The information systems controlling our critical infrastructure are vulnerable to cyber attack. Cyber war is therefore inevitable unless we improve our cyber defenses. The only way to do this is by building security into systems at the design stage. Key Words: Cyber WarSoftware SecurityComputer SecurityAttributionBuilding Security In Acknowledgements Parts of this article were originally published as 'Software Security,' IEEE Security & Privacy Magazine (March/April 2004), <www.cigital.com/papers/download/bsi1-swsec.pdf>; on the SearchSecurity website as 'Software security assurance: Built it in, built it right', SearchSecurity (April 2012), <http://searchsecurity.techtarget.com/opinion/Gary-McGraw-on-software-security-assurance-Build-it-in-build-it-right>; and as part of America's Cyber Future: Security and Prosperity in the Information Age Volumes I and II (Center for New American Security 2011). Special thanks to Ivan Arce of Fundación, Dr Manuel Sadosky (Argentina), Sammy Migues from Cigital, and Ralph Langner for insightful comments. Notes 1Miles McQueen, Trevor McQueen, Wayne Boyer, and May Chaffin, 'Empirical Estimates and Observations of 0 Day Vulnerabilities', Proc. HICSS (2009), 1–12, <www.inl.gov/technicalpublications/Documents/4045031.pdf>. 2Verizon Business RISK Team, 2011 Data Breach Investigations Report, <www. verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2012_en_ xg.pdf>. 3David DeWalt, 'Unsecured Economies – A Trillion Dollar Headwind,' McAfee Blog Central (29 Jan. 2009). 4Gary McGraw and Nathaniel Fick, 'Separating the Threat from the Hype: What Washington Needs to Know About Cyber Security', in America's Cyber Future: Security and Prosperity in the Information Age Volumes I and II (Washington DC: Center for a New American Security June 2011); Thomas Rid, 'Cyber War Will Not Take Place', Journal of Strategic Studies 35/1 (Feb. 2012), 5–32. 5Richard Clarke and Robert Knake, Cyber War (New York: Ecco 2010). 6Uzi Mahnaimi, Sarah Baxter and Michael Sheridan, 'Israelis "blew apart Syrian nuclear cache"', The Sunday Times, 16 Sept. 2007. 7David E. Sanger, 'Obama order sped up wave of cyberattacks against Iran', New York Times, 1 June 2012. See especially, <www.nytimes.com/interactive/2012/06/01/world/middleeast/how-a-secret-cyberwar-program-worked.html>. 8According to Ralph Langer (personal communication): 'Stuxnet was clearly designed with the goal to not harm any operator. It is an intentional low-yield weapon, as can be shown by forensic analysis which I plan to publish later this year. Thomas Rid apparently does not understand control and safety systems. It is certainly possible to kill with a cyber attack, or to damage a building.' 9Rid, 'Cyber War Will Not Take Place', 11. 10Scott Peterson and Payam Faramarzi, 'Exclusive: Iran hijacked US drone, says Iranian engineer', Christian Science Monitor (15 Dec. 2011), <www.csmonitor.com/World/Middle-East/2011/1215/Exclusive-Iran-hijacked-US-drone-says-Iranian-engineer-Video>. 11Gary McGraw, 'Cyber War: Hype or Consequences', InformIT (17 June 2010), <www.informit.com/articles/article.aspx?p=1597476>. 12Greg Hoglund and Gary McGraw, Exploiting Software (Reading, MA: Addison-Wesley Professional 2004). 13Gary McGraw, Software Security (Reading, MA: Addison-Wesley Professional 2006). 14McGraw and Fick, 'Separating the Threat from the Hype'. 15Gary McGraw, 'Software [In]security: How to p0wn a Control System with Stuxnet', InformIT (23 Sept. 2010), <www.informit.com/articles/article.aspx?p=1636983>. 16Thomas Ricks, 'Covert wars, waged virally', review of Confront and Conceal, by David Sanger, New York Times, 5 June 2012, <www.nytimes.com/2012/06/06/books/confront-and-conceal-by-david-sanger.html>. 17Ralph Langer, Robust Control Systems Networks (New York: Momentum Press 2011), <www.langner.com/en.>. 18Ralph Langer, personal communication with author. 19Ralph Langer, personal communication with author. 20Gary McGraw, Exploiting Online Games (New York: Addison-Wesley 2009). 21Gary McGraw, Software Security. 22See <http://bsimm.com>. 23Gary McGraw, Building Secure Software (Reading, MA: Addison-Wesley Professional 2001). 24McGraw, Software Security. 25William J. Lynn, 'Defending a New Domain', Foreign Affairs 89 (2010), 101.
No takes yet. Share an insight, caveat, or question.
Gary McGraw (2013) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: