Pentagon seeks to expand rules of engagement in cyber war

By Ellen Nakashima

The Washington Post

WASHINGTON — The Pentagon has proposed that military cyber-specialists be given permission to take action outside its computer networks to defend critical U.S. computer systems — a move that officials say would set a significant precedent.

The proposal is part of a pending revision of the military’s standing rules of engagement. The secretary of defense has not decided whether to approve the proposal, but officials said adopting the new rules would be within his authority.

“Without a doubt it would be a very big and significant step forward,” said a senior defense official, speaking on the condition of anonymity to discuss a sensitive topic. “It would account for changes in technology that will give more flexibility in defending the nation from cyberattack.”

Currently, the military is permitted to take defensive actions or to block malicious software – such as code that can sabotage another computer – only inside or at the boundaries of its own networks. But advances in technology and mounting concern about the potential for a cyberattack to damage power stations, water-treatment plants and other critical systems have prompted senior officials to seek a more robust role for the department’s Cyber Command.

The proposed rules would open the door for U.S. defense officials to act outside the confines of military-related computer networks to try to combat cyberattacks on private computers, including those in foreign countries.

In establishing the new regulations, officials have sought to overcome concerns that action in another country’s networks could violate international law, upset allies or result in unintended consequences, such as the disruption of civilian networks.

The Pentagon, in consultation with the White House and other agencies, has developed strict conditions governing when military cyber-specialists could take action outside U.S. networks. Some officials said these conditions are so stringent that the new capability to go outside military boundaries might never be used.

Pentagon and other officials say such military action is meant to be taken only in extreme emergencies and with great care.

The proposed revision to Cyber Command’s standing rules is significantly narrower than what the military originally sought, officials said. But, one senior Pentagon official said, “we want to have something approved that starts the dialogue that allows us to start seeking more.”

Generally, the new rules would allow the two-year-old Cyber Command to take defensive action in a foreign country or in the United States if reliable intelligence indicates that a threat is imminent and could have certain consequences, such as deaths, severe injury or damage to national security, said several current and former officials.

“We’re not talking about shooting back, not talking about tit-for-tat,” said the Pentagon official, who like many interviewed for this article spoke on the condition of anonymity and would not discuss operational details. “We’re talking about stopping the bleeding, lest something really bad happens to the country.”

The standing rules of engagement, or SROE, were last revised in 2005. They are intended to give military commanders guidance on what they can do when they find their troops or systems under attack and they need to act quickly without having to consult the president or defense secretary.

While the rules for air, sea and land operations are fairly straightforward, the rules for cyberspace have posed great challenges for policymakers. For one thing, cyberattacks can take place in milliseconds. The assailant may be unknown. The attack route may be hard to trace, crossing multiple countries.

“The legal and policy entanglement in cyber is far, far more difficult than it is in some of the other domains” of warfare, William J. Lynn III, a former deputy defense secretary, said at a global security conference this year.

The SROE discussion is part of a larger interagency policy debate over the role of government in fighting attacks on the nation’s privately owned critical computer systems.

Ideally, current and former officials say, the Pentagon would like Cyber Command to be able to undertake a range of activities, from blocking or redirecting viruses to disabling a computer server in another country to prevent destructive malware from being launched.

But something as aggressive as shutting down a server in another country is probably going to require presidential permission, Gen. Keith Alexander, the head of Cyber Command, has said.

Indeed, “going after something outside the network in defense of the nation, which may still be characterized as offensive, is definitely the hardest policy part,” a senior U.S. official said.

Even actions on networks in the United States would involve an integrated cyber operations center with personnel from all relevant agencies: the National Security Agency, Cyber Command, the Department of Homeland Security and the FBI. When a cyber threat is detected, whichever agency has the lead by law – FBI for criminal and counterintelligence cases, Cyber Command for foreign adversary and terrorist attacks – would take over, officials said.

DHS has the lead for working with critical industries. NSA and Cyber Command are able to lend their expertise to DHS and other agencies, officials said.

“We’re very careful about roles and responsibilities between Justice, DHS and DOD,” the U.S. official said. “Those are being carefully reviewed. But in every domain, ultimately DOD has the responsibility to defend the nation.”

A variety of blocking techniques can be used that are not destructive to networks, officials said. They include diverting malware into a “sinkhole,” effectively a cyber black hole, which is something Internet service providers do now to protect their own networks.

