Reports & Papers

21 Items

A miniature of “The War Room” as depicted in the 1964 classic film Dr. Strangelove

Courtesy Eric Chan  and the Los Angeles County Museum of Art, CC-BY 2.0

Paper

Toward a Collaborative Cyber Defense and Enhanced Threat Intelligence Structure

| August 2021

National security structures envisioned in the 20th century are inadequate for the cyber threats that America faces in the 21st century. These structures, created to address strategic, external threats on one end, and homeland security emergencies on the other, cannot protect us from ambient cyber conflict, because they were designed for different times and threats. Our nation—comprising the federal government, private sector companies, critical infrastructure operators, state and local governments, nonprofits and universities, and even private citizens—are constantly under attack by a myriad of cyber actors with ever-increasing capabilities. 

Report - Cyber Project

Zero Botnets: An Observe-Pursue-Counter Approach

June 2021

Adversarial Internet robots (botnets) represent a growing threat to the safe use and stability of the Internet. Botnets can play a role in launching adversary reconnaissance (scanning and phishing), influence operations (upvoting), and financing operations (ransomware, market manipulation, denial of service, spamming, and ad click fraud) while obfuscating tailored tactical operations. Reducing the presence of botnets on the Internet, with the aspirational target of zero, is a powerful vision for galvanizing policy action. Setting a global goal, encouraging international cooperation, creating incentives for improving networks, and supporting entities for botnet takedowns are among several policies that could advance this goal.

A MEP walks in the mostly-vacant Plenary chamber of the European Parliament in Brussels, Tuesday, March 10, 2020.

AP Photo/Virginia Mayo

Paper

Transatlantic Dialogue: The Missing Link in Europe’s Post-Covid-19 Green Deal?

| April 2020

This policy brief emphasizes that the European Green Deal's effectiveness in a post Covid-19 world will require the involvement of strategic partners, especially the US. In the context of a potential US withdrawal from the Paris Agreement and the consequential vacuum, it will be even more important to engage the US in implementing the GD. In light of divergence between the US and the EU during past climate negotiations (e.g. Kyoto, Copenhagen, and Paris), we suggest a gradual approach to US engagement with GD initiatives and objectives.

teaser image

Paper

The Case for Transatlantic Cooperation in the Indo-Pacific

| Dec. 18, 2019

The evolving strategic dynamics in the Indo-Pacific are of paramount importance for the future of the rules-based international order. While the United States is redirecting strategic focus to the region as part of its Free and Open Indo-Pacific strategy, Europe is also stepping up its role—leveraging a strong economic profile, long-standing bilateral ties, and active engagement in various regional multilateral forums. The European Union (EU) and its member states can make distinct contributions to an open, transparent, inclusive, and rules-based regional order, though not necessarily always in lockstep with Washington.

Workers dismantle the Belt and Road Forum logo next to the “Golden Bridge of Silk Road” structure outside the media center as leaders are attending the round table summit of the Belt and Road Forum chaired by Chinese President Xi Jinping in Beijing, Saturday, April 27, 2019

AP Photo/Andy Wong

Paper - Belfer Center for Science and International Affairs, Harvard Kennedy School

The Triangle in the Long Game

| June 19, 2019

The purpose of this paper is to analyze how China’s new power is reaching Europe, the challenges that it poses, and the European responses to this new reality. This process has to be examined in the context of the current strategic competition between China and the U.S. and its reflection on the transatlantic relationship.

Paper - Cyber Security Project, Belfer Center

Too Connected to Fail

| May 2017

This paper argues that threats to core internet infrastructure and services can, in fact, rise to the level of a serious national security threat to the United States and will explore scenarios where this may be the case. The paper will discuss several kinds of core internet services and infrastructure and explore the challenges with understanding interdependencies between the internet and critical infrastructure; review recent attack techniques that can cause systemic risk to the internet; discuss various nation state capabilities, intentions and recent activities in this area; and describe how these attacks could be used against the United States to deter the U.S., control escalation, or potentially degrade U.S. warfighting capabilities in a conflict. Finally, the paper concludes with recommendations for what the United States and other governments can do to build defenses and resiliency against systemic threats to the internet.

Paper - Centre for International Governance Innovation

Getting beyond Norms: When Violating the Agreement Becomes Customary Practice

| Apr. 20, 2017

This paper offers five standards of care that can be used to test individual states' true commitment to the international norms of behaviour. Only with a concerted and coordinated effort across the global community will it be possible to change the new normal of "anything goes" and move forward to ensure the future safety and security of the Internet and Internet-based infrastructures.

Paper - Carnegie Endowment for International Peace

Russia and Cyber Operations: Challenges and Opportunities for the Next U.S. Administration

| December 13, 2016

Russian cyber operations against the United States aim to both collect information and develop offensive capabilities against future targets. Washington must strengthen its defenses in response.

Discussion Paper - Cyber Security Project, Belfer Center

Government's Role in Vulnerability Disclosure: Creating a Permanent and Accountable Vulnerability Equities Process

| June 2016

"When government agencies discover or purchase zero day vulnerabilities, they confront a dilemma: should the government disclose such vulnerabilities, and thus allow them to be fixed, or should the government retain them for national security purposes?"