外专家首次开展联合行动。
弗罗斯特说:“我们正在积极寻求与那些过去与我们关系不太密切的伙伴国家建立更紧密的联系。看到这种趋势的形成,真的令人兴奋。”
美国高级官员拒绝透露美国究竟计划如何打击和惩罚恶意网络攻击者。网络空间的军事行动通常都是秘密进行的,细节很少公开,更遑论及时披露。
总的来说,该战略的理念是将情报和军事力量(包括动能和非动能手段)与外交、金融和法律手段相结合,以遏制不法行为。这种强硬姿态可以被视为特朗普政府政策的延续,该政府曾赋予网络司令部更大的权力,并对俄罗斯和伊朗采取了网络行动。
一位不愿透露姓名的美国高级官员表示:“我们希望缩小人们可以肆无忌惮地进行恶意网络活动的范围,给他们施加压力,让他们的日子不好过一些。如果犯罪分子只能在俄罗斯境内活动,无法离开国境,那么或许就能起到一定的威慑作用。”
合作镇压
根除网络不法行为是一个崇高的目标,需要许多政府的合作、许多部门的协调以及许多有影响力的思想家的集结。
该战略预料到了这一点。拜登政府打算依靠志同道合的国家“来应对威胁”,执行网络规范,并开发“适用于数字时代的新型合作执法机制”。
2021 年 Colonial Pipeline 和 JBS Foods 遭受的破坏性勒索软件攻击日益普遍,而且这些攻击往往源自美国以外的地区。该蓝图引用了欧洲刑警组织于 2013 年设立的欧洲网络犯罪中心的成功经验,并承诺在其他地区推广该模式。
通用动力信息技术公司网络客户互动副总裁马特·海登表示,该文件超越了传统的“保护美国国内关键基础设施,通过与盟友合作,加大力度向国际上的不良行为者施加成本”。
他在周三的一份声明中说:“一个例子是与乌克兰的合作,该合作涉及共享网络威胁情报、工具和培训,以挫败攻击并维护具有弹性的关键系统。”
7 月,华盛顿和基辅同意加强网络安全关系,网络安全和基础设施安全局与其东欧对应机构——国家特殊通信和信息保护局达成协议。
该安排旨在扩大网络安全教育、联合演习和分享最佳实践的途径。
“我们需要确保我们做好准备应对各种威胁,应对针对我们关键基础设施的入侵,无论是国家支持的行动者、与犯罪分子勾结的勒索软件组织,甚至是级联攻击,例如在乌克兰发生的攻击可能会蔓延到俄罗斯或美国,就像我们在 2017 年看到的 NotPetya 事件一样,”拥有二十多年军事情报和网络经验的 CISA 主任 Jen Easterly 去年表示。
NotPetya恶意软件瘫痪了全球各地的重要系统,造成了巨大的经济损失。俄罗斯被指责应对这场灾难负责。与NotPetya类似,拜登政府的战略指出,俄罗斯的网络攻击“为了支持其2022年对乌克兰的残酷且无端的入侵,对其他欧洲国家的民用关键基础设施造成了不负责任的溢出效应”。
总统2023财年的预算申请中包括为网络安全和基础设施安全局(CISA)拨款25亿美元,比2022年申请的金额增加了约18%。该预算申请还包括为五角大楼网络安全拨款约112亿美元,比政府之前的申请增加了近8%。
拜登最新的2024年总统候选人提名预计将于本月晚些时候公布。
科林·德马雷斯特曾是C4ISRNET的记者,负责报道军事网络、网络安全和信息技术方面的新闻。此前,他曾为南卡罗来纳州的一家日报报道美国能源部及其下属的国家核安全管理局,主要关注冷战后的清理工作和核武器研发。科林还是一位屡获殊荣的摄影师。