Of four books, the new book as some people might imagine. A surprise winning journalist with his days at the boston globe. In a while he s will give a few minutes describing the book and whats in it. Some of the themes and what we might contribute from that and then i will open up to the floor give you the opportunity to ask some questions and we will wrap upqu at 1 45. [applause] ing didnt know what the title s going to be for a while but how long the history is it because most people think that it started with the outskirts of shanghai and no but now in prace goes back all the way to the dawn of the internet itself. This was the network where they would talk with one another in their Computer Program an into there was a computer pioneer who was also on the Scientific Advisory board and wrote a paper that has been declassified since but he said heres the problem once you have accessed from multiple locations. He wont be able to keep secrets anymore. When i was doing my research i talked with this man and asked if they read the paper. I took it to the guys on the team with. Lets just do this one step at a time. They wont be able to do this for decades. Two and a half, three decades the whole systems and networks have grown upe with no provisios for security whatsoever. P so i see this situation created from the very beginning. All of this went on noticed until june of 93 when Ronald Reagan watched a movie about camp david. One of the guys that wrote it, not when coming here tomorrow, his parents were hollywood producers and on the following sunday hes in the white house to discuss the missile. And everybody there were nationalem security advisers. He puts down his index cards and asked has anybody seen this movie. So he turns to the chairman of the joint chiefs of staff and says code Something Like this really happened can someone break into our computers. He comes back and says it is much worse than you think. So, one year later there was a National Security about the Telecommunications Security that went in a strange direction basically written by the nsa. The way they wrote it controlled the standards for all in the United States. Government, military. So they reloaded so they wouldt have security and the Commerce Department would have Everything Else. Of course they had no ability to do this. They had no interest in securing the peace channels. O app that time they were exploiting security gaps. So, for about a decade nothing was done about this problem and i wont go any further but the point is these incidents at the dawn of the internet were extremely unlikely. It led to the systems and programs and the issues and policies and controversies in the decision to persist to this day. This is something that i discovered almost by accident. It turnedy out that im assuming you remember basically they get into the norad computer to something called human dialing, he sets up a system and they dial the phone numbers and when the modem is reached they go back into the computer and its just on some online game. Is this possible. Can somebody from the outside get in. So they called the corporation. He leaves the port open and if somebody happened to dial the number to get in, the only secure computer is the computer that nobody can use so that is the lesson we all learned a. We will be talking to him about for the next movie is going to bedn about. Before we get there, youve written a history of cyber war and when people write about th this, people tend to study so they can get a sense of how to fight battles in the future. What do you think having done your research and writing the book on the offensive team 1983 and now students of the cyber war should look back on and instead of working the battlefield of gettysburg to study for the future. I guess a Pivotal Moment came in 1997. Hed beeshe then the commander f something called san antonio where they were doing things about cybersecurity. He couldnt get any of the other officerse interested at all. Of 25 team members would hack into the departments and would have to use commercial available equipment. So they prepared scoping out the networks and what they would do. People who were victimized, the only people that knew about it for the people doing it and the lawyers. It turned out that within four days they hacked into all of the defensefoac department networks including the command center which is how the president communicate. Sometimes they would just leave as marker and sometimes they would intercept messages like what going on here i dont know whats happening. There was a marine in the pacific who knew something was going on but even if you knew something was going on, what do you do about this they unplugged the computer from the internet. Heres what we found an in heres some passwords we dug out and heres the tape recorder, we just changed passwords. They said whos in charge but nobody was in charge so they set up and within a few months, somebody starts hacking into the u. S. Military. Other people set of data minute, if two kids in california can do this, what other nation states can do this. Then there were the Defense Networks looking around for particular things and they traced it back. Then the chinese started doing it and one thing very interesting when the nsa was in spite of the Defense Department networks they noticed them strolling around so this was already really happening. In 1997. But then there