Högskolan i Skövde

his.sePublications
Change search
Link to record
Permanent link

Direct link
Publications (7 of 7) Show all publications
Huskaj, G. (2022). What is a Substantial Contribution to a Research Project in Offensive Cyberspace Operations that Merits Co-Authorship?. In: Dean Robert P. Griffin; Unal Tatar; Benjamin Yankson (Ed.), Proceedings of the 17th International Conference on Cyber Warfare and Security ICCWS 2022: A Conference Hosted By State University of New York at Albany, Albany, New York, USA, 17-18 March 2022. Paper presented at 17th International Conference on Cyber Warfare and Security (ICCWS), State University of New York at Albany, Albany, New York, USA, 17-18 March 2022 (pp. 385-394). Academic Conferences International Limited
Open this publication in new window or tab >>What is a Substantial Contribution to a Research Project in Offensive Cyberspace Operations that Merits Co-Authorship?
2022 (English)In: Proceedings of the 17th International Conference on Cyber Warfare and Security ICCWS 2022: A Conference Hosted By State University of New York at Albany, Albany, New York, USA, 17-18 March 2022 / [ed] Dean Robert P. Griffin; Unal Tatar; Benjamin Yankson, Academic Conferences International Limited , 2022, p. 385-394Conference paper, Published paper (Refereed)
Abstract [en]

This article reviews the question what is a substantial contribution to a research project in offensive cyberspace operations that merits co-authorship? Frustrations and conflicts may develop during research projects when researchers with different backgrounds, cultures, research fields and expertise decide to conduct research and produce and publish those results. The focus of this paper is a research project in cyberspace operations while taking into account the power-dynamics inherent in the academic system and how these can affect the co-authorship of research products. First, the purpose with doing research is presented. Next, three models of the research process are reviewed, describing their differences and similarities. Then, linguistic analysis is applied on a set of terms in guidelines for co-authorship described in some different universities in Sweden. The results present a model for a research project in offensive cyberspace operations and based on the output of the linguistic analysis, the model is used to quantify and describe what a substantial contribution is in three scenarios that merits co-authorship.

Place, publisher, year, edition, pages
Academic Conferences International Limited, 2022
Series
International Conference on Cyber Warfare and Security, ISSN 2048-9870, E-ISSN 2048-9889
Keywords
Co-authorship, Linguistic Analysis, Offensive Cyberspace Operations, Power-dynamics, Substantial Contribution
National Category
Information Systems, Social aspects
Research subject
Information Systems
Identifiers
urn:nbn:se:his:diva-21732 (URN)000833469700044 ()978-1-914587-27-6 (ISBN)978-1-914587-26-9 (ISBN)
Conference
17th International Conference on Cyber Warfare and Security (ICCWS), State University of New York at Albany, Albany, New York, USA, 17-18 March 2022
Available from: 2022-08-26 Created: 2022-08-26 Last updated: 2025-09-29Bibliographically approved
Kävrestad, J. & Huskaj, G. (2021). How the Civilian Sector in Sweden Perceive Threats from Offensive Cyberspace Operations. In: Thaddeus Eze; Lee Speakman; Cyril Onwubiko (Ed.), Proceedings of the 20th European Conference on Cyber Warfare and Security: . Paper presented at 20th European Conference on Cyber Warfare and Security, Reading, 24-25 June 2021 (pp. 499-506). Reading: ACI Academic Conferences International
Open this publication in new window or tab >>How the Civilian Sector in Sweden Perceive Threats from Offensive Cyberspace Operations
2021 (English)In: Proceedings of the 20th European Conference on Cyber Warfare and Security / [ed] Thaddeus Eze; Lee Speakman; Cyril Onwubiko, Reading: ACI Academic Conferences International, 2021, p. 499-506Conference paper, Published paper (Refereed)
Abstract [en]

