Overview
This article analyzes and examines implementation methods for counter operations against attackers in Active Cyber Defense (ACD) and the definition and evaluation methods of "victory" from the perspective of military strategic theory.
## Key Points
### 1. Cyber Attack Campaigns and Counter Operations Overview
- Security-impacting cyber attacks are conducted as "attack campaigns" (repeated over years)
- Volt Typhoon discovered in 2023: Intermittent preparatory attacks for critical infrastructure destruction/disruption during contingencies
- 2022 Ukraine invasion: Preparatory activities months in advance, similar attacks repeated since 2015
- Repeated attacks inevitably expose attacker "weaknesses," creating opportunities for counter operations
- Counter options range from access/neutralization, communication blocking (strong) to alerts, information sharing (soft)
### 2. Challenges and Expected Effects of Counter Operations
- Current challenges: Delayed implementation timing due to "friction" from insufficient inter-organizational cooperation and delayed information sharing
- Attack campaigns have not been completely interrupted or stopped
- Expected effects from establishing Active Cyber Defense posture:
- Review and strengthening of information sharing
- New means of communication information analysis
- Running counter operation cycles faster to deliver effective damage to attackers
### 3. Four Evaluation Perspectives for Counter Operation "Victory"
- ① Goal-based evaluation: Declaring victory when target state achieved (Volt Typhoon and Hunt Forward operations)
- ② Cost-effectiveness evaluation: Comparison with costs to achieve political objectives
- ③ Perception-based evaluation: Victory concept is socially constructed (US-China meeting case reported by WSJ in April 2025)
- ④ Norm-based evaluation: Victory understood through shared normative structure between parties
- 2016 US presidential election Russian intervention: Rule mismatch between US (criminal procedure) and Russia (military operation)
### 4. Four Challenges in Explaining to Strategic Audiences
- ① Goal-based evaluation challenge: Inappropriate threat analysis failing to capture attack objectives (February 2022 automotive supply chain attack case)
- ② Cost-effectiveness evaluation challenges:
- Victim organizations incur similar response costs even after blocking attack campaigns
- Enormous "invisible costs" including investigating data leak "possibilities," coordinating with ministries/stakeholders/media
- ③ Perception-based evaluation challenge: Threat overestimation problem, structural issues with "fear-inducing" approaches
- ④ Norm-based evaluation challenge: Attackers and defenders operating under different systems and rules
### 5. Recommendations for Active Cyber Defense Success
- Avoid excessive focus on prominent measures like "access/neutralization" and "communication information analysis"
- Focus lies in traditional efforts of "threat analysis" and "incident response"
- Revisiting fields with accumulated knowledge reveals path to counter operation "victory"
- Author: Hayato Sasaki (JPCERT Coordination Center Threat Analyst)
- Published: July 10, 2025
The article concludes that success in Active Cyber Defense requires not only new technical means but also institutional design that reviews existing threat analysis and incident response mechanisms according to attacker realities and can properly explain "victory" to strategic audiences.
This summary was automatically generated by AI. Please refer to the original article for accuracy.
This article analyzes and examines implementation methods for counter operations against attackers in Active Cyber Defense (ACD) and the definition and evaluation methods of "victory" from the perspective of military strategic theory.
Key Points
1. Cyber Attack Campaigns and Counter Operations Overview
- Security-impacting cyber attacks are conducted as "attack campaigns" (repeated over years)
- Volt Typhoon discovered in 2023: Intermittent preparatory attacks for critical infrastructure destruction/disruption during contingencies
- 2022 Ukraine invasion: Preparatory activities months in advance, similar attacks repeated since 2015
- Repeated attacks inevitably expose attacker "weaknesses," creating opportunities for counter operations
- Counter options range from access/neutralization, communication blocking (strong) to alerts, information sharing (soft)
2. Challenges and Expected Effects of Counter Operations
- Current challenges: Delayed implementation timing due to "friction" from insufficient inter-organizational cooperation and delayed information sharing
- Attack campaigns have not been completely interrupted or stopped
- Expected effects from establishing Active Cyber Defense posture:
- Review and strengthening of information sharing
- New means of communication information analysis
- Running counter operation cycles faster to deliver effective damage to attackers
3. Four Evaluation Perspectives for Counter Operation "Victory"
- ① Goal-based evaluation: Declaring victory when target state achieved (Volt Typhoon and Hunt Forward operations)
- ② Cost-effectiveness evaluation: Comparison with costs to achieve political objectives
- ③ Perception-based evaluation: Victory concept is socially constructed (US-China meeting case reported by WSJ in April 2025)
- ④ Norm-based evaluation: Victory understood through shared normative structure between parties
- 2016 US presidential election Russian intervention: Rule mismatch between US (criminal procedure) and Russia (military operation)
4. Four Challenges in Explaining to Strategic Audiences
- ① Goal-based evaluation challenge: Inappropriate threat analysis failing to capture attack objectives (February 2022 automotive supply chain attack case)
- ② Cost-effectiveness evaluation challenges:
- Victim organizations incur similar response costs even after blocking attack campaigns
- Enormous "invisible costs" including investigating data leak "possibilities," coordinating with ministries/stakeholders/media
- ③ Perception-based evaluation challenge: Threat overestimation problem, structural issues with "fear-inducing" approaches
- ④ Norm-based evaluation challenge: Attackers and defenders operating under different systems and rules
5. Recommendations for Active Cyber Defense Success
- Avoid excessive focus on prominent measures like "access/neutralization" and "communication information analysis"
- Focus lies in traditional efforts of "threat analysis" and "incident response"
- Revisiting fields with accumulated knowledge reveals path to counter operation "victory"
- Author: Hayato Sasaki (JPCERT Coordination Center Threat Analyst)
- Published: July 10, 2025
The article concludes that success in Active Cyber Defense requires not only new technical means but also institutional design that reviews existing threat analysis and incident response mechanisms according to attacker realities and can properly explain "victory" to strategic audiences.