January 08, 2008

Botnets: The new political activism

Security researchers find evidence of politically motivated botnet DOS attacks that appear to be tied to recent Russian and Ukrainian elections

As the United States' presidential candidates pinball their way across New Hampshire on the day of the state's closely watched primary elections, a new form of grassroots activism appears to be taking root across the Atlantic, in Eastern Europe, that melds dirty pool tactics with the cutting edge of malware technology.

Researchers with carrier security specialists Arbor Networks claim that they recently discovered several additional incidents of botnet-driven DOS attacks that were tied to political issues. Danny McPherson, chief research officer at Arbor, will report his group's findings to the assembled computer security and law enforcement experts at next week's Department of Defense Cyber-crime conference in St. Louis.

Since April 2007, when a campaign of targeted denial-of-service (DOS) attacks against Web sites controlled by the prime minister of Estonia and several regional banks were carried out with crushing results -- crippling the URLs for a period of several days -- experts have wondered aloud to what extent politics played a hand in the scheme.

At the time, press reports and IT security experts speculated that tension between Estonia and Russia -- sparked by Estonia's decision to move a Soviet-era World War II memorial of a bronze soldier -- may have motivated the coordinated DOS attacks. With a number of well-known malware distribution and botnet control networks based out of the region, experts speculated that Russian hackers, either on their own or at the behest of a paying customer, took out the Estonian sites to display their displeasure with the statue's removal.

Now new evidence has been discovered that indicates the same sort of political activism believed to have driven the 2007 Estonian Web site attacks not only exists but is becoming more popular.

"We spent some time after the Estonia attacks looking into this part of the world, and we've found evidence of other politically motivated botnet DOS attacks," said Jose Nazario, senior software engineer at Arbor. "It's hard to tell who is responsible for these campaigns, but they definitely appear to be tied to some recent Russian and Ukrainian elections."

According to Nazario, who is known as an expert tracker of botnets -- the armies of malware-infected computers that can be controlled remotely to be used for everything from DOS campaigns to the distribution of spam -- two elections in particular appear to have drawn activity similar to the Estonia incidents.

In one instance, Nazario said his team uncovered a botnet-driven DOS threat carried out against several Web sites controlled by Viktor Yanukovych, the recently defeated Ukranian prime minister, during his re-election campaign.

In another incident, Nazario said that his team was able to discover a DOS campaign aimed at sites controlled by the "Other Russia" political party led by one-time 2008 Russian presidential candidate Garry Kasparov, who is more widely known as one of the greatest chess players of all time.

During each of the individual attacks, banks of botnet-infected computers successfully took the candidates' sites down for several days before they were restored, according to Arbor.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
How to Improve Delivery of Advanced Web Applications

White Paper

How to Improve Delivery of Advanced Web Applications

The increasing demands for high availability, reliability and security of application access are driving the need for load balancers that not only provide traditional networking traffic management functions, but also a comprehensive set of network-level and application-level services. Learn more about these services and how they improve Web application delivery.

Download now »
IDC White Paper: CCM for IT Compliance and Risk Management

White Paper

IDC White Paper: CCM for IT Compliance and Risk Management

Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these organizations are applying the resulting processes to enhance security and improve operational efficiency in order to increase their level of service delivery.

Download now »
HP - Staying Ahead of the Virtualization Curve

White Paper

Staying Ahead of the Virtualization Curve

Get real-world, timely information on supporting virtualization throughout your enterprise environment in this collection of articles from InfoWorld and its sister publications. Virtualization is no longer a question of if, but when. And if you're not deploying it today, what are you waiting for?

Download now »
Successfully Achieve Storage Efficiency

White Paper

Successfully Achieve Storage Efficiency

Dramatically lower your storage and operational cost savings by following the four steps to storage efficiency spelled out in this whitepaper. The keys include developing and implementing effective policies along with deploying new technologies including intelligent storage tiering.

Download now »

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.