The presence of state-sponsored actors executing offensive cyberspace operations (OCO) has been made evident in recent years. The term offensive cyberspace operations encompass a range of different actions, including cyberespionage, disinformation campaigns, spread of malware and more. Based on an analysis of past events, it is evident that state-sponsored actors are causing harm to the civilian sector using OCO. However, the degree to which civilian organizations understand the threat from state-sponsored actors is currently unknown. This research seeks to provide new a better understanding of OCO and their impact on civilian organizations. To highlight this domain, the case of the threat actor Advanced Persistent Threat 1 (APT1) is presented, and its impact on three civilian organizations discussed. Semi-structured interviews were used to research how the threats from OCO and state-sponsored actors are perceived by civilian organizations. First, a computational literature review was used to get an overview of related work and establish question themes. Next, the question themes were used to develop questions for the interview guide, followed by separate interviews with five security professionals working in civilian organizations. The interviews were analysed using thematic coding and the identified themes summarized as the result of this research. The results show that all respondents are aware of the threat from OCO, but they perceive it in different ways. While all respondents acknowledge state-sponsored actors at a threat agent executing OCO, some respondent’s argue that state-sponsored actors are actively seeking footholds in systems for future use while others state that the main goal of state-sponsored actors is to steal information. This suggests that the understanding of the threat imposed by OCO is limited, or at least inconsistent, among civilian security experts. As an interview study, the generalisability of this research is limited. However, it does demonstrate that the civilian society does not share a common view of the threat from state-sponsored actors and OCO. As such, it demonstrates a need for future research in this domain and can serve as a starting point for such projects.

Place, publisher, year, edition, pages
Reading: ACI Academic Conferences International, 2021
Series
Proceedings of the ... European conference on information warfare and security (ECCWS), ISSN 2048-8602, E-ISSN 2048-8610
Keywords
cybersecurity, state-sponsored, advanced persistent threat, civilian, offensive cyberspace operations
National Category
Information Systems
Research subject
INF303 Information Security; Information Systems
Identifiers
urn:nbn:se:his:diva-20493 (URN)978-1-912764-43-3 (ISBN)978-1-912764-99-0 (ISBN)
Conference
20th European Conference on Cyber Warfare and Security, Reading, 24-25 June 2021
Note

10.34190/EWS.21.106

Available from: 2021-08-20 Created: 2021-08-20 Last updated: 2025-09-29Bibliographically approved
Huskaj, G. & Wilson, R. L. (2020). An anticipatory ethical analysis of offensive cyberspace operations. In: Brian K. Payne, Hongyi Wu (Ed.), Proceedings of the 15th International Conference on Cyber Warfare and Security, ICCWS 2020: . Paper presented at 15th International Conference on Cyber Warfare and Security, ICCWS 2020, Norfolk, United States, 12 March 2020 through 13 March 2020, Code 158670 (pp. 512-520). Reading: Academic Conferences and Publishing International Limited
Open this publication in new window or tab >>An anticipatory ethical analysis of offensive cyberspace operations
2020 (English)In: Proceedings of the 15th International Conference on Cyber Warfare and Security, ICCWS 2020 / [ed] Brian K. Payne, Hongyi Wu, Reading: Academic Conferences and Publishing International Limited, 2020, p. 512-520Conference paper, Published paper (Refereed)
Abstract [en]

This article presents the ethical issues using offensive cyberspace operations. Previously enshrouded in secrecy, and now becoming the new norm, countries are using offensive cyberspace operations to achieve their strategic interests. Russia has conducted multiple offensive operations targeting Estonia, Georgia and the Ukraine; Hamas has targeted Israeli targets; and Iran has been targeting U.S. targets. The response to these operations has varied; Estonia and Georgia struggled with the attacks and were unable to respond while Ukraine tried to respond but the response was inefficient. Israel's response on Hamas offensive operations was an air strike on a building with Hamas Cyber-operatives. Iran shot down a U.S. Drone over the Strait of Hormuz, and the U.S. initially intended to respond with kinetic capabilities in the form of missile strikes. However, in the last minute, the U.S. chose to respond with offensive cyberspace operations targeting the Iranian missile systems. This last-minute change of response choosing between kinetic or cyber capabilities shows a need to further investigate how offensive cyberspace operations can be used against which targets from an ethical perspective. This article applies anticipatory ethical analysis on U.S. offensive operations in the “Global Hawk”-case when Iran shot down a U.S. drone over the Strait of Hormuz. Anticipatory ethical analysis looks at emerging technologies and their potential consequences. Offensive cyberspace operations present a range of possibilities, which include lowering the risk of harm to cyber operatives' lives belonging to the responding nation. However, a response can also be kinetic. Therefore, the analysis of the “Global Hawk”-case is compared with the Israeli-air strike of the building of Hamas Cyber-operatives. The authors argue that applying anticipatory ethical analysis on offensive operations and kinetic operations assist decision makers in choosing response actions to re-establish deterrence through the use of offensive cyberspace operations. 