were other thing. Remember when they were planning to invade haiti into favor looking up plans into there was a very rudimentary system. This is when they said i found out that its wired into the commercial telephone system and i know how to. Years later a member played on for weeks and weeks and months. They did some of the same things. They got into the phone system and then they were able to hone in on the plan and the Defense System was why youre afraid of. So it would look like there were planes coming from the northwe northwest. So they would send messages saying we know you own this copper plant we are going to get rid of most such and they would turn out the lights and if you keep this up we are going to bomb you tomorrow. Soso thats how because they wee it threatened by Information Warfare so this is the firsthe Information Warfare. Its about one tenth of what we could have done but after that, we know about some of the thin things. I will give one more en and thae should probablygs move on. When they bombed the syrian reactors they were helped by the north korean scientists they didnt acknowledge it a it is dd to about 150 miles from the territory without being detected even though they just installed the missiles and radar. What happened is they used the program developed by the air force and implemented by nsa to the people looking at the screen for nothing. The radar was protecting so it took a little nerve to continue. They were able to intercept to make sure this worked, to make sure they really were saying nothing, and they were saying nothing. Our screens show nothing. We accepted the idea and this is the only thing i will retractcta bit. It was the change of strategy. Basically they capture and get t into the systems and did things saying lets meet at such and such place by 4 00 and there will be some force is waiting there to kill them or they would detect somebody planting a roadside bomb but then you have to send the data back to washington. Within one minute theyas could target through the techniques they killed 4,000. I remember the first person i asked he looked a little alarmed that i knew anything about it. When the history gets written about this if the equivalent of breaking the code, so its been part of the operation plans for quite some time. [inaudible] they decided they should send a delegation to moscow. Maybe they didnt know that this was going on and it was presented as a criminal investigation seeking assistance from the russian federation. So they sent over thishe delegation into there was a general in the military helping out. We will not stand for this. So they were going to be there for five or six days. We woulde go around sightseeing and then on the fourth day, there is nothing. Can we talk to this guy, hes busy now. We will send you a memo on this. But they realized when they got back from those that happened to him for helping the United States, the military h intelligences coming over and he just didnt know about it. The story that you just pull livlist to the establishment ofe new organizations of the Network Defense and computer operations butna there was a parallel Development Going on in the white house where people started to realize the Critical Infrastructure is vulnerable. Can you talk more about what he was upuc to . As all of this other stuff was going on, a couple years before the Oklahoma City bombings, it led to the policy and they started setting up a joint task force on the Critical Infrastructure working group. So then theres some electrical facilities into something that could affect the entire economy. So transportation, banking and finance and then they decided most working groups like this. They thought its pretty obvious if you protect something from physical damage, but there is this other thing going on, vulnerability to electronic and computer hacking and that sort of thing. So as the report is written, half of it and this is where the term was used, they talked about the two types of vulnerabilities, fiscal and cyber and this i assessing futue somebodyne could do more damage with a keyboard and with a bomb. They were looking at it as a new nuclear weapon. In 97, this analyst named Richard Clarke was put in charge of this and he didnt know anything about computers. They would go to talk to executives and microsoft has a lot ofiv operating systems. But nobodyps knew about anything else and they didnt know about vulnerabilities and the things in between. I dont know how much you want me to get into this but he met them in the square and this whole group is called the law on the second floor of the warehouse in boston and they have stuff and they were able to do things their, replicate any kind of equipment, hack into anything and got changed the whole model. He realized okay you are getting things word you are able to do things that in the white house we have said on th many nationstates can do and clark at the time was chasing Osama Bin Laden and said this will be great for part of my portfolio, cyber terrorism. If they were terrorists they could do acts, so this was the whole cyber war and what it might result in. This one thing thatn. Has not panned out yet. I dont think there are any terrorist groups out there that are able to do things as the hackers are getting paid to do things in theey infrastructure. Is there yet one more iteration where the surveillance becomes a part of the story . Can