The Guardian Online just posted an assessment I co-wrote with my friend Jim Hendler (computer science professor at RPI) about the Georgia-Russia Cyberwar.
The first modern cyberwar?
Aaron Mannes and James Hendler
Friday August 22 2008
The Russian-Georgian conflict is being described as the first time cyber-attacks have accompanied an actual war. Last year, the Russian-Estonian spat was described as the first modern cyber-war. These descriptions over dramatise events and are a distraction from the more prosaic, but more serious, danger these illicit cyber-actions represent. The technology used in these cyber-conflicts has only limited strategic impact, but represents a major threat to one of the most successful engines of human freedom and opportunity – the World Wide Web itself.
The strikes against Georgian government websites, along with last April's attacks against Estonian websites, were distributed denial of service attacks (DDoS) where many computers simultaneously send messages to a website, preventing legitimate traffic from reaching the site. These attacks are relatively easy to launch, but taking a website down does not affect real world infrastructure and competent IT professionals can counter or at least mitigate DDoS attacks. The increasing volume and sophistication of these attacks is a subject much discussed among IT professionals, but its impact is to create an inconvenience.
Theoretically taking down Georgian government sites could have prevented Georgia from publicising its side of the conflict. However, some Georgian sites were migrated to new locations. More importantly, the Georgian government's message was getting out to the world. The problem was that the United States and Nato had limited options for supporting Georgia. In short, the cyber component had no significant known impact.
Advanced economies and militaries rely on sophisticated information networks. Damaging or infiltrating these networks will probably be an important component of future wars. The ability to listen in on or disable an enemy's military communications net could be the difference between victory and defeat. It is also conceivable that information inside these networks could be influenced, or that the networks running critical infrastructure - military or civilian - could be infiltrated and used to cause real-world damage. However the skills and technologies needed for these attacks will be highly specialised, and not akin to the DDoS attacks which a relative amateur can launch.
Russia, home to a sophisticated core of cyber-criminals, undoubtedly possesses some of these capabilities. But, considering Russia's massive military advantage over tiny Georgia, it is unlikely that Russia would have turned to advanced cyber war to guarantee victory, particularly when deploying it would provide potential future adversaries with valuable intelligence about Russia's cyber war strategies and tactics. In addition, much of Georgia's infrastructure is old and consequently not online and therefore invulnerable to a cyber strike. (The Georgians claim that Russia has targeted their phone system, and while that is possible, it is more likely that Georgian phone systems were overwhelmed in the general crisis accompanying the Russian attacks.)
The Russian government may have instigated the DDoS attacks, although the evidence is unclear, and it is difficult to identify the origins of a DDoS attack. It appears that the DDoS attacks were in fact a mass action by regular Russian citizens. For the future of the Web, this is even more worrisome.
DDoS attacks typically use botnets, networks of thousands of compromised computers that, unbeknownst to their owners, are used to disseminate spam. Five years ago DDoS attacks and botnets were the domain of highly skilled cyber-criminals. Now, botnets can be rented online, and rentals come with tech support. The massive DDoS attacks on Georgia included botnets, but ordinary citizens joined in, using simple tools distributed online to join in the attacks. The tools of cybercrime are becoming progressively easier to use.
The Web was established as an open environment, with minimal governance, that puts a premium on individual liberty and initiative. This openness has been essential to the Web's success as a tremendous engine of creativity, opportunity, and liberty. DDoS attacks that take down websites are bad manners and one threat to the open spirit that underpins the Web. But the technology behind these attacks represents even greater threats.
The primary use of botnets is not DDoS attacks, but to perpetrate an ever expanding repertoire of online frauds and distribute malicious software. These activities undermine the physical and moral integrity of the Web. Some estimates are that more than 75% of the emails sent worldwide are spam. With botnets becoming easier and easier to create and manage, the rate of spam is increasing faster than new internet capacity. Spam also represents a moral threat to the Web, as online fraud undermines trust in e-commerce and online communications in general.
