The SolarWinds hack – a cyber espionage campaign compromising critical organisations of the U.S. – has fundamentally disrupted the power dynamics of cyberspace.(Getty Images/iStockphoto)
The SolarWinds hack – a cyber espionage campaign compromising critical organisations of the U.S. – has fundamentally disrupted the power dynamics of cyberspace.(Getty Images/iStockphoto)

SolarWinds: Cyber strategists are back to the drawing board

Cyber strategists are now back to the drawing board as even the most meticulously derived variables and equations of cyber power look like unfounded abstractions. It is a moment of reckoning for the neoliberal system which was the very foundation of the Internet.
By Pukhraj Singh
PUBLISHED ON DEC 27, 2020 06:12 PM IST

The SolarWinds hack – a cyber espionage campaign compromising critical organisations of the US – has fundamentally disrupted the power dynamics of cyberspace.

It is not only a major setback to the cyber statecraft initiatives of the United States (US) which took years to mature, but also challenges the basic assumptions upon which the West’s strategy for cyber dominance rest.

The operation, said to have begun in March, was only discovered this month when FireEye – an American cyber intelligence company – found out that its own network had been breached.

The investigation led responders through a proverbial rabbit hole as it became obvious that, before the intruders audaciously pivoted to FireEye’s network, they had “popped” almost 50 other US organisations including the departments of Treasury, Commerce, State, Energy & Homeland Security; companies such as Cisco, Intel, Nvidia, and VMware; and critical agencies such as the National Nuclear Safety Administration.

The hack of the decade is being attributed to SVR, the discrete Russian foreign intelligence agency. The tradecraft employed by the spies was brilliant as they managed to evade every defence in a global surveillance dragnet feeding the counterintelligence capability of the US and its allies.

By backdooring the update mechanism of a wildly popular IT administration software called SolarWinds Orion, the intruders managed to acquire a beachhead in any of its 300,000 customers.

At every step of the “kill chain,” the operators showed remarkable ingenuity.

They had no plans to outmatch the strategic cyber offensive might of the US, so the spies tactically blended-in with the environment, exploited “transitive trust” of the computers, and used deception to look like routine processes.

Yet, beyond all the technical details, it was the palpable strategic calculus which strikes at the heart of US cyber policy.

The intrusion came at a time when the US Cyber Command (USCYBERCOM) – it has a powerful mandate since the Russian interference into the 2016 presidential elections – declared itself as a formidable force.

Its Defend Forward strategy was premised upon undertaking pre-emptive, extrajudicial cyber operations within the adversary’s own information space – neutralising a potential threat even before it was instantiated.

However, the strategy did not assume that USCYBERCOM could undertake such expeditionary manoeuvres in every hostile network. The idea was to send a credible deterrence threat by a selective use of “force” to coerce or compel the adversary.

USCYBERCOM aspired to strike a ‘tacit bargain’ (from the international relations parlance) with the adversary by ‘signalling’ that any malicious action would lead to the imposition of unacceptable costs.

The Defend Forward strategy was based on some broad, sweeping assumptions.

First, that the traditional structures of deterrence by denial and punishment remained valid in cyberspace.

Second, that cyberspace is a ‘domain’ allowing militaristic power projection at a ‘place and time of choosing.’ There was also a retroactive implication that cyber operations more or less adhered to the law of armed conflict, thus bestowing legitimacy upon Western offensive counteractions.

Third, that on a broader scale, pre-emptive cyber operations legitimised by the West would trigger a kind of creative destruction, thus calcifying a rules-based order in cyberspace. The overall strategy was that the establishment of global cyber norms premised upon international law would reinstate the ‘neoliberal institutionalist’ concept of power by punishing states that thrived on impunity.

Busy with the 2020 elections and potentially distracted by the threat of Russian disinformation, the US establishment thought that it could somehow stretch Defend Forward into a national doctrine. And so, what was basically an expeditionary manoeuvre, which had evolved in a specific cultural silo of the US cyber apparatus, became the cornerstone of statecraft.

The groupthink was obvious as the Cyberspace Solarium Commission – a whole-of-government grand strategy for cyberspace formulated by the US government – even elevated Defend Forward to the hallowed pedestal of “Layered Cyber Deterrence,” a proposed international strategy.

All this happened almost overnight even as the evidence of Defend Forward’s success remained limited in the public sphere.

It was a perfect storm in the making and the SVR made the best of it. Russia was neither deterred nor compelled; it could not be coerced, nor did it opt for an explicit or tacit bargain.

In fact, as a dichotomy which would never ever be encountered in a conventional domain of war like land, sea or air, Russia chooses to see cyberspace using a wholly different assumptive paradigm.

Its structures of power projection are purely cognitive. And being an undemocratic entity, such a projection does not impinge upon its internal stability.

General-Major V. D. Ryabchuk, the father of Russian strategic deception, alluded that “thought is the first to enter battle.” In that sense, Russia’s cyber actions have successfully managed to break the will, demoralise and eventually deter its adversaries – including those from the West – quite a few times.

