Sea Control - Sea Control 293 - Cyber Threats & Chokepoints with Dr. Diane Zorri & Dr. Gary Kessler
Episode Date: November 14, 2021Links1. "Cyber Threats and Choke Points: How Adversaries are Leveraging Maritime Cyber Vulnerabilities for Advantage in Irregular Warfare," by Dr. Diane Zorri and Dr. Gary Kessler, Modern Warfare Inst...itute, September 8, 2021.2. Cross Domain IW Threats to SOF Maritime Missions: Implications for U.S. SOF, by Dr. Gary Kessler and Dr. Diane Zorri, Joint Special Operations University Report 21-4, 2021.
Transcript
Discussion (0)
Hey folks, Anna here. Thanks for tuning back in to Sea Control. Today we're talking with
Dr. Diane Zori and Dr. Gary Kessler about their recently published article, Cyber Threats
and Choke Points, How Adversaries are Leveraging Maritime Cyber Vulnerabilities for Advantage
in Irregular Warfare, which was published online by the Modern War Institute. And as
always, we want to advertise and strongly recommend our friends in the SimSec Podcast
Network and our second podcast feed, The Bilge Bumps. You can find Alex, Drac, Jamie, and
a pile of empty iron brew bottles on Apple Podcasts, Stitcher, Spotify, or wherever else
you download your podcasts from. It's a more low-key, slightly less serious approach to
current events in the maritime domain and naval history.
Diane and Gary, thank you for joining us today. Would you please tell our audience a bit about
yourselves and your background. Thank you so much for having me. It's a true pleasure.
My name is Diane Zori. I am an assistant professor at Embry-Riddle Aeronautical University in Daytona
Beach, Florida. I teach in the security studies and international affairs department. Prior to
working at Embry-Riddle, I was a professor at a university in Italy called John Cabot.
And before that, I was in the defense industry.
And even before that, I was an Air Force officer.
I teach mostly classes on terrorism, international relations, Middle Eastern studies, homeland
security, and I freelance as a fellow at Joint Special Operations University.
And this year, I'm actually a fellow with the Modern War Institute at West Point, New
York.
Well, hello, everybody.
Also, like Diane, I'm thrilled to be here.
My name is Gary Kessler.
I have been involved in information security, oh, since the late 1970s.
My academic background is in mathematics and computer science.
Professionally, I've spent four decades dealing with data communications and information security.
It has been a growth industry for the last 45 years.
I'm a retired professor of cybersecurity from Embry-Riddle Aeronautical University, where
I worked in the same department as Diane.
I'm also a principal consultant at Fathom5.
I'm a non-resident senior fellow at the Atlantic Council, and I'm chief of the cyber augmentation branch for the U.S. Coast Guard Auxiliary.
I co-wrote a book on maritime cybersecurity that came out just about a year ago.
I'm also a guest faculty member in the electrical engineering and cyber systems section at the U.S. Coast Guard Academy.
That, and I am a scuba instructor with a captain's license, so that explains why I live in Florida.
Thank you both. And as a reminder to our listeners, all views expressed are our own and not representative of any institution with which we might be otherwise associated. So can you both tell me what other published work or events prompted you to write this article?
Sure. So this was a little bit of a deviation for me. Most of my writing is really focused on U.S. foreign policy, military, and lately I've been writing a lot on the applicability of different sort of frameworks to special forces.
So I've written about proxies in the Middle East, I've written about different things that are affecting special operators. This came about partially because of my work with Joint Special Operations University, but it paired well with the department.
I wrote a piece about the vulnerabilities of small UASs. And then this opportunity came up, it was really Gary Kessler's idea, and I'll let him talk about that. You know, I was assisting him with the sort of applicability to the special operator, because that's more of my expertise.
So I did a sabbatical at the Coast Guard Academy a couple years ago. And in early 2020, when I got back, I was indeed talking to Diane about the issues of maritime cyber, which is a field that I've actually now been involved in for about four, four and a half years.
But we were talking about what kind of work it is we're doing, and we quickly realized that there's an intersection to cybersecurity threats to warfare in the littoral waters.
And part of the whole concept of asymmetric warfare, at least for terrorists, is that they're starting to use the near shore water as one of their avenues of attack.
and they're never going to take on our Navy in blue water, but they certainly might attempt to
in brown water and cybersecurity issues that might be minimal or have minimal impact in the
middle of the ocean might have a big impact once you get nearer to ports and near shore.