Place, publisher, year, edition, pages
Reading: Academic Conferences and Publishing International Limited, 2020
Series
Proceedings of the International Conference on Cyber Warfare and Security, ISSN 2048-9870, E-ISSN 2048-9889
Keywords
Anticipatory Ethics, Deterrence, Kinetic, Offensive Cyberspace Operations, Response, Computer crime, Decision making, Drones, Kinetics, Missiles, Philosophical aspects, Decision makers, Emerging technologies, Ethical issues, Ethical perspectives, Missile strike, Missile systems, Offensive operations, Strategic interest, Computers
National Category
Peace and Conflict Studies Other Social Sciences not elsewhere specified Information Systems Information Systems, Social aspects Political Science (excluding Public Administration Studies and Globalisation Studies)
Research subject
Information Systems
Identifiers
urn:nbn:se:his:diva-18419 (URN)000560067200060 ()2-s2.0-85083363637 (Scopus ID)978-1-912764-52-5 (ISBN)978-1-912764-53-2 (ISBN)1-912764-53-9 (ISBN)
Conference
15th International Conference on Cyber Warfare and Security, ICCWS 2020, Norfolk, United States, 12 March 2020 through 13 March 2020, Code 158670
Note

10.34190/ICCWS.20.054

Available from: 2020-04-30 Created: 2020-04-30 Last updated: 2025-09-29Bibliographically approved
Huskaj, G. & Wilson, R. L. (2020). Anticipatory ethics for vulnerability disclosure. In: Brian K. Payne, Hongyi Wu (Ed.), Proceedings of the 15th International Conference on Cyber Warfare and Security, ICCWS 2020: . Paper presented at 15th International Conference on Cyber Warfare and Security, ICCWS 2020; Norfolk; United States; 12 March 2020 through 13 March 2020; Code 158670 (pp. 254-261). Reading: Academic Conferences and Publishing International Limited
Open this publication in new window or tab >>Anticipatory ethics for vulnerability disclosure
2020 (English)In: Proceedings of the 15th International Conference on Cyber Warfare and Security, ICCWS 2020 / [ed] Brian K. Payne, Hongyi Wu, Reading: Academic Conferences and Publishing International Limited, 2020, p. 254-261Conference paper, Published paper (Refereed)
Abstract [en]

This article presents the ethical dilemma related to under what circumstances vulnerabilities should be disclosed. Vulnerabilities exist in hardware and software, and can be as a consequence of programming errors or design flaws. Threat actors can exploit these vulnerabilities to gain otherwise unintended access to information systems, resources and/or stored information. In other words, they can be used to impact the confidentiality, integrity and availability of information in information systems. As a result, various types of vulnerabilities are highly sought after since they enable this type of access. The most highly sought are so-called “zero-day”-vulnerabilities. These are vulnerabilities that exist but are unknown, and when exploited, enable one way of entry into a system that is not thought possible. This is also why zero-day vulnerabilities are very popular among criminal organizations, states and state-sponsored advanced persistent threats. The other side of the coin is when a state identifies a zero-day, and ends up in the ethical dilemma of whether to release the news and inform the vendor to patch it, i.e. close the vulnerability, or to use it for offensive or intelligence purposes. This article employs these distinctions to apply anticipatory ethics in the Stuxnet-case. Stuxnet was a computer software that was allegedly developed by the U.S. together with Israel to disrupt Iran's development of uranium for their nuclear program. More exactly, it was developed to disable the uranium centrifuges used to enrich uranium. To achieve this, Stuxnet exploited four zero-day vulnerabilities and, according to some experts, managed to delay Iran's nuclear program by one to two-years, forcing them to the negotiation table. Using vulnerabilities like zero-days presents opportunities but also risks. The results of the application of anticipatory ethics to the Stuxnet case are then compared with the “Osirak”-case and the “al-Kibar”-case. Osirak was the nuclear reactor in Iraq and was bombed in 1981; al-Kibar was the nuclear reactor being built up in Syria, also bombed in 2007. 

