Estonian Attacks Raise Concern Over Cyber 'Nuclear Winter'
Larry Greenemeier writes on InformationWeek:
As NATO technical assistance this week begins to flow into the cyberwar-torn Estonia, additional details are surfacing about the cyberattacks launched during the first two weeks of May against the Baltic nation. Thoughts also are turning to how future attacks might be averted.
The cyberattacks against Estonia, mainly in the form of Distributed Denial of Service (DDoS) attacks, primarily targeted the Estonian government, banking, media, and police sites. "Private sector banking and online media were also heavily targeted and the attacks affected the functioning of the rest of the network infrastructure in Estonia," the European Network and Information Security Agency, or ENISA, reported Thursday on its Web site. As a result, the targeted sites were inaccessible outside of Estonia for extended periods in order to subdue the attacks and to maintain services within the country.
DDoS attacks are particularly difficult to prevent and require a lot of coordination to contain the damage when multiple sites are hit. In order to weather the 128 separate strikes launched against its cyber infrastructure, Estonia sought help from not only its own Computer Emergency Readiness Team, established late last year, but also the Trans-European Research and Education Networking Association (pdf) and CERTs from other countries, including Finland and Germany, according to ENISA.
While cyberattacks against governments are nothing new, the Estonian attacks were particularly damaging, as the country had to shut down key computer systems for their own protection.
More
here.
Russia's Cyber-Attacks on Georgia and Estonia Draw Criticism
Jacob Goodwin writes on GSN.com:
The popular concept of the cyber-attacks launched by Russia against Estonia and Georgia in recent years is that an army of volunteer hackers bombarded government computers in those target countries with disabling botnet attacks.
But the reality is that most of the cyber-pain suffered by Estonia, for example, was caused when the U.S. and European banking system chose intentionally to cut off Estonia from the Internet-based financial clearing networks, because the networks couldn't distinguish bona fide transactions emanating from Estonia from botnet-induced bogus transactions.
"We lost the U.S. Treasury for four hours," explained Stephen Spoonamore, a partner with Global Strategic Partners and an expert in international cyber warfare, "and that's really bad."
While Estonia's banking system was being bombarded, the European banking settlement networks were trying to close for the day, but were being flooded with botnet attacks from Estonia and Lithuania (another target of Russia's cyber-offensive).
Trillions of dollars of flow was at stake, said Spoonamore, during a luncheon presentation at the GovSec security show in Washington on March 11, "but no one could tell what was real." To protect the integrity of its financial system, the European banking network cut off Estonia and Lithuania, he added.
More
here.
Estonia Gets Respite From Denial of Service Attacks
Robert Lemos writes on SecurityFocus:
Denial-of-service attacks on Web sites in the northern European country of Estonia have trailed off three weeks after civil unrest spurred partisan attackers to level massive data floods against government sites.
In an analysis of the last two weeks of attacks, a researcher for network security firm Arbor Networks identified at least 128 separate attacks on nine different Web sites in the country, including 35 attacks on the Web site of the Estonian Police, another 35 attacks on the Web site of the Ministry of Finance, and 36 attacks on the Estonian parliament's, prime minister's, and general government Web sites. Some of the attacks lasted more than 10 hours and topped 95Mbps.
"All in all, someone is very, very deliberate in putting the hurt on Estonia, and this kind of thing is only going to get more severe in the coming years," Jose Nazario, senior security researcher for Arbor Networks, said in the blog post.
More
here.
Behind The Estonia Cyber Attacks
Robert Coalson writes on Radio Free Europe/Radio Liberty:
In the spring of 2007, a cyberattack on Estonia blocked websites and paralyzed the country's entire Internet infrastructure. At the peak of the crisis, bank cards and mobile-phone networks were temporarily frozen, setting off alarm bells in the tech-dependent country -- and in NATO as well.
The cyberattacks came at a time when Estonia was embroiled in a dispute with Russia over the removal of a Soviet-era war memorial from the center of Tallinn. Moscow denied any involvement in the attacks, but Estonian officials were convinced of Russia's involvement in the plot.
A new blog post for Ekho Moskvy makes a startling revelation about the 2007 attacks. The post, by journalist Nargiz Asadova -- a columnist for RIA Novosti based in Washington, and an Ekho Moskvy host -- describes a March 3 panel discussion between Russian and American experts on information warfare in the 21st century.
Asadova, who was moderating the discussion, asked why Russia is routinely blamed for the cyberattacks in Estonia and Georgia, where government sites were seriously disrupted during the August war.
She might not have been expecting the answer she got from Sergei Markov, a State Duma Deputy from the pro-Kremlin Unified Russia party: "About the cyberattack on Estonia... don't worry, that attack was carried out by my assistant. I won't tell you his name, because then he might not be able to get visas."