Governments can better prepare for specific events, such as international cyberspats. There are a number of improvements that could be made in coordination and in developing early warning systems. But the systemic issues also need to be addressed. Software designs need to be improved to reduce the vulnerabilities that cyber-criminals exploit and the public needs to be better educated about safer online behaviour. Major Web users such as governments, ISPs, universities, and corporations need incentives to better secure their networks, and educate their users. Finally, serious efforts must be made to develop international laws that can prevent increasingly sophisticated cyber attacks and to prosecute cyber-criminals. All of these steps are costly, but without them more draconian efforts that impinge on individual privacy may be needed to keep the Web viable.
The cyber-component of the Russian-Georgian conflict was only a sideshow, but it highlighted the threats facing one of history's great promoters of freedom and innovation - the World Wide Web.
Mostly about terrorism, world affairs, a little computational modeling and big data, some political science, plus history, travel, philosophy and whatever else grabs me! Opinions strictly my own.
Friday, August 22, 2008
Friday, August 15, 2008
Golden Oldie: Russian-Estonian Cyberwar Overview
Spring 2007, a spat between Russia and Estonia was accompanied by a "cyberwar." With my friend, and former boss, Jim Hendler (now a professor at RPI) I wrote an overview. The story is now relevant again for assessing the cyber component of the Georgian-Russian conflict. This difference is that this time, for all of the hype about cyberwar, there is real world fighting that is having a more permanent impact.
At the same time the growing level of illicit activity on the web is a concern in its own right.
June 5, 2007
COMMENTARY
Net Attack
By AARON MANNES and JAMES HENDLER
June 5, 2007
The age of cyberwar has arrived. The attacks on Estonian government and commercial Web sites following the relocation of a Soviet World War II memorial in Tallinn in late April made news around the world. Yet these were not the only, or even the most significant, such assaults this year.
In February, hackers laid siege to six of the 13 "root servers" that form the backbone of the Internet. Had they succeeded in disabling these servers, the Internet would have ceased to function. Fortunately, only two of the root servers were severely affected, causing only some localized slowdowns. The emerging threat of cyberattacks against vital parts of the global economy highlights the urgent need to protect the Net from criminals.
The attack on Estonia was perhaps more akin to a riot than a military strike. Just as a mob might wreck storefronts, cyberattacks defaced or knocked prominent commercial and government Web sites offline. Similar attacks have accompanied other international political spats. Arab and Israeli hackers attack each other's Web sites, as do Pakistani and Indian hackers. After a South Korean speed skater was disqualified for bumping an American rival during the 2002 Winter Olympics, several strikes apparently originating from South Korea hit U.S. servers.
In all these cases, the hackers can cause email delays and fetter access to targeted Web sites. In Estonia, they prevented the national government from explaining the situation, hampered financial transactions and interfered with telephone systems, which rely in part on the Internet to function.
The strikes against the Estonian sites and the Internet root servers are of a type known as Distributed Denial of Service attacks, or DDoS. The assailants begin by installing a virus or other malicious software on a computer, directing it to send messages without its owner's knowledge. These compromised computers, known as bots, are bound together into large networks called botnets. They then simultaneously send messages to the targeted system, overwhelming it and leaving it unable to respond to queries. Low-end estimates indicate that there are tens of millions of bots in the world, and experts have identified some botnets that included more than 100,000 compromised computers.
One reason for the increasing frequency of these attacks is that they don't require high-level skills. In chat rooms where cybercriminals congregate, botnet builders offer their "products" for rent, their real identities obscured behind aliases. There are even online help desks to assist users. Because botnets consist of computers from all over the world, it is difficult to trace the origin of an attack, making it particularly attractive to governments who can deny any responsibility.
Consider the Estonian case. Tallinn accuses Russian state officials of involvement in the recent attacks. But even if that is true, it is difficult prove that this was state policy instead of the actions of sympathetic individuals. State computers may have been part of botnets, but so were other computers around the world. Russia is also a major center for cybercriminals, many of whom happen to be staunch Russian patriots. In this recent cyber levée en masse, many ordinary Russians participated in the attacks against Estonia; at its peak over one million computers were involved.
