NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Technology
Slice by Program

Estonia's unsolved zombie insurgence

By: Richard Bray, CIO Government Review(07-23-2007)



The origin of the attacks on Estonia's Internet infrastructure may never be known. Hackers typically don't sign their work with real names.

The denial-of-service attacks that began in April are linked, at least in a time sequence, to the removal of a statue honouring a Second World War Soviet soldier from a public park in the Estonian capital of Tallinn.

One in four Estonian citizens is of Russian descent and many take great pride in "liberating" Estonia from the Germans. Many ethnic Estonians hated the Soviets then, hate Russia now and are not particularly grateful to the Red Army, which departed in 1994 only.

The removal of the statue triggered several days of street protests in Estonia by the Russian minority, which the authorities anticipated. They also anticipated Internet-based attacks, but not their scale nor duration.

More than a month of attacks created chaos in the Estonian economy. The month-long assault against government Web sites, banks, media outlets and ISPs was neither unusual nor unexpected.

The New York Times hedged its bets by citing anonymous observers, calling it "what some describe as the first real war in cyberspace." But "first," "real" and "war" still scored a hat trick of untruths.

In fact, it is hardly the first online conflict. Japan, China and the Koreas probe each other's networks all the time, and there are occasional assaults against the United States.

Palestinians and Arabs try to disrupt Israel's communications. Nations created by the collapse of the "formers," Yugoslavia and the Soviet Union, hack away at each other all the time, as do India and Pakistan.

The attacks against Estonia are also not "real" in the sense there is no identifiable attacker. In the early days of the cyberstorm, Estonian government officials directly blamed official Russia. Prime Minister Andrus Ansip even claimed some of the attacking computers were in Russian President Vladimir Putin's office.

The attacks also do not constitute a "war," defined as a "state of armed conflict" or a "sustained contest" between rivals. Shutting down Internet access was not accompanied by physical raids or a coup d'etat. If the attackers had a goal, it was disruption, and they achieved it.

There is no comfort in believing that the attackers were not under the orders of a government. One plausible source of the attacks is Russian criminal gangs, exploiting their technological expertise and resources in what they might see as a patriotic cause.

If the attacks against Estonia were state-sponsored, by Russia or any other nation, then the attacking nation could quickly find itself in deeper trouble than it bargained for. The tools of retaliation are cheap, easy to use and freely available to all.

What happened in Estonia could be a mild example of fourth-generation warfare, broadly defined as combat in which one side refuses to "fight fair" and whose main aim is the chaos it creates.

Estonia is particularly susceptible to Internet-based attacks because much of its government, banking, commercial and communications infrastructure has been built on top of the Internet. There was no apparent attempt to target national critical infrastructure other than Internet resources, and no extortion demands were made.

Digital attacks are inexpensive and can wreak economic havoc far out of proportion to the investment. The basic techniques are clearly understood, and as the case of Estonia shows, the zombie networks are available. There is a global, instant, anonymous marketplace in attack technologies that are beyond the control of any government.

The attacks also punched big holes in the idea that the Internet is so universal and has so much inherent redundancy that it can heal itself, patching around damaged nodes and getting the data safely to its destination, despite any and all obstacles. At different points during the attacks, Estonia deliberately isolated itself from the rest of the Internet.

As John Robb says in his new book, Brave New War, "The threshold necessary for small groups to conduct warfare has finally been breached, and we are only starting to feel its effects," and, "Nonstate actors in the form of terrorists, crime syndicates, gangs and networked tribes are stepping into the breach to lay claim to areas once in the sole control of states."

If he is right, that means the attacks against Estonia may have been not only unsanctioned by the Russian government but completely beyond its control. For its part, Estonia has reportedly backed away from blaming the Russian government and is instead asking the European Union to classify the attacks as terrorism.

In the end, the impact of the attacks against a country or an organization is the same. The difference now is that groups beyond the control of any state can organize and use advanced weapons of cyberwar.

Richard Bray is an Ottawa-based freelance journalist specializing in high technology and security. He can be contacted at rbray@itworldcanada.com

Related content:

Cyber attack prompts U.S. to send team to Estonia

Blog: Why Estonia matters to us all

Cyber crisis test sends Feds back to security school

The European advantage

Waterloo wins battle of 'intelligent communities'

New cybersecurity czar rips indecisive bureaucracy

Cyber-crime protection pushes new precedents for privacy

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Info-Tech Research Note: WAN Optimization Tools worth the investment
Multi-site enterprises experiencing WAN bandwidth demand growth and struggling to maintain acceptable application performance should evaluate WAN optimization technology immediately. WAN optimization appliances can dramatically improve inter-site WAN performance, reduce bandwidth requirements, and allow for server centralization. For many enterprises a positive ROI can be achieved in less than a year. Download this research note now. Complimentary with registration.
Advertisement

2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada