Üçlü ilişkilerde dış politika aracı olarak siber araçlar: Birleşik Krallık'ı hedef alan siber saldırıların analizi
2024
0 views
0 downloads
Advisor: Doç. Dr. Menent Savaş Cazala
Abstract (EN)
This study examines the roles of cyber-attacks as foreign policy instruments in trilateral relations, focusing on the United Kingdom's (UK) relations with "Russia-Ukraine", "China-Hong Kong" and "Iran-Israel" as well as cyber-disruption operations targeting the UK between 2014 and 2023. Over the past decade, the UK has been the most targeted European country for Distributed Denial of Service (DDoS) attacks, according to data from NETSCOUT. There is a correlation between a country's level of technological development and its likelihood of being the target of cyber-attacks. This is because if a country has a limited level of technological development and a limited number of users of these technologies, it means that attackers also have limited alternatives to attack. However, the UK has been targeted much more than other European countries at a similar level of technological development, such as Germany and France. This suggests that the UK's situation cannot be explained solely by its level of technological development. In this respect, this study argues that the UK's more active and assertive foreign policy, both systemic and regional levels, particularly in line with the Global Britain doctrine, is a significant causal factor for its higher frequency of being targeted to cyber-attacks compared to other European countries. In this respect, this study firstly aims to explore "under what circumstances do states resort to cyber-attacks as instruments of foreign policy". Additionally, to elaborate on this research question, the study also investigates "in which cases, which states utilize which type of cyber tools against which states". Ever since Carl von Clausewitz wrote his famous passage, "War is merely the continuation of politics by other means" the primary political objectives have remained unchanged; however, the methods of warfare for achieving these political goals have significantly expanded. Throughout history, states have utilized new technologies as a new power instrument alongside other instruments in tailored ways to achieve political goals without resorting to traditional means. However, there is a fundamental difference between cyber technologies and other technological advancements. Cyberspace has a unique structure and logic: It is human-made and prioritizes secrecy over security. As a result, cyberspace provides states with the advantage of plausible deniability, allowing for ambiguity and visibility while enabling states to operate easily in the grey area, where the line between peace and war is significantly blurred. This situation makes it challenging to prevent and deter cyber-attacks, highlighting the necessity of increasing the resilience of states and societies in combating hybrid tools such as cyber-attacks. In this context, this study secondly examines another question: "How can states enhance their detection and identification capabilities of politically motivated cyber-attacks as major hybrid threats?" To further explore this research question, the study also addresses "How can early warning systems be developed to analyse complex political indicators and alert states to the increasing possibility of state-sponsored cyber disruption operations based on these political indicators?" Based on these research questions, in the first chapter, this study addresses the hybrid warfare approach and its changing nature in the last two decades. The so-called Gerasimov doctrine, which highlights the increasing significance of non-military methods for achieving political and strategic objectives, and the widespread belief that Russia has adopted hybrid warfare as part of its foreign policy, have contributed to the rising popularity of the concept. However, there is criticism that the concept has deviated from its original definition and has become a buzzword and ambiguous, reducing conceptual clarity. Furthermore, as the emphasis on non-kinetic tools increases, some argue that hybrid warfare differs from grey zone warfare/political warfare and two concepts should not be used interchangeably. This study compares two approaches by highlighting their differences and similarities. Accordingly, this study asserts that the main difference lies in their emphasis on the use of non-kinetic tools. Nevertheless, this study contends that just because non-kinetic tools are non-military does not mean that they are necessarily harmless and non-violent and harmless as seen in the Stuxnet case, which causes physical damage as conventional tools. Moreover, with further technological developments (e.g., artificial intelligence), offensive capabilities will also increase significantly, and this will make it difficult to classify these tools more than ever. Hence, this study suggests focusing on the role of the tools themselves rather than engaging in further theoretical debates on the inclusion/exclusion of tools. In this respect, in the second chapter, the different roles of cyber tools in interstate relations are addressed via "three groups of scholars". The first group argues that cyber-attacks have been changing the nature of war and led to a revolution in military affairs. Hence, cyber war would be a substitute for conventional war, and cyber tools could change the balance of power in the international system. The second group opposes the concept of cyber war, and they argue that cyber tools are rather limited tools in terms of escalation and coercion, and cyber tools become effective when combined with other traditional tools. Moreover, some of the scholars in the second group even argue that the main motivation for states to choose a limited-effect cyber-attack instead of a conventional weapon is to use cyber tools for conflict management. The last group assumes that cyber tools are new standalone tools that can change the balance of power without resorting to conventional tools. They argue that states intentionally limit the impact of cyber tools to conduct "fait accompli" and exploit vulnerabilities gradually. Hence, they emphasize the long-term cumulative impacts of cyber-attacks instead of analysing their individual effectiveness. Based on these approaches, this study mainly adopts the second group's assumptions and evaluates cyber tools as complementary foreign policy instruments within the framework of coercive diplomacy to gain a strategic advantage over rivals. Nevertheless, similar to the third group, instead of analysing cyber-attacks individually, this study emphasizes the long-term use of cyber tools because rival states employ these tools to shape long-term rivalry in a more indirect manner instead of obtaining immediate concessions. In this way, how states use cyber instruments as foreign policy tools can be evaluated from a more holistic perspective. In addition to these discussions in the literature, this study also expands the understanding of cyber-attacks' role by focusing on trilateral relations. In general, cyber-attacks are examined through bilateral relations. Nevertheless, states' relations take place in complex networks. In