The fact of the matter is that state-to-state espionage is a-okay, which is what this hack was.

Cyber strategists are now back to the drawing board as even the most meticulously derived variables and equations of cyber power look like unfounded abstractions. It is a moment of reckoning for the neoliberal system which was the very foundation of the Internet.

Pukhraj Singh is a cyber intelligence analyst who has worked with the Indian government and response teams of global companies

The views expressed are personal

SHARE THIS ARTICLE ON
app
Close
How do we address this cyclical pattern of hailing and rubbishing financiers? It is time for an honest review of the entire issue (Getty Images/iStockphoto)
How do we address this cyclical pattern of hailing and rubbishing financiers? It is time for an honest review of the entire issue (Getty Images/iStockphoto)

The policy landscape around digital and physical micro-lending

By Amol Agrawal
PUBLISHED ON JAN 24, 2021 06:37 PM IST
In 1870s, a similar backlash emerged in Poona and Ahmednagar districts of the Bombay presidency. The agriculture boom in the early 1860s led farmers to take loans from moneylenders
Close
A tiny tax on stock market transactions can help fund India’s vaccination drive without burning a hole in the wallets of stock market investors and give the government headroom for other expenditure to help save lives (AFP)
A tiny tax on stock market transactions can help fund India’s vaccination drive without burning a hole in the wallets of stock market investors and give the government headroom for other expenditure to help save lives (AFP)

Vaccinating all Indians, for free

By Praveen Chakravarty
PUBLISHED ON JAN 24, 2021 06:37 PM IST
The markets are at an all-time high. Impose a Covid-19 surcharge on transactions and use it for vaccination
Close
Why is it that, despite the government displaying its willingness to take a step back, the matter was not resolved? (PTI)
Why is it that, despite the government displaying its willingness to take a step back, the matter was not resolved? (PTI)

Farm protests: The costs of a prolonged standoff

By Shashi Shekhar
UPDATED ON JAN 24, 2021 06:52 PM IST
The government has extended an olive branch. The farmers must respect this and reciprocate. The tone set on Saturday should pave the way for a permanent solution.
Close
Pushing against the climate crisis — in spite of the terrible fire and hurricane damage — was his way of putting the economy before all else. This is what Biden-Harris will have to overcome with smart policies and even smarter communication. (AFP)
Pushing against the climate crisis — in spite of the terrible fire and hurricane damage — was his way of putting the economy before all else. This is what Biden-Harris will have to overcome with smart policies and even smarter communication. (AFP)

On climate, what the US needs to do

By Sunita Narain
UPDATED ON JAN 24, 2021 06:25 AM IST
Joe Biden has done well to rejoin the Paris accord. But his administration will have to overcome Trumpism, take responsibility for historic emissions, and change energy consumption patterns at home
Close
The JPC, hence, has a daunting task ahead, balancing the needs of State security against individual privacy. Giving entry to security agencies will compromise the encryption grid and data of millions. The State has to collaborate with tech giants in using the meta-data more meaningfully and for meeting other requirements without breaking the encryption. (Getty Images/iStockphoto)
The JPC, hence, has a daunting task ahead, balancing the needs of State security against individual privacy. Giving entry to security agencies will compromise the encryption grid and data of millions. The State has to collaborate with tech giants in using the meta-data more meaningfully and for meeting other requirements without breaking the encryption. (Getty Images/iStockphoto)

Data bill: The security vs privacy debate

By Yashovardhan Azad
UPDATED ON JAN 24, 2021 06:26 AM IST
The Data Protection Bill also does not touch upon State surveillance methods. Who watches over the watchers? How can an officer of the same rank give permission to another for snooping? And how can another in the same system oversee its justification?
Close
The massive sacrifice of hundreds of Secret Service officers of Netaji Subhas Chandra Bose’s Indian National Army remains a secret and an enigma. On the 125th anniversary of Netaji’s birth, I appeal to the nation to document and recognise these sacrifices (HT PHOTO)
The massive sacrifice of hundreds of Secret Service officers of Netaji Subhas Chandra Bose’s Indian National Army remains a secret and an enigma. On the 125th anniversary of Netaji’s birth, I appeal to the nation to document and recognise these sacrifices (HT PHOTO)

The secrets of Netaji’s secret service

By Amit Mitra
PUBLISHED ON JAN 22, 2021 06:49 PM IST
The Indian National Army’s Secret Service men remain unrecognised, despite their sacrifices during the freedom struggle. We must revere them
Close
Prime Minister Imran Khan has contended that Pakistan's economy has made a remarkable turnaround.(Facebook/ImranKhanOfficial)
Prime Minister Imran Khan has contended that Pakistan's economy has made a remarkable turnaround.(Facebook/ImranKhanOfficial)

Imran Khan jumped the gun. This time, over Pakistan’s economic turnaround

UPDATED ON JAN 22, 2021 03:51 PM IST
  • Pakistan's GDP growth had slowed down much before the coronavirus outbreak, growing by 1.9% in 2019 as compared to a decade-high of 5.8% the previous year when Imran Khan's Pakistan Tehreek-e-Insaf came to power.
Close
While social media has the ability to democratise politics, it can also silence voices. This is troubling (AFP)
While social media has the ability to democratise politics, it can also silence voices. This is troubling (AFP)