Because of their ease of use, DDoS attacks have proved attractive to various malevolent actors. According to a report by the Middle East Media Research Institute, Islamist chat rooms have included discussions of attack techniques and work to coordinate attacks on Web sites that oppose their cause. DDoS attacks may favor the assailant, but skilled IT professionals can counter them. More important, they have limited efficacy: Knocking out the power company's Web site is not the same as taking down the power grid. Breaking into a system to gather information, or launching an attack that damages real-world infrastructure, requires more extensive skills. So far, the few publicly known incidents involving real-world infrastructure -- most famously an April 2000 case in Australia in which raw sewage was released into rivers and streams -- have involved disgruntled insiders.
DDoS is also of limited utility in economic warfare. Knocking out the Web site of an online business is obviously bad for that business, but it has a negligible overall economic effect: Frustrated customers can simply purchase from competitors.
Little is known about the people behind the February attacks on the Internet root servers. The investigation into the incident suggested that the attack was by cybercriminals who wanted to advertise their sophisticated botnet. Criminals have used DDoS to blackmail online businesses, particularly gambling sites. But botnets are used more profitably to disseminate spam and malware. While the botnets cannot yet destroy the Web technically, they are undermining its vital trust and openness.
There are no simple ways to prevent the World Wide Web from becoming a zone where powerful criminals operate unfettered and large players can push around small ones. Software makers can work to make systems more secure, but many computers are compromised by user error rather than technical flaws. The public can be better educated in computer security, but human nature is imperfect.
International standards for addressing the problem, such as the Council of Europe's Convention on Cybercrime, are evolving. Setting international standards to counter cybercrime, while still protecting civil liberties, will be a continuing challenge. But the greater challenge will be pressing nation-states to adhere to these standards by enacting and enforcing laws against cybercrime.
Yet as the attacks against Estonia show, the task cannot be delayed -- the increasing sophistication and accessibility of malware means these problems will only become worse. The future of the Web is at stake.
Mr. Mannes is a researcher in international security affairs and Ph.D. student at the University of Maryland. Mr. Hendler is a professor of computer science at Rensselaer Polytechnic Institute.
At the same time the growing level of illicit activity on the web is a concern in its own right.
June 5, 2007
COMMENTARY
Net Attack
By AARON MANNES and JAMES HENDLER
June 5, 2007
The age of cyberwar has arrived. The attacks on Estonian government and commercial Web sites following the relocation of a Soviet World War II memorial in Tallinn in late April made news around the world. Yet these were not the only, or even the most significant, such assaults this year.
In February, hackers laid siege to six of the 13 "root servers" that form the backbone of the Internet. Had they succeeded in disabling these servers, the Internet would have ceased to function. Fortunately, only two of the root servers were severely affected, causing only some localized slowdowns. The emerging threat of cyberattacks against vital parts of the global economy highlights the urgent need to protect the Net from criminals.
The attack on Estonia was perhaps more akin to a riot than a military strike. Just as a mob might wreck storefronts, cyberattacks defaced or knocked prominent commercial and government Web sites offline. Similar attacks have accompanied other international political spats. Arab and Israeli hackers attack each other's Web sites, as do Pakistani and Indian hackers. After a South Korean speed skater was disqualified for bumping an American rival during the 2002 Winter Olympics, several strikes apparently originating from South Korea hit U.S. servers.
In all these cases, the hackers can cause email delays and fetter access to targeted Web sites. In Estonia, they prevented the national government from explaining the situation, hampered financial transactions and interfered with telephone systems, which rely in part on the Internet to function.
