Demilitarize civilian cyber defense, and you’ll gain deterrence将民用网络防御非军事化,就能获得威慑力。
By constantly flexing the military’s cyber muscles to defend the homeland from inbound criminal cyber activity, the public demand for a broad federal response to illegal cyber activity is satisfied. Still, over time, the potential adversary will understand our military’s offensive cyber operations’ tactics, techniques and procedures.

U.S. Defense Department cyber units are incrementally becoming a part of the response to ransomware and system intrusions orchestrated from foreign soil. But diverting the military capabilities to augment national civilian cyber defense gaps is an unsustainable and strategically counterproductive policy.
The U.S. concept of cyber deterrence has failed repeatedly, which is especially visible in the blatant and aggressive SolarWinds hack where the assumed Russian intelligence services , as commonly attributed in the public discourse, established a presence in our digital bloodstream. According to the Cyberspace Solarium Commission, cyber deterrence is established by imposing high costs to exploit our systems. As seen from the Kremlin, the cost must be nothing because blatantly there is no deterrence; otherwise, the Russian intelligence services should have restrained from hacking into the Department of Homeland Security .
After the robust mitigation effort in response to the SolarWinds hack , waves of ransomware attacks have continued. In the last years, especially after Colonial Pipeline and JBS ransomware attacks, there has been an increasing political and public demand for a federal response. The demand is rational; the public and businesses pay taxes and expect protection against foreign attacks, but using military assets is not optimal.
Presidential Policy Directive 41 , titled “United States Cyber Incident Coordination,” from 2016 establishes the DHS-led federal response to a significant cyber incident. There are three thrusts: asset response, threat response and intelligence support. Assets are operative cyber units assisting impacted entities to recover; threat response seeks to hold the perpetrators accountable; and intelligence support provides cyberthreat awareness.
The operative response — the assets — is dependent on defense resources. The majority of the operative cyber units reside within the Department of Defense, including the National Security Agency, as the cyber units of the FBI and the Secret Service are limited.
In reality, our national civilian cyber defense relies heavily on defense assets. So what started with someone in an office deciding to click on an email with ransomware, locking up the computer assets of the individual’s employer, has suddenly escalated to a national defense mission.
The core of cyber operations is a set of tactics, techniques and procedures, which creates capabilities to achieve objectives in or through cyberspace . Successful offensive cyberspace operations are dependent on surprise — the exploitation of a vulnerability that was unknown or unanticipated — leading to the desired objective.
The political scientist Kenneth N. Waltz stated that nuclear arms’ geopolitical power resides not in what you do but instead what you can do with these arms. Few nuclear deterrence analogies work in cyber, but Waltz’s does: As long as a potential adversary can not assess what the cyber forces can achieve in offensive cyber, uncertainties will restrain the potential adversary. Over time, the adversary’s restrained posture consolidates to an equilibrium: cyber deterrence contingent on secrecy. Cyber deterrence evaporates when a potential adversary understands, through reverse engineering or observation, our tactics, techniques and procedure.
By constantly flexing the military’s cyber muscles to defend the homeland from inbound criminal cyber activity, the public demand for a broad federal response to illegal cyber activity is satisfied. Still, over time, bit by bit, the potential adversary will understand our military’s offensive cyber operations’ tactics, techniques and procedures. Even worse, the adversary will understand what we can not do and then seek to operate in the cyber vacuum where we have no reach. Our blind spots become apparent.
Offensive cyber capabilities are supported by the operators’ ability to retain and acquire ever-evolving skills. The more time the military cyber force spends tracing criminal gangs and bitcoins or defending targeted civilian entities, the less time the cyber operators have to train for and support military operations to, hopefully, be able to deliver a strategic surprise to an adversary. Defending point-of-sales terminals from ransomware does not upkeep the competence to protect weapon systems from hostile cyberattacks.
Even if the Department of Defense diverts thousands of cyber personnel, it can not uphold a national cyber defense. U.S. gross domestic product is reaching $25 trillion; it is a target surface that requires more comprehensive solutions.
First and foremost, the shared burden to uphold the national cyber defense falls primarily on private businesses, states and local government, federal law enforcement, and DHS.
Second, even if DHS has many roles as a cyberthreat information clearinghouse and the lead agency at incidents, the department lacks a sizable operative component.
Third, establishing a DHS operative cyber unit is limited net cost due to higher military asset costs. When not engaged, the civilian unit can disseminate and train businesses as well as state and local governments to be a part of the national cyber defense.
Establishing a civilian federal asset response is necessary. The civilian response will replace the military cyber asset response, which returns to the military’s primary mission: defense. The move will safeguard military cyber capabilities and increase uncertainty for the adversary. Uncertainty translates to deterrence, leading to fewer significant cyber incidents. We can no longer surrender the initiative and be constantly reactive; it is a failed national strategy.