And all of a sudden we realized that we had a new thing to write about, which as Diane said,
brought us into writing the JSAO paper, which came into this later paper. And so is your article
about irregular warfare, warfare in the cyber domain, cybersecurity resilience, or all of the
above and how so? Well, a little bit of it was a little bit of all of those things. It's not
warfare in the cyber domain as we typically will think about it. Cyber weapons from one country,
cyber weapons with another. Like I said, since we were really talking about irregular warfare
and certain aspects of asymmetric software, it was talking about what things in the cyber domain
could make one of our adversaries, either a terrorist organization or a small nation state,
be able to minimize the advantages that we have via a cyber vector, such as attacking GPS or
attacking AIS or other situations where, in fact, our vessels have less maneuverability and or a
small error can cause really big results. Yeah, you know, the framework now is that we're pivoting
towards a different kind of grand strategy or grand strategic construct, and that's the great
power competition. And as we pivot towards that paradigm, what we're seeing is a lot of activity
and conflict taking place, not necessarily kinetic warfare, but in these gray zones.
And so there's a lot of plausible deniability, you know, which state is perpetuating these
things?
Are they just proxious actors that are not linked to any state?
And we saw this as an opportunity to really bring to light some of the real challenges
that we're going to be facing as we pivot towards this era of great power competition,
that conflicts aren't going to go away.
They're just going to look a little bit different.
So what cyber vulnerability worries you the most in the maritime, Demi?
So there's actually a long list of them.
We focused a little bit on things related to GPS and AIS because in some sense, it's
the most common type of thing that is going to impact, if you will, a military audience.
So if I stick with GPS and AIS for a bit, the ability to jam GPS is almost trivial and
is well within the reach of any of the adversaries that we have. GPS spoofing is a little bit harder,
but again, it is well within the capabilities of any of the nation states with whom we are
adversaries. And indeed, there are a bunch of reports that are already talking about how Russia
and China and Iran and North Korea have already engaged in GPS spoofing activities. And since so
many of the terrorist organizations are actually proxies for some of these nation states, it
basically means that GPS spoofing is within the reach of any adversarial force that we have to
deal with. AIS spoofing, of course, the automatic identification system, is the system that gives
vessels situational awareness when they're at sea. And not only vessels, but also maritime
administrations. And it is, again, very trivial to spoof AIS, primarily because there are no security
protections that have been built in. So for example, when an AIS signal is transmitted,
there's no authentication to prove to anybody that if I'm purporting to be a certain vessel,
I'm actually that vessel. There's also no timing built into the system so that you know when a
message is being sent, it's actually current. And then there's also other errors. Can I really prove
that this message is correct? And the one that was actually transmitted. So on the one hand,
We want to train our mariners to be able to maneuver their vessels using a seaman's eye.
But if you're getting GPS spoofed while you're in the middle of the ocean at night, obviously you have quite a reliance on your global navigation satellite systems.
And so I sort of alluded to earlier that a small air in blue water that you could sort of ignore being, you know, 100 meters away from where you really think you are.
Once you get into brown water, you can obviously have some much bigger problems there.
And one of the examples, and the timing just worked out for Diane and I to use this as an example, were the events that went on in the Black Sea last June during the NATO exercises, where a British ship, a Dutch ship, and later a U.S. warship, all were shown to have AIS tracks,
showing them leaving Odessa and going right to Sevastopol in Crimea and being two miles offshore.
And Russia then using this as the ability to rattle a saber and say, this were provocative
acts, these could lead to acts of war, when in fact, there's third party evidence that shows
that those vessels never left their port. Again, it is so easy to spoof AIS that at the DEFCON
meeting last August, I gave a demonstration showing a Russian cruiser two miles off of
Port Canaveral because, well, it's easy enough to do that kind of stuff.
Cyber is a really, really big field, and the maritime transportation system is more than
ships, and it's more than ports, and it's more than GPS and AIS, and so you have to
look at the much broader system of systems of the MTS, where you also have my shipping lines,
I've got people, cargo, intermodal transfers, inland waters. And now I'm worried about a whole
bunch of other things. We hear about ransomware all the time. That's big, big news. But a bigger
problem in the maritime transportation sector are things like phishing and other kind of just
standard hacking events that happen against maritime companies. We are in a system that is
using vessels that are very old, and they're using communication protocols that are very old.
