大西洋理事会-未准备的美国:海盗时代勒索软件的教训(英)-2022.4-14页_1mb
报告摘要
Summary: America the Unready: Viking Age Lessons for Ransomware
Core Content
This report draws parallels between the historical Viking Age and the modern ransomware threat, using the Viking Age as a lens to understand how the United States can better respond to ongoing cyberattacks. The central argument is that, like the Vikings, ransomware groups exploit weaknesses in fragmented and unprepared systems, and that effective defense requires a coordinated, long-term strategy.
Main Points
-
Ransomware as a Modern Extortion Tool: Ransomware attacks have evolved from medieval Viking raids to a sophisticated form of cyber extortion. These attacks target critical infrastructure, such as hospitals, schools, and energy systems, and have become increasingly frequent and damaging.
-
The Danegeld Analogy: Paying ransomware groups for data decryption is compared to paying the Vikings (danegeld) to avoid attacks. However, such payments are seen as ineffective and potentially dangerous, as they may encourage further attacks and do not guarantee the recovery of data.
-
Need for Collective Resilience: The report emphasizes that the US must move beyond reactive measures and build a system of collective resilience, much like King Alfred the Great did during the Viking Age. This involves aligning incentives across stakeholders, improving cyber competencies, and enhancing detection and response capabilities.
Key Lessons from History
Lesson One: Altering Incentives
-
Historical Context: King Alfred the Great changed the incentive structure of the nobility to ensure collective support for national security. He replaced traditional noble appointments with individuals who were directly loyal to him.
-
Modern Application: Governments and private sector stakeholders should align incentives to promote preparedness over payment. This includes shaping vendor behavior through policies and funding, such as supporting secure software development and transparency in supply chains.
-
Recommendations:
- Establish a Cybersecurity and Infrastructure Security Agency (CISA) team with dedicated funds for improving open-source projects.
- Implement a Software Bill of Materials to enhance supply chain transparency.
- Provide guidance and resources to companies that choose not to pay ransoms, encouraging a nonpunitive approach to cyber defense.
Lesson Two: Raising Competencies
-
Historical Context: Alfred reformed the fyrd, a military force, to ensure a more professional and mobile defense system. He also introduced service rotation, allowing local forces to protect their own territories.
-
Modern Application: Cybersecurity should be treated as a "whole of nation" issue, requiring widespread competence and awareness. End users are a critical point of vulnerability but also of potential improvement.
-
Recommendations:
- Promote cyber-literate behaviors among the general population.
- Invest in cybersecurity education and diversity initiatives.
- Encourage collaboration between government, private sector, and civil society.
- Consider establishing a cyber defense league within the National Guard, similar to Estonia's model, to foster a shared mission and responsibility.
Lesson Three: Detection and Response
-
Historical Context: Alfred created the burh system, a network of fortified settlements that allowed for rapid response and communication during Viking attacks.
-
Modern Application: A similar approach is needed in cyberspace to ensure timely detection and response to ransomware attacks. This requires a centralized and decentralized approach, combining organizational structure with local expertise.
-
Recommendations:
- Streamline information sharing and response mechanisms between government and private sector.
- Enhance detection capabilities and incident response protocols.
- Foster collaboration through initiatives like the CISA Joint Cyber Defense Collaborative.
Critical Takeaways
- Ransomware is not a new threat, but its scale and impact have grown significantly.
- Paying ransoms is not a viable long-term solution and can exacerbate the problem.
- Collective action is essential to build resilience against ransomware.
- Historical failures such as those of Aethelred the Unready should not be repeated; instead, we should look to Alfred the Great for inspiration on how to effectively counter the modern "Vikings" of cyberspace.
Conclusion
While the cyber domain is vastly more complex than the medieval world, the principles of collective resilience, incentive alignment, and proactive defense remain relevant. The US must learn from the past to develop a more robust and sustainable approach to combating ransomware. History may not repeat itself, but it can rhyme—offering valuable lessons for the future of cybersecurity.
试读结束,高清完整版pdf/doc/ppt,请点下载