Markov, a political analyst who has long been one of Vladimir Putin's glibbest defenders, went on to explain that this assistant happened to be in "one of the unrecognized republics" during the dispute with Estonia and had decided on his own that "something bad had to be done to these fascists." So he went ahead and launched a cyberwar.
"Turns out it was purely a reaction from civil society," Markov reportedly said, adding ominously, "and, incidentally, such things will happen more and more."
In Russia, Markov's confession is all over the blogosphere, but has yet to be picked up by the Russian media.
More
here.
Hat-tip: IntelFusion
Estonia Urges Firm EU, NATO Response to Cyber Attacks
Via The Sydney Morning Herald.
Estonia has urged its allies in the European Union and NATO to take firm action against a new mode of warfare that has been unleashed on the Baltic state in a bitter row with Russia over a Soviet war memorial: cyber-attacks.
"Taking into account what has been going on in Estonian cyber-space, both the EU and NATO clearly need to take a much stronger approach and cooperate closely to develop practical ways of combatting cyber-attacks," Estonian Defence Minister Jaak Aaviksoo told AFP Tuesday.
"Considering the scale of damage and the way these cyber-attacks have been organised, we can compare them to terrorist activities," Aaviksoo said a day after raising the new mode of warfare at talks with his fellow EU defence ministers in Brussels.
Estonian institutional websites have been under regular cyber-attack since the end of last month, when a row blew up with Russia over the removal from central Tallinn of a memorial to Soviet Red Army soldiers.
Officials in Estonia, including Prime Minister Andrus Ansip, have claimed that some of the cyber-attacks, which forced the authorities in the Baltic state to temporarily shut down websites, came from Russian government computers, including in the office of President Vladimir Putin.
More
here.
Background
here,
here, and
here.
Estonia Arrests Suspect Over 'Cyber-Attacks'
An AFP newswire article, via PhysOrg.com, reports that:
Police arrested Saturday a 19-year-old Tallinn resident who is suspected of involvement in a wave of attacks against Estonian computer servers.
"The criminal police have detained the first person who stands accused in involvement in the recent cyber-attacks against Estonian servers," Kristiina Herodes, spokeswoman for the Estonian prosecutor's office, told AFP.
"Dmitri was posting on Internet forums calls to organise mass attacks against Estonian servers, called the DdoS attacks," Herodes said.
"He collected addresses of crucial Internet sites in Estonia and passed them in various Internet forums, instructing users to attack servers in Estonia," she said.
More
here.
Estonia to Bolster Cyber Defenses After Attacks
Via Reuters.
Estonia unveiled a plan on Thursday to boost its cyber security after an assault on its Internet infrastructure which it blamed on Russians angry at its removal of a Soviet-era statue.
Estonia suffered attacks on public and private Web sites in April and May year after the Red Army monument was moved from a Tallinn square. The removal of the monument led to two nights of riots by ethnic Russians.
The [Economy and Transport] ministry said that, although the cyber attacks did not paralyze daily life, they raised questions as to what other key areas could come under attack and pose a security risk.
The new measures would aim to protect data and increase information security as well as make sure there were adequate legal weapons to fight cyber crime.
At an international level, Estonia said it would like other countries to sign up to a convention against cybercrime.
More
here.
Estonia Hit by 'Moscow Cyber War' - UPDATE
Via The BBC.
Estonia says the country's websites have been under heavy attack for the past three weeks, blaming Russia for playing a part in the cyber warfare.
Many of the attacks have come from Russia and are being hosted by Russian state computer servers, Tallinn says. Moscow denies any involvement.
Estonia says the attacks began after it moved a Soviet war memorial in Tallinn. The move was condemned by the Kremlin.
A NATO spokesman said the organisation was giving Estonia technical help.
"In the 21st century it's not just about tanks and artillery," NATO spokesman James Appathurai told BBC News.
More
here.
Additional background information can be found
here,
here,
here,
here and
here.
UPDATE: 11:02 PDT: A UPI article quotes Estonian foreign minister, Urmas Paet, as saying
"When there are attacks coming from official (Internet protocol) addresses of Russian authorities and they are attacking not only our Web sites but our mobile phone network and our rescue service network, then it is already very dangerous." Details
here.
Attack on Estonia Puts Cyber Security on EU Agenda
Via Reuters.
The European Union will address cyber security issues after attacks on the Internet sites of Estonia, EU Information Society commissioner Viviane Reding said on Saturday.
Estonia suffered cyber attacks on private and government Internet sites, peaking in May after a decision to move a Soviet-era statue from a square in Tallinn prompted outrage from some Russian nationals in Estonia and triggered a diplomatic row with Moscow.