particular, when a state that holds strategic importance for two rival states increases its cooperation with one of the rivals, the other rival is significantly impacted by this collaboration. However, in such rapprochement cases, states have a limited set of foreign policy tools than in the circumstances compared to deteriorating relations. This study posits that cyber-attacks offer viable options in such cases. Therefore, for states who are unwilling to use other tools but want to do "something" "rather than doing nothing"; cyber-attacks offer strategic utility to convey signals without triggering a significant response. In this regard, this study hypothesizes that "when one of two rival states increases its cooperation level with a strategically important third country for both rival states, the likelihood of the other rival state launching cyber-disruption operations against its rival increases". To test this hypothesis, the relationship between the UK's trilateral relations with "Russia-Ukraine", "China-Hong Kong" and "Iran-Israel" and cyber disruption operations targeting the UK between 2014 and 2023 is examined. According to official UK reports, the UK's primary objective is to "counter state threats", particularly those originating from China (systemic threat), Russia (most acute threat), and Iran (destabilizing threat). Furthermore, China, Russia and Iran are identified as the top cyber threat actors targeting the UK. In this context, this study investigates how cyber disruption operations are utilized by these 'usual suspects' as a foreign policy instrument in response to the UK's increased collaboration with strategic actors – Ukraine, Hong Kong, and Israel, respectively. Quantitative research methods are employed for this investigation. Specifically, among the various types of cyber-attacks, only DDoS attacks are selected due to their ease of conduct, their occurrence during crises and geopolitical events, their complementary role to political and military events, and the availability of data that allow for quantitative research. Secondly, to quantitatively analyse the UK's relations over a specific period, this study employs event data, which codes various political events between states through text-based analysis. These coded events are then scored by the Goldstein scale, ranging from -10 to 10. After creating datasets of cyber-attack and event data and examining these three trilateral relations from a historical perspective, this study conducted three Binary Logistic Regression analyses to test the causal relationship between the UK's trilateral relationships and cyber-disruption operations targeting it. Accordingly, these analyses reveal that there is an increased likelihood of serious cyber-disruption operations towards the UK when the UK's cooperation level increases with Israel, Ukraine, and Hong Kong, whereas the UK's conflict level increases with China and Russia. Moreover, even though the UK-Iran relations have no statistical relations, this study stresses that the UK's relations with Israel - the archenemy of Iran in the region - could be more urging for Iran to use cyber disruption operations against the UK. With DDoS attacks, these states target institutions/businesses that are widely used by the people rather than military or governmental targets. Through frequent cyber-attacks, their goal is to increase the number of people impacted by these attacks. Even if the attacks themselves are not overly destructive, their aim is to conduct frequent, limited DDoS attacks and publicize them to heighten the perception of insecurity and reduce trust in governments. As a result, cyber disruption operations are used as "influence operations" to influence society and create disruption for political purposes. In this sense, this study contends that rather than using formal/informal diplomacy (explicit bargaining) to influence the UK's decision when directly involved in regional/internal affairs by engaging in relations with Ukraine, Hong Kong, and Israel, these usual suspects conduct cyber disruption operations as instruments of tacit bargaining against the UK in the framework of coercive diplomacy. Furthermore, Pearson Correlation analysis is also conducted to examine the use of cyber-attacks against allies in the same region and to test whether there is a correlation between the frequency of cyber-attacks targeting the UK and other countries in Europe. Accordingly, this analysis indicates a significant positive correlation between the UK and Germany, Belgium, Italy, and Spain regarding the frequency of cyber-attacks between 2015 and 2022. These findings provide important clues about the possible threat actors in Europe, usage of cyber-attacks in regional dynamics, the European security dynamics after Brexit, the foreign policy of the UK in the last decade, and the usual suspects' perception toward it. Based on all these findings, as a final step, an "AI-based early warning model" is developed to detect/predict significant politically motivated cyber disruption operations by simultaneously analysing dyadic relations of the UK and cyber-attacks targeting it. To develop this model, four machine learning algorithms are trained by the UK's dyadic relations with 14 countries along with cyber disruption operations targeting the UK between 2014-2023. According to the validation and test performance of these models, it is observed that K-Nearest Neighbors (KNN) has the highest AI performance metrics (accuracy, precision, recall and F1-Score) in both the validation and test phases. These results suggest that KNN can be effectively used to predict potential politically motivated cyber disruption attacks targeting the UK. Additionally, the KNN model also provides a feature that shows the importance of each dyadic relationship on the model's performance. Thus, this feature presents valuable insights into the relative importance of bilateral relations for predicting significant politically motivated cyber-attacks and offers a way of enhancing the model's performance. To sum up, these findings are significant because the KNN model could serve as a pioneering model for the development of a more complex and advanced version, such as a real-time automated predictive model. In this way, this model could contribute to making states and societies more resilient by enabling necessary mechanisms to react/respond earlier to possible significant state-sponsored cyber-attacks.
Author
Dr. Atakan Yılmaz
Institution

Galatasaray University
Uluslararası İlişkiler Bilim Dalı
How to Cite
Atakan Yılmaz (Doctorate thesis). Üçlü ilişkilerde dış politika aracı olarak siber araçlar: Birleşik Krallık'ı hedef alan siber saldırıların analizi, 2024, Galatasaray University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Galatasaray University
- International state responsibility arising from new space activities(2025)
- The liability of shareholders and organs for public debts in capital companies(2022)
- Karşı kültürel bir kimlik olarak taraftarlık: istanbul futbol tribünlerinde kimliksel yapılanış biçimleri çalışması(2014)
- Yeni roman: claude simon ve william faulkner(2014)
- Directors and officers liability insurance(2015)
- Langlands fonktörsellik ilkesi(2021)