Alexander, who is also director of the NSA, has pushed publicly for new rules on rules of engagement. Officials “need standing rules of engagement and execute orders that allow the government to do defense that is reasonable and proportionate,” he said at a recent conference in Aspen.

Earlier efforts to establish the ability for the military to defend private critical networks failed in the face of opposition from the Justice Department, which did not want to set a legal precedent for military action in domestic networks, and the State Department, which feared the military might accidentally disrupt a server in a friendly country, undermining future cooperation.

Alexander said an enhanced ability for the Pentagon to take action to defend the nation rests in part on expanded cyberthreat data-sharing.

He said that in debating the rules, policymakers are “trying to do the job right.” But what concerns him is the discussion over whether “you can use this tool, but not that one, without understanding what that really means.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Alan Edward Dean, convicted of the 1993 murder of Melissa Lee, professes his innocence in the courtroom during his sentencing Wednesday, April 24, 2024, at Snohomish County Superior Court in Everett, Washington. (Ryan Berry / The Herald)
Bothell man gets 26 years in cold case murder of Melissa Lee, 15

“I’m innocent, not guilty. … They planted that DNA. I’ve been framed,” said Alan Edward Dean, as he was sentenced for the 1993 murder.

Bothell
Man gets 75 years for terrorizing exes in Bothell, Mukilteo

In 2021, Joseph Sims broke into his ex-girlfriend’s home in Bothell and assaulted her. He went on a crime spree from there.

A Tesla electric vehicle is seen at a Tesla electric vehicle charging station at Willow Festival shopping plaza parking lot in Northbrook, Ill., Saturday, Dec. 3, 2022. A Tesla driver who had set his car on Autopilot was “distracted” by his phone before reportedly hitting and killing a motorcyclist Friday on Highway 522, according to a new police report. (AP Photo/Nam Y. Huh)
Tesla driver on Autopilot caused fatal Highway 522 crash, police say

The driver was reportedly on his phone with his Tesla on Autopilot on Friday when he crashed into Jeffrey Nissen, killing him.

James McNeal. Courtesy photo
Charges: Ex-Bothell council member had breakup ‘tantrum’ before killing

James McNeal was giving Liliya Guyvoronsky, 20, about $10,000 per month, charging papers say. King County prosecutors charged him with murder Friday.

Edmonds City Council members answer questions during an Edmonds City Council Town Hall on Thursday, April 18, 2024 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds wants to hear your thoughts on future of fire services

Residents can comment virtually or in person during an Edmonds City Council public hearing set for 7 p.m. Tuesday.

Girl, 11, missing from Lynnwood

Sha’niece Watson’s family is concerned for her safety, according to the sheriff’s office. She has ties to Whidbey Island.

A cyclist crosses the road near the proposed site of a new park, left, at the intersection of Holly Drive and 100th Street SW on Thursday, May 2, 2024, in Everett, Washington. (Ryan Berry / The Herald)
Everett to use $2.2M for Holly neighborhood’s first park

The new park is set to double as a stormwater facility at the southeast corner of Holly Drive and 100th Street SW.

The Grand Avenue Park Bridge elevator after someone set off a fire extinguisher in the elevator last week, damaging the cables and brakes. (Photo provided by the City of Everett)
Grand Avenue Park Bridge vandalized, out of service at least a week

Repairs could cost $5,500 after someone set off a fire extinguisher in the elevator on April 27.

A person turns in their ballot at a ballot box located near the Edmonds Library in Edmonds, Washington on Sunday, Nov. 5, 2023. (Annie Barker / The Herald)
Everett approves measure for property tax increase to stave off deficit

If voters approve, the levy would raise the city’s slice of property taxes 44%, as “a retaining wall” against “further erosion of city services.”

Vehicles turn onto the ramp to head north on I-5 from 41st Street in the afternoon on Friday, June 2, 2023, in Everett, Washington. (Ryan Berry / The Herald)
Weather delays I-5 squeeze in Everett

After a rain delay, I-5 will be down to one lane in Everett on May 10, as crews replace asphalt with concrete.

Everett
2 men arrested in dozen south Snohomish County burglaries

Police believe both men are connected with a group from South America suspected of over 300 burglaries since 2021.

James McNeal. Courtesy photo
Ex-Bothell council member arrested for investigation of killing woman

James McNeal, 58, served eight years on the Bothell City Council. On Tuesday, he was arrested for investigation of murdering a 20-year-old woman.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.