The strikes against the Estonian sites and the Internet root servers are of a type known as Distributed Denial of Service attacks, or DDoS. The assailants begin by installing a virus or other malicious software on a computer, directing it to send messages without its owner's knowledge. These compromised computers, known as bots, are bound together into large networks called botnets. They then simultaneously send messages to the targeted system, overwhelming it and leaving it unable to respond to queries. Low-end estimates indicate that there are tens of millions of bots in the world, and experts have identified some botnets that included more than 100,000 compromised computers.
One reason for the increasing frequency of these attacks is that they don't require high-level skills. In chat rooms where cybercriminals congregate, botnet builders offer their "products" for rent, their real identities obscured behind aliases. There are even online help desks to assist users. Because botnets consist of computers from all over the world, it is difficult to trace the origin of an attack, making it particularly attractive to governments who can deny any responsibility.
Consider the Estonian case. Tallinn accuses Russian state officials of involvement in the recent attacks. But even if that is true, it is difficult prove that this was state policy instead of the actions of sympathetic individuals. State computers may have been part of botnets, but so were other computers around the world. Russia is also a major center for cybercriminals, many of whom happen to be staunch Russian patriots. In this recent cyber levée en masse, many ordinary Russians participated in the attacks against Estonia; at its peak over one million computers were involved.
Because of their ease of use, DDoS attacks have proved attractive to various malevolent actors. According to a report by the Middle East Media Research Institute, Islamist chat rooms have included discussions of attack techniques and work to coordinate attacks on Web sites that oppose their cause. DDoS attacks may favor the assailant, but skilled IT professionals can counter them. More important, they have limited efficacy: Knocking out the power company's Web site is not the same as taking down the power grid. Breaking into a system to gather information, or launching an attack that damages real-world infrastructure, requires more extensive skills. So far, the few publicly known incidents involving real-world infrastructure -- most famously an April 2000 case in Australia in which raw sewage was released into rivers and streams -- have involved disgruntled insiders.
DDoS is also of limited utility in economic warfare. Knocking out the Web site of an online business is obviously bad for that business, but it has a negligible overall economic effect: Frustrated customers can simply purchase from competitors.
Little is known about the people behind the February attacks on the Internet root servers. The investigation into the incident suggested that the attack was by cybercriminals who wanted to advertise their sophisticated botnet. Criminals have used DDoS to blackmail online businesses, particularly gambling sites. But botnets are used more profitably to disseminate spam and malware. While the botnets cannot yet destroy the Web technically, they are undermining its vital trust and openness.
There are no simple ways to prevent the World Wide Web from becoming a zone where powerful criminals operate unfettered and large players can push around small ones. Software makers can work to make systems more secure, but many computers are compromised by user error rather than technical flaws. The public can be better educated in computer security, but human nature is imperfect.
International standards for addressing the problem, such as the Council of Europe's Convention on Cybercrime, are evolving. Setting international standards to counter cybercrime, while still protecting civil liberties, will be a continuing challenge. But the greater challenge will be pressing nation-states to adhere to these standards by enacting and enforcing laws against cybercrime.
Yet as the attacks against Estonia show, the task cannot be delayed -- the increasing sophistication and accessibility of malware means these problems will only become worse. The future of the Web is at stake.
Mr. Mannes is a researcher in international security affairs and Ph.D. student at the University of Maryland. Mr. Hendler is a professor of computer science at Rensselaer Polytechnic Institute.
If Musharraf Goes: Assessments and Opportunities
There are reports that Pakistani President Pervez Musharraf will be stepping down in the next few days in order to avoid impeachment. Musharraf has denied these reports, but the prominence of the rumors indicates strongly that the political balance of power has shifting against Musharraf – he will almost certainly be reduced to a figurehead. It is difficult to say how history will judge Musharraf. From the American perspective he was not adequately taking on Islamic extremism. But from the Pakistani perspective he was becoming an American lackey. The truth is somewhere in between. What Musharraf lacked was either the desire or the capability to take on the systemic problems bedeviling Pakistan. It is possible that with his exit from the scene, a new opportunity to take on these challenges could emerge.
