Lessons from the cyberattacks on Estonia - Information Security Magazine - Page 1

Perspectives: The Lesson of Estonia

Were the attacks on Estonia state-sponsored cyberterrorism? Probably not, but the month-long protest signals a troubling trend.


Reports on the cyber assault against Estonia this spring once again raised the specter of pending doom in cyberspace--the "electronic Pearl Harbor" that always seems to be just over the horizon. One headline even upped the doomsday language to "cyber nuclear winter."

Is all this hype, as many experts have argued, or should we worry about cyberterrorism? So far, no attack in cyberspace has come close to bringing about the devastation, grief and political consequences of Pearl Harbor or Sept. 11, let alone nuclear war. Certainly not the cyber protest against Estonia, which left no one dead or even physically injured.

Yet the assault deserves our attention, as it took online activism to a new, worrisome level.

In one of the first cases of Internet-based protest 12 years ago, cyber activists conducted a one-hour "netstrike" against the French government. At the appointed hour, participants amassed at selected Web sites and repeatedly hit the reload button in an attempt to block legitimate use of the sites. Not much happened, but later, software was developed to automate these so-called "sit-ins." The Electronic Disturbance Theater's FloodNet software allowed activists to visit an EDT-sponsored site, where they could simply click a link to launch a barrage of page requests against a target. EDT and other groups

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

used FloodNet and similar software for Web sit-ins relating to the Mexican Zapatistas, globalization and other issues. The effects were relatively benign.

However, more powerful cyber attack tools have emerged. One of the most potent is the botnet--a network of hijacked computers used to conduct DDoS attacks or send spam. By some estimates, 70 million computers have been compromised and assigned to botnets, which are sold and rented in underground markets.

This was first published in September 2007

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.