When American forces entered Afghanistan shortly after the terrorist attacks of 9/11, the picture soon emerged of U.S. Army Special Forces (“Green Berets”) and CIA paramilitary officers operating together with Afghan warlords against a common al Qaeda and Taliban enemy.75  Presidential approval of the unconventional warfare plan for Afghanistan did much to quell rumblings about blurring of military and intelligence authorities, yet as the war in Afghanistan continued and the “war on terror” expanded globally those concerns became more prominent. Some argued the “tight integration” between special operations forces and the CIA in Afghanistan signaled “the erosion of distinctions between SOF and the CIA”—an “erosion” with supposedly dire legal consequences.76

A former general counsel for the CIA suggested an erosion of distinctions between military operations and covert action in the context of cyberwarfare.77 John Rizzo characterized the Title 10-Title 50 debate in terms of a dichotomy between “war-making authority” and “covert action” before concluding that “how these cyber-operations are described will dictate how they are reviewed and approved in the executive branch, and how they will be reported to Congress, and how Congress will oversee these activities.”78 Some commentators used Rizzo’s observation to suggest that the executive branch was disingenuously describing cyberwarfare in attempt to evade congressional oversight. We saw in Part II that oversight by the armed services committees is still congressional oversight. Part III will now explain why the same activities can properly be described as military or intelligence activities depending on their command and control, as well as funding, context and mission intent.

A. Unconventional Warfare

Just eight days after the terrorist attacks of September 11, 2001, Gary Schroen, a CIA paramilitary officer, packed three boxes with $9 million and flew to Afghanistan.79 The money would be used to pay Afghan warlords to fight with CIA and Special Forces personnel against al Qaeda and its Taliban collaborators. The operational plan was drafted by the CIA, vetted by the military and approved by the President. For the first time in American history, Special Forces working with CIA operatives were “the lead element in [a] war.”80 Yet even Secretary of Defense Donald Rumsfeld reportedly questioned who was really in charge.81 Eleven Special Forces teams operated with and coordinated the efforts of indigenous Tajik, Uzbek, Hazar, and Pashtun fighters, who were colloquially referred to as the Northern Alliance. Less than three months later, the Taliban government fell in an archetypal unconventional warfare campaign—small groups of highly skilled personnel operating with indigenous forces against a common enemy.

The U.S. military defines unconventional warfare as “[a]ctivities conducted to enable a resistance movement or insurgency to coerce, disrupt, or overthrow a government or occupying power by operating through or with an underground, auxiliary, and guerrilla force in a denied area.”82 This definition reveals three defining characteristics of unconventional warfare: 1) it is conducted “by, with, or through” indigenous forces, 2) those indigenous forces are “irregular” (i.e., non-governmental) forces,83 and 3) it supports “activities” against the government or occupying power.84

Activities conducted under the rubric of unconventional warfare include guerilla warfare, subversion, sabotage, intelligence collection, and unconventional assisted recovery.85 These activities do not necessarily by themselves constitute unconventional warfare, but rather they typify tactics and techniques commonly employed in unconventional warfare.86 In other words, not all intelligence collection falls under the unconventional warfare umbrella—even when it is conducted by SOF. Nor is guerilla warfare always conducted under the rubric of unconventional warfare.

Unconventional warfare is distinguished from other forms of warfare in that it uses irregular indigenous (surrogate) forces against the established or governing power in denied areas.87 The indigenous forces may be guerillas waging their own campaign against the government or they may be, essentially, independent agents working for the U.S. government. The indigenous forces have objectives of their own (political or pecuniary), so the mission for U.S. forces is to develop and sustain indigenous capabilities and channel them in ways that simultaneously accomplish U.S. national security objectives. For this reason, unconventional warfare is known colloquially as “by, with, or through.”

