Cyberspace is now a key arena in which attacks are becoming increasingly complex and dynamic, and often take place below the threshold of open conflict. For Switzerland’s security and the Swiss Armed Forces’ ability to act, it is crucial to understand technological developments at an early stage, to exploit their potential and to possess sound expertise. The Cyberspace Research Programme strengthens the relevant capabilities and lays the groundwork for anticipating new technologies and translating them into military applications.
As a central arena of activity, cyberspace now permeates all state, societal and military domains. Cyberattacks of various kinds are a daily occurrence and are becoming increasingly complex and dynamic – not least due to rapid developments in the field of artificial intelligence (AI). Switzerland’s security and the Armed Forces’ ability to act therefore depend on the continuous development of the relevant capabilities and expertise in cyberspace.
Contribution of research
In this context, the Cyberspace research programme makes an important contribution to strengthening Switzerland’s defence capabilities and security.
It provides in-depth expertise to identify technological developments in the cyber domain at an early stage and to scientifically assess their potential for the armed forces – for example, in the context of procurement projects.
It enables early access to new technologies and methods, so that we can be prepared for future threats and play an active role in shaping technological developments.
These research projects give rise to innovative solutions and technologies which can be further developed in collaboration with the Academy and industry, and deployed by the armed forces.
Thanks to new methods for identifying vulnerabilities, more security flaws are being detected, reported and rectified. This results in a direct improvement in security for Switzerland.
Collaboration with Swiss research institutions
Research activities are carried out in collaboration with leading research institutions. Particular emphasis is placed on cooperation with the Swiss Federal Institutes of Technology (ETH Zurich and EPFL), universities, universities of applied sciences and other research institutions in Switzerland, with a view to promoting and further developing existing expertise. These partnerships ensure access to up-to-date knowledge and highly qualified talent, and make an important contribution to the sustainable development of key competencies in the Swiss cyber sector.
Areas of expertise
The Cyberspace Research Programme is based on the overall cyber strategy of the Swiss Army, with the aim of further developing the capabilities listed therein in a targeted manner. The focus is on the areas of expertise of self-protection in cyberspace, operations in cyberspace, and robust and secure data processing.
The area of expertise ‘Self-protection in cyberspace’ encompasses the ability to effectively protect one’s own information and communication systems against cyber threats. The aim is to ensure the availability, integrity and confidentiality of these systems even under attack. This includes both preventive measures such as hardening and monitoring, as well as the detection, defence against and management of cyber attacks. Self-protection is a key prerequisite for the Army’s command and operational capability in all situations.
The competence area ‘Operations in cyberspace’ encompasses the capability to operate actively in cyberspace in order to support military operations. This includes, in particular, gathering intelligence on adversarial activities, influencing information flows, and disrupting or restricting adversarial systems. Such operations serve to protect one’s own forces and to deny the adversary room for manoeuvre. They are always conducted in accordance with legal and political guidelines. Overall, the competence area ‘Operations in cyberspace’ contributes to achieving immediate military effects via the digital domain.
The competence area ‘Robust and secure data processing’ encompasses the capability to process data reliably, securely and under all operational conditions. The focus is on resilience, reliability and protection against manipulation or unauthorised access. To this end, high-performance, redundant and hardened systems are used which remain functional even in the event of malfunctions or attacks. The secure processing and storage of data forms the basis for situation-appropriate decisions and effective command.
Current research topics
The following topics provide an insight into the research activities of the research programme. They are representative of the broad range of topics covered by the Cyberspace research programme.
By systematically searching for vulnerabilities in hardware and software, potential risks relevant to the systems of the Federal Administration and the Armed Forces can be identified at an early stage. At the same time, methods and tools are continuously reviewed and further developed, particularly with a view to achieving a higher degree of automation. Furthermore, vulnerability research helps to make the impact of cyber attacks tangible and to raise awareness of security risks.
As buildings become increasingly digitalised, the attack surface of their control systems is also growing. Many existing solutions were not designed with today’s threat landscape in mind and therefore have corresponding vulnerabilities. Research in this area encompasses the analysis of realistic system environments, the identification of vulnerabilities, and collaboration with manufacturers to address these risks. At the same time, testing procedures and tools are being developed to specifically improve the cyber security of future systems right from the procurement and implementation stages.
Wide-area networks (WANs) form the backbone of modern information infrastructures and connect geographically dispersed locations such as data centres or office sites. Whilst confidentiality and integrity can often be guaranteed by cryptographic methods, ensuring availability poses a particular challenge. Attacks such as Distributed Denial of Service (DDoS) can significantly impair communication. In collaboration with research partners, we are investigating how the robustness and security of such networks can be sustainably improved.
Mobile devices (smartphones) are also playing an increasingly important role in security-critical environments. One research focus centres on the development of platforms that enable applications requiring a high level of protection to be run in isolated and trusted environments. Through the use of technologies such as hardware isolation and virtualisation, sensitive applications can be shielded from the operating system and other apps. Current research is looking, amongst other things, at new approaches to the secure execution of software that further reduce the level of trust required in underlying system components.
Humans play a central role in cybersecurity – both as potential targets of attacks and as a crucial line of defence. This is why research is being conducted into how perception, behaviour and decisionmaking processes influence security. There is a particular focus on phishing attacks, which remain highly effective despite technical protective measures. Building on these findings, new approaches are being developed, such as through the use of augmented and virtual reality, to better support users in identifying dangerous content.