On one level, Musharraf has been cooperative on counter-terror issues, arresting high-profile al-Qaeda and acquiescing to missile strikes on Pakistani territory. However, while missile strikes are a useful tool – they are no substitute for a serious policy. They have also contributed to Musharraf’s loss of standing in Pakistan, since he is seen as subordinating Pakistani sovereignty – and lives (these strikes have, unfortunately, killed civilians) – to American priorities.
On the other hand, Pakistan has not successfully taken control of the tribal areas where al-Qaeda is re-grouping. Americans would be wise to temper their criticism of the Pakistani military’s counter-insurgency efforts. Imagine a heavy military force designed for conventional conflict being forced to fight a major conventional war stumbling when forced to fight a tough insurgency in hard terrain.
In addition, when Pakistan has cracked down harshly on Islamist groups (such as storming the Lal Masjid Mosque in Islamabad) the response has been waves of Islamist violence – a certain amount of trepidation is understandable.
Large organizations do not change quickly or easily – no matter what the political leadership orders. Ultimately, the Pakistani military’s size (a drag on the economy), shape (oriented towards conflict with India), and operations (such as meddling in Afghanistan) are due to its ongoing conflict with India over Kashmir. The Kashmir issue probably cannot be effectively resolved. However, in general Pakistan’s civilian leaders have been willing to lower the level of tension (in fairness, so did Musharraf). When PPP chief Asif Zardari stated that relations with New Delhi should not be held hostage to the Kashmir issue he was criticized from almost every quarter. Several days later General Kayani made a highly publicized visit to the Line of Control in Kashmir.
Pakistan is at a severe disadvantage vis-à-vis India, both in geography and power (Pakistan’s Afghanistan policy is motivated by a desire to keep that country weak, and thus potential strategic depth for Pakistan in a conflict with India.) U.S. policy has to take Pakistan’s security concerns seriously.
With a civilian government holding real power, the United States might be able to offer security guarantees that would reduce Pakistani fears of conventional defeat by India. Equally important would be the framework of this dialogue. The United States should work to structure these discussions so that Pakistan’s leadership is not negotiating from an inferior position. This combination of real guarantees and the appearance of dealing with the U.S. from a position of strength (essential for the new leadership to establish that it is not in the American pocket) might give Pakistan’s civilian leadership the strength to re-shape the security establishment for its current challenges, reduce the size of the ISI, and counter-act the military’s ongoing expropriation of Pakistan’s civilian economy.
This approach will require a combination of strength and subtlety from both the Pakistani and American sides – qualities that have been in short supply. Nonetheless, a nuclear-armed nation of 200 million, in a strategic location – and at least some democratic currents in its politics – demands this level of attention.
On one level, Musharraf has been cooperative on counter-terror issues, arresting high-profile al-Qaeda and acquiescing to missile strikes on Pakistani territory. However, while missile strikes are a useful tool – they are no substitute for a serious policy. They have also contributed to Musharraf’s loss of standing in Pakistan, since he is seen as subordinating Pakistani sovereignty – and lives (these strikes have, unfortunately, killed civilians) – to American priorities.
On the other hand, Pakistan has not successfully taken control of the tribal areas where al-Qaeda is re-grouping. Americans would be wise to temper their criticism of the Pakistani military’s counter-insurgency efforts. Imagine a heavy military force designed for conventional conflict being forced to fight a major conventional war stumbling when forced to fight a tough insurgency in hard terrain.
In addition, when Pakistan has cracked down harshly on Islamist groups (such as storming the Lal Masjid Mosque in Islamabad) the response has been waves of Islamist violence – a certain amount of trepidation is understandable.
Large organizations do not change quickly or easily – no matter what the political leadership orders. Ultimately, the Pakistani military’s size (a drag on the economy), shape (oriented towards conflict with India), and operations (such as meddling in Afghanistan) are due to its ongoing conflict with India over Kashmir. The Kashmir issue probably cannot be effectively resolved. However, in general Pakistan’s civilian leaders have been willing to lower the level of tension (in fairness, so did Musharraf). When PPP chief Asif Zardari stated that relations with New Delhi should not be held hostage to the Kashmir issue he was criticized from almost every quarter. Several days later General Kayani made a highly publicized visit to the Line of Control in Kashmir.