The goal of unconventional warfare is to exploit an adversary’s political, military, economic, and psychological vulnerabilities by developing and sustaining indigenous resistance forces to accomplish U.S. objectives. Unconventional warfare is “a classically indirect, and ultimately local, approach to waging warfare.”88 Unconventional warfare “is fought by subterranean armies composed of volunteers, revolutionists, guerillas, spies, saboteurs, provocateurs, corrupters, [and] subverters,” and it is waged through military, political, economic, and psychological means.89 In peacetime, unconventional warfare “operates at a level below that of outright provocations and the instigators do not appear in the open.”90

As we saw above, the U.S. military limits its definition of unconventional warfare to activities that take place within the context of insurgencies (conflicts in denied areas against the government or force in power). U.S. support to insurgencies “can be categorized as one of two types of campaign efforts: general war scenarios and limited war scenarios.”91 A typical general war scenario is when the U.S. military wants to prepare for possible conventional invasion of a foreign country by establishing an unconventional capability (i.e., the ability to use indigenous surrogates). During the preparation phase, which consists of initial contact and infiltration, the goal is to identify exactly what U.S. military needs or requirements would be, as well as which indigenous individuals or groups would be willing to work with U.S. personnel. Initial contact is when contact with resistance forces (potential partners) is first made; this may take place in another country (contacting expatriates or exiles), or through intermediaries such as CIA personnel. Infiltration is when U.S. personnel first enter the country where the potential indigenous partners are located; given the clandestine nature of unconventional warfare, the U.S. personnel will not likely enter the country in uniform, nor will their true intentions be apparent. Organization and buildup are stages where the capabilities of indigenous forces are developed through training and equipping. These indigenous capabilities are then employed to accomplish U.S. objectives. Unconventional warfare concludes with a transition phase that may include demilitarization. Historical examples of the U.S. military conducting unconventional warfare in the context of general war include the Jedburg teams inserted by the Office of Strategic Services (OSS) into occupied France during World War II,92 Afghanistan in 2001–2002,93 and Iraq in 2003.94

Unconventional warfare in the context of a limited warfare scenario is conducted in very similar phases. The key difference, however, is significant to our purposes here: in limited warfare the U.S. government seeks to apply pressure against an adversary via internal forces rather than a military invasion. In limited warfare, the U.S. government does not use conventional military forces to overtly invade the adversary, but seeks instead to accomplish political objectives through the use of small numbers of SOF, and often CIA personnel, working “by, with, or through” indigenous forces. Limited warfare is politically risky and, thus, conducted in secret: it is colloquially referred to as secret war, dirty war, small war, or low-intensity conflict.95 The United States conducted unconventional warfare in the context of limited war in North Vietnam in 1961–1964,96 the Bay of Pigs in 1961, Nicaragua in 1980–1988,97 and Afghanistan in 1980–1989.

Unconventional warfare is generally effectuated in seven phases: preparation, initial contact, infiltration, organization, buildup, employment, and transition.98 Each phase may not always be required, and phases may be conducted simultaneously or out of sequence.99 Each phase highlights the Title 10-Title 50 debate and related congressional oversight concerns that are the focus of this paper, yet these concerns are particularly acute in the initial contact and infiltration phases. During the initial contact phase, an interagency pilot team “composed of individuals possessing specialized skills” may make contact with indigenous forces and begin assessing the potential to conduct unconventional warfare.100 SOF often augment pilot teams led by, and primarily constituted of, CIA personnel.101

This brief overview of unconventional warfare illustrates why unconventional warfare often appears very similar to activities conducted by CIA personnel. Indeed, SOF typically work closely with CIA personnel while conducting unconventional warfare, although the relationship tends to be informal and focused more on mutual support. In other words, the relationship is one of cooperation in pursuit of mutual objectives rather than a formal superior-subordinate relationship. As we will examine in more detail in Part IV of this paper, this is an important distinction that directly answers whether the unconventional warfare mission is a military operation or intelligence activity.

