National Defense in Obama’s Second Term

Senator Jon Kyl (R, AZ (Ret)) outlined in a Wall Street Journal op-ed what we can see and expect from President Barack Obama during his second term.  It isn’t pretty.  On missile defense, Obama is doing this [emphasis added]:

  • The president is on course to systematically reduce America’s capabilities in both areas despite specific commitments he made while securing bipartisan support for the 2010 New Strategic Arms Limitation Treaty with Russia.
  • [Adding 14 ground-based interceptors in Alaska only] gets us back to the numerical level planned during the Bush administration—and without the technological improvements in ground-based interceptors, or GBIs, that the Bush administration supported.
  • US national missile defense will continue to rely on obsolete 1980s “kill vehicle” technology involving kinetic energy and small warheads.  At 44 GBIs, the system should be effective against the current threat from North Korea, but not against an attack from countries like Russia and China with more robust and mature capabilities.
  • US has canceled the final phase of the Europe-based missile-defense system, which was to have included NATO allies such as Poland as the hosts of sensors and other elements of the system. This will please Russia.
  • [T]he Aegis system the Navy uses to track enemy missiles and guide American ones will be less capable of protecting Europe—from Iran, for instance—and offer even less protection for the U.S. The assurance of deploying the final phase of missile defense in Europe was the Obama administration’s pretext for capping the improvement of America’s GBI system.

On strategic deterrent, Obama is doing this to our triad of ICBMs, SLBMs, and bomber fleet [emphasis added]:

  • Russia is preparing to field a new generation of intercontinental ballistic missiles (one type of which can carry as many as 15 warheads); Obama is still studying whether to develop its own modernized ICBMs.
  • Replacement of the Ohio-class nuclear-ballistic-missile submarine—the foundation of the sea-based leg of the triad—has been delayed for two years, leaving the force with only 10 boats.
  • No decision has been made on whether the next generation strategic-bomber force will even be capable of delivering nuclear weapons.
  • Energy Department and National Security Agency five-year budgets for modernization have been cut by some $4.4 billion.  That’s the same amount Obama had agreed to add to secure Senate support for the New Start treaty in 2010.
  • The building of a modern Chemical and Metallurgy Research Replacement facility for handling plutonium—critical to modernization and added to the Treaty Resolution of Ratification and in the president’s message to the Senate upon entry of the treaty into force—has been delayed at least five years—tantamount to killing it.

As Kyl puts it,

President Obama’s antipathy to both missile defense and our nuclear deterrent risks leaving the U.S. and its allies vulnerable not just to attack, but also to nuclear blackmail and proliferation.

This is a national disaster waiting to reverse the defeat of the Soviet Union.

A Cyber First Strike

John Wohlstetter in The Wall Street Journal defines cyberspace as the software that controls the operation of networks linking computers in the governmental and private sphere.  This is incomplete, though.  Cyberspace includes that, but it also includes the software running on individual computers, whether they are linked into a (the) network or are operating in isolation.  Even those isolated computers, after all, are susceptible to cyber attacks, with many of them (unless they are physically disconnected from any network at all) susceptible to being hijacked into cyber attacks against other computers/networks through such means as social engineering, a process whereby hackers, or hostile governments, or terrorists, or… convince, usually through subterfuge, the human operator of those computers to load malware onto them.

Wohlstetter then identifies the People’s Republic of China’s “military’s massive continuing cyberspying” as an example of one type of cyber attacks that may be simple spying, or that may be preparation for further adventuring.  People’s Liberation Army spies, he notes, have stolen “volumes of documentation on the ultra-advanced F-35 Lightning, the only fifth-generation fighter still being produced by the US,” and they’ve penetrated “every major national-security database that they can within the Pentagon and US defense companies.”  But this could be just ordinary pre-battle preparation.  Every general is going to investigate his enemy so as to understand as clearly as possible that enemy’s force disposition and the strengths and vulnerabilities of that enemy’s systems so as to efficiently neutralize those systems at the battle’s start.

To support these efforts, the PLA “Third Department” (among others),

which handles telecommunications, can call on 12 operation bureaus to carry out cyberattacks, and three research institutes for technical support with some 13,000 staff upon request.