Pakistan is at a severe disadvantage vis-à-vis India, both in geography and power (Pakistan’s Afghanistan policy is motivated by a desire to keep that country weak, and thus potential strategic depth for Pakistan in a conflict with India.) U.S. policy has to take Pakistan’s security concerns seriously.
With a civilian government holding real power, the United States might be able to offer security guarantees that would reduce Pakistani fears of conventional defeat by India. Equally important would be the framework of this dialogue. The United States should work to structure these discussions so that Pakistan’s leadership is not negotiating from an inferior position. This combination of real guarantees and the appearance of dealing with the U.S. from a position of strength (essential for the new leadership to establish that it is not in the American pocket) might give Pakistan’s civilian leadership the strength to re-shape the security establishment for its current challenges, reduce the size of the ISI, and counter-act the military’s ongoing expropriation of Pakistan’s civilian economy.
This approach will require a combination of strength and subtlety from both the Pakistani and American sides – qualities that have been in short supply. Nonetheless, a nuclear-armed nation of 200 million, in a strategic location – and at least some democratic currents in its politics – demands this level of attention.
Monday, August 4, 2008
College Park Maryland Cougar Video: Unanswered Questions
Here is footage of the Savannah Cat terrorizing the University of Maryland College Park.
Notice how easily the cat disappears from the camera. Why did it allow itself to be caught on camera at that time? Steganography perhaps? A signal to al-Cata?
Meanwhile, what else does the University know? What else are they concealing from us?
Tune in next time, same cat blog, same cat url.
Sunday, August 3, 2008
Large Cats@UMD Updates & Analysis: Infiltration Potential
My top secret campus briefing has been confirmed by mainstream media. First, the sightings were not humidity-induced mirages. Security cameras on campus have captured the elusive large cat's image. Specialists have determined that it is not a cougar, but probably a Savannah Cat.
A Savannah Cat is a mix between a Serval and a domestic short hair cat. A Savannah Cat, known as the "Great Dane" of the cat family, usually weighs in at around 35 pounds (75 lbs. less than a typical cougar.) So in terms of raw feline firepower the campus appears to be safer. But we must not be lulled into a false sense of security. There is more going on here than is generally realized. Highly placed campus sources tell me the sightings had been going on for over a week - and the University was keeping it quiet.
Why?
First, do not under-estimate the Savannah Cat, a creature so dangerous it was banned in Australia (although no permits are needed to own one in the U.S.):
It is possible that some unknown corner of the University's research facilities scientists have engineered an uber-feline part animal, part machine - a cat-borg.
I will reiterate my concern - Redouble security around COLUSSUS ( the Internet backbone server at UMD) - some sort of cyber-feline alliance could be afoot!*

Also, based on this picture I found, it is clear a Savannah Cat could eat a small child - thus it is no accident that the beast was first sighted near the University's Center for Young Children.
(This picture comes from SelectExotics "a progressively innovative, TICA registered cattery that has continually been striving to produce the highest quality domesticated companions." So I guess if you wish to own one of these demon-spawn these are the people who can hook you up.)
Let me reiterate my previous call to the University of Maryland's feline intruder:
*I am not worried that this bionic cat could somehow do damage to the Internet. Legend has it that there are enormous boxes of Legos from a defunct robotics lab somewhere in the bowels of the computer science department at MD. No one has ever found them (and I've looked high and low.) This Lego Dorado will probably never be found, because the Internet has appropriated them and is building a giant Legotron that will one day rise from its underworld home and do its cyber-master's bidding.
A Savannah Cat is a mix between a Serval and a domestic short hair cat. A Savannah Cat, known as the "Great Dane" of the cat family, usually weighs in at around 35 pounds (75 lbs. less than a typical cougar.) So in terms of raw feline firepower the campus appears to be safer. But we must not be lulled into a false sense of security. There is more going on here than is generally realized. Highly placed campus sources tell me the sightings had been going on for over a week - and the University was keeping it quiet.
