As more entities employ its tactics, is cyberwarfare the future of war?

With Russian missiles flying and foot soldiers advancing on their largest cities, the courageous people of Ukraine are living a tragedy unseen on the European continent since World War II. The loss of lives and livelihoods, and destruction of public and private property, will take a toll for decades to come.

Another almost equally as destructive part of the war is more obscure, taking place behind the scenes on computers and the internet. Cyberwar, as it is now called, has increasingly become an important adjunct to military confrontation between countries. It is increasingly common for an aggressor to attack and take down another country’s military, financial and/or communications systems using computer hackers, in addition to—and sometimes in place of—troops and aircraft.

To get a better understanding of cyberwarfare—what it is, how it works and why it is used—we sat down with Stephen Haag, professor of the practice in the Department of Business Information and Analytics at the Daniels College of Business. Haag is an expert in cybersecurity and has consulted with corporations and federal agencies on computer security issues.

How do you define cyberwarfare?

Cyberwarfare falls under the broader category of cybercrime, which includes everything from targeting or taking down a computer, stealing an identity, to installing a virus. It’s anything where someone uses a computer in the commission of a crime.

Cyberwarfare is the more specific country-to-country commission of cybercrime with one country trying to harm or disrupt the systems of another country.

Computer viruses, malware and social engineering are commonly used to perpetrate fraud, but how do those efforts differ from cyberwarfare?

They’re actually a part of cyberwarfare, but the motivation is different. What you’re looking at is the end game—the desired result. Cyberwarfare has a political motivation to it, as opposed to an individual or financial motivation. There may not be any financial gain for a country by conducting cyberwarfare with another country. Instead, they’re trying to disable or deny system structures in some way.

What are the most common targets of cyberwarfare attacks?

The primary targets are government and military systems that help maintain a country’s physical defenses. Bank and financial services systems are also prime targets. Countries cannot operate without access to worldwide structures of banking and financial systems like SWIFT, which connects more than 11,000 institutions globally. There also are banks’ internal systems that allow people to withdraw funds and pay bills that are targets.

Other targets include a country’s utility infrastructures—electricity, gas and water. Also important are communications structures, which can include telephone and internet, as well as news media. The focus is removing or disrupting a country’s fundamental operating components and placing stress on their systems and people.

What are the most common kinds of cyberwar attacks and how do they work?

The most common one is what’s called a distributed denial-of-service (DoS) attack.

Computers generally do two things—they process information and they communicate with other computers. In a DoS attack, the notion is to overload a computer with communications so that it can’t do any processing. Hackers write programs to hit a web server with thousands of communications every second. It doesn’t destroy the system or render it permanently useless. It denies its ability to process information.

Cyberwarfare hackers also employs the use of malware, or putting a virus on a computer, so that its software doesn’t operate properly. It’s not intended to destroy the system, but significantly interfere with its operation.

The news media often cite ‘Russian hackers’ carrying out cyberattacks. Are these government employees? ‘Hired guns?’ Independent people with allegiance to the Russian cause?

It typically is not a government employee. It’s generally a hybrid of the others. For the most part, they’re independent contractors who are, indeed, paid by the government but through very distant and circuitous channels to conduct cyberattacks.

The idea, of course, is to be able to establish plausible deniability, which often isn’t very plausible. These governments want to say they’re not conducting these attacks, but they’re unable to control what their people do independently. Clearly, not plausible.

How does the U.S. government defend against cyberattacks?

It’s about being proactive and having the systems in place that can thwart those attacks or render them useless. The challenge is that whenever you develop a strong security measure, the wrong people look at it and develop ways to get around it. It’s a continuous cycle of introducing better and better defenses, more layers for attackers to get through.

It’s also a matter of using defense as an offensive tool, by being able to approximate the IP address from which an attack is coming and shut it down as soon as you start to see a flood.

Is it fair to say that countries that are subject to cyberattacks retaliate in a similar manner? Is there a possibility of escalation in these cases?

Yes. Countries often do retaliate in a similar manner and threat of escalation is very real. For example, a retaliatory response can be aimed at an aggressor’s communications infrastructure as a means of blunting an attack. Using a battlefield analogy, communications is just another supply line in today’s warfare tactics, whether it’s boots on the ground or cyber. Looking for ways to disrupt those systems—the supply line—is a viable strategy.

Is this the future of warfare?

I believe it is. We’re witnessing a brutal physical battle in Ukraine right now, but the ideal in warfare—if there is one—is to defeat an enemy without ever firing a shot.

Also, what we’re not seeing right now is the destruction ports of call, roads, bridges, rail lines and other basic infrastructure. The idea is that if you take over a country by destroying those things, then you have to rebuild them if you want to use them. Rebuilding bridges, for example, takes time and money.

I think the most important part that people really need to understand about cyber warfare is it’s not meant to destroy. It’s meant to disable. It’s meant to deny so that the basic structures are still in place for you to use because you don’t want to have to rebuild.

Overcoming an enemy without firing a shot. That’s the goal of cyberwarfare.