战略与国际研究中心-Cyber_2页_137kb
报告摘要
Cyber-terrorism and Cybersecurity Summary
Core Content
This document, published by the Center for Strategic and International Studies on January 6, 2002, by James A. Lewis, discusses the emerging threat of cyber-terrorism and the importance of cybersecurity in protecting the United States' critical infrastructure.
Main Points
-
Context of Cyber-terrorism:
The document highlights that the September 11 attacks brought national attention to the vulnerabilities of the United States, including the risk of cyber-terrorism. Cyber-terrorism is defined as the use of the Internet to attack essential components of the American economy. -
Nature of Cyber-terrorism:
Cyber-terrorism is portrayed as a less damaging threat compared to physical attacks, but it is still a serious concern. It is currently more akin to "cyber-graffitti" rather than a major destructive force, as most attacks have been limited to defacing websites. -
Potential Impact of Cyber-attacks:
Although not as destructive as physical attacks, cyber-attacks can have significant economic consequences. Examples include the disruption of the electrical power grid or the banking system, which could cause substantial financial damage. Additionally, cyber-attacks can be combined with physical attacks, such as disabling the 911 system during a crisis, thereby increasing the overall impact. -
Overlap with Cybercrime:
Cyber-terrorism may also intersect with cybercrime, where malicious groups could steal sensitive data or credit card information for both harm and profit. -
Current Government Response:
The U.S. government has taken steps to address these threats, including the establishment of the National Infrastructure Protection Center (NIPC) at the FBI and the Critical Infrastructure Assurance Office (CIAO) at the Department of Commerce. The current administration has further integrated cybersecurity into the Office of Homeland Security. -
Recommendations for Improvement:
The document suggests several measures to enhance cybersecurity, such as:- Encouraging insurance companies to incorporate cybersecurity into their business insurance policies.
- Modifying the Freedom of Information Act to facilitate information sharing about vulnerabilities.
- Funding cybersecurity research and development.
- Requiring corporations to disclose their cybersecurity vulnerabilities and mitigation strategies in annual reports, similar to the approach taken during the Y2K crisis.
Key Information
- Threat Assessment: Cyber-terrorism is a real threat, but it is often less damaging than physical attacks. However, its economic impact can be severe.
- Critical Infrastructure: The U.S. power grid, banking system, and communication networks are particularly vulnerable to cyber-attacks.
- Government Initiatives: The establishment of NIPC, CIAO, and ISACs represents a significant step in addressing cybersecurity threats.
- Collaboration Needed: The document emphasizes the need for collaboration between the government and the private sector to reduce vulnerabilities and enhance security.
Conclusion
While the current level of cyber-terrorism is not as devastating as physical attacks, the potential for economic and strategic damage remains high. The U.S. is making progress in addressing these threats through policy and institutional changes, but more comprehensive and proactive measures are necessary to ensure long-term cybersecurity resilience.
试读结束,高清完整版pdf/doc/ppt,请点下载