奥运会网络安全_2020届奥运会和其他重大赛事的经验教训(英文版)_95页_1mb
报告摘要
Olympic-Caliber Cybersecurity: Summary
Core Content
This report provides an in-depth analysis of the cybersecurity threat landscape for the 2020 Tokyo Summer and Paralympic Games, offering insights and policy recommendations to safeguard such major international events. The study was conducted by RAND Corporation and focuses on identifying potential cyber threats, threat actors, and the necessary strategies to mitigate them. It also draws on lessons from previous Olympic Games to inform Tokyo 2020's cybersecurity preparedness.
Main Objectives
- To profile the cybersecurity threat landscape faced by Japan as the host of the 2020 Olympic Games.
- To develop a threat actor typology based on a risk assessment of the Tokyo 2020 threat landscape.
- To provide a visualization of the threat landscape for guidance in cybersecurity planning.
- To inform public policy debates on cybersecurity preparations for mega-events.
- To serve as a basis for future research on cyber threats to international events.
Key Threat Categories
The report identifies four high-level threat categories that should be prioritized for the Tokyo 2020 Games:
-
Targeted Attacks
- Aimed at high-profile Olympic assets, individuals, or organizations.
- Motivation: Ideology or political gain.
- Sophistication: High.
- Risk: High (likelihood and impact).
- Priority: Highest.
-
Distributed Denial of Service (DDoS) Attacks
- Can disrupt availability of services or distract from other attacks.
- Can be launched by both advanced threat actors (e.g., nation-states) and less sophisticated groups (e.g., hacktivists).
- Risk: Medium (likelihood and impact).
- Priority: High.
-
Ransomware Attacks
- Can affect a wide range of devices, services, and infrastructure.
- Includes participant and visitor devices, transportation systems, and point-of-sale systems.
- Risk: Medium (likelihood and impact).
- Priority: Medium.
-
Cyber Propaganda or Misinformation
- Aimed at causing reputational loss or political disruption.
- Risk: Medium (likelihood and impact).
- Priority: Medium.
Threat Actor Typology
The report provides a prioritized risk assessment of threat actors, as outlined in Table S.1:
| Threat Actor | Adversary Motivation | Sophistication | Risk (Likelihood) | Risk (Impact) | Risk Prioritization | Rank |
|---|---|---|---|---|---|---|
| Foreign intelligence services | Ideology | High | Medium | High | High | 1 |
| Cyberterrorists | Ideology/revenge | Medium | Medium | High | High | 2 |
| Cybercriminals/organized crime | Profit | High | Medium | Medium | Medium | 3 |
| Hacktivists | Ideology/revenge | Medium | Medium | Medium | Medium | 4 |
| Insider threats | Revenge/profit | Medium | Low | Medium | Medium | 5 |
| Ticket scalpers | Profit | Medium | High | Low | Low | 6 |
Lessons from Previous Olympic Games
The report outlines five general categories of lessons from past Olympic cybersecurity experiences:
-
Plan early
- Allow sufficient time to assess threats, build trust, and establish mechanisms for information sharing and incident reporting.
-
Prioritize cooperation and information sharing
- Involve both public and private sector stakeholders in cybersecurity planning and response.
-
Establish a shared mission and common goal
- Foster trust and commitment among stakeholders through a unified cybersecurity objective.
-
Clearly define roles and responsibilities
- Ensure all parties understand their contributions and know whom to refer challenges or incidents to.
-
Incorporate cybersecurity into broader security planning
- Integrate cybersecurity into overall security training and exercises from the outset.
Policy Recommendations
The report suggests seven key policy options for Olympic cybersecurity planners:
-
Plan early
- Ensure enough time for threat assessment and stakeholder engagement.
-
Cooperate and share information
- Encourage collaboration between public and private sectors.
-
Know the mission and have a common security goal
- Promote a shared understanding of the cybersecurity mission.
-
Define roles and responsibilities
- Clarify the roles of all stakeholders to ensure effective response.
-
Allocate resources to mitigate risks
- Invest in threat actors identified as most risky, based on a risk-based approach.
-
Deter the riskiest adversaries
- Implement targeted cyber defense campaigns to dissuade attacks, such as public cybersecurity exercises.
-
Incorporate cybersecurity into broader security planning
- Integrate cyber considerations into all aspects of Olympic security planning.
Japan's Cybersecurity Structure
Japan's cybersecurity policy involves a multi-stakeholder approach, with the following key bodies:
- IT Strategic Headquarters: Established in 2000, responsible for promoting an advanced ICT society and adapting to socioeconomic changes. Led by the Prime Minister.
- National Security Council: Established in 2013, focusing on strategic discussions on national security issues.
- Cyber Security Strategic Headquarters: Established in 2014 under the Cybersecurity Basic Act, responsible for coordinating cybersecurity policies and monitoring government-related organizations handling personal data.
- Government Security Operation Coordination Team: Part of the Cyber Security Strategic Headquarters, coordinates with critical infrastructure ministries.
- JPCERT/CC: Japan's first computer emergency response team, formed in 1996. Coordinates with various stakeholders and publishes regular reports.
Limitations
- The analysis is based on open-source data and does not include classified information.
- Limited interviews with experts were conducted.
- The lack of independent empirical research on hacker subcategories constrained the attribution of cyber incidents.
- The report treats policy options as suggestions rather than definitive recommendations.
Conclusion
This report serves as a valuable reference for stakeholders involved in securing the Tokyo 2020 Games and for future research on cyber threats to mega-events. It emphasizes the importance of early planning, stakeholder collaboration, and a unified cybersecurity strategy to effectively mitigate risks and ensure the safety of the Olympic Games.
试读结束,高清完整版pdf/doc/ppt,请点下载