Place, publisher, year, edition, pages
Reading: Academic Conferences and Publishing International Limited, 2020
Series
Proceedings of the International Conference on Cyber Warfare and Security, ISSN 2048-9870, E-ISSN 2048-9889
Keywords
Anticipatory Ethics, Ethical Dilemma, Information Systems, Iran Nuclear Program, Stuxnet, Vulnerabilities, Zero-Days, Computer crime, Information use, Nuclear reactors, Uranium, Hardware and software, Programming errors, Vulnerability disclosure, Zero day vulnerabilities, Ethical aspects
National Category
Peace and Conflict Studies Other Social Sciences not elsewhere specified Information Systems Political Science (excluding Public Administration Studies and Globalisation Studies)
Research subject
Information Systems
Identifiers
urn:nbn:se:his:diva-18417 (URN)000560067200031 ()2-s2.0-85083400703 (Scopus ID)978-1-912764-52-5 (ISBN)1-912764-53-9 (ISBN)978-1-912764-53-2 (ISBN)
Conference
15th International Conference on Cyber Warfare and Security, ICCWS 2020; Norfolk; United States; 12 March 2020 through 13 March 2020; Code 158670
Note

10.34190/ICCWS.20.053

Available from: 2020-04-30 Created: 2020-04-30 Last updated: 2025-09-29Bibliographically approved
Huskaj, G., Iftimie, I. A. & Wilson, R. L. (2020). Designing attack infrastructure for offensive cyberspace operations. In: Thaddeus Eze, Lee Speakman, Cyril Onwubiko (Ed.), Proceedings of the 19th European Conference on Cyber Warfare and Security: a virtual conference hosted by University of Chester UK 25-26 June 2020. Paper presented at 19th European Conference on Cyber Warfare and Security, a virtual conference, University of Chester, UK, 25-26 June 2020 (pp. 473-482). Reading, UK: Academic Conferences and Publishing International Limited
Open this publication in new window or tab >>Designing attack infrastructure for offensive cyberspace operations
2020 (English)In: Proceedings of the 19th European Conference on Cyber Warfare and Security: a virtual conference hosted by University of Chester UK 25-26 June 2020 / [ed] Thaddeus Eze, Lee Speakman, Cyril Onwubiko, Reading, UK: Academic Conferences and Publishing International Limited, 2020, p. 473-482Conference paper, Published paper (Refereed)
Abstract [en]

This article addresses the question ‘what considerations should be taken by cyber commands when designing attack infrastructure for offensive operations?’. Nation-states are investing in equipping units tasked to conduct offensive cyberspace operations. Generating ‘deny, degrade, disrupt, destroy or deceive’ effects on adversary targets requires to move from own (‘green’), through neutral (‘grey’), to adversary (‘red’) cyberspace. The movement is supported by attack infrastructure for offensive cyberspace operations. In this paper, we review the professional and scientific literature identifying the requirements for designing an attack infrastructure. Next, we develop and define the concepts for attack infrastructure. Finally, we explain and describe the considerations for designing attack infrastructure. The research question is answered by proposing a framework for designing attack infrastructure. This framework is vital for military and civilian commands designing attack infrastructure for offensive cyberspace operations. 