you talk about the impact of the changes and the technology that takes us up that . Up to about this time, they were intercepting radio signals into that kind of thing. Then they noticed the hippies listening towers over the world and certain parts of the world nothing is coming in anymore. They are not getting any communications because theyve gone to fiber optics and they have no to do this. Somebody that has been a director before wrote a paper for that classified Congressional Committee that was called are we a going to. The cold war was ending about this time, too. The nsa used the divide in the group tracking the russians and the rest of the group. Shouldnt this becomes quite a lot, and this is where we get into the movie sneakers. So, Mike Mcconnell gets into the nsa looking around saying what does this organization to . We are not getting the radio signals anymore. What c do we do . Here is a map of the communication and that you need to look at and the only maps of fiber optics. Okay thats interesting. So for those who didnt see it, its about hackers. Nothing like this existed so there was a kind of ridiculous plots where they get a call from the nsa with a decrypting code and it turns out the nsa people were the criminals and he was working for the government to try to get back. Its one thing where ben kingsley who is kind of an evil mastermind who used to be a College Roommate and theres this whole monologue is about the information. So he sits up in his chair and said this is our Mission Statement now. Since goes back and gets the last reel of the film and has everybody at the nsa watching. He tells everybody to go watch this movie and to even take off the afternoon to go watch the movie. He takes one of the best field offices, brings him back to fore meade, creates a child called the director of Information Warfare and all these kind of may send outfits around the military and this is the Information Warfare center. But what they really did is create the access operation so they figured out how to get into the computers and so they said i need to get into thisis guys email. So we designed the phon where tr the radio signal anymore. It now they created an air gap. How do we cross over to air gap and then theres the information n. Center. They look over and planto a device and with that i would inserts some malware and kept him from that. He said what can i do to protect myself and i said if all youre interested is keeping out petty criminals, there are things you can y do. But somebody that really knows what hes doing and want some that you have the resources of the nationstate. The pentagon, this is skipping ahead a little bit, but they had a special panel on the cyber warfare c and concluded the inherent fragility of thee infrastructure. The inherent fragility. They report it and looked at the record and the red team was tasked to hack into the command control system. So now they dont talk about prevention much. You dont just leave your door open. Y they are talking about detection and resilience. You can detect when somebody is coming and resilience you can repair the damages. You dont want to give up the game, the day are going to get in. The advantage is built on things that are networked and its back to the tang and rifles. So thats what people are very worried about. One of the other things raises the important question of what it means for the nature of warfare going forward. Ithats a lot of information and the attack on the civilian system that may not be as well protected, what does this mean for a student of National Security . There are a lot of networks that are not classified. How do you get supplies, a lot of that is on the open networks. They play the games that people mess with that on the air task orders are supposed to play this up is to meet up with a refueling plane. You can do a lot of funny business with that and not even know that it happened. So, that sort of thing. In terms of the vulnerability of infrastructure, the idea is in the South China Sea turning off the lights of the eastern seaboard of independent becomes more plugged in. The interesting thing about the civilian infrastructure, the military has become more aware ofil this. Theyveav reduced the number of intersections between their own network and the internet to about eight. They can do that so they can actually see when somebody is comingng over. Civilian governments there are hundreds and thousands. Even if they had the right, the department of Homeland Security that supposedly are out to lunch so thats what this led to a good computer Network Defense and attack and exploitation. This is a double edged sword. The only way that i can tel do t they are planning an attack at the same time it is just one step short all you have to do is push a button. Its kind of generally accepted that they can do this. Theres this directive they tried to get the Critical Infrastructures to get some security going that you trust that youwith your money wont g. While we hear a lot about the banks, there are thousands of attempts a day but not very many get in. Youve given some advice on the best practices and th the amount costs to do this is to pay for it anyway. Its for the Critical Infrastructure the secretarys treasury and commerce said you were going to impede to make the servers slover and reduce the competitiveness all of which is true they have their own selfinterestnt they