"Estonia was a wakeup call," Reding told a European Business Leaders Convention. "We have to wake up our governments ... If people do not understand the urgency now, they never will."
More
here.
Estonia Hosts Georgian Websites to Halt Hackers
An AP newswire article, via SFGate.com, reports that:
The government of Estonia is temporarily hosting the Web sites of Georgia's central bank and Foreign Ministry to try to protect them from cyber attacks, officials said Tuesday.
Georgia has transferred key Web sites to servers in other countries, including Poland and France, after some came under attack following the outbreak of war with Russia, the state-run Estonian Informatics Center said.
"This is a way to help Georgia make their Web pages visible to the world," said Katrin Pargmae, a spokeswoman for the Estonian center. Estonia is also hosting a Georgian English-language news portal.
Estonia has experience coping with similar attacks: Its government and private sector Web sites were targeted in May 2007, just days after the Baltic state decided to relocate a Soviet war memorial and grave, angering Estonia's ethnic Russian minority and neighboring Russia.
More
here.
Internet Attacks Grow More Potent
John Markoff writes in The New York Times:
Attackers bent on shutting down large Web sites — even the operators that run the backbone of the Internet — are arming themselves with what are effectively vast digital fire hoses capable of overwhelming the world’s largest networks, according to a new report on online security.
In these attacks, computer networks are hijacked to form so-called botnets that spray random packets of data in huge streams over the Internet. The deluge of data is meant to bring down Web sites and entire corporate networks. Known as distributed denial of service, or D.D.O.S., attacks, such cyberweapons are now routinely used during political and military conflicts, as in Estonia in 2007 during a political fight with Russia, and in the Georgian-Russian war last summer. Such attacks are also being used in blackmail schemes and political conflicts, as well as for general malicious mischief.
A survey of 70 of the largest Internet operators in North America, South America, Europe and Asia found that malicious attacks were rising sharply and that the individual attacks were growing more powerful and sophisticated, according to the Worldwide Infrastructure Security Report. This report is produced annually by Arbor Networks, a company in Lexington, Mass., that provides tools for monitoring the performance of networks.
The report, which will be released Tuesday, shows that the largest attacks have grown steadily in size to over 40 gigabits, from less than half a megabit, over the last seven years. The largest network connections generally available today carry 10 gigabits of data, meaning that they can be overwhelmed by the most powerful attackers.
More
here.
Denial of Service Attacks Force Estonian Bank to Close Website
An AFP newswire article, via Yahoo! News, reports that:
Estonia's second-biggest bank, Swedish-owned SEB Eesti Uhispank, was forced Tuesday to block access from abroad to its online banking service after it came under "massive cyber-attack", an official said.
"Massive attacks were launched at noon against our Internet bank, blocking access to our website," Silver Vohu, head of communications at the bank, told AFP.
"Access was restored at 2:00 pm (1100 GMT), but only for users in Estonia. Access from computers located outside Estonia will continue to be restricted for security reasons," he said.
The cyber attacks were the first to target the bank group since a series of similar assaults were launched at the end of last month against the websites of Estonian state institutions, said Vohu.
More
here.
Estonian Cyber Attacks: Lessons Learned, A Year Later
Tom Espiner writes on ZDNet UK:
The idea that attacks on computer systems could provide an alternative method of spreading terror and disruption has been a concern for governments since IT systems began to proliferate.
But it wasn't until Estonia suffered a series of concerted attacks in April 2007 that theory became reality. The movement of the Bronze Soldier, a Soviet-era war memorial commemorating an unknown Russian who died fighting the Nazis, from a square in the capital Tallinn to a military cemetery, has been traced as the main flashpoint for the attacks.
Protests and riots involving ethnic Russians living in the country were the immediate result, but what no-one foresaw was the subsequent series of attacks aimed at computer systems managing the country's critical national infrastructure.
More
here.
Note: I also noted over on the
Trend Micro Malware Blog that "Hacktivism" incidents are becoming more frequent, and much more malicious.
-ferg
Large-Scale Website Attacks Due to Unrest in Estonia
Mikko Hyppönen writes on the F-Secure "News from the Lab" Blog:
Quoting CNN:
"Police arrested 600 people and 96 were injured in a second night of clashes in Estonia's capital over the removal of a disputed World War Two Red Army monument ... Russia has reacted furiously to the moving of the monument ... Estonia has said the monument had become a public order menace as a focus for Estonian and Russian nationalists."
We're now seeing large attacks against websites run by Estonian goverment. Some of the sites are unreachable. Others are up, but do not allow any traffic from foreign IP addresses.
Here's the status as we saw it on Saturday at 15:00 GMT.
More
here.
