A friend pointed me to this article that tried to analyse the lessons learnt from the attacks on various web-sites in Estonia.
I personally think that the article is naive at best.
First of all it claims that this was the first government to be attacked, this is certainly not true. While not a government I was fighting (actually I was in the EUnet NOC watching Pierre and James fight, but anyway) Yu attacks on the Nato web-site during the bombing raids on Sagreb, and I am sure it had been done before. There where also several reports of various forms of attacks against Iraqi infrastructure before the start of the second Iraq war.
The article goes on to claim that no collateral damage was done. This show a pretty poor understanding of the nature of these attacks. In most cases, there certainly will be collateral damage as the attacks can be large enough to never reach their intended destination and therefor infrastructure used to provide service to others is also taken out. However, even the notion of collateral damage get interesting when you talk about cyber attacks. If I attack an on-line bank web-site used for on-line trading. The users of that site is likely to loose money as they are not capable of completing their planned transactions. Are they 'real' damage or collateral damage? Does it matter? The term collateral damage is used in real warfare as a way to separate intended (read legitimate) targets from casualties that whose non-loss wouldn't have affected the ability to conclude the intended operational goal. Cyber attacks on banks and/or government web-sites seems highly unlikely to help in achieving these operational goals from a military point of view. Command and control systems of foreign forces, sure - but I am sure the Estonian government would not succumb to Russian rule just because their web-site could not be reached....
Third the article brings up the (lack of) panic created by the attacks. Having had the luxury of being invited to the Estonian CERT and had the privilege of working with the Estonian CERT during the attacks, they where far from panicking. While I don't understand Estonian so my capability of following local news was limited, I think I dare to say that there where no panic among the Estonian population in general either. What I could follow though, and that I dare to say is that there where far more panic in the International press-reports than anywhere else. And here is a real problem with reporting and handling incidents like these. I blogged about this when the DNS root-servers allegedly where attacked. The problem is that while you DO want to inform the public on what is going on, you are at the same time for operational reasons hindered to say all that you know. And the way the press will present the events is likely to more help the attacker achieve their purpose than to help inform the public. This is really worrisome as we for example have very little insight into how banks are handling on-line extortion etc and they are also afraid of reporting similar events to the police.
There is plenty more I could say about the article, but I do not want to disclose facts that could damage operations that the people on the ground are working on. Again, this is the sad fact working with incidents like this, you just can't correct misconceptions in real-time, no matter how much you would like.
Last, personally I am not so much worried about this being the first attack or the attack happening. We knew that all along, Estonian friends made an effort to point out that as far as they where concerned this was nothing more than cyber riots, i.e Internet events mirroring the physical events (I think there have been a fair bit of politicising and word in mouth putting going on, but that I just my personal perception) - the two things that DO worry me is that
1) A point on which I agree with the article. How hard it is to actually bring about arrests in these cases. Even when the criminals are known, and the locations and whereabouts can be tracked, we can't get them behind bars as legislation and international agreements are lacking. If the IGF is serious with fighting cybercrime and making a difference, this is where it will have to start2) That not more governments are trying to draw their own conclusions and work on contingency plans.
But that is just me...
Comments (64)
http://kriminal.jvl.com/ kriminal
Posted by Batwe | March 29, 2008 6:15 PM
Posted on March 29, 2008 18:15
It has just been discovered that research causes cancer in rats.
Posted by Kramam | April 2, 2008 6:39 PM
Posted on April 2, 2008 18:39
By working faithfully eight hours a day, you may eventually get to be boss and work twelve.
Posted by Kraunchtk | April 3, 2008 7:40 PM
Posted on April 3, 2008 19:40
By working faithfully eight hours a day, you may eventually get to be boss and work twelve.
Posted by Kraunchtk | April 3, 2008 7:46 PM
Posted on April 3, 2008 19:46
http://men-wearing-panthose.k2free.com men wearing panthose
Posted by Obraz | April 10, 2008 1:05 AM
Posted on April 10, 2008 01:05
