In the first part of this series of articles, we discussed the nature of threats and cybersecurity, briefly addressing threats to infrastructure, military, economic, communication, and banking structures. This current article begins with the nature and domains of cybersecurity and concludes with a discussion from the perspective of national and international security strategy regarding cyber threats. Cybersecurity - many researchers define security as the absence of threats, and accordingly, they believe that cybersecurity is achievable in the absence of major cyber threats to systems, which consequently allows for the protection of cyber information. Cybersecurity is a set of tools, policies, security concepts, protective regulations, guidelines, risk management approaches, best practice training, protective technologies, and cybersecurity organizations, ultimately protecting the assets of users. This last aspect includes computing devices, computers, personal infrastructures, applications, services, telecommunications systems, and all information stored or ready for transfer among users in the cyber environment. Cybersecurity must secure all assets of organizations and users against threats in the cyber environment. In the shadow of cybersecurity: - Accessibility for all users will be ensured according to the type of access, - Integrity, authenticity, and non-repudiation of service can only be achieved in the presence of cybersecurity - Wherever necessary, confidential information must be preserved as such and made available to its specific users. Any violation of this principle is an infringement on cybersecurity. However, given the nature of cyber threats, the concept of cybersecurity expands into three domains. Each of these three domains can undermine part of cybersecurity: 1- Cyberterrorism, which aims to disrupt the free flow of technological communications for a short, medium, or long time. The success of cyberterrorism, to any extent, facilitates the presentation and dissemination of the thoughts and ideologies of terrorists, transforming the cyber arena into an ideological environment for terrorists. This type of cyber attack targets communication networks, computer systems, and telecommunications infrastructures. The frequency of such attacks is measurable, and according to statements from U.S. cyber command officials, such attacks have increased seventeenfold since 2009. 2- Cyberwarfare; during which any state utilizes its maximum cyber capabilities and technologies with the intent to destroy or incapacitate the cyber environment and systems of its rival. The United States and some other governments recognize cyberwarfare as the fifth domain of warfare, following land, sea, air, and space warfare. Cyberwarfare attacks are initially carried out by 'hackers' who are well-acquainted with the intricacies of computer networks. These experienced forces are prepared for battle under the supervision and support of the nation-state. The goal of cyberwarfare is not necessarily to shut down the opponent's computer system. Cyberwarfare can pursue broader objectives. It may aim to obtain valuable information, damage communication and telecommunications systems, harm infrastructure systems and services such as transportation and medical services, or disrupt trade. For example, during the war in South Ossetia in 2008, before the Russians invaded Georgian territory, a cyber attack was launched against the online resources of the Georgian government, rendering Georgian government websites inaccessible. At that time, the New York Times claimed in an article that a cybersecurity researcher in Massachusetts witnessed an attack on the cyber space of the Georgian government with the message: 'win+love+in+Russia.' Cyber attacks typically begin with a wave of distributed denial-of-service attacks aimed at making services inaccessible to users. This type of attack is essentially a calculated effort to simultaneously access a site, domain, or server. For this purpose, attackers use computer programming to simultaneously access a domain in such a way that the multitude of simultaneous and calculated requests saturates the response capability, effectively rendering it unable to respond to all requests at once. The result is a slowdown, and subsequently, a wave of calculated subsequent simultaneous attacks causes the domain to become inaccessible to users. At this moment, 'hackers display their message from the server'; in fact, the service request turns into a command for denial of service. Therefore, perhaps the closest Persian translation of this term is 'calculated denial-of-service attack.' In Iran, a group of hackers operates under the name of the Iranian Cyber Army. During the Georgia war, the website of Georgian President Mikheil Saakashvili was subjected to denial-of-service attacks simultaneously with Russian military actions against Georgian territory. This was the first time that military action coincided with a cyber attack. On the presidential website, images of Saakashvili were placed alongside images of dictators. Following this, communication and telecommunications domains, as well as the press in Georgia, were also attacked. Subsequently, the National Bank of Georgia was also targeted. According to the definition, this type of attack on resources that do not play a role in the decision-making of the opponent has a tactical or propaganda aspect. 3- Cyber espionage is another type of cyber threat. In short, cyber espionage means acquiring confidential information through technological means without the permission of the owner of the computer facilities. Cyber espionage can be carried out for various reasons or to achieve different objectives. Since 2010, U.S. officials have officially warned about the existence of a threat known as cyber espionage and confirmed its possibility. A report from the National Counterintelligence Executive Office published in 2011 confirmed that this type of espionage has the potential to undermine strategic and economic advantages of the country. Following this, Michael Chertoff, the then Secretary of Homeland Security, detailed how China undermines U.S. intellectual property through cyber espionage. China, due to its vast pool of cheap labor, has been able to incorporate several ideas obtained through cyber espionage into its national production cycle. Advanced industrial countries spend vast sums on research, development, and industrial innovation. Countries like China steal the costly investments in research and development from advanced countries and proceed to produce and supply the same goods in their domestic and regional markets, which constitutes a significant blow to strategic and economic resources. Recently, Pentagon officials reported that a Chinese cybersecurity company named Bo Yao Guangzhou Information Technology (Biosky) collaborates with its security, intelligence, and telecommunications officials and engages in cyber espionage. The information on the company's website indicates that it is based in Guangzhou and is active in assessing the security of local government information and evaluating software. Cybersecurity companies have also had a history of collaboration with security officials in Russia, and in the past, Russian cybersecurity firms have collaborated with that country's security officials. Both China and Russia are accused of engaging in espionage against critical and strategic U.S. infrastructure, including power networks, although espionage is not limited to economic resources. A week after the presidential election on November 8 in the U.S., NBC News reported on the comprehensive efforts of Russian espionage sites to obtain information related to the elections. A news headline regarding Russian cyber espionage sites stated: 'They want to see what happens before that event becomes policy and strategy.' In this context, non-Russian employees of two well-known American think tanks (Brookings Institution and Council on Foreign Relations), which are involved in analyzing and policymaking in U.S.