Why?
First, do not under-estimate the Savannah Cat, a creature so dangerous it was banned in Australia (although no permits are needed to own one in the U.S.):
An assessment commissioned by the government found that the savannah cat posed an extreme threat... with a likelihood that each generation would retain the more efficient hunting traits of the wild African serval.If infiltration is the plan, not frontal assault - typical in asymmetric threats - then the Savannah Cat could prove to be a deadly foe. Its domestic cat side will ensure it has tremendous familiarity and knowledge of human society. The Serval, a small hunter has evolved enormous ears and will sit and listen for up to 15 minutes while on a hunt. A self-contained killing machine that combines collection and analytical capabilities.
[The Australian government stated it] would "not hesitate" to use [its] powers... to prevent the live import of any species or breed that poses a significant risk...
It is possible that some unknown corner of the University's research facilities scientists have engineered an uber-feline part animal, part machine - a cat-borg.
I will reiterate my concern - Redouble security around COLUSSUS ( the Internet backbone server at UMD) - some sort of cyber-feline alliance could be afoot!*
Also, based on this picture I found, it is clear a Savannah Cat could eat a small child - thus it is no accident that the beast was first sighted near the University's Center for Young Children.
(This picture comes from SelectExotics "a progressively innovative, TICA registered cattery that has continually been striving to produce the highest quality domesticated companions." So I guess if you wish to own one of these demon-spawn these are the people who can hook you up.)
Let me reiterate my previous call to the University of Maryland's feline intruder:
They will hunt you down and give you to someone qualified to take care of you. If such a boring, unchallenging life is what you seek, surrender. Otherwise, come to my office - I still have several pounds of raw meat waiting for you - and I can give you sanctuary.
*I am not worried that this bionic cat could somehow do damage to the Internet. Legend has it that there are enormous boxes of Legos from a defunct robotics lab somewhere in the bowels of the computer science department at MD. No one has ever found them (and I've looked high and low.) This Lego Dorado will probably never be found, because the Internet has appropriated them and is building a giant Legotron that will one day rise from its underworld home and do its cyber-master's bidding.
Friday, August 1, 2008
Pakistani Intelligence Sponsoring Terror
This morning, The New York Times has a front page story stating that U.S. intelligence has determined that Pakistan’s intelligence agency, Inter-Services Intelligence, aided the July 7, 2008 attack on the Indian Embassy in Kabul. The conclusion was “based on intercepted communications between Pakistani intelligence officers and militants who carried out the attack…”
This is a very big deal. Indian intelligence sees the ISI behind every adverse event (it should be noted that sometimes, this assessment is correct), but oftentimes the follow-up investigation is lax and inconclusive. India’s security services are of uneven quality (with, it should be emphasized, some able people in top slots) and blaming the ISI is easier than engaging in the needed long-term reform. More recently Afghanistan’s President Karzai has been publicly accusing Pakistan of supporting the Taliban against his regime.
But for U.S. intelligence, particularly the CIA (which has a long working relationship with the ISI) to come to this conclusion – and allow it to appear in the newspaper of record is an event of a different magnitude altogether and it should be taken very seriously. Unsurprisingly, Pakistan’s Prime Minister has denied this support. But the U.S., which has given Pakistan billions in aid since 9/11 and tried to build a strategic alliance, would have little incentive to accuse Pakistan of something so serious.
Unfortunately, effective policy options are not readily available. Too much pressure could isolate Pakistan and lead to a rupture in relations. This is inadvisable - since Pakistan is nuclear-armed, and al-Qaeda cannot be neutralized and Afghanistan cannot be stabilized without Pakistani cooperation. Pakistan can also turn to other powers (particularly China, which is building a giant port at Gwadar) for support.