The PRC isn’t alone in this sort of effort.  Russia and Iran are two others who maintain major efforts in offensive cyberspace.

A necessary, but not sole, prelude to defending against a first strike is understanding the nature and depth of what’s happening in a particular incident.  Siobhan Gorman and Siobhan Hughes address this in part, citing Army General Keith Alexander, Commander, US Cyber Command

When does a nuisance become a real problem and when are you prepared to step in for that?  That’s the work that I think the administration is going through right now and highlighting that.

But this is the question concerning a physical problem, too—when does any incursion stop being an error, or stop being minor, and start being an act of war?  And what do we do about it, and when?  Do we simply defend against the incident?  To we take offensive measures to encourage the attacker to not do that anymore, do we take more extensive measures to defeat outright the attacker and compel his acquiescence?  When?  In accordance with what criteria?

And that’s part of where a first strike starts to come into play.  A cyber attack as a first strike in all likelihood won’t occur.  A first strike, though, will include a decisive cyber attack.  We’ve seen rehearsals of the cyber component:

  • the “PLO virus,” a logic bomb designed to infect and destroy files on computers [a very early virus, its “rehearsal” aspect is in the lessons learned in managing and delivering such malware]
  • 2010’s stuxnet, which damaged or destroyed hardware—high-speed centrifuges, in one case, by causing them to run too fast and burn themselves out
  • 2012’s cyberassaults on the websites of many US banks
  • 2012’s more destructive attack on a Saudi oil company that destroyed 30,000 computers
  • the implantation of malware on computing equipment prior to sale and delivery to the target nation.  For instance, I bought a laptop from an otherwise reputable major computer company; it was delivered to me directly from the factory in Shanghai—with a Trojan carefully installed.

Given the penetration of American systems by the Chinese, it’s not beyond the pale that either a) this kind of malware has infected the computing systems managing any target nation’s infrastructure—water, electricity, communications, et al.—and the target nation’s defense systems, including, but not necessarily limited to, sensor suites and communications, or b) this kind of malware is ready to be emplaced in the weeks prior to the intended first strike.

How would a first strike work, then?  With the malware in place, sufficient of it could be triggered to shut down a nation’s electrical grid, its water handling and delivery systems, and its financial infrastructure.  With responders deployed to deal with this—and so widely dispersed—communications then could be crippled, isolating those responders, and isolating that nation’s population from each other and from their government.  Far fetched?

Russia tested a limited cyber attack against Estonia in 2007.  Moreover, as Gorman and Hughes note the temptation offered by our own continued vulnerability:

US intelligence officials told a Senate hearing that the nation is vulnerable to cyberespionage, cybercrime, and outright destruction of computer networks, both from sophisticated, government-sponsored assault as well as criminal hacker groups and cyberterrorists.

“It’s hard to overemphasize its significance,” Director of National Intelligence James Clapper said, addressing members of the Senate Intelligence Committee. “These capabilities put all sectors of our country at risk—from government and private networks to critical infrastructures.”

Then, with cyber’s civil battlefield preparation in place and domestic upset rising, additional malware could be triggered to attack defense sensory and communications systems (among others), greatly disrupting, if not crippling them.  This phase of the cyber preparation could functionally blind physical military units and cut off their communications with adjacent units and higher command echelons.  In this environment, many of those units might not even know they’re next coming under physical attack until they start being destroyed.

This isn’t even a new strategy; it just uses modern facilities.  Karl Marx and Friedrich Engels wrote about this a century and a half ago, as noted by Sigmund Neumann and Mark von Hagen in Makers of Modern Strategy:

They were fully aware that military campaigns could be lost before the first shot, that they would in fact be decided beforehand on the preliminary battlefronts of economic and psychological warfare….  To [Marx and Engels] war was fought with different means in different fields.

Modern economies expand the opportunities to be gained from a first strike.  Most modern economies don’t have an industrial capacity.  Modern industry either assembles components that have been manufactured in other countries or it consists of component manufacture which are then shipped to those assembling economies.