And almost all of them do not have built-in security. So the shipboard networks are not
internally secure. We have unencrypted satellite communications. And then there's more and more
of a drive throughout the community. And although this is primarily in the commercial community
for autonomous vessels, not just adding certain autonomous systems on ships or more and more
automation, but now we're talking fully autonomous vessels. Of course, all of this relies on
operational technology, industrial control systems, other cyber physical systems. And,
you know, my background is in computer science. So I know and fully believe that I can build
autonomy into a vessel and safely get that vessel from any sea buoy to any other sea
buoy in the world.
But these systems are not, at least in an obvious sense, being built with the cyber
protections against an intelligent adversary who's trying to break into those vessels and
have them do, you know, untoward things.
So that's what keeps me up.
The article mentions that advances in the integration of technology have greatly enabled
US forces, but without fully functional ancillary systems or the fundamental knowledge of how and
why these systems were designed, it leaves them vulnerable to cyber attack. Do you want to
elaborate on that at all? Sure. So I think this goes without question and it even goes beyond
just this particular subject. As humans are evolving and as the next generation is onboarding
into the military, a lot of times they're skipping generations of technology that enabled them to
really understand what is going on. And so a simple example would be using a calculator without
even understanding how to do addition if the calculator was to break. So if you don't understand
the fundamental principles of navigation without all of the equipment, then you're vulnerable in
the sense that if that equipment isn't working, you don't know that it isn't working. You don't
know that it might be a little bit off. And so just having that fundamental skill is very helpful.
And in fact, there are some institutions that are going back to some of the basics like
celestial navigation, just so you understand the premise if your technology is failing
you.
Another part of that is as we integrate more and more equipment for the warfighter, this
hyper-enabled operator.
But as you do that, you open up more points of failure if one component piece is not to
work or one component piece gets hacked or one component piece has malware or ransomware
or some sort of bug built into it, now you're even more vulnerable.
So all of that efficiency, all of those great things then become a huge liability.
So I would add a slightly different perspective.
I mean, I agree with everything that Diane just said.
But when it comes to cybersecurity and the human element, we're very, very quick to talk
about humans being the weakest link in security and certainly in cyber, the weakest link in
cybersecurity.
And in some ways, I think we're too quick to blame people.
I don't think that people are necessarily the weakest link in cybersecurity.
They're certainly the least understood link.
And indeed, people are a great target.
I mean, social engineering attacks work.
But blaming the user for failures of a cybersecurity or even a physical security system somehow
implies that the system was perfect and it worked in the first place and the user's presence
just screwed it up.
So, I mean, to Diane's point, consider the collisions of the Fitzgerald and McCain in 2017. Some of the elements that came out in the investigation of that was you had an overly complex human machine interface and inadequate training.
People just didn't even understand the interface. And again, it goes right to the heart of what Diane is saying. People don't know how to do the basics by hand. Therefore, they don't understand when the automated system is not doing what they want it to do or think it should do.
So we've talked about the human in the loop. Is there any risk mitigation policy or frameworks out there which have been put in place to try and help manage the equipment vulnerabilities for ships?
I think, unfortunately, the mitigation is the exact thing that Diane talked about, is getting back to the basics and the fundamentals of understanding what the machines are telling you in the first place.
I remember about six years ago when the Navy ROTC Commander Riddle told me, hey, the Navy is bringing back sextant training.
Because again, Diane alluded to the fact about 20, 25 years ago, they dropped it.
My friends at the Coast Guard Academy proudly tell me they never stopped teaching sextants.
And we have some great systems that can truly augment people, but sometimes people are at a loss when those systems go away because they never knew how to do it before.
I mean, I'll give you a silly example. When I was in graduate school in the mid-70s, I was on a mountain rescue team in Arizona. And we used to communicate each other by pulling on the rope. So the number of pulls signaled a message between the person at the top and the person at the bottom. Then we got radios. And from that point on, we had an entire generation of mountain rescuers who did not know how to pull on a rope and what a rope pull meant. And if the battery died on the radio, they were in trouble. And we continue to see that kind of stuff.
Well, and you know, I will say, sometimes the left hand doesn't know what the right hand is doing. And I'll just give you an example. China does a lot of manufacturing, and they have all kinds of products that are embedded across our military. We have tons and tons of Chinese parts.
Some of these parts and some manufacturers have actually been banned by the NDAA, but yet, you know, sometimes the defense procurement offices haven't caught up with that yet.