The democratic dilemma posed by social media

By Manjari Chatterjee Miller
UPDATED ON JAN 22, 2021 06:20 AM IST
The banning of Trump and others from Twitter and Facebook, and the shutdown of Parler made clear that the power to silence voices, whether of the one or of millions, lies with just three men on the planet – Mark Zuckerberg of Facebook, Jack Dorsey of Twitter, and Jeff Bezos of Amazon. No wonder defending democracy will be a huge and unenviable task for President Biden’s team.
Close
The Supreme Court, in 2019, acknowledged that internet access is integral to the right to freedom of speech and expression while adding that any restriction on internet access must pass the test of proportionality, and suggested the evolution of a rules-based mechanism to govern the internet. (Getty Images/iStockphoto)
The Supreme Court, in 2019, acknowledged that internet access is integral to the right to freedom of speech and expression while adding that any restriction on internet access must pass the test of proportionality, and suggested the evolution of a rules-based mechanism to govern the internet. (Getty Images/iStockphoto)

Putting the consumer at the centre of Digital India

By Lloyd Mathias
UPDATED ON JAN 22, 2021 06:21 AM IST
One way to empower consumers is by creating mechanisms to ensure inter-operability, by making it easier to switch services from one platform to another. In telecom, interoperability is implemented. However, in the internet space, and more prominently in the app space, consumers do not have this choice.
Close
Project finance economies have different imperatives from working capital economies. They need investment to fill the gaps in their infrastructure and lack the resources to do so (Pratik Chorge/HT PHOTO)
Project finance economies have different imperatives from working capital economies. They need investment to fill the gaps in their infrastructure and lack the resources to do so (Pratik Chorge/HT PHOTO)

The working of a ‘project finance economy’

By Janmejaya Sinha
UPDATED ON JAN 22, 2021 06:19 AM IST
It is time to question neo-classical economic precepts on deficit and inflation for an economy of India’s nature
Close
Their success highlights the depth and strength of talent in the country (PTI)
Their success highlights the depth and strength of talent in the country (PTI)

Courage, calibre, character: India’s greatest series win

By Ayaz Memon
PUBLISHED ON JAN 20, 2021 08:07 PM IST
The experienced pros and newcomers combined to prove a point to themselves, the opponents and the world. And created history
Close
The Centre ensured the supply of drugs with equitable and integrated access (REUTERS)
The Centre ensured the supply of drugs with equitable and integrated access (REUTERS)

Managing drug security effectively in times of a pandemic

By Sudhansh Pant
UPDATED ON JAN 20, 2021 09:19 PM IST
The Centre’s strategy to ensure sufficient access, monitor stocks and distribution, issue approvals, maintain seamless supply chain of drugs, effectively communicate with stakeholders, and evolve a dynamic Clinical Management Protocol (CMP) has contributed significantly to India’s Covid-19 management success
Close
A new report by Chatham House describes India as UK’s ‘rival’ or ‘at best, an awkward counterpart’ on par with Russia, Turkey and Saudi Arabia. It also weighs in against the idea of expanding G7 to include India (Getty Images)
A new report by Chatham House describes India as UK’s ‘rival’ or ‘at best, an awkward counterpart’ on par with Russia, Turkey and Saudi Arabia. It also weighs in against the idea of expanding G7 to include India (Getty Images)

Is ‘Global Britain’ inimical to India?

By Syed Akbaruddin
UPDATED ON JAN 20, 2021 09:10 PM IST
There are disturbing signals from both segments of British polity and civil society. India will need to assess the UK’s position carefully
Close
Pakistan's opposition parties had united last year under the aegis of Pakistan Democratic Movement to launch coordinated attacks on Prime Minister Imran Khan(AFP)
Pakistan's opposition parties had united last year under the aegis of Pakistan Democratic Movement to launch coordinated attacks on Prime Minister Imran Khan(AFP)

Imran Khan gets squeezed between shrinking economy and proactive opposition

UPDATED ON JAN 20, 2021 05:48 PM IST
  • Differences between China and Pakistan over funding of CPEC's biggest railway project spotlights the growing pressures on PM Imran Khan on the economy front
Close
There is evidence to indicate that the PLA's work and engineering force deployed to upgrade infrastructure in occupied Aksai Chin moved back after completion of work last month
There is evidence to indicate that the PLA's work and engineering force deployed to upgrade infrastructure in occupied Aksai Chin moved back after completion of work last month

India should be wary of Chinese mind games

UPDATED ON JAN 13, 2021 12:31 PM IST
  • Withdrawal from the vast Tibetan and Xinjiang military region means little in an era of stand-off weapons and long-range missiles. The Chinese PLA has capacity to deploy troop divisions within a week with metalled roads and optical fibre cables up to the last military post and advanced landing grounds (ALGs) all along the LAC.
Close
SHARE
Story Saved
OPEN APP