B. Cyberwarfare

Cyberwarfare is no longer the future of warfare—it is the present and future. While a “hot” cyber war between major powers has thankfully not occurred, there are minor skirmishes, a silent cyber arms race, and major intelligence gathering.102 According to Mike Jacobs, formerly of the NSA, countries “are learning as much as they can about power grids and other systems, and they are sometimes leaving behind bits of software that would allow them to launch a future attack.”103 These may be acts of cyber espionage rather than cyberwarfare, but they are at least preparing cyberspace for warfare—and they highlight the integration of intelligence and warfare in cyberspace.

In January 2011, a front-page New York Times article detailed a sophisticated cyberattack straight out of science fiction.104 Strong circumstantial evidence suggested Iran’s nuclear program was delayed for several years after a computer worm named Stuxnet infiltrated the industrial control systems responsible for manufacturing Iran’s nuclear centrifuges. Since the computers controlling Iran’s nuclear enrichment facilities are not connected to the Internet, Stuxnet was apparently designed to infiltrate the computers of contractors working for Iran’s nuclear program and hitchhike on thumbdrives or similar removable media devices that were later connected to computers at Iran’s enrichment facilities. Stuxnet then caused the machines spinning centrifuges to create defective centrifuges while simultaneously reporting that all systems were performing normally. Experts suggested Stuxnet could only have been created by American or Israeli intelligence agencies.105 If true, Stuxnet heralded a new age of cyberwarfare able to destroy “targets with utmost determination in military style.”106

On June 23, 2009, U.S. Cyber Command was established to lead U.S. military efforts against “cyber threats and vulnerabilities” and “secure freedom of action in cyberspace.”107 Accepting the recommendation of Secretary of Defense Robert Gates, President Barack Obama nominated Lieutenant General Keith B. Alexander, the Director of the National Security Agency, to also serve as the Commander of U.S. Cyber Command. During the confirmation process, the Senate Armed Services Committee questioned various aspects of General Alexander’s proposed dual responsibilities—questions at the heart of the Title 10-Title 50 debate. How would he carry out his responsibilities as Director of the National Security Agency, an intelligence agency and member of the intelligence community, while also carrying out his responsibilities as Commander of U.S. Cyber Command, a military war-fighting command?

The Committee asked General Alexander, for example, whether the military conducts intelligence gathering of foreign networks, whether intelligence gathering of foreign networks is “authorized and reported to Congress under Title 10 or Title 50,” and whether cyberspace operations are traditional military activities. While many of General Alexander’s answers were provided to the Committee in a classified supplement, his unclassified answers and testimony at his confirmation hearing presumably provide insight into how the Secretary of Defense exercises his statutory and delegated authorities to conduct intelligence activities and military operations.108 General Alexander repeatedly explained that “while there will be, by design, significant synergy between NSA and Cyber Command, each organization will have a separate and distinct mission with its own identity, authorities, and oversight mechanisms.”109

Cyberspace is defined by the U.S. government as the “global domain within the information environment consisting of the interdependent network of information technology infrastructures, including the Internet, telecommunications networks, computer systems, and embedded processors and controllers.”110 Others suggest a definition that emphasizes cyberspace as a global information environment unique in its “use of electronics and the electromagnetic spectrum to create, store, modify, exchange and exploit information via interdependent and interconnected networks using information communications technologies.”111 Indeed, the distinctive use of electronics and electromagnetic spectrum distinguishes cyberspace from the domains of land, sea, air, and space: it is “a physical environment . . . managed by rules set in software and communications protocols.”112 Cyberspace is governed by the laws of physics and the logic of computer code.113

Wikipedia defines Cyberwarfare simplistically: as the use of computers and the Internet to conduct warfare in cyberspace.114 The U.S. military does not define cyberwarfare in its unclassified dictionary, wisely avoiding the term “war” with its associated baggage and implications. The U.S. military instead categorizes cyber operations as defense, exploitation, or attack.115 This article focuses on the last two categories, exploitation and attack, and attempts to define the legal authorities and identify the type of activities associated with these categories. In the minds of some, exploitation infers intelligence activities while attack sounds like a military operation, yet our analysis here will add nuance to this simplistic characterization.

