2007 cyberattacks on Estonia

2007 cyberattacks on Estonia

Cyberattacks on Estonia refers to a series of cyber attacks that began April 27, 2007 and swamped websites of Estonian organizations, including Estonian parliament, banks, ministries, newspapers and broadcasters, amid the country's row with Russia about the relocation of the Bronze Soldier of Tallinn, an elaborate Soviet-era grave marker, as well as war graves in Tallinn.[1][2] Most of the attacks that had any influence on the general public were distributed denial of service type attacks ranging from single individuals using various methods like ping floods to expensive rentals of botnets usually used for spam distribution. Spamming of bigger news portals commentaries and defacements including that of the Estonian Reform Party website also occurred.[3]

Some observers reckoned that the onslaught on Estonia was of a sophistication not seen before. The case is studied intensively by many countries and military planners as, at the time it occurred, it may have been the second-largest instance of state-sponsored cyberwarfare, following Titan Rain.[4]

Estonian Foreign Minister Urmas Paet accused the Kremlin of direct involvement in the cyberattacks[5]. On September 6, 2007 Estonia's defense minister admitted he had no evidence linking cyber attacks to Russian authorities. "Of course, at the moment, I cannot state for certain that the cyber attacks were managed by the Kremlin, or other Russian government agencies," Jaak Aaviksoo said in interview on Estonian's Kanal 2 TV channel. Aaviksoo compared the cyber attacks with the blockade of Estonia's Embassy in Moscow. "Again, it is not possible to say without doubt that orders (for the blockade) came from the Kremlin, or that, indeed, a wish was expressed for such a thing there," said Aaviksoo. Russia called accusations of its involvement "unfounded," and neither NATO nor European Commission experts were able to find any proof of official Russian government participation.[6]

As of January 2008, one ethnic-Russian Estonian national has been charged and convicted.[7]

During a panel discussion on cyber warfare, Sergei Markov of the Russian State Duma has stated his unnamed aide was responsible in orchestrating the cyber attacks. Markov alleged the aide acted on his own while residing in an unrecognised republic of the former Soviet Union, possibly Transnistria.[8] On March 10, 2009 Konstantin Goloskokov, a "commissar" of the Kremlin-backed youth group Nashi, has claimed responsibility for the attack.[9] Experts are critical of these varying claims of responsibility.[10]

Contents

Legalities

On May 2, 2007, a criminal investigation was opened into the attacks under a section of the Estonian Penal Code criminalising computer sabotage and interference with the working of a computer network, felonies punishable by imprisonment of up to three years. As a number of attackers turned out to be within the jurisdiction of the Russian Federation, on May 10, 2007, Estonian Public Prosecutor's Office made a formal investigation assistance request to the Russian Federation's Supreme Procurature under a Mutual Legal Assistance Treaty (MLAT) existing between Estonia and Russia. A Russian State Duma delegation visiting Estonia in early May in regards the situation surrounding the Bronze Soldier of Tallinn had promised that Russia would aid such investigation in every way available.[11] On June 28, Russian Supreme Procurature refused assistance,[11] claiming that the proposed investigative processes are not covered by the applicable MLAT.[12] Piret Seeman, the Estonian Public Prosecutor's Office's PR officer, criticized this decision, pointing out that all the requested processes are actually enumerated in the MLAT.[12]

On 24 January 2008, Dmitri Galushkevich, a student living in Tallinn, was found guilty of participating in the attacks. He was fined 17,500 kroons (approximately US$1,640) for attacking the website of the Estonian Reform Party.[3][13]

As of 13 December 2008, Russian authorities have been consistently denying Estonian law enforcement any investigative cooperation, thus effectively eliminating chances that those of the perpetrators that fall within Russian jurisdiction will be brought to trial.[14]

Opinions of experts

Critical systems whose network addressed would not be generally known were targeted, including those serving telephony and financial transaction processing.[15] Although not all of the computer crackers behind the cyberwarfare have been unveiled, some experts believed that such efforts exceed the skills of individual activists or even organised crime as they require a co-operation of a state and a large telecom company.[4]

A well known Russian hacker Sp0Raw believes that the most efficient online attacks on Estonia could not have been carried out without a blessing of the Russian authorities and that the hackers apparently acted under "recommendations" from parties in higher positions.[16] [17] At the same time he called claims of Estonians regarding direct involvement of Russian government in the attacks [18] "empty words, not supported by technical data".[17]

Mike Witt, deputy director of the United States Computer Emergency Readiness Team (CERT) believes that the attacks were DDoS attacks. The attackers used botnets - global networks of compromised computers, often owned by careless individuals. "The size of the cyber attack, while it was certainly significant to the Estonian government, from a technical standpoint is not something we would consider significant in scale," Witt said.[19]

Professor James Hendler, former chief scientist at The Pentagon's Defense Advanced Research Projects Agency (DARPA) characterised the attacks as "more like a cyber riot than a military attack."[19]

"We don't have directly visible info about sources so we can't confirm or deny that the attacks are coming from the Russian government," Jose Nazario, software and security engineer at Arbor Networks, told internetnews.com.[20] Arbor Networks operated ATLAS threat analysis network, which, the company claimed, could "see" 80% of Internet traffic. Nazario suspected that different groups operating separate distributed botnets were involved in attack.