Place, publisher, year, edition, pages
Reading, UK: Academic Conferences and Publishing International Limited, 2020
Series
Proceedings of the European Conference on Information Warfare and Security, ISSN 2048-8602, E-ISSN 2048-8610
Keywords
Attack Infrastructure, Cyber Commands, Offensive Cyberspace Operations, Operational Security, Computer crime, Cyberspaces, Offensive operations, Research questions, Scientific literature, Computers
National Category
Control Engineering Information Systems Computer Systems
Research subject
Information Systems
Identifiers
urn:nbn:se:his:diva-19245 (URN)10.34190/EWS.20.077 (DOI)2-s2.0-85094642484 (Scopus ID)978-1-912764-61-7 (ISBN)978-1-912764-62-4 (ISBN)
Conference
19th European Conference on Cyber Warfare and Security, a virtual conference, University of Chester, UK, 25-26 June 2020
Available from: 2020-11-13 Created: 2020-11-13 Last updated: 2025-09-29Bibliographically approved
Iftimie, I. A. & Huskaj, G. (2020). Strengthening the cybersecurity of smart grids: The role of artificial intelligence in resiliency of substation intelligent electronic devices. In: Thaddeus Eze, Lee Speakman, Cyril Onwubiko (Ed.), Proceedings of the 19th European Conference on Cyber Warfare and Security: a virtual conference hosted by University of Chester UK 25-26 June 2020. Paper presented at 19th European Conference on Cyber Warfare and Security, a virtual conference, University of Chester, UK, 25-26 June 2020 (pp. 143-150). Reading, UK: Academic Conferences and Publishing International Limited
Open this publication in new window or tab >>Strengthening the cybersecurity of smart grids: The role of artificial intelligence in resiliency of substation intelligent electronic devices
2020 (English)In: Proceedings of the 19th European Conference on Cyber Warfare and Security: a virtual conference hosted by University of Chester UK 25-26 June 2020 / [ed] Thaddeus Eze, Lee Speakman, Cyril Onwubiko, Reading, UK: Academic Conferences and Publishing International Limited, 2020, p. 143-150Conference paper, Published paper (Refereed)
Abstract [en]

The Executive Order 13800—Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure—issued by the President of the United States, calls for an evaluation of the “readiness and gaps in the United States’ ability to manage and mitigate consequences of a cyber incident against the electricity subsector.” In May of 2018, the Office of Management and Budget finished evaluating the 96 risk assessments conducted by various agencies and published Federal Cybersecurity Risk Determination Report and Action Plan (Risk Report). While the report embraced a broad defending forward strategy, it made no reference to smart grids or their vulnerable intelligent substations and did not address how federal agencies plan to respond to emerging threats to these systems. While the paper does not discuss how to attack the smart grids in the cyber domain, the contribution to the academic debate lies in validating some of the vulnerabilities of the grid’s substations in order for government, private industry, academia, and civil society to better collaborate in disrupting or halting malicious cyber activities before they disrupt the power supply of the United States and its Transatlantic allies. We also discuss how Artificial Intelligence and related techniques can mitigate security risks to cyber-physical systems. Until this technology becomes available, however, standardization of cyber security efforts must be enforced through regulatory means, such as the enforcement of security-by-design Intelligent Electronic Devices and protocols for the smart grid. 