And so you'll still see these products out there.
One example that comes to mind is, are these cameras?
And so these cameras, a lot of them have malware and spyware on them, and they even get white labeled.
So white labeling is when the manufacturer knows that they've been banned, but they just sell the generics to another company and then that company throws their label on it.
And so those cameras still end up on ships.
They end up, you know, in different places.
And, you know, sometimes it takes a few years for different agencies will get involved and be like, hey, these are actually illegal products.
And by then they've already gone through the procurement cycle.
So yeah, it's really going to be a whole of government effort, I think, to get behind some of the things that are going on in terms of cyber vulnerabilities. Because, I mean, you look at that supply chain, there are component parts all the way up and down the chain that can be compromised. And at different points in that chain, they can be compromised. So it really turns into a bigger effort than just a Navy effort or a DOD effort. It's really like a whole of government effort in order to mitigate this problem.
shifting gears here, how can maritime shipping or really any business operating today protect
itself against the cost of a cyber attack? When I hear that question, I actually hear
two questions. One of the questions is how do I protect myself against a cyber attack?
And then how do I deal with the costs? To protect yourself against a cyber attack,
people need to understand how to do basic cyber 101. What are the fundamental things you need to
do to keep yourself safe. One of the big focuses has to be on user awareness and training. Even
simple things. If you get an email asking you to do something that sounds weird, don't do it. Talk
to somebody first. And you need to have management support that when you didn't do that weird
sounding thing, we got your back. Don't click on attachments. Don't go to weird websites.
It seems obvious, but it's not. We need to have staff awareness on not only our information technology side, but it's important to realize that information security is not the function of the information technology department.
The information technology department has to put out good technology that serves the needs of the users and needs to build networks properly and all that kind of stuff. Securing those networks is a different skill set and has to be managed by somebody else. So neither information security, no information technology are subservient to each other, but they're parallel efforts.
I think also we have to stop quoting the mantra, it's not a matter of if but when you're going to have a cyber attack, because what that does is it gives us the mindset that no matter what we do, we can't stay safe.
Oh, and by the way, therefore, when something bad happens, it's not really our fault because there was no way to stay safe.
There is always some low-level cyber attack going on on all of us all the time, but it's not inevitable that you're going to be victimized by a killer cyber attack.
I think one of the other things we need to realize is that cybersecurity, just like physical security and just like real life, it's an exercise in risk assessment and risk management.
So, for example, what that means is when we're looking at risk, I need to differentiate the difference between a threat and a vulnerability.
And there's a maxim in the information security world called the vulnerabilities trump threats maxim.
And it basically says vulnerabilities are internal.
You should be able to go through your systems and find the weaknesses in your systems.
And when you find them, you should fix them.
Whereas threats are something that's external.
Maybe you can identify a threat, but you can't control the threat because you don't know
who all the bad guys are, and you don't know all the things that the bad guys might want
to do for you.
In understanding our vulnerabilities, we also need to differentiate between what's a vulnerability
and what's an exploit because not all vulnerabilities can be exploited.
So it means that we really have to take the mindset of a bad guy and pretend if a bad
guy knew everything about my network and my system that I did and was smarter than me,
how would they attack my system? Now, that may not be true that the bad guy knows everything
that you do and is smarter, but that's the way to plan. The second part of the question was,
how do you protect yourself against the cost of a cyber attack? Well, ironically, there's not a
lot you can do. Some people will get cyber insurance. And ironically, we're now having
attackers that are hacking into the cyber insurance companies to find out who has cyber
insurance, because those companies are most likely to pay in case they get hacked, which,
like I said, I mean, this is the picture definition of irony, I suppose.
And the last thing I would say about that is before anybody tries to do nothing or tries
to justify cybersecurity expenses by doing some form of return on investment type of
analysis, cybersecurity is not an asset, and you can't measure it the way you measure
assets and their return.
And I propose that people look instead at the return on negligence.
If you don't take the proper protections, what's going to be the cost consequence of
you, in fact, having a cyber incident?
In some cases, particularly for commercial mariner organizations, things like the Privacy Act in the EU, they can levy very, very stiff fines against a company who the EU determines is not taking appropriate protection.
So like I said, the return on negligence is by not taking all the appropriate protections, you can get hit with some very, very heavy fines.
And when you say cost, you're thinking specifically about monetary cost?