If the distinguishing characteristics of cyberspace are electronics and electromagnetic spectrum governed by the laws of physics and computer code, then how can we best distinguish cyber exploitation from attack? One could argue that cyber attacks affect electronics and electromagnetic spectrum by altering their physical characteristics or computer code, while exploitation merely gathers information. The problem is that cyber attack thus defined would include acts of computer network exploitation where computer code is left behind or altered (for example, keystroke logging or insertion of a “backdoor”).

Perhaps cyber attack should be defined or interpreted more in the classical international relations sense of forced political coercion.116 Cyber operations would not be considered attacks if they seek only to gain information or intelligence, and are not intended to alter or control the primary functions of the adversary’s electronics or electromagnetic spectrum—even if they do leave computer code behind, such as keystroke logging software or the insertion of a back door. Subsequent acts to exploit the identified vulnerabilities by asserting control, or coercion, over the systems would rise to the level of attacks.117

This distinction between merely altering computer code without asserting control or degrading function and actually assuming control or degrading functions is consistent with international law, which does not generally consider intelligence activities to be acts of war. Its weakness, however, is definitional reliance upon the intent of the sponsor.

Distinguishing cyber attack from exploitation based on the intent of the sponsor is analogous to the challenge of distinguishing between warning shots and an initiation of armed conflict: intent is clear to the person pulling the trigger, but much less so to those on the receiving end.

The salient point is this: during the initial period after you discover someone is or was inside your network, you may not know whether the other person is initiating an attack or merely attempting to exploit your network. The other party knows why he is inside your network, but you do not. If you know your network is being attacked, a broad range of responses may be justified in self-defense; however, if your network is merely being exploited (an intelligence activity) your range of responses are arguably more limited. Thus, this distinction helps define the legal authority to carry out an operation, but does little to define appropriate defensive responses.

Which is why intelligence is the key to successful cyberwarfare. Cyber exploitation plays a critical supporting role in cyber attack. Knowing where an adversary’s cyber systems are vulnerable will likely require computer network exploitation “to understand the target, get access to the right attack vantage point, and collect BDA [battle damage assessment].”118  In the words of one expert on cyber attack, “those who prepare and conduct operational cyberwar will have to inject the intelligence operative’s inclinations into the military ethos”—inclinations that include discrete effects, patience, an intuitive understanding of the adversary’s culture, a “healthy wariness of deception, indirection, and concealment . . . [and] a willingness to abandon attack plans to keep intelligence instruments in place.”119

As noted above, the intent or purpose of the actor is typically a key distinction between cyber exploitation and cyber attack. A recent report issued by the National Research Council suggests the distinction is really the nature of the payload, but acknowledges that technical similarities between attack and exploitation “often mean that a targeted party may not be able to distinguish easily between a cyberexploitation and a cyberattack.”120 The Report provides this helpful illustration:


This illustration is a helpful starting point, but its simplistic separation of Title 10 and cyber attack in one column and Title 50 and cyber exploitation in another column belies the stovepiped thinking of congressional overseers and ignores current operational realities. It ignores military intelligence collection efforts and operational preparation of the cyber environment by military personnel operating under military command and control— activities that are properly understood to be military operations and not intelligence activities, as we will see in Part IV of this paper.

Cyberwarfare differs from other forms of warfare in that the skills or tools necessary to collect intelligence in cyberspace are often the same skills or tools required to conduct cyber attack. Furthermore, the time lag between collecting information and the need to act upon that information may be compressed to milliseconds. Unlike the traditional warfighting construct where intelligence officers collect and analyze information before passing that information on to military officers who take direct action, cyber attack may require nearly simultaneous collection, analysis, and action. The same government hacker may identify an enemy computer network, determine its strategic import, and degrade its capabilities all in a matter of seconds.

This is precisely why President Obama put the same man in charge of cyber intelligence activities and military cyber operations. This is also the reason Congress evidenced considerable apprehension and asked many questions about authorities and oversight. After all, congressional oversight retains its antiquated, stovepiped organizational structure and presumes a strict separation between intelligence activities and military operations even when no such separation is legally required.

