2018-国家和地方选举网络安全手册(英文版)
报告摘要
Summary of The State and Local Election Cybersecurity Playbook
Core Content
The State and Local Election Cybersecurity Playbook is a guide developed by the Defending Digital Democracy Project (D3P) to help state and local election officials protect the democratic process from cyber attacks and information operations. The document emphasizes the importance of cybersecurity in modern elections, which are increasingly vulnerable due to the decentralized and complex nature of the U.S. election system.
Main Purpose
The Playbook aims to:
- Educate election officials on the most likely and serious cybersecurity and information operation threats.
- Provide actionable risk-mitigation strategies for securing the election process.
- Offer a framework for understanding and responding to these threats through best practices and technical recommendations.
Key Information
Threat Landscape
Elections face a variety of threats from both cyber attacks and information operations. These threats are designed to undermine the integrity of the vote and public trust in the election process.
Cybersecurity Threats
- Cyber attacks can disrupt, disable, or manipulate election systems. Common types include:
- Spear phishing: Targeted attacks that trick individuals into revealing sensitive information.
- Denial of Service (DoS): Attacks that prevent users from accessing critical election systems.
- Device takeover: Unauthorized access to election infrastructure.
- SQL injection: Exploiting database vulnerabilities to alter or steal data.
- Port scanning: Identifying and targeting unprotected systems.
- Man-in-the-middle (MITM) attacks: Intercepting data between two parties.
- Distributed Denial of Service (DDoS): Overloading systems with traffic to disrupt services.
- Insider threats: Malicious use of access by employees or authorized individuals.
Information Operations
- Information operations involve the spread of false or misleading information to manipulate public opinion and influence behavior. These tactics include:
- Leaking stolen information: Disclosing sensitive data to erode trust.
- Spreading false information: Disseminating misleading content about election procedures or candidates.
- Amplifying divisive content: Using social media to deepen political or social divisions.
- Interrupting public-facing online resources: Disrupting websites or services to undermine public confidence.
Adversaries and Motivations
-
Possible actors include:
- Nation-state actors: Such as Russia, China, Iran, and North Korea.
- Criminals: Motivated by financial gain or notoriety.
- Black hat hackers: Individuals seeking to exploit systems for personal or ideological reasons.
- Insiders: Employees or contractors with access to election systems.
- Politically motivated groups: Seeking to influence or disrupt the democratic process.
-
Motivations for these attacks include:
- Financial gain
- Retribution for perceived grievances
- Fame and reputation
- Sowing social division
- Terrorist activities
- Politically motivated interference
- Fomenting chaos or anarchy
- Subverting political opposition
- Supporting foreign policy objectives
- Undermining trust in democracy
Known Hostile Actors
- Russia: Involved in the 2016 U.S. presidential election through cyber attacks and information operations. It also targeted Ukrainian and French elections.
- China: Believed to have hacked Democratic and Republican campaigns in 2008 and 2012.
- Iran: Conducted cyber attacks on U.S. financial institutions and demonstrated cyber capabilities in 2013.
- North Korea: Responsible for the "WannaCry" ransomware attack and has targeted financial institutions and SWIFT systems.
The Election System Overview
The Playbook breaks down the election process into three levels of cybersecurity risk:
- Level 1 (Core Systems): Includes voter registration databases, electronic poll books, vote capture devices, tally systems, and election night reporting (ENR) systems.
- Level 2 (Intermediary Systems): Includes state and county-level systems and internal communication channels.
- Level 3 (External Functions): Includes vendors and media (both traditional and social) that interact with the election process.
Vendor Involvement
Vendors are integral to the election process, providing:
- Software and hardware for voter registration and ballot casting.
- Server and database management.
- Websites and tools for displaying election results.
- Ballot design and system integration.
Some vendors are involved in such a large scale that they could become a single point of failure. Over 60% of American voters use systems owned by a single vendor, highlighting the risk of centralized vulnerabilities.
Importance of Leadership
- The leadership of election officials, such as Secretaries of State and Election Directors, is critical in establishing a culture of security.
- Proactive leadership is essential to defend democracy against evolving cyber threats.
Mitigation Strategies
-
The Playbook outlines 10 best practices that apply to all jurisdictions.
-
It includes technical recommendations for securing each component of the election system.
-
Two appendices provide detailed guidance on:
- Vendor selection and management
- Election audits
-
Additional resources include:
- The Election Cyber Incident Communications Coordination Guide
- The Election Cyber Incident Communications Plan Template for State and Local Election Officials
Conclusion
The State and Local Election Cybersecurity Playbook is a comprehensive resource aimed at enhancing the security of the U.S. election system. It acknowledges the complexity and decentralization of elections, the growing threat of cyber attacks and information operations, and the need for a coordinated, proactive approach to cybersecurity. The Playbook is intended to be a practical guide for election officials, emphasizing the importance of understanding threats and implementing risk-mitigation strategies. It also serves as a model for election officials globally facing similar challenges.
试读结束,高清完整版pdf/doc/ppt,请点下载