Estonia Calls For EU Law to Combat Cyber Attacks
A Reuters newswire article, via crime-research.org, reports that:
Estonia called on the European Union on Wednesday to make cyber attacks a criminal offense to stop Internet users from freezing public and private Web sites for political revenge.
Estonian President Toomas Hendrik Ilves said he believed the Russian government was behind an online attack on Estonia over its decision to move a Red Army monument from a square in the capital Tallin. Russia has denied any involvement.
The decision triggered two nights of rioting by mainly Russian-speaking protesters, who argued that the Soviet-era memorial was a symbol of sacrifices made during World War Two.
The rioting coincided with repeated requests to Web sites, forcing them to crash or freeze. Network specialists said at the time at least some of the computers used could be traced to the Russian government or government agencies.
More
here.
Estonia, NATO Allies to Sign Deal on Cyber Defense Center
Via The Age.
Estonia and six NATO allies sign a deal this week to provide staff and funds for a new research center designed to boost the alliance's defenses against cyber terrorism.
The agreement to be signed in Brussels on Wednesday comes a year after the small Baltic nation was exposed to an unprecedented wave of cyber attacks that crippled government and corporate computer networks.
The attacks lasted three weeks and followed deadly riots sparked by the relocation of a Soviet war memorial. Many Estonians suspect the Kremlin was behind the virtual strikes but Moscow has denied involvement.
The attacks showed how vulnerable individual countries are to cyber warfare and underscored the need for a joint NATO response, said Estonian Maj. Raul Rikk, who heads the center.
More
here.
Hat-tip: Flying Hamster
After Attacks, U.S. Government Sending Team to Estonia
Robert McMillan writes on InfoWorld:
Two months after much of Estonia's online infrastructure was targeted by an online attack, the U.S government is sending cyberinvestigators to help the Baltic state better understand what happened.
A representative from the U.S. Department of Homeland Security's US-CERT (U.S. Computer Emergency Response Team) division is heading to Estonia this week to help analyze the large volume of data that was generated by the attacks, said Gregory Garcia, assistant secretary for cyber security and telecommunications with the DHS. "We are sending someone from our organization ... to help them with forensic analysis and to do some additional training on how to secure their infrastructure," he said.
Additionally, a member of the U.S. Secret Service will be there to help with training on incident response and computer crime investigations, according to a DHS spokesman.
More
here.
U.S. General: Recent Cyber Attacks Serve as Lesson
Via DefenseLink News.
Recent cyber attacks against government information systems overseas should serve as a lesson that the United States needs to continue to strengthen its defenses against those who would target the country’s financial, business and military systems, the commander of U.S. Northern Command said today.
Appearing on C-Span’s “Newsmakers,” Air Force Gen. Victor E. Renuart Jr., who leads both NorthCom and North American Aerospace Defense Command, cited recent cyber attacks against the former Soviet republic of Georgia in which government Web sites were intermittently knocked offline, as well as last year’s cyber attacks against government computer systems in the Baltic nation of Estonia.
“We need to ensure that we learn the lessons of those two events, and that we continue to strengthen an integrated process to defend ourselves against these kinds of intrusion,” Renuart said.
Since early this month, hackers have attacked Georgian servers and Web sites, forcing the government to relocate the sites to other servers. Some sites were defaced, while others were simply rendered unavailable.
The general said NorthCom relies on space- and land-based sensors to identify threats, and that intrusions into its computer networks could disrupt the command’s ability to provide warning of an attack.
More
here.
Estonia's CTO Speaks Out on Cyber Attacks
Tom Espiner writes on ZDNet UK:
Speaking to ZDNet.co.uk at the RSA Conference Europe 2007 in London, Mikhel Tammet, director of the Estonian communication and information technology department, said he believes forces within the Russian government may have initiated and sponsored attacks against his country's critical national infrastructure earlier this year.
In May this year the Estonian critical national infrastructure (CNI) came under sustained cyberattack from perpetrators whose identity remains unknown. However, Tammet said he suspected the forces behind the attacks to be linked to the Russian government.
"It was a political campaign induced by the Russians; a political campaign designed to destroy our security and destroy our society," said Tammet on Tuesday. "The attacks had hierarchy and co-ordination."
More
here.
After Estonia Cyber Attacks, U.S. Frets Over Potential Cyber War
Karen Krebsbach writes on U.S. Banker:
The U.S. Treasury Department's decision to sponsor an industry-wide exercise this fall for the financial-services sector to test its ability to respond to a pandemic crisis, such as a bird flu outbreak, is taking on a different, and more sinister tone, in light of the cyber attack that nearly disabled Estonia-including the country's biggest bank-in late May.
The heavily wired Baltic country has been subject to massive and coordinated cyber attacks on Web sites of the government, financial institutions, telecommunications companies, Internet-service providers and news organizations.
More
here.