Place, publisher, year, edition, pages
Reading, UK: Academic Conferences and Publishing International Limited, 2020
Series
Proceedings of the European Conference on Information Warfare and Security, ISSN 2048-8602, E-ISSN 2048-8610
Keywords
Artificial Intelligence, Cyber Security, Intelligent Electronic Devices, Smart Grids, Substations, Budget control, Computer crime, Electric power transmission networks, Embedded systems, Risk assessment, Security of data, Thermoelectric equipment, Federal agency, Forward strategy, Intelligent electronic device, Office of management and budgets, Private industries, Risk determination, Security risks, Smart power grids
National Category
Computer Systems Computer Sciences
Research subject
Information Systems
Identifiers
urn:nbn:se:his:diva-19243 (URN)10.34190/EWS.20.043 (DOI)2-s2.0-85094663818 (Scopus ID)978-1-912764-61-7 (ISBN)978-1-912764-62-4 (ISBN)
Conference
19th European Conference on Cyber Warfare and Security, a virtual conference, University of Chester, UK, 25-26 June 2020
Available from: 2020-11-13 Created: 2020-11-13 Last updated: 2025-09-29Bibliographically approved
Huskaj, G. & Iftimie, I. A. (2020). Toward an ambidextrous framework for offensive cyberspace operations: A theory, policy and practice perspective. In: Brian K. Payne, Hongyi Wu (Ed.), Proceedings of the 15th International Conference on Cyber Warfare and Security, ICCWS 2020: . Paper presented at 15th International Conference on Cyber Warfare and Security, ICCWS 2020, Norfolk, United States, 12 March 2020 through 13 March 2020, Code 158670 (pp. 243-253). Reading, UK: Academic Conferences and Publishing International Limited
Open this publication in new window or tab >>Toward an ambidextrous framework for offensive cyberspace operations: A theory, policy and practice perspective
2020 (English)In: Proceedings of the 15th International Conference on Cyber Warfare and Security, ICCWS 2020 / [ed] Brian K. Payne, Hongyi Wu, Reading, UK: Academic Conferences and Publishing International Limited, 2020, p. 243-253Conference paper, Published paper (Refereed)
Abstract [en]

This article addresses the rise in state-sponsored cyber attacks over the past three decades and proposes a new ambidextrous framework for offensive cyberspace operations. Since 1982, nation states have embarked in a fierce race to develop both clandestine and covert offensive cyber capabilities. Their intended targets range from foreign militaries and terrorist organizations to civilian populations and the critical infrastructures that they rely upon. Advancements in cyber security have, however, contributed to the discovery and attribution of offensive cyber operations, such as state-sponsored ransomware attacks, where state-built cyber capabilities have been used to attack governments, industries, academia and citizens of adversary nations. The financial and psychological costs of these ransomware attacks are today a threat to any state's national security. This article draws from academic research, the cyber military doctrines of four countries-a total of eight models from the Netherlands, Sweden, the U.S., and the U.K.-and the authors' operational experience to propose a new ambidextrous framework for offensive cyberspace operations. This ambidextrous framework for offensive cyberspace operations and the associated Cyberspace Operations Canvas are needed today in order to increase the resilience of national critical infrastructures against attacks from state-developed tools. We use the WannaCry-case to illustrate how the implementation of the ambidextrous framework for offensive cyberspace operations would result in increased awareness and understanding of the prospective cyber threats, their intended target(s), the likelihood of cascading effects and the options available by nation states to minimize them. 

Place, publisher, year, edition, pages
Reading, UK: Academic Conferences and Publishing International Limited, 2020
Series
Proceedings of the International Conference on Cyber Warfare and Security, ISSN 2048-9870, E-ISSN 2048-9889
Keywords
Ambidextrous Framework for Offensive Cyberspace Operations, Critical Infrastructure Protection, Cyber Resilience, Cyberspace Operations Canvas, State-Sponsored Cyber-Attacks, WannaCry, Computers, Critical infrastructures, National security, Network security, Public works, Terrorism, Academic research, Cascading effects, Civilian populations, Cyber operations, Cyber security, Operational experience, Practice perspectives, Terrorist organization, Malware
National Category
Political Science (excluding Public Administration Studies and Globalisation Studies) Peace and Conflict Studies Other Social Sciences not elsewhere specified Information Systems
Research subject
Information Systems
Identifiers
urn:nbn:se:his:diva-18420 (URN)000560067200030 ()2-s2.0-85083394573 (Scopus ID)978-1-912764-52-5 (ISBN)978-1-912764-53-2 (ISBN)1-912764-53-9 (ISBN)
Conference
15th International Conference on Cyber Warfare and Security, ICCWS 2020, Norfolk, United States, 12 March 2020 through 13 March 2020, Code 158670
Note

10.34190/ICCWS.20.052

Available from: 2020-04-30 Created: 2020-04-30 Last updated: 2025-09-29Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-7552-9465

Search in DiVA

Show all publications