Yeah, and of course, the monetary costs, including the tangible and the intangible,
but yes, absolutely.
And this might be a good chance to segue into a question I've had for a while now, which is,
what's the nexus between irregular warfare and cyber operations? Is it all about making
someone else incur costs, or is there another way that you can look at this problem?
When I look at irregular warfare, you're really looking at warfare outside the conventional realm.
I think there's so much discussion about this right now. You hear the terms, the domains. So there's the land domain, the air domain. Well, then you have the cyber domain. I mean, this domain is really everywhere.
It's becoming very important as we do this pivot to great power competition, where the great power competition isn't necessarily happening inside the great powers.
A lot of it is happening outside the great powers in third countries, in places like cyberspace.
And so this nexus with cyber and irregular warfare, the cyber domain is a great space.
If you want to compete, if you want to have conflict, if you want to have plausible deniability, if you want to do damage to your competition without taking it into the kinetic realm.
So that's really that nexus. It's a place to fight. It's a place to compete. It's a place to spy. And so in some ways, it's back to the future. We're going back to some of our Cold War thinking.
And in another way, the technology has changed.
The world has completely changed since the Cold War.
So we're having to come up with new frameworks for how we understand this new era.
But a lot of the principles are still the same.
It's just different battlefields, so to speak.
And nobody understands this battlefield.
I've got a buddy at the University of Alabama at Birmingham, and he always brings up this
analogy.
If somebody were to launch a rocket at General Motors, the United States is there.
We're going to knock that rocket down.
We're going to retaliate.
We're going to go crazy.
But if somebody launches a cyber attack from China into General Motors, sorry, GM, you're
on your own.
When North Korea ostensibly launched a cyber attack some years ago against Sony because
of a really bad movie that now all of us were forced to see because we wanted to know what
all that smiths was about.
You know, there were all sorts of politicians.
If this isn't a cyber war, then what is?
Well, it was not a cyber war.
Sorry.
On the other hand, Sony was on their own.
Did the United States say anything at all? And part of the problem really is attribution. If
somebody lobs a rocket at GM, I got satellites and heat signatures. I know the latitude and
longitude where that rocket came from. Nobody knows where a cyber attack comes from. And that's
why NATO Article 5, the Mutual Defense Clause, has never been invoked for a cyber attack. And
people have been talking about this because do we know when we can respond kinetically to a cyber
attack. Can you tell us a bit about what current professional projects you're working on and where
the audience can find you on social media? Sure. So I'm pretty active on LinkedIn. I have a profile
there and I like to post different things that I'm doing. And if I publish, I usually share it
on LinkedIn. I also have a Twitter account. My handle is at Diane Lee May, or you can just find
me under Diane Zori. And I occasionally tweet out different things that I'm doing via Twitter. So
I am a non-resident fellow at Joint Special Operations University. And I do quite a bit
of work with them when they have different projects or they do research collaborative
conferences. So I try to stay pretty busy with them. And I'm also a non-resident fellow with
the Modern War Institute this year. And so in that capacity, I'm planning to perhaps do a
conference of some sort, maybe work with Joint Special Operations University to marry the two
together and maybe have a conference to talk about great power competition. So that's in the works
and that might be my big project. And I've also been awarded a Department of Homeland Security
Preventing Terrorism Award. It's a grant. So I'll be working on that. It's an initiative to bring
media literacy and critical thinking to the local community. And so that's something I'll
be working on this year. I'm actually going to be speaking at the Cyberships Conference
later on this month. I'll be speaking at Maritime Risk Symposium next month. I just got invited to
give a keynote. Hopefully, it's a virtual conference in Indonesia in December. My social
media presence pretty much is limited to LinkedIn. Gary Kessler. Thank you, Diane and Gary, for
joining us today. And to our listeners, thanks for tuning back in to Sea Control.
I walked up to the far-oom counter
Way, hey, put it in the alley
There I met with Greasy Annie
Put it on the shimbo now
So help me, Bob, I'm put in the alley
Way, hey, put it in the alley
Help me, Bob, I'm put in the alley
Put it on the shimbo now
A potter, oh, and a potter, gin, oh.
Way, hey, put it in the alley.
A potter, wine, both white and red, oh.
Put it on the shimbo now.
So help me, Bob, I'm putting it in the alley.
Way, hey, put it in the alley.
Help me, Bob, I'm putting it in the alley.
Put it on the shimbo now.