http://men-wearing-panthose.k2free.com men wearing panthose
Posted by Obraz | April 10, 2008 1:05 AM
Posted on April 10, 2008 01:05
http://men-wearing-panthose.k2free.com men wearing panthose
Posted by Obraz | April 10, 2008 1:05 AM
Posted on April 10, 2008 01:05
http://pantyhosed.cyberinkshop.com/ pantyhosed
Posted by Obraz | April 10, 2008 1:05 AM
Posted on April 10, 2008 01:05
http://pantyhosed.cyberinkshop.com/ pantyhosed
Posted by Obraz | April 10, 2008 1:05 AM
Posted on April 10, 2008 01:05
http://collet-chucks.ok.tc/ collet chucks
Posted by Hughes | April 14, 2008 2:28 PM
Posted on April 14, 2008 14:28
http://collet-chucks.ok.tc/ collet chucks
Posted by Hughes | April 14, 2008 2:28 PM
Posted on April 14, 2008 14:28
http://collet-chucks.ok.tc/ collet chucks
Posted by Hughes | April 14, 2008 2:28 PM
Posted on April 14, 2008 14:28
http://www-youtbe-copm.fr33webhost.com/ www youtbe copm
Posted by Hughes | April 14, 2008 2:29 PM
Posted on April 14, 2008 14:29
http://www-youtbe-copm.fr33webhost.com/ www youtbe copm
Posted by Hughes | April 14, 2008 2:29 PM
Posted on April 14, 2008 14:29
http://xxnx.freehostplace.com/cnxx.html cnxx
Posted by Negoto | April 15, 2008 2:37 PM
Posted on April 15, 2008 14:37
http://xxnx.freehostplace.com/cnxx.html cnxx
Posted by Negoto | April 15, 2008 2:37 PM
Posted on April 15, 2008 14:37
respect
Posted by Spinu | June 19, 2008 7:08 AM
Posted on June 19, 2008 07:08
respect
Posted by Spinu | June 19, 2008 2:42 PM
Posted on June 19, 2008 14:42
respect
Posted by Spinu | June 23, 2008 3:39 PM
Posted on June 23, 2008 15:39
respect
Posted by Spinu | June 23, 2008 7:39 PM
Posted on June 23, 2008 19:39
respect
Posted by Spinu | June 23, 2008 11:20 PM
Posted on June 23, 2008 23:20
respect
Posted by Spinu | June 24, 2008 6:04 PM
Posted on June 24, 2008 18:04
respect
Posted by Spinu | June 25, 2008 8:40 AM
Posted on June 25, 2008 08:40
respect
Posted by Spinu | June 25, 2008 8:40 AM
Posted on June 25, 2008 08:40
respect
Posted by Spinu | June 25, 2008 6:40 PM
Posted on June 25, 2008 18:40
respect
Posted by Spinu | June 26, 2008 11:24 PM
Posted on June 26, 2008 23:24
respect
Posted by Spinu | June 26, 2008 11:25 PM
Posted on June 26, 2008 23:25
respect
Posted by Spinu | June 27, 2008 2:32 AM
Posted on June 27, 2008 02:32
respect
Posted by Spinu | June 27, 2008 2:32 AM
Posted on June 27, 2008 02:32
respect
Posted by Spinu | June 27, 2008 5:50 AM
Posted on June 27, 2008 05:50
respect
Posted by Spinu | June 27, 2008 5:50 AM
Posted on June 27, 2008 05:50
respect
Posted by Spinu | June 27, 2008 5:03 PM
Posted on June 27, 2008 17:03
respect
Posted by Spinu | June 28, 2008 12:13 AM
Posted on June 28, 2008 00:13
respect
Posted by Spinu | June 28, 2008 12:13 AM
Posted on June 28, 2008 00:13
respect
Posted by Spinu | June 28, 2008 3:13 AM
Posted on June 28, 2008 03:13
respect
Posted by Spinu | June 28, 2008 3:13 AM
Posted on June 28, 2008 03:13
respect
Posted by Spinu | June 28, 2008 3:13 AM
Posted on June 28, 2008 03:13
respect
Posted by Spinu | June 28, 2008 10:19 AM
Posted on June 28, 2008 10:19
respect
Posted by Spinu | June 28, 2008 1:20 PM
Posted on June 28, 2008 13:20
respect
Posted by Spinu | June 28, 2008 4:42 PM
Posted on June 28, 2008 16:42
respect
Posted by Spinu | June 28, 2008 7:46 PM
Posted on June 28, 2008 19:46
respect
Posted by Spinu | June 29, 2008 1:40 AM
Posted on June 29, 2008 01:40
respect
Posted by Spinu | June 29, 2008 1:41 AM
Posted on June 29, 2008 01:41
respect
Posted by Spinu | July 1, 2008 8:30 AM
Posted on July 1, 2008 08:30
respect
Posted by Spinu | July 1, 2008 8:30 AM
Posted on July 1, 2008 08:30
respect
Posted by Spinu | July 1, 2008 8:30 AM
Posted on July 1, 2008 08:30
respect
Posted by Spinu | July 1, 2008 8:31 AM
Posted on July 1, 2008 08:31
respect
Posted by Spinu | July 1, 2008 11:38 AM
Posted on July 1, 2008 11:38
respect
Posted by Spinu | July 1, 2008 11:38 AM
Posted on July 1, 2008 11:38
respect
Posted by Spinu | July 1, 2008 3:26 PM
Posted on July 1, 2008 15:26
respect
Posted by Spinu | July 1, 2008 3:26 PM
Posted on July 1, 2008 15:26
respect
Posted by Spinu | July 1, 2008 3:27 PM
Posted on July 1, 2008 15:27
respect
Posted by Spinu | July 1, 2008 3:27 PM
Posted on July 1, 2008 15:27
respect
Posted by Spinu | July 1, 2008 9:51 PM
Posted on July 1, 2008 21:51
respect
Posted by Spinu | July 2, 2008 8:01 AM
Posted on July 2, 2008 08:01
respect
Posted by Spinu | July 2, 2008 8:01 AM
Posted on July 2, 2008 08:01
respect
Posted by Spinu | July 2, 2008 8:02 AM
Posted on July 2, 2008 08:02
respect
Posted by Spinu | July 2, 2008 8:02 AM
Posted on July 2, 2008 08:02
respect
Posted by Spinu | July 4, 2008 3:04 AM
Posted on July 4, 2008 03:04
respect
Posted by Spinu | July 4, 2008 10:10 PM
Posted on July 4, 2008 22:10
respect
Posted by Spinu | July 5, 2008 12:39 AM
Posted on July 5, 2008 00:39
respect
Posted by Spinu | July 5, 2008 3:24 AM
Posted on July 5, 2008 03:24
respect
Posted by Spinu | July 5, 2008 3:24 AM
Posted on July 5, 2008 03:24
respect
Posted by Spinu | July 5, 2008 11:38 AM
Posted on July 5, 2008 11:38