appreciate just how far back. For example president obama on the Cybersecurity National action plan which if you read the book sounds like eight or nine other commissions that have been formed or planned. There is no other executive order giving themti the power. Then you have a month to fix this. Nobody has the power to do that. One thing several people told me that they learned about the executive branch and maybe some of you know this, people go to the executive branch and say im going to create policy. About 10 is creating policy and the other is implemented. They are going back time and time to make sure that its still implemented. It is what has always been lackingg and its always been known on a president ial level for more than 30 years. With reason not necessarily to create new ideas but [inaudible] it is a little late its going to land on the doorstep of the next administration. The other commissioners have a been chosen and they have to find a space to work. Treated by the next administration which is something to put your desk on. What lesson should be taken from that books have explici the boot policy directives at the end. They would look at that and i hope some of them have a history going on for a long time to see how this led to something to make it seem we need somebody in the executive branch that has a lot of power. You need to create a bizarre and its kind of interesting in this. I dont know how these people that work in places like the white house i wouldnt be able to get away from this from 30 different subjects in the light of the problem of Critical Infrastructure. I have people being kidnapped and killed over here a right now its like the scene in all the president s men. It still looks very theoretical to a lot of people. Something has to be decided tomorrow. It is very difficult to focus your attention on something as complicated as this of which there doesnt seem to be an obvious solution. We have a room full of people. Give your affiliation, keep questions short. A few months back, the Computer Systems wall street, United Kingdom simultaneously i think that was coincidental. Some things really are coincidental. Theres about 20 nations with these units. Some are better than others. They are good at hacking into the times and the journal so maybe its a little harder to get into now. Another thing if somebody launches a t Ballistic Missile n go from one place to another to another. They are Getting Better at tracing that but its still not a 100 thing you want to know the reason why we know they attacked sony, basically they did this in real time. We also infiltrated into the network that going back into the finals they can actually watch on their monitors while they are doing a hack. We have extremely high confidence it looks more like an inside job and they absolutely knew. [inaudible] [inaudible] its just a bunch of numbers on the screen and if you are a foreign power. It wasnt the focus of my book, but sure one thing that is interesting, they know how to get into every bank account. It can go the other way [inaudible] it didnt have a chance operation. Its all out there and open a. Its writing a report on cyber deterrence. Is it too deter and attack on the bank, is it just government its pretty clear what the deterrence means. How big of s an impact robert gates asked at what point does this constitute an act of war and they wrote that under certain circumstances because nobody has. With Nuclear Weapons there is a red line between them using Nuclear Weapons. That is one reason nobody is using them in the past few years because you dont know whats going to happen afterwards. There are Cyber Attacks going on thousands of times a day and nobody knows where the line of attack is. Theres this attack that just happened when they attacked over a movie who would have thought that. So there are many opportunities for misunderstanding things getting out of hand because one persons nuisance turns out to be a National Threat and then what happens on day number two. I said i dont know if theyre trying to figure that out. Its something that they just havent thought through and part of the reason is tied up in the nsa. The joke used to be that it stood for no such agency. Even when the bomb went off in 1945, certain things that were classified. They are well understood and from the beginning we have civilian strategists thinking about what does this mean, what does deterrence means. They arrived up in things thinking about this and having an influence. In this labor until very recently, you have to have a clearance so theres nobody that canod think about this that is n the position to think about it seriously. The title of the book i always say the title will emerge from my notes but this time it did. Y book. Then i looked it up, did a Google Search of Dark Territory and what does this mean, i didnt want to have some obscenity so it turns out this is a north american rebel that signifies the stretch of track that is ungoverned by [inaudible] and im thinking wow, that is perfect. I wrote him an email and said did you know this and he said oh yeah, my grandfather worked as a stationmaster on the Santa Fe Railroad across kansas for 50 years. We talked Railroad Terminology all the time. So, that is where i get the perfect description of what is going on except the stretch is much bigger, the engineers are unknown, the consequences of a collision are far more