📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

Cyberwar | Amy Zegart | TEDxStanford

TEDx Talks16:54

Transcription

[Music] On November 24th, 2014, it was the Monday before Thanksgiving. Amy Pascal is driving to her Sony Pictures Studio office in Culver City, California. It's a day just like any other day for the Sony studio chief, until she turns on her computer. And there, on the screen, is an image of a creepy red skeleton with a message: hacked by #goop.

Now, at first, Amy Pascal thinks this has got to be some kind of joke. But it wasn't a joke; it was the beginning of a cyber nightmare so bizarre that not even Hollywood screenwriters could have imagined it. Now we know that the cyber attack was eventually attributed to the government of North Korea. It was one of the most damaging cyber attacks in American history, and it was perpetrated by one of the most isolated and poorest countries on Earth. The attackers stole and then publicly released terabytes of data from Sony, including vital trade secrets, yet-to-be-released movie scripts, salary and contract information, and personal information from thousands of Sony employees.

But the attackers didn't just steal; they destroyed. They wiped data from hard drives of thousands of Sony computers and servers. The attack forced Sony off the grid entirely, and the attack revealed private emails so embarrassing that Amy Pascal, one of Hollywood's most powerful executives, eventually had to resign. And then it got worse. The attackers darkly warned of 9/11 and they vaguely threatened violence in movie theaters if Sony went ahead with its planned release of the movie, *The Interview*, the comedy depicting the assassination of North Korea's leader, Kim Jong-un. President Obama got involved; the FBI began to investigate. And in the end, the Sony hack wasn't just about Sony anymore; it was a national security incident, an international crisis, and a sneak preview at the future of cyber warfare.

Now, just how serious are cyber threats to our nation as a whole, to our nation's economic vitality, to our national security? And how do leaders think about cyber threats in the context of other national security dangers that we confront in the United States? That's the story that I want to tell today, and the story starts by taking a look at the broader threat landscape that U.S. forum policy leaders have been confronting, uh, for the past several decades.

This is a picture of the threat environment during the Cold War. It's a picture of a medium-range Soviet ballistic missile, an SS-4, as it's being paraded through Red Square in Moscow. This particular photograph is a Central Intelligence Agency reference photograph that was used during the Cold War. During the Cold War, foreign policy leaders knew that they faced the grave prospect of nuclear Armageddon, but they also knew that they faced a single principal adversary. They knew who that adversary was; they knew where that adversary was; and they had a pretty good idea of the Soviet Union's intentions and its capabilities. After all, the Soviets are parading their nuclear weapons through Red Square, and they're operating at the bureaucratic speed of five-year plans.

This is a picture of the threat environment today. It's more crowded and more uncertain and more complicated than any time in modern American history. It's filled with rising states, declining states, weak states, failed states, rogue states, non-state actors ranging from ISIS to Anonymous, and transnational threats like global climate change. And the threat environment isn't just more crowded or complicated today; it's changing faster than ever before, too. Every year, the Director of National Intelligence issues a public threat assessment where he runs down the list of dangers confronting the country. In 2007, not that long ago, that threat assessment did not put one word in it about cyber—not one. As late as 2009, cyber threats were so far down the list they were right near the bottom, just after drug trafficking in West Africa. Not anymore. Cyber threats in the past few years have vaulted to the top of the threat list, and today many experts and government officials are worried about three classes of cyber attacks or threats to our country.

The first is the massive theft of intellectual property from American corporations that could degrade our economic competitiveness for generations. The second is attacks that could inflict massive disruption on our way of life in ways that we have never imagined before. And the third is cyber attacks that could degrade, disable, or destroy our nation's military ability to defend itself or to attack if our vital interests are threatened. The threat environment today is crowded; it's complicated; and it's uncertain; and it's changing at the speed of cyber. Cyber threats are a part of this threat environment, and they're new, but they're also very different from other traditional national security threats. And they're different in five key ways that I want to talk about with all of you.

The first key difference between traditional national security threats and cyber threats is that the United States is simultaneously the most powerful country in cyberspace and the most vulnerable country in cyberspace. And that's different. In the military, we often talk about domains. The military talks about the air domain, the land domain, the sea domain. And in those physical domains, the countries that have the most weapons and the most sophisticated weapons are the most powerful. But that's not true in cyber. The United States has the most sophisticated offensive cyber capabilities of any nation in the world, and yet we, in the United States, are the most vulnerable. Why? Because we're the most connected. We rely on networks and connectivity for our economy, for our civil society, for our government, for our military in tremendous and wide-ranging ways. Our connectivity is the source of our strength and the source of our weakness.

The second major difference between traditional national security threats and cyber threats is that in cyberspace the U.S. government cannot go it alone. And this, too, is new. In every other security realm, the government is considered the legitimate monopoly provider of security. Now, what do I mean by that? If you think about how you want safe streets in your neighborhood, you pick up the phone; you call the police. The police—the government—legitimate monopoly provider of security for safe streets in your neighborhood. Well, the same thing is true if you want a safer country; if if you want to secure your country from foreign attack, you strengthen your military—legitimate monopoly provider of security. But in cyberspace, it doesn't work that way, because 85% of our nation's critical infrastructure is not owned by the U.S. government; it's owned and operated by the private sector. Our power system, our telecommunications networks, our financial system—owned and operated by private actors. The government can't defend those sectors from attack by itself. The government can't go it alone.

