• On TV.com: THE GIRLS NEXT DOOR photos
May 21, 2007 1:56 PM PDT

Cyber war in Estonia

Posted by Robert Vamosi
  • Font size
  • Print

Warning: disturbing a war memorial can provoke all out cyber war--at least in Estonia. On April 27, 2007, Estonia officials relocated the "Bronze Soldier," a Soviet-era war memorial commemorating an unknown Russian who died fighting the Nazis, a move that incited rioting by ethnic Russians and the blockading of the Estonian Embassy in Moscow. It also started a large and sustained distributed denial-of-service attack on several Estonian Web sites, including those of government ministries and the prime minister's Reform Party. A denial-of-service attack (DoS) occurs when someone directs a large number of requests to a target URL; the requests occur so quickly that the Web server can't respond and the site becomes inaccessible to everyone. A distributed denial-of-service attack (DDoS) occurs when hundreds or thousands of compromised computers are enlisted. Within the last week, the intensity of the attacks diminished.

Arbor Networks' Jose Nazario has now blogged his analysis of the Estonian DDos attacks. He reports that Arbor Networks recorded 128 unique DDoS attacks on Estonian-based URLs. Most lasted less than one hour, with the longest lasting 10 hours and 30 minutes. As for the strength, measured in how many packets of information flooded the given URL to make it inaccessible, the attacks were relatively light, with only ten of the attacks measuring 90-plus Mbps, including one of the 10-hour attacks. At its peak on May 9, the attack shut down up to 58 sites at once.

That's a lot of fire power, and it suggests the use of "botnets"--collections of compromised home and office computers worldwide. In this scenario, a "botherder" directs thousands of compromised computers to request simultaneous access to a single URL, effectively shutting down that site. Computer Security Incident Response Teams (CSIRTs) in several countries, as well as NATO, have assisted the Estonian government in handling the attacks. Early analysis suggests the attacks may have originated in Russia.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Crave
Samsung LED monitor takes advantage
Ion's bevy of turntables and iPod accessories
Psyko 5.1 headset puts speakers where they've never been before
T-Mobile slide show
Panasonic SC-TZ1: wireless, ultra-slim speaker system
LG BD390 Blu-ray player includes built-in Wi-Fi
Nokia shows off the BH-804 Bluetooth headset
News of home theater tech from LG comes streaming in
advertisement

About Crave

The name says it all. Crave is our blog about gorgeous gadgets and other crushworthy stuff. If you would like to contact Crave with a tip or comment, please write to: crave@cnet.com

Add this feed to your online news reader

Crave topics

In the news now

Yahoo's Decker strong contender for CEO

Sources say the president of the embattled Internet search pioneer has been through two rounds of interviews with the board.


Gadget extravaganza in Las Vegas

CES 2009 is in full swing. Highlights so far include Palm's WebOS and Pre device, Microsoft's Windows 7 beta, and much more.


advertisement

Inside CNET News

Scroll Left Scroll Right
-->