Also, Pakistan is not completely hopeless. While radical Islam is on the rise in Pakistan, considering how poorly the country has been governed it is surprising that the Pakistani people have not turned even more strongly to radical Islam. The government has recently returned to democracy - a corrupt, inept democracy - but one of the few in the Muslim world.
Pakistan, is one of the central theaters in the war on terror. The recently reported revelations about its intelligence agency's involvement with Islamist terrorists make this an unavoidable reality about Pakistan that the next administration will need to face directly, with resolve, subtlety, and creativity.
But, as Doug Farah notes, simply writing checks is insufficient.
This is a very big deal. Indian intelligence sees the ISI behind every adverse event (it should be noted that sometimes, this assessment is correct), but oftentimes the follow-up investigation is lax and inconclusive. India’s security services are of uneven quality (with, it should be emphasized, some able people in top slots) and blaming the ISI is easier than engaging in the needed long-term reform. More recently Afghanistan’s President Karzai has been publicly accusing Pakistan of supporting the Taliban against his regime.
But for U.S. intelligence, particularly the CIA (which has a long working relationship with the ISI) to come to this conclusion – and allow it to appear in the newspaper of record is an event of a different magnitude altogether and it should be taken very seriously. Unsurprisingly, Pakistan’s Prime Minister has denied this support. But the U.S., which has given Pakistan billions in aid since 9/11 and tried to build a strategic alliance, would have little incentive to accuse Pakistan of something so serious.
Unfortunately, effective policy options are not readily available. Too much pressure could isolate Pakistan and lead to a rupture in relations. This is inadvisable - since Pakistan is nuclear-armed, and al-Qaeda cannot be neutralized and Afghanistan cannot be stabilized without Pakistani cooperation. Pakistan can also turn to other powers (particularly China, which is building a giant port at Gwadar) for support.
Also, Pakistan is not completely hopeless. While radical Islam is on the rise in Pakistan, considering how poorly the country has been governed it is surprising that the Pakistani people have not turned even more strongly to radical Islam. The government has recently returned to democracy - a corrupt, inept democracy - but one of the few in the Muslim world.
Pakistan, is one of the central theaters in the war on terror. The recently reported revelations about its intelligence agency's involvement with Islamist terrorists make this an unavoidable reality about Pakistan that the next administration will need to face directly, with resolve, subtlety, and creativity.
But, as Doug Farah notes, simply writing checks is insufficient.
Cougar of College Park
Usually this blog focuses on the threat of trans-national terrorism – but major threats come in various forms. Reports of a cougar stalking the University of Maryland College Park (where, full disclosure, I am employed as a researcher) could represent more than a wayward large cat (strictly speaking cougars are not “great cats” because they don’t roar – although some great cats, like leopards, are actually smaller than cougars) – it could be a homeland security issue.
This appears to be an extraordinarily clever cougar, it was most recently spotted near the Center for Young Children - perfect prey for a cougar in search of an appetizer.
Although the brutal fact is that we are at the beast’s mercy. Cougars are lightning fast, whereas Terrapins are notoriously slow.
But there is reason to believe there is more going on. The University of Maryland is home to a number of sensitive projects and institutions. Most notably, one of the 13 DNS root name servers that run the internet is based at Maryland (exact location undisclosed – and possibly unknown.) Could the cougar be attempting to hijack the internet for purposes unknown?
This is particularly worrisome if, as many (or at least I) believe, the server has achieved an independent consciousness – like the super-computer in Colossus: The Forbin Project.
All things considered, our best bet is to attempt to negotiate with the cougar and come to terms with it. I have extensive experience with large cats (I’ll discuss this in a future post) so I will volunteer to be an emissary. As a tribute to our new feline over-Lord I am bringing several pounds of raw meat into my office.
So, let me address the cougar directly. If you are out there and scared, come to my office – I can offer you sanctuary (and possibly a research assistant position.)
If you can’t smell the raw meat, look me up in the directory, or stop by the main office of my lab.
Subscribe to:
Posts (Atom)