A Cyber first strike would be no worse than a Pearl Harbor?  On the contrary, a properly executed first strike, as a classical combined arms assault that would include cyber warfare, could prevent us utterly from responding in any way at all, whether in cyberspace or in meat space.  There may not be any opportunity to work our way through our response decision criteria.

In a modern war (now exacerbated by those modern national economies), there will be no time to recover, to build up our forces, to bring our industrial capacity to a wartime footing and production rate.  We’ll fight this war with the army we have and with nothing at all, including replacement equipment and soldiers, else.

We could be left prostrate, begging for mercy.  If we could get our radios and telephones to work well enough to beg.

None of this is to suggest that a first strike is imminent.  But responding after the fact will be no response at all.  If we’re not better prepared, though, after the fact is what will be left to us.

Update:  Here’s a realtime example of a cyber attack rehearsal.

Computer networks at major South Korean banks and top TV broadcasters crashed simultaneously Wednesday, paralyzing bank machines across the country and prompting speculation of a cyberattack by North Korea.

Screens went blank at 2 p.m., the state-run Korea Information Security Agency said, and more than six hours later some systems were still down.

Something about Missile Defense

I won’t go into the older history of the Progressives’ vilification of President Ronald Reagan over his push for a missile defense, and I won’t mention then-Senator John Kerry’s (D, MA) denunciation of such a system as

a dream based on illusion, but one which could have real and terrible consequences[.]

But we do need to think about Presidential Candidate Barack Obama’s 2008 promise to gut missile defense development programs and—in one of the few spending cuts to which Progressives have agreed in recent history—to cut spending on such things.

We do need to think about President Barack Obama’s betrayal of Poland and the Czech Republic when he cancelled agreements to deploy missile defense systems there on the basis of Russian demurral.

We do need to think about spending $2 billion to add a whole 14 interceptors to our existing de minimis system in this time of world-ending sequester.

We do need to think about Defense Secretary Chuck Hagel’s analysts justifying all of this:

Although American and South Korean intelligence officials doubt the North is close to being able to follow through on a nuclear strike, or that it would even try, given its almost certain destruction, analysts say the country’s aggressive behavior is an important and worrying sign of changing calculations in the North.

After all, this “analysis” comes in light of the Russians and the Iranians having or being allowed to achieve this capability, yet we withdraw missile defenses from European locations that could defend Israel and Europe.

We do need to think about DoD delaying deployment at additional sites, including the East Coast, in order to do an environmental study, first.

We do need to think about whether this administration has any sort of clue at all about a coherent national defense policy.

Congressman Mike Rogers (R, AL), Chairman of the House Armed Services Committee’s Strategic Forces Subcommittee, is saying

Four years ago, the Obama administration began to unilaterally disarm our defenses and deterrent in the hope our enemies would follow suit.  President Obama is finally realizing what President Reagan taught us 30 years ago—the best way to keep the peace is through strength.

But is he?  Or is all of this just the loud posturing of a paper tiger?  After all, Pentagon officials are dismissing Rogers’ criticism, insisting that northern Korean technology was considerably less developed four years ago.  Yet surely they know that Russia’s wasn’t, when Reagan’s missile defense efforts were so loudly pooh-poohed, and surely they know that Russian technology was 30 years improved when Obama acceded to Russian demands to cancel our missile defense plans in eastern Europe.

Hmm….

Obama and the Iranians

If you have to deny that you’re bluffing, it’s pretty clear that you are bluffing.  Yet Vice President Joe Biden ran exactly that line in front of last week’s AIPAC conference.  America’s policy, he said,

is to prevent Iran from acquiring a nuclear weapon, period.  President Barack Obama is not bluffing.  He is not bluffing.

The next day, General James Mattis, Commander US Central Command, testified before the Senate Armed Services Committee, which included this exchange:

Senator James Inhofe (R, OK):  Are the current diplomatic and economic efforts to stop Iran from obtaining a nuclear weapons capability, are they working?
General Mattis: No sir…[Tehran’s] nuclear industry continues.

