A PDF version of this article is also available for download.
In the early part of April of this year, the country of Estonia was attacked in cyberspace. While there has been much to do about the event in the press there are some very important issues that are being missed. First and foremost, nothing about the attack (including its duration) is new. Second, the attack is noteworthy because it was not coordinated by the Russians. This puts strategic cyberwarfare in the hands of non-state actors. Third, there are things we can do to prepare for eventual future attacks.
To those in the business of information security and assurance, nothing about the attack, how it was conducted or the technologies used, is new. The attacks used were standard bot-net distributed denial of service (DDoS) attacks. DDoS are a tried and true form of internet extortion and attack. We have seen large scale attacks against the US military infrastructure (Network Attack Disables Naval College) and private companies. In fact, attacks of this type drove an Israeli company out of business ( Blue Security Folds Under Spammer's Wrath).
The power of a botnet lies in its size, simplicity and synchronicity. In the physical realm, the hardest attack is one that coordinates operations in multiple geographic regions with simultaneity in attack time and target. A bot-net solves these issues very well. A single command in a handful of chatrooms sends the exact same order to every member of the botnet. In the case of a DDoS attack, the order is simple; "at a specific time, continually send large amounts of traffic to the following target or targets".
Using a very quick von Clausewitz analysis, here's how the attack measures up:
The fact that the attack against Estonia was not state sponsored is even more chilling than if it had been an open act of state aggression. For the past 10 plus years, the world has seen most nations develop military based information operations units. The nations in this list are of varying degrees of industry and wealth. We expect that most nations either are developing, or have developed, the ability to conduct offensive operations in cyberspace. Similarly, we know and expect the private sector to engage in its own brand of warfare. Organized crime regularly targets companies and private networks for theft, extortion, etc. What we see in the Estonia attack is the first incident of a private sector actor(s) attacking a state with strategic impact. Furthermore, since this is most likely the act of individuals instead of a government, the attackers are shielded through a maze of legal issues involving jurisdiction, extradition, trial and punishment.
The second chilling part of this fact is that our enemies learn from each other. Botnet attacks are cheap when compared to conventional strategic weapons. Any Al-Qaeda cell has the financial means to purchase a time limited DDoS attack against any target on the internet. Most believe that this is contrary to the traditional need to create blood, bodies and terror. However, when you combine a targeted DDoS attack against critical infrastructure and couple that with the core competency of terrorism, bombings; you have a very real and very dynamic result.
A concerted DDoS attack is an excellent force multiplier for a traditional physical attack. With technology convergence, DDoS attacks are not just for websites. Cell phones, pagers and other mobile communication devices are susceptible to denial of service attacks.
There are two primary principles for the future:
At this time, the modern world (with few exceptions) believes that counter attacking, "cyber self defense" or "active defense", is illegal. I am not aware of any national or international agreements, laws or treaties that require a nation to stand by and allow its citizenry and infrastructure to be freely attacked. Use of cyberforce in the defense of a nation and its populace is no different than the use of physical force. (For a complete discussion on this please see Offensive Operations in Cyberspace by White Wolf Security ). A sovereign nation is allowed to take reasonable steps in the protection of itself. It is time we start doing so.
This is not the first multi-day attack that we've seen, nor will it be the last. The owner/operators of IT infrastructure need to start thinking about ways to train that will realistically prepare them for a protracted and directed attack. The best training model for this is the military exercise. The military is very adept at multi-day exercises. These exercises not only test the equipment our forces use to fight, but also build the unit cohesion and leadership skills that no amount of technology can replace. The exercises have aggressors and defenders, missions and op orders. Best of all is the after action review. A process that formalizes the debriefing process and maximizes lessons learned. White Wolf Security offers its MANTA (Multi-day Active Network Tactical Assault) exercise. MANTA is an around the clock exercise that focuses on several core combat principles
We must treat our IT professionals as combat personnel and train them accordingly. Not just in skill, but in spirit, too.