Jan Kallberg is a research scientist at the U.S. Army Cyber Institute. The views expressed are those of the author and do not reflect the official policy or position of the Army Cyber Institute, the U.S. Army or the U.S. Defense Department.
美国国防部网络部队正逐步参与应对来自境外的勒索软件和系统入侵。但将军事能力转移到弥补国家民用网络防御漏洞上,是一种不可持续且在战略上适得其反的政策。
美国的网络威慑理念屡屡失败,这一点在公然且咄咄逼人的SolarWinds黑客攻击事件中体现得尤为明显。据公众普遍认为,幕后黑手是俄罗斯情报机构,他们成功地渗透到我们的数字系统中。根据网络空间日光浴委员会的说法,网络威慑的建立在于对攻击我们系统的攻击者施加高昂的成本。然而,在克里姆林宫看来,这个成本必须为零,因为显然不存在任何威慑;否则,俄罗斯情报机构就不会入侵美国国土安全部。
在针对 SolarWinds 黑客攻击采取强有力的缓解措施之后,勒索软件攻击浪潮依然持续不断。近年来,尤其是在 Colonial Pipeline 和 JBS 勒索软件攻击事件发生后,公众和政界人士越来越呼吁联邦政府采取应对措施。这种呼声合情合理:公众和企业缴纳税款,理应受到保护,免受外国攻击,但动用军事力量并非最佳选择。
2016 年发布的第 41 号总统政策指令,题为“美国网络事件协调”,确立了国土安全部牵头的联邦政府应对重大网络事件的机制。该机制包含三个重点:资产响应、威胁响应和情报支持。资产响应是指协助受影响实体恢复的作战网络部门;威胁响应旨在追究肇事者的责任;情报支持则提供网络威胁预警。
实际应对措施——即所需资源——取决于国防资源。大多数网络作战部队隶属于国防部,包括国家安全局,因为联邦调查局和特勤局的网络部队规模有限。
事实上,我国的民用网络防御严重依赖国防资产。因此,最初只是办公室里有人点击了一封带有勒索软件的电子邮件,导致其所在单位的电脑系统被锁定,如今却突然升级为一项国家防御任务。
网络作战的核心是一套战术、技术和程序,它能够帮助作战单位在网络空间内或通过网络空间实现目标。成功的网络空间进攻行动依赖于出其不意——即利用未知或未预料到的漏洞——从而达成预期目标。
政治学家肯尼斯·N·沃尔兹指出,核武器的地缘政治力量不在于你做了什么,而在于你能用这些武器做什么。核威慑的类比很少适用于网络空间,但沃尔兹的类比却很适用:只要潜在对手无法评估网络部队在进攻性网络空间所能取得的成就,不确定性就会限制潜在对手的行动。随着时间的推移,对手的克制姿态会逐渐趋于平衡:网络威慑依赖于保密性。一旦潜在对手通过逆向工程或观察了解了我们的战术、技术和程序,网络威慑就会消失。
通过不断展现军方的网络实力,保卫国土免受网络犯罪活动的侵害,公众对联邦政府全面应对非法网络活动的诉求得到了满足。然而,随着时间的推移,潜在的对手会逐渐了解我军进攻性网络行动的战术、技术和程序。更糟糕的是,对手会了解我们的局限,然后试图在我们无法触及的网络真空地带开展行动。我们的盲点将暴露无遗。
网络进攻能力依赖于操作人员不断更新和掌握技能的能力。军事网络部队花费在追踪犯罪团伙和比特币或保护特定平民实体上的时间越多,网络操作人员用于训练和支持军事行动的时间就越少,也就难以对对手发动战略性突袭。保护销售终端免受勒索软件攻击并不能维持保护武器系统免受敌方网络攻击的能力。
即使国防部调集数千名网络安全人员,也无法维护国家网络防御。美国国内生产总值已达25万亿美元,这是一个亟需更全面解决方案的目标区域。
首先,维护国家网络防御的共同责任主要落在私营企业、州和地方政府、联邦执法部门和国土安全部身上。
其次,尽管国土安全部承担着网络威胁信息交换中心和事件牵头机构等诸多角色,但该部门缺乏规模可观的行动部门。
第三,由于军事资产成本较高,建立国土安全部网络作战部门的净成本有限。在非作战阶段,该民事部门可以向企业以及州和地方政府传播和培训知识,使其成为国家网络防御的一部分。
建立一套民事联邦资产响应机制势在必行。这套民事响应机制将取代军事网络资产响应机制,使军事部门回归其首要任务:防御。此举将保障军事网络能力,并增加对手的不确定性。不确定性本身就是一种威慑,能够减少重大网络事件的发生。我们不能再放弃主动权,被动应对;这种做法是失败的国家战略。
Jan Kallberg是美国陆军网络研究所的研究科学家。文中表达的观点仅代表作者个人观点,并不反映陆军网络研究所、美国陆军或美国国防部的官方政策或立场。