cataclysmic than two trains and that is the situation we are in. I have no interest in speaking for the Us Government but there are beginnings of this work and the strong relation to the chinese and the they are talking about setting up a forum to discuss a process by which they can discuss rules of the road. It is that far out but now gates said this when you are talking about russia and israel in france and china, now how do you bring north korea and iran and syria and how do you bring these guys into this cooperative back room and you know, in the back room someplace and how to divvy up the heroin market. How do you do this now . Its a tough one. There is a document one of the documents that snowden out called tpd 20 which was Cyber Operation policy and it had certain things like different departments were supposed to do and one of them was precisely this, setting rules of the road, state department. There was a Progress Report a year later pending, Progress Report was pending. Its the hardest thing in the world to do because the other thing is if you are going to say okay lets stay out of each others whatever, electrical power plants, youve got to stay out of their electrical power plants, to and how can this be verified. How do you know that they are not in the one time the first discovery of a known intrusion into a classified territory happened in 2008 called buckshot yankee operation and they discovered soviet russian its and other things inside a classified network of us central command. They discovered this because they had the entrance points locked. What if someone is in there messing around and they thought we should go look for the networks and see if anyone is in their and they discovered someone in there. They hadnt gone looking, they might still be in there. So, its a very we are talking about things we have lines of code and thereby meet malware taking up 150 lines of code so how do you even detect that contract how do you detect the lines of code within something that is millions of lines of code its within five minutes they come up with a concept solution. Within 24 hours, they have the solution, tested it and put it into motion. So by monday morning, people were alerted to this and going around counting the number of computers that might be infected and hes saying ridiculous. So he did what people had been urging him to do for a while and put the director of the nsa in charge of Cyber Command as well. And that is when the offense and defense knew what happened. The problem was with the same technology and the only company that knows how to do this everybody else is completely leftsided. So okay, we now have 7 billion. They have links with the combatant commands and if they are devising and have action plans. Tens of thousands of people assigned to this. Where is your area of growth and yet as i was saying a few minutes ago, there is no concept of deterrence or what happens on the second day of the cyber war so you have this machinery and it is all incredibly classified. This machinery going up so you are advanced in the Technology Field before even the finished the year of the policy and strategy have been cemented in two. Is it thathis event is kind of a dangerous thing. The gentle man in the middle. David spencer, georgetown students. What do you propose we do to respond to the level of Cyber Attacks . What do you mean by strategic strategically or hypothetically in the situation not energy but other Critical Infrastructures safe transportation. One thing thats true about our economy if you shut down the subway system of new york with what goes on in washington, san francisco, some countries it could be shot down like transportation and tokyo. They are expending on the smart grid for cyber purposes but it still doesnt take up the entire country. In some ways, everything just looks up to Computer Networks to get the economies of scale. You have everything monitored by sensors and it makes perfect sense. Its everything in control of the computer network. They didnt shut down the centrifuges. They manipulated the control devices that were governing. So theres something thats controlling the amount of water going in and out and the amount flowing through the electrical line. In some ways, the networks are set up in a way that is hard to defend them. The trend in economic commerce is to make them more and more centralized. They want something going on in the entire region of the United States controlled by then this was done. They looked to them like security, what do you mean . You can do things to make the networks more secure. Maybe its been open for years and short of starting all over, which nobody is going to do, its like they were in control and they would go to the government and say what can you do to help us . While, one thing we can do is just sitting on your network, no, not really. Maybe we can give you some of this information sharing ideas and come in for commentary secf briefing with some tools you can use in the justice department. This isnt typical of a terribly happy ending. [inaudible] you might argue one of the factors that are at play [inaudible] is a certain amount of deterrence and now russia and china have their stuff hooked up to the networks. The more this happens the more it rises up suite is a Dark Territory rise. Can you wait for the people who are online . Its slow and the Wind Technology leaders. As far as you are