Former director of the United States National Security Agency (NSA), Keith Alexander, has called upon the United States, Australia, and other allies to operate under a unified cyber defence “radar” to defend against international cyber attackers and protect critical infrastructure.
“Cyber is going to be hugely important for our future,” Alexander said. “It’s the one area where adversaries can attack Australia and the United States without trying to cross the oceans.”
In particular, Alexander suggested a radar-like mechanism that would allow organisations to report cyber attacks to a centralised location visible by the cyber security departments of both governments and private organisations.
“We need an ‘event generator’ that shows events that are hitting companies at network speed, that can be anonymised, pushed up to the cloud, and create a radar picture so you can now see all the companies where these types of events are hitting.”
“Imagine if we built a radar picture for cyber that covered not only what impacts Australia, but what impacts other countries, and we could share in real time threats that are hitting our countries and protect from that,” Alexander said.
Alexander highlighted that a rising threat of cyber actors was becoming increasingly difficult to face, especially without cooperation from vulnerable industries.
“I think the biggest problem that I faced in government, and that we face today, is governments—not just ours, but yours as well—can’t see attacks on the private sector. Yet the government is responsible for defending the private sector,” Alexander said.
However, regardless of source, Alexander argued that almost none had been brought to justice with repercussions often limited solely to verbal condemnation.
“We have to attribute who’s doing it and make them pay a price right now,” Alexander said. “The ransomware guys, and Russia, predominantly get off pretty much free.”
“Imagine if we indicted [them] and put their picture up and said ’that’s the guy,'” Alexander said. “And if we can, we will arrest you. You can’t move out of Russia, you’re gonna have to stay there for the rest of your life ... we got you, we know who you are.”
Typically, governments have been incapable of cooperating with private organisations to the extent necessary to address cyber threats.
Bradshaw said that while an optional reporting system was already in place, more government involvement through a mandatory system would be necessary to identify future threats.
“The threat against critical infrastructure is real,” Bradshaw said.
“We analysed that at least a quarter of those attacks which were recorded relate to entities which we would regard as critical infrastructure. That’s a scary statistic. It’s more scary when we know that the instances of attacks are severely underreported.”
“We are in hand-to-hand combat with the bad guys every day. We know what they look like, probably because we’ve seen them before. We can establish patterns ... and we draw those patterns together and use the full range of our intelligence capabilities to make assessments as to who might be next.”