Expert dissects Estonian cyber-war

  • Email a Friend
  • Print Page
Expert dissects Estonian cyber-war

A security researcher involved in defending against last year's Web attacks on Estonia has shared his account of the crisis, and is offering advice on how to prevent similar assaults in the future..

Gadi Evron has published an article in the Georgetown Journal of International Affairs detailing his experiences in helping Estonia's government defend against a "cyber-riot" from Russian nationalist hackers.

The attacks began in April 2007 when authorities from the former Soviet state disclosed plans to move a Russian World War II memorial out of a town square and into a military graveyard.

An outcry from ethnic Russians in the country led to a series of real-world riots as well as an outbreak of cyber-attacks on Estonian government websites.

The attacks were especially devastating for Estonia, which has become highly reliant on web-based services in recent years.

"While the exact source of the attacks remains unknown, evidence suggests a highly organised assault," wrote Evron.

"Not only did the cyber-riot start almost simultaneously with the actual riots, but fresh posts in the Russian-language blogosphere appeared with new targets and instructions."

Evron claims that the Estonian government went so far as to lobby the EU to pressure the Russian government to step in, a move which was ultimately blocked for diplomatic reasons.

The attacks began soon after. Fuelled by Russian-language blogs and websites, a mob of users joined with botnet controllers to attack Estonian government sites, and then target the country's banks and news outlets.

The government enlisted its own computer emergency response team to defend against the attacks along with volunteers and outside security consultants.

While the team was eventually able to weather the attacks, Evron said that the process might have been slowed by a lack of clear leadership.

"The Estonian response team was able, to a degree, to mitigate the impact of the attacks," he wrote. "But due to its ad hoc, unofficial status, it lacked the authority to enforce its recommendations on all parties involved."

Evron suggested that all governments need to develop a plan for responding to a cyber-attack and establish a clear chain of command.

"Public and political attitudes to cyber-crime must change, and law enforcement must be given greater resources to cope with its growing presence in the virtual community," he said.

"Different national law enforcement agencies and operations should collaborate and establish a common framework that will help trace recent developments involving internet security in a significantly faster fashion, as current measures have completely failed to cope."

Copyright © 2009 v3.co.uk


 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
TIO website hit by malware
Weekend malware runs one new process per target machine.
 
Microsoft announces Azure launch date
Australia in second wave of country releases.
 
CBA embarks on "database-as-a-service"
Analysis: How the bank intends to save megabucks.
 

Spotlightthe topics we're following

Latest Comments

"It never fails to astound me at the greed of corporate executives and politicians, and this ..."
by BernieG Feb 10, 2010 7:55 AM
 
"Hahahah...What a joke!! "Conroy had said that it was not possible to apply ISP-level filtering ..."
by gerson Feb 9, 2010 10:39 PM
 
"@@Comments, yes, and history keeps repeating itself. Remember the earlier pr-and-media-fuelled ..."
by anonymous Feb 9, 2010 6:40 PM
 
"I would have paid good money to be in court when that clanger dropped. Could you imagine, the ..."
by Private Citizen Feb 9, 2010 6:23 PM
 
"He is not yet listed on NBN Co. website as part of their team of executives (http://www.nbnco.com..."
by Private Citizen Feb 9, 2010 6:07 PM
1) HTC Magic16 plans 2%
2) Nokia N9743 plans 9%
3) Nokia E7149 plans 1%
4) Apple iPhone 3GS 16GB30 plans 11%
5) Apple iPhone 8GB42 plans 5%
1) iiNet32 plans 5%
2) Netspace36 plans 11%
3) TPG Internet19 plans 14%
4) Optus33 plans 1%
5) Telstra BigPond30 plans 2%

Mobiles | Broadband | Credit Cards

iTnews

Polls

What is the sweet spot for Apple's entry 16GB Wi-Fi iPad?




   |   View results
$549
  78%
 
$579
  10%
 
$619
  4%
 
$649
  3%
 
$699
  5%
TOTAL VOTES: 382

Vote