Now, the third key difference between traditional national security threats and cyber threats is that in cyberspace the attack surface is huge. There are no safe neighborhoods in cyberspace. One senior military official described cyberspace to me this way: He said, "Imagine that there's a street in cyberspace that runs through the best parts of town and the worst parts of town all at the same time." And on this street in cyberspace, people are doing the exact same things they're doing in the physical world: They're going shopping; they're going to their bank; they're watching movies; they're visiting friends. But there are also people on this street that are robbing banks, selling drugs, mugging people, committing all sorts of other crimes. Good guys, bad guys—they're all there together; they're all connected. There are no safe neighborhoods in cyberspace.

Now, in part, this is because the internet was never designed to create safe neighborhoods in cyberspace. It was designed by a handful of researchers, including some right here at Stanford, to connect each other—a handful of people who knew each other, trusted each other, and wanted to share their work with each other. Only now there aren't a handful of researchers on the internet; more than 40% of the world is on the internet, and internet traffic is expected to triple in the next 3 years alone. And then there's the growing internet of things. We are moving to a world where we are going to have appliances that are so smart they turn themselves on when power rates are low and they remind us to buy milk before we run out. We're moving to a world of driverless cars and implantable medical devices that can transmit vital data about our bodies directly to our doctors. The growing internet of things is incredible, but it comes with a dark side, and that dark side is called vulnerability, because anything that is smart is vulnerable.

Now, technologists and computer scientists have a rule of thumb, and that rule of thumb is that when it comes to code, there is one defect for roughly every 2,500 lines of code. Okay, one defect roughly every 2,500 lines of code. Think of it as a chain-link fence where every 2,500 links in that fence there's a weak link or a missing link, right? One defect for every 2,500 lines of code. And think about the cyber bad guys that are out there; they're like the velociraptors in the movie *Jurassic Park*—anyone remember them—always trying to get out, out of the fence. So the cyber bad guys are out there, and they're spending every minute of every day testing the fence, penetrating the fence, looking for that one in every 2,500 links that might be weaker, missing, so they can get through. Okay. Now consider this: If you have an Android phone, that phone has 12 million lines of code making it do all those great things. That's nearly 5,000 inherent vulnerabilities in the code—not malicious vulnerabilities, just mistakes or oversights or weaknesses that are inherent in the code that the coder never thought about. If you have a Windows operating system on your computer, that's 40 million lines of code. The attack surface in cyberspace is huge.

That leads to the fourth difference, which is that in cyberspace victims often don't even know that they're victims until sometimes long after the fact. The Home Depot breach that made headlines in 2014 wasn't discovered until 5 months after it began. One study found that 85.5% of cyber breaches were discovered weeks after they occurred, and more than 90% of them were discovered by third parties, not the victims themselves. The military is not immune from this challenge either. The worst publicly revealed breach in U.S. military history occurred in 2008 when an infected thumb drive was placed inside a U.S.—a device inside a U.S. military installation in the Middle East. A foreign intelligence service had put on that infected thumb drive something called a worm, and that worm spread malicious code from computer to computer and eventually accessed classified and unclassified networks. And that malicious code also directly sent that information directly to a server under foreign government control. And all of this was going on for 14 months before it was detected by the Pentagon—14 months. This was a wake-up call for the Department of Defense. Victims often don't know their victims until long after the fact.

That leads to the fifth and final difference between traditional national security threats and cyber threats, and that difference has to do with warning time before an attack and response time after an attack. Now, throughout history and warfare, there's usually been a long lead time for potential warning before an attack occurs, and this is because moving people and equipment across territory takes time; it takes effort. And that means there are often telltale signs that an adversary might be up to no good, like massing troops along the border. Once an attack occurs, however, response can be swift, because in the physical world, of course, we usually know who attacked us and we know where they are. So long warning time before an attack, short response time after an attack. In cyber, it's flipped: no warning time before an attack, but response is hard, and sometimes it takes a long time. Why? Because of attribution. Attribution, or figuring out who's actually responsible for a cyber attack, is sometimes fast, but usually it's not, because even if you know the computer or the server where the attack originated, figuring out who's typing behind that keyboard, what's their relationship to a company or an organization or a foreign government, is much, much harder. So these timing differences have pretty significant implications for how we think about defense and deterrence in a cyber age, and we're just beginning to figure that out now.

How does the real cyber movie end? I don't know. But the Nobel laureate Tom Schelling once warned, "We should be very careful about confusing the unfamiliar with the improbable." The Sony attack was bizarre, but for most of us it wasn't particularly scary. For most of us, we think about cyber threats of today like this: The cyber threats of today are about our information; it's about people who steal our credit cards; it's about making access to our computers and our smartphones harder; it's about—remember how to remember those passwords. Now, the cyber threats of today are annoying; they're not alarming. But the cyber threats of tomorrow won't just make our information unsafe; they could make our physical world unsafe, too. The cyber threats of tomorrow could disable the cars that we drive, the airplanes that we fly; they could turn off power or water to cities across the country for days or weeks or longer; they could incapacitate our military or even turn our own weapons against us. The cyber threats of tomorrow could affect anything that requires a networked computer to operate, and increasingly that means everything. Thank you very much.