aware, has the government done anything to create, classify some kind of safe environment for Technology Leaders to be talking to them about how the government could be aware and leverage that . In the Defense Industry there was a security base. There are lots of interchanges like this like lockheed martin. Luckily theres about three big Defense Companies left. There are things like that are available. And in recent years, again, there is information sharing system. When he was the cyber guy in the white house that was a certain authoritarian personality. He wanted to create basically an intranet for critical structure where their intranet with the hooked up to Something Like the government agency. In the domestic context unless they have a court order. There are some very good people ahead of the private industry and the nsa but again they cant really show. [inaudible] speak into the microphone, please. There is some thinking to make Innovative Companies comfortable about what they are doing because it would be a position to manage one of the hackers in my book went to work for about 1 18 months have cread 140 projects, the most expensive of which 100,000. He funded the experiment when they hacked into a Jeep Cherokee to show this is the way to do something about this. What they should have done is look at the top ten graduates to give 100,00 100,000 go work o. Theres the offense Defense Cyber arms race [inaudible] wednesday at the conference we had prevented this for the Security Officials specifically talking up the publicprivate partnerships retired physicist, spent a lot of my career. As i look around at the Defense Department, a very vulnerable place to attack you would think somehow the signals are going out over the air someplace. Are there any stories about that happening . Thereve been certain rumors, but they are very vocalized. Theif they can get into this s signal. Maybe it is signaling a drone that is just doing surveillance. They had a little game where they are going to hack into the command and control for the refueling plane was sent over here. Drones crash. Id neveive never seen that ve. There could be that like what is this drone looking at then you can look at what the u. S. Is interested in. Im going to take on this side the gentleman but some questions. If there are supports that they have been chalking around for freelancers to do that but maybe there arent that many that are willing to do this. They have their eyes on certain groups that do work for that guy operating out of singapore. They have enough money that they actually do get a permanent so its not out of the question but i do think the convergence of the forces has not happened yet. Talking about the industry and the government. There are a few things. The public statements of both sides do not really coincide with what they are up to. The the fbi already had the metadata. The nsa director said i dont know what is in this phone that they need right now for National Security purposes they could send the letter to the nsa and the attorney general. They didnt require the active cooperation with the bat. At the same time i think basically what the fbi is trying to do is looking for a new legal precedent that gives them the authority to do this sort of thing before encryption gets really, really hard. When this started happening i talked with a number of people in the intelligence agency, and i am pretty convinced there tha way they could have cooperated without having to write a whole new operating system which they say they were being forced to do. The way this works is a security feature that if you type in the ten passcodes and Everything Else what the fbi could do is create a program, we dont even have to be in the same room. So thats after 10,000 tries. We need to have you take away this linear. Im told he can play people on this side of this there are ways they can make that change without writing a whole new operating system. What they are concerned about is once they succumb to this that could be succumbing to other things were saying the things the fbi had to do, we want to have you do that although the chinese could do that anyway. Somebody said i dont know if i can quietly cooperate on this one because you talk about hes dead and has no privacy rights. For practical reasons and political operatives it doesnt look like a great test case for apple. They are writing amicus briefs and if you have a contract with the government you want to sell an operating system for the government. The first Windows Program that went through they found 1500 points of vulnerability. Microsoft knew that and they were fine with it. The system was hacked. Theres been a twoway street and shot for this gambling going on so theres a bit of hypocri hypocrisy. But he does believe in this very strongly and they often go to the companies that seethe compaa meeting to talk about the interests. Although again, [inaudible] the way that they elevated this battle could end up having senator feinstein has code written in law presented with a lawful for rent. There are people worried about elections soft on terrorism. So again i dont know why theyve decided to make a big political issue of this. [inaudible] heidelberg was the one thing we should take away from your buck, but one thing [inaudible] ho how many cyber books can you say that about . Thank you very much for coming. [applause] [inaudible conversations]