Experts interviewed by IT security resource SearchSecurity.com "say it's very unlikely this was a case of one government launching a coordinated cyberattack against another": Johannes Ullrich, chief research officer of the Bethesda said "Attributing a distributed denial-of-service attack like this to a government is hard." "It may as well be a group of bot herders showing 'patriotism,' kind of like what we had with Web defacements during the US-China spy-plane crisis [in 2001]." Hillar Aarelaid, manager of Estonia's Computer Emergency Response Team "expressed skepticism that the attacks were from the Russian government, noting that Estonians were also divided on whether it was right to remove the statue".[21]

Clarke and Knake report that upon the Estonian authorities informing Russian officials they had traced systems controlling the attack to Russia, there was some indication in response that incensed patriotic Russians might have acted on their own.[15] Regardless of conjectures over official involvement, the decision of Russian authorities not to pursue individuals responsible — a treaty obligation — together with expert opinion that Russian security services could readily track down the culprits should they so desire, leads Russia observers to conclude the attacks served Russian interests.[15]

Claiming responsibility for the attacks

A Commissar of the Nashi pro-Kremlin youth movement in Moldova and Transnistria, Konstantin Goloskokov (Goloskov in some sources [22]), admitted organizing cyberattacks against Estonian government sites.[16] Goloskokov stressed, however, that he was not carrying out an order from Nashi's leadership and said that a lot of his fellow Nashi members criticized his response as being too harsh.[17]

Like most countries, Estonia does not recognise Transnistria, a secessionist region of Moldova. As an unrecognised nation, Transnistria does not belong to Interpol[23]. Accordingly, no Mutual Legal Assistance Treaty applies. If residents of Transnistria were responsible, the investigation may be severely hampered, and even if the investigation succeeds finding likely suspects, the legal recourse of Estonian authorities may be limited to issuing all-EU arrest warrants for these suspects. Such an act would be largely symbolic.

Head of Russian Military Forecasting Center, Colonel Anatoly Tsyganok confirmed Russia's ability to conduct such an attack when he stated: "These attacks have been quite successful, and today the alliance had nothing to oppose Russia's virtual attacks", additionally noting that these attacks did not violate any international agreement.[24]

Influence on international military doctrines

The attacks triggered a number of military organisations around the world to reconsider the importance of network security to modern military doctrine. On June 14, 2007, defence ministers of NATO members held a meeting in Brussels, issuing a joint communiqué promising immediate action. First public results were estimated to arrive by autumn 2007.[25]

On June 25, 2007, Estonian president Toomas Hendrik Ilves met with the president of USA, George W. Bush.[26] Among the topics discussed were the attacks on Estonian infrastructure. [27] NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) operates out of Tallinn, Estonia, since August 2008 [28]

The events have been reflected in a NATO Department of Public Diplomacy short movie War in Cyberspace.[29]

