iTnews
  • Home
  • News
  • Technology
  • Security

Revealed: How paranoia helped bring down the PM's web site

By Ben Grubb
Oct 21 2009 3:08PM
Follow google news

Key lessons from DDoS attack on Kevin07's site.

A Senate Estimates hearing has revealed that countermeasures put in place by secuirty professionals charged with protecting Prime Minister Kevin Rudd's web site contributed to the site's failure in early September.

Revealed: How paranoia helped bring down the PM's web site

The attack, which saw the site become unavailable for 30 minutes and sluggish for several hours afterwards on September 9, was publicised in advance by the 'Anonymous' hacker group, to protest against the Government's proposed web filter.

Mike Rothery, first assistant secretary of the National Security Resilience Policy Division within the Australian Government told a Senate Estimates committee on Monday that "a number of measures put in place to prepare for the attack actually contributed to the site being unavailable."

Rothery said the Defence Signals Directorate knew about the possibility of an attack more than a week in advance and informed security personnel within the Department of Prime Minister and Cabinet accordingly.

To prepare for the attack, IT security professionals working for the Department of Prime Minister and Cabinet "reduced the number of concurrent users that could connect to the website," Rothery said. They had also "sought support from their internet service provider to manage an anticipated increase in demand."

"That capacity was met very early, because the attack continued for about another 20 hours," he explained. "In fact, the attack was less than anticipated and some of the protective measures had been probably unnecessarily strict."

Over time, he said, the security professionals realised that the restrictions on concurrent users was causing the site to appear offline. "They turned that capacity up and were able to maintain the website despite the attack," he said.

Rothery said the attack peaked at "a few thousand concurrent inquiries" on the Prime Minister's web site.

Liberal Senator Guy Barnett said that "this did not seem like that many."

"Surely a website can be appropriately protected from a few thousand hackers," the Senator asked.

But Rothery defended the Government's response, explaining to Senator Barnett that all websites are provisioned with capacity based on "what you would expect the normal traffic to be".

"Otherwise you are paying for capacity that you are not using," he said. "A normal practice for any organisation, be it private sector or public sector is: if you assess that the normal peak demand is perhaps 200 concurrent users, you might buy the capacity for a few hundred more than that so that normal users would not notice any significant degradation should they all be on at the same time."

Centrelink, he said by way of further example, would anticipate far more hits than the Prime Minister's site, and would thus have "redundant capacity in excess of that" and a larger attack would be required to take its site down.

"The issue is that we do not allocate extremely large amounts of bandwidth, which government departments have to pay for on an ongoing lease basis, without there being a legitimate or identified business need for it," he said.

Two phases

Rothery explained how the Distributed Denial of Service attack came in two surges.

“The first was at 7pm on Wednesday [September 9] that week and there was another surge at 10 am [September 10] on the next day,” Rothery said.

He said that the second surge was “slightly more severe” but said adjustments - made prior to it - had prevented the site from being inaccessible.

“There was a better balancing of the arrangements the next morning and, whilst the site became slower, it did not become unavailable,” Rothery said.

Prime Minister briefed

It was also revealed that Prime Minister Kevin Rudd had personally been briefed through a report from the Attorney General’s Department as to why his website was inaccessible on the night of September 9.

“The Attorney-General’s Department coordinated a report on behalf of all of the agencies that were involved in managing the incident, with special emphasis on those arrangements around the protective measures and the mitigation measures," Rothery said. “The report went to the Prime Minister.”

The report came to the Minister the week following the incident, he said.

Prevention of future attacks

Rothery explained advice that had been given to government agencies in how they should deal with future attacks.

"The advice that we give to agencies ... is for them to have relationships with their internet service providers to be able to increase, for a short period, the amount of bandwidth allocated to a particular site until such time as either the attack can be disrupted or the attack wraps up for its own reasons," Rothery said.

The attacks are believed to have been initiated by a group of protesters calling themselves Anonymous who launched the attack to protest against the Government's proposed web filter, which the group describes as "draconian internet censorship".

Charges were yet to be made and "inquiries" by the Australian Federal Police were still being looked into, Rothery said.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
attackfilteringministerprimesecurity

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.