When people say things occur on the Internet at light speed they are not that far off.
Similarly, when you say that activity in the cyber domain unfolds quickly, it is a gross understatement. Just recently, a software vulnerability was publically announced. Within 24 hours of that announcement, an exploit (malware) was listed on the black market that took advantage of that software vulnerability.
Consider this factoid about the current cyber threat environment: In 2014 one cyber security vendor reported there were over 148 million new strains of malware. That equates to nearly 5 new strains of malware being released each and every second. Five new strains of malware per second!
One has to wonder how many signatures it would take to cover all 148 million pieces of malware in anti-virus software. Or even better, how long would an anti-virus scan take on a laptop that now comes with a 750 GB hard drive.
Not only are the threats growing rapidly, but the cyber attack surface known as the Internet is also growing at a significant pace. In 2014 the number of Internet users grew at just under 8 percent to just short of 3 billion. Now you have to add to that all of the tablets, vehicles connected to the Internet, the Internet of Things (IoT) and so on. Current thinking puts IoT devices at 1.5 billion in 2014. ABI Research estimates the number of wireless connected devices at over 16 billion in 2014. Now we need to consider that almost all of our nation’s critical infrastructures operate in a digital environment, so we must add all the servers and other devices that may fall under that heading. At this point you begin to get a feeling for just how massive the cyber attack surface really is.
Now combining those two off-the-cuff assessments, we need to examine how likely it is that a major event will take place. In the fourth quarter of 2014, Pew Research released the results of a survey that asked over 1500 “experts and Internet builders” to share their predictions with respect to cyber. What they found was alarming to most everyone I spoke with about it.
To the question, “By 2025, will a major cyber attack have caused widespread harm to a nation’s security and capacity to defend itself and its people?” an astonishing 61 percent of those experts and Internet builder respondents said “Yes” that a major attack causing widespread harm would occur by 2025. You should take the time to read the entire PEW report.
Note: By “widespread harm,” they meant significant loss of life or property losses/damage/theft at the levels of tens of billions of dollars.
Combining the cyber attack surface estimate with the current cyber threat you begin to see just how massive the cyber domain is and you can imagine how much larger it will be in 2020. This is the context for a discussion about near-real-time cyber threat analysis, decision making and response. The compressed time frame demanded by the highly dynamic cyber domain requires a much more streamlined decision making process. Critical activities/threats in this domain do not lend themselves to calling a meeting or scheduling a conference call as malware spreads in milliseconds. The risks associated with the current cyber attack threat level that target businesses, government, industry, non-profits, individual users and equipment/devices connected to the Internet has become so pervasive the thought of the Pew scenario identified above is very concerning.
An event like that would without question be considered an act of cyber war. Speaking before Congress back in the spring of 2014, Army General Keith Alexander, then the head of U.S. Cyber Command stated that any possible attack would be cyber warfare and that we’re just not ready for it. Put all this together and this becomes very scary. This is real-time-enough analysis of the current cyber threat condition. Sitting and hoping the Pew report and General Alexander are wrong is a totally unacceptable way to deal with this issue. If we are to address this clear and present danger, choices must be made and action taken now.
Near-real-time decision making processes must be put in place and business, government and academia must immediately begin to work together. This typical bloviation by business and government executives won’t cut it. There is too much at stake!