See also

References

  1. ^ The Guardian May 17, 2007: Russia accused of unleashing cyberwar to disable Estonia by Ian Traynor
  2. ^ "War in the fifth domain. Are the mouse and keyboard the new weapons of conflict?". The Economist. July 1, 2010. http://www.economist.com/node/16478792. Retrieved 2010-07-02. "Important thinking about the tactical and legal concepts of cyber-warfare is taking place in a former Soviet barracks in Estonia, now home to NATO’s “centre of excellence” for cyber-defence. It was established in response to what has become known as “Web War 1”, a concerted denial-of-service attack on Estonian government, media and bank web servers that was precipitated by the decision to move a Soviet-era war memorial in central Tallinn in 2007." 
  3. ^ a b "Estonia fines man for 'cyber war'". BBC. 2008-01-25. http://news.bbc.co.uk/2/hi/technology/7208511.stm. Retrieved 2008-02-23. 
  4. ^ a b The Economist May 24, 2007: Cyberwarfare is becoming scarier
  5. ^ Estonia accuses Russia of 'cyberattack'
  6. ^ Estonia has no evidence of Kremlin involvement in cyber attacks
  7. ^ "Estonia fines man for 'cyber war'". BBC News. January 25, 2008. http://news.bbc.co.uk/2/hi/technology/7208511.stm. Retrieved April 22, 2010. 
  8. ^ Radio Free Europe March 6, 2009: Behind The Estonia Cyberattacks by Robert Coalson
  9. ^ Kremlin-backed group behind Estonia cyber blitz Financial Times March 11, 2009
  10. ^ Authoritatively, Who Was Behind The Estonian Attacks? DarkReading March 17, 2009
  11. ^ a b Postimees July 6, 2007: Venemaa jätab Eesti küberrünnakute uurimisel õigusabita
  12. ^ a b Eesti Päevaleht July 6, 2007: Venemaa keeldus koostööst küberrünnakute uurimisel
  13. ^ Leyden, John (2008-01-24). "Estonia fines man for DDoS attacks". The Register. http://www.theregister.co.uk/2008/01/24/estonian_ddos_fine. Retrieved 2008-02-22 
  14. ^ ERR 13 December 2008 16:43: Venemaa keeldub endiselt koostööst küberrünnakute uurimisel
  15. ^ a b c Clarke, R.A., Knake, R.K. Cyber War: The Next Threat To National Security And What To Do About It. Harper Collins. 2010.
  16. ^ a b Swiss Baltic Chamber of Commerce in Lithuania/Baltic News Service June 2, 2007: Commissar of Nashi says he waged cyber attack on Estonian government sites
  17. ^ a b c (Russian) Электронная бомба. Кто стоит за кибервойной России с Эстонией
  18. ^ Times Online: Urmas Paet, the Estonian Foreign Minister, accused the Kremlin of direct involvement
  19. ^ a b United Press International: Analysis: Who cyber smacked Estonia?
  20. ^ Internetnews.com: Estonia Under Russian Cyber Attack?
  21. ^ Experts doubt Russian government launched DDoS attacks, by Bill Brenner, 18 May 2007. SearchSecurity.com
  22. ^ Monument dispute with Estonia gets dirty
  23. ^ Tiraspol Times June 9, 2007: Ministry of Internal Affairs lists PMR's 10 most wanted
  24. ^ Руководитель российского Центра военного прогнозирования полковник Анатолий Цыганок считает, что кибератаки против Эстонии не нарушали никаких международных договоренностей, потому что таковых просто нет. "Эти атаки были вполне успешными, и сегодня альянсу нечего противопоставить российским виртуальным атакам, - заявил Цыганок в интервью «Газете». - В принципе потери вооружений НАТО могут быть огромными, если в результате таких атак вывести из строя компьютерное военное управление».
  25. ^ Eesti Päevaleht June 15, 2007: NATO andis rohelise tule Eesti küberkaitse kavale by Ahto Lobjakas
  26. ^ White House May 4, 2007: President Bush to Welcome President Toomas Ilves of Estonia
  27. ^ Yahoo/AFP June 25, 2007: Bush, Ilves eye tougher tack on cybercrime
  28. ^ NATO to set up cyber warfare center
  29. ^ Postimees 28 March 2009 14:02: NATO tegi filmi Eesti «kübersõjast»

External links


Wikimedia Foundation. 2010.

Игры ⚽ Поможем решить контрольную работу

Look at other dictionaries:

  • Cyberattacks during the 2008 South Ossetia war — The website of the Parliament of Georgia (parliament.ge) had its content replaced with a montage of photos depicting Mikheil Saakashvili and Adolf Hitler. The Russian language caption reads, He too will come to an end as well. [1] During the …   Wikipedia

  • Estonia–Russia relations — Estonia Russia relations refers to bilateral foreign relations between Estonia and Russia. Diplomatic relations between Republic of Estonia and Russian SFSR were established on February 2, 1920, when Bolshevist Russia recognized de jure the… …   Wikipedia

  • 2008 cyberattacks on Georgia and Azerbaijan — Cyberattacks on Georgia and Azerbaijan refers to a series of cyber attacks that began August 9, 2008 [http://www.stupidsheeple.com/index.php/2008081036/latest/russian cyber attacks georgia.html] and swamped websites of Georgian… …   Wikipedia

  • 2010 cyberattacks on Burma — The 2010 cyberattacks on Myanmar were distributed denial of service attacks that began on 25 October,[1] occurring ahead of the Burmese general election, 2010, which is widely viewed as a sham election.[2][3] The attacks were significantly larger …   Wikipedia

  • Military of Estonia — Estonian Defence Forces Eesti Kaitsevägi Estonian Defence Forces emblem and flag Service b …   Wikipedia

  • Dates of 2007 — ▪ 2008 January Ladies and gentlemen: on this day, at this hour, it is still within our power to shape the outcome of this battle. Let us find our resolve, and turn events toward victory. U.S. Pres. George W. Bush, asking for support for his… …   Universalium

  • Cyberwarfare in Russia — includes allegations of denial of service attacks, hacker attacks, dissemination of disinformation over the internet, participation of state sponsored teams in political blogs, internet surveillance using SORM technology, and persecution of cyber …   Wikipedia

  • Cyberterrorism — Not to be confused with Internet and terrorism. Terrorism Definitions · Counter terrorism International conventions Anti terrorism …   Wikipedia

  • 2008 cyber-attacks on Georgia and Azerbaijan — The Cyberattacks on Georgia and Azerbaijan were a series of cyber attacks that began August 9, 2008 [http://www.stupidsheeple.com/index.php/2008081036/latest/russian cyber attacks georgia.html] and swamped websites of Georgian… …   Wikipedia

  • Cooperative Cyber Defence Centre of Excellence — Küberkaitse Kompetentsikeskus Cooperative Cyber Defence Centre of Excellence Located in Tallinn, Estonia Type NATO Centre of Excellence Coo …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”