War in Iran risks triggering cyber insurgency - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号):
请您阅读我们的用户注册协议隐私权保护政策,点击下方按钮即视为您接受。
战争

War in Iran risks triggering cyber insurgency

Hackers are usually more interested in money than patriotism but this time might be different
00:00

{"text":[[{"start":7.99,"text":"The writer is director of the Cambridge Cybercrime Centre and professor of emergent harms at the University of Cambridge"}],[{"start":17.52,"text":"When a major conflict erupts, there is always speculation that it will spark a full-blown cyber war. "}],[{"start":25.619999999999997,"text":"Since Russia’s full-scale invasion of Ukraine in 2022, my team at the Cambridge Cybercrime Centre has been measuring high-volume civilian cybercrimes committed during large conflicts. What we have found suggests that patriotism is usually a far less motivating factor than self-interested financial gain. "}],[{"start":48.81999999999999,"text":"Both Russia and Ukraine have high levels of technical capability. There was speculation that invasion meant cyber war was imminent. This turned out not to be the case. Some state-sponsored cyber attacks have taken place in the intervening years but the war has largely been fought using “hard iron” drones and tanks rather than “soft silicon” network exploitation. "}],[{"start":75.96,"text":"The cyber attacks that took place, such as denial of service attacks to disrupt networks or the defacement of websites, rose sharply in the early days of the invasion but returned to their baseline levels within weeks. "}],[{"start":91.28999999999999,"text":"Non-state actors who support Russia and Ukraine also have the ability to unleash cyber attacks. Yet despite predictions of “Cybergeddon”, any attacks have tended to be financially driven. Even when hackers leave messages of support for one side or another on defaced websites, their main focus seems to be to advertise their own hacking services and the tools they are selling for financial gain. "}],[{"start":117.38999999999999,"text":"Cyber attacks at the start of the Israel-Hamas conflict in 2023 followed the same pattern. Again, attack volume rose at the start of the conflict and then petered out. "}],[{"start":129.92999999999998,"text":"The main difference was that the destruction of internet infrastructure in Gaza meant retaliation was mostly one-sided. With very few remaining Palestinian targets to attack, the wrath of the cyber criminal underground was mainly directed towards Israeli infrastructure."}],[{"start":150.01999999999998,"text":"The picture in Iran is still evolving but what we observe suggests that this conflict may be a little different. Pro-Iranian ideological attackers could break the pattern."}],[{"start":162.21999999999997,"text":"A pro-Iranian group has already claimed responsibility for an attack against the US medical equipment firm Stryker. This attack, which has caused major network disruption and data deletion, is not believed to be financially motivated. Rather, the group claims it is retaliation for a deadly missile strike against an Iranian primary school. "}],[{"start":184.60999999999996,"text":"Attribution is always difficult to verify, meaning it is hard to know who is behind attacks and how they are funded. But this conflict is tripartite and all three countries involved have technical capabilities in this area. "}],[{"start":199.99999999999994,"text":"Israel and the US are widely thought to be jointly responsible for the sophisticated Stuxnet malware that in 2009 damaged the Natanz nuclear facility in Iran. "}],[{"start":211.22999999999993,"text":"Meanwhile, reports indicate that Iran’s investments in the technology sector have primarily focused on military power, including cyber weapons. The 2012 Shamoon cyber attack against Saudi Aramco, for example, which rendered more than 30,000 computers inoperable, has been attributed to Iranian state-sponsored actors."}],[{"start":234.00999999999993,"text":"A highly skilled tech workforce doesn’t stop when the state collapses. They become unemployed, armed and aggrieved. This could lead to the rise of a decentralised, ideologically motivated cyber insurgency that operates outside both the traditional economic motivations of the cyber underground and the geographical constraints of traditional conflict. They may target the sort of high-cost, high-disruption, low-reward attacks that are not economically rational to most cyber criminals."}],[{"start":266.44999999999993,"text":"The question is: will the war in Iran follow the same pattern we have tracked in other recent conflicts? In this scenario, there is likely to be a brief flash of low-level attacks, mostly against the US and Israel. Given communication blackouts and the current poor state of Iranian infrastructure, these attacks would then diminish. "}],[{"start":291.7899999999999,"text":"If this is the case then war in Iran will take place mostly in the physical world with little sustained, organised civilian cyber attack activity."}],[{"start":302.7399999999999,"text":"But if we look back further in history, we can see that when a state’s structure is destroyed, power tends to disperse. In 2003, the dismantling of the formal military in Iraq gave rise to a decade of insurgency. The key difference now is the opportunity for technology-facilitated attacks and the presence of technically skilled adversaries. If a power vacuum is created in Iran, it may be a step towards techno-economic guerrilla warfare that no longer requires a state to function."}],[{"start":345.5299999999999,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1774409670_2293.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

从温泉到米饼:海湾能源危机重创日本小企业

对进口燃料的依赖正在扼住全球第五大经济体的喉咙,暴露了作为其经济核心的小企业的脆弱性。

软银追加300亿美元OpenAI投资,考验自身借贷上限

孙正义将巨额资金投入人工智能领域,需要面对投资者的不安情绪。

特朗普能否与伊朗达成协议?

任何结束战争的外交努力都面临重重障碍。

特朗普因新关税计划面临法律挑战

在最高法院裁定先前关税非法后,美国总统转而援引一些鲜为人知的法律。

整顿还是圈地?印尼领导人瞄准资源公司

印尼总统普拉博沃•苏比延多誓言将对违反环境法规的资源企业采取强硬措施。

伊朗战争威胁海湾资金的全球流动

海合会六个成员国数十年来已集体成长为全球金融领域最具影响力的力量之一,投资足迹遍及全球。世界对中东资本的依赖程度比许多人意识到的更深。
设置字号×
最小
较小
默认
较大
最大
分享×