Indeed, the sanctions may well be hurting the Iranian people.  However, the Iranian government cares more about getting nuclear weapons than it does about the welfare of its people.  Since the sanctions aren’t hurting the government, they cannot work.

Informed by this mindset, the Iranian government is quite satisfied that the US is bluffing.  They’ve seen in all these years (not limited to the Obama years) no evidence that the US is serious on the matter of a nuclear armed Iran, no evidence that we will ever become serious, no evidence that we will go beyond sanctions to real moves to stop them.

PRC Cyberwar

Here’s an example of the People’s Republic of China’s war on us, here in cyberspace, described in BusinessWeek.

In 2011, [Dell SecureWorks Director of Malware Research, Joe] Stewart turned his sights on China. “I thought I’d have this figured out in two months,” he says.  Two years later, trying to identify Chinese malware and develop countermeasures is pretty much all he does.

Malware from China has inundated the Internet, targeting Fortune 500 companies, tech startups, government agencies, news organizations, embassies, universities, law firms, and anything else with intellectual property to protect.  A recently prepared secret intelligence assessment described this month in the Washington Post found that the US is the target of a massive and prolonged computer espionage campaign from China that threatens the US economy.  With the possible exceptions of the US Department of Defense and a handful of three-letter agencies, the victims are outmatched by an enemy with vast resources and a long head start.

Stewart tracks about 24,000 Internet domains, which he says Chinese spies have rented or hacked for the purpose of espionage. … He catalogs the malware he finds into categories, which usually correspond to particular hacking teams in China.  He says around 10 teams have deployed 300 malware groups, double the count of 10 months ago. “There is a tremendous amount of manpower being thrown at this from their side,” he says.

The intel assessment to which the BusinessWeek article referred was summarized here.

The National Intelligence Estimate identifies China as the country most aggressively seeking to penetrate the computer systems of American businesses and institutions to gain access to data that could be used for economic gain.

The report, which represents the consensus view of the U.S. intelligence community, describes a wide range of sectors that have been the focus of hacking over the past five years, including energy, finance, information technology, aerospace and automotives, according to the individuals familiar with the report, who spoke on the condition of anonymity about the classified document. The assessment does not quantify the financial impact of the espionage, but outside experts have estimated it in the tens of billions of dollars.

An example of the cascade effects of China’s war, from that intel summary:

In 2011, when Chinese hackers attacked network security company RSA Security, the technology stolen was used to penetrate military-industrial targets.  Shortly after, the networks of defense contracting giant Lockheed Martin, which used RSA security tokens, were penetrated by Chinese hackers.

There are a couple of questions remaining in this cynic’s mind.  One concerns the apparent ease with which Stewart and his Indian follow-on tracked down this Chinese hacker (an effort described in the BusinessWeek article).  I have to wonder whether the “hacker” was a honeypot and how well the two trackers covered their own tracks—or whether they left their employers exposed.

The other flows from that first question.  Assuming no honeypot, it seems apparent that the hacker was discovered because he was careless, and not because our guys were better at the cyber combat.  Is the US helplessly bringing a jackknife to a combined arms assault?  Is that why our government’s efforts to protect us—and to counter and retaliate—are so infantile?  And the latter so timid:

[T]he Obama administration is seeking ways to counter the online theft of trade secrets, according to officials.  Analysts have said that the administration’s options include formal protests, the expulsion of diplomatic personnel, the imposition of travel and visa restrictions, and complaints to the World Trade Organization.

Pleas and chit-chat, nothing serious.

How did we get so helplessly far behind?  Our government (not just the present administration) has had no understanding at all of the threat posed.  A former government official said,

The problem with foreign cyber-­espionage is not that it is an existential threat, but that it is invisible, and invisibility promotes inaction.

Understanding how our weapons work so they can be neutralized, knowing where and how to plant malware to shut down our financial, transportation, and energy infrastructure—and having the malware to plant—threatens our sovereignty.  That it’s “invisible” is simply an aspect of any war: camouflage and stealth.  The government has first to understand that we’re in a war with the Chinese for our independence; then the fact of invisibility for the Chinese combatants will be understood for what it is—just a technique for advancing their attacks.