-Russia relations, received suspicious emails. Six hours after Donald Trump's victory announcement in this year's election, a cyber espionage group named Volexity, believed to be based in Russia, sent phishing emails from a Gmail account with the username Harvard College of Arts and Sciences to think tanks and NGOs in the U.S., containing a Trojan backdoor virus to gather confidential information. The use of viruses for espionage and sabotage has a history. Hackers even attacked the National Security Agency and managed to steal technology from an agency that itself conducts cyber espionage. At the height of nuclear activities in Iran, multiple viruses were sent in various ways to users of computers in nuclear centers. Israel is one of the countries known for having very strong cyber espionage units, one of the most famous of which is Unit 8200, which is part of Israeli intelligence. The Stuxnet virus, which is said to have been produced in collaboration with the U.S., is one of the best or, depending on the perspective, the worst examples of cyber espionage in Israel. The Stuxnet virus inflicted irreparable damage on Iran's nuclear technology. Additionally, during the nuclear negotiations between Iran and the P5+1 in Switzerland, computer viruses were found in the hotels where the nuclear negotiations between Iran and the West were taking place, which were allegedly planted for espionage purposes regarding the content of the negotiations. This espionage has also been attributed to Israeli circles. The work of Unit 8200 is similar to that of the U.S. National Security Agency, which is part of the U.S. Department of Justice. The difference is that Unit 8200 has existed since the 1950s and has long been secret and underground. Another task of this unit is to train cybersecurity specialists. Many graduates of this unit have established their own cybersecurity companies. Gradually, Israel has become one of the most famous countries in the world active in cybersecurity and parallel to it in cyber espionage. Additionally, many viruses and antivirus programs are also developed in Israel. In recent months, cyber attacks for espionage purposes have also been reported from Iran. Although the target and nature of the attack are not very clear or have been kept secret, what we know is that Iranians hacked a water supply system in New York that supplies water to part of New York. Recently, Saudi Arabia accused Iran of being involved in the destruction of 35,000 computers in Saudi Arabia's oil industry (Aramco) and also claimed that a government agency in the energy and civilian air transport industries was targeted by 'Iranian hackers.' Although the core of the matter is under investigation, in recent days, fingers have been pointed at Iran. Some consider the timing of this 'hack,' which occurred just days before the OPEC oil agreement to reduce production, significant. Colin Anderson, an expert on Iranian hacking operations, suggests that the timing of this operation was intended to pressure Saudi Arabia to accept Iran's desired production cuts. Several reputable American cybersecurity companies like CrowdStrike, FireEye, McAfee, Palo Alto Networks, and Symantec have recently released documents indicating Iran's involvement in cyber attacks against an American casino. These attacks were carried out using a specific type of cyber weapon known as 'Shimon Shimon,' which acts like a time bomb. Apparently, this weapon was timed to operate during the presence of employees so that they could prevent its explosion. North Korea is also on the list of countries with cyber espionage programs. Although two years have passed, the final FBI report regarding the 'hack' of Sony Pictures has not yet been released, but there is a belief that North Korea was behind the cyber attack on Sony Pictures, which produced a satirical film about its leader, Kim Jong-un. In the cybersecurity program of President-elect Donald Trump, addressing cyber threats is a high priority, with Iran and North Korea being at the forefront of this effort. An important point that applies to all three cases of cyber threats is the role of the internet and the existence of internet connectivity for the realization of these threats. That is, if computer devices are not connected to the international internet, the possibility of realizing threats in the described forms, if not impossible, is minimized. For this reason, some countries attempt to engage in national internet projects, which is a very broad discussion and raises significant doubts about its application. Some cybersecurity experts believe that it is not necessary for your computer to be constantly connected to the internet. You can reduce vulnerability by disconnecting your computer from the internet and only connecting when needed. Naturally, this solution may be beneficial for personal computers, but in today's world, it is impossible to deprive thousands of working computers in a company of internet access. Cyber attacks are both a strategy and a tactic - as shown in various sections of this article and the previous one, cyber threats have become an undeniable reality in our daily lives. Our modern life is interconnected through a multitude of devices that have internal dependencies, and if one part of this connection is damaged, another part fails. At any moment, various and unimaginable aspects of our daily lives are exposed to cyber threats. In this regard, potential hackers target everything from gaming devices in a children's park to the most sophisticated hospital devices, energy infrastructures, security, and military systems. Airplanes or submarines and ships are also not immune.
Cybersecurity: From Theory to Strategy
The article discusses the nature of cybersecurity threats, including cyberterrorism, cyberwarfare, and cyber espionage, emphasizing their implications for national and international security. It highlights the increasing frequency of such attacks and the need for robust cybersecurity measures to protect critical infrastructure. The significance of these threats is underscored by the involvement of state actors like the U.S., Russia, China, and Iran.
👥 Key Players
⚡ Actions
📰 What Happened
Cybersecurity threats are escalating, impacting national and international security strategies.
- cyberterrorists attack communication networks, computer systems, telecommunications infrastructures
- state actors attack cyber environment, systems of its rival
- cyber attackers disrupt Georgia's government websites
💡 Why It Matters
📚 Background
Cybersecurity is a critical aspect of national and international security.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%